MiCA in 2026: From Rulemaking to Enforcement
Europe's crypto rulebook is fully live, and on 8 October ESMA told platforms to drop non-compliant stablecoins by January. Here is how MiCA moved from writing rules to enforcing them.
For most of the past two years, the story of Europe’s crypto rulebook was a story about dates on a calendar. The Markets in Crypto-Assets Regulation, known as MiCA, was drafted, published, and switched on in stages while the industry argued about what it would eventually mean in practice. In October 2026, with Bitcoin trading at around $83,000, that phase has ended. MiCA is fully in force, the grace period for legacy firms has closed, and the authorities who spent three years writing rules have started using them.
The clearest signal came on 8 October 2026, when the European Securities and Markets Authority (ESMA) told national regulators to make crypto platforms stop offering stablecoins that do not comply with MiCA, and gave them three months to do it. It was not a new law. It was the enforcement of rules that have sat on the statute book since 2024, and it captures where MiCA now stands: the debate has moved from what the rulebook says to who makes it bite, and how hard.
What changed on 8 October 2026
ESMA’s intervention took the form of an opinion, document reference ESMA75-113276571-1742. An opinion is not legislation; it is a supervisory-convergence tool, a formal instruction to the national competent authorities about how they should read and apply a rule everyone already has to follow. In this case the message was blunt. Any firm authorised under MiCA must stop providing services tied to asset-referenced tokens (ARTs) or e-money tokens (EMTs) that are not themselves authorised in the European Union, and national regulators must require the remaining exposures to be remediated within three months of publication. Three months from 8 October lands on 8 January 2027.
The scope is wide, and that is the point. It is not just trading pairs. The opinion reaches the full range of MiCA services: operating a trading platform, exchange, execution of orders, placement, reception and transmission of orders, investment advice, transfers, custody and administration, and portfolio management, whether offered on their own or bundled together. During the wind-down a platform may still help a client out of a non-compliant token, through liquidation, conversion, withdrawal, transfer, or safekeeping, but it may not sell it, promote it, or otherwise keep it available for new purchases. ESMA was careful to say this is not a fresh three-month exemption. It is a deadline for dealing with legacy balances that should, in principle, have been dealt with already.
Verena Ross, who chairs ESMA, framed the wider shift plainly in front of the European Parliament’s Economic and Monetary Affairs Committee on 28 September. “Following the entry into application of MiCA, the focus has moved from rulemaking towards supervision and supervisory convergence,” she told lawmakers. The stablecoin opinion that landed ten days later is exactly that: supervision, not drafting.
MiCA in one paragraph: what the rulebook actually is
MiCA is Regulation (EU) 2023/1114, a single regime that covers the issuance of crypto-assets, the stablecoins used to pay with them, and the firms that trade, hold, and move them on behalf of the public. It applies across the European Union and, through the European Economic Area, in Norway, Iceland, and Liechtenstein. It does three big things: it licenses crypto-asset service providers (CASPs) and lets a licence from one member state passport across the bloc; it imposes reserve, redemption, and disclosure rules on stablecoin issuers; and it prohibits market abuse such as insider dealing and manipulation on regulated venues. What all of that does for an ordinary user, from the register check to the white paper to the right of withdrawal, we set out in a companion guide to what the rulebook does for you. This piece is about the other side of the same coin: how the rules are being applied now that the writing is finished.
Two boundaries matter for everything that follows. MiCA governs the spot market and the intermediaries around it, not derivatives, which sit under the older Markets in Financial Instruments Directive (MiFID II) and its national markets regulators. And it regulates identifiable firms, not software; a service provided in a genuinely decentralised way, with no intermediary, falls outside the perimeter by design. Both carve-outs are where enforcement gets complicated, and we return to them below.
The phased rollout, and why 2026 is the inflection point
MiCA did not land in one piece. It entered into force on 29 June 2023, but its obligations switched on in waves so that issuers and firms had time to prepare. The stablecoin titles came first, on 30 June 2024, setting reserve, redemption, and authorisation rules for asset-referenced and e-money tokens. The larger part of the regime, the CASP licensing framework and the market-abuse prohibitions, followed on 30 December 2024. A parallel rulebook, the Digital Operational Resilience Act (DORA), began to apply on 17 January 2025, pulling the same crypto firms into strict requirements on information-technology risk, incident reporting, and outsourcing.
The piece that turned 2026 into the inflection point was the transitional period. MiCA let member states allow firms that were already operating under national rules to keep going for a limited time while they applied for a full licence. That bridge has now been pulled up. Add the stablecoin wind-down deadline and the close of the first formal review, and 2026 is the year MiCA stopped being a project and became a supervised market.
| Date | Milestone | What it meant |
|---|---|---|
| 29 Jun 2023 | MiCA enters into force | The regulation becomes law; the staged countdown to application begins |
| 30 Jun 2024 | Stablecoin titles apply | ART and EMT issuers must be authorised; reserve and redemption rules go live |
| 30 Dec 2024 | CASP and market-abuse rules apply | The licensing regime and the insider-dealing and manipulation ban switch on |
| 17 Jan 2025 | DORA applies | Operational-resilience and ICT rules bite CASPs alongside MiCA |
| 1 Jul 2026 | Transitional period closes | Grandfathering ends across the bloc; unlicensed firms must stop |
| 30 Sep 2026 | MiCA review consultation closes | The Commission gathers input for a possible MiCA 2 |
| 8 Jan 2027 | Non-compliant stablecoin wind-down deadline | CASPs must end services tied to unauthorised ARTs and EMTs |
| 30 Jun 2027 | Commission report due (Articles 140 and 142) | The formal review that can trigger legislative change |
Each of those dates changed what a firm or a user could legally do. The last three, clustered across the back half of 2026 and the first half of 2027, are the ones that turn text into enforcement.
Grandfathering is over: the 1 July 2026 cliff
The transitional regime was the single biggest piece of forbearance in MiCA, and it expired on 1 July 2026 across the entire bloc. There is no extension mechanism written into the regulation, so no member state could push the date out even if it wanted to. Several ran shorter clocks than the maximum: Finland, the Netherlands, Germany, Austria, Ireland, Latvia, Lithuania, and Hungary all closed their windows earlier, which is why firms in those markets had to be licensed sooner than peers in slower-moving states.
The practical effect is simple and harsh. A provider that did not obtain a CASP licence, or passport one in from another member state, can no longer serve clients in the European Union. It must wind down the local business in an orderly way. The one narrow escape hatch, reverse solicitation, lets an offshore firm deal with an EU client only where the client approached it entirely on its own initiative, and ESMA has repeatedly warned that the carve-out cannot be used as a marketing strategy. A website, an advert, or an onboarding funnel aimed at Europeans breaks it. The default after 1 July 2026 is straightforward: if a venue is not on the register, it should not be taking European money.
367 licences and counting: the CASP map
Enforcement needs a register, and the register is filling up. As of 9 October 2026, 367 firms held a CASP authorisation somewhere in the EU or EEA, according to independent tracker casptracker.eu, which aggregates the national registers that feed into ESMA’s central list. The distribution is lopsided. Germany has crossed 100 licences, more than France, the Netherlands, and Cyprus combined, a reflection of BaFin’s early start and the depth of the German market. A long tail of smaller jurisdictions holds a handful each, and three member states (Hungary, Poland, and Romania) still show zero.
| Member state | Authorised CASPs (9 Oct 2026) |
|---|---|
| Germany | 100 |
| France | 36 |
| Netherlands | 29 |
| Cyprus | 25 |
| Malta | 23 |
| Spain | 15 |
| Luxembourg | 13 |
| Czechia | 12 |
| Ireland | 12 |
| Latvia | 12 |
| Liechtenstein | 12 |
| Austria | 11 |
| Italy | 9 |
| Total, EU and EEA | 367 |
Behind the numbers is a mix most readers will recognise. Kraken runs its European business on a CASP licence granted in Ireland; other global and European names, including OKX, Bybit, Coinbase, and Bitpanda, have secured authorisations in one member state or another and passported out from there. Just as telling is who is not on the list. The register is public and searchable by anyone, and a brand’s absence from it is now a warning sign rather than a technicality, because after the transitional cliff there is no lawful way to serve EU retail clients without appearing on it.
One passport, 27 supervisors
MiCA’s central promise to firms is the passport: get licensed once, in one member state, and offer services across all thirty EU and EEA markets without reapplying. That is a genuine single market, and it is why a firm authorised in Ireland or Malta can serve customers in Spain or Finland. But the passport sits on top of a supervisory structure that is anything but single. The authorities that grant and police CASP licences are national: BaFin in Germany, the AMF and ACPR in France, the Central Bank of Ireland, CySEC in Cyprus, the MFSA in Malta, Consob and the Bank of Italy, and their equivalents across the bloc. ESMA coordinates them, writes technical standards, issues guidelines and opinions like the one on stablecoins, and maintains the central register, but it does not itself license most CASPs.
That split is the structural tension in MiCA enforcement. A licence from the most permissive regulator is valid everywhere, so standards converge only as fast as the most cautious authority can push. ESMA’s answer is supervisory convergence: shared guidelines, common questions and answers, and peer reviews that probe how individual authorities actually granted licences. It is not a hypothetical concern. Regulators in France, Italy, and Austria have jointly argued that the largest, most systemic CASPs should be supervised directly at the European level rather than through a single home-state authority, an idea that would make ESMA look a little more like a pan-European markets cop. For now, the money and the market abuse are watched by dozens of separate national teams reading the same text.
Stablecoins are the exception that proves the rule. Once an asset-referenced or e-money token grows large enough to be designated significant, crossing at least three thresholds such as more than 10 million holders, more than 5 billion euros in issuance, or more than 2.5 million transactions a day, supervision moves up to the European Banking Authority (EBA) in Paris. The biggest tokens are already pulled into direct European oversight, while the long tail stays national.
The stablecoin wind-down: USDT’s European exit
To see why the 8 October opinion matters, look at the shape of the stablecoin market. The total sits at roughly $292 billion, and it is overwhelmingly a dollar market. Tether’s USDT alone is about $184 billion, close to 63% of the whole sector. Circle’s USDC is around $73 billion, another quarter. The largest euro-denominated token, Circle’s EURC, is under $500 million, a rounding error at roughly 0.17% of the total. More than 99 cents of every stablecoin dollar is pegged to the US dollar, not the euro.
| Stablecoin (issuer) | Market cap (approx.) | EU status under MiCA |
|---|---|---|
| USDT (Tether) | $184B | Not authorised; EU platforms must wind down by 8 Jan 2027 |
| USDC (Circle) | $73B | Authorised e-money token (France); available in the EU |
| USDS (Sky) | $10B | Not an authorised EU e-money token |
| USDe (Ethena) | $4.8B | Not authorised; issuer pushed out of Germany in 2025 |
| DAI (Sky) | $4.5B | Not an authorised EU e-money token |
| EURC (Circle) | $496M | Authorised euro e-money token; MiCA-compliant |
The problem for Europe is that the single most important token in that market, USDT, is not authorised under MiCA, and its issuer has said it does not intend to seek authorisation. Tether’s objection is specific. MiCA requires an e-money token issuer to hold a large share of its reserve, up to 60% for a token deemed significant, in bank deposits rather than in short-dated government paper. Chief executive Paolo Ardoino argues that makes the token less safe, not more, because “a bank deposit is not equivalent to immediately available cash,” he told reporters, warning that a bank can lend those deposits out and leave an issuer short in a run. Whatever the merits of the argument, the outcome is the same: USDT does not meet the rule, so after 8 January 2027 an EU-licensed platform cannot offer it.
Circle took the opposite path and built for the rules, securing e-money token authorisation in France and marketing USDC and EURC as the first MiCA-compliant offering from a global issuer. That is the trade the opinion forces into the open. A European user holding USDT on a regulated exchange will be able to convert it, withdraw it, or move it to self-custody during the wind-down, but will not be able to keep buying it on that venue. Many exchanges had already been nudging EEA customers out of USDT and into USDC; the opinion turns that nudge into a hard stop.
Enforcement was already happening: the Ethena case
The 8 October opinion reads like the start of enforcement, but the first real action came more than a year earlier, and it came from a national regulator. In March 2025, BaFin ordered Ethena GmbH, the German entity behind the synthetic-dollar token USDe, to halt all public sales and froze its reserve assets, citing deficiencies in the firm’s organisation and breaches of MiCA rules on reserves and capital. The regulator also flagged concerns that a related staked token might amount to an unauthorised securities offering.
Ethena did not fight to the end. It agreed to stop the German entity’s activities, dropped its MiCA authorisation effort, and moved the token’s issuance outside Germany. In June 2025, BaFin ordered the orderly wind-up of the German operation and set a redemption window, giving holders until early August to redeem their tokens. The episode was a template for what the ESMA opinion now scales up: a regulator identifies a non-compliant token, orders issuance and sales to stop, and forces an orderly exit that protects existing holders without letting the product keep growing. The difference is scale. Ethena was one firm in one country; the stablecoin opinion points the same tool at every CASP in the bloc at once.
What MiCA does not touch
Enforcement has edges, and knowing where they fall matters as much as knowing what is covered. MiCA regulates firms that provide crypto services to the public. It does not regulate the technology itself, and it does not follow you into your own wallet. Self-custody is outside the perimeter: if you hold your own keys, no authorised intermediary sits between you and your coins, so there is no CASP to supervise and no deposit-guarantee scheme behind you. That freedom comes with the full weight of the risk. A phishing drainer, a lost seed phrase, or a tampered hardware wallet bought through a grey-market reseller is your problem alone, and the newer smart-account wallets that add social recovery and spending limits are features of software, not rights granted by a regulator.
Decentralised finance is the second big carve-out, and it is narrower than the headlines suggest. Recital 22 of the regulation says that where a service is provided in a fully decentralised manner without any intermediary, MiCA does not apply. The catch is that almost nothing is fully decentralised. A protocol with a front-end website, admin keys, a fee switch, or a concentrated governance token has an identifiable operator somewhere, and identifiable operators can be authorised, warned, or sanctioned. The question of who actually controls a supposedly trustless system, and who answers when it breaks, is the same one we examined in our look at DAO security councils. Where a protocol genuinely has no operator, MiCA’s investor protections simply do not reach. There is no custody-liability rule for a smart contract, and risks like maximal extractable value and front-running have no regulated party to hold responsible.
Two more boundaries round out the map. Most non-fungible tokens are excluded as genuinely unique items, though ESMA has warned that a large series of near-identical NFTs, or fractionalised pieces of one, can behave like fungible crypto-assets and be pulled back into scope on substance rather than label. And crypto derivatives, the perpetual futures and options that drive a huge share of trading volume, are not MiCA products at all; they are financial instruments under MiFID II, supervised by national markets regulators, which is why a venue can list a perpetual future and still sit under a completely different rulebook from the spot exchange next door. Above all, MiCA does not make crypto safe. It does not cap volatility or guarantee that a token holds its value. It makes the firms around the asset accountable, and leaves market risk where it has always been.
DORA, the Travel Rule, and AMLA: the rest of the stack
MiCA is the headline, but a CASP in 2026 answers to a stack of rules that arrived alongside it, and enforcement of the whole bundle is what firms actually feel. DORA, which began to apply in January 2025, holds crypto firms to the same operational-resilience standard as banks: documented information-technology risk management, mandatory reporting of serious incidents, resilience testing, and oversight of the cloud providers and other third parties they lean on. An exchange that goes dark during a volatile session is no longer only a customer-service problem; it is a potential supervisory one.
Anti-money-laundering rules add a second layer. The EU’s recast Transfer of Funds Regulation, the bloc’s version of the Travel Rule, took effect on the same day as the CASP regime and requires providers to collect and pass on information about the sender and recipient of a crypto transfer, ending the idea that on-chain payments move anonymously through regulated venues. Above that sits a new single AML rulebook and a new enforcer: the Anti-Money Laundering Authority, or AMLA, being stood up in Frankfurt, which will directly supervise a group of the highest-risk financial firms, crypto providers among them, as its powers phase in toward 2028. A licensed CASP therefore lives inside four overlapping regimes at once, MiCA for conduct and authorisation, DORA for resilience, the Travel Rule for transfers, and the AML rulebook for financial crime, and a serious failure in any one of them is an enforcement hook.
The review, and the rewrite fight
Even as it starts enforcing MiCA, Europe is already arguing about how to change it. The European Commission ran a formal review consultation that closed on 30 September 2026, feeding a report it must deliver by 30 June 2027 under Articles 140 and 142, which can in turn trigger a second-generation MiCA. ESMA used the moment to ask for sharper tools of its own. In its 30 September response, reference ESMA75-113276571-1721, the authority set out a wish list that reads like a supervisor impatient to act.
- Stricter marketing rules, including for influencers and third parties, plus clearer cost transparency for investors.
- Proportionate disclosure for staking, lending, and borrowing services, so users can see the risks and rewards.
- Power to detect, block, and deactivate fraudulent websites and to freeze crypto assets where market abuse or terrorist financing is suspected.
- A new regulated category for providers that give access to DeFi, with clearer criteria for what counts as genuinely decentralised.
- Binding ESMA opinions on how individual tokens are classified, to stop the same asset being treated differently across the bloc.
- An explicit prohibition on regulated firms offering services tied to non-compliant stablecoins.
The last item on that list is worth pausing on, because the 8 October stablecoin opinion is ESMA reaching the same destination without waiting for the law to change. Rather than hold out for a legislative ban, it used a convergence tool it already has to tell national authorities to treat non-compliant stablecoin services as off-limits now. That is the enforcement mindset in miniature: use the powers already on the books, hard, while asking for more.
Industry wants the review to pull in the opposite direction, toward simplification and competitiveness rather than new powers. Katie Harries, Coinbase’s Director and Head of Policy for Europe, put the industry line carefully: “We support targeted improvements to ensure Europe can combine its strong safeguards with global competitiveness, not a reopening of first principles,” she said. The regulators’ counterpoint is just as pointed. As ESMA chair Verena Ross framed it in an earlier interview, “The MiCA rulebook will only protect investors if it is effectively applied.” Her thesis has not changed; what is new in 2026 is that she finally has a fully live market to apply it to.
Europe versus the United States: two enforcement models
MiCA’s enforcement turn looks sharper still next to the United States, where the direction of travel is almost the reverse. Europe wrote one comprehensive rulebook and is now applying it; the US still has no single federal framework for the crypto spot market. Its one firm piece of statute is the GENIUS Act, a dedicated stablecoin law signed in 2025 and due to take effect on 18 January 2027, ten days after ESMA’s European stablecoin deadline. Beyond stablecoins, oversight is split between the SEC and the CFTC and has been shaped more by enforcement actions and court rulings than by statute, after a broader market-structure bill failed to clear the Senate in 2025.
| European Union | United States | |
|---|---|---|
| Spot-market rulebook | MiCA, comprehensive and in force | No single federal framework |
| Stablecoins | EMT and ART rules; non-compliant tokens barred from 8 Jan 2027 | GENIUS Act, effective 18 Jan 2027 |
| Lead supervisors | ESMA, EBA, and national authorities | SEC and CFTC, by enforcement and rule |
| Overall approach | Written first, now enforced | Case-by-case, broad legislation still pending |
The gap creates the so-called Brussels effect: because MiCA is detailed and already live, global firms that want EU access tend to build to its standard and then export that compliance elsewhere, which is part of why Circle structured USDC and EURC the way it did. The risk for Europe is the mirror image. Push too hard, and activity migrates to lighter-touch jurisdictions; the same review that could hand ESMA more power is also, officially, a competitiveness exercise.
What the enforcement turn means for you
For an ordinary European user, the shift from rulemaking to enforcement is mostly good news wrapped around a few deadlines. The practical checklist is short.
- Check the register. Before you trust a platform, confirm it holds a CASP licence in an EU or EEA member state. The lists are public; an absent brand is a reason to walk away, not a quirk.
- Plan your USDT exit. If you hold USDT or another non-compliant stablecoin on a regulated EU venue, expect to convert, withdraw, or move it to self-custody before 8 January 2027, when platforms must stop supporting it.
- Use your white-paper rights. On a primary offer you get a disclosure document and, in defined cases, a short right to withdraw. Read the first and know the second.
- Self-custody is still on you. No regulator reimburses a lost seed phrase or a signed malicious transaction. The protections stop at the exchange door.
- Derivatives are a different rulebook. Perpetuals and options sit under MiFID II, with their own leverage caps and protections, not under MiCA.
- Offshore is not a loophole. Reverse solicitation is narrow. A venue outside the EU that advertises to you is operating against the rules, not around them.
None of this removes the oldest risk in the asset class. MiCA will not stop Bitcoin from falling, a token from going to zero, or a market from panicking. What the enforcement turn does is narrow the second kind of loss, the one that comes from an unlicensed venue, an opaque stablecoin, or a firm that cannot keep its systems running. In 2026, Europe finished writing that promise down. In 2027, it has to prove it can keep it.
Frequently Asked Questions
What is MiCA, and is it fully in force in 2026?
MiCA is the EU regulation, number 2023/1114, that governs crypto-asset issuers, stablecoins, and the firms that trade and hold crypto for the public. Its rules applied in stages through 2024, and the transitional period for existing providers closed on 1 July 2026, so the regime is now fully live across the EU and EEA.
What happens to USDT in the EU after the ESMA ruling?
On 8 October 2026 ESMA told national regulators that MiCA-licensed platforms must stop offering stablecoins that are not authorised in the EU, including USDT, and remediate remaining exposures within three months, by 8 January 2027. Holders can still convert, withdraw, or self-custody the token during the wind-down, but cannot keep buying it on an EU venue.
Did the MiCA transitional period really end on 1 July 2026?
Yes. The grandfathering window that let pre-existing providers operate while applying for a licence closed on 1 July 2026 across the whole bloc, with no extension mechanism. Several states, including Germany, the Netherlands, Finland, and Austria, ended it even earlier. A firm without a CASP licence can no longer serve EU clients.
Does MiCA cover DeFi and self-custody wallets?
Mostly no. MiCA regulates identifiable firms, not software, so self-custody wallets and genuinely decentralised protocols fall outside it under Recital 22. In practice most DeFi has an operator somewhere (a front-end, admin keys, or governance), which can pull it back into scope. If you hold your own keys, no regulator stands behind you.
How can I check if a crypto exchange is MiCA-licensed?
Every authorised CASP appears on a public register kept by its national regulator and collected centrally by ESMA, and independent trackers mirror the same data. As of 9 October 2026 there were 367 authorised CASPs across the EU and EEA. If a platform is not listed, treat that as a warning sign rather than a formality.
By Anneke de Vries, regulation correspondent at HOGE Wire.