Wiki / Tax & investments / MiCA: EU Single Regime for Crypto-Assets

MiCA: EU Single Regime for Crypto-Assets

Concept

Until 2023, the crypto market in Europe existed in a legal fog. Exchanges obtained local licenses in some places, operated almost without supervision in others, and investors lost all protection when moving across borders—hence the patchwork map of crypto jurisdictions. Regulation (EU) 2023/1114, known as MiCA—Markets in Crypto-Assets—closed this gap: for the first time, crypto-assets and those who service them were described by a single law across all 27 EU countries.

Through the EEA Joint Committee mechanism, the regime has been extended to EEA countries outside the Union: Joint Committee Decision No 41/2025 incorporated MiCA into the EEA Agreement and entered into force on 24 June 2025. Liechtenstein had its national implementing act (EWR-MiCA-DG) ready by 1 February 2025; Norway and Iceland completed their constitutional requirements by June 2025, and the Norwegian regulator has been granting CASP authorisations since 2026.

MiCA covers the issuance of crypto-assets and the provision of services with them—custody, exchange, execution of orders, advice, portfolio management. Excluded from its scope are instruments already regulated as financial (securities under MiFID II), fully decentralized protocols, and NFTs in their pure, unique form.

Key parameters of the regime:

RegulationRegulation (EU) 2023/1114 (MiCA)
Territory27 EU Member States; Iceland, Liechtenstein and Norway under the EEA Agreement since 24 June 2025
Who is coveredCrypto-asset issuers and service providers (CASPs): exchanges, brokers, custodians, platforms
SupervisionESMA and EBA at Union level, national competent authorities locally; significant stablecoins — EBA
CASP capital€50,000 / €125,000 / €150,000 by service class (Annex IV)
Application dates30 June 2024 — ART and EMT; 30 December 2024 — CASP services
Transitional periodExpired 1 July 2026, not extended
Status to date324 authorised CASPs as of 10 August 2026 (public-register estimate)

Three Token Categories

The law divides tokens into three baskets. An asset-referenced token (ART) maintains value through a basket of assets, currencies, or commodities. An e-money token (EMT) is pegged to a single official currency and functions as electronic money—this definition covers most stablecoins pegged to the euro or dollar. Everything else—utility tokens and other crypto-assets—forms the third, general category with lighter requirements.

Issuers must publish a white paper: a standardized document describing the project, risks, and holder rights, with liability for misleading information. For ARTs and for significant tokens that have reached scale, additional requirements apply for capital, reserve composition, and prior regulatory approval.

Significant Tokens and Third-Country-Currency Stablecoins

Within stablecoins, MiCA distinguishes "significant" ARTs and EMTs—those that have grown to systemic scale. A token is considered significant if it meets at least three criteria from the set (Article 43(1)):

  • more than 10 million holders;
  • more than 2.5 million transactions and €500 million of daily turnover simultaneously;
  • an issuance value, market capitalisation or reserve size above €5 billion;
  • close interconnection with the financial system.

Supervision of such issuers is elevated to Union level: significant ARTs come under direct EBA control, significant EMTs under joint EBA and national regulator control.

A separate mechanism targets stablecoins in foreign currencies. If an EMT pegged to a currency that is not an official currency of any EU Member State (primarily the dollar; the Swedish krona, the Polish złoty and the Romanian leu fall outside the mechanism) is used as a means of payment, a ceiling applies: once both 1 million transactions and €200 million per day are exceeded (quarterly averages; Article 23 read with Article 58(3)), the issuer must stop issuing the token and submit a plan to the regulator to bring it back below the threshold.

The logic here is directly political—the ECB sought to prevent dollar stablecoins from displacing the euro in European settlements. For private holders, this means that the depth and availability of certain USD stablecoins in the EU hits a regulatory ceiling.

CASP and Single Passport

Crypto-Asset Service Provider (CASP) is a licensed status for exchanges, brokers, custodians, and platforms. Having obtained authorization from the national regulator of one EU country, a company can operate across the entire single market through the passporting mechanism without a separate license in each jurisdiction—the same logic has long applied to banks and investment firms. Supervision is shared between ESMA and EBA at Union level and national competent authorities (NCAs) locally; EBA handles significant stablecoins directly. Market entry is also possible under another's authorization—through the white-label CASP model, where a licensed partner provides the regulatory wrapper.

Capital by Service Class

A CASP's minimum capital tracks its service set (Annex IV of the Regulation). Class 1—€50,000: reception, transmission and execution of orders, placing, transfer services, advice, and portfolio management. Class 2—€125,000: the same plus custody and the exchange of crypto-assets for funds or other crypto-assets. Class 3—€150,000: all of the above plus operating a trading platform. This is only the floor of the prudential requirements: under Article 67, the safeguard must equal at least the higher of the Annex IV amount or one quarter of the preceding year's fixed overheads, held as own funds or an insurance policy. For clients the figures are modest: real protection rests on asset segregation and provider liability rather than on the platform's capital.

Custodian Liability

Custody is the most sensitive service, and MiCA regulates it more strictly than the rest. A custodian must segregate client crypto-assets from its own holdings—so that its creditors have no recourse to them in insolvency—and may not use them for its own account (Articles 70, 75). For loss of crypto-assets or means of access through an incident attributable to it, the custodian is liable to the client; compensation is capped at the market value of the asset lost at the time the loss occurred (Article 75(8)). Failures inherent in the blockchain itself, beyond the custodian's control, fall outside this liability. Unlike a bank deposit, there is no guarantee fund like the €100,000 deposit scheme—the holder is protected only by segregation and the provider's civil liability.

Stages and Transitional Period

MiCA was introduced in stages. Rules for stablecoins (Titles III and IV, i.e., ART and EMT) came into force on 30 June 2024, rules for services (Title V, CASP) on 30 December 2024. For companies already operating under national regimes, a transitional period (grandfathering) was provided; it expired on 1 July 2026, and a number of countries set an earlier deadline.

The deadline itself is set by national law rather than by the Regulation, and has to be read there: in the Czech Republic a CASP application had to be filed by 31 July 2025, operating on a legacy VASP registration was permitted only until 1 July 2026, and activity without a CASP is prohibited thereafter — Article 26 of the Digital Finance Act 31/2025 Sb. The standing of a Czech entity is verified in the Czech National Bank register.

It was not, however, a single uniform date: Article 143(3) let a Member State disapply the transitional regime or shorten it, and in a number of countries it ended earlier—ESMA maintained a separate list of national periods, and its April statement expressly carves out states where the period had already ended before 1 July 2026.

A provider without authorization had to have an executable wind-down plan already implemented by 1 July 2026: client offboarding, transfer of their assets to an authorized CASP or to a self-hosted wallet; a formal document on paper was not sufficient.

The scale of the transition is visible in the numbers: on industry trackers' counts from public registers, by August 2026 a total of 324 CASPs had been authorised against more than 1,200 previously registered VASPs—slightly over a quarter (count as of 10 August 2026). ESMA publishes no official conversion statistic, so the figure should be read as an estimate.

Reverse Solicitation: A Narrow Exception

The licensing ban has one exception—Article 61: where an EU client approaches a non-EU provider at its own exclusive initiative, no MiCA authorization is required for that service. ESMA's guidelines read the exemption extremely narrowly: any solicitation of clients in the Union—advertising, mailings, sponsorships, a website or app in an EU country's language, promotion through influencers—counts. The client's initiative covers only the requested service and the same type of crypto-asset: offering new types of assets or services after the first contact is prohibited (Article 61(2)), and the exemption attaches to the original transaction, not to the relationship forever. In practice, an EU resident may remain a client of Kraken's or Coinbase's US perimeter only on their own initiative, and the platform may not actively push new products to them.

The Market After 1 July 2026

The outcome of the transition is now visible in one place. ESMA's interim register consists of five CSV files: white papers, ART issuers, EMT issuers, authorised CASPs and the non-compliant list. As of August 2026 there are 324 authorised CASPs—an industry tracker's count from the public registers as of 10 August; ESMA still publishes no official aggregate. The geography of authorisations upended the VASP-era predictions: Germany (69), France (35) and the Netherlands (29) lead, followed by Cyprus and Malta, while Lithuania—champion of the old VASP registrations—did not make the top.

Supervision has moved from reminders to targeted measures. Luxembourg's CSSF warned on 2 July 2026 about abuse of reverse solicitation; France's AMF on 8 July about unlicensed websites, having added 38 names to its blacklist since the start of the year. The non-compliant list grew to 159 entities by mid-July—98% filed by Italy's Consob, with the Dutch AFM adding MEXC, the first top-tier global venue caught providing services without authorisation (Article 59). The route for those building their own authorisation is in the practicum The MiCA CASP Licence: How to Get Authorised.

MiCA does not work alone. From 30 December 2024, the travel rule applies to all CASPs in the EU—the updated Transfer of Funds Regulation (Regulation (EU) 2023/1113): when transferring crypto-assets, platforms must collect and transmit data about the sender and recipient, and for a transfer to or from a self-hosted address above €1,000—take adequate measures to assess whether that address is controlled by their own client (Articles 14(5) and 16(2)). The regulation does not require them to establish the identity of the owner of an arbitrary third-party wallet.

This is the same identification logic as in banking compliance for private clients, transferred to blockchain. Since 17 January 2025 a further layer applies: a CASP sits inside the perimeter of DORA alongside banks and EMIs, owing a register of ICT contracts, incident reporting within hours and demonstrable operational resilience — and the ICT section of a licence file is now assessed as closely as the AML block.

Outside the Perimeter: DeFi, NFTs and MiFID II

The regime also has clear boundaries. Outside its perimeter remain financial instruments under MiFID II, fully decentralized protocols (DeFi) without an identifiable operator, and unique NFTs. These zones still exist outside the unified framework, but the assessment is already under way: the European Commission's MiCA review consultation covers both DeFi and tokenized assets—more in the MiCA 2 section below. MiCA should be read as the first layer, on top of which the rules are being built out.

MiCA 2 and the Centralisation of Supervision

The framework is already being revisited along two tracks. The first is supervision: the European Commission's package of 4 December 2025 (the Market Integration and Supervision Package) moves CASP authorisation and ongoing supervision from national regulators to ESMA; carve-outs are provided for regulated financial groups, but once crypto revenue exceeds half of turnover for two consecutive years, supervision shifts to Union level. Negotiations in the Council and Parliament are expected to run at least until the end of 2026.

The second track is substance: in May 2026 the Commission opened a consultation on the MiCA review—staking and lending, DeFi, stablecoin multi-issuance, access for third-country venues; the response deadline has been extended to 30 September 2026, 23:59 CEST, as stated on the DG FISMA consultation page, while the consultation document itself still carries the original date of 31 August 2026.

The Commission must present its formal report on the application of the Regulation by 30 June 2027 (Article 140), and a "MiCA 2" legislative package is realistic no earlier than 2028. For holders this means staking, lending and DeFi still live outside the single protective framework—and that the supervisory map will change again by 2028.

Platform Status and Tax Transparency

The practical effect of MiCA lies in infrastructure. A platform's licensing status should be checked in advance: an account with an authorized CASP means asset segregation, audited reserves, and clear supervision, whereas access for Europeans to an unlicensed service has been closed since July 2026.

Tax transparency operates in parallel: CARF is implemented in the EU by the DAC8 directive, which applies from 1 January 2026, and the first automatic exchange of data on crypto accounts between tax administrations will cover the 2026 reporting year and must take place within nine months of its end—that is, by 30 September 2027 (Article 8ad(6) DAC). By the end of January 2027 platforms only file their report with their own tax authority. Relying on the anonymity of a European platform has lost its meaning—details in the crypto taxes by country overview.

Checking the ESMA Register

Platforms can be verified at the source: ESMA maintains a public register of authorized CASPs and issuers, as well as registered white papers. If a company is not there, it has had no right to work with European clients since 1 July 2026. For storing large positions, it makes sense to look toward regulated custody—with a licensed provider, assets are segregated and audited.

Q/A

My platform never got a MiCA licence — what happened to my assets?

It may no longer serve EU clients: the transitional period expired on 1 July 2026, and on 17 April 2026 ESMA confirmed there would be no extension. A provider without authorisation had to have executed a wind-down plan by that date — offboarding clients and moving their assets to an authorised CASP or to a self-hosted wallet.

Can I stay with a non-EU exchange under reverse solicitation?

Yes, but only on your own initiative and only for what you asked for. Article 61 disapplies the authorisation requirement where an EU client approaches a third-country provider at its own exclusive initiative, and Article 61(2) bars the provider from marketing new types of asset or service afterwards. On ESMA's guidelines even a website in an EU language counts as solicitation.

Are crypto-assets with a licensed custodian protected the way a bank deposit is?

No: there is no guarantee fund for crypto-assets comparable to the €100,000 deposit scheme. MiCA offers something different — client assets are legally segregated from the provider's estate and beyond the reach of its creditors in insolvency, while liability for a loss attributable to the provider is capped at the asset's market value at the time the loss occurred (Article 75(8)).

Are dollar stablecoins banned in the EU?

There is no ban — there is a ceiling on use as a means of payment. Where an EMT is pegged to a currency that is not the official currency of any EU Member State and its payment traffic exceeds both 1 million transactions and €200 million a day (quarterly averages), the issuer must stop issuing and file a plan with the regulator to bring it back below the threshold (Article 23 read with Article 58(3)).

Will my tax authority see my account on an EU platform?

Yes, from the 2026 reporting year. CARF is implemented in the EU by DAC8, which applies from 1 January 2026: the platform files with its own tax authority by the end of January 2027, and administrations exchange the data by 30 September 2027 (Article 8ad(6) DAC). A MiCA licence adds no confidentiality — see the country-by-country overview.

Download the offer «MiCA CASP license in the EU»

How we approach such matters, the stages, the team and the contacts in one short document.

If you have questions or need a consultation, our experts will be glad to help.

Request a callback

Your contacts are used to answer this request. No mailing lists.