The EU’s crypto licence wall operating after MiCA’s grandfathering deadline is now a hard commercial reality, not a future risk. Article 143 of the Markets in Crypto-Assets Regulation (Regulation (EU) 2023/1114, “MiCA”) provided for a transitional window that member states could shorten, with the maximum transitional period ending on 1 July 2026. The European Securities and Markets Authority (ESMA) has encouraged national authorities to limit the length of transitional regimes. Firms that continue to serve clients in the European Union or the European Economic Area (EEA) without a crypto-asset service provider (CASP) authorisation risk operating outside the regulatory perimeter, and national supervisors have signalled that they intend to act.
This practical, Malta-focused guide explains who must be authorised, what enforcement looks like across member states, how Malta functions as an authorisation and passporting hub, and how boards should choose between authorisation, partnership and withdrawal.
Understanding the EU’s crypto licence wall operating after the MiCA cut-off starts with the transitional framework. MiCA introduced a single, harmonised authorisation regime for crypto-asset services across the EU/EEA, replacing the previously fragmented patchwork of national regimes. The CASP rules in Title V began to apply from 30 December 2024. Article 143 allowed firms that had been lawfully providing crypto-asset services under national law before that date to continue during a transitional period, the length of which each member state could set up to a maximum ending on 1 July 2026. Once a member state’s transitional period expires, providing crypto-asset services to clients in that market requires either a MiCA CASP authorisation or a clearly evidenced exemption.
The practical effect is stark. Only firms that have obtained MiCA authorisation hold the internal-market passport that permits cross-border servicing. A growing number of CASPs across the EU/EEA now hold that passport, and ESMA maintains a public register of authorised providers; every other firm still serving EU clients after its market’s transitional period ends is doing so outside the regulatory perimeter. National regulators have moved to communicate their expectations, with several authorities publishing guidance on the end of transitional arrangements. For exchanges, wallet providers, token issuers and payment institutions with any EU footprint, the decision to authorise, partner or exit can no longer be deferred.
MiCA defines a crypto-asset service provider by reference to the specific services it performs. If your business provides one or more of these services to persons established in the EU/EEA, you fall within scope unless a narrow exemption applies. The question is not only whether you are established in the EU, it is whether you are offering regulated services into the EU market.
MiCA sets out an exhaustive list of crypto-asset services. The activities that most commonly trigger the need for authorisation include:
Token issuance and public offers are treated separately under MiCA’s offer and admission rules, but where a firm intermediates the distribution of tokens it may still perform a CASP service. The clearest way to assess your position is to ask two questions: do you provide any listed service to EU/EEA clients, and does your entity appear on ESMA’s register of MiCA-authorised CASPs? If the answer to the first is yes and the second is no, you are inside the crypto licence wall and need to act.
An exchange offering fiat-to-crypto and crypto-to-crypto trading pairs to EU users clearly requires authorisation to operate a trading platform and to exchange crypto-assets. A custodial wallet provider holding private keys for EU clients requires authorisation for custody and administration. A token issuer that also runs a distribution channel or facilitates secondary trading needs to consider both the offer rules and the CASP services being performed. A payment institution embedding a crypto-to-fiat conversion feature for EU customers is very likely providing an exchange service and cannot rely on its existing payments licence to cover the crypto activity.
The EU’s crypto licence wall operating after the deadline is enforced at national level. MiCA harmonises the substantive rules, but supervision and enforcement remain in the hands of national competent authorities, coordinated through ESMA and the European Banking Authority. That means the tools available to regulators, and the appetite to use them, vary by member state, but the underlying prohibition is uniform: unauthorised provision of crypto-asset services to EU/EEA clients is unlawful once the applicable transitional period has ended.
National supervisors have a familiar toolkit. Depending on the jurisdiction and its implementing legislation, enforcement may include:
Several national authorities have published communications confirming that unauthorised provision of crypto-asset services after the transitional deadline is prohibited and setting out the supervisory consequences. Because national supervisors cooperate across borders through ESMA’s coordination mechanisms, a firm cannot assume that operating from one member state shields it from action initiated elsewhere. For non-EU firms with EU clients, the exposure is real: passive presence in the market, an accessible website, EU-language marketing, or active onboarding of EU residents, may be scrutinised.
If you conclude that you are serving EU/EEA clients without authorisation, the priority is to reduce ongoing exposure while preserving optionality. Practical first steps include mapping your EU client base and revenue, pausing active marketing into the EU, documenting the decision-making, and taking legal advice on whether to submit an authorisation application, transition clients to an authorised partner, or wind down EU servicing in an orderly way. Doing nothing is the highest-risk option, because continued unauthorised activity compounds the breach and weakens any future engagement with a supervisor.
Malta was an early mover in crypto regulation and remains a credible authorisation hub within the crypto licence wall operating after MiCA. Its Virtual Financial Assets Act (Chapter 590 of the Laws of Malta, the “VFA Act”), supervised by the Malta Financial Services Authority (MFSA), established a licensing regime for virtual financial asset services before MiCA existed. With MiCA now the governing EU framework, Malta’s prior experience translates into supervisory familiarity and an established pathway for firms seeking a MiCA CASP authorisation with an EU/EEA passport.
The commercial value of MiCA authorisation is the single-market passport. Once a firm is authorised as a CASP in its home member state, it can provide the services covered by its authorisation across the EU/EEA either through the freedom to provide services (cross-border, without a local establishment) or through the freedom of establishment (a branch in another member state). Passporting operates through a notification procedure: the authorised CASP notifies its home supervisor of the member states in which it intends to operate, and the home authority communicates that information to the host authorities. Home-state supervision remains the anchor, with host authorities retaining defined powers.
The result is that a single authorisation obtained in Malta can support servicing clients throughout the Union.
Firms consider Malta for CASP authorisation for several reasons: an English-language legal and administrative environment, a supervisor with a track record in crypto and fintech authorisations, and an ecosystem of advisers, auditors and service providers experienced in digital-asset regulation. The MFSA sets clear supervisory expectations covering governance, prudential soundness, custody, and anti-money-laundering controls, and it expects a well-prepared, complete application. In practice, firms should engage early with the supervisor, align their VFA Act experience where relevant with MiCA requirements, and ensure that internal policies are drafted to MiCA standards rather than to legacy national rules. Because the VFA Act and MiCA are not identical, it is essential to map obligations precisely and avoid conflating the two regimes.
A regulator-ready application is the single biggest determinant of how quickly a firm crosses the crypto licence wall operating after MiCA. Supervisors expect a coherent, evidence-backed file that demonstrates the firm is financially sound, well governed, operationally resilient and compliant with anti-money-laundering standards. The checklist below reflects the core pillars MiCA requires.
MiCA requires CASPs to hold prudential safeguards calibrated to the services they provide. Applicants must maintain own funds at least equal to the higher of a minimum capital requirement fixed by reference to the class of services offered, or an amount based on one quarter of the preceding year’s fixed overheads. MiCA permits the prudential safeguard to be met through own funds, an insurance policy or a comparable guarantee, subject to conditions. The minimum capital threshold scales with the risk of the service, a firm operating a trading platform or providing custody sits at the higher end, while a firm providing only advice or order transmission sits lower.
Applicants should present a clear own-funds calculation, a fixed-overheads calculation, and evidence that capital is in place and will remain so under stressed scenarios.
| Prudential element | What regulators expect |
|---|---|
| Minimum capital | Held according to the service category as set out in MiCA, evidenced at application and maintained on an ongoing basis. |
| Fixed-overheads requirement | Calculation based on the firm’s projected operating expenses, with supporting financial projections. |
| Own funds composition | Eligible instruments demonstrably available; no double counting; audited or verifiable evidence. |
| Insurance or guarantee (where used) | Policy or guarantee meeting MiCA conditions, with scope and limits aligned to the services provided. |
MiCA requires CASPs to have robust governance arrangements, including a clear organisational structure, a competent and reputable management body, and effective risk management. Applicants must demonstrate that members of the management body and qualifying shareholders are fit and proper, of good repute, with the knowledge, skills and experience appropriate to their roles. Regulators will look for defined reporting lines, segregation of duties, a risk-management function, an internal audit or compliance function proportionate to the firm’s size, and evidence of substantive local presence and decision-making. A frequent deficiency is a governance model that exists only on paper, with key functions outsourced to entities outside the EU and no genuine local control.
Where a firm holds clients’ crypto-assets, MiCA imposes strict custody obligations. Client assets must be segregated from the firm’s own assets, held in a way that protects clients in the event of the firm’s insolvency, and safeguarded against loss arising from fraud, cyber threats or operational failure. Applicants should describe their custody architecture in detail: the split between hot and cold storage, key-generation and key-management procedures, multi-signature or equivalent controls, backup and recovery arrangements, and the register of client positions. Supervisors treat opaque custody descriptions as a serious red flag, so the file must show precisely how private keys are generated, stored, accessed and recovered, and who within the organisation has control.
Anti-money-laundering and counter-terrorist-financing (AML/CFT) compliance is central to any CASP application. Crypto-asset service providers are treated as obliged entities and must apply the controls that the Financial Action Task Force (FATF) sets for virtual-asset service providers (VASPs), as implemented in EU and national law. In Malta, this includes compliance with the Prevention of Money Laundering Act, related regulations, and guidance issued by the Financial Intelligence Analysis Unit (FIAU). Applicants should present a documented AML/CFT framework including:
Applicants should also supply supporting documents: a programme of operations, a business plan and financial projections, the organisational chart, policies for governance, custody, complaints, conflicts of interest, business continuity and cybersecurity, and the AML/CFT manual. A complete, internally consistent documentation set is what distinguishes an application that clears quickly from one that stalls.
Many firms hope that reverse solicitation will let them keep serving EU clients without confronting the crypto licence wall operating after the deadline. That hope is usually misplaced. Reverse solicitation is a narrow carve-out, not a business model, and national supervisors interpret it strictly.
The core principle is that where a client established in the EU initiates, entirely at its own exclusive initiative, the provision of a crypto-asset service by a third-country firm, the service is not treated as being provided in the Union. The initiative must be genuine and client-driven. Crucially, the exemption does not extend to services or crypto-assets beyond the one the client sought, and it cannot be used to market other products. To rely on it, a firm should maintain contemporaneous evidence:
Reverse solicitation fails the moment there is active marketing. A firm cannot advertise into the EU, run targeted campaigns, or maintain EU-facing onboarding funnels and then claim that clients arrived on their own initiative. Supervisors look at the substance of the relationship, and the burden of proof rests with the firm. Where the carve-out fails, the firm is providing unauthorised services and is exposed to the full range of enforcement measures. Treating reverse solicitation as a systematic route to the EU market is therefore a high-risk strategy that few advisers would recommend as anything more than a tightly documented exception.
Once a firm has mapped its exposure, the board faces a strategic choice. The right answer depends on the size of the EU opportunity, the firm’s tolerance for cost and control trade-offs, and the speed with which it needs market access.
| Option | Time to implement | Capital / fee magnitude | Control over compliance | Passporting ability | Best for |
|---|---|---|---|---|---|
| Authorisation (MiCA CASP) | 6–12+ months | High (own funds plus application costs) | Full control | Full EU/EEA passporting | Firms committed to the EU market long-term |
| Partnership with authorised CASP | Typically a few months (commercial onboarding) | Medium (commercial fees / revenue share) | Shared; risk allocated by contract | Passporting via the partner | Firms needing faster access without a licence |
| Withdrawal | Weeks (client notice and orderly exit) | Low direct cost; revenue and reputational loss | No control over EU servicing | None | Firms exiting the EU or with immaterial exposure |
Partnering with an authorised CASP can be a faster route to compliant EU access, but it transfers dependency rather than eliminating risk. Due diligence is essential. Confirm the partner’s authorisation status and the exact scope of services it covers, verify its passporting notifications for the member states you target, and assess its financial stability and operational resilience. The commercial contract should allocate regulatory responsibility clearly, define liability for compliance failures, address data protection and client-asset arrangements, and provide for orderly termination. A partner whose licence does not actually cover your intended activities offers false comfort, so the mapping of your services to the partner’s authorisation must be precise.
Where the EU opportunity does not justify the cost of authorisation and no suitable partner exists, an orderly exit is the responsible choice. A wind-down should include clear, timely notice to EU clients, arrangements for the return or transfer of client crypto-assets and funds, cessation of EU-facing marketing and onboarding, retention of records, and internal documentation of the decision. A disorderly exit that leaves clients without access to their assets can itself attract supervisory attention, so the process must be planned and executed carefully.
The difference between a smooth authorisation and a protracted one is almost always the quality of the file. Supervisors repeatedly identify the same deficiencies: weak or generic AML frameworks, opaque custody and key-management descriptions, under-resourced governance and compliance functions, missing or unconvincing prudential calculations, and unclear statements of which services and which markets the firm actually intends to serve.
Early, structured engagement with the home supervisor pays dividends. A pre-application dialogue allows the firm to test its business model, clarify supervisory expectations and identify gaps before formal submission. Realistic timelines run from six to twelve months or more from submission, driven heavily by file completeness and responsiveness to supervisory questions. A well-prepared file with credible governance, a clear custody model and a robust AML framework can move materially faster than one that triggers repeated rounds of clarification.
A practical roadmap runs from exposure assessment and strategy decision, through pre-application engagement and policy drafting, to formal submission, supervisory review and clarification, authorisation, and finally passporting notifications for target markets. Building assurance work, such as independent reviews of custody or AML controls, into the early stages strengthens the file and reduces the risk of late-stage challenge.
Navigating the EU’s crypto licence wall operating after MiCA’s grandfathering cut-off is now a governance responsibility, not a technical footnote. Boards and senior management should act on a clear, prioritised list:
For firms weighing Malta as an authorisation base, the combination of MFSA supervisory experience and full EU/EEA passporting makes it a serious contender. Tailored legal advice is essential, because the right path depends on each firm’s activities, footprint and appetite for the EU market. Global Law Experts can connect firms and their advisers with Malta cryptocurrency and blockchain specialists to assess exposure and build a compliant strategy.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Anton Dalli at A2CO, a member of the Global Law Experts network.
posted 9 minutes ago
posted 25 minutes ago
posted 42 minutes ago
posted 47 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
No results available
Find the right Legal Expert for your business
Send welcome message