
The grace period is gone. As of July 1, 2026, the Markets in Crypto-Assets Regulation (MiCA) applies in full across the European Union, and the national transitional regimes that let existing virtual asset service providers keep trading on old registrations have expired. On June 23, ESMA put the point beyond doubt: “There is no grace period coming. No last-minute reprieve.” Any firm still providing crypto-asset services in the EU without a MiCA authorisation is now operating in breach of EU law.
The numbers explain why this deadline mattered more than most regulatory dates. Of the roughly 1,200 entities that held national-level crypto registrations before MiCA, only 244 had secured full CASP (Crypto-Asset Service Provider) authorisation by June 29 — a compliance rate of 17-20%. Germany leads with 57 licenses, France follows with 26. That leaves well over 900 previously registered providers on the wrong side of the line, most of them now required to be in wind-down rather than growth mode.
What changes on the ground
For authorised CASPs, July 1 is mostly an operational milestone: client migration, onboarding flows and AML/CFT controls now run under full MiCA supervision rather than a transitional overlay. For everyone else, ESMA’s expectations are explicit and leave no room for interpretation. Unauthorised firms must immediately stop onboarding new EU clients, halt all marketing directed at EU customers, and limit activity to an orderly exit — asset transfers to authorised CASPs or to clients’ self-hosted wallets, and account closures, with prior notice to clients. There is no version of “we’ll keep operating quietly while the application is pending.” The transitional window either converted into an authorisation or it closed.
Enforcement sits with 27 national competent authorities, which means practical treatment will vary — but the underlying obligation does not. Clients of unauthorised firms lose the protections MiCA was built to guarantee: asset segregation, complaint-handling standards, custody rules, and the investor safeguards that come with a genuine license rather than a legacy registration. That gap is itself a commercial risk for any counterparty, bank, or payment provider still dealing with an unlicensed platform.
The Cyprus angle
Cyprus offers a clean illustration of how the transition actually worked. CySEC closed its local CASP registration regime to new applicants on 17 October 2024 and stopped accepting cross-border EEA applications on 30 October 2024, signalling from early on that the national regime was a bridge, not a destination. Firms already registered before 30 December 2024 were allowed to keep operating under transitional protection until 1 July 2026 or until their MiCA application was decided, whichever came first. That bridge is now behind us. Firms that used the transitional window without converting it into a CySEC-issued MiCA authorisation are, as of this month, in the same position as any other unauthorised provider — regardless of how long they had been registered locally.
This matters beyond crypto-native firms. Cyprus remains a preferred jurisdiction for EMI/PSP structuring, fund administration and holding structures serving crypto-adjacent business, and banking partners are now actively screening counterparties for MiCA status before onboarding or renewing relationships. A local registration that predates MiCA is no longer a credential a bank or payment partner will accept at face value.
What this means in practice
Three groups need to act differently starting now.
Firms that already hold a MiCA/CASP authorisation should treat this as a compliance baseline, not a finish line — supervisory attention typically intensifies once a licensing wave settles, and early enforcement actions tend to focus on firms whose actual operating model diverges from what was described in the application.
Firms still mid-application, or that let the window close without applying, need an honest assessment of two separate tracks: an orderly wind-down of EU-facing activity if authorisation isn’t realistic in the near term, versus a genuine restructuring — new entity, new jurisdiction, revised business model — if the underlying business is worth relicensing properly. Trying to keep serving EU clients informally while “sorting out the paperwork” is the scenario ESMA’s statement was written to close off.
Businesses adjacent to crypto — banks, EMIs, payment processors, corporate service providers, and investors — should treat MiCA/CASP status as a standing due-diligence item for any counterparty in this space, not a one-time check at onboarding. A registration that was valid in 2024 tells you nothing about a firm’s standing in July 2026.
Where SK Consult can help
We work with crypto and fintech businesses on the structuring side of exactly this problem: assessing whether a MiCA application is realistic for a given entity and jurisdiction, building the cross-border structure to support it, and handling the banking and EMI/PSP relationships that increasingly hinge on clean licensing status. If your business — or a counterparty you rely on — is still working through what July 1 means in practice, this is a conversation worth having now rather than after a bank asks the question first.
This article reflects the regulatory position as of July 2026 and is provided for general information. It does not constitute legal advice for any specific situation — please contact us directly to discuss your circumstances.


