Part 3 of 3 · The method
Is this entity really MiCA-regulated?
Eight steps from a brand name to a dated, filed answer. Run them in order — the sequence is the method: identity before lookup, the affirmative record before the negative channels, and the omission rule before any conclusion. Nothing here judges any real entity; it equips you to check the one in front of you.
Step 1
Fix the exact legal identity first: the registered company name and, where given, the LEILegal Entity Identifier — the 20-character code that names a legal entity unambiguously in filings and registers. Registers record legal entities; firms market brands, and the LEI is how the two are matched. — from the entity's own terms, imprint or white paperThe disclosure document MiCA requires before most crypto-assets are offered to the public or admitted to trading — contents prescribed, liability attached, notified to the regulator., not its brand.
WhyRegisters record legal entities; firms market brands. Most false negatives in register checks are name mismatches, and most deliberate deception lives in the gap between a brand and a company.
Where: The entity's own legal documents · Method — the identity precedes the lookup
Step 2
Check the ESMAThe European Securities and Markets Authority — the EU-level supervisor that drafts most of MiCA's detailed rules and keeps its registers. It drafts; the Commission adopts. CASPCrypto-asset service provider — a firm authorised under MiCA to provide one or more of the ten listed crypto-asset services in the EU. One home-state authorisation covers the whole Union. register for that legal entity: is it there, granted by which home authority, and for which of the ten services?
WhyThis is the affirmative record of authorisation. A licence claim that cannot be found here, under the legal name, has no EU-level support.
Where: ESMA's registers page (the practice works from dated CSV snapshots) · MiCA Arts 59, 63; register snapshot of 24 Aug 2026
Step 3
Confirm on the home state's national register — the entry's scope, services and client types, in the granting authority's own record.
WhyThe national register is the granting authority's own statement, often richer than the EU roll-up: Malta's Financial Services Register names services, classes and client scope.
Where: The home NCA's register (named on the ESMA entry) · The national layer — e.g. the MFSA Financial Services Register
Step 4
Read the scope against the claim: does the authorisation cover the specific service being offered to you, in your member state?
WhyAn authorisation names services; providing an eleventh thing, or providing into a state without the cross-border notification, is outside it. 'Licensed' is always 'licensed for what, where'.
Where: The register entry's service list; Art 65 for cross-border scope · MiCA Arts 59(1), 65
Step 5
Check the negative channels — the ESMA non-compliant register AND the home and your-state NCAsNational competent authority — the member-state regulator that authorises and supervises under an EU regime. For MiCA that means bodies like Malta's MFSA or Austria's FMA.' warning lists and penalty publications.
WhyA hit on any of these is decisive the other way. But treat only hits as evidence: the ESMA register is non-exhaustive by statute, with no duty on any authority to feed it.
Where: ESMA's non-compliant register; NCA websites (Art 114 publications live there) · MiCA Arts 110, 114
Step 6
Apply the omission rule before concluding: a register evidences what it records, never what it omits.
WhyThe checker's most common error is reading absence as clearance. Absence from the affirmative register (after step 1's naming care) is a red flag; absence from the negative register means nothing at all.
Where: — · MiCA Art 110(1) — 'non-exhaustive', in the register's own statute
Step 7
If the entity claims it needs no authorisation — reverse solicitationThe narrow exemption letting a non-EU firm serve an EU client who approached it entirely on their own initiative. Construed narrowly and factually — a disclaimer cannot outweigh contrary facts., 'we only serve clients who come to us' — treat the claim as unregisterable and test it on the facts.
WhyReverse solicitation appears in no register and produces no evidence of authorisation; the guidelinesA supervisory authority's published position on how rules should be applied. EU guidelines bind authorities on a comply-or-explain basis — they are not themselves the law. close every door a business model could be built through. A firm SERVING the EU public at scale on that theory is describing conduct, not authority.
Where: The facts of who solicited whom · MiCA Art 61; ESMA reverse-solicitation guidelines
Step 8
Date and file the whole check: names as searched, registers as read, snapshots or page prints of what each showed.
WhyRegisters change and entries move. A dated record of what was checked, and what it showed that day, is the difference between diligence and a recollection.
Where: Your own file · Method — the check is only as good as its record
Try the method on
Check yourself
A platform's site footer says 'regulated in the EU' and shows an impressive-looking certificate. Which steps does that claim survive on its own — and which produce the actual answer?
Check yourself
The entity appears in no register at all — neither the authorised roll nor the non-compliant register. What may you conclude?
So what— So what — run the eight steps once, today, on a firm you already deal with, and file the dated result. The first run teaches the method; the file it produces is the template every later check copies. This is the practice’s own discipline, handed over: evidence, dated, or it is only a recollection.
As at — instrument lifecycle stages verified 2026-08-26 to 2026-08-27, per instrument (each citation above shows its own date); register figures are from the dated snapshots of 24 August 2026. The method's register citations work from the dated snapshots of 24 August 2026; run every real check against the live registers on the day, and date what you saw.