Compliance11 min read
MB
Editorial Team
·August 3, 2026

What Happens After the MiCA Transitional Period Ended?

The MiCA transitional period ended on 1 July 2026, after which any entity providing crypto-asset services to EU clients without authorisation is in breach of EU law and must cease. Firms that had operated under national regimes since before 30 December 2024 could rely on grandfathering until that date, or until authorisation was granted or refused, whichever came sooner. In a public statement on 23 June 2026, ESMA told unauthorised crypto-asset service providers to stop onboarding immediately, limit activity to what an orderly exit requires, and communicate a wind-down timeline to clients — and reminded those clients that they no longer benefit from MiCA safeguards, including protections for client assets. This guide covers what the deadline changed, what ESMA expects during wind-down, and which dependencies a tokenized asset program needs to re-check.

TL;DR — Key Takeaways

  • The Date: 1 July 2026. Grandfathering for CASPs operating under national regimes before 30 December 2024 ended; no member state could extend past it, and several ended earlier.
  • The Consequence: Providing crypto-asset services to EU clients without MiCA authorisation is a breach of EU law. Services must cease.
  • ESMA's Wind-Down Test: Stop onboarding and marketing immediately; limit services to selling, transferring, reallocating or closing positions; custody only for as long as an orderly exit strictly requires.
  • What Clients Lost: Clients of unauthorised CASPs do not benefit from MiCA safeguards, including client-asset protections — whether the provider is an EU or non-EU entity.
  • The Supply-Chain Trap: MiCA bars CASPs from delegating certain services, notably custody, to entities that are not authorised CASPs. An authorised provider with an unauthorised sub-custodian is non-compliant.

Ready to get started?

Join others who are already using our platform.

What Happens After the MiCA Transitional Period Ended?

A Deadline That Removed an Option Rather Than Adding a Rule

The MiCA transitional period expired on 1 July 2026. From that date, a firm providing crypto-asset services to EU clients without MiCA authorisation can no longer rely on a previous national regime, and is in breach of EU law. Nothing in the substantive rulebook changed on that day — what ended was the permission to operate outside it.

That distinction is why the deadline caught firms that had followed MiCA's development closely. The obligations had been readable for years. The transitional period made them optional for incumbents, and an optional obligation gets scheduled behind whatever is not optional. When the option closed, the gap between a firm's roadmap and its legal position closed with it, in one step, on a fixed date.

“While a number of CASPs will have obtained authorisation by 1 July 2026, other entities, including significant providers currently servicing EU clients under national regimes, may not be authorised by the deadline.”

— ESMA public statement, 23 June 2026 (ESMA75-113276571-1710)

“Significant providers” is the phrase worth pausing on. ESMA was not describing a fringe of small unlicensed operators; it anticipated that material firms with real EU client books would reach the deadline unauthorised. For anyone whose tokenized program depends on an EU service provider, that is a statement about counterparty risk, not about someone else's compliance problem.

How the Grandfathering Clock Actually Ran

CASPs that provided services in accordance with applicable law before 30 December 2024 could continue until 1 July 2026, or until authorisation was granted or refused, whichever came sooner. Member states were free to shorten or waive that window, so the operative deadline varied by country — but 1 July 2026 was the outer boundary no member state could push past.

The “whichever came sooner” clause is the part that surprised firms. Grandfathering did not run to the calendar date regardless; it ran until the application was decided. A refusal in early 2026 ended the transitional protection immediately, months before the headline deadline, and a firm that had planned around July found itself unauthorised in March.

DateWhat it established
30 December 2024MiCA became fully applicable; the cut-off for qualifying for grandfathering as an existing provider
17 April 2026ESMA statement clarifying supervisory expectations for the end of the transitional periods
23 June 2026ESMA public statement setting out wind-down expectations and warning consumers
1 July 2026Outer boundary of grandfathering across the EU; unauthorised provision to EU clients becomes a breach

The wider framework these dates sit inside — token classification, authorisation routes, whitepaper obligations and passporting — is set out in navigating MiCA regulations for compliant RWA tokenization. This article covers only what the deadline changed.

What ESMA Requires of an Unauthorised Provider

ESMA expects unauthorised CASPs to take immediate steps to wind down EU activities in an orderly manner while safeguarding client interests and mitigating risks to market integrity. The statement specifies three obligations, and each is drawn narrowly enough to be tested.

1. Stop taking on anything new

Immediately stop onboarding new EU clients, refrain from opening new client relationships or accounts, and cease marketing activities and solicitation.

2. Shrink the service to the exit

Limit services to what is necessary to sell or transfer crypto-assets, reallocate assets, or close positions. Custody of clients' crypto-assets can only continue for the period strictly necessary to complete an orderly exit.

3. Tell clients the timeline

Communicate clearly, promptly and repeatedly with retail and institutional clients about safeguarding measures and wind-down plans, including a deadline by which any residual positions would be closed automatically.

4. Keep AML controls running

Maintain effective AML and CFT controls throughout the wind-down: customer due diligence, transaction monitoring, sanctions screening, suspicious activity reporting, record-keeping, and transfer traceability obligations.

5. Hand over cleanly

Where clients transfer to a MiCA-authorised CASP, the onboarding CASP carries out all necessary onboarding procedures, including customer due diligence and other required AML and CFT checks.

Key Insight

Item four is the one that gets underestimated. A firm winding down has every incentive to shed cost, and the AML function is expensive, unglamorous, and apparently pointless once no new clients are arriving. ESMA closed that reasoning off explicitly: the controls run throughout the process. A wind-down is a period of unusually high AML risk — clients moving assets at speed, positions closing under deadline pressure — and it is precisely when a degraded control environment produces the transactions a supervisor will ask about afterwards.

What Clients Lose, and What They Are Told to Do

ESMA reminded clients of unauthorised CASPs, whether EU or non-EU entities, that they do not benefit from MiCA safeguards, including protections for client assets. It invited clients using crypto-asset services in the EU to verify whether their provider is authorised in the ESMA Register and to act promptly where it is not — by transferring assets to an authorised CASP where one is identified, or to a self-hosted wallet.

The instruction to move to a self-hosted wallet is worth reading carefully, because a European supervisor does not casually tell retail clients to take custody of their own assets. It is what remains when the alternative is leaving assets with an entity that is outside the supervisory perimeter and under an obligation to shut down. The advice measures how little protection an unauthorised provider offers rather than expressing enthusiasm for self-custody.

Safeguard under MiCAPosition with an unauthorised provider
Segregation of client assetsNot available; assets sit wherever national law and the firm's own practice put them
Custody policy and individual position registerNo MiCA-mandated policy, client agreement, or register of positions
Liability for loss through operational failureNo MiCA liability standard to fall back on
Governance and organisational requirementsOutside the authorisation perimeter, so unsupervised against them
Supervisory recourse via an NCAThe NCA's interest is enforcement and wind-down, not client remediation

The Dependency Check a Tokenized Program Owes Itself

The exposure that matters for an issuer is rarely its own authorisation status, which it knows. It is the authorisation status of everything it depends on — and MiCA makes that a chain rather than a checkbox: CASPs are prohibited from outsourcing or delegating certain services, notably custody, to entities that are not authorised as CASPs.

So an authorised provider that sub-delegates custody to an unauthorised entity is itself in breach, and the issuer relying on that provider has a problem it did not create and cannot see from the provider's registration status alone. Checking the counterparty in the ESMA Register is necessary and insufficient. The question is who actually holds the assets at the end of the chain.

Check now

  • Every EU-facing provider against the ESMA Register
  • Whether custody is sub-delegated, and to whom
  • Whether authorisation was granted or refused, not just applied for
  • Which member state deadline actually applied

Warning signs

  • “Authorisation pending” presented as compliance
  • A non-EU entity serving EU clients on a reverse-solicitation theory
  • Marketing into the EU alongside a client-initiative claim
  • No named sub-custodian anywhere in the documentation

Out of scope here

  • Financial instruments under MiFID II, not MiCA
  • Programs with no EU clients or marketing
  • The DLT Pilot Regime, a separate framework
  • National regimes outside the EU

One boundary is worth stating plainly, because it is the most common misreading: a tokenized security is generally a financial instrument regulated under MiFID II and the securities regime, not a crypto-asset under MiCA. The DLT Pilot Regime, covered in the EU DLT Pilot Regime reform, is the framework built for those instruments. MiCA still reaches most tokenized programs indirectly, through the service providers, stablecoins, and custody arrangements they depend on.

How Blockmaze Makes Authorisation Dependencies Visible

No protocol grants authorisation, and none substitutes for it. What a compliance layer can do is make the program's dependence on a counterparty's regulatory status an explicit, monitored parameter rather than an assumption that surfaces the week a deadline expires.

Counterparty Status Recorded

Each service provider's authorisation, jurisdiction, and the date it was last verified are recorded against the program, so a lapse registers as a change rather than staying invisible.

Delegation Chain Disclosed

Where custody is sub-delegated, the entity at the end of the chain is named, since MiCA bars delegation of custody to entities that are not authorised CASPs.

Jurisdictional Eligibility Enforced

Investor eligibility rules evaluate the holder's jurisdiction at the protocol level, so an instrument that may not be offered into the EU cannot settle to an EU holder.

Migration Without Reconstruction

Because holdings and their eligibility evidence are attributable on-chain, moving clients to a new authorised provider is a transfer of records rather than a re-onboarding from scratch.

The general lesson generalises past this deadline. Authorisation is a state that changes — granted, refused, lapsed, withdrawn — and a program that treats it as a fact established at launch is carrying an unmonitored risk. The same pattern in other jurisdictions is examined in navigating cross-border RWA regulatory challenges.

Re-Checking Your EU Compliance Dependencies?

Blockmaze provides the compliance layer that records counterparty authorisation status, discloses delegation chains, and enforces jurisdictional eligibility at the protocol level rather than in a policy document.

Frequently Asked Questions

When exactly did the MiCA transitional period end?

On 1 July 2026. Crypto-asset service providers that were operating lawfully under national regimes before 30 December 2024 could continue under grandfathering until 1 July 2026, or until authorisation was granted or refused, whichever came sooner. Individual member states were permitted to shorten or waive the transitional period, so some national deadlines fell earlier — but 1 July 2026 was the hard outer boundary that no member state could extend. ESMA confirmed the date in a public statement issued on 23 June 2026, building on an earlier statement of 17 April 2026.

What must an unauthorised CASP do now?

Wind down its EU activities in an orderly manner while safeguarding client interests. ESMA set out three specific obligations: immediately stop onboarding new EU clients, refrain from opening new client relationships or accounts, and cease marketing and solicitation; limit services to actions necessary to sell or transfer crypto-assets, reallocate assets, or close positions, with custody continuing only for the period strictly necessary to complete an orderly exit; and communicate clearly, promptly and repeatedly with both retail and institutional clients about safeguarding measures and the wind-down timeline, including a deadline by which residual positions would be closed automatically.

What protections do clients of an unauthorised provider lose?

All of them. ESMA reminded clients of unauthorised CASPs, whether EU or non-EU entities, that they do not benefit from MiCA safeguards, including protections for client assets. That is the substantive point rather than a technicality: MiCA's client-asset segregation, custody policy requirements, liability for operational loss, and governance standards attach to authorisation. An unauthorised provider holding client assets offers whatever its national law and its own balance sheet offer, which in an insolvency may be nothing.

Can a non-EU provider keep serving EU clients?

No, apart from a narrow exception. ESMA reminded CASPs established outside the EU that they cannot provide MiCA services to EU clients or solicit EU clients, and stated explicitly that this also applies in a business-to-business context. The only carve-out is where services are provided strictly at the client's own exclusive initiative under the narrow reverse solicitation regime described in ESMA's guidelines. Reverse solicitation is a narrow exemption, not a business model, and a provider that markets into the EU cannot then characterise the resulting relationships as client-initiated.

What does this mean for a tokenized asset program with EU exposure?

Every EU-facing service provider in the program has to be checked against the ESMA Register, not against its own marketing. The dependency that most often goes unexamined is custody: MiCA prohibits CASPs from outsourcing or delegating certain services, notably custody, to entities that are not authorised as CASPs. So an authorised CASP relying on an unauthorised sub-custodian is itself non-compliant, and the issuer inherits the problem. Authorisation status is a supply-chain question, not a single counterparty question.

What happens to firms that keep operating without authorisation?

They are in breach of EU law and face coordinated supervisory action. ESMA stated that it and the National Competent Authorities are directly engaged with the entities concerned and will coordinate to monitor whether significant unauthorised cross-border CASPs wind down without delay, focusing on client protection, financial stability and market integrity. ESMA and the NCAs will also work with the EBA and AMLA, and NCAs may take coordinated action against unauthorised CASPs after the transitional period. Wind-down does not suspend AML obligations either — ESMA required effective AML and CFT controls throughout the process.

Ready to get started?

Join others who are already using our platform.