us

216.73.217.78

Back
Blogs

MiCA Regulation: What EU Crypto Businesses Must Do After July 2026

MiCA Regulation: What EU Crypto Businesses Must Do After July 2026
Amir RizwanAmir Rizwan JUNE 19, 2026 11 minutes read

MiCA’s transitional deadline passed on 1 July 2026, but the regulation itself is now under EU review. Here’s what CASPs, stablecoin issuers, and compliance teams still need to track.

On 1st July 2026, the EU’s Markets in Crypto-Assets Regulation, known as MiCA, was closed.  National licenses that were issued under the previous regulations became irrelevant. That means any crypto asset service provider that is still using the old regulation and the old national license cannot serve EU clients from that day onward. And there are no extensions or exceptions to that rule, which has been in place for the last two years. 

Now, most guidance that you’ll find online still dates back to that previous regulation that’s no longer in place, whereas this guide will help you build a compliance program built to survive the new rules and the deadlines.

What is MiCA regulation, and why does July 2026 feel like the finish line?

MiCA, formally Regulation (EU) 2023/1114, is one rulebook that covers crypto businesses across the whole EU. Before it, a crypto company needed a separate licence in each of the 27 EU countries it wanted to serve. After MiCA, one licence from any single EU country covers all 27.

Who MiCA regulation applies to

MiCA applies to three groups, and it doesn’t matter which group a company falls into; if it serves the EU, it has to comply with the regulation.

  1. Token issuers: Anyone offering an asset-referenced token or an e-money token to the EU market.
  2. Crypto-asset service providers (CASPs): Exchanges, custody providers, portfolio managers, and advisers serving EU clients.
  3. Public offerors: Anyone making a public offer of a crypto-asset not already regulated as a traditional financial instrument.

As an example, a crypto exchange based in Singapore or the US that serves EU retail clients falls under MiCA exactly as a Frankfurt-based one does.

Why teams think MiCA’s rules are now fixed

Compliance work like AML checks and monitoring never stops; that’s not what’s confusing teams. What teams did assume is that the MiCA rulebook itself was final. For two years, every guide focused on one deadline: get authorised by 1 July 2026. Once a CASP cleared that date, teams assumed the requirements they built their systems around were locked in.

That assumption was wrong. The EU Commission opened a review of MiCA in May 2026, and that review could change what MiCA actually requires. So the rulebook is not fixed yet, even though the authorisation deadline has passed.

When did MiCA regulation come into full force, and what’s still moving?

MiCA didn’t arrive as one law on one date. It phased in across three dates, and the third one, the deadline everyone quotes, is not the end of the process.

The phased rollout: June 2024 to July 2026

Phase Date What applied Who it covered
Phase 1 30 June 2024 Rules for asset-referenced tokens and e-money tokens (Titles III-IV) Stablecoin issuers
Phase 2 30 December 2024 Rules for crypto-asset service providers (Titles I, II, V, VI, VII) Exchanges, custody providers, portfolio managers, advisers
Phase 3 1 July 2026 End of the transitional period for CASPs operating under national licences CASPs that had not yet secured MiCA authorisation

Stablecoin issuers have followed MiCA’s rules on reserves, redemptions, and the ban on paying interest since June 2024. That’s over two years now.

Exchanges and custody providers had until 30 December 2024 for the CASP rules to apply to them, then 18 months to get authorised, ending 1 July 2026.

Both deadlines lead to the same result. After 1 July 2026, every business that touches EU crypto-asset markets must follow one single rulebook. There is no option to keep operating under an old national licence instead.

The EU Commission is reviewing MiCA and could still change it

On 20 May 2026, the European Commission opened a consultation on MiCA. A consultation is a formal process where the Commission asks the industry a set of questions before deciding whether to change a law. This one asks whether MiCA is working properly, even though the law has only been fully active for about 18 months. It covers who MiCA applies to, the capital rules for stablecoins, how crypto businesses get authorised, and where DeFi, staking, and NFTs fit in. It closes on 31 August 2026.

MiCA itself requires this kind of check. Article 140, a section of the regulation, says the Commission must report its findings to the European Parliament by 30 June 2027. If that report says changes are needed, the Commission can then propose a new law.

This matters for any CASP (crypto-asset service provider) that just got authorised. The rules it followed to get authorised could still change within the next eighteen months.

Two specific issues have already come up in public discussion about this review.

  • No asset-referenced token, a stablecoin backed by a mix of currencies or other assets, has been authorised anywhere in the EU since these rules started in June 2024. Some people involved in the consultation see this as a sign that the capital requirements for asset-referenced tokens are set too high. Their reasoning: if a requirement has gone unmet for two years, it may be harder to satisfy than intended.
  • MiCA currently bans stablecoin issuers from paying interest to people who hold their stablecoins. This rule exists so stablecoins can’t compete with bank savings accounts by offering better returns. The Commission is now asking whether this ban should stay in place.

MiCA timeline: June 2024–July 2026, with EU review consultation from May–August 2026

Who needs a MiCA licence, and what does CASP authorisation require?

Any CASP serving EU clients needs authorisation from a national competent authority in one EU member state, and that single authorisation then passports across all 27.

The authorisation and passporting process

The application has to show a real business plan, a governance structure, a cybersecurity policy, and proof of sufficient own funds, where capital thresholds vary by the specific service the CASP provides. National competent authorities have three months to grant or refuse a complete application. Once authorised, a CASP can serve clients in every member state without a second national licence, which is the main commercial reason firms pursue MiCA authorisation instead of staying in one market.

As of mid-2026, legal trackers following ESMA’s public CASP register put the count at roughly 170 authorised providers across 18 member states, which is evidence that the passporting system is now working at scale rather than sitting on paper.

What happens if a CASP misses the deadline

A CASP still operating under a national transitional arrangement after 1 July 2026 has to stop serving EU clients immediately, per ESMA’s April 2026 statement on the end of the transitional periods. There’s no grace window and no case-by-case extension. National competent authorities enforce against non-compliant firms, and for a client caught on the wrong side of that line, the consequences could include account restrictions, withdrawal delays, and loss of access to funds during a wind-down the CASP didn’t plan for.

CASPs must run anti-money-laundering checks from the day they get authorised

Once a CASP gets MiCA authorisation, it automatically becomes what regulators call an “obliged entity.” This means EU anti-money-laundering law now requires it to run four ongoing checks.

  1. Customer due diligence: Verifying who a customer is, both when they sign up and again later if something about them changes in a way that raises risk.
  2. Transaction monitoring: Watching customer transactions on an ongoing basis to spot unusual or suspicious activity.
  3. Suspicious activity reporting: If the CASP spots something suspicious, it must report it to the Financial Intelligence Unit, the national body that receives and investigates these reports.
  4. Sanctions and PEP screening: Checking customers against government sanctions lists and against lists of politically exposed persons, people who hold public office or have close ties to someone who does, since these customers carry higher financial-crime risk.

Travel Rule obligations under Regulation (EU) 2023/1113

MiCA doesn’t cover payment-level detail, so a second regulation fills that gap. Regulation (EU) 2023/1113, the EU’s recast Transfer of Funds Regulation, extends the same information-sharing rule that has applied to bank wire transfers for decades to crypto-asset transfers. 

When a CASP moves crypto on a client’s behalf, it has to transmit the originator’s and beneficiary’s identifying information to the receiving CASP, and the obligation applies to every qualifying transfer regardless of amount. The European Banking Authority published final guidelines on the rule in July 2024, setting out what a CASP has to do when the accompanying information is missing or incomplete.

Why regulators focus here
Tom Gadsden, VP of Product at Shufti, described the tension this way in an interview on Brave New Coin’s The Crypto Conversation podcast: crypto was built to remove intermediaries, but wherever it meets fiat on-ramps and off-ramps, governments have made clear they want visibility into where the money goes. He points to Europe’s PSD2 card-payment rules a decade earlier as the closest parallel, a moment when regulators decided the losses the industry had quietly absorbed were a cost the wider economy shouldn’t have to carry.

What are the MiCA stablecoin rules for ARTs and EMTs?

MiCA splits stablecoins into two categories, and the rules diverge sharply on capital, redemption, and who can issue them.

Requirement E-money token (EMT) Asset-referenced token (ART)
Reference asset Single fiat currency Basket of currencies, commodities, or other assets
Issuer licence E-money or credit institution, plus a MiCA whitepaper Fresh MiCA ART authorisation
Reserve backing Full liquid-asset backing Reserve of assets, calibrated to the basket
Redemption At par value, in fiat, at any time At the reserve’s current market value
Interest to holders Prohibited Prohibited
Authorised in the EU, mid-2026 Multiple issuers, including USDC, EURC, and EURI None

The gap in that last row isn’t a coincidence. ART capital and prudential requirements sit well above EMT requirements, and that’s exactly one of the questions the Commission’s review consultation is asking about. Every euro or dollar-backed stablecoin authorised under MiCA to date has taken the EMT route, because referencing a single currency, rather than a basket, keeps the capital bar lower. 

The interest ban applies to both categories without exception, so a business model built around paying holders interest or a staking-style reward on stablecoin balances runs into a structural wall here, not a paperwork delay.

Does MiCA regulation apply to DeFi protocols?

MiCA excludes fully decentralised protocols that have no identifiable issuer or intermediary, but that exemption is narrower than most teams assume.

In practice, “fully decentralised” has a specific meaning. A protocol with a governance token, a legal entity anywhere in its structure, or a treasury someone controls is unlikely to qualify. ESMA continues to review where exactly that perimeter sits, and the Commission’s review consultation lists DeFi as one of the areas it’s actively reconsidering. Teams that treat the DeFi exclusion as a broad safe harbour, without a specific legal review of the protocol’s actual governance structure, make the mistake that shows up most often in the compliance briefings covering this question.

How Shufti helps crypto businesses meet MiCA compliance requirements

Obliged-entity status is easy to explain, but hard to run in practice. The AML programme it triggers has to work across onboarding, ongoing transaction monitoring, and Travel Rule data exchange at once, and most compliance teams end up stitching that together from separate vendors with no shared audit trail.

Shufti’s AML screening covers 4,000+ watchlists and 215+ sanctions regimes, spanning all four PEP tiers and adverse media in 80+ languages, in the same decisioning layer that handles onboarding and ongoing monitoring. Its Transaction Trust Monitoring captures and matches originator and beneficiary data for Travel Rule reporting through that same layer, instead of a separate vendor integration. 

See how Shufti’s AML and Travel Rule stack holds up against your MiCA compliance programme on real onboarding data, book a 20-minute demo.

Frequently Asked Questions

What is MiCA regulation, and who does it apply to?

MiCA, Regulation (EU) 2023/1114, is the EU's single legal framework for crypto-asset issuers and service providers. It applies to anyone issuing crypto-assets or providing crypto-asset services to EU clients, including exchanges, custody providers, portfolio managers, and advisers, regardless of where the business is headquartered.

When does MiCA come into full force?

MiCA phased in across three dates. Stablecoin rules applied from 30 June 2024, rules for crypto-asset service providers applied from 30 December 2024, and the transitional period for CASPs operating under old national licences closed on 1 July 2026, with no national fallback left after that.

Who needs a MiCA licence to operate in the EU?

Any crypto-asset service provider serving EU clients needs MiCA authorisation from a national competent authority in one EU member state. CASPs licensed under national law before 30 December 2024 could operate under an 18-month transitional arrangement, but that window closed on 1 July 2026 and was not extended.

Does MiCA apply to DeFi protocols?

MiCA excludes protocols that are fully decentralised, with no identifiable issuer or intermediary. In practice that exemption is narrow. A protocol with a governance token, a legal entity, or a controlled treasury is unlikely to qualify, and ESMA continues to review exactly where that perimeter sits.

What happens if a CASP misses the July 2026 deadline?

A CASP still operating under a national transitional arrangement after 1 July 2026 has to stop serving EU clients immediately, per ESMA's April 2026 statement. National competent authorities enforce against non-compliant firms, and affected clients can face account restrictions, withdrawal delays, and loss of access to funds during an unplanned wind-down.

What are the KYC and AML requirements under MiCA?

Once authorised, a CASP automatically becomes an obliged entity under EU AML law. That means customer due diligence at onboarding and at risk-trigger events, ongoing transaction monitoring, suspicious activity reporting, and sanctions and PEP screening, all required from day one with no grace period.

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Join the
Shufti Sphere Newsletter

Get the latest trends, insights, and expert opinions on KYC, AML, fraud prevention, and more, straight to your inbox.

    Pitch a piece and get a verified byline in the Media room.

    Partnership Inquiries?
    Email us at [email protected]

    iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
    Copyright © 2026 Shufti. All rights reserved.