Follow

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use
Subscribe

MiCA Authorisation Deadline Strands 1,062 EEA Crypto Firms Outside Licensing Regime

MiCA authorisation deadline MiCA authorisation deadline

The MiCA authorisation deadline of 1 July 2026 passed with only 281 of 1,343 identified crypto-asset service providers (CASPs) across the European Economic Area holding valid licences, leaving 1,062 firms that must now exit the market, restructure, or transfer customers to an authorised provider. The figures come from blockchain intelligence firm TRM Labs, whose dataset tracked firms it could identify as actively providing crypto services rather than every entry on national registers.

The headline number understates how long the contraction has been building. Several member states, including Finland, Lithuania, Germany, the Netherlands, Ireland, Latvia, Hungary, and Austria, closed their national grandfathering windows between 2025 and January 2026, well ahead of the EU-wide cutoff, according to Narvi. The Central Bank of Ireland required any registered virtual asset service provider (VASP) intending to continue operating to obtain CASP authorisation before 30 December 2025, six months ahead of the final EU deadline.

Risk Profiles Diverge Sharply Across the MiCA Authorisation Deadline

The licensing gap correlates with risk. TRM found that 12% of unauthorised firms carry a High or Severe rating, six times the 2% recorded among authorised providers. Every firm assigned a Severe rating fell in the unauthorised cohort.

Aggregate illicit exposure across each group looks similar on the surface: unauthorised providers recorded 0.09% of outgoing volume going directly to illicit or high-risk counterparties, versus 0.07% among licensed firms. The distribution within the unauthorised group is far more skewed. Half of those firms showed no measurable direct illicit exposure at all, while a small number sent between 1% and 12% of their volume directly to illicit addresses, pushing the group average roughly four times higher than it would otherwise be.

Sanctions exposure produced the clearest gap. Unauthorised firms sent $5 billion directly to sanctioned counterparties, roughly three times the $1.7 billion recorded among authorised providers. The unauthorised cohort also included HTX, which TRM described as a designated exchange, and Huione Pay, named under US special measures. Entities subject to EU measures restricting dealings connected to Russia were also among firms holding national registrations but no MiCA licence.

The composition of the two groups differs, too. Exchanges made up 42% of unauthorised providers versus 29% of authorised firms. Payment companies represented 16% of unauthorised providers and 9% of authorised ones. Financial and investment service providers were more common in the authorised group at 25% and 21% respectively, compared with 9% and 7% among those without licences.

Uneven Authorisation Across Jurisdictions Raises Passporting Questions

Authorisation has not been distributed evenly. Germany’s BaFin authorised 55 firms in TRM’s July 1 dataset; by 3 July, Zitadelle AG’s tracking of the ESMA register put the BaFin figure at 58 and the total at 280. The snippet cites 300 authorised CASPs on the ESMA register by 3 July after 57 firms were added around the deadline, including Standard Chartered and FalconX; the two counts reflect slightly different compilation times.

France and the Netherlands each authorised 29. Malta approved 20 and Cyprus 19. Italy, despite hosting 145 operating firms, issued only nine home authorisations. Lithuania converted eight licences from a previous register of more than 400 providers. Poland issued none despite a prior register exceeding 1,800 entries, most of which TRM said showed no observable crypto activity.

MiCA’s passporting system means home authorisation and operational footprint can diverge significantly. A CASP licensed by one member state can serve customers across all 27 EU member states and the three additional EEA markets. Coinbase, Bitpanda, and Kraken have each used this mechanism to operate from a single regulatory base while covering multiple European markets.

TRM found no correlation between the number of authorisations a jurisdiction issued and the illicit exposure of firms it supervises, across 23 jurisdictions with measurable licensed transaction volume. For counterparty due diligence, that means a regulator’s licence count is a poor proxy for individual provider risk.

The supervisory pressure now shifts to offboarding. AMLA’s advisory note warns that abrupt exits reduce transparency over asset flows, create conditions for rapid movement of illicit funds, and complicate sanctions oversight during wind-down. The authority has instructed supervisors to prioritise exit plan oversight and cross-jurisdictional coordination as customers migrate.

TRM identified 30 unauthorised providers carrying High or Severe risk ratings, giving receiving CASPs a screenable population before customer migrations begin. Entity-level screening matters here: most firms that missed authorisation still carry Low risk ratings and negligible direct illicit exposure, but the tail risk from the Severe-rated cohort is measurable enough that blanket treatment of all migrating customers would obscure it.

One compliance dimension that will intensify pressure on newly authorised firms: Cyfrin notes that from March 2026, Electronic Money Token custody and transfer services may require both MiCA authorisation and a separate payment services licence under PSD2, potentially doubling compliance costs for euro stablecoin providers. Receiving CASPs absorbing customers from unauthorised payment-focused firms will face that dual-licensing question alongside the customer migration workload.

ESMA separately launched a review of MiCA-authorised crypto custodians in July, examining custody controls, private-key management, incident response, and third-party provider risks. K&L Gates noted that ESMA had set out its expectations for transitioning unauthorised CASPs in a public statement on 23 June 2026. The custodian review signals that the post-deadline supervisory focus is not limited to the firms that failed to get licensed.

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use