MiCA Regulation (EU) 2023/1114 — In force since December 2024
VASP→CASP Transition Deadline: 1 July 2026
Offices in Düsseldorf · Vilnius · Tallinn
Free Initial Consultation

MiCA Deadline 2026 — What Crypto Businesses Must Do Now

EU Parliament building — MiCA regulation enforcement deadline 2026

The MiCA grandfathering period ended on December 30, 2025. Businesses providing crypto-asset services in the EU without a CASP authorization are now operating in breach of MiCA Regulation (EU) 2023/1114. This updated March 2026 guide explains exactly what happened at each deadline, which member states offered grandfathering extensions, and the concrete steps businesses must take right now.

Complete MiCA Implementation Timeline

Understanding the MiCA deadlines requires tracking four distinct regulatory events. Here is the complete implementation chronology:

June 2023
MiCA Regulation Published — 18-Month Clock Starts
MiCA Regulation (EU) 2023/1114 was published in the Official Journal of the EU on June 9, 2023, and entered into force 20 days later. The regulation immediately set the 18-month clock running for stablecoin provisions (Title III/IV) and the 36-month clock for CASP provisions (Title V). ESMA and EBA began developing the extensive Level 2 regulatory technical standards (RTS) required under MiCA.
June 30, 2024
MiCA Title III and IV Enter Force — Stablecoin Rules Live
MiCA Titles III and IV (Asset-Referenced Token and E-Money Token issuance rules) entered into force on June 30, 2024. Stablecoin issuers — including e-money token issuers and asset-referenced token issuers — were required to hold ESMA/NCA authorization from this date. This was the first major MiCA deadline that affected operating businesses, primarily stablecoin projects.
Dec 30, 2024
MiCA Title V Enters Force — CASP Rules Live, Applications Open
MiCA Title V (CASP authorization and ongoing obligations) entered into force on December 30, 2024. From this date: (1) NCAs began accepting CASP authorization applications, (2) a national VASP transitional (grandfathering) period started for VASPs registered under pre-MiCA national regimes — its length was set independently by each member state under MiCA Art. 143(3), ranging from 6 months up to the maximum 18 months, (3) new businesses wishing to provide crypto-asset services in the EU could apply for CASP authorization. The grandfathering window was a gift to legacy businesses — not to new entrants.
Dec 30, 2025
Shorter National Windows Begin Closing
Member states set their own transitional period lengths under MiCA Art. 143(3), so windows closed on different dates: the shortest (6 months) closed June 30, 2025; a 9-month window closed September 30, 2025; and the 12-month cohort — including Germany, Ireland, Lithuania, Austria, and Slovakia — closed on December 30, 2025. From each country's closing date, businesses that were relying on a pre-MiCA VASP registration there must hold a MiCA CASP authorization or be operating in breach of EU law.
1 July 2026
Absolute Hard Deadline — No Further Extensions
1 July 2026 is the absolute final date — the latest closing date among all member states' transitional windows. No further grandfathering or transitional provisions exist under MiCA. Any business providing crypto-asset services in the EU without a CASP authorization after this date is operating in clear breach of MiCA regardless of any prior VASP registration status or pending application. NCAs are expected to increase enforcement actions materially after this date.

Grandfathering Rules — Member State Variations

MiCA Art. 143(3) lets each member state set its own transitional (grandfathering) period for previously VASP-registered businesses, up to a maximum of 18 months from December 30, 2024 — i.e., no later than 1 July 2026. This was an optional member state provision, not a mandatory EU-wide rule, and the length adopted varied significantly by country:

Lithuania

Lithuania adopted one of the shortest transitional periods in the EU — only 12 months. VASPs registered with Lithuania's FNTT (Financial Crime Investigation Service) could continue operating under their VASP registration only until the window closed on 30 December 2025. There is no remaining grandfathering protection for Lithuanian VASPs — the Bank of Lithuania requires a valid CASP authorization to operate.

Estonia

Estonia did not implement the full optional grandfathering extension. The FSA had already substantially wound down Estonia's pre-MiCA VASP registry through its 2022–2023 cleanup. Entities wishing to provide crypto-asset services in Estonia from December 30, 2024 were expected to apply for CASP authorization directly. Estonia has been among the stricter NCAs in enforcing the transition.

Poland

Poland has operated a VASP registration regime under its AML Act since 2018, administered by KNF, and registered Polish VASPs remain covered by MiCA's transitional provisions until 1 July 2026. However, Poland's national Crypto-Assets Market Act — the legislation KNF needs to actually process and grant MiCA CASP authorizations — has not been enacted (repeatedly vetoed, as of 2026), so KNF is not currently accepting or deciding CASP applications at all. The practical route for Poland-focused businesses today is CASP authorization from another EU member state, passported into Poland ahead of the 1 July 2026 deadline.

Germany

Germany had required crypto custody providers to hold BaFin authorization under §1 KWG since 2020, and offered a specific transition for these existing BaFin-authorized entities. BaFin permitted authorized crypto custodians to continue operating under their existing BaFin authorization while filing for CASP authorization upgrade. New CASP service categories (exchange, trading platform, portfolio management) require fresh CASP applications.

Key Point: Grandfathering Required Filing by Dec 30, 2025

Grandfathering protection only ever applied to businesses that already held a valid pre-MiCA VASP registration before December 30, 2024. The length of that protection depended on the member state and, in some cases, on national filing-deadline conditions — verify the specific rules of your home member state before assuming grandfathering still applies. Businesses without a valid grandfathering exemption must either obtain CASP authorization immediately or cease EU operations.

What Happens if You Operate Without Authorization

MiCA Art. 111 and national implementing legislation create a clear enforcement framework for unauthorized CASP activities. NCA powers against unauthorized operators include:

  • Public warnings: NCAs can publish a public warning on their official website identifying the unauthorized operator and the nature of the breach — a reputationally damaging sanction
  • Cease-and-desist orders: NCAs can order immediate cessation of all CASP activities directed at EU clients
  • Administrative fines: Up to €5 million or 3% of total annual turnover (whichever is higher) for legal persons; up to €700,000 for natural persons
  • Criminal referral: National implementing laws may create criminal offences for operating without authorization — penalties vary by member state
  • Bank and payment provider pressure: NCAs communicate with banks and payment service providers about unauthorized operators; banking relationships may be terminated

As of March 2026, several EU NCAs have begun formal investigations into businesses operating without CASP authorization. ESMA maintains a public register of authorized CASPs — absence from this register is a clear signal to counterparties and clients.

Urgent Action Steps — March 2026

If you are providing crypto-asset services in the EU without a CASP authorization, here are the steps to take immediately:

1
Assess Your Scope
Determine whether your activities fall within MiCA's definition of "crypto-asset services" under Art. 3(1)(17). DeFi protocols, non-custodial software, and NFT platforms may fall outside scope — but this requires a legal opinion. Get a MiCA scope legal opinion if uncertain.
2
Check Your Grandfathering Status
If you hold a legacy VASP registration in Malta or another EU member state with an 18-month transitional period, verify whether your jurisdiction's window is still open — some member states (e.g. Lithuania, Germany, Austria, Slovakia, Ireland) closed theirs already on 30 December 2025, and others closed even earlier. If your jurisdiction's window is still open, it runs no later than 1 July 2026.
3
Select Your CASP Jurisdiction Immediately
If you do not have a valid grandfathering exemption, you need CASP authorization urgently. Select your jurisdiction based on processing speed and your business needs. Lithuania (3–4 months) is the fastest EU option. See our jurisdiction comparison guide.
4
Start Documentation Preparation Now
CASP documentation preparation takes 4–8 weeks: AML program, DORA ICT framework, business plan, director fit-and-proper dossiers (criminal record certificates alone take 4–6 weeks). Every day of delay extends your authorization gap.
5
Consider Interim Risk Mitigation
While your CASP application is in process, consider whether your business can temporarily limit EU client onboarding, use geographic restrictions, or take other compliance risk reduction measures. Document all steps taken to demonstrate good faith to the NCA.

Which Businesses Are Affected by the MiCA Deadline?

The MiCA deadline affects a broader range of businesses than many operators initially assumed. You are affected if:

  • You provide crypto exchange services to EU clients — exchanging crypto for fiat or for other crypto on behalf of EU users
  • You custody crypto assets for EU clients — holding private keys or controlling crypto wallets on behalf of EU users
  • You operate a crypto trading platform accessible by EU users — whether you are EU-incorporated or not
  • You provide crypto portfolio management to EU clients — including robo-advisory services
  • You advise EU clients on crypto investments
  • You were VASP-registered in any EU member state and have not yet obtained CASP authorization
  • You are a non-EU company actively marketing crypto services to EU clients — MiCA applies based on where clients are located, not where the business is incorporated

Businesses that may be outside MiCA's scope include: purely non-custodial wallet software providers, DeFi protocol developers with no operational role in service provision, NFT platforms (subject to NFT characterization analysis), and businesses providing services exclusively to non-EU clients with genuine geographic restrictions.

Frequently Asked Questions

Has the MiCA CASP deadline passed?
National grandfathering deadlines have mostly passed — they varied by member state, from 30 June 2025 (shortest, 6 months) up to 1 July 2026 (longest, 18 months), with a 12-month cohort — including Germany, Ireland, Lithuania, Austria, and Slovakia — closing on 30 December 2025. Businesses operating without CASP authorization and without a valid grandfathering exemption are in breach of MiCA. New CASP applications can still be submitted at any time — there is no application deadline — but operating without authorization during the review period carries regulatory risk.
What happens if I operate without a CASP license after the deadline?
Operating without authorization in breach of MiCA Art. 59 exposes you to: NCA public warnings, cease-and-desist orders, administrative fines up to €5 million or 3% of turnover, criminal prosecution under national law, and loss of banking relationships. NCAs are actively monitoring and the enforcement environment is tightening in 2026.
Can I still apply for a CASP license in 2026?
Yes. CASP authorization applications can be submitted to NCAs at any time in 2026 and beyond — MiCA is a permanent licensing framework with no application cutoff. Authorization takes 3–8 months depending on jurisdiction. The urgency is that you should not be operating regulated services without authorization during the review period (unless a valid grandfathering exemption applies in your jurisdiction).
Which businesses are affected by the MiCA deadline?
MiCA applies to any business providing crypto-asset services to EU clients professionally — regardless of where the business is incorporated. This includes EU and non-EU companies providing exchange, custody, trading platform, portfolio management, advice, and transfer services to EU users. DeFi protocols, non-custodial software developers, and NFT platforms may fall outside scope but require individual legal analysis to confirm. See our MiCA scope legal opinions service.
Thomas Mueller — MiCA CASP Deadline Expert
MiCA Deadline & Compliance Expert
Thomas Mueller
Senior CASP Licensing Advisor · Düsseldorf & Vilnius

Thomas Mueller is a senior licensing advisor at Crypto License Europe specializing in urgent CASP authorization matters, grandfathering compliance analysis, and enforcement risk mitigation. He monitors NCA enforcement actions across the EU and advises clients facing deadline pressure on the fastest compliant path to authorization. Get urgent CASP advice →

Operating Without a CASP? Act Now.

The MiCA grandfathering period has ended. Our team provides urgent CASP authorization support — jurisdiction selection, entity formation, documentation preparation, and NCA submission — on accelerated timelines. Free 30-minute consultation.

Get Urgent CASP Support