What is MiCA and who does it affect?

What is MiCA and who does it affect?

The Markets in Crypto-Assets Regulation is the EU's comprehensive framework for crypto-asset oversight. This article explains what MiCA covers, who falls within its scope, and what the key obligations are for issuers, exchanges, and wallet providers.

8 min read

This article is for informational purposes only and does not constitute legal advice. Consult a qualified legal professional for advice specific to your situation.

  • MiCA is the EU's comprehensive crypto-asset framework, fully applicable since December 2024. It covers crypto-asset issuers, trading platforms, exchanges, custody providers, portfolio managers, and advisers. The EU is the first major jurisdiction to implement purpose-built crypto regulation at this scale, and for any business with EU customers or EU ambitions, MiCA is now a baseline compliance requirement.
  • The passporting mechanism is one of MiCA's most commercially significant features. A firm authorised in any one EEA member state can provide services across all 30 EEA countries without separate authorisation in each country. This creates a real incentive to choose the home member state carefully, and ESMA has issued supervisory convergence guidance to reduce material differences in how member states apply the authorisation criteria.
  • The regulated population splits into issuers and service providers, with materially different obligations. General crypto-asset issuers must publish a white paper and bear legal liability for its contents. ART and EMT issuers face prior authorisation requirements, capital and reserve rules, and ongoing governance standards. CASPs must obtain authorisation covering their specific services, hold minimum capital, segregate client assets, and comply with market integrity and disclosure obligations.
  • Transitional provisions for existing operators expire by mid-2026 for most member states. Firms that have not obtained CASP authorisation by the end of the applicable transitional period cannot continue to offer regulated services in the EU. The ART and EMT provisions applied six months earlier, in June 2024, so stablecoin issuers faced an earlier deadline.
  • Several areas of interpretive uncertainty remain live. The treatment of DeFi protocols without a clear operator, the intersection of MiCA obligations with AI Act requirements for firms using automated decisioning, and the varying supervisory readiness of national competent authorities are all active variables that affect how MiCA applies in practice in 2026.

LIVE TOOL

The regulation that changed crypto in Europe

The Markets in Crypto-Assets Regulation, known as MiCA, is the EU's primary legislative framework governing crypto-assets and the firms that issue or provide services around them. It entered into force in June 2023 and became fully applicable in December 2024, making the EU the first major jurisdiction to implement comprehensive, purpose-built crypto regulation at scale.

MiCA matters beyond Europe. Because it establishes a passporting regime, a firm authorised in one EEA member state can operate across all 30 EEA countries. For any business with EU customers or EU ambitions, MiCA is now a baseline compliance requirement, not a regional consideration.

This article covers what MiCA regulates, which entities fall within its scope, and what the core obligations look like in practice. For a broader orientation to EU financial regulation, see EU financial regulation in 2026: what it covers, who it affects, and why horizon scanning matters.

📋

Live MiCA registry: See which crypto-asset service providers are already authorised across all 30 EEA countries in our MiCA crypto registry.

Browse notified white papers: The MiCA white papers directory lists all crypto-asset white papers notified to ESMA under MiCA, by issuer and home member state.

What MiCA regulates

MiCA covers three categories of asset and the firms that work with them.

Crypto-assets in general. The regulation applies to any digital representation of value or rights that can be transferred and stored electronically using distributed ledger technology. This is a deliberately broad definition intended to capture the full range of tokens in use, rather than specific technical implementations.

Asset-referenced tokens (ARTs). These are tokens that maintain a stable value by referencing a basket of assets: fiat currencies, commodities, or other crypto-assets. They are subject to the most demanding requirements in MiCA because of their potential systemic relevance.

Electronic money tokens (EMTs). These reference a single fiat currency and function similarly to e-money. EMT issuers must hold reserves equal to the outstanding token value and are subject to rules that closely mirror existing e-money regulation.

MiCA explicitly excludes certain categories. Securities tokens that qualify as financial instruments under MiFID II, central bank digital currencies, and tokens issued as part of a limited network (loyalty schemes, for example) fall outside its scope. NFTs are generally excluded unless they exhibit characteristics of fungibility that bring them back within the definition.

Who MiCA applies to

The regulation draws a distinction between two types of regulated entity: issuers and service providers.

Issuers

Any entity issuing crypto-assets to the public in the EU, or seeking admission of those assets to a trading platform, is subject to MiCA's issuer requirements. The obligations vary by asset type.

For general crypto-assets, the primary obligation is the publication of a white paper: a standardised disclosure document covering the issuer's identity, the asset's technical and economic characteristics, the rights attached to it, and the risks involved. The white paper must be submitted to the relevant national competent authority before publication. The issuer is not required to obtain prior approval for most general crypto-assets, but the white paper is a public document and the issuer bears legal liability for its contents.

For ARTs and EMTs, the requirements are substantially more onerous. Issuers must obtain prior authorisation from their home member state regulator. They are subject to ongoing capital requirements, reserve asset rules, governance standards, and redemption rights for token holders. Significant ARTs and EMTs, determined by the number of holders and the transaction volume they generate, are placed under direct European Banking Authority supervision rather than national oversight.

Crypto-asset service providers

MiCA defines a crypto-asset service provider (CASP) as any entity providing one or more regulated services as a business. The regulated services include:

  • Custody and administration of crypto-assets on behalf of clients
  • Operation of a trading platform for crypto-assets
  • Exchange of crypto-assets for fiat currency or for other crypto-assets
  • Execution of orders on behalf of clients
  • Placing of crypto-assets
  • Reception and transmission of orders
  • Providing advice on crypto-assets
  • Portfolio management in crypto-assets
  • Providing transfer services for crypto-assets

Check whether major exchanges have already obtained CASP authorisation in our MiCA major exchanges tracker.

CASPs must be authorised by the national competent authority of their home member state. Authorisation in one member state grants the right to provide services across the EU under the passporting mechanism, which is one of MiCA's most commercially significant features for firms building European operations.

Browse authorised CASPs by home member state in the MiCA registry by country.

Authorised entities under existing EU financial regulation, including credit institutions and investment firms, can provide certain CASP services under a notification procedure rather than a full authorisation process.

Key obligations for CASPs

Authorisation is the entry point, not the full picture. Once authorised, CASPs are subject to ongoing requirements across several dimensions.

Capital requirements. CASPs must hold own funds of at least 50,000 euros for the least complex services, rising to 150,000 euros for operators of trading platforms. These are minimum floors; regulators may impose higher requirements based on the firm's risk profile and scale.

Custody. CASPs providing custody must segregate client assets from their own, maintain detailed records, and have policies in place for the return of client assets in the event of insolvency. The regulation addresses one of the most consequential failure modes seen in unregulated crypto markets.

Conflicts of interest. Firms providing multiple services, such as operating a trading platform while also managing client portfolios, face explicit requirements to identify, disclose, and manage conflicts. Proprietary trading by CASPs on their own platforms is restricted.

Market integrity. MiCA introduces provisions against insider dealing, market manipulation, and unlawful disclosure of inside information, extending the logic of MAR (the Market Abuse Regulation) into crypto markets.

Disclosure and marketing. Marketing communications must be clearly identified as such, must be fair and not misleading, and must be consistent with the published white paper. There are specific requirements around the targeting of retail clients and the prominence of risk warnings.

Complaints handling and dispute resolution. CASPs must maintain accessible complaints procedures and cooperate with alternative dispute resolution schemes.

The passporting mechanism

One of MiCA's most consequential provisions for firms planning EU operations is the single passport. A CASP authorised in any EEA member state can provide its services across all 30 EEA countries by notifying its home regulator and following a defined process. It does not need separate authorisation in each country where it operates.

This creates a real incentive for regulatory arbitrage: firms may seek authorisation in member states perceived to have more efficient or favourable supervisory environments. Regulators and the European Securities and Markets Authority (ESMA) are aware of this dynamic, and supervisory convergence guidance has been issued to reduce material differences in how member states apply the authorisation criteria.

For non-EU firms serving EU customers, MiCA takes a strict approach. Reverse solicitation, where EU clients independently and on their own initiative approach a non-EU firm, is the primary available exemption. ESMA has issued guidance indicating that this exemption is narrow and that proactive marketing to EU clients by unauthorised non-EU firms falls within MiCA's scope regardless of where the firm is established.

Deadlines and transitional provisions

MiCA became fully applicable in December 2024, but transitional provisions allow existing service providers operating legally under national regimes to continue doing so for a limited period while seeking MiCA authorisation. The length of the transitional period varies by member state, with a maximum of 18 months from the date of full application. For most member states, transitional provisions expire by mid-2026.

Firms that have not obtained CASP authorisation by the end of the applicable transitional period cannot continue to offer regulated services in the EU.

The MiCA registry tracks which firms are currently authorised across all 30 EEA countries.

The timeline for ARTs and EMTs has different characteristics. The ART and EMT provisions became applicable in June 2024, six months ahead of the CASP provisions. Issuers who were already operating significant stablecoin products faced an earlier compliance deadline.

Frequently asked questions

When did MiCA become fully applicable?

MiCA entered into force in June 2023 and became fully applicable in December 2024. The provisions covering asset-referenced tokens (ARTs) and electronic money tokens (EMTs) applied six months earlier, in June 2024. Transitional arrangements for existing service providers operating under national regimes continue in most member states until mid-2026, with the outer limit being 1 July 2026.

What types of crypto-asset does MiCA cover?

MiCA covers three categories: general crypto-assets, which are any digital representations of value or rights transferable via distributed ledger technology; asset-referenced tokens (ARTs), which maintain a stable value by referencing a basket of assets; and electronic money tokens (EMTs), which reference a single fiat currency. Securities tokens qualifying as financial instruments under MiFID II, central bank digital currencies, and tokens issued in limited networks such as loyalty schemes are explicitly excluded.

Do I need prior authorisation to issue a crypto-asset under MiCA?

It depends on the asset type. General crypto-asset issuers must publish a MiCA-compliant white paper and notify the relevant national competent authority, but prior approval is not required in most cases. ART issuers must obtain prior authorisation from their home member state NCA. EMT issuers must already hold an e-money institution or credit institution licence and notify the NCA when issuing, but do not apply for a separate MiCA authorisation.

What is a crypto-asset service provider (CASP) under MiCA?

A CASP is any entity providing one or more of MiCA's ten regulated services as a business. The ten services are: custody and administration of crypto-assets on behalf of clients, operation of a trading platform, exchange of crypto-assets for fiat or other crypto-assets, execution of orders, placing, reception and transmission of orders, advice, portfolio management, and transfer services. Each service provided must be named in the CASP authorisation.

What are the minimum capital requirements for CASPs?

MiCA sets three capital tiers based on the services provided. Advisory-only CASPs must hold at least EUR 50,000 in own funds. Most other CASP services, including exchange and custody, require a minimum of EUR 125,000. Operators of trading platforms face the highest floor at EUR 150,000. These are minimums; NCAs may impose higher requirements based on the firm's risk profile and scale.

Does MiCA passporting allow a CASP to serve customers across the whole EU?

Yes. A CASP authorised in one EEA member state can provide its named services across all 30 EEA countries under the passporting mechanism, without needing separate authorisation in each country. The passporting right covers only the services explicitly listed in the home state authorisation. Firms operating under a transitional arrangement, rather than a full authorisation, do not benefit from passporting.

Can a credit institution or investment firm provide CASP services without a separate MiCA licence?

Yes, via a simplified notification route. Credit institutions and certain MiFID II investment firms may provide CASP services by notifying their home member state NCA rather than applying for full CASP authorisation. However, the notification route does not exempt them from MiCA's ongoing conduct obligations. All client asset segregation, market integrity, disclosure, and complaints handling requirements apply in full.

What happens to non-EU firms serving EU customers under MiCA?

MiCA takes a strict approach to non-EU firms. The primary available exemption is reverse solicitation, where an EU client independently and on their own initiative approaches a non-EU firm. ESMA has issued guidance indicating that this exemption is narrow and that proactive marketing to EU clients by unauthorised non-EU firms falls within MiCA's scope regardless of where the firm is established.

How do I know which MiCA regime applies to my firm?

The MiCA obligations checker at the top of this page identifies the applicable regime, authorisation route, minimum capital, passporting status, and key ongoing obligations based on your entity type. Select from general crypto-asset issuer, ART issuer, EMT issuer, trading platform operator, exchange, custodian, portfolio manager or adviser, or credit institution using the notification route.

What to watch in 2026

MiCA is not a fixed point. ESMA and EBA have been active in publishing regulatory technical standards, guidelines, and Q and A documents that flesh out the detail of the regulation's application. Several areas of interpretive uncertainty remain live.

The treatment of DeFi protocols and decentralised governance structures is one. MiCA's authorisation framework is built around identifiable legal entities, and protocols without a clear operator face genuine ambiguity about whether and how the regulation applies to them.

The AI Act's intersection with MiCA is another developing area, particularly for firms using AI systems in credit scoring, customer onboarding, or trading functions within crypto-asset services. Both regulations are in scope for financial services firms operating at that intersection.

Enforcement is also developing. National competent authorities are at different stages of readiness to handle CASP authorisation applications and ongoing supervision. The gap between the regulation's requirements on paper and supervisory practice in any given member state is a practical reality for firms navigating the authorisation process.

For ongoing updates on MiCA and other EU financial regulation, the EU financial regulation overview is the reference hub. For the case for systematic regulatory monitoring rather than reactive compliance, see what is regulatory horizon scanning and why compliance teams need it.

Forseti monitors MiCA developments continuously, including ESMA and EBA technical standards, and delivers personalised impact analysis anchored to verified official sources. Start for free.

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.