QuiverCrypto QUIVERCRYPTO SUBSCRIBE
QuiverCrypto
← Guides Crypto

MiCA Deadline: What Crypto Firms Must Do | QuiverCrypto

MiCA's CASP transitional period ends July 1, 2026. Learn country-specific deadlines, grandfathering rules and what EU crypto firms must do to comply.

27 June 2026 · 9 min read

The Markets in Crypto-Assets Regulation (MiCA) is the most consequential piece of crypto legislation the European Union has ever enacted. For crypto-asset service providers (CASPs) operating across EU member states, the clock has been ticking since MiCA’s CASP provisions became applicable on 30 December 2024. An absolute ceiling of 1 July 2026 marks the end of any grandfathering protection — after which no unauthorised CASP may legally serve EU customers, regardless of which member state they are based in.

This guide explains how the transitional provisions work, why deadlines vary by country, and what your firm must do right now to remain on the right side of European regulators.


What Is the MiCA Transitional Period?

MiCA establishes a unified licensing framework for crypto-asset service providers across all 27 EU member states. Rather than forcing every existing firm to comply overnight, the regulation includes a transitional (grandfathering) mechanism set out in Article 143(3). Firms that were already providing crypto-asset services under applicable national law before 30 December 2024 were permitted to continue operating temporarily — either until they received a MiCA authorisation, were refused one, or until the transitional period in their member state expired.

The key word is temporarily. Grandfathering is not a permanent exemption; it is a runway, and that runway has a hard end date.

For a broader grounding in the regulation, see our MiCA Explained: The Complete Guide to EU Crypto Regulation.


Why Deadlines Differ Across EU Member States

This is where many compliance teams get caught off guard. MiCA allowed each member state to choose its own transitional period length, subject to a maximum of 18 months from the 30 December 2024 application date. That ceiling lands on 1 July 2026.

Member states that chose shorter windows have already closed theirs. Based on ESMA’s official published list of grandfathering periods under Article 143(3), the breakdown is broadly as follows:

  • 6-month period (expired 30 June 2025): Latvia, Hungary, the Netherlands, and Slovenia
  • 12-month period (expired 30 December 2025): Austria, Germany, Greece, Ireland, Lithuania, and Slovakia
  • 18-month period (expires 1 July 2026): Belgium, Bulgaria, Cyprus, Luxembourg, Malta, and a number of other member states

Some member states modified their initially communicated period over the course of 2025 — Spain, for example, extended from 12 months to 18 months. Because individual country positions can change, CASPs should verify their applicable deadline directly against ESMA’s current official list rather than relying on any third-party summary, including this one.

The practical implication: A CASP that serves customers across multiple EU member states is not bound by a single deadline — it is bound by the earliest applicable deadline among all the countries where it actively operates. A firm with customers in the Netherlands and Belgium faced a Dutch deadline of June 2025, even if its Belgian operations were covered until July 2026.


What “Grandfathering” Actually Means — And What It Does Not

Grandfathering under MiCA is frequently misunderstood. It does not mean a firm can operate as it always has and ignore MiCA until the last day. The European Securities and Markets Authority (ESMA) has stated in its supervisory communications on MiCA transitional measures that national competent authorities (NCAs) are expected to monitor grandfathered CASPs throughout the transitional period and verify that firms are actively working toward full MiCA compliance.

ESMA has also reinforced that NCAs should apply rigorous and consistent scrutiny to all authorisation applications, meaning that submitting an application close to a deadline does not guarantee a smooth or expedited outcome.

What the transitional period does provide:

  • Legal continuity to serve existing customers without an immediate shutdown
  • Time to prepare the documentation, systems, governance structures, and capital reserves required under MiCA
  • Protection from enforcement for services lawfully offered under prior national rules — provided the firm demonstrates genuine progress toward authorisation

The Authorisation Process: What CASPs Must Apply For

MiCA authorisation is not a simple registration. Under Article 62, firms must submit a comprehensive application to their home member state’s NCA. The application must cover, among other things:

Organisational and Governance Requirements

  • A clear description of the legal entity, its ownership structure, and any qualifying holdings
  • Fit-and-proper assessments for management body members
  • Internal governance arrangements and risk management frameworks

Financial and Prudential Requirements

  • Evidence of meeting minimum own funds requirements (which vary by the type of crypto-asset services offered)
  • Insurance cover or comparable guarantees where applicable

Operational and Technical Requirements

  • Systems and security access protocols
  • Customer onboarding procedures including KYC/AML controls compliant with the EU’s Anti-Money Laundering framework
  • Complaints handling and conflicts-of-interest policies
  • Safeguarding arrangements for client crypto-assets

Disclosure and Consumer Protection Requirements

  • White paper or marketing communications obligations as applicable
  • Clear disclosure of fees, risks, and terms of service

Regulators in larger member states — including the Autorité des marchés financiers (AMF) in France and BaFin in Germany — have published detailed national guidance on what a complete application must contain.


The Compliance Checklist: Actions for CASPs Right Now

Whether your firm is approaching the 1 July 2026 ceiling or is in a member state whose window already closed, the following checklist captures what authorised and grandfathered CASPs alike must address.

Pre-Application Readiness

  • Confirm which EU member states your firm actively serves and map the applicable transitional deadline for each against ESMA’s official list
  • Identify your home member state for MiCA purposes (where your registered office is located)
  • Engage external legal counsel specialising in MiCA or your home country’s NCA guidance
  • Conduct an internal gap analysis comparing current operations against MiCA’s Title V requirements

Governance and Structure

  • Review and update your management body composition to satisfy fit-and-proper criteria
  • Document conflicts-of-interest policies specific to crypto-asset services
  • Establish a dedicated compliance function or appoint a MiCA compliance officer

Technical and Operational

  • Audit your AML/KYC controls against the EU’s updated Anti-Money Laundering framework
  • Implement or verify client asset segregation arrangements
  • Review your custody or safekeeping arrangements if you hold client crypto-assets
  • Ensure your trading systems include the controls and disclosures MiCA mandates

Application Filing

  • Compile the full application dossier per your NCA’s published template
  • Submit well in advance of the applicable transitional deadline — NCA review times vary significantly
  • Track the NCA’s 25-working-day completeness assessment window (set out in MiCA Article 64) and respond promptly to any requests for additional information

Post-Application

  • Do not assume that filing an application equals continued operational permission indefinitely — monitor NCA communications actively
  • Prepare contingency plans in the event of a refusal: geographic restrictions, service wind-downs, or appeals

What Happens If a Firm Misses the Deadline?

Once the transitional period for a given member state expires, any CASP that has not received MiCA authorisation — and is not actively awaiting a decision on a pending application — must cease providing crypto-asset services to customers in that jurisdiction. Operating without authorisation after the deadline constitutes a regulatory breach subject to supervisory enforcement by the relevant NCA, which can include public warnings, fines, and orders to suspend services.

NCAs in several member states have already taken supervisory action against firms that failed to meet earlier transitional deadlines. ESMA coordinates oversight across the bloc to prevent regulatory arbitrage. Attempting to restructure into a non-EU entity to serve EU customers without authorisation is unlikely to succeed; MiCA’s geographic scope captures services offered to EU residents regardless of where the provider is domiciled.


DeFi, Stablecoins, and the Scope Question

MiCA primarily targets centralised CASPs — exchanges, custodians, brokers, and portfolio managers in crypto-assets. However, several adjacent categories require attention.

Stablecoin issuers operating under MiCA’s e-money token (EMT) or asset-referenced token (ART) provisions face different requirements and in some cases earlier applicable dates that pre-date the CASP transitional period.

DeFi protocols remain in a regulatory grey zone. Truly decentralised protocols with no identifiable legal entity may fall outside MiCA’s scope, but protocols with governance tokens, identifiable developers, or fee-taking front-ends are increasingly scrutinised. ESMA has indicated it will continue assessing where decentralised services meet the definition of regulated CASP activity.

For context on cross-border security risks that regulators also weigh when assessing crypto infrastructure, our DeFi Bridge Exploits Explained: How They Happen guide covers one of the operational risk categories NCAs examine.


How MiCA Compares to the US Regulatory Landscape

While EU firms navigate MiCA’s transitional mechanics, their US counterparts operate in a fundamentally different — and significantly more fragmented — environment. There is no single federal crypto-asset licence equivalent to MiCA authorisation, and state-level money transmission and BitLicense frameworks vary dramatically. Our US Crypto Regulation by State: 2026 Tracker provides a current breakdown of how different US states approach crypto licensing requirements.

On the enforcement side, our coverage of SEC Crypto Enforcement 2026: Latest Actions Explained highlights how US federal regulators have been using enforcement actions to fill the gaps that congressional legislation has not yet addressed — a sharp contrast to MiCA’s pre-emptive, comprehensive approach.


Key Takeaways

  • 1 July 2026 is the absolute final deadline for any EU member state’s MiCA CASP transitional period. No member state can extend beyond this date.
  • Transitional periods vary by country — several member states closed their windows in 2025. Firms serving multiple EU markets must comply with the earliest applicable deadline. Always verify your exact deadline against ESMA’s official list.
  • Grandfathering requires active compliance progress, not passive waiting. ESMA expects demonstrable movement toward MiCA authorisation during the transitional window.
  • Last-minute applications carry real risk. NCA review timelines are not guaranteed, and firms submitting close to deadlines may face gaps in operational coverage.
  • Failure to obtain authorisation in time requires service suspension. Enforcement consequences for post-deadline unauthorised operation are real and escalating.
  • DeFi and stablecoin issuers face distinct MiCA obligations that may not follow the same CASP transitional timeline.
  • Start the authorisation process now — compliance preparation, governance changes, and documentation take months, not days.

Last updated: June 2026