Review date: 4 August 2026. The outer limit of the transitional regime in Article 143 of MiCA fell on 1 July 2026 and has passed. Firms still providing crypto-asset services to clients in the EU should now be reading their position against the authorisation they actually hold, not against a transitional window.
Regulation (EU) 2023/1114 (MiCA) applies across the EU, with the title governing crypto-asset service providers (CASPs) applicable from 30 December 2024. The consolidated text on EUR-Lex, at https://eur-lex.europa.eu/eli/reg/2023/1114/oj, is the controlling reference for everything summarised below, and it should be read alongside the national implementing measure in the relevant Member State.
The transitional regime was optional, and it was not uniform.
Article 143 permitted, but did not oblige, Member States to allow firms that were lawfully providing crypto-asset services under national law before 30 December 2024 to continue doing so for a limited period, with 1 July 2026 as the outer limit. Member States were free to shorten that period or to decline to apply it at all, and the transitional entitlement could also end earlier for an individual firm on the date its CASP authorisation was granted or refused. ESMA issued statements and Q&A material on the transitional arrangements and on the risks of relying on them; these are published at https://www.esma.europa.eu.
Two points follow. There was no single grandfathering rule that applied identically in every Member State, so any statement of the form "the deadline was X across the EU" is inaccurate. And an assessment of a firm's current position has to begin with the national implementing measure in its home Member State, not with the 1 July 2026 date on its own.
What the current posture looks like.
Where a firm provides crypto-asset services covered by MiCA to clients in the EU, in circumstances that require authorisation, and holds neither a CASP authorisation nor another permission that allows the activity, it is in breach of EU law. That statement is scoped deliberately. Whether it applies to a given firm depends on which services are actually provided, on whether the firm solicits or serves EU clients or falls within the narrow reverse solicitation limits, on the authorisation or exemption status of the entity (credit institutions and certain other regulated firms are treated differently), and on the position taken by the competent authority in the relevant jurisdiction. This is general commentary and not legal advice on any specific structure.
What CASP authorisation actually requires.
The application is not a registration form. It is a regulatory submission that is assessed on corporate governance, capital adequacy, compliance infrastructure, IT security and consumer protection.
Minimum own funds are set by class in Annex IV of the Regulation rather than as one figure for all applicants. Annex IV sets Class 1 at EUR 50,000 for services such as reception and transmission of orders, execution of orders, placing, transfer services, advice and portfolio management; Class 2 at EUR 125,000 for custody and administration on behalf of clients and for exchange of crypto-assets for funds or for other crypto-assets; and Class 3 at EUR 150,000 for operating a trading platform. Article 67 then requires prudential safeguards of at least the higher of the applicable Annex IV amount or one quarter of the preceding year's fixed overheads, so the Annex figure is a floor rather than the full calculation. Confirm the applicable class against the current Annex IV text on EUR-Lex before budgeting.
Establishment is governed by Article 59 of the Regulation, which sets three conditions on the applicant entity: a registered office in a Member State in which it carries out at least part of its crypto-asset services; a place of effective management in the Union; and at least one director resident in the Union. Those are the conditions in the text on EUR-Lex and they should be read there rather than in summaries. There is no MiCA-wide requirement that all decision-making be conducted on-site in the home Member State. Individual competent authorities may apply their own local substance expectations to an application, but that is national add-on commentary rather than a condition of the Regulation, and it has to be confirmed against the position of the specific authority. Governance structures must be defined, with clear reporting lines and accountability. The compliance function must be operational rather than merely documented: supervisors examine whether AML and KYC controls, transaction monitoring and suspicious activity reporting function in practice.
The fragmentation problem.
Despite MiCA's harmonisation objective, implementation varies across Member States. Transitional measures differed. Regulatory interpretation differs. Application processing speed differs. An applicant that satisfies one national authority may face different expectations from another. The choice of home Member State is strategic rather than administrative.
Passporting, the ability to operate across the EU from a single authorisation, is the principal advantage, and it runs from the authorisation granted by the home competent authority.
Octus operational commentary, not empirical evidence. In the files we have worked on, an application that is thinly evidenced in a more permissive jurisdiction has tended to generate further questions when the firm subsequently operates into stricter markets. That is a description of our own casework and not a measured effect. We are not aware of published data establishing that jurisdiction choice produces defined supervisory outcomes, and we do not assert one.
What most operators get wrong.
They treat CASP authorisation as an extension of VASP registration. VASP registration under the national regimes was largely an AML process. MiCA authorisation is a financial services licensing regime with prudential requirements, consumer protection obligations and ongoing supervisory expectations.
Octus operational commentary, not empirical evidence. Where we have seen MiCA approached with retrofitted AML, minimal governance and template policies, those submissions are the ones that have absorbed the most remediation work before they could be filed with any confidence. That is our own experience of preparing applications. Octus holds no dataset on application outcomes across Member States and makes no general claim about whether such firms fail applications or draw supervisory attention.
Where this leaves firms now.
The transitional route has closed at its outer limit. The remaining questions are narrower and firm-specific: whether an application is pending and what the competent authority has said about continued activity while it is assessed, whether the services provided fall inside or outside the MiCA perimeter, and whether EU clients are being served in a way that requires authorisation at all. Each of those has to be answered against the Regulation, the national measure and the supervisor's published position, and documented.