Complete MiCA Implementation Timeline
Understanding the MiCA deadlines requires tracking four distinct regulatory events. Here is the complete implementation chronology:
Grandfathering Rules — Member State Variations
MiCA Art. 143(3) lets each member state set its own transitional (grandfathering) period for previously VASP-registered businesses, up to a maximum of 18 months from December 30, 2024 — i.e., no later than 1 July 2026. This was an optional member state provision, not a mandatory EU-wide rule, and the length adopted varied significantly by country:
Lithuania
Lithuania adopted one of the shortest transitional periods in the EU — only 12 months. VASPs registered with Lithuania's FNTT (Financial Crime Investigation Service) could continue operating under their VASP registration only until the window closed on 30 December 2025. There is no remaining grandfathering protection for Lithuanian VASPs — the Bank of Lithuania requires a valid CASP authorization to operate.
Estonia
Estonia did not implement the full optional grandfathering extension. The FSA had already substantially wound down Estonia's pre-MiCA VASP registry through its 2022–2023 cleanup. Entities wishing to provide crypto-asset services in Estonia from December 30, 2024 were expected to apply for CASP authorization directly. Estonia has been among the stricter NCAs in enforcing the transition.
Poland
Poland has operated a VASP registration regime under its AML Act since 2018, administered by KNF, and registered Polish VASPs remain covered by MiCA's transitional provisions until 1 July 2026. However, Poland's national Crypto-Assets Market Act — the legislation KNF needs to actually process and grant MiCA CASP authorizations — has not been enacted (repeatedly vetoed, as of 2026), so KNF is not currently accepting or deciding CASP applications at all. The practical route for Poland-focused businesses today is CASP authorization from another EU member state, passported into Poland ahead of the 1 July 2026 deadline.
Germany
Germany had required crypto custody providers to hold BaFin authorization under §1 KWG since 2020, and offered a specific transition for these existing BaFin-authorized entities. BaFin permitted authorized crypto custodians to continue operating under their existing BaFin authorization while filing for CASP authorization upgrade. New CASP service categories (exchange, trading platform, portfolio management) require fresh CASP applications.
Grandfathering protection only ever applied to businesses that already held a valid pre-MiCA VASP registration before December 30, 2024. The length of that protection depended on the member state and, in some cases, on national filing-deadline conditions — verify the specific rules of your home member state before assuming grandfathering still applies. Businesses without a valid grandfathering exemption must either obtain CASP authorization immediately or cease EU operations.
What Happens if You Operate Without Authorization
MiCA Art. 111 and national implementing legislation create a clear enforcement framework for unauthorized CASP activities. NCA powers against unauthorized operators include:
- Public warnings: NCAs can publish a public warning on their official website identifying the unauthorized operator and the nature of the breach — a reputationally damaging sanction
- Cease-and-desist orders: NCAs can order immediate cessation of all CASP activities directed at EU clients
- Administrative fines: Up to €5 million or 3% of total annual turnover (whichever is higher) for legal persons; up to €700,000 for natural persons
- Criminal referral: National implementing laws may create criminal offences for operating without authorization — penalties vary by member state
- Bank and payment provider pressure: NCAs communicate with banks and payment service providers about unauthorized operators; banking relationships may be terminated
As of March 2026, several EU NCAs have begun formal investigations into businesses operating without CASP authorization. ESMA maintains a public register of authorized CASPs — absence from this register is a clear signal to counterparties and clients.
Urgent Action Steps — March 2026
If you are providing crypto-asset services in the EU without a CASP authorization, here are the steps to take immediately:
Which Businesses Are Affected by the MiCA Deadline?
The MiCA deadline affects a broader range of businesses than many operators initially assumed. You are affected if:
- You provide crypto exchange services to EU clients — exchanging crypto for fiat or for other crypto on behalf of EU users
- You custody crypto assets for EU clients — holding private keys or controlling crypto wallets on behalf of EU users
- You operate a crypto trading platform accessible by EU users — whether you are EU-incorporated or not
- You provide crypto portfolio management to EU clients — including robo-advisory services
- You advise EU clients on crypto investments
- You were VASP-registered in any EU member state and have not yet obtained CASP authorization
- You are a non-EU company actively marketing crypto services to EU clients — MiCA applies based on where clients are located, not where the business is incorporated
Businesses that may be outside MiCA's scope include: purely non-custodial wallet software providers, DeFi protocol developers with no operational role in service provision, NFT platforms (subject to NFT characterization analysis), and businesses providing services exclusively to non-EU clients with genuine geographic restrictions.