From the journal

AFM Reiterates Supervision of Crypto-Asset Service Providers Under MiCAR

The AFM has emphasized that crypto-asset service providers must obtain a license or notification to legally operate in the EU under MiCAR.

1 min read

The AFM is currently enforcing compliance requirements for crypto-asset service providers (CASPs) as of the date of this announcement. CASPs must obtain a license or notification from the AFM or another European supervisory authority to legally offer crypto services within the EU.

The AFM relies on the Markets in Crypto-Assets Regulation (MiCAR), specifically Article 63 for licensing CASPs and Article 60 for notifications from other financial institutions.

This requirement applies to all entities providing crypto-asset services, including custody, trading platforms, exchanges, and portfolio management, as defined under MiCAR.

Firms that are not authorized must take immediate steps to either apply for a license or cease operations in the EU.

Source: AFM, official publication, retrieved 2026-08-11

Crypto Regulatory

More from the journal

See all
Illia Prokopiev

MLR Registration and the FCA Cryptoasset Gateway to 25 October 2027

This matter concerns the transition of a United Kingdom cryptoasset business from FCA registration under the Money Laundering Regulations 2017 to Part 4A permission under the Financial Services and Markets Act 2000. The question is whether MLR registration gives conversion, grandfathering, priority, or a right to continue after 25 October 2027, and what an affected firm should do before the gateway closes. This analysis assumes an existing UK-facing cryptoasset business, no relevant Part 4A permission, and an intention to continue after commencement.

Illia Prokopiev

ESMA's 2026 Custody Resilience CSA and the Rules That Actually Bind

ESMA’s 2026 Common Supervisory Action is a coordinated national review of digital operational resilience in crypto-asset custody. It will test whether selected crypto-asset service providers can demonstrate effective controls across six announced workstreams. The legal questions are which requirements are binding, how national competent authorities may assess control effectiveness, and what consequences may follow from a deficiency. This analysis assumes that the firm is permitted under MiCA Article 59 to provide custody and administration within Article 3(1)(17).

Illia Prokopiev

Stablecoin regulation in the US, Hong Kong and Singapore

Stablecoin and digital-token regulation now combines market-entry authorization with continuous financial-crime controls in daily operations. The question is whether the United States’ proposed payment-stablecoin customer identification program, Hong Kong’s narrow first licensing round, and Singapore’s digital payment token (DPT) directory support a bank-like compliance characterization. They do, with material limits. The more accurate proposition is that compliance is moving beyond approval into continuous financial-institution-grade operations.