h hoge.gg
Subscribe
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
● Regulation & Policy

MiCA in 2026: One Passport, Many Supervisors

MiCA's transitional period closed on 1 July 2026, leaving one rulebook, a single passport across 30 markets and 349 licensed firms. The fight now is over who actually supervises them.

For the first time since crypto existed in Europe, the market has both a single rulebook and a closed door. The Markets in Crypto-Assets Regulation, or MiCA, formally Regulation (EU) 2023/1114, finished its phased rollout on 1 July 2026, when the last transitional windows shut. A firm that wants to serve European retail users now needs one thing it never needed before: a license. As of 17 September 2026, 349 crypto-asset service providers held one, according to the industry-run CASP tracker. Bitcoin trades around $81,000, the market has largely digested the Federal Reserve’s September rate move, and Brussels is eleven days from closing the biggest review of the rulebook since it was written.

The pitch for MiCA was always elegant. Get authorised once, in one member state, and passport your services across roughly 30 markets without asking two dozen other regulators for permission. One license, a continent-sized market. That promise is now being tested in the least glamorous way imaginable, through the plumbing of who signs off on a license and who checks the work afterward.

This is a guide to how MiCA implementation actually functions in late 2026: what the passport does, where the 349 firms sit, why a single rulebook has produced more than two dozen different front doors, and why the fight over that inconsistency, rather than the rules themselves, is the story to watch as the European Commission’s review closes on 30 September.

What MiCA Regulates, and What It Leaves Alone

MiCA governs three things: crypto-assets offered to the public, the service providers that stand between users and those assets, and the issuers of certain tokens. It does not govern the technology. A blockchain is not licensed, a validator is not authorised, and a smart contract answers to no supervisor directly. MiCA regulates people and companies, the service providers and issuers, not the protocol. That distinction draws the line between what falls inside the perimeter and what sits outside it.

The regulation sorts tokens into three buckets. Asset-referenced tokens, covered by Title III, reference a basket of currencies, commodities or other crypto-assets. E-money tokens, covered by Title IV, reference a single official currency and are the category that captures fiat-backed stablecoins such as USDC and EURC. Everything else, the other crypto-assets of Title II, from Bitcoin to a freshly minted utility token, falls under lighter disclosure rules built around a mandatory white paper that issuers must publish and notify to a regulator.

Several large categories are deliberately outside MiCA. Crypto derivatives, meaning futures, options and the perpetual futures that dominate offshore volume, are financial instruments under MiFID II, supervised by national markets regulators rather than by the MiCA regime. Fully decentralised finance, non-custodial staking, most non-fungible tokens, and lending and borrowing protocols are largely untouched. Those gaps are not oversights so much as deferrals, and they are exactly what the September review is probing.

A Four-Year On-Ramp

MiCA did not switch on overnight. It entered into force on 29 June 2023 and then phased in by title. The stablecoin rules under Titles III and IV applied from 30 June 2024. The rules for service providers and market abuse, under Titles II, V, VI and VII, applied from 30 December 2024. Then came the part that varied by country: a transitional, or grandfathering, period under Article 143 that let firms already operating under national regimes keep going while they applied for full MiCA authorisation.

That transitional period is where the single market frayed before it even opened. The regulation allowed up to 18 months, which set a hard EU-wide backstop of 1 July 2026, but member states were free to shorten it. Germany, Ireland and Spain cut the window to roughly 12 months, ending on 31 December 2025. The Netherlands and Finland went shorter still; Finland’s window closed on 30 June 2025, among the earliest in the bloc. France, Italy, Austria and others ran the full 18 months to 1 July 2026. The upshot was that a firm’s grace period depended entirely on where it happened to be based.

MiCA milestoneDateWhat changed
Regulation enters into force29 June 2023Legal text becomes binding; clocks start
Stablecoin rules apply (Titles III, IV)30 June 2024ART and EMT issuers must be authorised
CASP and market-abuse rules apply30 December 2024Licensing regime and Title VI abuse rules go live
Shortened transitions end31 December 2025Germany, Ireland, Spain close grandfathering
Full transitional period ends1 July 2026EU-wide backstop; unlicensed firms must stop
Review consultation closes30 September 2026Feeds the Commission’s MiCA report
Commission report due30 June 2027Possible legislative proposal (MiCA 2.0)

The Ten Regulated Services

To become a service provider, a firm applies for authorisation to offer one or more of ten defined services under Article 3. A firm is licensed for the specific activities it lists, not for crypto in the abstract, and the license names each one.

  • Custody and administration of crypto-assets on behalf of clients
  • Operation of a trading platform for crypto-assets
  • Exchange of crypto-assets for funds
  • Exchange of crypto-assets for other crypto-assets
  • Execution of orders for crypto-assets on behalf of clients
  • Placing of crypto-assets
  • Reception and transmission of orders on behalf of clients
  • Providing advice on crypto-assets
  • Providing portfolio management on crypto-assets
  • Providing transfer services for crypto-assets

The capital a firm must hold scales with what it does. MiCA sets three classes of minimum own funds: 50,000 euros for the lightest services (advice, order reception, execution, placing, portfolio management and transfers), 125,000 euros once a firm adds custody or exchange, and 150,000 euros for operating a trading platform. The binding number is the higher of the class floor or one quarter of the previous year’s fixed overheads, so a large exchange holds far more than the headline figure suggests.

Authorisation is not a rubber stamp. The home regulator runs a statutory clock: acknowledge the application, check that it is complete, then assess it on the merits, a process the regulation frames in working days but that in practice has taken many firms the better part of a year. Already-regulated institutions, meaning banks, investment firms, e-money institutions and a handful of others, can use a lighter notification route instead of a full authorisation. That single provision explains why so many licensed providers are incumbents rather than crypto natives.

The Single Passport: One License, Thirty Markets

Here is the mechanism that makes MiCA more than 27 national rulebooks stapled together. Once a firm is authorised in its home member state, it can passport its services across the whole European Economic Area. Under Article 65, the provider tells its home regulator which countries it intends to serve; the home regulator passes that notification to the host regulators, along with ESMA and the European Banking Authority, within 10 working days; and the firm can begin operating in those countries from the fifteenth calendar day after the notification. No second license, no separate application in each capital.

Every authorised firm lands in a single public register maintained by ESMA, the European Securities and Markets Authority, so a user, a competitor or a journalist can check whether a given platform is actually licensed and for which services. The register is the closest thing MiCA has to a public source of truth about who sits inside the perimeter, and checking it is the first practical step any European should take before funding an account.

The passport is the entire economic case for MiCA. It turns a fragmented set of national markets into one addressable bloc of more than 440 million people, and it is why a firm will happily spend a year and six figures on authorisation: the license it earns in Dublin, Paris or Frankfurt is a license for the continent. For a resident, it means a platform authorised anywhere in the EEA can serve them under one consistent set of consumer protections. At least, that is the promise. The complication is that the passport exports the home regulator’s judgement along with the license, and not every home regulator judges the same way.

Where the 349 Firms Actually Sit

Authorisations have not spread evenly. Germany is the runaway leader, with 91 authorised providers as of mid-September 2026, according to the CASP tracker, a roster heavy with banks and incumbent financial institutions using the notification route. France follows with 35, the Netherlands 29, Cyprus 25, Malta 22, Spain 15, Luxembourg 13, Ireland 12 and Italy 9. Across the EEA, roughly 349 firms are licensed, split between crypto-native businesses and traditional finance entrants.

Member stateAuthorised CASPs (approx.)
Germany91
France35
Netherlands29
Cyprus25
Malta22
Spain15
Luxembourg13
Ireland12
Italy9
EEA total~349

The distribution is not only about market size. Germany’s lead owes a great deal to its cooperative and savings-bank networks bringing custody and execution to retail customers through licenses they already held. Smaller jurisdictions such as Malta, Cyprus, Ireland and Luxembourg punch well above their economic weight, which in a passport regime raises an obvious question: if a firm can be authorised in the most accommodating member state and then serve the entire bloc, what stops a race to the most lenient front door?

One Rulebook, Many Referees

That question stopped being hypothetical in July 2025, when ESMA published a peer review of how Malta had authorised crypto firms. The finding was carefully two-sided. Malta’s regulator, the MFSA, showed a good level of resources and supervisory engagement, ESMA said, but some material issues were not fully resolved when the MFSA granted the authorisation, and some risk areas were not adequately assessed during the process. ESMA told every national regulator to sharpen how it examines business growth, conflicts of interest, governance and intragroup structures, ICT, and Web3 or decentralised products before it hands out a license.

The peer review crystallised the structural tension inside MiCA. The rules are uniform; the supervision is not. A single regulation is applied across the EU’s 27 member states, and through the EEA agreement by Iceland, Liechtenstein and Norway as well, policed by roughly two dozen national competent authorities with different resources, different risk appetites and different histories with the industry. A passport earned from a lenient authoriser is exactly as valid as one earned from a strict one. The floor is written down; whether it is truly enforced can depend on the address on the application.

This is not a uniquely crypto problem, but crypto makes it acute, because the firms are young, cross-border by default, and often larger than the regulators licensing them. Ondřej Kovařík, the Czech member of the European Parliament who was a lead negotiator on MiCA, argues the framework needs more proportionality, not less. Regulators, he told BeInCrypto, should not treat in the same way the global trade crypto exchanges coming from the US and listed on the US stock exchange market with the same rules that they treat a small startup company running a crypto business. The same uniform rulebook lands very differently on a global bank and on a ten-person team.

Would ESMA Become Europe’s SEC?

The proposed fix is centralisation. In September 2025, the French, Austrian and Italian regulators, the AMF, the FMA and Consob, published a joint position paper calling for ESMA to directly supervise the largest, most cross-border firms rather than leaving them to national authorities. The European Commission went further in December 2025 with its Market Integration and Supervision Package, a set of proposals that would transfer authorisation, monitoring and enforcement for crypto service providers from national regulators to ESMA outright. The European Central Bank, in an opinion published in April 2026, said it fully supports the plan and framed it as an overdue step toward a genuine single market for capital.

The comparison everyone reaches for is the US Securities and Exchange Commission: one federal supervisor for a continental market, rather than fifty state regulators pulling in different directions. ESMA Chair Verena Ross has argued the reform would help build a more integrated and globally competitive European financial system, and has floated a compromise familiar from banking supervision: the biggest, systemically important cross-border firms answer to the central authority, while purely domestic ones stay with national supervisors. Ross has been blunt about the stakes of getting supervision right at all, warning that the MiCA rulebook will only protect investors if it is effectively applied.

Centralisation is far from settled. Ireland, Luxembourg and Malta, the jurisdictions whose financial sectors have grown fastest around crypto licensing, have pushed back hard against handing oversight to Paris, arguing it would hollow out national supervisors and the local industries built around them. Any transfer of power is still under negotiation and unlikely to apply before 2028 at the earliest. But the direction of travel is clear, and it is the single biggest open question in European crypto policy: whether the passport keeps two dozen referees or gets one. Whichever way it lands, the underlying lesson of the past year is one HOGE Wire has made before, that for a crypto firm in Europe the license was the easy part.

Stablecoins, the Part That Bit First

Long before the licensing deadline, MiCA’s stablecoin rules were already reshaping the market. Under Titles III and IV, a fiat-backed stablecoin can only be issued by an authorised bank or e-money institution, must hold reserves that fully back the tokens in issue, must let holders redeem at par on demand, and, notably, cannot pay interest to holders. Reserve composition faces limits too: a meaningful share, rising for tokens deemed significant, has to sit in deposits at EU credit institutions, with the rest in high-quality liquid assets and no exposure to volatile crypto or commodities.

The practical effect split the market in two. Circle became the first global stablecoin issuer to comply, securing an e-money license in France and keeping USDC and its euro token EURC on EU venues. Tether, whose USDT is the largest stablecoin in the world, chose not to seek authorisation, and European exchanges duly delisted USDT for retail users across the bloc. In a market worth roughly $310 billion, where USDT commands close to 60 percent and USDC around a quarter, MiCA effectively pushed the biggest token off regulated European rails and handed the compliant runner-up the field.

There is also a brake designed to protect the euro itself. A non-euro stablecoin used widely as a means of exchange faces a hard cap under Article 23: exceed one million transactions or 200 million euros in daily payment volume, and the issuer must stop issuing. The goal is to stop a dollar token from quietly becoming Europe’s everyday digital cash. It is one of the clearest examples of MiCA doing something no American rule does, treating monetary sovereignty as an explicit regulatory objective rather than an afterthought.

MiCA Is Only One Layer

A licensed firm does not answer to MiCA alone. It sits under a stack of EU rules that arrived alongside it, and treating MiCA as the whole job is a common and expensive mistake. Compliance is a set of overlapping obligations, not a single certificate on the wall.

The Digital Operational Resilience Act, in force since January 2025, sets ICT and cyber-resilience requirements: incident reporting on a strict clock, resilience testing, and oversight of critical third-party technology providers. The Transfer of Funds Regulation, the EU’s crypto Travel Rule, has applied since December 2024 and requires originator and beneficiary information to travel with transfers, with a zero threshold between service providers and identity checks on transfers to and from self-hosted wallets above 1,000 euros. Anti-money-laundering supervision is consolidating under a new EU authority, AMLA, operational in Frankfurt since July 2025, ahead of a single AML rulebook that applies from July 2027. And derivatives sit under MiFID II, not MiCA at all: ESMA confirmed in February 2026 that crypto perpetual futures are contracts for difference, capping retail leverage at 2:1 on regulated venues, a world away from the 100:1 advertised offshore.

RulebookWhat it coversApplies since
MiCA (Reg 2023/1114)Spot crypto-assets, service providers, token issuersPhased; full 1 Jul 2026
DORA (Reg 2022/2554)ICT and operational resilience17 Jan 2025
Travel Rule (Reg 2023/1113)Transfer information, AML data30 Dec 2024
AML rulebook and AMLASingle AML code and EU supervisorAMLA since 1 Jul 2025; rules from 10 Jul 2027
MiFID IICrypto derivatives (perps as CFDs)Existing; ESMA statement 24 Feb 2026

For a user, the takeaway is that a MiCA license signals a firm has cleared a broad compliance bar, not a narrow one. For a firm, it means the paperwork never really ends. If a resident instead uses high-leverage offshore perpetual futures venues, they step outside both the MiCA and the CFD investor-protection perimeters at once.

From Licensing to Enforcement

With the transitional period closed, 2026 became the year MiCA grew teeth. In June, ESMA and national regulators reminded firms operating without authorisation that they must wind down in an orderly way, and warned that clients of unlicensed providers do not enjoy MiCA’s protections for client assets. The marquee case was Binance, which withdrew its MiCA application in Greece and told users in several EU countries it would stop offering services from 1 July, even as it kept some European clients through reverse solicitation and a non-EU entity.

Reverse solicitation, the idea that a firm outside the EU can serve a European client who approached it entirely on their own initiative, is the obvious loophole, and ESMA has moved to narrow it. Its guidance treats almost any marketing as solicitation, says disclaimers cannot override the facts of how a client was reached, and bars follow-on marketing after a first own-initiative trade. Under Article 111, the penalties for getting this wrong are real: administrative fines up to at least 5 million euros for service-provider breaches by a company, and up to 15 million euros or 15 percent of annual turnover for market-abuse breaches.

Supervision is also turning proactive rather than reactive. In July 2026, ESMA launched its first Common Supervisory Action under MiCA, a coordinated review across national regulators of how firms handle custody and digital operational resilience, reading across to DORA. It is the clearest sign yet that the job has shifted from handing out licenses to checking what firms do with them, and it puts the fragmentation problem to the test in real time: a coordinated action only works if 26 regulators actually apply it the same way.

The Gaps MiCA Left Open

For all its breadth, MiCA has holes, and everyone in Brussels knows where they are. Decentralised finance is essentially unaddressed: the regulation applies to identifiable service providers, and a genuinely decentralised protocol has none, so a DeFi front end can sit in a grey zone while a licensed exchange beside it carries the full compliance load. Non-custodial staking is unregulated, even as custodial staking is treated as an ancillary service. Crypto lending and borrowing, an on-chain credit market worth many billions of dollars, is not regulated as a standalone activity under MiCA at all.

Non-fungible tokens are mostly carved out, but the carve-out is narrow. A token issued as part of a large series or collection, or one that is fractionalised, can be pulled back into scope, and ESMA has warned that substance beats labels when deciding whether a collectible is really a financial instrument. Where a token sits, in or out, often turns on how it behaves rather than what it is called, a boundary HOGE Wire has walked through in detail for tokens, NFTs and games. Prediction markets and perpetual futures, meanwhile, live in the MiFID II world, not MiCA’s. Each of these gaps is a place where users take real risk with none of MiCA’s protections, and each is squarely on the table in the review.

The 30 September Deadline and MiCA 2.0

MiCA was written with its own review built in. The European Commission opened a targeted consultation on 20 May 2026, asking 86 questions across four areas: scope and definitions, the stablecoin regime, the service-provider rules, and the activities currently beyond MiCA’s reach. Originally due to close on 31 August, the deadline was pushed back to 30 September 2026 to give the industry more time. The answers feed reports the Commission owes under Articles 140 and 142 by 30 June 2027, and those reports may carry a legislative proposal, the change the industry has already nicknamed “MiCA 2.0.”

The consultation is framed as a tune-up rather than a rewrite, and the industry wants to keep it that way. Katie Harries, Director and Head of Policy for Europe at Coinbase, told The Block that “MiCA has set an early global standard for clear and harmonized rules,” and that the company supports “targeted improvements to ensure Europe can combine its strong safeguards with global competitiveness, not a reopening of first principles.” The tension running through every submission is the one this article keeps circling: how to close the gaps and tighten supervision without making Europe so heavy that builders simply leave.

The Digital Euro in the Wings

Running in parallel is a project that could reshape the same market from the public side: the digital euro. This is not a private stablecoin but central-bank money in digital form, a retail central bank digital currency the ECB has been designing for years. The legislative file has moved into trilogue negotiations among the Parliament, the Council and the Commission, with the aim of adopting the regulation by the end of 2026. If that timeline holds, the ECB plans a pilot in 2027, with the first digital euros issued around 2029.

ECB Executive Board member Piero Cipollone, who chairs the project, has pitched it as a matter of payment sovereignty: a public option that keeps Europeans from depending entirely on foreign card networks and dollar stablecoins for everyday digital payments. Banks worry about deposits fleeing into a risk-free ECB liability, which is why holding limits are central to the design. For crypto specifically, a digital euro would sit awkwardly beside MiCA’s euro stablecoins, a public token competing with private ones, and it explains part of why MiCA moved to cap the reach of dollar tokens in the first place.

MiCA and the American Alternative

The contrast with the United States sharpens what MiCA is. Europe chose one comprehensive regulation, negotiated over years and applied across a bloc, before most of the market existed at scale. The US has taken the opposite path: rules built case by case through the SEC and the CFTC, plus targeted statutes rather than a single code. The GENIUS Act gave the US a federal stablecoin law, and American market regulators have since clarified that payment stablecoins are not securities. But the broader market-structure bill, the CLARITY Act, failed a crucial Senate vote in September 2026, leaving the US without the comprehensive framework MiCA already has in place.

DimensionEuropean Union (MiCA)United States
FrameworkOne regulation, EEA-wideAgency action plus targeted statutes
Primary supervisorNational regulators (ESMA push to centralise)SEC and CFTC, plus states
StablecoinsE-money token rules; issuer must be bank or EMI; no interestGENIUS Act; payment stablecoins not securities
Market-structure lawIn forceCLARITY Act failed Senate vote, Sept 2026
PassportingOne license across 30 marketsState-by-state money-transmitter patchwork

The result is a genuine divergence. MiCA gives firms certainty and a passport at the cost of a heavy, uniform compliance burden; the US offers lighter, more fragmented rules with less legal certainty. Which model wins talent and capital over the next few years is an open contest, and it is the unspoken subtext of Europe’s own review. The fear in Brussels is not that MiCA is too soft, but that too much friction, or too much supervisory inconsistency between one member state and the next, sends the next generation of builders across the Atlantic before the rules are even finished.

Frequently Asked Questions

Is MiCA fully in force in 2026?

Yes. MiCA’s rules phased in between 2024 and the end of 2025, and the last transitional period for existing firms closed on 1 July 2026. Any provider serving EU retail users now needs a MiCA license, and unlicensed firms have been told to wind down.

What is the MiCA passport?

Once a crypto firm is authorised in one EEA member state, it can offer its services across the whole European Economic Area without a separate license in each country. It notifies its home regulator, which informs the host regulators and ESMA, and can begin operating in the new markets within about two weeks.

Why was USDT delisted in Europe but not USDC?

MiCA requires stablecoin issuers to be authorised and to meet reserve, redemption and disclosure rules. Circle obtained a license and kept USDC and EURC on EU venues, while Tether chose not to apply, so European exchanges removed USDT for retail users.

Who regulates crypto under MiCA?

National competent authorities in each member state, for example BaFin in Germany, the AMF in France and Consob in Italy, authorise and supervise firms, coordinated by ESMA and the EBA at EU level. A live proposal would move supervision of the largest cross-border firms to ESMA directly.

What is “MiCA 2.0”?

It is the informal name for possible changes coming out of the Commission’s review. A consultation closes on 30 September 2026, feeding reports due by 30 June 2027 that may propose new rules for areas MiCA left out, such as DeFi, staking, lending and NFTs.

By Anneke de Vries, Regulation Lead, HOGE Wire.

Share 𝕏 Post Telegram