MiCA License Deadline Has Passed: What Crypto Companies Without a CASP License Can Do Now (2026)
The transition period under the Markets in Crypto-Assets Regulation (MiCA) closed on 1 July 2026. Most coverage stopped…
The transition period under the Markets in Crypto-Assets Regulation (MiCA) closed on 1 July 2026. Most coverage stopped at the headline number — a few hundred licensed firms against the thousands that had been serving EU clients under old national rules. Two months later, the more interesting number is the one nobody predicted in July: the licensed pool kept growing. CASP Tracker’s read of the official European Securities and Markets Authority (ESMA) register put the count at 338 authorised crypto-asset service providers (CASPs) on 7 September — up from the low-to-mid 200s that held a licence on deadline day. Firms are still clearing the bar, weeks after the “final” cut-off, and that fact quietly undercuts how a lot of unlicensed businesses have been framing their options since July.
The menu going around looks like three equally live paths for unlicensed crypto exchanges and other crypto businesses: move the business outside the EU, find a licensed partner to work through, or apply for a MiCA licence of your own. Treating them as interchangeable is the mistake. Only one of the three is a durable MiCA crypto license in the full sense of the word. The other two are stopgaps — they buy time, and a business that picks one without knowing exactly how much time it buys is choosing blind.
MiCA replaced a patchwork of national Virtual Asset Service Provider (VASP) registrations with a single EU-wide CASP authorisation, passportable across all 30 EEA states once granted — our earlier overview of MiCA’s rules and timeline covers the fuller background. Article 59 of the MiCA regulation is what makes 1 July absolute: it requires authorisation to provide crypto-asset services in the EU, full stop, and unlike the transitional years, there is no pending-application shield left to stand behind for crypto exchanges still working through the process.
Article 111(3)(a) sets the cost of ignoring that. National regulators must be empowered to fine an unauthorised legal entity up to at least €5 million — a floor on how high the ceiling has to be, set directly in the regulation rather than left to national discretion. We flagged the shape of this problem back in April, when ESMA’s own statement on the end of the transitional periods set out the wind-down and client-transfer expectations regulators would apply.
Enforcement is no longer theoretical, either. In mid-August, Austria’s Financial Market Authority fined Bitpanda €70,000 — the country’s first published MiCA penalty decision. Bitpanda already holds a MiCA licence; the FMA penalised how the firm timed a disclosure, a procedural failure entirely separate from the authorisation question. A fully licensed exchange drawing a public enforcement decision over a procedural detail is a signal worth reading correctly: an unlicensed one betting on nobody noticing has misjudged the moment.
Leaving the EU and Relying on Reverse Solicitation
The first path in most “what now” conversations is relocation: base the company somewhere outside the EU with a workable local licence — Canada’s MSB regime, El Salvador, South Africa, or another licensed jurisdiction outside the bloc — and keep serving EU users under reverse solicitation, the principle that a client who approaches a firm entirely unprompted is not someone the firm is “targeting.”
Reverse solicitation genuinely exists under MiCA and genuinely protects a business that qualifies for it, but what it means in practice is narrower than the phrase suggests. It covers a client who approaches the company entirely on their own initiative. A client who found the company through EU-facing marketing, EU-language landing pages, or an app-store listing still live in the bloc does not qualify, however the arrangement gets described afterward. A regulator reconstructs reverse-solicitation status after the fact, from the company’s own marketing footprint — nothing in MiCA lets a company declare the status for itself in advance. A jurisdiction change only holds up if the marketing genuinely moves with it — leave the old campaigns running, and a relocated company is still committing the same infringement, just from a new mailing address.
What Partnering With a Licensed CASP Actually Requires
The second path gets pitched most often as “white label” — operate under someone else’s MiCA licence, the way an unlicensed brand can run under a licensed casino’s gambling licence, or an agent can act for a licensed payment institution under the EU’s payment services rules. MiCA does not have that model. Articles 59 and 60 draw a hard line around who is allowed to provide crypto-asset services at all, and there is no agency exception sitting between “authorised” and “not authorised.” A business advertising itself as running crypto services “under” a partner’s CASP licence, in its own name, is describing an arrangement MiCA’s crypto regulation does not leave room for.
What does work, and what several EU-authorised platforms are already doing, is narrower: supplying an already-licensed CASP with technology, infrastructure, or marketing, while the licensed partner stays the counterparty of record for every client, every wallet, and every transaction. Structuring that arrangement correctly comes down to one question — whose name is actually on the client relationship — and getting the answer wrong is what turns a legitimate technology-supply deal into an unlicensed crypto-asset service by another name.
Applying for Your Own MiCA CASP License
The third path is the slowest of the three, and the one businesses most often rule out first for exactly that reason. The register numbers argue against ruling it out too fast: the pool of licensed CASPs grew from the low-to-mid 200s in July to 338 by early September, proof that firms which started this process months ago are still finishing it. It is also the only one of the three that ends in an actual MiCA CASP licence rather than a workaround with an expiry date attached.
What it requires is demanding: company formation in the chosen member state, a governance and Anti-Money Laundering (AML) package built for that specific regulator, and a filing that gets read for whether the business understands its own risk model. A technically complete application only carries it as far as a first read. Germany, the Netherlands, and Austria have each authorised meaningful numbers of CASPs so far, but the busiest register is not automatically the easiest one — a fast queue behind a thin application usually just produces a fast rejection.
This is also the only path where the work continues well after the licence is granted. A licence carries ongoing obligations — active risk monitoring, AML reporting, the same disclosure discipline Austria just enforced against Bitpanda — and a company that treats authorisation as the finish line is quietly setting up its own first enforcement case.
Questions to Answer Before You Commit
- If a regulator reconstructed the company’s marketing footprint from the outside, would it look like genuine reverse solicitation, or like EU marketing with a new return address?
- If a technology or distribution partner’s own CASP licence were suspended tomorrow, what happens to the company’s clients, and how much of that risk has actually been priced in?
- If a CASP application goes in today, what exactly is the company telling EU clients about the months it takes to process — and is that the answer it would want a regulator reading back later?
What the Next Wave of Enforcement Will Probably Target
Expect the next published MiCA penalty decisions to land on the seam between the three paths above: relocations where the marketing never actually moved, and technology partnerships where the question of whose name sits on the client relationship was never really settled. More national regulators are likely to start publishing decisions of their own now that Austria has set the precedent.
Missing the 1 July deadline was survivable — the growing CASP register through September is the proof. The businesses still standing a year from now will be the ones that chose a path for how long it had to hold up, and built the marketing wind-down, the partnership terms, or the licence application to match.
Weighing which of these three paths fits a specific business — or checking whether a technology partnership is structured on the right side of the line MiCA draws — is exactly the kind of question SBSB’s crypto licensing team works through with crypto exchanges and other digital-asset businesses every week under the current deadline pressure.