MiCA After the Deadline: Where CASP Licences Are Actually Being Granted

The MiCA transition ended on 1 July 2026. What the register shows now, why the passport is not holding, and how CASP timelines differ across the 27 states.
"My beef with MiCA is that, instead of making the system more secure, it actually creates significant systemic risk."
Paolo Ardoino, CEO of Tether, in an interview with Cointelegraph, 2024
On 1 July 2026 Europe's crypto market went through the harshest thinning-out in its history, carried out under the banner of consumer protection. Ten weeks have passed. The regulation sold for three years as harmonisation and a single passport has had time to show what it actually produced: 27 regulators of differing strictness, a passport that has become a prize in a race to the bottom, and consumer protection that began by cutting consumers off from their own platform.
The forecasts written in June are now checkable against the register. Some of them held. One of the loudest did not. Let us take it in order, because the devil here lives in the article numbers.
What actually happened on 1 July
Article 143(3) of MiCA, Regulation (EU) 2023/1114, gave companies legally operating under national law before 30 December 2024 the right to keep going, but only until 1 July 2026, or until authorisation under Article 63 was granted or refused, whichever came first. It was never a soft deadline. In its statement of 17 April 2026 (ESMA75-113276571-1679) ESMA spelled it out: a single EU-wide wall, no extensions, regardless of whether a member state had transposed MiCA into national law. After that date, providing regulated services without authorisation is a breach of Union law.
That much went exactly as written. What did not go as written was the arithmetic.
The number everyone got wrong
In May 2026, Hogan Lovells counted 194 licensed crypto firms across the EU, banks included, against more than 3,000 registered companies in 2024. From that gap came the headline forecast of the spring: roughly three-quarters of the old market would lose the right to operate, a controlled demolition on a calendar.
The register tells a more complicated story. As of 8 September 2026 the ESMA interim MiCA register holds 341 authorisation records covering 335 unique active firms, spread across 26 countries. In other words, the licensed population did not collapse over the summer. It nearly doubled, because a queue that had been sitting in NCA inboxes for a year finally cleared.
The demolition thesis was half right, and the half it got wrong matters. Yes, thousands of national registrations went dark. But those registrations were never comparable to authorisations. A Polish or Estonian VASP entry was a notification regime; a CASP authorisation is a licence with capital, governance and custody conditions attached. Counting one against the other overstates the cull and understates something more interesting: the survivors are not spread evenly.
Myth one: the single market
MiCA was sold as one passport for 27 countries. Get authorised by a national competent authority and operate across the whole Union. In practice, licences are issued by 27 separate regulators working at different speeds and to different standards, and the transition alone proved it.
Germany closed its grandfathering window on 31 December 2025. The Netherlands closed it on 1 July 2025. Sweden closed in September 2025, and Finansinspektionen went further by publishing two public lists, one of firms that had notified under 143(3) and a separate one of firms that had actually filed an application. Not appearing on the second list put you in plain sight. France, by contrast, ran the full eighteen months to 1 July. A single deadline landed in different countries up to a year apart.
There is a related point that even seasoned practitioners kept getting wrong, and it produced real exposure. Relying on the transitional period never granted a European passport. ESMA said so directly in QA_2086: while you operate under grandfathering, you operate only where you are registered. Firms that spent the year onboarding clients across the EU on the assumption that 143(3) covered them pan-European were in breach in each jurisdiction separately, and some of those breaches are now being looked at retrospectively.
Grandfathering was never equivalence either. National regimes before MiCA differed sharply from what Articles 70 on custody, 73 on conflicts of interest and 76 on segregation of client assets require. An old registration did not carry compliance forward. It postponed the conversation, and the bill for that postponement came due in the spring.
Myth two: mutual recognition
The passport rests on one assumption, that a licence issued in country A is worth something in country B. The continent's largest regulator publicly withdrew that assumption before the deadline, and nothing since has restored it.
On 28 May 2026, at a briefing in Paris, the head of France's AMF warned unlicensed firms in plain terms.
"It's becoming very, very urgent to finalize the license applications."
Marie-Anne Barbat-Layani, President of the AMF, Paris, 28 May 2026
She then said something that, from a national regulator, sounds close to heresy: France is prepared to block the passporting of licences issued elsewhere if it disagrees with the decision behind them. She called such an outcome undesirable and described it in one phrase.
"A serious collective failure." Marie-Anne Barbat-Layani, on refusing to recognise other countries' national licences
Translated out of regulator-speak, one NCA said aloud that it does not consider itself obliged to recognise another NCA's passport. That was not paranoia from nowhere. After a Reuters investigation into how one of the EU's smallest regulators manages to issue licences faster than far better-staffed peers, ESMA published a review of Malta's MFSA in July 2025 and concluded that the regulator "should have been more thorough," with problems in the timing of the authorisation process itself. Malta pushed back publicly, and by October 2025 the MFSA was calling the suggestion that it grants licences at the expense of scrutiny a myth: "Under no circumstances did we compromise on rigour, oversight, or regulatory integrity." Luxembourg's CSSF drew similar questions.
Who is right there is an open question. That a national regulator had to publicly prove it is not rubber-stamping says more about trust inside the single market than any peer review does. What has been called into doubt is not fringe operators, but specific national regulators inside the system that is supposed to recognise their decisions.
The consequences are no longer theoretical. Gate Group secured a full CASP licence through Malta's MFSA on 1 October 2025. Binance, the world's largest exchange, filed in Greece with the HCMC, and in July, after Reuters reported the application was heading for rejection, withdrew it, leaving its EU users without a clear home venue. One regulator uses the same system as a filter, another as a conveyor belt, a third threatens not to recognise the second's output, and the largest player in the market walked away rather than take the decision. That is the single market as it actually functions.
Two poles of one regulation: Estonia and Poland
The full scale of the divergence shows up in two countries running the same regulation to the same deadline in opposite directions.
Estonia effectively wrote MiCA's draft. Its VASP regime was one of the reference models and its national law took effect on 1 July 2024. The model student. The result, by the autumn of 2026: few CASP licences granted, new applicants told to budget nine to fifteen months, and old VASP licences dark since 1 July with no automatic conversion. The country that issued the region's first crypto licence in 2017 has methodically shrunk its market to a handful. At its peak it held more than 1,300 licensed VASPs, half of all of them worldwide; after the 2022 cleanup around a hundred were left. That is minus ninety percent before MiCA had even started. From 2026 the Estonian tax authority allows trading losses to be written off only where the exchange holds a MiCA licence. Trade on an unlicensed venue and as far as the state is concerned your loss does not exist. Consumer protection sewn into the tax return.
Poland is the opposite pole, and the only EU country that still has no law implementing MiCA. President Nawrocki vetoed it three times, the Sejm failed to override, and he has since been re-elected, which removes the obvious route out of the deadlock. No competent authority has been designated, so there is physically nowhere to file a CASP application. The KNF was already the Union's slowest regulator by reputation, with two brokerage licences in a decade against well over a hundred in neighbouring Lithuania. The market voted with its feet: by the Polish Chamber of Commerce for Blockchain's estimate, 70 to 80 percent of companies had already moved to Latvia and the Czech Republic before the deadline, and the country that once held more than 1,400 registrations now contributes almost nothing to the register.
Between those poles sits the rest of Europe on a stopwatch. Lithuania around six months. Germany's BaFin twelve to twenty-four months, with advisory costs reported in the range of €80,000 to €200,000. Estonia nine to fifteen months. Poland, for now, never. All of it is still called one licence in a single market.
Myth three: protection, or consolidation
MiCA compliance is expensive. Capital requirements, fit-and-proper management, conflicts policies, custodial segregation, incident reporting and the Travel Rule are all paid for in lawyers, capital and a compliance team. Banks, large exchanges and well-funded platforms carry it. Most others cannot.
The stablecoin market gave the preview. USDT, the world's largest stablecoin, never brought itself into compliance and was pulled from European shelves at Coinbase, Kraken, Crypto.com and Binance, while Circle's USDC and its euro version EURC kept their place. The safest did not win. The most compliant did. Those are different things, and it is worth being precise about which one the regulation optimises for.
The register bears the pattern out. A licensed population concentrated in a handful of well-resourced jurisdictions, dominated by incumbents with prior supervisory relationships, is what a consolidation looks like. Whether it is also what safety looks like is a question the enforcement record will answer over the next two years, and the tell will be simple: whether actions are brought over actual consumer harm, or mostly over operating unlicensed.
What it meant for users
A regulation written to protect consumers did one thing for them first: it showed that their platform might no longer have the right to serve them.
Unlicensed platforms blocked new deposits and pushed users to withdraw. Clients moved to a licensed sister entity received emails asking them to verify their identity again, because ESMA had made the point plainly. Migration is not grandfathering. The receiving licensed CASP has to run a full, fresh AML and CFT check on every transferring client rather than inherit the old one, which is exactly where KYB onboarding and sanctions screening processes built for a lighter national regime started failing in volume.
For firms, the exposure is not only administrative. In France, operating without a licence after 1 July is a criminal offence, carrying up to two years' imprisonment and a €30,000 fine, alongside a public blacklist and court-ordered website blocking.
Protection that arrives as a shutdown is politically expensive protection, and that is where most of the tension around MiCA over the past year came from.
The last-minute trap
The final illusion to go was "we will file in time and they will leave us alone."
In its statements of 17 April 2026 (ESMA75-113276571-1679) and 4 December 2025 (ESMA75-113276571-1631), ESMA required unauthorised CASPs to have orderly wind-down plans ready and immediately executable by 1 July, and told NCAs to examine last-minute applications with particular care, to the same standard as any other, even where that means the applicant winds down while its application is still under review. Filing in May bought nobody the right to operate. It bought the right to wind down by the rules. Regulatory pressure did not end on 1 July either: a disorderly exit still draws consequences afterwards, with cross-border cooperation between regulators, and several of those files are open now.
So was it all bad?
"MiCA is the global gold standard of crypto regulation; Europe's pioneering regulation should be celebrated, but the bloc cannot afford to watch others race ahead." EU Commissioner for Financial Services, December 2025
What the tuning will not fix is not the banks or the big exchanges, because those survive anything. It is the young projects, the ones that brought speed and experiment and new models, and for whom the wall of compliance turned out to be higher than the wall of technology. Many were squeezed out before they got to prove anything at all. That part is not a temporary glitch in the calibration. A regime built around lawyers and capital leaves less room, by construction, for those who were only just starting.
But "less room" and "no room" are not the same finding, and ten weeks of live data separate them. The register now holds a few hundred authorised firms rather than the handful the pessimists sketched in June, and the distribution is the real story: one country carries roughly a quarter of all licences, a dozen carry a scattering, and one still has no competent authority to file with at all. The door did not close. It moved, and it now opens at very different speeds depending on which side of the map you knock on.
Which turns the question from a political one into an operational one. Not "did MiCA kill the small player" but "which jurisdiction, which structure and which timeline still work for a company of this size." Those have concrete answers today, and they are unrecognisable from the answers that applied eighteen months ago. Some regulators reward applicants with prior national supervision and treat a fresh file as a two-year project. Others process lean operations faster than their headcount suggests. Some paths do not require a licence of your own at all, only supervised access to somebody else's, which is a different balance of cost, control and counterparty risk, and one that deserves a clear-eyed comparison rather than a slogan.
None of that is visible from the outside, and that is the honest cost of the reform. The regulation was written to make the market legible to consumers, and its first effect was to make it illegible to the founders inside it: 27 supervisory cultures, no reliable published benchmarks, and advice that goes stale every quarter. The firms that got through were rarely the ones with the best technology. They were the ones who read the map before they started walking.
So the right question, now that the black box is open, is not whether MiCA failed. It is what kind of market is left, and whether there is still room in it for ambition. On the evidence so far there is, but the room is unevenly distributed and it is not found by accident. If you are deciding where to file, whether to file at all, or how to unwind cleanly from a national regime that no longer exists, that decision is worth an hour with someone who has watched all 27 of these processes run.
FAQ
Did the MiCA transitional period really end on 1 July 2026?
Yes. Article 143(3) allowed firms operating legally under national law before 30 December 2024 to continue until 1 July 2026 at the latest. ESMA confirmed there would be no extension and no exception for member states that had not transposed MiCA.
Can a firm still operate under an old national registration?
No. Providing regulated crypto-asset services in the EU without a CASP authorisation is now a breach of Union law, and in some states, France among them, a criminal offence.
How many CASP licences have been granted?
The ESMA interim register showed 341 authorisation records covering 335 active firms across 26 countries as of 8 September 2026, up from roughly 194 in May. Germany holds close to a quarter of them.
Did the transitional period give a European passport?
No. ESMA addressed this in QA_2086: during grandfathering a firm could operate only in the state where it was registered. Cross-border onboarding on the assumption of a pan-EU passport created exposure in each jurisdiction separately.
How long does a CASP authorisation take?
It depends heavily on the regulator. Lithuania is around six months, Estonia nine to fifteen, and Germany's BaFin twelve to twenty-four with substantial advisory costs. Poland has no competent authority designated and no route to file.
Is a licence from one member state recognised everywhere?
In law, yes. In practice, France's AMF has publicly said it is prepared to block passporting of licences it disagrees with, and ESMA's 2025 review of Malta's MFSA raised questions about authorisation practice. Passporting is not a formality to be assumed.
What happens to clients when a platform loses the right to operate?
Deposits are blocked and withdrawals pushed. Clients moved to a licensed entity have to be onboarded afresh, because migration does not inherit the previous AML and CFT checks.
What is a wind-down plan and who needs one?
An orderly exit plan that unauthorised CASPs were required to have executable by 1 July. Filing an application late did not remove the requirement, and a disorderly exit still attracts regulatory consequences after the fact.
Which jurisdiction should a new project apply in?
There is no universal answer. It turns on the services in scope, existing supervisory history, capital, where clients actually sit, and how much time the business can survive without authorisation. The gap between the fastest and slowest regulator is measured in years, not weeks.
