From the journal

Spain's MiCAR Grandfathering Period Expired 1 July 2026 for Crypto-Asset Service Providers

The transitional period under Article 143(3) of Regulation (EU) 2023/1114 (MiCAR) expired on 1 July 2026 in Spain, ending the right of previously registered crypto-asset service providers to continue operating without a full MiCA authorisation. Spain selected a 12-month transitional period, the shortest permissible under MiCAR. Providers without authorisation must now cease offering crypto-asset services or face enforcement action by the CNMV.

2 min read

Article 143(3) of Regulation (EU) 2023/1114 (MiCAR) permits member states to apply a transitional period of up to 18 months for crypto-asset service providers (CASPs) registered under prior national law. Spain selected the 12-month option, setting 1 July 2026 as the expiry date. ESMA confirmed in April 2026 that member state transitional periods would not be extended.

Article 143(3) of MiCAR provides that member states 'may decide to apply a transitional period of up to 18 months' for entities authorised or registered under national law before 30 December 2024. In Spain, entities on the Banco de España's virtual asset service provider register as of 30 December 2024 could rely on grandfathering until 1 July 2026. That right terminated earlier if a MiCA authorisation application was refused before that date. The CNMV is the primary MiCA competent authority for most CASP categories in Spain.

CASPs operating in Spain, including cryptocurrency exchanges, custody wallet providers, and portfolio managers, needed a MiCA authorisation from the CNMV by 1 July 2026 to continue serving clients. Operators without authorisation must stop providing crypto-asset services. Clients of unauthorised providers should expect account restrictions or mandatory migration to authorised platforms.

CASPs that submitted a timely MiCA authorisation application before 1 July 2026 may be able to continue operating pending a CNMV determination, subject to Spanish national law and CNMV discretion. EU-licensed CASPs passporting services into Spain from another member state are not affected by Spain's transitional period. Branches of third-country firms face separate requirements under Article 60 of MiCAR.

Licentium advises crypto-asset service providers on MiCA authorisation strategy, including application preparation for the CNMV and Banco de España. Work we undertake includes MiCA licensing triage, CASP authorisation application drafting, AML/CFT programme alignment, white paper review, and cross-border passport notification.

Source: ESMA, Statement on the End of Transitional Periods under MiCA, April 2026

Crypto Regulatory

More from the journal

See all

Hong Kong SFC and FSTB Conclude Consultation on Virtual Asset Advisory and Management Regimes, 26 May 2026

On 26 May 2026, Hong Kong's Securities and Futures Commission and Financial Services and the Treasury Bureau published consultation conclusions on proposed licensing regimes for virtual asset advisory and management service providers. The regimes apply the same business, same risks, same rules principle and align SFC licensing requirements with those for securities advisory and management businesses. A bill implementing the regimes is planned for introduction into the Legislative Council in 2026.

OCC Grants Circle Final Charter for First National Digital Currency Bank N.A., 9 July 2026

The Office of the Comptroller of the Currency granted final approval on 9 July 2026 for Circle Internet Group to establish First National Digital Currency Bank, N.A., operating as Circle National Trust. The bank opened 24 July 2026 under direct OCC oversight and will manage USDC reserves on a directed basis, act as collateral trustee for USDC holders, and provide digital asset custody services to Circle affiliates.

Manitoba Enacts Public Sector AI and Cybersecurity Governance Act June 2026

On 1 June 2026, Bill 51, The Public Sector Artificial Intelligence and Cybersecurity Governance Act (S.M. 2026, c. 43), received Royal Assent in Manitoba, Canada. The Act mandates transparency, accountability structures, and cybersecurity incident reporting for public sector entities using AI systems. Substantive obligations take effect only through regulations yet to be made.