From the journal

MiCAR Grandfathering Period Expired on 1 July 2026, All EU CASPs Now Require Authorisation

The MiCAR grandfathering period expired on 1 July 2026, ending the transitional window that allowed crypto-asset service providers operating under national laws before 30 December 2024 to continue without a MiCA licence. Any CASP without authorisation must now cease providing services to EU clients or face breach of EU law.

2 min read

The transitional period under Article 143(3) of Regulation (EU) 2023/1114 (MiCAR) expired on 1 July 2026. This grandfathering clause permitted crypto-asset service providers operating under pre-existing national authorisations to continue providing services within their home member states from 30 December 2024 until the earlier of the date they received or were refused a MiCA authorisation, or 1 July 2026. With no further extension available, all national transitional permissions ceased as of that date.

The basis for the grandfathering regime was Article 143(3) of MiCAR, which granted member states the discretion to allow entities already licensed under domestic frameworks to continue operations during the transitional window. ESMA issued a public statement in June 2026 calling on all unauthorised CASPs to wind down EU-facing services ahead of the deadline and reminding national competent authorities of their enforcement obligations.

Crypto-asset service providers, including exchanges, custodians, portfolio managers, and transfer service operators, that have not received a MiCA authorisation from a national competent authority must now cease accepting EU clients or executing transactions for existing EU clients. Providers that continue operating without authorisation breach Article 59 of MiCAR and may be subject to supervisory action and administrative fines under Article 111.

Member states granted varying grandfathering window lengths under Article 143(3), ranging from 12 to 18 months from 30 December 2024. Belgium and Bulgaria opted for the full 18-month period, meaning those national windows ran until 30 June 2026. Entities that applied for authorisation before the expiry date and remain pending may qualify for continued operation under applicable member state law; applicants should verify the applicable national transitional rules.

Licentium advises crypto-asset service providers on MiCA authorisation requirements across EU member states, including identifying the appropriate national competent authority, preparing authorisation applications, and assessing ongoing compliance obligations once authorised. Work we undertake includes crypto regulatory compliance, MiCA authorisation advisory, CASP licensing, virtual asset service provider licensing, and ESMA regulatory guidance.

Source: ESMA, Public Statement on the End of MiCA Transitional Periods, June 2026

Crypto Regulatory

More from the journal

See all
Illia Prokopiev

Hawala and Underground Banking in FATF’s 2026 Report

The Financial Action Task Force (FATF) published a September 2026 report on professional money laundering through underground banking, hawala and other similar service providers (HOSSPs). The questions are what its findings establish, how they relate to FATF standards, and what responses they support. No domestic jurisdiction, transaction or enforcement proceeding has been specified. The analysis addresses international standards and attributed country examples; it does not determine liability or operational duties under an unidentified national law.

China's Supreme People's Court Issues AI Dispute Adjudication Opinions, 7 September 2026

The Supreme People's Court of China issued the Opinions on Lawfully Adjudicating Disputes Involving Artificial Intelligence, Fafa [2026] No. 10, on 7 September 2026. The document runs to 24 articles across five parts and directs courts nationwide on infringement liability, intellectual property, procedural rules and criminal matters arising from the use of AI. It is the first national judicial guidance of its kind in China.

California CCPA Automated Decisionmaking Rules Bind Businesses from 1 January 2027

The California Privacy Protection Agency regulations on automated decisionmaking technology were approved by the Office of Administrative Law on 22 September 2025 and took effect on 1 January 2026. A business that uses automated decisionmaking technology to make significant decisions about consumers must comply from 1 January 2027. The same rulemaking sets staged deadlines for cybersecurity audits and for risk assessment reporting to the Agency.