MiCA is a single European Union regulation that creates one authorization and conduct regime for crypto-assets that previously sat outside financial services law, and for the firms that sell, hold, trade, or manage them. Regulation (EU) 2023/1114, the Markets in Crypto-Assets Regulation, entered into force on 29 June 2023 and became fully applicable on 30 December 2024.
This guide covers what MiCA regulates, who holds an authorization under it, and which parts of the crypto market the regulation does not reach. Figures are current as of 7 September 2026 and are sourced at the foot of the page.
What MiCA is
MiCA is a regulation rather than a directive, and that distinction determines how it works. A directive tells member states what result to legislate toward and leaves each one to write its own law. A regulation applies directly in every member state with no national transposition. MiCA therefore replaced twenty-seven separate national crypto regimes instead of sitting on top of them, and an authorization issued in Vilnius carries the same legal content as one issued in Frankfurt.
The regulation arrived in stages. Titles III and IV, which govern the two categories of stablecoin, began to apply on 30 June 2024. Everything else, including the whole service provider regime, applied from 30 December 2024. A transitional regime under Article 143(3) then allowed firms already operating under national law to continue until 1 July 2026 at the latest.
MiCA does four things. The regulation defines categories of crypto-asset; requires a published white paper for public offers and admissions to trading; authorizes and supervises issuers of stablecoins; and authorizes and supervises the intermediaries it calls crypto-asset service providers. Market abuse rules for crypto, covering insider dealing, unlawful disclosure, and manipulation, sit in Title VI and apply to anyone, not only to authorized firms.
Where MiCA applies
MiCA applies across the European Economic Area: the 27 EU member states plus Norway, Iceland, and Liechtenstein. The EEA Joint Committee adopted the decision incorporating MiCA into the EEA Agreement on 20 February 2025, taking effect in each EFTA state once its constitutional requirements were lifted. All three appear in ESMA's list of national transitional periods, and Norway implemented through its kryptoeiendelsloven in July 2025. Switzerland and the United Kingdom sit outside the perimeter and run their own regimes.
For firms based outside the EEA, the practical question is whether they can serve clients inside it at all. MiCA's only opening is the reverse solicitation exemption in Article 61, and ESMA's guidelines of 26 February 2025 read that exemption narrowly. The service must be at the client's own exclusive initiative. Disclaimers do not override conduct. Solicitation includes websites, apps, push notifications, social media, search optimization, sponsorships, press releases, and third parties acting on the firm's behalf, and follow-on marketing of even a similar service falls outside the exemption.
The three token classes
Every crypto-asset in scope falls into one of three classes, and the class determines which rulebook applies.
| Class | Definition | Issuer obligation |
|---|---|---|
| Asset-referenced token | Purports to hold a stable value by referencing another value or right, or a basket of currencies, commodities, or crypto-assets | Authorization plus a segregated reserve (Title III) |
| E-money token | Purports to hold a stable value by referencing a single official currency | Must be issued by an authorized credit institution or e-money institution, at par and redeemable at par (Title IV) |
| Other crypto-assets | Everything else in scope, including bitcoin, ether, and utility tokens | No issuer authorization, but a white paper is required for a public offer or admission to trading (Title II) |
The white paper is not a prospectus and no regulator approves it. A white paper is notified to the competent authority, published, and its accuracy is legally actionable against the issuer. Since 23 December 2025 it must be filed in a machine-readable format, XHTML marked up with Inline XBRL, under an implementing standard adopted in November 2024 with a year of deferred application.
Some offers escape Title II entirely, including crypto-assets offered free of charge and those created automatically as a reward for maintaining a distributed ledger or validating transactions. Others escape only the white paper and marketing requirements: offers to fewer than 150 persons per member state, and offers whose total consideration stays under one million euros over twelve months. Art. 4(2)-(3)
How the stablecoin rules work in practice
The stablecoin titles are the strictest part of MiCA and the part with the most visible effect on the market. E-money tokens are issued at par against funds received and are redeemable at par at any time without a fee, giving the holder a direct claim against the issuer. Asset-referenced tokens are redeemable at the market value of the referenced assets or by delivery of those assets, not at par. Reserve assets are segregated and held with a custodian, and at least 30 percent of the funds backing an e-money token must sit as deposits with credit institutions, rising to 60 percent where the token is designated significant.
No interest on either type
Neither issuers nor crypto-asset service providers may grant interest on asset-referenced tokens or e-money tokens. That prohibition is the provision that most sharply separates a European stablecoin from its offshore equivalents, and it is one of the questions the European Commission reopened in its 2026 review.
Significance and who supervises it
A token becomes significant on meeting at least three of seven criteria, which include more than ten million holders, issuance or reserve value above five billion euros, and average daily transactions above 2.5 million or 500 million euros. Significance raises own funds, tightens reserve and liquidity requirements, and adds an interoperability policy. Significance also moves the supervisor. The European Banking Authority takes over supervision of significant asset-referenced token issuers outright, while for significant e-money token issuers the EBA's remit is narrower and the national authority keeps the rest. Art. 43, 56, 117
The payment caps
MiCA caps the use of a stablecoin as a means of exchange within a single currency area. An issuer must stop issuing once transactions used as a means of exchange exceed one million per day, or 200 million euros in daily value, measured on a quarterly average. The cap applies to asset-referenced tokens under Article 23, and Article 58(3) extends it to e-money tokens denominated in a currency that is not an official currency of a member state. A dollar-denominated e-money token is therefore caught, while one denominated in Swedish krona or Polish zloty is not. The provision is aimed at dollar stablecoins displacing European currencies in payments.
The asset-referenced token figure is the striking one. Two years into the regime, no asset-referenced token has been authorized anywhere in the EEA. The category legislators expected would carry multi-currency and commodity-backed stablecoins has no occupants. The e-money token side filled steadily, from 19 issuers in the first quarter of 2026 to 23 by September, with the euro dominating the tokens issued, dollar-denominated tokens second, and a scattering denominated in koruna, sterling, and Swiss francs. France hosts the largest cluster of issuers.
The most consequential absence is Tether. USDT was not brought into compliance, and European venues progressively removed it from spot trading for EEA users. The largest stablecoin in the world, with roughly 140 billion dollars in circulation, is not available on regulated European exchanges.
What a crypto-asset service provider is
A crypto-asset service provider is any legal person whose occupation or business is providing one or more of ten defined crypto-asset services to third parties on a professional basis. Providing any one of the ten requires authorization.
| Service | Provision | Own-funds class |
|---|---|---|
| Custody and administration on behalf of clients | Art. 3(1)(17) | 2 |
| Operation of a trading platform | Art. 3(1)(18) | 3 |
| Exchange of crypto-assets for funds | Art. 3(1)(19) | 2 |
| Exchange of crypto-assets for other crypto-assets | Art. 3(1)(20) | 2 |
| Execution of orders on behalf of clients | Art. 3(1)(21) | 1 |
| Placing of crypto-assets | Art. 3(1)(22) | 1 |
| Reception and transmission of orders | Art. 3(1)(23) | 1 |
| Advice on crypto-assets | Art. 3(1)(24) | 1 |
| Portfolio management of crypto-assets | Art. 3(1)(25) | 1 |
| Transfer services on behalf of clients | Art. 3(1)(26) | 1 |
Capital
Own funds must be at least the higher of the Annex IV minimum for the class of services provided, or one quarter of the previous year's fixed overheads. Class 1 covers advice, portfolio management, reception and transmission, execution, placing, and transfers, and requires 50,000 euros. Class 2 covers custody and the two exchange services, at 125,000 euros. Class 3 covers operating a trading platform, at 150,000 euros. A new firm uses projected overheads for its first twelve months.
Getting authorized
Applications go to the national competent authority of the member state where the applicant has its registered office, its effective management, and at least one director resident in the European Union. The authority has 25 working days to confirm the file is complete and a further 40 working days to assess it. That nominal 65 working days stretches to many months in practice, because the clock stops each time the regulator raises a question.
The assessment reaches well beyond the application form. Governance and the fitness of management, conflicts of interest, client asset segregation, custody arrangements, ICT resilience under DORA, complaints handling, marketing communications, prudential safeguards, outsourcing, and an orderly wind-down plan are all examined. Firms in scope also carry Transfer of Funds Regulation obligations, which require originator and beneficiary information on transfers under what the industry calls the crypto travel rule.
Credit institutions, central securities depositories, investment firms, e-money institutions, UCITS management companies, and alternative investment fund managers do not need a separate authorization for services their existing license already covers. Those firms give the competent authority 40 working days' notice instead. The route is confined to services equivalent to what the firm is already authorized for, so an e-money institution can take custody of and transfer only the e-money tokens it issues. That provision is why the register contains more than forty banks. Art. 60
How a CASP differs from a VASP
A crypto-asset service provider holds a MiCA authorization, while a virtual asset service provider held an anti-money-laundering registration under the previous regime. The two terms are used interchangeably in the market and come from different legal worlds.
VASP, under the Fifth Anti-Money Laundering Directive
- A term of art from the Financial Action Task Force, Recommendation 15
- Brought into EU law for exchanges and custodian wallet providers
- An anti-money-laundering registration: fitness and probity, AML controls, reporting
- Registered nationally, with no cross-border rights
- No prudential capital, conduct rules, client-asset regime, or market abuse regime
CASP, under MiCA
- An authorization assessed on substance, not a registration
- Own funds, governance, client asset segregation, best execution, and disclosure obligations
- Passportable across the whole EEA on one authorization
- AML obligations continue in parallel, because MiCA sits alongside AML law rather than replacing it
- Supervised by a securities or banking regulator, with ESMA and EBA convergence powers above
The move from one regime to the other is the largest structural change MiCA made, and it explains the licensing numbers below. A register entry was a filing. An authorization is assessed against the substance of the business, and most firms holding the former could not have obtained the latter.
How the passport works
The passport lets one authorization, granted in one member state, give access to all thirty EEA markets without a second license, a second capital requirement, or a second supervisor. The passport is the commercial reason MiCA exists.
The mechanics are light. Under Article 65 a firm notifies its home authority of the member states it intends to serve, the services it will provide cross-border, the intended start date, and any activities it carries on outside MiCA's scope. The home authority passes that to the single points of contact of the host states, to ESMA, and to the EBA within 10 working days, and confirms to the firm that it has done so. The firm may begin on receiving that confirmation, or from the fifteenth calendar day after submitting the notification, whichever comes first.
The host state approves nothing. Prudential and conduct supervision stays with the home authority, which is why the choice of home state became a strategic decision and why supervisory convergence became a live political question. ESMA's peer review of Malta's authorization of one crypto-asset service provider, published on 10 July 2025, found that some material issues were not fully resolved and some risk areas not adequately assessed before the license was granted. The review told every national authority to raise its standards on business growth assumptions, conflicts of interest, governance, intragroup arrangements, ICT, and the promotion of unregulated services alongside regulated ones.
What the transition did
Article 143(3) let each member state decide how long firms already providing crypto services under national law before 30 December 2024 could continue without a MiCA authorization, up to a cap of eighteen months. States chose very differently, which produced eighteen months of regulatory arbitrage inside a single market.
| Window | Ends | Member states |
|---|---|---|
| 6 months | 30 Jun 2025 | Latvia, Hungary, Netherlands, Poland, Slovenia, Finland |
| 9 months | 30 Sep 2025 | Sweden |
| 12 months | 30 Dec 2025 | Germany, Ireland, Lithuania, Austria, Slovakia, Norway |
| 18 months | 30 Jun 2026 | Belgium, Bulgaria, Czechia, Denmark, Estonia, Greece, Spain, France, Croatia, Italy, Cyprus, Luxembourg, Malta, Portugal, Romania, Iceland, Liechtenstein |
From 1 July 2026 no grandfathering remains anywhere in the EEA. An unauthorized firm serving EEA clients is providing regulated services without authorization, and ESMA maintains a public register of non-compliant entities that names them.
What the licensing numbers show
MiCA reduced the number of firms operating in the European crypto market by roughly four fifths. One analysis counting firms actually operating across the EEA before the regime applied identified 1,343. At the close of the transition on 1 July 2026, 281 held an authorization. The register has grown since, reaching 321 active entries at the end of July, 333 by late August, and 338 as of 7 September 2026, spread across 26 of the 30 national regulators.
The raw counts overstate the fall, because the old national registers were much larger than the population of real businesses. Poland's register carried more than 1,800 entries and has produced no MiCA authorizations at all, having entered the post-transition period without a formally designated competent authority. Lithuania's carried more than 400 and produced eight. Italy's OAM register held 138 registered providers in mid-2025, and nine Italian entities appear on the MiCA register. Germany runs in the other direction: 57 firms operated there beforehand under a genuine licensing regime that predated MiCA, and 55 are authorized.
Authorized crypto-asset service providers by member state, 7 September 2026
Enforcement is similarly concentrated. Of 167 entries on ESMA's register of non-compliant entities, 165 were submitted by Italy, which says more about national reporting practice than about where unauthorized activity is occurring.
Composition matters as much as the count. On an August 2026 snapshot of the register, around 63 percent of authorized firms were crypto-native and 37 percent came from traditional finance, including 41 banks and credit institutions and 43 investment firms and asset managers. MiCA has functioned in part as an on-ramp for incumbents.
The absences at the top of the market
Binance, Bitfinex, Bitget, MEXC, HTX, and Upbit are all absent from the register. Binance is the case worth understanding in detail, because the sequence was not one of indifference. Binance filed a MiCA application in Greece with the Hellenic Capital Market Commission. Its Europe head, Gillian Lynch, has said the company was told in April 2026 that the file was complete, that "nothing was missing, nothing material was outstanding," and that it expected authorization in early June. Board meetings with the Greek regulator were repeatedly postponed, no decision came, and days before the deadline Binance withdrew the application, saying it had made the decision "after careful consideration of the current status and timeline of the Greek process, with our users' interests at the center." The Hellenic Capital Market Commission declined to comment.
From 1 July 2026 the largest exchange in the world stopped providing crypto-asset services to clients in EU markets, telling users their assets remained accessible. Lynch's framing was that the company is "not leaving Europe. This is an obstacle in our way at the moment." Binance has since argued publicly that MiCA should be judged by who it authorizes rather than by who it excludes.
Whichever reading is correct, the structural point holds. A regime that grants a single passport also creates a single point of failure, and one national authority's inaction removed the largest venue in the market from thirty countries at once.
Who sits outside MiCA
A substantial share of crypto activity is untouched by MiCA. Some of it is excluded because another regime already covers it, and some because the legislator chose not to reach it.
Excluded, already regulated elsewhere
- Crypto-assets qualifying as financial instruments under MiFID II, including tokenized shares, bonds, fund units, and most derivatives
- Deposits, including structured deposits
- Funds, except where they qualify as e-money tokens
- Securitization positions
- Insurance and reinsurance products, and pension products and schemes
- Central bank money, and the ECB or national central banks acting as monetary authorities
Excluded, outside the perimeter entirely
- Crypto-assets that are unique and not fungible with other crypto-assets
- Services provided in a fully decentralized manner without any intermediary
- Persons providing services exclusively to their parent, subsidiaries, or other group companies
- Insolvency practitioners and liquidators acting in that capacity
- Free distributions, mining and validation rewards, offers to fewer than 150 persons per member state, and offers below one million euros over twelve months
The NFT carve-out is narrower than it reads
Article 2(3) excludes crypto-assets that are unique and not fungible. Both limbs must hold, and the assessment looks at substance rather than labels. A large series issued as a collection, whose members are effectively interchangeable, is not saved by minting each item to a distinct token ID. Fractionalized non-fungible tokens are assessed case by case and generally fall in scope. Regulators have been explicit that calling an asset an NFT does not make it one for MiCA purposes.
Full decentralization is a demanding test
Recital 22 states that where crypto-asset services are provided in a fully decentralized manner without any intermediary, they should not fall within the scope of the regulation. A recital guides interpretation without creating an exemption a firm can rely on, and ESMA has said the exact scope remains uncertain and must be assessed case by case, treating decentralization as a spectrum rather than a switch. Administrator keys, upgradeable contracts, a concentrated governance token, a front end operated by an identifiable company, a treasury, and active marketing by a named team each tend to reintroduce an intermediary, and with it the authorization requirement.
Where the gaps are
MiCA regulates issuance, intermediation, and trading, and does not regulate most of what holders do with crypto-assets once they own them. The ten services in Article 3(1)(16) are a MiFID list translated into crypto, and what the list omits is almost everything that generates a return: lending, borrowing, staking, liquidity provision, and the on-chain structures built on top of them. A firm can hold a full authorization and run a lending book beside it that MiCA has nothing to say about, which is why ESMA has told national authorities to examine how authorized firms promote unregulated products alongside regulated ones.
| Activity | Status under MiCA | Consequence |
|---|---|---|
| Lending and borrowing | Not a crypto-asset service | Covered by no EU regime unless the arrangement constitutes a deposit or a financial instrument |
| Staking | Treated as incidental to custody | Lock-ups, slashing risk, validator concentration, and liquid staking tokens attract no tailored requirements |
| Vaults and curation | No defined category | Caught only where the activity amounts to discretionary portfolio management under Art. 3(1)(25) |
| Perpetual futures | Unsettled between MiCA and MiFID II | Venues have been able to choose their own characterization |
| Prediction markets | Outside both regimes | No settled European home |
The vault question is the live one
On-chain vaults now hold billions in deposits and are managed by curators who choose which protocols and strategies the capital flows into. Whether that activity is asset management, and whether the curator is therefore a manager, is unresolved in the United States. In Europe the position is more settled than market behavior suggests, because MiCA does not need a vault rule to reach a vault.
Article 3(1)(25) makes portfolio management of crypto-assets a licensable service, and the authorization attaches to discretion over someone else's assets however that discretion is expressed. A curator holding permissions to allocate depositors' capital is exercising discretion. That the discretion is executed by a contract rather than a dealing desk changes the mechanism, not the activity. James Harris, chief executive of the Helsinki-based digital asset manager Tesseract, made the same argument publicly in July 2026.
Since the beginning of the year we have been clear about vaults: this is asset management, it is a regulated activity, and you cannot get away from that.
The gap is therefore less a hole in the text than a distance between the text and the market's behavior. Two structures offering the same economics to the same depositor can sit on opposite sides of the perimeter depending on whether an identifiable person exercises discretion, and on whether a national authority has examined the question. That is the space the European Commission is now looking at.
Twenty-six front doors
One passport is granted by twenty-six authorizing authorities with different resources, appetites, and speeds, and the supervisory gap between them is itself a gap in the regime. ESMA's own peer review found material issues unresolved at the point an authorization was granted. Uneven authorization standards travel with the passport into every other member state, which is the mechanism behind the proposal to move supervision of the largest firms to ESMA.
What comes next
The European Commission opened a targeted consultation on MiCA's functioning on 20 May 2026, aimed at financial institutions, service providers, national authorities, central banks, and finance ministries. The consultation is exploratory. No amending regulation has been proposed, and any amendment would need the full legislative process. The questions map closely onto the gaps above.
- 10 July 2025ESMA peer review on CASP authorizationFinds material issues unresolved at the point of licensing and instructs all national authorities to tighten their assessments.
- April 2026ECB opinion on supervisionThe European Central Bank backs centralizing supervision of significant crypto firms under ESMA rather than leaving it with national authorities.
- 20 May 2026Commission consultation opensAsks whether lending and borrowing should become a regulated activity, whether staking needs stand-alone rules, whether firms giving clients access to DeFi should owe due diligence over the protocols they connect them to, how full decentralization should be tested, where perpetual futures belong, and whether the prohibition on paying interest on stablecoins should be relaxed.
For firms, the practical position as of September 2026 is that the authorization perimeter is settled and the activity perimeter is not. A firm that intermediates knows which authorization it needs. A firm that lends, stakes, or curates does not yet know whether the activity will be brought inside the regime, and the consultation is the first formal signal of where the boundary may move.
