Skip to content
← Dossiers

Method · the MiCA perimeter

Finding the unauthorised

August 2026·EU
MiCACASPsAuthorisationRegistersReverse solicitationMethod

Since 1 July 2026 the question "may this firm serve EU clients with crypto-asset services?" has had a binary answer. The transitional windows have all closed. Either an entity holds a MiCA authorisation — in which case it appears, as a specific legal entity, in a public register — or it does not, and outside one narrow exemption it may not provide those services in the Union at all.

That makes the perimeter checkable, by anyone, in minutes. This dossier is the method: how to check an entity's authorisation status, how to read the two ESMA registers without over-reading them, what the supervisor of the regime expects now the windows have shut, and where the one exemption — reverse solicitation — actually runs.

One thing this dossier deliberately is not: a list. It names no entity as unauthorised on this practice's own judgment, and it draws no conclusion about any national supervisor. The registers are quoted as evidence of what they record — never of what they omit — and every figure carries the date of the snapshot it comes from.

In summary

  • The first check is the ESMA register of authorised CASPs. On the practice's snapshot of 24 August 2026 it held 335 authorisation records — 330 distinct firms. An entry tells you the exact legal entity, its home authority, its permitted services and where it passports.
  • Authorisation attaches to a legal entity, not a brand. ESMA's own warning: MiCA protections apply to the specific authorised entity — not to other companies in the same group, and not to non-EU entities trading under the same name.
  • There is also a register of the non-compliant — 167 entries on the same snapshot date, and "non-exhaustive" by its own statute (Article 110 MiCA). No authority is obliged to feed it, so what it records is evidence and what it omits is nothing at all.
  • Since 1 July 2026 an unauthorised provider serving EU clients "will be in breach of EU law and must cease offering such services" — ESMA's words — and was expected to have implemented, not merely drafted, an orderly wind-down by that date.
  • Reverse solicitation is a narrow, factual defence, not a business model. Disclaimers cannot supersede contrary facts, influencer marketing counts as solicitation, and the exemption is in any case an argument an entity makes after it has been noticed.

The first check: the register of the authorised

MiCA's Article 59 states the rule the whole regime hangs on: no person may provide crypto-asset services in the Union unless authorised as a crypto-asset service provider (or a notified EU financial entity such as a credit institution). Article 109 makes ESMA keep a public register of everyone who is. That register — ESMA's interim MiCA register, downloadable as a dataset — is therefore the first and cheapest diligence step on any crypto counterparty, provider or vendor with EU exposure.

What an entry carries is exactly what a counterparty review needs:

FieldWhat it answers
Legal entity name and LEIWho precisely is authorised — the contracting entity, not the brand
Home member state and authorityWho supervises it, and under which national procedure it was assessed
Service codesWhich of the ten crypto-asset services it may provide — custody, exchange, execution, transfer services, platform operation and the rest
Passported statesWhere in the EU/EEA it may actually operate on that authorisation

On the practice's dated snapshot (24 August 2026) the register held 335 authorisation records. Three reading notes, each learned by actually parsing the file rather than citing it:

  1. Records are not firms. The 335 records resolve to 330 distinct firms by legal-entity identifier — a small number of firms hold two authorisations (typically ring-fencing a trading platform from the rest of the business). Diligence on "the firm" should ask which of its authorisations covers the service in question.
  2. A naive line count of the CSV gives 393, not 335. The file contains quoted fields with embedded newlines — addresses, service-code lists — so counting lines overstates the authorised population by 17%. Anyone re-deriving figures from the register should parse it properly, and anyone quoting figures about it should say how they counted.
  3. Home state is not footprint. Passporting means an entity authorised in one member state may operate across nearly all of them — the first record the practice inspected carries notifications into 29 states. "Authorised CASPs per country" is a statement about home authorities, not about where activity happens.

The entity, not the brand

The sharpest edge in practice is entity identity. Crypto groups commonly operate one brand through many companies — an authorised EU entity beside non-EU affiliates under the same name. ESMA's statement on the end of the transitional periods (17 April 2026) makes the point in terms a diligence file can quote: MiCA protections "only apply to the specific authorised legal entity in the EU – not to other companies of the same group, and not to non-EU entities", providers "may operate under the same brand across multiple companies or countries", and the reader should "review your contract carefully to confirm which entity is actually providing your service."

So the check is never "is Brand X authorised?" It is: which legal entity is my counterparty under the contract, and is that entity in the register, for this service, passported into this state? Four sub-questions, all answerable from one register entry — and any mismatch between the register entry and what the website claims is itself a finding.

The second register: the non-compliant, read correctly

ESMA also publishes a register of entities not compliant — entities providing crypto-asset services in violation of the authorisation requirement or the reverse-solicitation boundary. Its legal basis is Article 110 MiCA, and the article's first paragraph does more limit-setting than any caveat this dossier could write: ESMA "shall establish a non-exhaustive register of entities that provide crypto-asset services in violation of Article 59 or 61." Non-exhaustive is the register's own statutory character. Its content floor is equally instructive — Article 110(2) requires only "the commercial name or the website" of the entity plus the name of the submitting authority — and the article gives national authorities no duty to submit anything: it centralises what authorities choose to send. The publication duty MiCA does impose points elsewhere: an authority's penalty and measure decisions must be published "on their official websites" (Article 114) — nationally.

On the practice's 24 August 2026 snapshot the register held 167 entries. It is a genuinely useful negative check: an entity appearing here has been the subject of a national authority's published measure, and that is a fact with a date. But it must be read for what the statute makes it, and three features of the data match the statute exactly:

  • The entries are mostly website-level, not corporate. The bulk of the register names commercial names and URLs — sites, not identified legal persons. Zero legal-entity identifiers appear on the large majority of entries. That is not a shortcut: it is entries meeting Article 110(2)'s name-or-website floor exactly, and it tells you what kind of measure typically feeds this register — warnings about operations encountered online, not adjudications against identified companies.
  • Almost no entry states its reason. 166 of the 167 entries carry no stated reason and no described measure. The single exception — the Dutch AFM's entry — reads in full: "MEXC Global provides crypto-asset services in the Netherlands without the required MiCAR license. MEXC is in breach of section 59 MiCAR." That is the only entry in the EU-wide register that states what the entity did and against which provision, and it is quoted here as the register records it — this practice adds nothing to it.
  • One field is uniform across all 167 rows (an "infringement" flag reading No on every entry, from every authority). A field with one value across an entire register carries no information — it is far more likely unused or mis-mapped than substantively true, and nothing should be read from it in either direction.

And the rule that governs the whole register, stated once and applied throughout: a register is evidence of what it records, never of what it omits. Here that rule is not caution — it is the statute. Because no provision obliges an authority to submit a measure to this register, and because the mandatory publication site for national measures is the authority's own website, an entity's presence on the register means a national authority published a measure and chose to submit it; a state's absence from the register means nothing determinable at all, about the state or about any firm operating there — several authorities with no entries here run active national warning channels of their own. A diligence process should therefore treat this register as a one-way test — appearing on it is a serious red flag; not appearing on it is not clearance — and should check the national warning lists of the states that matter to the transaction as a separate step.

After 1 July 2026: what the supervisor expects

The transitional regime that softened all of this is over. Under Article 143(3), firms lawfully operating under national law before 30 December 2024 could continue at most until 1 July 2026 — many states chose far shorter windows — and ESMA's statement of 17 April 2026 closes the question bluntly: after that date, any entity providing crypto-asset services to EU clients without a MiCA authorisation "will be in breach of EU law and must cease offering such services." The prohibition applies, in ESMA's words, "irrespective whether the MiCA has been implemented in a Member State or not" — a state's own legislative delay is no defence for a firm operating there.

For firms that missed the door, ESMA's expectations are specific enough to test against:

  • Wind-down plans had to be implemented — not drafted — by 1 July 2026: "operational, credible, and immediately executable", designed to enable an orderly exit "without causing undue economic harm to clients".
  • Offboarding is part of the plan: arranging the transfer of client crypto-assets to an authorised CASP or to a self-hosted wallet, with prior notice to clients before the plan is executed.
  • The receiving side carries a mirror duty. Authorised CASPs were expected to manage the migration of arriving clients and to "apply robust onboarding processes to ensure full compliance with applicable AML/CFT requirements" — no lighter customer due diligence because the client arrives from a wind-down.
  • The third-country position includes B2B. Non-EU entities are, outside reverse solicitation, "not permitted" to provide MiCA services to EU clients — and ESMA states expressly that this "also applies in a business-to-business context". The structural reason closes a specific back-door: MiCA prohibits CASPs from outsourcing custody to entities not themselves authorised, so an authorised EU front with an unauthorised group custodian behind it is not a compliant structure. Anyone diligencing a provider should ask where custody actually sits.

ESMA's three instructions to investors in the same statement double as the shortest possible counterparty-check method, and they are the ones this dossier began with: verify the provider in the register before transferring anything; know exactly which legal entity you are dealing with; and if the answers are wrong, act — move to an authorised provider or self-custody.

The one exemption: where reverse solicitation actually runs

Everything above has one carve-out. Article 61 permits a third-country firm to serve an EU client where the client initiated the service at their own exclusive initiative. ESMA's guidelines under Article 61(3) — both limbs of them, adopted in a final report of 17 December 2024 — define how narrow that is, and four holdings matter for anyone testing a "they came to us" claim:

  1. Solicitation is read broadly and technology-neutrally — "any means", from pop-ups and app-store presence to road shows, affiliation campaigns and sponsorship; even general brand advertising addressed to the EU public may qualify. Purely educational content is outside — until it steers the audience to the firm's services.
  2. Who solicits does not matter. A firm solicits through anyone acting on its behalf — by contract, "implicitly via an informal agreement", or through close links — expressly including paid influencers, with remuneration "a strong indication" but its absence not decisive. And an EU-regulated entity that redirects clients to a third-country firm, same group or not, makes the provision a breach.
  3. Disclaimers cannot supersede contrary facts. The click-through "I was not solicited" checkbox is worth nothing against evidence of marketing, and the record-keeping burden sits on the firm: it must be able to show who initiated what.
  4. The exemption does not open a relationship. It covers the service the client sought, in the context of the original transaction — ESMA's own example is that the firm cannot market even the same crypto-asset to the same client "a month later" — and the "same type" categories are drawn deliberately fine, so the exemption "cannot be used to circumvent" the authorisation requirement.

Two further points complete the picture. The second limb of the guidelines is addressed to supervisors, and it is effectively a detection-methods list — monitoring online activity, local-language and country-code web presence, social-media marketing tools, complaints and whistle-blowers — which is worth knowing because it describes what a well-resourced authority will look at. And the practical structure of the exemption bears stating plainly: reverse solicitation is a defence an entity argues after it has been noticed. It is not a licence category, it appears in no register, and a business model that rests on it has no affirmative evidence of authorisation to show anyone — which, for a counterparty running the checks above, is the point.

What this dossier deliberately does not say

Three silences, kept on purpose. It does not characterise any member state's supervision — submission to the non-compliant register is voluntary by statute, so cross-state comparisons of its contents measure submission practice, not diligence, and this practice does not publish inferences its evidence cannot carry. It does not offer any list of entities "believed" unauthorised — the registers are the record, and the method above lets any reader run the check against the live registers rather than against someone's snapshot. And it asserts no application day for the reverse-solicitation guidelines: the guidelines as issued (26 February 2025) state the rule — sixty calendar days from publication in all official EU languages — but the all-languages publication date itself is stated nowhere ESMA publishes it, and a rule without its trigger date yields no day worth asserting. The comply-or-explain phase is in any event demonstrably running: ESMA's compliance table of 10 July 2026 records the national declarations.

For the regime behind these checks — how a MiCA rule becomes law, the token taxonomy, the member-state map and worked exercises on closed records — see the practice's MiCA training path.

Sources

Registers (figures from the practice's dated snapshots of 24 August 2026; the live registers supersede them for any current check)

The instruments

ESMA statements on the transition


Research and analysis, not legal advice · register figures are from dated snapshots of 24 August 2026 and the live ESMA registers supersede them · guideline statements carry the comply-or-explain caveat: guidelines bind authorities, not firms, directly · positions stated as at 27 August 2026. The information provided is for research and educational purposes only and does not constitute legal advice.

Working on a matter this touches?

Start a conversation