Since 1 July 2026 the question "may this firm serve EU clients with crypto-asset services?" has had a binary answer. The transitional windows have all closed. Either an entity holds a MiCA authorisation — in which case it appears, as a specific legal entity, in a public register — or it does not, and outside one narrow exemption it may not provide those services in the Union at all.
That makes the perimeter checkable, by anyone, in minutes. This dossier is the method: how to check an entity's authorisation status, how to read the two ESMAThe European Securities and Markets Authority — the EU-level supervisor that drafts most of MiCA's detailed rules and keeps its registers. It drafts; the Commission adopts. registers without over-reading them, what the supervisor of the regime expects now the windows have shut, and where the one exemption — reverse solicitationThe narrow exemption letting a non-EU firm serve an EU client who approached it entirely on their own initiative. Construed narrowly and factually — a disclaimer cannot outweigh contrary facts. — actually runs.
One thing this dossier deliberately is not: a list. It names no entity as unauthorised on this practice's own judgment, and it draws no conclusion about any national supervisor. The registers are quoted as evidence of what they record — never of what they omit — and every figure carries the date of the snapshot it comes from.
In summary
- The first check is the ESMA register of authorised CASPs. On the practice's snapshot of 24 August 2026 it held 335 authorisation records — 330 distinct firms. An entry tells you the exact legal entity, its home authority, its permitted services and where it passports.
- Authorisation attaches to a legal entity, not a brand. ESMAThe European Securities and Markets Authority — the EU-level supervisor that drafts most of MiCA's detailed rules and keeps its registers. It drafts; the Commission adopts.'s own warning: MiCA protections apply to the specific authorised entity — not to other companies in the same group, and not to non-EU entities trading under the same name.
- There is also a register of the non-compliant — 167 entries on the same snapshot date, and "non-exhaustive" by its own statute (Article 110 MiCA). No authority is obliged to feed it, so what it records is evidence and what it omits is nothing at all.
- Since 1 July 2026 an unauthorised provider serving EU clients "will be in breach of EU law and must cease offering such services" — ESMAThe European Securities and Markets Authority — the EU-level supervisor that drafts most of MiCA's detailed rules and keeps its registers. It drafts; the Commission adopts.'s words — and was expected to have implemented, not merely drafted, an orderly wind-down by that date.
- Reverse solicitation is a narrow, factual defence, not a business model. Disclaimers cannot supersede contrary facts, influencer marketing counts as solicitation, and the exemption is in any case an argument an entity makes after it has been noticed.
The first check: the register of the authorised
MiCA's Article 59 states the rule the whole regime hangs on: no person may provide crypto-asset services in the Union unless authorised as a crypto-asset service provider (or a notified EU financial entity such as a credit institution). Article 109 makes ESMAThe European Securities and Markets Authority — the EU-level supervisor that drafts most of MiCA's detailed rules and keeps its registers. It drafts; the Commission adopts. keep a public register of everyone who is. That register — ESMA's interim MiCA register, downloadable as a dataset — is therefore the first and cheapest diligence step on any crypto counterparty, provider or vendor with EU exposure.
What an entry carries is exactly what a counterparty review needs:
| Field | What it answers |
|---|---|
| Legal entity name and LEI | Who precisely is authorised — the contracting entity, not the brand |
| Home member state and authority | Who supervises it, and under which national procedure it was assessed |
| Service codes | Which of the ten crypto-asset services it may provide — custody, exchange, execution, transfer services, platform operation and the rest |
| Passported states | Where in the EU/EEA it may actually operate on that authorisation |
On the practice's dated snapshot (24 August 2026) the register held 335 authorisation records. Three reading notes, each learned by actually parsing the file rather than citing it:
- Records are not firms. The 335 records resolve to 330 distinct firms by legal-entity identifier — a small number of firms hold two authorisations (typically ring-fencing a trading platform from the rest of the business). Diligence on "the firm" should ask which of its authorisations covers the service in question.
- A naive line count of the CSV gives 393, not 335. The file contains quoted fields with embedded newlines — addresses, service-code lists — so counting lines overstates the authorised population by 17%. Anyone re-deriving figures from the register should parse it properly, and anyone quoting figures about it should say how they counted.
- Home state is not footprint. PassportingProviding services across every EU/EEA state on one home-state authorisation, after a notification. A licence in one member state opens the whole single market. means an entity authorised in one member state may operate across nearly all of them — the first record the practice inspected carries notifications into 29 states. "Authorised CASPsCrypto-asset service provider — a firm authorised under MiCA to provide one or more of the ten listed crypto-asset services in the EU. One home-state authorisation covers the whole Union. per country" is a statement about home authorities, not about where activity happens.
The entity, not the brand
The sharpest edge in practice is entity identity. Crypto groups commonly operate one brand through many companies — an authorised EU entity beside non-EU affiliates under the same name. ESMAThe European Securities and Markets Authority — the EU-level supervisor that drafts most of MiCA's detailed rules and keeps its registers. It drafts; the Commission adopts.'s statement on the end of the transitional periods (17 April 2026) makes the point in terms a diligence file can quote: MiCA protections "only apply to the specific authorised legal entity in the EU – not to other companies of the same group, and not to non-EU entities", providers "may operate under the same brand across multiple companies or countries", and the reader should "review your contract carefully to confirm which entity is actually providing your service."
So the check is never "is Brand X authorised?" It is: which legal entity is my counterparty under the contract, and is that entity in the register, for this service, passported into this state? Four sub-questions, all answerable from one register entry — and any mismatch between the register entry and what the website claims is itself a finding.
The second register: the non-compliant, read correctly
ESMAThe European Securities and Markets Authority — the EU-level supervisor that drafts most of MiCA's detailed rules and keeps its registers. It drafts; the Commission adopts. also publishes a register of entities not compliant — entities providing crypto-asset services in violation of the authorisation requirement or the reverse-solicitation boundary. Its legal basis is Article 110 MiCA, and the article's first paragraph does more limit-setting than any caveat this dossier could write: ESMA "shall establish a non-exhaustive register of entities that provide crypto-asset services in violation of Article 59 or 61." Non-exhaustive is the register's own statutory character. Its content floor is equally instructive — Article 110(2) requires only "the commercial name or the website" of the entity plus the name of the submitting authority — and the article gives national authorities no duty to submit anything: it centralises what authorities choose to send. The publication duty MiCA does impose points elsewhere: an authority's penalty and measure decisions must be published "on their official websites" (Article 114) — nationally.
On the practice's 24 August 2026 snapshot the register held 167 entries. It is a genuinely useful negative check: an entity appearing here has been the subject of a national authority's published measure, and that is a fact with a date. But it must be read for what the statute makes it, and three features of the data match the statute exactly:
- The entries are mostly website-level, not corporate. The bulk of the register names commercial names and URLs — sites, not identified legal persons. Zero legal-entity identifiers appear on the large majority of entries. That is not a shortcut: it is entries meeting Article 110(2)'s name-or-website floor exactly, and it tells you what kind of measure typically feeds this register — warnings about operations encountered online, not adjudications against identified companies.
- Almost no entry states its reason. 166 of the 167 entries carry no stated reason and no described measure. The single exception — the Dutch AFM's entry — reads in full: "MEXC Global provides crypto-asset services in the Netherlands without the required MiCAR license. MEXC is in breach of section 59 MiCAR." That is the only entry in the EU-wide register that states what the entity did and against which provision, and it is quoted here as the register records it — this practice adds nothing to it.
- One field is uniform across all 167 rows (an "infringement" flag reading
Noon every entry, from every authority). A field with one value across an entire register carries no information — it is far more likely unused or mis-mapped than substantively true, and nothing should be read from it in either direction.
And the rule that governs the whole register, stated once and applied throughout: a register is evidence of what it records, never of what it omits. Here that rule is not caution — it is the statute. Because no provision obliges an authority to submit a measure to this register, and because the mandatory publication site for national measures is the authority's own website, an entity's presence on the register means a national authority published a measure and chose to submit it; a state's absence from the register means nothing determinable at all, about the state or about any firm operating there — several authorities with no entries here run active national warning channels of their own. A diligence process should therefore treat this register as a one-way test — appearing on it is a serious red flag; not appearing on it is not clearance — and should check the national warning lists of the states that matter to the transaction as a separate step.
After 1 July 2026: what the supervisor expects
The transitional regime that softened all of this is over. Under Article 143(3), firms lawfully operating under national law before 30 December 2024 could continue at most until 1 July 2026 — many states chose far shorter windows — and ESMAThe European Securities and Markets Authority — the EU-level supervisor that drafts most of MiCA's detailed rules and keeps its registers. It drafts; the Commission adopts.'s statement of 17 April 2026 closes the question bluntly: after that date, any entity providing crypto-asset services to EU clients without a MiCA authorisation "will be in breach of EU law and must cease offering such services." The prohibition applies, in ESMA's words, "irrespective whether the MiCA has been implemented in a Member State or not" — a state's own legislative delay is no defence for a firm operating there.
For firms that missed the door, ESMAThe European Securities and Markets Authority — the EU-level supervisor that drafts most of MiCA's detailed rules and keeps its registers. It drafts; the Commission adopts.'s expectations are specific enough to test against:
- Wind-down plans had to be implemented — not drafted — by 1 July 2026: "operational, credible, and immediately executable", designed to enable an orderly exit "without causing undue economic harm to clients".
- Offboarding is part of the plan: arranging the transfer of client crypto-assets to an authorised CASPCrypto-asset service provider — a firm authorised under MiCA to provide one or more of the ten listed crypto-asset services in the EU. One home-state authorisation covers the whole Union. or to a self-hosted wallet, with prior notice to clients before the plan is executed.
- The receiving side carries a mirror duty. Authorised CASPsCrypto-asset service provider — a firm authorised under MiCA to provide one or more of the ten listed crypto-asset services in the EU. One home-state authorisation covers the whole Union. were expected to manage the migration of arriving clients and to "apply robust onboarding processes to ensure full compliance with applicable AML/CFT requirements" — no lighter customer due diligence because the client arrives from a wind-down.
- The third-country position includes B2B. Non-EU entities are, outside reverse solicitationThe narrow exemption letting a non-EU firm serve an EU client who approached it entirely on their own initiative. Construed narrowly and factually — a disclaimer cannot outweigh contrary facts., "not permitted" to provide MiCA services to EU clients — and ESMAThe European Securities and Markets Authority — the EU-level supervisor that drafts most of MiCA's detailed rules and keeps its registers. It drafts; the Commission adopts. states expressly that this "also applies in a business-to-business context". The structural reason closes a specific back-door: MiCA prohibits CASPsCrypto-asset service provider — a firm authorised under MiCA to provide one or more of the ten listed crypto-asset services in the EU. One home-state authorisation covers the whole Union. from outsourcing custody to entities not themselves authorised, so an authorised EU front with an unauthorised group custodian behind it is not a compliant structure. Anyone diligencing a provider should ask where custody actually sits.
ESMAThe European Securities and Markets Authority — the EU-level supervisor that drafts most of MiCA's detailed rules and keeps its registers. It drafts; the Commission adopts.'s three instructions to investors in the same statement double as the shortest possible counterparty-check method, and they are the ones this dossier began with: verify the provider in the register before transferring anything; know exactly which legal entity you are dealing with; and if the answers are wrong, act — move to an authorised provider or self-custody.
The one exemption: where reverse solicitation actually runs
Everything above has one carve-out. Article 61 permits a third-country firm to serve an EU client where the client initiated the service at their own exclusive initiative. ESMAThe European Securities and Markets Authority — the EU-level supervisor that drafts most of MiCA's detailed rules and keeps its registers. It drafts; the Commission adopts.'s guidelinesA supervisory authority's published position on how rules should be applied. EU guidelines bind authorities on a comply-or-explain basis — they are not themselves the law. under Article 61(3) — both limbs of them, adopted in a final reportThe document in which ESMA or the EBA answers the consultation and hands its final draft to the Commission. The draft inside it is settled — but it is still not law. of 17 December 2024 — define how narrow that is, and four holdings matter for anyone testing a "they came to us" claim:
- Solicitation is read broadly and technology-neutrally — "any means", from pop-ups and app-store presence to road shows, affiliation campaigns and sponsorship; even general brand advertising addressed to the EU public may qualify. Purely educational content is outside — until it steers the audience to the firm's services.
- Who solicits does not matter. A firm solicits through anyone acting on its behalf — by contract, "implicitly via an informal agreement", or through close links — expressly including paid influencers, with remuneration "a strong indication" but its absence not decisive. And an EU-regulated entity that redirects clients to a third-country firm, same group or not, makes the provision a breach.
- Disclaimers cannot supersede contrary facts. The click-through "I was not solicited" checkbox is worth nothing against evidence of marketing, and the record-keeping burden sits on the firm: it must be able to show who initiated what.
- The exemption does not open a relationship. It covers the service the client sought, in the context of the original transaction — ESMAThe European Securities and Markets Authority — the EU-level supervisor that drafts most of MiCA's detailed rules and keeps its registers. It drafts; the Commission adopts.'s own example is that the firm cannot market even the same crypto-asset to the same client "a month later" — and the "same type" categories are drawn deliberately fine, so the exemption "cannot be used to circumvent" the authorisation requirement.
Two further points complete the picture. The second limb of the guidelinesA supervisory authority's published position on how rules should be applied. EU guidelines bind authorities on a comply-or-explain basis — they are not themselves the law. is addressed to supervisors, and it is effectively a detection-methods list — monitoring online activity, local-language and country-code web presence, social-media marketing tools, complaints and whistle-blowers — which is worth knowing because it describes what a well-resourced authority will look at. And the practical structure of the exemption bears stating plainly: reverse solicitationThe narrow exemption letting a non-EU firm serve an EU client who approached it entirely on their own initiative. Construed narrowly and factually — a disclaimer cannot outweigh contrary facts. is a defence an entity argues after it has been noticed. It is not a licence category, it appears in no register, and a business model that rests on it has no affirmative evidence of authorisation to show anyone — which, for a counterparty running the checks above, is the point.
What this dossier deliberately does not say
Three silences, kept on purpose. It does not characterise any member state's supervision — submission to the non-compliant register is voluntary by statute, so cross-state comparisons of its contents measure submission practice, not diligence, and this practice does not publish inferences its evidence cannot carry. It does not offer any list of entities "believed" unauthorised — the registers are the record, and the method above lets any reader run the check against the live registers rather than against someone's snapshot. And it asserts no application day for the reverse-solicitation guidelinesA supervisory authority's published position on how rules should be applied. EU guidelines bind authorities on a comply-or-explain basis — they are not themselves the law.: the guidelines as issued (26 February 2025) state the rule — sixty calendar days from publication in all official EU languages — but the all-languages publication date itself is stated nowhere ESMAThe European Securities and Markets Authority — the EU-level supervisor that drafts most of MiCA's detailed rules and keeps its registers. It drafts; the Commission adopts. publishes it, and a rule without its trigger date yields no day worth asserting. The comply-or-explainHow EU guidelines bind: each national authority must say whether it complies, and explain publicly if not. Pressure on authorities — not a rule that binds firms directly. phase is in any event demonstrably running: ESMA's compliance table of 10 July 2026 records the national declarations.
For the regime behind these checks — how a MiCA rule becomes law, the token taxonomy, the member-state map and worked exercises on closed records — see the practice's MiCA training path.
Sources
Registers (figures from the practice's dated snapshots of 24 August 2026; the live registers supersede them for any current check)
The instruments
- Regulation (EU) 2023/1114 (MiCA) — Arts 59, 61, 109, 143(3)
- ESMA, Final Report on the Guidelines on reverse solicitation under MiCA, 17 December 2024 (ESMA35-1872330276-1899)
ESMA statements on the transition
- Statement on the end of the transitional periods under MiCA, 17 April 2026 (ESMA75-113276571-1679)
- Statement on MiCA transitional measures, 17 December 2024 (ESMA75-453128700-1396)
- List of grandfathering periods decided by member states under Article 143(3)
Research and analysis, not legal advice · register figures are from dated snapshots of 24 August 2026 and the live ESMA registers supersede them · guideline statements carry the comply-or-explain caveat: guidelines bind authorities, not firms, directly · positions stated as at 27 August 2026. The information provided is for research and educational purposes only and does not constitute legal advice.