MiCA stopped having a grace period on 1 July 2026. Every grandfathering window that any Member State chose has now closed, and a crypto-asset service provider operating in the EU without authorisation is simply unauthorised.
That is the state of play as of today, and it is the single fact most guidance on the internet has not caught up with.
What MiCA covers
The Markets in Crypto-Assets Regulation — Regulation (EU) 2023/1114 — creates uniform EU market rules for crypto-assets that existing financial services legislation did not already regulate. It entered into force in June 2023.
Its provisions run across three groups:
- Asset-referenced tokens (ARTs) — tokens referencing a basket of assets, currencies or other values.
- E-money tokens (EMTs) — tokens referencing a single official currency.
- Other crypto-assets, and the crypto-asset service providers (CASPs) that offer services around all of them.
The obligations cover transparency and disclosure, authorisation, and supervision of transactions — with the crypto-asset white paper as the central disclosure document.
The MiCA transitional period is over

Article 143(3) is the provision that mattered. It allowed crypto-asset service providers that were operating lawfully before 30 December 2024 to continue doing so until 1 July 2026, or until authorisation was granted or refused — whichever came sooner.
Member States could shorten that window, or decline it entirely, where they judged their pre-existing national framework less strict than MiCA. They did so unevenly, and the spread was wide: six months in the Netherlands, Poland, Finland, Latvia, Hungary and Slovenia; nine in Sweden; twelve in Germany, Ireland, Austria, Lithuania, Slovakia and Norway; the full eighteen in France, Spain, Italy, Malta, Luxembourg and others.
Several also imposed application cut-offs partway through — Czechia required applications by 31 July 2025, Italy by 30 December 2025, Denmark by 30 December 2024. Miss the application date and the grandfathering ended early regardless of the headline period.
All of them have now expired. The longest ran out six weeks ago.
What that means in practice
ESMA maintains an Interim MiCA Register covering white papers for crypto-assets other than ARTs and EMTs, issuers of ARTs, issuers of EMTs, authorised CASPs — and, separately, non-compliant entities. It was last updated on 12 August 2026.
That last list is the part worth dwelling on. Operating without authorisation is no longer a quiet regulatory risk; it is a published one, on a register your counterparties, banks and prospective customers can read.
One caveat ESMA states plainly: crypto-asset white papers listed in the register have not been reviewed or approved by any competent authority. The offeror or issuer is solely responsible for the content. A white paper appearing on the register is not a regulatory endorsement, and should not be presented as one.
The MiCA Level 2 and Level 3 detail
MiCA delegates a substantial amount to technical standards, developed by ESMA with EBA, EIOPA and the ECB, and delivered in three sequential packages. Most have now entered into application following adoption by the Commission and scrutiny by Parliament and Council.
Two areas produce the most operational work and are frequently underestimated:
- White paper formatting and data standards. MiCA and its implementing regulations set technical format requirements for white papers — not just content, but machine-readable structure.
- Order book and record-keeping standards for CASPs operating a trading platform, and data standards for those placing orders or executing transactions.
ESMA published a statement on 28 November 2025 to support smooth implementation of these standards and formats. If your compliance team has read the Regulation but not the format specifications, that gap is where projects overrun.
Beyond MiCA: what else applies
| Regime | Why it also lands on you |
|---|---|
| DORA | An authorised CASP is a financial entity under DORA. ICT risk management, incident reporting and third-party oversight apply — this is the obligation most crypto firms discover last |
| ISO 27001 | Not required, but the most efficient way to build the security governance both regimes assume you already run |
| GDPR | Customer onboarding and transaction monitoring generate substantial personal data with no crypto-specific exemption |
| NIS2 | Relevant depending on classification and Member State implementation; worth checking rather than assuming DORA displaces it |
The pattern for a newly authorised CASP: MiCA gets you the licence, DORA governs how you run the technology behind it, and neither substitutes for the other.
Where to start
- Establish your actual status. Authorised, refused, in process, or operating without authorisation — there is no fourth position now that grandfathering has ended.
- Check the ESMA register, including the non-compliant entities list.
- Classify your tokens as ART, EMT or other, because the obligations diverge sharply from that point.
- Read the format specifications, not only the Regulation — white paper structure and order book records are technical deliverables.
- Plan DORA alongside, since authorisation brings it with you.
- Watch the Level 2 and Level 3 table, which ESMA maintains as measures enter application.
This guide reflects ESMA’s MiCA pages and the Article 143 grandfathering list at 15 August 2026. National positions were notified by competent authorities and some were not yet in national law when published — verify your own jurisdiction with its regulator.
The MiCA Toolkit provides 100+ editable templates covering the authorisation application, the white paper structure, the governance and prudential documentation, complaints and conflicts procedures, and the record-keeping artefacts a competent authority expects to see.