Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Regulatory Compliance

MiCA's Transition Window Just Closed: What US Crypto Companies Still Serving EU Clients Must Do Now

The 18-month MiCA transitional period for crypto-asset service providers ended June 30, 2026. US exchanges and crypto firms that continue serving EU clients without authorization risk fines up to €5M or 3% of global turnover enforced simultaneously across 27 EU jurisdictions. Here's what changed, what the reverse solicitation exception actually allows, and the three paths forward.

By Rebecca Leung · July 9, 2026 ·
Table of Contents

The 18-month window closed ten days ago.

On June 30, 2026, the transitional period under MiCA’s Article 143(3) expired in the EU member states that ran it for its full duration. Since December 30, 2024, when MiCA’s Title V provisions governing crypto-asset service providers (CASPs) took full effect, firms that were already operating under pre-MiCA national registration frameworks had borrowed time to either get authorized or get out. That time is now up.

If your firm is a US exchange, crypto broker, custody provider, or platform with EU clients and no MiCA authorization, you are — as of July 1, 2026 — providing regulated financial services without a license across the world’s largest unified regulatory zone.

TL;DR

  • The MiCA 18-month CASP transitional period ended June 30, 2026 — CASPs now need full MiCA authorization to serve EU clients with no grace period remaining
  • MiCA has no third-country equivalence regime: US licenses do not substitute for EU authorization, and there is no Commission equivalence decision pathway for CASPs
  • The reverse solicitation exception (Article 61) is extremely narrow — ESMA’s February 2025 guidelines confirm it cannot be manufactured through disclaimers, affiliate structures, or prior marketing
  • Fines reach €5M or 3% of global annual turnover, enforced by NCAs in each member state where affected clients are located — 27 jurisdictions with independent enforcement authority
  • Three realistic options exist: pursue MiCA authorization, exit the EU market, or wind down to genuine reverse-solicitation-only interactions — and most firms with meaningful EU client bases can’t credibly live at option three

What Happened on July 1, 2026

MiCA — Regulation (EU) 2023/1114 — is the EU’s comprehensive framework for crypto-asset markets. It created a licensing regime that superseded 27 separate national approaches and established a single EU-wide authorization with passporting rights.

For crypto-asset service providers, the key dates were:

  • December 30, 2024: MiCA Title V, governing CASP authorization and ongoing obligations, became fully applicable across the EU.
  • June 30, 2026: Article 143(3) transitional protection expired. CASPs grandfathered under pre-MiCA national registration frameworks lost that protection. Full MiCA authorization is now required.

Some EU member states didn’t give CASPs the full 18 months. The Netherlands, Finland, and Latvia — among others — applied shorter national transitional windows, creating earlier effective deadlines for firms with significant operations in those countries.

On June 23, 2026, ESMA issued a public statement reminding market participants that the transitional period was ending and that crypto-asset services provided to EU clients after the deadline without MiCA authorization would constitute unlicensed activity. ESMA subsequently updated its CASP register post-deadline, adding newly authorized firms — including Standard Chartered’s EU crypto entity and dozens of others — while removing entities whose transitional protection expired without authorization being granted.

The message from the EU’s regulatory apparatus is unambiguous: the transition period is finished.

No Third-Country Regime — The Core Problem for US Firms

The most common misconception among US crypto companies is that MiCA works like other EU financial services frameworks — that there’s a third-country equivalence pathway, or that a US regulatory license can substitute for EU authorization if ESMA or the European Commission recognizes the home jurisdiction.

MiCA does not work that way.

Unlike EU banking regulation (CRD/CRR), AIFMD, or UCITS — each of which contains provisions allowing the Commission to recognize non-EU jurisdictions as equivalent, permitting remote cross-border services under certain conditions — MiCA’s CASP framework has no general equivalence mechanism. There is no pathway for the Commission to declare US SEC or CFTC oversight “equivalent” to MiCA and thereby allow US-registered entities to serve EU clients remotely.

ESMA has been explicit on this point. A US exchange registered with the SEC and fully compliant with US digital asset regulations has zero regulatory authorization to serve EU clients under MiCA. It has potential enforcement exposure in every EU member state where its clients reside.

The only path to serving EU clients under MiCA is obtaining authorization from one EU member state’s national competent authority, and then using the MiCA passport to operate across all 27 member states from that single home-state license.

That’s what the major exchanges have been executing on. Coinbase obtained authorization through its EU subsidiary. Kraken received MiCA authorization. Bybit, OKX, Crypto.com, and others have either licensed up or are in process. The firms that treated MiCA seriously recognized that the EU market is too significant — and the compliance requirement too unambiguous — to treat as optional.

For smaller US firms that deferred this assessment: the window to rely on transitional protection is closed. The question is what to do now.

The Reverse Solicitation Trap

MiCA Article 61(1) contains an exception that many US firms have latched onto as a potential compliance safe harbor: the “exclusive initiative” or “reverse solicitation” provision. If an EU client approaches a CASP entirely on their own initiative — without any solicitation, marketing, or promotion by the CASP targeting EU residents — the CASP may provide services to that client without MiCA authorization.

ESMA issued guidelines in February 2025 specifically addressing how to apply this exception. Those guidelines eliminated most of the compliance strategies US firms were building around it.

ESMA’s guidance established that reverse solicitation:

Cannot be triggered after prior marketing. If a US firm ran social media ads targeting EU countries, purchased keyword advertising reaching EU users, or operated a website clearly directed at EU audiences, any services that follow do not qualify as “exclusively at the client’s initiative” — they resulted from solicitation, regardless of the formal sign-up steps the client took.

Cannot be created through contractual language. A terms-of-service clause stating “EU clients use this service at their own exclusive initiative” is not a safe harbor. The operational and economic reality — was the firm marketing to, targeting, or facilitating EU client access? — determines whether the exception applies, not the legal framing in the contract.

Does not extend to additional services. If a client genuinely initiated contact without any solicitation, the exception covers the specific service requested. If the CASP then markets additional products — upsells, promotions, loyalty programs, new service features — it has now solicited that client, and future services fall outside the exception.

Cannot be maintained through affiliate structures. Using EU-based affiliates, referral partners, or influencers to generate EU client leads, while asserting that clients “came to us on their own,” is exactly the kind of manufactured reverse solicitation the ESMA guidelines address directly.

The practical consequence is this: genuine reverse solicitation — where an EU resident proactively finds a US firm with no EU marketing presence and opens an account without any prior exposure to the firm’s EU-directed promotion — may legitimately qualify under Article 61. But most US crypto firms with meaningful EU customer bases did not acquire those customers that way. If your EU customer acquisition involved any of the above, your reverse solicitation analysis is almost certainly wrong. National enforcement authorities now have ESMA’s guidelines to support challenging it.

What MiCA Authorization Actually Requires

For US firms evaluating the authorization path, here’s what the process involves:

RequirementDetails
EU legal entitySeparate legal person incorporated in an EU member state — not a branch of the US parent
Effective management in EUBoard and senior leadership must be EU-resident with demonstrated crypto-asset market competency
At least one EU-resident senior managerOperational leadership physically in the EU; US-based remote management does not satisfy this
Application to home NCAFiled with the national competent authority of the chosen home member state
Capital requirements€50,000 (basic services: exchange, transfer) to €150,000 (operating a trading platform)
AML/CFT frameworkFull EU AML framework compliance, including Travel Rule for crypto transfers
IT security and custodyDocumented information security program; client asset segregation; custody procedures
Governance and conflictsWritten policies addressing MiCA’s specific requirements for conflicts of interest and governance

Authorization from one NCA provides the MiCA passport: the firm notifies other member state NCAs and can operate across all 27 EU countries from a single home-state license. This is the structural advantage of MiCA over the fragmented pre-MiCA landscape where each country ran its own registration system.

Ireland, Luxembourg, France, Germany, and Malta have been the most common choices for crypto firms seeking MiCA authorization, driven by established NCA infrastructure and familiarity with complex crypto-asset applications. Processing times have ranged from 6 to 18 months depending on application completeness and NCA capacity.

Stablecoin Issuers Face Additional Requirements

If your firm issues stablecoins — or if your products hold or use stablecoins that function as e-money tokens (EMTs) or asset-referenced tokens (ARTs) — MiCA imposes a separate regulatory layer that predated the CASP provisions.

MiCA’s ART and EMT framework (Titles III and IV) applied from June 30, 2024 — six months before the CASP provisions. Stablecoin issuers who missed that deadline have been operating without authorization for over a year.

Under MiCA, EMTs — stablecoins pegged to a single fiat currency — must be issued by an authorized credit institution or electronic money institution. Circle obtained EMI authorization in France for EURC, allowing it to issue a MiCA-compliant euro-denominated stablecoin. Circle’s USDC, denominated in USD and used by EU market participants, occupies a more complex position regarding EU client exposure.

“Significant” EMTs — those exceeding specific thresholds for transaction volume or user base — trigger additional oversight from the European Banking Authority rather than just the national NCA. ESMA and EBA jointly assess significance, and crossing the threshold imposes heightened supervisory intensity, stricter capital requirements, and EBA directly supervising the issuer.

For crypto firms that use EMTs or ARTs in their products — as payment infrastructure, liquidity instruments, or client-held assets — the question is whether the underlying stablecoin was issued by a MiCA-authorized entity. Using a non-compliant stablecoin in EU-facing products creates a separate regulatory exposure independent of your CASP authorization status.

For firms assessing a stablecoin product launch or embedding stablecoin infrastructure, the New Product Risk Assessment includes a worked example for stablecoin products covering the MiCA authorization questions — from issuer status to reserve transparency requirements — within the risk review framework your compliance team and bank partners will expect.

The Three Options US Crypto Companies Have Right Now

With the transitional period over, US crypto firms with EU exposure face three realistic paths:

Option 1: Obtain MiCA authorization. The full compliance path. Establish an EU legal entity, apply for CASP authorization in a chosen home member state, and operate within the MiCA framework. Realistic timelines are 6 to 18 months, requiring meaningful legal and operational investment. But authorization from one NCA gives passportable access to the entire EU market. Firms that began this process in 2024 are through or close. Firms that delayed are now serving EU clients without authorization while their applications are pending — which itself creates enforcement exposure during the gap.

Option 2: Exit the EU market. Cease providing services to EU clients, block EU IP addresses and payment methods, close EU client accounts through an orderly wind-down process. This eliminates regulatory exposure and removes the compliance complexity of dual-jurisdiction operation. It is also a meaningful business decision — EU market access, once surrendered, is not quickly recaptured if the firm later decides to pursue MiCA authorization. For smaller firms where EU clients represent a small fraction of revenue and the authorization investment is disproportionate, exit may be the correct calculation.

Option 3: Wind down to genuine reverse solicitation only. Stop all EU-facing marketing, affiliate programs, paid search targeting EU users, and any EU-directed acquisition activity. Remove features and content clearly designed to attract EU clients. If genuine, unsolicited EU client contact continues at a residual level — EU residents proactively discovering the firm without any EU-directed promotion — the Article 61 exception may apply to those interactions under the ESMA guidelines framework. This requires a complete marketing audit, credible documentation that EU acquisition has ceased, and an honest assessment of whether the remaining EU activity is genuinely unsolicited. Most firms with significant EU client bases cannot credibly execute this option; for those with truly minimal organic EU activity, it may be defensible.

The option that does not exist: continuing EU operations as before while hoping enforcement doesn’t arrive. MiCA enforcement is conducted by 27 NCAs, each with independent investigation and sanctioning authority. France’s AMF, Germany’s BaFin, and the Netherlands’ AFM have each signaled active attention to post-deadline unlicensed CASP activity. Enforcement actions were expected to materialize in Q3 2026.

So What?

MiCA is not a coming regulatory event — it’s a present compliance requirement that a significant portion of the US crypto industry underestimated or deferred past its deadline.

The regulatory math is clear. Serving EU clients after June 30, 2026 without MiCA authorization is providing unlicensed financial services in the EU. Each member state where affected clients are located has its own enforcement authority. The fines are calibrated to reach large organizations (3% of global turnover hits tens of millions for top-tier exchanges), and NCAs can pile on simultaneously.

The US regulatory framework is still being built out — GENIUS Act implementing regulations are due July 18, as analyzed in the GENIUS Act stablecoin implementing regulations post, and the broader 2026 crypto compliance roadmap for US-licensed firms is covered in the 2026 crypto compliance roadmap. But US regulatory progress does not substitute for MiCA authorization for EU-facing activity. The EU is not waiting for US-EU alignment.

The pattern is consistent: the EU sets a deadline, publishes extensive advance guidance, and then enforces. The EU AI Act is now following the same playbook — Article 50 chatbot disclosure obligations take effect August 2, 2026 with no grace period, as covered in the EU AI Act Article 50 transparency analysis published this morning. MiCA is not a soft guideline. The CASP deadline was real, and enforcement infrastructure is in place.

If your firm hasn’t made the Option 1/2/3 decision, that decision is now overdue. Every additional week of EU client service without MiCA authorization is another week of accumulating enforcement exposure.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is the MiCA transitional period and when did it end?
MiCA (Markets in Crypto-Assets Regulation, Regulation EU 2023/1114) required all crypto-asset service providers to obtain authorization to operate in the EU. Title V of MiCA, governing CASPs, fully applied from December 30, 2024. Article 143(3) allowed member states to grant CASPs already operating under national law a transitional period of up to 18 months to obtain MiCA authorization — ending June 30, 2026. As of July 1, CASPs need a MiCA authorization to provide crypto-asset services to EU clients. Some member states (including the Netherlands, Finland, and Latvia) applied shorter national transitional windows, meaning earlier deadlines in those jurisdictions.
Does MiCA apply to US crypto companies that serve EU customers remotely?
Yes. MiCA applies to any entity providing crypto-asset services to clients located in the EU, regardless of where the provider is established. Unlike some EU financial services regimes, MiCA has no general third-country equivalence or passporting mechanism for CASPs. A US exchange offering crypto trading to EU residents is providing crypto-asset services in the EU under MiCA. Without authorization from an EU member state national competent authority (NCA), that constitutes unlicensed provision of regulated services — subject to enforcement by any of the 27 member state NCAs where affected clients are located.
What is the reverse solicitation exception and does it actually help US firms?
MiCA Article 61(1) allows a CASP established outside the EU to provide crypto-asset services to EU clients without MiCA authorization if the client initiates the service request exclusively on their own initiative — without any marketing, promotion, or solicitation targeting EU residents. ESMA published guidelines in February 2025 making clear this exception is very narrow. It cannot be manufactured: a US firm cannot market to EU residents, target EU IP addresses with ads, use affiliate referrals to generate EU leads, or rely on 'exclusive initiative' disclaimers in terms of service. The exception applies to genuinely unsolicited client approaches — not as an alternative compliance pathway for firms with significant EU customer bases.
What does obtaining MiCA authorization actually require?
MiCA authorization requires establishing a legal entity in an EU member state with effective management and at least one EU-resident senior manager. The entity must apply to the national competent authority in its home member state with documentation covering: organizational structure, governance, AML/CFT procedures, capital requirements (€50,000 to €150,000 depending on service type), IT security controls, client asset custody arrangements, and conflict-of-interest policies. Once authorized by one NCA, the firm can passport across all 27 EU member states. Ireland, Luxembourg, France, Germany, and Malta have been common choices for crypto firms.
What are the penalties for providing crypto-asset services in the EU without MiCA authorization?
Under MiCA Article 148, national competent authorities can impose fines on entities providing crypto-asset services without required authorization. Fines can reach €5,000,000 or 3% of total annual turnover for the preceding financial year, whichever is higher. Enforcement is conducted by the NCA of each member state where clients are located — meaning a US firm with clients across multiple EU countries could face simultaneous enforcement actions in multiple jurisdictions. NCAs also have power to issue public notices, order cessation of services, and disqualify individuals from management roles.
What is ESMA's CASP register and how can I verify whether a firm is MiCA-authorized?
ESMA maintains a public register of all MiCA-authorized CASPs, updated as member state NCAs grant authorizations and submit data to ESMA. The register is searchable by firm name, country, and authorized service type. Following the June 30, 2026 deadline, ESMA updated the register to reflect the post-transitional landscape — adding newly authorized firms and removing entities whose grandfathering protection expired without authorization. Any EU client, NCA, or counterparty can query the register to verify whether a CASP is licensed for a particular service. Operating outside the register for EU-facing services is the core enforcement exposure for US firms.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

New Product Risk Assessment

Structured risk review process for new products, services, and business initiatives.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.