[codicts-css-switcher id=”346″]

Global Law Experts Logo
eu crypto licence wall

Our Expert in Malta

The Eu's Crypto Licence Wall: Operating After Mica's Grandfathering Cut-off

By Global Law Experts
– posted 2 hours ago

The EU’s crypto licence wall operating after MiCA’s grandfathering deadline is now a hard commercial reality, not a future risk. Article 143 of the Markets in Crypto-Assets Regulation (Regulation (EU) 2023/1114, “MiCA”) provided for a transitional window that member states could shorten, with the maximum transitional period ending on 1 July 2026. The European Securities and Markets Authority (ESMA) has encouraged national authorities to limit the length of transitional regimes. Firms that continue to serve clients in the European Union or the European Economic Area (EEA) without a crypto-asset service provider (CASP) authorisation risk operating outside the regulatory perimeter, and national supervisors have signalled that they intend to act.

This practical, Malta-focused guide explains who must be authorised, what enforcement looks like across member states, how Malta functions as an authorisation and passporting hub, and how boards should choose between authorisation, partnership and withdrawal.

Lede, what changed under MiCA’s transition and why the crypto licence wall matters

Understanding the EU’s crypto licence wall operating after the MiCA cut-off starts with the transitional framework. MiCA introduced a single, harmonised authorisation regime for crypto-asset services across the EU/EEA, replacing the previously fragmented patchwork of national regimes. The CASP rules in Title V began to apply from 30 December 2024. Article 143 allowed firms that had been lawfully providing crypto-asset services under national law before that date to continue during a transitional period, the length of which each member state could set up to a maximum ending on 1 July 2026. Once a member state’s transitional period expires, providing crypto-asset services to clients in that market requires either a MiCA CASP authorisation or a clearly evidenced exemption.

The practical effect is stark. Only firms that have obtained MiCA authorisation hold the internal-market passport that permits cross-border servicing. A growing number of CASPs across the EU/EEA now hold that passport, and ESMA maintains a public register of authorised providers; every other firm still serving EU clients after its market’s transitional period ends is doing so outside the regulatory perimeter. National regulators have moved to communicate their expectations, with several authorities publishing guidance on the end of transitional arrangements. For exchanges, wallet providers, token issuers and payment institutions with any EU footprint, the decision to authorise, partner or exit can no longer be deferred.

Who must be authorised: scope and service-by-service map

MiCA defines a crypto-asset service provider by reference to the specific services it performs. If your business provides one or more of these services to persons established in the EU/EEA, you fall within scope unless a narrow exemption applies. The question is not only whether you are established in the EU, it is whether you are offering regulated services into the EU market.

MiCA definitions and which activities trigger authorisation

MiCA sets out an exhaustive list of crypto-asset services. The activities that most commonly trigger the need for authorisation include:

  • Operation of a trading platform. Running a venue where third parties can buy and sell crypto-assets.
  • Exchange of crypto-assets. Exchanging crypto-assets for funds or for other crypto-assets, including dealing on own account against clients.
  • Custody and administration. Safekeeping or controlling crypto-assets, or the means of access to them (such as private keys), on behalf of clients.
  • Reception and transmission of orders for crypto-assets on behalf of clients.
  • Execution of orders for crypto-assets on behalf of clients.
  • Placing of crypto-assets, and providing advice or portfolio management on crypto-assets.
  • Providing transfer services for crypto-assets on behalf of clients.

Token issuance and public offers are treated separately under MiCA’s offer and admission rules, but where a firm intermediates the distribution of tokens it may still perform a CASP service. The clearest way to assess your position is to ask two questions: do you provide any listed service to EU/EEA clients, and does your entity appear on ESMA’s register of MiCA-authorised CASPs? If the answer to the first is yes and the second is no, you are inside the crypto licence wall and need to act.

Examples by business model

An exchange offering fiat-to-crypto and crypto-to-crypto trading pairs to EU users clearly requires authorisation to operate a trading platform and to exchange crypto-assets. A custodial wallet provider holding private keys for EU clients requires authorisation for custody and administration. A token issuer that also runs a distribution channel or facilitates secondary trading needs to consider both the offer rules and the CASP services being performed. A payment institution embedding a crypto-to-fiat conversion feature for EU customers is very likely providing an exchange service and cannot rely on its existing payments licence to cover the crypto activity.

Consequences for firms that missed the deadline, enforcement and remedies

The EU’s crypto licence wall operating after the deadline is enforced at national level. MiCA harmonises the substantive rules, but supervision and enforcement remain in the hands of national competent authorities, coordinated through ESMA and the European Banking Authority. That means the tools available to regulators, and the appetite to use them, vary by member state, but the underlying prohibition is uniform: unauthorised provision of crypto-asset services to EU/EEA clients is unlawful once the applicable transitional period has ended.

Member-state enforcement examples

National supervisors have a familiar toolkit. Depending on the jurisdiction and its implementing legislation, enforcement may include:

  • Cease-and-desist orders requiring the firm to stop offering services immediately.
  • Administrative fines calibrated to the gravity of the breach and, in some cases, to turnover.
  • Public warnings naming the firm and alerting consumers, with significant reputational impact.
  • Injunctions and website-blocking measures against firms marketing into the jurisdiction.
  • Criminal exposure, where national implementing law provides for it.

Several national authorities have published communications confirming that unauthorised provision of crypto-asset services after the transitional deadline is prohibited and setting out the supervisory consequences. Because national supervisors cooperate across borders through ESMA’s coordination mechanisms, a firm cannot assume that operating from one member state shields it from action initiated elsewhere. For non-EU firms with EU clients, the exposure is real: passive presence in the market, an accessible website, EU-language marketing, or active onboarding of EU residents, may be scrutinised.

Practical immediate steps if you find yourself non-compliant

If you conclude that you are serving EU/EEA clients without authorisation, the priority is to reduce ongoing exposure while preserving optionality. Practical first steps include mapping your EU client base and revenue, pausing active marketing into the EU, documenting the decision-making, and taking legal advice on whether to submit an authorisation application, transition clients to an authorised partner, or wind down EU servicing in an orderly way. Doing nothing is the highest-risk option, because continued unauthorised activity compounds the breach and weakens any future engagement with a supervisor.

Malta as an authorisation hub, VFA Act interaction and passporting mechanics

Malta was an early mover in crypto regulation and remains a credible authorisation hub within the crypto licence wall operating after MiCA. Its Virtual Financial Assets Act (Chapter 590 of the Laws of Malta, the “VFA Act”), supervised by the Malta Financial Services Authority (MFSA), established a licensing regime for virtual financial asset services before MiCA existed. With MiCA now the governing EU framework, Malta’s prior experience translates into supervisory familiarity and an established pathway for firms seeking a MiCA CASP authorisation with an EU/EEA passport.

How passporting works under MiCA

The commercial value of MiCA authorisation is the single-market passport. Once a firm is authorised as a CASP in its home member state, it can provide the services covered by its authorisation across the EU/EEA either through the freedom to provide services (cross-border, without a local establishment) or through the freedom of establishment (a branch in another member state). Passporting operates through a notification procedure: the authorised CASP notifies its home supervisor of the member states in which it intends to operate, and the home authority communicates that information to the host authorities. Home-state supervision remains the anchor, with host authorities retaining defined powers.

The result is that a single authorisation obtained in Malta can support servicing clients throughout the Union.

Malta-specific advantages and practical steps to apply

Firms consider Malta for CASP authorisation for several reasons: an English-language legal and administrative environment, a supervisor with a track record in crypto and fintech authorisations, and an ecosystem of advisers, auditors and service providers experienced in digital-asset regulation. The MFSA sets clear supervisory expectations covering governance, prudential soundness, custody, and anti-money-laundering controls, and it expects a well-prepared, complete application. In practice, firms should engage early with the supervisor, align their VFA Act experience where relevant with MiCA requirements, and ensure that internal policies are drafted to MiCA standards rather than to legacy national rules. Because the VFA Act and MiCA are not identical, it is essential to map obligations precisely and avoid conflating the two regimes.

MiCA application checklist, capital, governance, custody and AML (regulator-ready)

A regulator-ready application is the single biggest determinant of how quickly a firm crosses the crypto licence wall operating after MiCA. Supervisors expect a coherent, evidence-backed file that demonstrates the firm is financially sound, well governed, operationally resilient and compliant with anti-money-laundering standards. The checklist below reflects the core pillars MiCA requires.

Capital and prudential requirements

MiCA requires CASPs to hold prudential safeguards calibrated to the services they provide. Applicants must maintain own funds at least equal to the higher of a minimum capital requirement fixed by reference to the class of services offered, or an amount based on one quarter of the preceding year’s fixed overheads. MiCA permits the prudential safeguard to be met through own funds, an insurance policy or a comparable guarantee, subject to conditions. The minimum capital threshold scales with the risk of the service, a firm operating a trading platform or providing custody sits at the higher end, while a firm providing only advice or order transmission sits lower.

Applicants should present a clear own-funds calculation, a fixed-overheads calculation, and evidence that capital is in place and will remain so under stressed scenarios.

Prudential element What regulators expect
Minimum capital Held according to the service category as set out in MiCA, evidenced at application and maintained on an ongoing basis.
Fixed-overheads requirement Calculation based on the firm’s projected operating expenses, with supporting financial projections.
Own funds composition Eligible instruments demonstrably available; no double counting; audited or verifiable evidence.
Insurance or guarantee (where used) Policy or guarantee meeting MiCA conditions, with scope and limits aligned to the services provided.

Governance and senior management requirements

MiCA requires CASPs to have robust governance arrangements, including a clear organisational structure, a competent and reputable management body, and effective risk management. Applicants must demonstrate that members of the management body and qualifying shareholders are fit and proper, of good repute, with the knowledge, skills and experience appropriate to their roles. Regulators will look for defined reporting lines, segregation of duties, a risk-management function, an internal audit or compliance function proportionate to the firm’s size, and evidence of substantive local presence and decision-making. A frequent deficiency is a governance model that exists only on paper, with key functions outsourced to entities outside the EU and no genuine local control.

Custody and crypto private-key management

Where a firm holds clients’ crypto-assets, MiCA imposes strict custody obligations. Client assets must be segregated from the firm’s own assets, held in a way that protects clients in the event of the firm’s insolvency, and safeguarded against loss arising from fraud, cyber threats or operational failure. Applicants should describe their custody architecture in detail: the split between hot and cold storage, key-generation and key-management procedures, multi-signature or equivalent controls, backup and recovery arrangements, and the register of client positions. Supervisors treat opaque custody descriptions as a serious red flag, so the file must show precisely how private keys are generated, stored, accessed and recovered, and who within the organisation has control.

AML/CFT controls and FATF alignment

Anti-money-laundering and counter-terrorist-financing (AML/CFT) compliance is central to any CASP application. Crypto-asset service providers are treated as obliged entities and must apply the controls that the Financial Action Task Force (FATF) sets for virtual-asset service providers (VASPs), as implemented in EU and national law. In Malta, this includes compliance with the Prevention of Money Laundering Act, related regulations, and guidance issued by the Financial Intelligence Analysis Unit (FIAU). Applicants should present a documented AML/CFT framework including:

  • Customer due diligence (CDD) and know-your-customer (KYC) procedures, including enhanced due diligence for higher-risk relationships.
  • Ongoing transaction monitoring with defined typologies and escalation procedures.
  • The travel rule, collection and transmission of originator and beneficiary information for transfers, consistent with EU transfer-of-funds requirements and FATF’s risk-based approach.
  • Sanctions screening against relevant lists at onboarding and on an ongoing basis.
  • Suspicious-transaction reporting and a designated money laundering reporting officer with sufficient seniority and independence.
  • A firm-wide business risk assessment that informs the calibration of controls.

Applicants should also supply supporting documents: a programme of operations, a business plan and financial projections, the organisational chart, policies for governance, custody, complaints, conflicts of interest, business continuity and cybersecurity, and the AML/CFT manual. A complete, internally consistent documentation set is what distinguishes an application that clears quickly from one that stalls.

Reverse solicitation, what it really allows and how to evidence it

Many firms hope that reverse solicitation will let them keep serving EU clients without confronting the crypto licence wall operating after the deadline. That hope is usually misplaced. Reverse solicitation is a narrow carve-out, not a business model, and national supervisors interpret it strictly.

Reverse solicitation test and evidentiary checklist

The core principle is that where a client established in the EU initiates, entirely at its own exclusive initiative, the provision of a crypto-asset service by a third-country firm, the service is not treated as being provided in the Union. The initiative must be genuine and client-driven. Crucially, the exemption does not extend to services or crypto-assets beyond the one the client sought, and it cannot be used to market other products. To rely on it, a firm should maintain contemporaneous evidence:

  • Records showing the client made the first approach, unprompted.
  • An audit trail of the communications, timestamped and preserved.
  • Documentation confirming the firm did not solicit, advertise or promote the service to that client or to the EU market generally.
  • Controls preventing cross-selling of additional services under cover of the initial request.

When reverse solicitation fails and what that means

Reverse solicitation fails the moment there is active marketing. A firm cannot advertise into the EU, run targeted campaigns, or maintain EU-facing onboarding funnels and then claim that clients arrived on their own initiative. Supervisors look at the substance of the relationship, and the burden of proof rests with the firm. Where the carve-out fails, the firm is providing unauthorised services and is exposed to the full range of enforcement measures. Treating reverse solicitation as a systematic route to the EU market is therefore a high-risk strategy that few advisers would recommend as anything more than a tightly documented exception.

Decision framework, authorise, partner with an authorised CASP, or withdraw

Once a firm has mapped its exposure, the board faces a strategic choice. The right answer depends on the size of the EU opportunity, the firm’s tolerance for cost and control trade-offs, and the speed with which it needs market access.

Option Time to implement Capital / fee magnitude Control over compliance Passporting ability Best for
Authorisation (MiCA CASP) 6–12+ months High (own funds plus application costs) Full control Full EU/EEA passporting Firms committed to the EU market long-term
Partnership with authorised CASP Typically a few months (commercial onboarding) Medium (commercial fees / revenue share) Shared; risk allocated by contract Passporting via the partner Firms needing faster access without a licence
Withdrawal Weeks (client notice and orderly exit) Low direct cost; revenue and reputational loss No control over EU servicing None Firms exiting the EU or with immaterial exposure

Selecting a partner CASP, commercial and regulatory checklist

Partnering with an authorised CASP can be a faster route to compliant EU access, but it transfers dependency rather than eliminating risk. Due diligence is essential. Confirm the partner’s authorisation status and the exact scope of services it covers, verify its passporting notifications for the member states you target, and assess its financial stability and operational resilience. The commercial contract should allocate regulatory responsibility clearly, define liability for compliance failures, address data protection and client-asset arrangements, and provide for orderly termination. A partner whose licence does not actually cover your intended activities offers false comfort, so the mapping of your services to the partner’s authorisation must be precise.

Withdrawal and wind-down checklist for EU clients

Where the EU opportunity does not justify the cost of authorisation and no suitable partner exists, an orderly exit is the responsible choice. A wind-down should include clear, timely notice to EU clients, arrangements for the return or transfer of client crypto-assets and funds, cessation of EU-facing marketing and onboarding, retention of records, and internal documentation of the decision. A disorderly exit that leaves clients without access to their assets can itself attract supervisory attention, so the process must be planned and executed carefully.

Building an application file a regulator will accept, practical tips and common pitfalls

The difference between a smooth authorisation and a protracted one is almost always the quality of the file. Supervisors repeatedly identify the same deficiencies: weak or generic AML frameworks, opaque custody and key-management descriptions, under-resourced governance and compliance functions, missing or unconvincing prudential calculations, and unclear statements of which services and which markets the firm actually intends to serve.

Pre-submission engagement and typical timelines

Early, structured engagement with the home supervisor pays dividends. A pre-application dialogue allows the firm to test its business model, clarify supervisory expectations and identify gaps before formal submission. Realistic timelines run from six to twelve months or more from submission, driven heavily by file completeness and responsiveness to supervisory questions. A well-prepared file with credible governance, a clear custody model and a robust AML framework can move materially faster than one that triggers repeated rounds of clarification.

Sample timeline and milestone map

A practical roadmap runs from exposure assessment and strategy decision, through pre-application engagement and policy drafting, to formal submission, supervisory review and clarification, authorisation, and finally passporting notifications for target markets. Building assurance work, such as independent reviews of custody or AML controls, into the early stages strengthens the file and reduces the risk of late-stage challenge.

Final checklist and next steps for boards and senior management

Navigating the EU’s crypto licence wall operating after MiCA’s grandfathering cut-off is now a governance responsibility, not a technical footnote. Boards and senior management should act on a clear, prioritised list:

  • Map all EU/EEA clients, revenue and marketing activity to establish exposure.
  • Confirm whether the entity appears on ESMA’s register of MiCA-authorised CASPs.
  • Pause active EU marketing and onboarding where the firm is unauthorised.
  • Decide between authorisation, partnership and withdrawal using a documented cost-benefit analysis.
  • Where authorising, begin pre-engagement with the supervisor and build a complete, MiCA-standard application file.
  • Where partnering, run full due diligence and align the partner’s licence scope with intended activities.
  • Where exiting, plan an orderly wind-down that protects client assets.
  • Document every decision to evidence good faith and reduce enforcement risk.

For firms weighing Malta as an authorisation base, the combination of MFSA supervisory experience and full EU/EEA passporting makes it a serious contender. Tailored legal advice is essential, because the right path depends on each firm’s activities, footprint and appetite for the EU market. Global Law Experts can connect firms and their advisers with Malta cryptocurrency and blockchain specialists to assess exposure and build a compliant strategy.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Anton Dalli at A2CO, a member of the Global Law Experts network.

Sources

  1. Regulation (EU) 2023/1114 (Markets in Crypto-Assets, MiCA), Official Journal
  2. European Securities and Markets Authority (ESMA), Markets in Crypto-Assets (MiCA) hub
  3. European Commission, MiCA (Markets in Crypto-Assets) overview
  4. Malta Financial Services Authority (MFSA)
  5. Financial Intelligence Analysis Unit (FIAU), Malta
  6. Financial Action Task Force (FATF), Guidance on Virtual Assets and VASP Risk-Based Approach

FAQs

When did MiCA's grandfathering period end?
MiCA’s CASP rules began to apply from 30 December 2024. Article 143 allowed firms already operating under national law to continue during a transitional period set by each member state, with the maximum period ending on 1 July 2026. Firms that are not MiCA-authorised and continue offering crypto-asset services once their market’s transitional period has ended are operating outside the regulatory perimeter and face enforcement risk. You should confirm the exact transitional deadline that applied in each relevant member state.
Any firm offering crypto-asset services to EU/EEA clients as defined by MiCA, including exchanges, custodians, portfolio managers, trading platforms and firms intermediating token distribution, must be authorised, unless a narrow exemption genuinely applies. The test is whether you provide a listed service into the EU market, not only where you are established.
Only in very limited circumstances. Reverse solicitation is narrowly construed: it requires genuine, client-initiated contact with contemporaneous evidence, and it does not extend to marketing or cross-selling. Supervisors scrutinise such claims closely and treat any active marketing into the EU as requiring authorisation, so it is not a viable systematic route to market.
Timelines vary with the quality and completeness of the application. A realistic expectation is six to twelve months or more from submission. Early pre-engagement with the MFSA and a complete, MiCA-standard file covering governance, custody, prudential requirements and AML controls can meaningfully shorten the review.
Under the crypto licence wall operating after the cut-off, a non-EU firm has three main options: seek MiCA authorisation by establishing an EU entity, partner with an authorised CASP that passports the relevant services, or withdraw from EU clients in an orderly way. Each involves trade-offs in time, cost and control, which the decision framework in this guide sets out.
Enforcement is a matter for national competent authorities, and approaches vary. Available measures include public warnings, supervisory reviews, cease-and-desist orders and administrative fines. Several authorities have issued guidance confirming that unauthorised provision is prohibited once the transitional period ends. Criminal exposure depends on each member state’s implementing legislation.
Amit Mishra Joins as Exclusive Commercial Litigation Member in India | GLE News
By Global Law Experts

posted 2 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

The Eu's Crypto Licence Wall: Operating After Mica's Grandfathering Cut-off

Send welcome message

Custom Message