MiCA Compliance Checklist for Crypto Firms After the Transition
In short
MiCA's Article 143(3) grandfathering window for crypto-asset service providers closed on 1 July 2026, so a crypto firm serving EU clients is now authorized, notified under Article 60, exempt, or operating unlawfully. This checklist maps obligations by entity type with article-level citations and the evidence a supervisor can ask to see.
The Markets in Crypto-Assets Regulation's grandfathering window closed on 1 July 2026. Article 143(3) of Regulation (EU) 2023/1114 let firms already serving EU clients under national law continue "until 1 July 2026 or until they are granted or refused an authorisation pursuant to Article 63, whichever is sooner." As of 30 September 2026, a crypto firm touching EU clients is authorized, notified under Article 60, exempt, or operating unlawfully.
That means most MiCA checklists written before July answer an expired question. "How to get ready for the deadline" stopped being useful on 1 July. The checklist that matters now is an operating document: which obligations attach to your entity type, on what cadence, and what evidence a supervisor will ask to see. Below is a full obligations register for five entity types with article-level citations, plus the dates where the travel rule, DORA and the EU's new AML rulebook land on the same firms.
The grandfathering window closed on 1 July 2026, and it was never uniform
Article 143(3) had a second subparagraph: member states could decide not to apply the transitional regime or to shorten it where they judged their pre-MiCA national framework to be less strict. Many did. According to ESMA's list of national grandfathering periods, the window was six months in Finland, Hungary, Latvia, the Netherlands, Poland and Slovenia, nine in Sweden, twelve in Austria, Germany, Ireland, Lithuania and Slovakia (and Norway), and the full eighteen in the rest, including France, Italy, Spain, Luxembourg and Malta. Anyone treating "the July 2026 deadline" as an EU-wide fact was already late in several markets, which ESMA made explicit in its December 2024 statement when it described member states' "complete discretion not to apply this transitional regime or to reduce its duration." Germany's KMAG, for example, let legacy permissions run no longer than "spätestens mit Ablauf des 31. Dezember 2025" (section 50). Article 143(6) also allowed member states to run a simplified authorization procedure for applications filed between 30 December 2024 and 1 July 2026 by entities already authorized under national law.
ESMA's interim MiCA register is the authoritative scoreboard for where the market stands three months after the deadline: five CSV files covering white papers, ART issuers, EMT issuers, CASPs and non-compliant entities, last updated on 30 September 2026, which ESMA says will run until the register is integrated into its IT systems. Counting the CASP file as published that day gives 364 rows covering 361 entities: 358 legal-entity identifiers plus three Greek entities listed without one. Two carry end dates, so 359 entities are currently listed across 27 jurisdictions: the 24 EU member states that have entries plus Liechtenstein, Norway and Iceland. Germany has 96, France 36, the Netherlands 28, Cyprus 24 and Malta 23. Three caveats apply. The file mixes Article 63 authorizations with Article 60 notifications, so many of the names are established banks. The register is back-filled, so counts for earlier months keep rising; June 2026, the last full month before the window closed, shows 76 entities by listed date. And Hungary, Poland and Romania have no CASP entries. Elsewhere in the register, the ART file holds no issuers (header row only), 25 distinct EMT issuers appear, and the non-compliant file lists 173 entries, 164 of them submitted by Italy's CONSOB. Article 110 calls that file "non-exhaustive," so absence from it proves nothing, but presence on it is public, and your banks and counterparties can read it.
Key dates: five regimes land on the same firms between 2024 and 2028
MiCA is the regime everyone names, but a crypto firm's 2026 to 2028 compliance calendar is at least four instruments deep, with a fifth if you also face the UK. This is the table I would pin to the wall, with statuses as of 30 September 2026:
| Date | What applies | Instrument | Who it hits |
|---|---|---|---|
| 29 Jun 2023 | MiCA entered into force (application staged later, a distinction that is easy to blur) | Reg (EU) 2023/1114, Art. 149 | Not yet operative |
| 30 Jun 2024 | Titles III and IV apply: ART and EMT issuer regimes | MiCA Art. 149 | Stablecoin issuers |
| 30 Dec 2024 | Rest of MiCA applies: Title II offers, CASP authorization (Title V), market abuse rules (Title VI) | MiCA Art. 149 | CASPs, offerors, anyone arranging crypto transactions professionally |
| 30 Dec 2024 | Travel rule: full originator and beneficiary data on every crypto transfer, with no de minimis threshold | Reg (EU) 2023/1113 (TFR) and EBA/GL/2024/11 | CASPs |
| 17 Jan 2025 | DORA applies: ICT risk framework, incident reporting, register of information | Reg (EU) 2022/2554 | CASPs and ART issuers, as financial entities |
| 30 Jun 2025 to 31 Dec 2025 | National grandfathering windows close in stages: six-month states first, then Sweden, then the twelve-month states | MiCA Art. 143(3) and national choices per ESMA | Legacy national-regime firms |
| 4 Dec 2025 | Commission proposes moving CASP authorization and supervision to ESMA (a proposal, not law; see below) | COM(2025) 943 final | CASPs, eventually |
| 1 Jul 2026 | Grandfathering ends in every member state | MiCA Art. 143(3) | Legacy firms |
| 30 Sep 2026 | Commission's MiCA review consultations close (deadline extended from 31 Aug); the UK cryptoasset authorization gateway opens | Commission consultation; FCA | Everyone in this table; firms serving the UK |
| 30 Jun 2027 | Commission report on MiCA due under Art. 140 | MiCA Art. 140 | Everyone in this table |
| 10 Jul 2027 | AMLR applies: CASPs are obliged entities under the single EU AML rulebook | Reg (EU) 2024/1624 | CASPs |
| 25 Oct 2027 | UK cryptoasset regime commences (application window 30 Sep 2026 to 28 Feb 2027) | SI 2026/102 | Firms serving UK clients |
| 31 Dec 2027 | Trading-platform operators must have white papers for crypto-assets admitted to trading before 30 Dec 2024 | MiCA Art. 143(2)(b) | Trading platforms |
| About 2028 | AMLA begins direct supervision of selected high-risk cross-border obliged entities, six months after its first selection list | Reg (EU) 2024/1620, Art. 13(4) | Selected CASPs |
Three conflations to kill before they cost you. First, MiCA is not silent on anti-money-laundering controls: Article 68(8) requires CASPs to have effective procedures and arrangements for risk assessment to comply with national law transposing the Anti-Money Laundering Directive. But the detailed obligations come from that Directive as amended, the TFR since 30 December 2024, and the AMLR from 10 July 2027, so when a vendor says their tool "covers MiCA AML requirements," ask which instrument they mean. Second, an EMT issuer does not get "a MiCA license": it must already be a credit institution or e-money institution (Article 48). Third, the transfer of supervision to ESMA is still a proposal, and its shape may change (see below).
Find your entity type before you open any checklist
MiCA is five regimes wearing one name. Everything below keys off this table:
| You... | You are | Core MiCA regime | Capital floor (as of 30 Sep 2026) |
|---|---|---|---|
| Execute orders, advise, manage portfolios, place, transfer, or receive and transmit orders for crypto-assets | CASP, Class 1 | Title V | EUR 50,000 (Annex IV) |
| Do any of the above plus custody and/or exchange crypto for funds or other crypto | CASP, Class 2 | Title V | EUR 125,000 (Annex IV) |
| Operate a trading platform for crypto-assets | CASP, Class 3 | Title V | EUR 150,000 (Annex IV) |
| Issue a token referencing one or more assets, currencies or baskets (not a single official currency) | ART issuer | Title III (Arts. 16 to 47) | Highest of EUR 350,000, 2% of average reserve, or a quarter of fixed overheads (Art. 35) |
| Issue a token referencing a single official currency | EMT issuer | Title IV (Arts. 48 to 58) | Whatever your credit institution or e-money regime requires |
| Offer to the public, or seek admission to trading of, any other crypto-asset | Title II offeror | Title II (Arts. 4 to 15) | None: disclosure duties, not prudential ones |
| Are a bank, investment firm, e-money institution, UCITS manager or AIFM, CSD or market operator adding crypto services | Article 60 notified entity | Title V by notification | Per your existing prudential regime (Art. 60(10) excludes Art. 67) |
For CASPs, the Annex IV figure is a floor, not the requirement. Article 67 makes the prudential safeguards the higher of the class minimum or one quarter of the preceding year's fixed overheads, reviewed annually, held as Common Equity Tier 1 items, as an insurance policy covering every EU territory where you provide services (or a comparable guarantee), or as a combination. A Class 1 adviser with a heavy cost base can owe far more than EUR 50,000, so check business plans that were modeled on the flat figure alone. A note for issuers: significant EMTs come with extra capital and reserve rules under Article 58, so "EMT issuers hold capital under their banking or e-money regime" is only a starting point.
The MiCA obligations register gives each entity type its own table
The register below has one table per entity type; every row carries the obligation in plain language, its legal basis, whether it is one-time or ongoing, the evidence a supervisor will expect, and a suggested owner by role. Copy your table into your tracker as it stands, then add two working columns, Status (RAG) and Last reviewed. The structure follows our obligations register template: one row per obligation, never one row per law, because rows are what you can assign, evidence and test. If the term is new, start with the obligations register definition.
All legal bases are stated as of 30 September 2026; MiCA articles cite Regulation (EU) 2023/1114 unless another instrument is named. The Level 2 technical standards under MiCA (for example the record-keeping standard in Delegated Regulation (EU) 2025/1140) sit beneath these rows and set the format of the evidence.
CASPs (all classes; Class 3 adds the platform rows)
| Obligation | Legal basis | Type / cadence | Evidence a supervisor expects | Owner |
|---|---|---|---|---|
| Hold (and keep) authorization; provide only the services authorized | Arts. 59, 62, 63 | One-time, then event-driven on scope changes | Authorization decision; service-scope mapping against Art. 3(1)(16) | CEO / GC |
| Keep the authorization alive and the passport current: use it within 12 months, keep providing services (withdrawal follows nine consecutive months without them), and notify the home authority before serving other member states | Arts. 64, 65 | Ongoing; event-driven | Activity log by service, cross-border notifications with start dates | HoC |
| Hold prudential safeguards of at least the higher of the Annex IV class minimum or a quarter of prior-year fixed overheads | Art. 67 and Annex IV | Ongoing; recalculated at least annually | Overheads calculation, CET1 evidence or an insurance policy covering all service territories | CFO |
| Keep management fit and proper; notify changes to the management body before new members act | Arts. 68(1), 69 | Ongoing; event-driven | Suitability assessments, board CVs, notifications to the authority | HoC |
| Act honestly, fairly and professionally; communications fair, clear and not misleading | Art. 66 | Ongoing; continuous | Marketing sign-off log, client disclosures, risk warnings | HoC |
| Safeguard clients' crypto-assets and funds; segregate them from your own book | Arts. 70, 75 | Ongoing; continuous | Daily reconciliations, segregation attestations, custody policy and client-asset registers | Head of Ops |
| Operate a complaints-handling procedure, free of charge | Art. 71 | Ongoing | Complaints register with timestamps, response templates, outcome statistics | HoC |
| Identify, prevent, manage and disclose conflicts of interest | Art. 72 | Ongoing; reviewed at least annually | Conflicts register, disclosures published to clients | HoC |
| Outsource without hollowing out the entity, and remain fully responsible | Art. 73 | Ongoing; event-driven per arrangement | Outsourcing register, due-diligence files, exit plans, intra-group agreements | COO |
| Keep a plan for an orderly wind-down (for custody, platform, exchange, execution and placing services) | Art. 74 | One-time, then maintained | Wind-down plan with continuity and recovery of critical activities, review minutes | CFO / COO |
| Keep records of all services, activities, orders and transactions for five years (up to seven on the authority's request) | Art. 68(9) | Ongoing; continuous | Retention policy, retrieval test results, sample client record requests | CTO |
| Prevent and detect market abuse, and report suspicious orders and transactions | Arts. 86 to 92 (esp. Art. 92) | Ongoing; continuous | Surveillance system output, suppression logic documentation, suspicious-report filings | HoC |
| Attach full originator and beneficiary data to every crypto transfer, with no de minimis threshold | TFR Reg (EU) 2023/1113 and EBA/GL/2024/11 | Ongoing; per transfer | Data-completeness sampling, counterparty CASP due diligence, handling policy for self-hosted addresses | MLRO |
| Run a DORA-grade ICT risk framework; classify and report incidents; maintain the register of information | DORA Reg (EU) 2022/2554 | Ongoing | Register of information in the prescribed format, incident log, resilience-testing results | CISO |
| Class 3: lay down, maintain and implement operating rules for the platform; meet white-paper duties for assets admitted to trading (legacy assets by 31 Dec 2027) | Arts. 76, 143(2)(b) | Ongoing; per listing | Platform rulebook, admission files, white-paper availability checks | Head of Markets |
ART issuers
| Obligation | Legal basis | Type / cadence | Evidence a supervisor expects | Owner |
|---|---|---|---|---|
| Obtain authorization (or approval as a credit institution) before offering an ART | Arts. 16 to 21 | One-time | Authorization decision, approved white paper | CEO / GC |
| Publish and maintain the approved white paper | Arts. 17, 19, 21, 25 | Ongoing; event-driven on modifications | Published white paper, modification notifications to the authority | GC |
| Hold own funds of at least the highest of EUR 350,000, 2% of the average reserve of assets, or a quarter of fixed overheads (3% of the reserve for significant ARTs) | Arts. 35, 45(5) | Ongoing; reserve averaged daily over the preceding six months | Own-funds calculation with the daily reserve series | CFO |
| Maintain a segregated reserve of assets backing the token, with compliant custody and investment | Arts. 36 to 38 | Ongoing; continuous | Reserve composition reports, custodian agreements, independent reserve audits | Treasurer |
| Grant holders a permanent right of redemption | Art. 39 | Ongoing | Redemption policy, execution statistics, fee schedule | Head of Ops |
| Maintain recovery and redemption plans | Arts. 46, 47 | One-time, then maintained | Plans filed with the authority, review minutes | CFO |
| Monitor the Article 43 significance criteria: more than 10 million holders; more than EUR 5 billion issued, market capitalization or reserve; more than 2.5 million transactions and EUR 500 million a day; plus four qualitative criteria. The EBA classifies a token as significant where at least three are met | Arts. 43 to 45; EBA supervision | Ongoing; quarterly indicator check | Indicator reporting pack; readiness plan for EBA handover and higher own funds | HoC |
EMT issuers
| Obligation | Legal basis | Type / cadence | Evidence a supervisor expects | Owner |
|---|---|---|---|---|
| Be an authorized credit institution or e-money institution before issuing | Art. 48(1) | One-time (status precondition) | Banking or e-money authorization; scope confirmation | CEO / GC |
| Notify your authority of the intention to offer at least 40 working days beforehand, and notify the white paper at least 20 working days before publication (notification, not approval) | Arts. 48(6), 51 | One-time per token; event-driven on changes | Notification receipts, published white paper | GC |
| Issue at par on receipt of funds, and redeem at par, at any time, without a fee | Art. 49 | Ongoing; continuous | Redemption policy, execution and timing statistics | Head of Ops |
| Invest funds received in line with the rules (at least 30% in separate accounts at credit institutions; the rest in secure, low-risk assets in the same currency) and safeguard funds under your e-money regime | Art. 54; Directive 2009/110/EC | Ongoing | Safeguarding accounts, reconciliation evidence, investment reports | CFO |
| Maintain recovery and redemption plans (notified within six months of the offer) | Art. 55 | One-time, then maintained | Plans filed with the authority | CFO |
| Monitor EMT significance criteria; prepare for EBA involvement if significant, including the extra requirements that apply to significant EMTs | Arts. 56, 58 | Ongoing; quarterly | Indicator reporting pack | HoC |
Title II offerors and admission-seekers
| Obligation | Legal basis | Type / cadence | Evidence a supervisor expects | Owner |
|---|---|---|---|---|
| Test the exemptions first: fewer than 150 persons per member state, total consideration not exceeding EUR 1 million over 12 months, or a qualified-investor-only offer removes the white-paper duty (not the marketing rules), and the exemptions do not apply to ARTs or EMTs | Art. 4(2) to (4) | One-time per offer | Exemption analysis memo with counting methodology | GC |
| Draft the white paper to the Annex I template and notify it to the authority at least 20 working days before publication. It is notification, not approval: Art. 8(3) bars authorities from requiring pre-approval | Arts. 6, 8 | One-time per offer | Notification receipt, dated white paper, publication evidence | GC |
| Keep marketing communications fair, clear and not misleading, and consistent with the white paper | Art. 7 | Ongoing during the offer | Marketing sign-off log against white-paper claims | Marketing |
| Honor the 14-calendar-day retail right of withdrawal (it does not apply where the asset was admitted to trading before purchase) | Art. 13 | Ongoing during the offer | Withdrawal mechanism, refund logs | Head of Ops |
| Update the white paper for significant new factors, material mistakes or inaccuracies | Art. 12 | Event-driven | Modified white paper, notification trail | GC |
Article 60 notified financial entities
| Obligation | Legal basis | Type / cadence | Evidence a supervisor expects | Owner |
|---|---|---|---|---|
| Map which crypto services your existing authorization allows (banks: all; investment firms: the equivalents of their MiFID permissions; e-money institutions: custody and transfers for their own EMTs; CSDs: custody only; UCITS managers and AIFMs: portfolio management, advice and order transmission; market operators: a trading platform) | Art. 60(1) to (6) | One-time | Service-equivalence mapping memo | GC |
| Notify your authority at least 40 working days before providing services for the first time, with the full information set: program of operations, AML controls and business continuity plan, ICT and security documentation, segregation procedures, and service-specific policies. The authority has 20 working days to check completeness, and the period is suspended while information is missing | Art. 60(7), (8) | One-time | Complete notification file; the authority's completeness confirmation | HoC |
| Comply with the CASP conduct obligations that attach despite the lighter entry route: Arts. 66 and 68 to 82 apply as relevant to the services notified, while Arts. 62, 63, 64, 67, 83 and 84 do not | Arts. 60(10), 66, 68 to 82 | Ongoing | Same evidence set as the CASP table above, scoped to the notified services | HoC |
| Keep TFR and DORA compliance running through your existing status | TFR; DORA | Ongoing | Travel-rule sampling; DORA register of information covering the crypto business line | MLRO / CISO |
The evidence column is the point, because a checklist that ends at "comply with Article 70" gives you nothing to show. Supervisors sample artifacts (reconciliations, registers, filings, logs), and the fastest gap-finder is asking, for each row, "could I produce this within 48 hours?"
Authorization was the easy part: ESMA told supervisors there are no low-risk CASPs
If you hold an authorization and consider the project finished, read ESMA's January 2025 supervisory briefing on CASP authorization. Its risk-based-approach section opens with this: "ESMA is of the view that there are no low-risk CASPs." A cursory assessment on the basis of a low-risk categorization, it adds, should never happen.
The briefing then gets specific in ways worth building controls around:
- Elevated scrutiny has thresholds, and other triggers too. More than 1,000,000 yearly active EU users or a balance sheet above EUR 3 billion earns it, as does serving more than 200,000 yearly active users outside your home member state, which drags in host-state authority coordination. Group complexity, an ecosystem role and issuer-plus-CASP models also draw attention, and authorities may scrutinize smaller firms.
- Substance is enforced. The CEO "should as a rule devote 100%" of their time to the CASP; at least one executive board member should be resident in the authorizing member state (smaller member states may accept a resident of a neighboring country); and the EU entity must decide autonomously, without "taking the discussed points back to the (head) group entity for clearance."
- Outsourcing cannot hollow out the entity. Key roles stay predominantly in the home jurisdiction; support functions can sit elsewhere. Your Article 73 outsourcing register is where this gets tested.
Supervisors are also being graded. In July 2025, ESMA published a fast-track peer review of a CASP authorization in Malta and found that the authorization process only partially met expectations, with several material issues unresolved at the time of the authorization. A supervisor publicly criticized for leniency does not usually respond by getting more lenient. On 8 July 2026, ESMA also launched a Common Supervisory Action on the digital operational resilience of CASPs, with an emphasis on custody: national authorities will test governance, key management, transaction controls, incident response, smart contracts and third-party dependencies from the second half of 2026 to the first half of 2027. If you provide custody, treat those six areas as your evidence list.
The bigger structural question is who supervises you. On 4 December 2025 the Commission proposed to move the authorization and supervision of CASPs from national authorities to ESMA (COM(2025) 943), with credit institutions staying with their existing supervisors, other Article 60 entities staying unless crypto becomes their main activity, and the transfer taking effect 24 months after the regulation enters into force. As of 30 September 2026 it is still a proposal. In the Council, the Irish Presidency reports broad support in principle for focusing direct ESMA supervision on genuinely significant cross-border entities, with the criteria for significance across CASPs and market infrastructures still to be decided, and is aiming for a general approach in October 2026 at the latest (ST 11406/26). In Parliament the ECON committee has a draft report and amendments tabled in July (procedure file), and ESMA itself expects final agreement in 2027 (ESMA, 28 September 2026). Plan for the direction of travel, not the final text.
Article 111 sets floors for national maximums, not caps
The most repeated penalty claim about MiCA, "fines go up to EUR 5 million," is wrong twice. Article 111 sets minimum levels for the maximum administrative fines that member states must make available to their authorities, and the market-abuse tier goes far past EUR 5 million. As of 30 September 2026:
| Infringement bucket | Maximum fine national law must allow, at least (legal persons) | MiCA basis |
|---|---|---|
| Title II offer and white paper rules | EUR 5,000,000 and 3% of total annual turnover | Art. 111(1)(a), 111(3)(a) and (b) |
| ART issuer obligations (Title III) | EUR 5,000,000 and 12.5% of total annual turnover | Art. 111(1)(b), 111(3)(a) and (d) |
| EMT issuer obligations (Title IV) | EUR 5,000,000 and 12.5% of total annual turnover | Art. 111(1)(c), 111(3)(a) and (d) |
| CASP obligations (Title V) | EUR 5,000,000 and 5% of total annual turnover | Art. 111(1)(d), 111(3)(a) and (c) |
| Art. 88 (public disclosure of inside information) | EUR 2,500,000 or 2% of total annual turnover | Art. 111(5)(j) |
| Arts. 89 to 92 (insider dealing, unlawful disclosure, market manipulation, prevention and detection) | EUR 15,000,000 or 15% of total annual turnover | Art. 111(5)(j) |
The text states each euro amount and each percentage as a separate floor for the authority's power, so read "and" as "the authority must be able to reach at least both," not as a formula. For natural persons the floors are at least EUR 700,000 for infringements of Titles II to V (Art. 111(2)(d)), and EUR 1,000,000 (Art. 88) or EUR 5,000,000 (Arts. 89 to 92) for market abuse (Art. 111(5)(i)). Authorities must also be able to fine at least twice the profit gained or loss avoided (three times for market abuse). Member states may set higher levels, and some have: Ireland's transposition provides for maximum fines of EUR 1,000,000 against natural persons for Titles II to V (S.I. 607/2024, regulation 6). Turnover is measured at the consolidated ultimate-parent level where consolidated accounts are required, which changes the arithmetic materially for group structures.
Two forward markers. The EBA opened a consultation on its methodology for setting fines under MiCA (EBA/CP/2026/10) on 26 June 2026; it closed on 28 September 2026 and the final methodology is pending. It applies only to fines the EBA itself imposes on issuers of significant ARTs and EMTs, not to national authorities, whose powers sit under Article 111. And with the transition over, expect the first real enforcement actions against formerly grandfathered firms; the register's non-compliant file and the national authorities' warning lists are the early-warning channel. As of 30 September 2026 we found no enforcement action against a formerly grandfathered firm in the sources we checked.
Stand up the register, calendar 2027 and 2028, and watch the sources weekly
Three moves, in order.
Stand up the register. Copy your entity-type table into a tracker, add Status and Last reviewed columns, put a named owner on every row, and date every row "as of." Run the 48-hour evidence test this month and treat every miss as the finding a supervisor would have written. Keep a visible change log on the register itself; the structure in our register template works unmodified here.
Put the 2027 to 2028 calendar into your impact process now. The AMLR makes you an obliged entity on 10 July 2027, AMLA supervision phases in from around 2028, the Commission's MiCA review report is due by 30 June 2027 with scope changes to NFTs, DeFi, staking and lending on the table, and the ESMA supervision proposal could move your supervisor. Each deserves a dated row in your change pipeline with an owner and a first-assessment deadline; a regulatory change impact assessment template is the right instrument, and the patterns in how compliance teams track regulatory changes apply directly.
Watch the sources weekly, because that is the cadence they publish on. The ESMA register files update on ESMA's own schedule, the EBA published a fines-methodology consultation five days before the transition ended, national transpositions diverge quietly, and the Council and Parliament files on ESMA supervision move every few weeks. This is more than a quarterly manual sweep can handle. It is the workflow RegWatch (my company) was built for: a Watchlist pointed at ESMA, the EBA and your national authorities, monitoring runs on the schedule you set, triage that scores each Finding against your company profile and writes a plain-language "Why this matters" for each one it accepts, and one step from an accepted Alert to a tracked Obligation with an owner, a deadline and evidence. A spreadsheet register plus a disciplined weekly sweep is a legitimate way to start. The failure mode is a register that was accurate on authorization day and never again.
MiCA compliance work from here on is register maintenance under tightening supervision, not project delivery. We maintain this same post-deadline structure for other regimes: the EU AI Act deployer checklist and the US state privacy laws tracker run on the identical register-plus-changelog pattern.
This article is general information, not legal advice.
Questions
Is MiCA compliance still possible if you missed the 1 July 2026 deadline?
Yes, but not while operating. Article 143(3)'s transitional cover ended on 1 July 2026, and earlier in member states that shortened it to as little as six months, so an unauthorized firm must stop providing crypto-asset services to EU clients. The Article 62 to 63 application route stays open: apply, wait, relaunch once authorized. ESMA's interim register also carries a non-exhaustive public file of entities operating in breach.
Who needs a MiCA license?
Anyone providing any of the ten crypto-asset services in Article 3(1)(16) to clients in the EU needs CASP authorization under Article 59, unless they are a credit institution, central securities depository, investment firm, market operator, e-money institution, UCITS manager or AIFM notifying under Article 60. ART issuers need Title III authorization (Articles 16 to 21). EMT issuers must already be credit institutions or e-money institutions (Article 48).
How much capital does MiCA require?
For CASPs, prudential safeguards of at least the higher of the Annex IV class minimum (EUR 50,000, EUR 125,000 or EUR 150,000) or one quarter of the preceding year's fixed overheads, held as Common Equity Tier 1 capital, insurance, or both (Article 67). ART issuers need the highest of EUR 350,000, 2% of the average reserve of assets or a quarter of fixed overheads (Article 35). EMT issuers hold capital under their banking or e-money regime.
What are the penalties for MiCA non-compliance?
Article 111 sets minimum maximums that member states must give their authorities. For legal persons that means at least EUR 5 million and, as a separate floor, at least 3% of turnover for offer rules, 5% for CASPs and 12.5% for ART and EMT issuers, and at least EUR 15 million or 15% for market abuse under Articles 89 to 92. Member states may go higher. Natural persons face at least EUR 700,000, and more for market abuse.
Does MiCA cover NFTs and DeFi?
Mostly no, with sharp edges. Crypto-assets that are unique and not fungible sit outside MiCA (Article 2(3)), but fractional parts of an NFT are not unique, and a large series can indicate fungibility (recital 11). Services provided in a fully decentralized manner without any intermediary fall outside the scope (recital 22). Both boundaries are open questions in the Commission's MiCA review consultations, which closed on 30 September 2026.
Terms in this guide
Sources
- Regulation (EU) 2023/1114 (MiCA), EUR-Lex accessed 30 Sep 2026
- Regulation (EU) 2023/1113 (Transfer of Funds Regulation), EUR-Lex accessed 30 Sep 2026
- Regulation (EU) 2022/2554 (DORA), EUR-Lex accessed 30 Sep 2026
- Regulation (EU) 2024/1624 (AML Regulation), EUR-Lex accessed 30 Sep 2026
- Regulation (EU) 2024/1620 (AMLA Regulation), EUR-Lex accessed 30 Sep 2026
- Commission Delegated Regulation (EU) 2025/1140: regulatory technical standards on records to be kept under MiCA Article 68 accessed 30 Sep 2026
- EBA Travel Rule Guidelines (EBA/GL/2024/11) accessed 30 Sep 2026
- ESMA: List of MiCA grandfathering periods under Article 143(3) accessed 30 Sep 2026
- ESMA: Statement on MiCA transitional measures (17 December 2024) accessed 30 Sep 2026
- ESMA: MiCA page and interim MiCA register (CSV files, last updated 30 September 2026) accessed 1 Oct 2026
- ESMA interim MiCA register: authorized and notified CASPs (CASPS.csv, 30 September 2026 update) accessed 1 Oct 2026
- ESMA: Supervisory briefing on the authorisation of CASPs (31 January 2025) accessed 30 Sep 2026
- ESMA: Fast-track peer review on a CASP authorisation and supervision in Malta (10 July 2025) accessed 30 Sep 2026
- European Commission: Proposal COM(2025) 943 final on market integration and supervision (4 December 2025) accessed 30 Sep 2026
- European Parliament Legislative Observatory: procedure 2025/0383(COD) accessed 30 Sep 2026
- Council of the EU: Irish Presidency steering note on the market integration and supervision package (ST 11406/26, 3 July 2026) accessed 30 Sep 2026
- ESMA: 2027 work program priorities (28 September 2026) accessed 30 Sep 2026
- European Commission: Targeted consultation on the review of the MiCA Regulation accessed 30 Sep 2026
- EBA: Consultation Paper on a methodology for setting fines under MiCA (EBA/CP/2026/10, 26 June 2026) accessed 30 Sep 2026
- EBA: supervisory role under MiCA accessed 30 Sep 2026
- ESMA: Common Supervisory Action on CASPs' digital operational resilience (8 July 2026) accessed 30 Sep 2026
- Ireland, S.I. No. 607 of 2024 (European Union (Markets in Crypto-Assets) Regulations 2024) accessed 30 Sep 2026
- Germany, Kryptomärkteaufsichtsgesetz (KMAG), section 50 transitional provision accessed 30 Sep 2026
- FCA: A new regime for cryptoasset regulation, and how the authorisation gateway will operate accessed 30 Sep 2026
- The Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026, SI 2026/102 accessed 30 Sep 2026
