MiCA Grandfathering Is Over: Can You Still Legally Serve EU Crypto Clients?

On 1 July 2026, the European Union’s crypto grace period did not fade out. It closed. If your firm is still serving EU clients on an old national registration, it may be operating unlawfully today without having changed a single thing about what it does.

The Markets in Crypto-Assets Regulation, formally Regulation (EU) 2023/1114 and universally known as MiCA, is the EU’s harmonised rulebook for crypto-assets that fall outside existing financial services legislation. It creates a single authorisation regime for crypto-asset service providers, or CASPs, replacing the patchwork of national virtual asset registrations most firms relied on until then. Its rules for service providers became applicable on 30 December 2024.

Firms already operating lawfully under national law before that date received a runway. Article 143(3) of MiCA allowed them to keep serving clients until 1 July 2026, or until their MiCA authorisation was granted or refused, whichever came first. That runway has now ended, and the Regulation contains no extension mechanism.

This article explains what closed and when, why a pending application is not a licence, which businesses are actually caught, how the reverse solicitation exception really works, and what the three lawful routes forward look like.

Here is the detail that caught out a great many founders. Article 143(3) permitted Member States to shorten the transitional period, or not to apply it at all, where they considered their existing national framework less strict than MiCA. States taking that option had to notify the European Commission and ESMA.

Many did. Germany, Ireland, Austria, Lithuania and Slovakia ran twelve-month windows that closed at the end of December 2025. Slovenia, together with the Netherlands, Latvia, Hungary and Finland, granted only six months, meaning the Slovenian window closed on 30 June 2025, a full year before the EU backstop. Sweden allowed nine months. A larger group, including France, Italy, Malta, Luxembourg and Spain, ran the full period to 1 July 2026, several with earlier cut-off dates for filing an application in order to qualify at all.

If your firm operated in more than one Member State, your real deadline was always the earliest applicable one, not the most generous. A transitional period in Paris did nothing for the same firm’s Ljubljana or Amsterdam clients.

The market effect has been substantial. ESMA’s interim MiCA register, published under Article 109, listed fewer than three hundred authorised providers when the transitional period closed, measured against a pre-MiCA population of national registrations widely estimated at well over a thousand entities. The runway ended. A large part of the legacy market never took off.

This is the misconception most likely to cause real damage, so it is worth stating plainly.

Article 59(1) of MiCA provides that a person shall not provide crypto-asset services within the Union unless that person is authorised as a CASP under Article 63, or is one of the already-regulated financial entities permitted to provide such services under Article 60. The transitional period did not suspend that rule. It deferred it. The rule now applies in full.

A pending application is not authorisation. ESMA confirmed on 17 April 2026 that there would be no extension, and in a public statement of 23 June 2026 it set out precisely what it expects unauthorised providers to do. They must immediately stop onboarding new EU clients, refrain from opening new accounts, and cease marketing and solicitation. They must limit services to what is necessary for clients to sell, transfer, reallocate or close positions, with custody continuing only for the period strictly necessary to complete an orderly exit. They must communicate clearly, promptly and repeatedly with clients about the wind-down, including the deadline by which residual positions will be closed automatically.

ESMA also made clear that this applies irrespective of whether a Member State has adjusted its national law to MiCA. Continuing to serve EU clients without authorisation is not a grey area. It is the unlicensed provision of regulated services.

Article 3(1)(16) of MiCA defines ten crypto-asset services: custody and administration of crypto-assets for clients, operating a trading platform, exchanging crypto-assets for funds, exchanging crypto-assets for other crypto-assets, executing orders for clients, placing crypto-assets, receiving and transmitting orders for clients, providing advice on crypto-assets, providing portfolio management, and providing transfer services for clients. Provide any of these to clients in the Union on a professional basis and you sit inside Title V of MiCA.

Three carve-outs are worth understanding, and two are narrower than commonly assumed.

First, issuing a token without providing any service falls into a different part of MiCA, the offering and white paper regime under Titles II to IV, rather than the CASP authorisation regime.

Second, certain already-authorised firms can use a notification route under Article 60 instead of applying for a fresh licence. Credit institutions, investment firms, market operators, central securities depositories, electronic money institutions, UCITS management companies and alternative investment fund managers may provide crypto-asset services equivalent to those they are already authorised to provide, after notifying their competent authority in advance. The equivalence limitation matters. An electronic money institution, for instance, may provide custody and transfer services only in relation to the e-money tokens it issues.

Third, the decentralised finance carve-out is real but considerably thinner than the industry assumes. It appears in Recital 22, which states that where crypto-asset services are provided in a fully decentralised manner without any intermediary, they should not fall within scope. A recital is an interpretive aid rather than a binding operative provision, the term “fully decentralised” is nowhere defined in the Regulation, and ESMA has itself acknowledged that the exact scope of the exemption remains uncertain. The same recital expressly brings services within scope where only part of the activity is decentralised. If there is an identifiable company, foundation or team controlling upgrades, parameters or the front end, expect a regulator to treat that person as providing the service.

A familiar piece of wishful thinking runs like this: we are established outside the EU, our EU clients found us, so MiCA does not apply. Careful.

MiCA follows the client. The authorisation requirement bites on the provision of services to clients established or situated in the Union, irrespective of where the provider is incorporated. Serving EU users from Dubai or Delaware changes nothing, and ESMA has confirmed that the prohibition applies in a business-to-business context too.

There is a genuine exception. Article 61(1) provides that where an EU client initiates a service at its own exclusive initiative, the Article 59 authorisation requirement does not apply to that service for that client. It is drafted narrowly and read narrowly.

The same provision states that where a third-country firm solicits clients or prospective clients in the Union, including through anyone acting on its behalf or having close links with it, and regardless of the means of communication used, the service is not deemed to be provided on the client’s own exclusive initiative. That applies notwithstanding any contractual clause or disclaimer purporting to state otherwise. ESMA’s Guidelines on reverse solicitation, issued under Article 61(3), read solicitation broadly and in a technology-neutral way, covering online advertising, social media and promotion by influencers whether or not there is a formal agreement or payment.

Finally, Article 61(2) provides that a client’s own exclusive initiative does not entitle the firm to market new types of crypto-assets or crypto-asset services to that client. Reverse solicitation is a narrow exception for the client’s benefit. It is not a growth strategy for yours.

Path one, authorisation. A full application to a national competent authority. Expect scrutiny of governance, prudential safeguards, custody arrangements, ICT resilience and AML controls, plus minimum capital under Article 67 and Annex IV of between 50,000 and 150,000 euros depending on the service class. The reward is real: one authorisation, passported across the Union under Article 65.

Path two, a licensed group entity. Services can flow through an authorised affiliate, but the structure needs genuine substance. Article 59(2) requires an authorised CASP to have its registered office in a Member State where it carries out at least part of its services, its place of effective management in the Union, and at least one director resident in the Union. ESMA has separately reminded the market that MiCA prohibits CASPs from outsourcing or delegating certain services, notably custody, to entities that are not authorised as CASPs, and that supervisors will scrutinise client migrations so that groups cannot keep trading through an unauthorised affiliate. A shared brand is not a compliance structure.

Path three, an orderly wind-down. If the EU market does not justify the licence, stop onboarding, return or transfer client assets, and close out in the manner ESMA has described. Pausing EU services while building a proper application is entirely legitimate. Orderly is lawful. Messy is not.

The cost of getting this wrong is not theoretical. Under Article 111, Member States must provide for maximum administrative fines for CASP infringements, which include breaches of Article 59, of at least 5 million euros or 5 percent of total annual turnover for legal persons, whichever is higher, and at least 700,000 euros for natural persons. Authorities may also impose fines of at least twice the benefit derived from the infringement where that benefit can be determined. Beyond money, competent authorities can order the conduct to cease, withdraw or suspend authorisations, ban individuals from management functions, and publish their decisions. Several Member States additionally treat the unlicensed provision of regulated financial services as a criminal offence.

The transitional regime was never a permission. It was a runway, and it has run out. The position from 1 July 2026 is simple. Authorised firms may serve EU clients. Everyone else must become authorised, route services through a genuinely authorised entity, or leave the market cleanly.

Three practical steps follow. Map each service you provide against the ten definitions in Article 3(1)(16), because scope is where most firms get their analysis wrong. Verify your own status, and that of every counterparty in your transaction flow, against the ESMA register. And if you are winding down, do it to ESMA’s stated expectations rather than improvising, because how you exit is now itself a supervised matter.

Have specific questions?

Not ready for a call

No worries! In the meantime, subscribe to our Knowledge center to stay updated on the latest legal developments.

And don't worry, it's free!

Share the Post:

Related Posts

Related Posts
Loading related posts…
Scroll to Top