Official registers identify crypto firms and the regulatory permissions or registrations they hold. The preceding How to obtain a MiCA CASP authorisation addresses the application route. Verification requires a different inquiry: whether the actual provider has the relevant status for the proposed service, territory and date. In the EU, that inquiry starts with the European Securities and Markets Authority's (ESMA) MiCA register. In the UK, it requires careful reading of the Financial Conduct Authority's (FCA) Financial Services Register. Regulation (EU) 2023/1114 (MiCA), Articles 59(4) and 109(5); FCA, Financial Services Register.
Summary
- EU: Search the crypto-asset service provider (CASP) records and match the legal entity, permitted services, countries and operative dates. A token white paper or issuer entry does not establish CASP permission. MiCA, Article 109(1) and (5).
- EU: Eligible financial entities providing services through Article 60 also enter ESMA's register. A standalone CASP authorisation is not the only valid route represented there. MiCA, Article 60(12).
- EU: ESMA updates its interim register weekly. Withdrawals and specified supervisory measures remain published for five years, so finding a name does not establish current unrestricted permission. MiCA, Article 109(6)–(7); ESMA, Interim MiCA Register, Update frequency.
- UK: Cryptoasset registration under the Money Laundering Regulations concerns anti-money laundering and counter-terrorist financing supervision. It does not by itself establish authorisation under the Financial Services and Markets Act 2000 (FSMA). S.I. 2017/692, regulations 54 and 56; FCA, Cryptoassets: AML / CTF regime.
- UK: The new cryptoasset application period opened on 30 September 2026. The 2026 Regulations set full commencement for 25 October 2027, with earlier commencement for specified purposes. An application does not establish that permission has been granted. S.I. 2026/102, regulation 1(2)–(3); FCA, Cryptoassets: How the gateway will operate, Application period.
- EU and UK: Warning lists supplement positive permission checks. Their silence does not establish authorisation, and copied regulatory details do not authenticate a website or caller. MiCA, Article 110(1); FCA, Warning List and Clone firms and individuals.
The legal entity behind the service
Verification should start with the provider named in the customer agreement and service disclosures. The reviewer should compare that entity with the official record, rather than stop at a matching brand. Where several group companies use one trading name, an affiliate's permission does not establish the contracting company's status. MiCA, Articles 59(1), 59(4) and 109(5)(a)–(b).
The EU comparison should include the legal entity identifier, or LEI, where the record supplies it. For UK searches, the FCA firm reference number, or FRN, helps distinguish records. The reviewer should match these identifiers to the entity that actually provides the service. MiCA, Article 109(5)(a); FCA, Clone firms and individuals, How clone firms work.
The ESMA MiCA register
The official starting point is ESMA's Markets in Crypto-Assets Regulation page, under Interim MiCA Register. Its downloads separate crypto-asset service providers from token white papers, token issuers and non-compliant entities. The CASP records are the relevant starting point for checking a service provider. ESMA, Markets in Crypto-Assets Regulation, Interim MiCA Register.
A token's appearance in the white-paper records does not establish that the firm selling or holding it has CASP permission. ESMA expressly states that the listed white papers for tokens other than asset-referenced tokens and e-money tokens have not received regulatory review or approval. That statement concerns the specified white-paper category; it should not be extended to every issuer procedure. MiCA, Article 109(1)–(4); ESMA, Interim MiCA Register, white-paper disclaimer.
The register also covers eligible financial entities using the Article 60 notification route addressed in the first instalment. After checking completeness, their competent authorities transmit the relevant information to ESMA. Verification must therefore accommodate that route rather than demand a standalone CASP authorisation from every provider. MiCA, Article 60(12).
Services and territorial coverage
The permitted activity must match the service being purchased. An entry covering custody does not establish permission to operate a trading platform. A commercial description of a business as a MiCA-licensed exchange cannot replace inspection of its actual service permissions. MiCA, Articles 59(6) and 109(5)(d). Where the arrangement includes payment services related to the crypto-asset service, the reviewer should also check the payment-service provider's status. Article 70(4) requires the CASP, or the third party providing those services, to be authorised under Directive (EU) 2015/2366. A CASP entry alone does not establish that separate permission. MiCA, Article 70(4).
Country information also needs careful interpretation. Article 109 requires the host Member States where the provider intends to operate, alongside a starting or intended starting date. Those entries must be read with the applicable cross-border commencement position. A proposed start date does not establish that service provision has already begun lawfully. Under Article 65(4), the right to start arises on receipt of the home authority's notice that it has transmitted the information, or at the latest on the fifteenth calendar day after submission of the information required by Article 65(1). MiCA, Articles 65 and 109(5)(e)–(f).
For a cross-border engagement, the reviewer should establish that the identified entity can provide the particular service in the customer's Member State. A reference to an EU authorisation does not resolve the separate UK registration, permission or promotion questions. The governing territory and activity determine which record needs checking. MiCA, Article 65; FCA, Cryptoassets: AML / CTF regime; Financial Services and Markets Act 2000, section 21(3).
Products outside the firm's MiCA permissions
A provider's authorised status does not extend MiCA protection to every product on its website. CASPs must communicate information fairly, clearly and without misleading clients. ESMA's non-binding supervisory guidance applies that duty to the distinction between regulated services and activities outside MiCA. MiCA, Article 66(1)–(2); ESMA Statement ESMA35-1872330276-2329, 11 July 2025, pp. 1–3.
Crypto-asset lending requires particular care. In its non-binding interpretation, ESMA states that MiCA does not address lending and borrowing as service categories. It also states that MiCA safeguarding arrangements do not apply to assets used in lending programmes. That does not remove the CASP's general MiCA duties: ESMA also states that lending requires prior express and specific consent on clearly defined terms, not inconspicuous consent in general terms and conditions. Where a CASP holds clients' crypto-assets or their means of access, Article 70(1) requires safeguarding of ownership rights and prevention of own-account use. A custody permission therefore cannot establish the protection available after assets enter a lending arrangement. MiCA, Articles 66(1)–(2) and 70(1); ESMA, Q&A 2883, 18 June 2026, answer.
That interpretation does not exclude other legislation. ESMA expressly reserves case-by-case classification under EU or national law. The reviewer must examine the lending terms and any separate permissions rather than treat the CASP entry as approval of the entire arrangement. ESMA, Q&A 2883, answer, final paragraph.
Dates, withdrawals and restrictions
An official entry can document a past authorisation. MiCA requires withdrawals and specified supervisory measures to remain published for five years. National authorities can suspend or prohibit services without the underlying record disappearing. The operative dates and restrictions therefore control the reading of a matching entry. MiCA, Articles 94(1)(b), (c), (f) and 109(6)–(7).
ESMA states that it updates the interim register weekly and that national information does not appear immediately. A recent announcement and a missing central entry can therefore reflect a reporting delay. That possibility requires confirmation from the home authority; it does not justify accepting the announcement as sufficient proof. ESMA, Interim MiCA Register, Update frequency.
The scope and exceptions addressed in the first instalment also determine whether a MiCA permission is required. A negative search cannot replace that assessment. The Article 143(3) grandfathering period expired across the EU by 1 July 2026. A historic national registration or a pending application cannot now justify continued service provision under that provision. MiCA, Articles 59(1) and 61(1); Article 143(3).
Where official records conflict, the reviewer should seek the relevant authority's current confirmation and any operative decision. An older download cannot establish whether a later restriction applies. The comparison should distinguish the date of the register extract from the effective date of the regulatory action. MiCA, Articles 94(1) and 109(5)(h), (6)–(7).
Non-compliant entities and warnings
ESMA's register of non-compliant entities is expressly non-exhaustive. It concerns entities providing services in breach of Articles 59 or 61. Absence from that list does not establish permission, because Article 110 does not require it to identify every unauthorised provider. MiCA, Article 110(1)–(3).
The FCA gives the same evidential warning about its Warning List: an unlisted firm can still be unauthorised or a scam. Searches should cover the trading name and website as well as the claimed legal entity. Where a notice concerns a clone, its false contact details must be distinguished from those of the genuine firm being impersonated. FCA, Warning List, Search the Warning List; Clone firms and individuals, How clone firms work.
The FCA crypto register
The UK check should use the full Financial Services Register. It contains current and historical records, so the appearance of a name requires inspection of its status and relevant permissions. For crypto businesses, the reviewer should identify the money-laundering registration and any published restrictions affecting the proposed activity. FCA, Financial Services Register; FCA Firm Checker, Information you won't find on this tool.
The FCA's simpler Firm Checker omits certain information available in the full register. The omitted information includes published crypto-activity restrictions and the right to approve financial promotions. It also excludes products and services offered only to firms or professionals. A business counterparty review should not stop at that consumer-facing tool. FCA, FCA Firm Checker, Information you won't find on this tool.
Under the current money-laundering regime, in-scope cryptoasset exchange providers and custodian wallet providers carrying on business in the UK require registration. The FCA's supervision under that regime concerns anti-money laundering and counter-terrorist financing. Registration alone does not establish a firm's separate FSMA permissions or regulatory approval of its products. Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, S.I. 2017/692, regulations 14A, 54 and 56; FCA, Cryptoassets: AML / CTF regime.
UK applications and future commencement
The FCA opened the new cryptoasset application period on 30 September 2026. The Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 set full commencement for 25 October 2027. Specified provisions already permit preparatory regulatory work and the submission and determination of applications. The opening of that process does not bring every substantive requirement into operation immediately. S.I. 2026/102, regulation 1(2)–(3); FCA, Relevant application period direction, 20 February 2026, section 2.
Existing money-laundering registrations do not convert automatically into FSMA authorisations. The FCA states that firms already authorised for other activities will need the appropriate variation of permission. A claim that a firm has applied must therefore be distinguished from a decision granting the relevant permission. Any advance grant also needs checking for its scope and effective date. FCA, Cryptoassets: How the gateway will operate, introductory provisions; S.I. 2026/102, regulation 1(3)(b)–(c).
UK promotions and overseas providers
The territory test for money-laundering registration differs from the test governing financial promotions. The FCA's registration guidance addresses business carried on in the UK. Section 21 can apply to a communication originating overseas where it is capable of having an effect in the UK. Absence from the cryptoasset register therefore cannot, without the territorial and activity analysis, establish that every overseas provider acts unlawfully. FCA, Cryptoassets: AML / CTF regime; Financial Services and Markets Act 2000, section 21(3).
An unauthorised firm's promotion can use the route requiring approval by an appropriately permitted authorised person. That approval concerns the communication and does not authorise the promoter's underlying business. The approver's identity and permission must therefore be distinguished from the operator's own status, subject to the statutory exemptions. Financial Services and Markets Act 2000, sections 21(2)(b), 21(2A) and 55NA(1), (11).
Cloned identities and contact details
A valid register record does not authenticate the person presenting it. The FCA documents scams using genuine firms' names, addresses and reference numbers alongside altered contact details. A website can also imitate the genuine business while redirecting communications to the fraudster. FCA, Clone firms and individuals, How clone firms work.
The reviewer should obtain contact details independently from the official record and compare the website address precisely. A claim that the regulator's details are outdated should be checked with the regulator. Until the discrepancy is resolved, a genuine firm's authorisation cannot establish that the proposed counterparty is that firm. FCA, Clone firms and individuals, Avoid clone firms.
Protection against losses
Authorised status does not eliminate crypto-asset investment risk. The European Supervisory Authorities warn that prices can fall sharply and that MiCA protection does not include compensation schemes comparable to those available for traditional financial products. Their warning also directs consumers to check which services a provider is authorised to offer. EBA, EIOPA and ESMA, Warning on crypto-assets, 6 October 2025, pp. 1–2.
UK money-laundering registration does not automatically establish Financial Ombudsman Service or Financial Services Compensation Scheme coverage. Where the relevant activity lacks either protection, regulation 60A requires the cryptoasset business to inform the customer before the relationship or transaction begins. The actual activity and applicable scheme conditions determine coverage. S.I. 2017/692, regulation 60A(1)–(3).
Evidence and unresolved discrepancies
A useful verification record preserves the check date, official source, entity identifier and matching contractual provider. It should also record the service, relevant country, operative dates and restrictions. This is a practical evidence-management recommendation: the record should support the precise status conclusion reached, without extending it to other products or group companies. MiCA, Articles 59(4), 65 and 109(5)–(7); FCA, Financial Services Register.
A material discrepancy warrants clarification before funds or assets are committed. Suspected MiCA infringements can be submitted to the competent authority through its complaints procedure. Suspected UK clone activity can be reported to the FCA. Regulatory reporting should be kept separate from any claim seeking repayment or compensation. MiCA, Article 108(1)–(2); FCA, Clone firms and individuals, Report a clone firm.
