Skip to content

For professional and eligible investors. Capital at risk. Product-specific materials are access controlled.

Block Asset Management
All insights
Risk & Market Structure

MiCA after the deadline: what an authorisation tells an allocator, and what it does not

Since 1 July 2026, only crypto-asset service providers authorised under MiCA may serve clients in the EU. Three months on, this note sets out what the deadline changed, what the public register shows, what an authorisation actually establishes about a venue or a custodian — and the questions it leaves for the allocator to ask.

Juan Carlos SerranoPartner & CFO / COO
7 October 202610 min read
  • The last of MiCA's national transitional periods ended on 1 July 2026. Since then a crypto-asset service provider needs an authorisation to serve clients in the EU, and a pending application does not preserve the right to operate.
  • ESMA's interim register listed 364 authorised providers from 27 EEA states at its 30 September update — concentrated in a handful of jurisdictions, and compiled from national submissions with a lag.
  • An authorisation carries concrete obligations that matter to an allocator: segregation of client crypto-assets, client money placed with a bank by the next business day, custody liability, and no own-account dealing on a platform the provider operates.
  • It does not certify creditworthiness or operational quality. Custody liability is capped and excludes incidents the provider does not control, and what segregation achieves in an insolvency still depends on national law.
  • The useful questions are entity-specific: which legal entity is authorised, where, for which listed services — and whether it is the entity that actually holds the assets and executes the trades.

What changed on 1 July

MiCA has applied to crypto-asset service providers since 30 December 2024, but it gave firms already operating under national rules time to adapt. Under Article 143(3) they could continue 'until 1 July 2026 or until they are granted or refused an authorisation pursuant to Article 63, whichever is sooner'.

Member States were allowed to shorten that period or not to apply it at all, and many did. ESMA's list of national choices runs from six months — the Netherlands, Poland, Hungary, Latvia, Slovenia and Finland — through nine in Sweden and twelve in Germany, Ireland, Austria, Lithuania, Slovakia and Norway, to the full eighteen elsewhere, including Luxembourg, Malta, France, Spain and Italy. 1 July 2026 was therefore not the deadline. It was the last of them. ESMA warned in December 2024 that the patchwork could leave a provider authorised in one Member State but, for a period, without the authorisation it needed to serve clients in another.

Since 1 July the position is simple. Article 59 provides that a person 'shall not provide crypto-asset services, within the Union' unless it has been authorised as a crypto-asset service provider, or is a bank, investment firm, fund manager or other regulated entity permitted to provide those services under Article 60. The wording of the transitional rule also settles a point that was widely misread: the right to continue ended on 1 July whether or not an application was still being decided.

What the register shows, three months on

ESMA publishes the authorisations that national authorities report to it in an interim register, a set of files it updates weekly. At its 30 September 2026 update, the file of authorised providers held 364 entries from 27 EEA states.

Three features stand out. The market is concentrated: Germany alone accounts for 99 entries, and Germany, France, the Netherlands, Cyprus and Malta together for close to six in ten. The deadline produced a queue: more authorisations are dated June 2026 than any other month — 76, against 44 in the next busiest. And authorisation continued after the deadline, with more than sixty entries dated after 1 July. Where those were firms that had been operating under the transitional regime, the date matters: between 1 July and their authorisation they had no basis on which to serve clients in the Union.

Of the 364 entries, 227 include custody and administration of crypto-assets on behalf of clients, and 22 include the operation of a trading platform. Far more firms hold client assets than run venues.

The register is an index, not a certificate. ESMA notes that information reported by national authorities 'will not be immediately displayed'; the file carries a handful of entries whose authorisation dates fall after its own update, one of them in 2028; and three Member States have no entry at all. ESMA's parallel list of entities providing services without authorisation is dominated by a single country — 164 of its 173 entries are Italian — so absence from it says little about any firm. The national authority's own register remains the record to check.

What an authorisation establishes

For an allocator, the value of MiCA is not the word 'authorised'. It is a set of specific obligations that change what happens to client assets if something goes wrong — several of which address directly the problem of a single entity acting as exchange, broker and custodian at once.

  • Safeguarding — a provider holding client crypto-assets, or the means of access to them, must make 'adequate arrangements to safeguard the ownership rights of clients, especially in the event of the crypto-asset service provider's insolvency', and may not use them for its own account (Article 70(1)).
  • Client money — client funds other than e-money tokens must be placed with a credit institution or a central bank by the end of the business day after they are received, in an account separately identifiable from the provider's own (Article 70(3)).
  • Segregation in custody — client crypto-assets must be kept apart from the provider's own, held separately on the distributed ledger, and 'legally segregated from the crypto-asset service provider's estate' so that its creditors have no recourse to them (Article 75(7)).
  • Custody liability — a custodian is liable to its clients for the loss of their crypto-assets, or of the means of access to them — in practice, the private keys — where the incident is attributable to it (Article 75(8)).
  • Sub-custody — a custodian that delegates may use only other authorised providers, and must tell its clients that it does (Article 75(9)).
  • Statements — clients receive a statement of their positions at least once every three months and on request (Article 75(5)).
  • Venue conflicts — the operator of a trading platform 'shall not deal on own account' on the platform it operates, may use matched principal trading only with the client's consent, and must have operating rules that ensure efficient settlement of both crypto-assets and funds (Article 76(1), (5) and (6)).

What it does not establish

Authorisation is a threshold, not an assessment. It does not say that a provider is well capitalised relative to its exposures, well run, or appropriately sized for an institutional client. Two authorised providers can differ as much as two authorised banks.

The protections also have edges, and they are written into the text. Custody liability is capped 'at the market value of the crypto-asset that was lost, at the time the loss occurred', and excludes incidents the provider shows occurred independently of its service, 'such as a problem inherent in the operation of the distributed ledger that the crypto-asset service provider does not control'. Legal segregation is required 'in accordance with applicable law' — so how well it holds in an insolvency remains a question for the national law and the courts where the provider sits.

Scope matters as well. MiCA does not apply to crypto-assets that qualify as financial instruments, deposits or funds, nor to those that are unique and not fungible (Article 2(3)–(4)). The own-account prohibition applies to the platform a provider operates, not to every entity in its group. And a firm outside the Union may serve a client in the Union without authorisation only where that client acted 'at its own exclusive initiative' — a basis Article 61 draws narrowly: any solicitation in the Union defeats it, 'notwithstanding any contractual clause or disclaimer purporting to state otherwise'.

Questions worth asking now

None of this replaces operational due diligence. It gives it sharper questions. For each venue, broker and custodian a manager relies on:

  • Which legal entity in the group is authorised, by which national authority and from what date — checked against that authority's own register rather than a summary of it.
  • Which of the listed services the authorisation covers, and whether they include the services actually used: custody, execution, exchange and the operation of a platform are listed separately.
  • Whether the authorised entity is the one that holds the assets and is party to the agreement — and, if client accounts were moved to a different group entity around 1 July, what was transferred, on what terms, and who the counterparty is now.
  • Where custody is delegated, to whom, and whether each sub-custodian is itself authorised.
  • Where client money sits, with which credit institution, and how it is identified as client money.
  • For a provider outside the Union, the documented basis on which a client in the Union is served.
  • And, unchanged by any regulation, the questions that authorisation does not answer: financial strength, concentration, and how quickly an exposure could be reduced.

The sources behind the factual claims in this note. Where a figure could not be traced to a source of this standard, it is not stated.

  1. Official Journal of the European Union — Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets (2023-06-09)

    Article 2(3)–(4) on scope; Article 59 on authorisation; Article 61 on services at the client's own exclusive initiative; Article 70 on safekeeping of clients' crypto-assets and funds; Article 75(5), (7), (8) and (9) on custody; Article 76(1), (5) and (6) on trading platforms; Article 143(3) on the transitional regime.

  2. European Securities and Markets Authority (ESMA) — Interim MiCA Register — authorised crypto-asset service providers (2026-09-30)

    The 364 entries from 27 EEA states at the 30 September 2026 update, their distribution by home Member State, authorisation date and listed service, and ESMA's note that information reported by national authorities is not immediately displayed.

  3. European Securities and Markets Authority (ESMA) — Interim MiCA Register — non-compliant entities providing crypto-asset services (2026-09-30)

    The 173 entries at the 30 September 2026 update, 164 of them with Italy as home Member State.

  4. European Securities and Markets Authority (ESMA) — List of grandfathering periods decided by Member States under Article 143 of Regulation (EU) 2023/1114 Markets in Crypto-Assets Regulation (MiCA) (2026)

    The national transitional periods: six months in the Netherlands, Poland, Hungary, Latvia, Slovenia and Finland; nine in Sweden; twelve in Germany, Ireland, Austria, Lithuania, Slovakia and Norway; eighteen elsewhere.

  5. European Securities and Markets Authority (ESMA) — ESMA Statement on MiCA Transitional Measures (2024-12-17)

    ESMA's warning that differing national periods could leave a provider authorised in one Member State without the required authorisation, for a period, in another.

How Block Asset Management helps

Regulatory standing and counterparty exposure are separate areas of our operational due diligence. MiCA has changed what can be verified in both; it has not changed the need to verify it.

Regulatory standing as its own area

Regulatory standing is one of the eleven areas in our operational due diligence, asking of a manager and of the parties around it: who authorised this, and to do what?

Counterparty and venue exposure

The venues, brokers and custodians a strategy relies on are assessed for the concentration and settlement risk that reliance creates, including where one party occupies several roles at once.

Custody and key management

How assets are held, and how private keys are secured, segregated and controlled, is examined as a question in its own right rather than inferred from a licence.

Legal structure

What is recoverable in a default depends on the structure and the jurisdiction that governs it, which is why legal structure is examined separately from regulatory status.

Ongoing rather than one-off

A change in a counterparty's regulatory position — an authorisation granted, restricted or withdrawn — is treated as new information requiring review, not as an administrative update.

MiCA has given the European market something it lacked: a single, public test of who may provide crypto-asset services, and a set of obligations that attach to passing it. For an allocator that is a better starting point than the patchwork it replaced. It remains a starting point.

If your organisation is reviewing the venues and custodians behind a digital asset allocation, our investor relations team can discuss how regulatory standing and counterparty exposure are examined within our operational due diligence.

Important information

This material is provided for information purposes only and is intended for professional and qualified investors. It is general commentary on the EU Markets in Crypto-Assets Regulation and does not constitute legal, regulatory, investment or tax advice, nor an offer, solicitation or recommendation of any service provider, strategy or financial instrument. It names no provider and expresses no view on any. Register figures are those published by ESMA in its interim MiCA register at its update of 30 September 2026; they are point-in-time observations compiled from national submissions and may have changed since. Any provider's status should be verified with the relevant national competent authority. Digital assets are volatile and involve significant risk, including the possible loss of the entire amount invested. Past performance is not a reliable indicator of future results.

Continue reading BAM research

This note is part of Block Asset Management's research on institutional digital asset investing. Explore the wider library, or read how we assess managers and structures before any allocation is made.