MiCA in 2026: The License Was the Easy Part
Three months after Europe's crypto transition deadline, MiCA has shifted from issuing licenses to enforcing them. Here is what supervision, DORA, and a looming review mean for crypto.
Europe spent three years arguing about how to regulate crypto, and then, on 1 July 2026, it stopped arguing. That was the day the last transitional window under the Markets in Crypto-Assets Regulation closed: the day every firm serving European users was supposed to hold a license or be gone. Most coverage that week treated the date as a finish line. It was not. Under MiCA, a license is a starting gun, not a trophy.
Three months on, the story has moved from who got authorized to what authorization costs to keep. In July, the European Securities and Markets Authority (ESMA) opened its first coordinated supervisory action, aimed squarely at how licensed custodians protect the keys they hold. A second rulebook, the Digital Operational Resilience Act, now sits underneath MiCA and dictates how firms manage their own technology risk. Fresh competence rules for client-facing staff took effect in late July. And in Brussels, a consultation that could rewrite large parts of MiCA closes on 30 September.
Bitcoin traded around $76,700 as this went to press, according to CoinGecko, but the numbers that matter most for European crypto this autumn are regulatory, not market. A few hundred firms now hold a MiCA license; a far larger number that once served European users do not. This is the part of the story nobody put on a launch slide: the supervision era, when a rulebook stops being a promise and starts being a daily obligation. What follows is a map of it, from the register as it stands today to the review that could reshape it by 2027.
MiCA in One Paragraph: What It Covers and What It Skips
MiCA (formally Regulation (EU) 2023/1114) is the European Union’s single rulebook for crypto-assets that existing financial law does not already capture. It does three big things: it sets rules for issuers of stablecoins, it licenses and supervises the intermediaries that hold and trade crypto for the public (crypto-asset service providers, or CASPs), and it layers disclosure and market-integrity duties on top. It sorts tokens into three buckets: asset-referenced tokens backed by a basket, e-money tokens pegged to one currency, and a catch-all category of other crypto-assets such as utility tokens. It applies directly in all 27 EU member states and, through the European Economic Area, in Norway, Iceland, and Liechtenstein, so one authorization is valid across roughly 30 countries. That single passport, earned once at home and valid everywhere, is the feature the whole framework is built around.
The supervisory division of labor matters too. ESMA and the European Banking Authority write the technical standards and coordinate, while day-to-day licensing and enforcement fall to a national competent authority in each country, such as BaFin in Germany or the AMF in France. What MiCA leaves out matters just as much as what it captures. Crypto derivatives (futures, perpetuals, and contracts for difference) are financial instruments under MiFID II, not MiCA; ESMA confirmed in early 2026 that retail crypto perpetuals are treated as CFDs, with leverage capped at 2:1. Genuinely decentralized finance, non-custodial staking, lending and borrowing, most non-fungible tokens, and self-custody all sit outside the perimeter, at least today. In other words, MiCA regulates the doors into crypto (the exchanges, brokers, and custodians) and the stablecoins that move through them, but it does not regulate the underlying protocols themselves. That boundary is precisely what the autumn review is prodding.
The Timeline That Ended on July 1
MiCA did not switch on all at once. It entered into force in June 2023, then applied in stages: the stablecoin titles first, the CASP and market-abuse titles next, and a long transitional period for firms already operating under national regimes. That grandfathering was the release valve that kept exchanges legal while they queued for a license. Member states could shorten the window, and several did; Germany closed its grandfathering on 31 December 2025 and Finland on 30 June 2025, while most used the full run to 1 July 2026. The staggered design meant the stablecoin rules had already bitten a year before the last exchanges were forced to choose between a license and the exit.
| Date | What took effect |
|---|---|
| June 2023 | MiCA enters into force |
| 30 June 2024 | Stablecoin rules apply (asset-referenced and e-money tokens) |
| 30 December 2024 | CASP authorization, market-abuse, and disclosure rules apply; the Travel Rule begins |
| 17 January 2025 | DORA operational-resilience rules apply to CASPs |
| 1 July 2026 | Transitional grandfathering ends across the EEA; a MiCA license becomes mandatory |
| 28 July 2026 | ESMA staff knowledge-and-competence guidelines apply |
| 30 September 2026 | Deadline for the Commission’s MiCA review consultation |
| 30 June 2027 | Commission report due; a possible MiCA 2.0 proposal |
The last two rows are the tell: MiCA is being reviewed before most of its supervisory machinery has finished a single cycle. A framework that took years to draft and phase in is already being reopened, which says something about how fast the market it governs moves and how nervous Brussels is about falling behind.
Three Months In: The State of the Register
The visible scoreboard is ESMA’s public register of authorized CASPs. As of 17 September 2026, industry tracker casptracker.eu counted 349 authorized providers across 30 EEA markets and 26 national regulators. The distribution is lopsided. Germany leads with 91 licenses, far ahead of France (35), the Netherlands (29), Cyprus (25), Malta (22), Spain (15), Luxembourg (13), Ireland (12), and Italy (9). Germany’s lead reflects a bank-heavy roster: an already-regulated bank or investment firm can enter the market through a simplified notification route rather than a full authorization from scratch, so custody banks, brokers, and neo-banks moved fastest while crypto-native startups queued behind them.
Once authorized in one country, a firm can passport its services across the entire EEA without a fresh license in each market, which is why the national counts understate reach: a German or French license is effectively a pan-European one. The number that did not make it into the register is the more revealing figure. Industry trackers estimated that roughly four in five firms that once served EU users did not hold a MiCA license when the window shut, per Finance Magnates. Many were small operators that never intended to apply; others gambled that enforcement would be slow. ESMA’s message to those firms was blunt. In a public statement issued as the transition ended, it warned that clients of unauthorized providers “do not benefit from MiCA safeguards, including protections for client assets,” and told non-compliant firms to wind down in an orderly way while keeping anti-money-laundering controls running (ESMA).
What a MiCA License Actually Buys a User
For an ordinary customer, the register is not a bureaucratic detail; it is the line between having recourse and having none. A licensed CASP must keep client crypto and client cash segregated from its own balance sheet, so that if the firm fails, customer assets can be identified and returned rather than swept into the insolvency. Crucially, this is not deposit insurance: there is no compensation fund that makes a crypto customer whole the way one would for a failed bank account. The protection is segregation and orderly return, which is why the operational-resilience rules discussed below matter so much.
A license also brings duties that touch users directly: a mandatory crypto-asset white paper with risk disclosures for tokens offered to the public, fair-and-clear marketing rules, a complaints-handling process, conflict-of-interest controls, and a named national regulator a customer can escalate to. None of that guarantees a token will hold its value or that a trade will be profitable; MiCA is about conduct and custody, not investment outcomes. But it does mean that, for the first time, a European user can check a single official register, confirm a platform is supervised, and know who to call when something goes wrong. The practical advice that follows from the whole framework is almost boring: before funding an account, look the provider up on the ESMA or national register.
From Licensing to Supervision: ESMA’s First Coordinated Action
The clearest sign that MiCA has entered a new phase came on 8 July 2026, when ESMA launched its first Common Supervisory Action under the regulation. A Common Supervisory Action is a coordinated exercise in which national regulators examine the same theme using a shared methodology, so supervision looks similar in Frankfurt, Paris, and Valletta rather than diverging by jurisdiction. ESMA aimed its first one at the most sensitive corner of the business: the digital operational resilience of CASPs that provide custody (ESMA).
Custody is where the value sits, so it is where the risk sits. National authorities will assess a risk-based sample of licensed custodians, meaning they target the firms and practices most likely to fail rather than checking everyone equally, against the failure modes specific to distributed-ledger technology: governance arrangements, key generation and storage, transaction controls, incident detection and response, smart-contract risk, and reliance on third-party providers. The exercise runs from the second half of 2026 into the first half of 2027, with a consolidated report reaching ESMA’s Board of Supervisors later in 2027. Because MiCA-licensed firms are also treated as financial entities under DORA, the review reads across that regime’s incident-reporting and testing obligations, effectively pressure-testing two rulebooks at once. This is the operational-resilience question at the center of every serious custody debate, the same one HOGE Wire has traced through who actually audits the non-EVM code that a growing share of custodians now depend on.
ESMA Chair Verena Ross has summed up the stakes in a single line that now reads like the motto of the supervision era: the rulebook “will only protect investors if it is effectively applied” (ESMA). Getting a license proved that a firm could describe good controls on paper. The Common Supervisory Action is about whether those controls actually hold when tested, and it sets the template for the thematic reviews that will follow it year after year.
The Rulebook Behind the Rulebook: DORA, the Travel Rule, and AMLA
MiCA is not a standalone. A licensed CASP now lives inside a stack of overlapping European regimes, and the license is only the entry ticket. The most demanding neighbor is DORA, the Digital Operational Resilience Act (Regulation (EU) 2022/2554), which has applied to CASPs since 17 January 2025 and treats them as “financial entities.” DORA requires formal information-and-communication-technology risk management, three-stage incident reporting, resilience testing, and a register of third-party technology providers, which is exactly why ESMA’s first custody action reads across it. A firm can hold a spotless MiCA license and still fall short on DORA the day a cloud provider goes down.
Alongside DORA sit the Travel Rule and the EU’s new anti-money-laundering architecture. Add MiFID II for anything that crosses into derivatives, and the compliance surface a European exchange must cover looks like this:
| Regime | What it governs | Status |
|---|---|---|
| MiCA (Reg. 2023/1114) | CASP licensing, stablecoin issuance, market abuse, disclosure | Fully applies since 1 July 2026 |
| DORA (Reg. 2022/2554) | ICT risk, incident reporting, resilience testing, third-party oversight | Applies to CASPs since 17 January 2025 |
| Travel Rule (Reg. 2023/1113) | Sender and beneficiary data on transfers; verification for large self-hosted transfers | In force since 30 December 2024 |
| AMLR / AMLA (Reg. 2024/1624) | Single AML rulebook; direct EU-level supervision of high-risk firms | Rulebook applies 10 July 2027; AMLA operational since July 2025 |
| MiFID II | Crypto derivatives (futures, perpetuals, CFDs) | Applies where a product is a financial instrument |
The Travel Rule (Regulation (EU) 2023/1113) has bound CASPs since 30 December 2024, with no minimum threshold for transfers between two providers and an ownership-verification duty for self-hosted wallet transfers above EUR1,000. The Anti-Money Laundering Authority (AMLA), headquartered in Frankfurt and operational since July 2025 under Chair Bruna Szego, will begin directly supervising a shortlist of around 40 high-risk firms from 2028, and it has flagged crypto as an early priority. The single AML rulebook it enforces applies across the EU from 10 July 2027 and includes a EUR10,000 cap on cash payments and tighter limits on anonymous instruments. Read together, these regimes explain why MiCA compliance is a program, not a project: the license is one obligation among five that all move on their own clocks.
Competence, Whistleblowing, and the Cost of Staying Licensed
Supervision reaches down to the help desk. From 28 July 2026, ESMA’s guidelines on staff knowledge and competence apply to anyone at a CASP who gives clients information or advice about crypto-assets, filling in the detail behind MiCA Articles 68(5) and 81(7) (ESMA). Staff who merely provide information face a lighter bar than those who advise, but both must meet defined standards, and ESMA suggests a floor of ten hours of continuing training a year for information providers and fifteen for advisers. A firm’s management body has to review the policies at least annually and fix any gaps it finds.
None of this is glamorous, and all of it costs money. MiCA also requires internal whistleblowing channels, segregation of client assets from the firm’s own, structured complaints handling, minimum own-funds tied to the services offered, and continuous reporting to the national regulator. Segregation is the quiet heart of it: because crypto is not covered by deposit-insurance schemes, the protection for a customer if a CASP fails is that their assets were kept separate and can be handed back, not that a fund makes them whole.
Add up the legal work, the capital, the audits, and the staffing, and a MiCA license costs a serious platform hundreds of thousands of euros to obtain and a recurring sum to maintain. That price is the real reason the register holds hundreds of firms rather than thousands, and it points to the next phase: consolidation. Smaller operators are selling to licensed rivals or exiting Europe altogether, while banks, brokers, and a handful of well-capitalized exchanges absorb the market. A rulebook written to protect consumers is, as a side effect, thinning the field of who serves them.
Reverse Solicitation and the Binance Question
The hardest enforcement question is not the firm that applied and failed; it is the firm that decided not to apply at all. The largest example is Binance, which withdrew its Greek MiCA application in June 2026 and told users in several EU countries that it would stop offering regulated services from 1 July. The exchange said client assets remained safe and kept withdrawals open, but the episode showed how a global venue can find itself outside a comprehensive perimeter it cannot, or will not, fit. When the biggest player in the market steps back, the rulebook is no longer theoretical.
The pressure point is “reverse solicitation,” the narrow exemption in MiCA Article 61 that lets a non-EU firm serve a European client only when the client approaches it entirely on their own initiative. ESMA’s February 2025 guidelines read that door as almost shut: nearly any marketing counts as solicitation, disclaimers cannot override the facts of a relationship, and a firm cannot use one unsolicited trade to pitch further products. Regulators have also questioned whether routing EU users to an offshore entity, in Binance’s case an Abu Dhabi arm, genuinely satisfies MiCA. The practical result is a reshuffle, with licensed venues such as Coinbase, Kraken, and OKX competing for the users that unlicensed rivals can no longer legally onboard, and national authorities issuing warning after warning about apps that keep serving Europeans without a license.
Stablecoins: The Part of MiCA That Already Bit
If supervision is the story of 2026, stablecoins are the part of MiCA whose effects were visible first. The regulation splits them into two buckets: e-money tokens (EMTs), pegged to a single currency such as the US dollar or the euro, and asset-referenced tokens (ARTs), backed by a basket. Issuers must be a bank or an authorized e-money institution, hold reserves that can be redeemed at par on demand, and pay no interest to holders. A non-euro EMT also faces usage caps (roughly 1 million transactions or EUR200 million per day as a means of exchange) designed to keep dollar tokens from dominating euro-area payments, and the largest tokens deemed significant fall under direct EBA oversight.
The clearest casualty was Tether’s USDT, the largest stablecoin, whose issuer chose not to seek authorization and which has been off EEA regulated venues since the transition. Circle went the other way: through a French e-money-institution license granted by the ACPR, it became the first global issuer to comply with MiCA, issuing both USDC and the euro-denominated EURC inside the perimeter (Circle). Euro-denominated stablecoins are growing but remain a rounding error next to the dollar giants, in a market still overwhelmingly dollar-denominated and worth several hundred billion dollars. That split, the biggest coin out and the compliant challenger in, is MiCA’s most concrete achievement to date, and its sharpest trade-off: less choice, in exchange for issuers a European authority can actually hold to account.
What MiCA Still Does Not Touch
For all its breadth, MiCA regulates intermediaries and issuers, not protocols. That leaves large and fast-growing activities outside the perimeter. Genuinely decentralized exchanges, where the automated market maker itself sets the price, are not licensed as CASPs. Staking is treated inconsistently: offered as a custodial service it can be caught, but run non-custodially from a user’s own wallet it is unregulated. Lending and borrowing have no bespoke MiCA regime, most NFTs are excluded unless they behave like fungible financial instruments, and newer categories such as prediction markets and tokenized deposits sit in a grey zone. Cross-chain bridges, whose failures have driven some of the sector’s largest losses, fall between the cracks, a gap HOGE Wire examined in its look at why the safest bridge is often no bridge.
The market-abuse rules show the seam clearly. MiCA’s Title VI attaches to any asset admitted to trading on a CASP, so manipulating a listed token on a decentralized venue can be caught, but a token that never touches a regulated platform is outside the net. The same is true of the on-chain price manipulation behind several exploits, including the oracle attacks that prompted rollback debates. Supervisors are left watching a regulated core surrounded by an unregulated fringe that users can reach in two clicks. Whether any of this should change, and how to define decentralization precisely enough to write a rule around it, is the question Brussels is now asking out loud.
MiCA 2.0: The Review That Could Rewrite the Rulebook
Barely a year into full application, the European Commission has reopened the code. Its targeted review of MiCA, launched on 20 May 2026, closes on 30 September, and it is unusually broad: 86 questions across four blocks covering scope and definitions, stablecoins, CASP rules, and the activities currently beyond MiCA’s reach (FinanceFeeds). The deadline was itself pushed from August into late September to give the industry more time to respond. Responses feed reports the Commission owes under MiCA Articles 140 and 142 by 30 June 2027, which may carry a legislative proposal, the change the market has already nicknamed MiCA 2.0.
On the table are the very gaps described above. The Commission is weighing how to define whether a protocol is genuinely decentralized (looking at admin keys, concentrated governance, custody, identifiable operators, and marketing), whether to add rules for staking, lending, and borrowing, and even whether regulated platforms should bear liability when they connect clients to DeFi. It is also asking whether to relax the stablecoin regime that pushed USDT out. The whole exercise sits inside a wider push for simplification and competitiveness, and MiCA’s architects want it used carefully. Ondřej Kovařík, a Czech member of the European Parliament who was one of the regulation’s lead negotiators, argues the rules must be proportionate: regulators, he says, “should not treat in the same way the global trade crypto exchanges coming from the US and listed on the US stock exchange market with the same rules that we treat a small startup company running a crypto business” (BeInCrypto).
Large platforms are wary of reopening too much. Katie Harries, who leads European policy for Coinbase, has said “MiCA has set an early global standard for clear and harmonized rules” and pushed for “targeted improvements… not a reopening of first principles” (The Block). The tension between those two positions, fix the burdens versus do not unpick the foundations, will define whatever MiCA 2.0 becomes, and the industry has a full year of lobbying before the Commission’s report lands.
One Rulebook, Twenty-Seven Supervisors
MiCA is a single rulebook, but it is enforced by more than two dozen national authorities, and they do not all supervise the same way. That gap became concrete in July 2025, when ESMA published a peer review of Malta’s authorization of CASPs. The finding was pointed: the Maltese regulator had good resources and engagement, but “some material issues were not fully resolved” when it granted authorizations, and “some risk areas were not adequately assessed” (ESMA). For critics, it confirmed the fear that firms would shop for the most lenient jurisdiction and passport everywhere from there, turning the single market into a race to the bottom.
The proposed fix is to move some supervision up to the EU level. France, Austria, and Italy pushed a joint paper in September 2025 for direct ESMA oversight of the largest CASPs, and the Commission went further in December 2025 with a package that would hand ESMA direct supervision of CASPs more broadly. The European Central Bank has backed centralization, while several smaller member states, protective of a lucrative national industry and the jobs and fees it brings, resist ceding control. Nothing here lands quickly: any real shift is unlikely to apply before 2028 or 2029. In the meantime, the Common Supervisory Action is ESMA’s tool for pulling 27 practices toward one standard without waiting for new law, a softer form of convergence than a formal transfer of power.
MiCA vs the SEC: A Comprehensive Code Against Case-by-Case
For a US reader, the sharpest way to understand MiCA is by contrast. Europe wrote one long statute and is now supervising against it. The United States has mostly regulated crypto through enforcement and, more recently, through narrower laws for specific problems. In March 2026, the SEC and the CFTC issued a joint interpretation sorting digital assets into categories and confirming that payment stablecoins are not securities; SEC Chair Paul Atkins called clearer treatment of crypto assets “a beginning, not an end” (SEC). The GENIUS Act gave stablecoins a federal framework in 2025, but the broader market-structure bill, the CLARITY Act, stalled in the Senate in mid-September 2026, leaving the SEC and CFTC to keep drawing lines case by case, much like the commodity-or-security gate that still governs US crypto ETFs.
| Dimension | European Union (MiCA) | United States |
|---|---|---|
| Core approach | One comprehensive statute, applied across 30 countries | Enforcement plus targeted laws; no single crypto statute |
| Primary regulators | ESMA and EBA, with national competent authorities | SEC and CFTC, split by asset type |
| Stablecoins | MiCA EMTs and ARTs; bank or e-money issuer, no interest | GENIUS Act framework (2025) |
| Market structure | Settled: CASP licensing and passporting | Unsettled: CLARITY Act stalled in 2026 |
| Derivatives | Outside MiCA, under MiFID II | CFTC-led |
Neither model is obviously winning. Europe has clarity and a live register but is already reworking its own rules; the US has deeper markets and looser constraints but persistent uncertainty about who decides what. The one thing both now agree on is that payment stablecoins are not securities, a small patch of common ground in an otherwise divergent map, and a reminder that the two blocs are watching each other closely as they write.
What to Watch Through 2027
The next twelve months are dense with milestones. The review consultation closes on 30 September 2026. ESMA’s custody Common Supervisory Action runs into 2027, with its consolidated findings due later that year, the first real read on whether licensed firms can actually withstand a technology failure. The single AML rulebook applies from 10 July 2027, and AMLA’s direct supervision of high-risk firms begins the year after. The Commission’s MiCA report, and any MiCA 2.0 proposal, is due by 30 June 2027. Verena Ross, the chair who has led ESMA through the whole rollout, steps down on 31 October 2026, handing the supervision era to a successor who inherits both the enforcement machinery and the fight over centralizing it.
Further out sits the digital euro, moving through EU legislative negotiations with a launch targeted around 2029, and the slow argument over whether Brussels or national capitals should hold the supervisory pen. For users and firms alike, the takeaway is simple: MiCA is no longer a thing that is coming, it is a thing that is running. The headline was written on 1 July: the rulebook is live. The real work, deciding whether a comprehensive rulebook can be comprehensively enforced, is only starting.
Frequently Asked Questions
Is MiCA fully in force in 2026?
Yes. MiCA’s stablecoin rules applied from June 2024 and its CASP rules from December 2024, and the last transitional grandfathering period ended on 1 July 2026. Since then, any firm serving EU users must hold a MiCA license, and the focus has shifted to ongoing supervision under MiCA, DORA, and the EU’s anti-money-laundering rules.
Does MiCA regulate DeFi and self-custody?
Not directly. MiCA regulates issuers and intermediaries, so genuinely decentralized protocols, non-custodial staking, lending, most NFTs, and self-custody wallets fall outside its scope. Whether to bring some of these activities inside the perimeter is one of the central questions in the Commission’s 2026 review.
Why did USDT and Binance leave the EU under MiCA?
Both chose not to fit the perimeter. Tether did not seek authorization for USDT, so the token has been removed from EEA regulated venues, while Circle’s USDC complied and stayed. Binance withdrew its EU license application and wound down regulated EU services from 1 July 2026, leaving licensed rivals such as Coinbase, Kraken, and OKX to absorb users.
What is the MiCA review, or MiCA 2.0?
It is a European Commission consultation, open until 30 September 2026, that asks 86 questions about how MiCA is working and about activities it does not yet cover, such as DeFi, staking, and lending. It feeds a Commission report due by 30 June 2027 that could include a legislative proposal, informally called MiCA 2.0.
How is MiCA different from US crypto regulation?
MiCA is a single comprehensive statute applied across roughly 30 countries and supervised by ESMA, the EBA, and national regulators. The United States relies on enforcement plus targeted laws such as the GENIUS Act for stablecoins, with the broader CLARITY Act stalled in 2026, so the SEC and CFTC still classify assets case by case.
Anneke de Vries is HOGE Wire’s regulation lead, covering European and US crypto policy.