The countdown to full Markets in Crypto-Assets Regulation ((EU) 2023/1114 (“MiCA”)) enforcement has officially begun. In a strong and unequivocal statement, the European Securities and Markets Authority confirmed that from 1 July 2026, any crypto-asset service provider operating in the European Union without a MiCA licence will be acting unlawfully. For the crypto industry, this is far more than another regulatory update, it is the moment where Europe’s new crypto framework moves from transition to enforcement.
The European Securities and Markets Authority’s (“ESMA”) message leaves little room for interpretation. Firms that have not secured authorisation by the end of the transitional period must stop servicing EU clients and implement orderly wind-down procedures. Regulators are no longer focusing solely on preparation; attention is now shifting towards supervision, enforcement, and consumer protection. The expectation is that businesses either become fully compliant or exit the market in a controlled and transparent manner.
What makes this particularly significant is the emphasis being placed on client protection during the transition. ESMA expects firms that fail to obtain authorisation to ensure that clients are not left exposed or unable to access their crypto-assets. This includes properly offboarding customers, facilitating transfers to authorised providers or self-hosted wallets, and maintaining compliance with anti-money laundering and conduct obligations until operations fully cease. In practical terms, firms are expected to have credible and executable exit strategies already prepared well before the deadline arrives.
The statement also signals increased regulatory scrutiny on international group structures and outsourcing arrangements. ESMA specifically warned that non-EU entities cannot continue providing MiCA-regulated services to EU clients through indirect structures or back-end arrangements. This is particularly relevant for crypto businesses operating across multiple jurisdictions while relying on offshore affiliates for custody, operational support, or customer servicing. Regulators are expected to examine closely whether firms are genuinely operating through authorised EU entities or merely creating the appearance of compliance.
Consumers are equally being urged to pay closer attention to who they are dealing with. ESMA highlighted that MiCA protections apply only when services are provided by a specifically authorised EU legal entity, not necessarily by other companies within the same corporate group or brand. Investors are therefore being encouraged to verify whether their provider is authorised under MiCA and to review carefully which entity is holding or servicing their assets.
The broader message behind ESMA’s statement is clear: the era of regulatory ambiguity in the European crypto market is rapidly coming to an end. The EU is positioning MiCA as a fully operational regulatory regime with meaningful supervisory expectations and cross-border enforcement. For crypto firms targeting the European market, the remaining transition period is no longer simply a grace period but it is the final opportunity to align their operations with one of the world’s most comprehensive crypto regulatory frameworks.
