Registers look like answers; they are actually evidence, and evidence has rules. This part reads each register in the landscape for exactly what an entry there proves, and what absence there cannot prove — then turns to what authorities actually do about firms operating without authority.
The landscape: four kinds of record
The ESMA register of authorised CASPs
Kept by ESMA, from NCA notifications
An entry evidencesThat a named entity holds a CASPCrypto-asset service provider — a firm authorised under MiCA to provide one or more of the ten listed crypto-asset services in the EU. One home-state authorisation covers the whole Union. authorisation: which home member state granted it, and for which of the ten services. This is the affirmative record — the one a genuine licence claim can always be checked against.
AbsenceAbsence needs care with timing and naming: a very recent grant may not yet appear, and firms often trade under names that differ from the authorised legal entity. Absence of the LEGAL entity after checking both is a serious red flag.
The white-paper registers
Kept by ESMA, from notified white papers
An entry evidencesThat a token's white paperThe disclosure document MiCA requires before most crypto-assets are offered to the public or admitted to trading — contents prescribed, liability attached, notified to the regulator. was notified — for e-money tokens, the register where the live market is actually visible (43 white-paper records from 23 issuers at the 24 August 2026 snapshot, against zero authorised ARTAsset-referenced token — a crypto-asset claiming to hold a stable value by referencing anything other than exactly one official currency: a basket, gold, another asset. MiCA checks e-money tokens first; ART is the stablecoin residual (Title III). issuers).
AbsenceA white-paper entry is not a licence: it evidences a disclosure filing about a token, never an authorisation of a service provider.
The register of non-compliant entities
Kept by ESMA, from voluntary submissions (MiCA Art 110)
An entry evidencesThat some authority took the step of submitting an entity as providing services in violation of Articles 59 or 61 — at a content floor of a commercial name OR a website, and usually without stated reasons or measures.
AbsenceNothing. The register is non-exhaustive by its own statute, and no authority is obliged to submit anything, on any trigger, in any period. A state can act vigorously against unauthorised firms, publish every measure on its own website as Art 114 commands, and lawfully never appear here.
The national registers and warning channels
Kept by Each NCA, on its own website
An entry evidencesThe mandatory national layer: authorisation registers (Malta's Financial Services Register shows the entity, the authorisation type, its services and client scope), penalty publications (Art 114 requires NCAsNational competent authority — the member-state regulator that authorises and supervises under an EU regime. For MiCA that means bodies like Malta's MFSA or Austria's FMA. to publish their decisions on their official websites), and each authority's own warning lists.
AbsenceEach national channel evidences its own state's record only — and warning lists are discretionary. Thirty jurisdictions means thirty places a warning could sit.
Why the non-compliant register is honest about being incomplete
The register of non-compliant entities calls itself non-exhaustivein its own statute — the incompleteness is not a data problem, it is the instrument’s legal character. Article 110 sets a content floor of a commercial name or a website plus the submitting authority; it makes the register a receptacle for what authorities choose to submit; and it obliges no authority to submit anything, on any trigger, within any period.
The mandatory publication duties sit elsewhere: each authority must publish its own penalty and measure decisions on its own official website, and reports penalties to ESMAThe European Securities and Markets Authority — the EU-level supervisor that drafts most of MiCA's detailed rules and keeps its registers. It drafts; the Commission adopts. in annual aggregate. So the national websites — not the EU register — are where enforcement is guaranteed to surface.
Check yourself
A member state has zero entries in the non-compliant register. Rutger reads this as 'nothing to worry about there'. What does the zero actually evidence?
The watch: what authorities do about unlicensed operators
Member states must provide for penalties for unauthorised provision, and the machinery is visibly in use. The regime’s first published sanctions exist — the operations page works one authority’s disclosure-rule sanction in full, from the authority’s own published decision documents. National warning lists flag entities encountered marketing without authority. And supervisors’ detection methods are published policy: half of the reverse-solicitation guidelinesA supervisory authority's published position on how rules should be applied. EU guidelines bind authorities on a comply-or-explain basis — they are not themselves the law. is a detection-methods list addressed to the supervisors themselves.
For the full data read — all entries of the non-compliant register at the dated snapshot, what the entries do and do not state, and the method for using them — the Finding the unauthorised dossier is this part’s deep companion.
So what— So what — read every register with two columns on your page: what an entry here proves, what absence here proves. The first column is real evidence; the second is almost always empty — and part 3 turns that discipline into the full method.
Regulation (EU) 2023/1114 (MiCA) · applicable — this binds · verified 2026-08-26 · Read the text ↗
As at — instrument lifecycle stages verified 2026-08-26 to 2026-08-27, per instrument (each citation above shows its own date); register figures are from the dated snapshots of 24 August 2026. Register readings from the dated snapshots of 24 August 2026; the register's statutory character read from the OJ text (Arts 110, 114, 115).