The EU MiCA Regulation (Markets in Crypto-Assets) is the first comprehensive law in any major jurisdiction that regulates crypto-assets across the entire chain — issuance of stablecoins (crypto tokens designed to hold a steady value, typically pegged 1:1 to an official currency like the euro), operation of crypto exchanges and custodians, advisory services, transfers, market abuse — under one harmonised EU framework. Before MiCA, every Member State had its own patchwork of national rules; one country issued VASP registrations (VASP — virtual asset service provider, the label crypto firms were given before MiCA), another required a payment institution licence, and most of the market lived in legal grey zones. MiCA replaces that patchwork.
If you run a crypto exchange, custody service, broker, advisor or stablecoin issuer that touches the EU/EEA market — this regulation applies to you. The rules for stablecoin issuers (asset-referenced tokens, backed by a basket of assets or currencies, and e-money tokens, pegged to a single official currency) have applied since 30 June 2024; the rules for all other crypto-asset service providers since 30 December 2024. Operators that were active on the local market before 30 December 2024 may continue under national law during a transitional period that ends no later than 1 July 2026 (and earlier in many Member States).
This page is the canonical klarproof guide — every key claim is sourced directly to EUR-Lex, ESMA, EBA, or named national supervisors.
Quick facts
- Full name: Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets
- Published in OJ: 9 June 2023 (OJ L 150/40)
- Entered into force: 29 June 2023 (twentieth day after publication, per Article 149)
- Title III + IV applies (stablecoins — ART and EMT): 30 June 2024
- Title V applies (CASPs and the rest): 30 December 2024
- Transitional period for pre-existing CASPs: ends no later than 1 July 2026; many Member States chose shorter periods (Netherlands 6 months, Germany / Ireland 12 months, France / Estonia 18 months)
- Penalties: graduated tiers under Articles 111-115 — for legal persons, the highest tier (serious market-abuse breaches under Articles 89-92) reaches at least €15,000,000 or 15% of total annual turnover, whichever is higher; for general issuer/CASP breaches the cap is at least €5,000,000 plus a turnover-based percentage (3% / 5% / 12.5% depending on which obligation was breached); for natural persons, at least €5,000,000 for the most serious market-abuse breaches
- Coordinating EU body: European Securities and Markets Authority (ESMA) and European Banking Authority (EBA)
- National enforcement: by the national competent authority (NCA) in each Member State — typically the financial-markets supervisor (BaFin in Germany, AMF in France, CONSOB / Bank of Italy in Italy, Central Bank of Ireland, Estonian Finantsinspektsioon, etc.)
What MiCA actually does
MiCA breaks the crypto industry into three groups of activities and applies a different rulebook to each.
1. Issuers of crypto-assets
Anyone who creates a crypto-asset and offers it to the EU public, or seeks admission to a trading platform, must publish a white paper describing the project, the issuer, the rights attached to the token, the underlying technology, the risks. For ordinary crypto-assets (Bitcoin-like tokens, utility tokens) the white paper is essentially a disclosure document — there is no prior authorisation, but the issuer is liable if the white paper is misleading.
For stablecoins (asset-referenced tokens — ART, e-money tokens — EMT), the bar is far higher: the issuer must be authorised by an EU competent authority before it can issue, must hold a reserve of assets backing the token, must provide redemption rights, and is subject to ongoing supervision.
2. Crypto-Asset Service Providers (CASPs)
Anyone who provides one of the ten regulated crypto-asset services to the EU public — exchange, custody, brokerage, advisory, etc. — must be authorised as a CASP by an NCA in one Member State and can then passport the licence across all 27 Member States plus the three EEA states (Iceland, Liechtenstein, Norway). One licence, single market.
3. Market integrity
MiCA imports a market-abuse regime modelled on MiFID II / MAR: prohibition of insider dealing in crypto-assets, prohibition of unlawful disclosure of inside information, prohibition of market manipulation. NCAs investigate and sanction, ESMA issues coordinating guidelines.
The three categories of crypto-assets under MiCA
MiCA classifies every crypto-asset that falls within its scope into one of three categories — and the rules vary sharply by category.
Asset-Referenced Tokens (ART) — Title III
A token that purports to maintain a stable value by referencing any other value or right or a combination of them, including one or more official currencies (Article 3(1)(6)). In practice: a stablecoin pegged to a basket of currencies, a basket of commodities, or a single non-EU currency.
Issuers must be authorised, hold a reserve of liquid, low-risk assets equal to the value of tokens in circulation, and grant holders a redemption right at par. If the ART becomes “significant” (large user base, high transaction volume, etc. — Article 43), supervision shifts from the national authority to the EBA directly, and additional requirements apply (higher capital, stricter governance, reserve composition rules).
E-Money Tokens (EMT) — Title IV
A token that purports to maintain a stable value by referencing the value of one official currency (Article 3(1)(7)). The textbook example: USDT or USDC pegged 1:1 to the US dollar; a euro-pegged token like EURC.
EMT issuers must be either an authorised credit institution or an authorised electronic-money institution under the EU’s e-money rules. They must back the token 1:1 with funds, segregate the reserve, and provide redemption at par at any time. Significant EMTs (Article 56) again move under EBA direct supervision.
Other crypto-assets — Title II
Everything else that is not an ART, an EMT, or already regulated under another EU financial-services regime (MiFID II, e-money, deposits, securitisations). Bitcoin, Ether, most utility tokens, governance tokens — they sit here. Issuers publish a white paper but do not need authorisation; they are liable for the accuracy of the white paper.
What MiCA does NOT cover
- Non-fungible tokens (NFT) — if genuinely unique and non-fungible (Recital 10). MiCA explicitly warns (Recital 11) that fractionalised NFTs or NFTs issued in a large series or collection may not qualify as truly non-fungible and could fall back into scope.
- Crypto-assets that qualify as financial instruments under MiFID II — they remain in the MiFID regime.
- Deposits, e-money (other than EMTs as defined here), securitisations, insurance — already regulated by other EU rules.
- Decentralised crypto-assets that are issued without an identifiable issuer — partially out of scope; market-abuse rules still apply, but issuer obligations cannot bind a non-existent issuer.
The 10 crypto-asset services (Article 3(1)(16))
A CASP authorisation covers one or more of the following ten services. Each service has its own ongoing prudential and conduct requirements:
- Custody and administration of crypto-assets on behalf of clients
- Operation of a trading platform for crypto-assets (i.e. running an exchange)
- Exchange of crypto-assets for funds (fiat on/off-ramp)
- Exchange of crypto-assets for other crypto-assets (e.g. BTC ↔ ETH)
- Execution of orders for crypto-assets on behalf of clients
- Placing of crypto-assets (helping issuers place new tokens with investors)
- Reception and transmission of orders for crypto-assets on behalf of clients
- Providing advice on crypto-assets
- Providing portfolio management on crypto-assets
- Providing transfer services for crypto-assets on behalf of clients
A CASP authorised under MiCA can request authorisation for one service and then add others; investment firms already licensed under MiFID II can extend into analogous crypto-asset services via a simpler 40-working-day notification to their home NCA — without a full CASP authorisation procedure (Article 60).
Phased timeline (Article 149)
MiCA does not switch on all at once. The phased schedule:
| Date | What starts to apply |
|---|---|
| 29 June 2023 | The Regulation enters into force — most provisions still dormant |
| 30 June 2024 | Title III (asset-referenced tokens) and Title IV (e-money tokens) apply — stablecoin issuers cannot offer to the EU public without authorisation |
| 30 December 2024 | Title V (CASP authorisation and supervision), Title II (other crypto-assets, white-paper rules), Title VI (market abuse), Title VII (cooperation between authorities) and the rest apply |
| Until 1 July 2026 (max) | Transitional grandfathering for crypto-asset service providers that were active under national rules before 30 December 2024 — they may continue, but only for as long as the Member State permits, and in no case beyond the absolute backstop of 1 July 2026 set by Article 143(3) |
The critical date for most operators is 30 December 2024. From that day, providing any of the 10 regulated services to the EU public without a CASP authorisation (or without being inside a national grandfathering window that has not yet expired) is unlawful.
Authorisation and passporting
The EU offers a single market for crypto-asset services under MiCA. The mechanics:
- The CASP applies to the NCA in one Member State of its choosing.
- The NCA assesses the application against MiCA’s prudential criteria — fit-and-proper management, capital requirements set in three classes under Annex IV (€50,000 for advice / RTO / execution / placing / transfer / portfolio management; €125,000 if custody or exchange services are added; €150,000 if a trading platform is operated), governance, custody segregation, complaint handling, and so on.
- Once authorised, the CASP notifies the NCA of every other Member State where it intends to provide services and can begin operating there — without a second authorisation procedure.
This is the same passporting model already familiar from MiFID II investment firms and from the EU banking and insurance frameworks. In practice it has driven a regulator-shopping race: by 30 April 2026, the ESMA MiCA Register listed 194 authorised CASPs across the EU/EEA. BaFin (Germany) led with 55, followed by the Netherlands (25), France (13), Malta (12), Cyprus (12), Ireland (11) and Austria (9). Coinbase chose Luxembourg (CSSF), Bitpanda added a German licence to its Austrian base, and Kraken (Payward Global Solutions / Payward Europe Solutions) went through the Central Bank of Ireland (Coindesk, January 2025).
Stablecoins under MiCA: stricter rules
The stablecoin regime is the part of MiCA with the most observable effect on the live market. Three big practical consequences:
Authorisation is mandatory
An EMT issuer must be a credit institution or an authorised e-money institution under the existing EU e-money framework, with an additional MiCA authorisation overlay. An ART issuer must be authorised specifically as an ART issuer under MiCA. There is no “de minimis” carve-out below which a stablecoin issuer can simply ignore the rules.
Reserve assets must back the token 1:1
The reserve must be held in low-risk, highly liquid assets, segregated from the issuer’s own assets, custodied with regulated custodians, and subject to monthly composition disclosure. Holders have a right to redeem at par at any time.
For significant ARTs and EMTs, the EBA can impose additional requirements — including that a portion of the reserve must be held with EU credit institutions (a real prudential constraint that has driven non-EU issuers to reorganise their treasury operations).
Real-world impact: USDT removed from EU exchanges
The most visible effect of MiCA in 2025 was the removal of Tether (USDT) from EU users by the major exchanges. Tether did not seek MiCA authorisation as an EMT issuer. Coinbase removed USDT for European users in December 2024; Crypto.com, Binance, Kraken, OKX and others followed in early 2025 (CryptoSlate, December 2024).
In parallel, MiCA-authorised stablecoins — Circle’s USDC and EURC, Société Générale’s EURCV — became the default fiat-backed crypto-assets in the EEA market.
Governance: who supervises and who enforces
MiCA uses a three-tier governance model.
EU level
- European Securities and Markets Authority (ESMA) — coordinates national supervisors, drafts the regulatory and implementing technical standards (RTS/ITS) that flesh out MiCA, maintains the public MiCA Register of authorised CASPs and white papers, and runs the market-abuse coordination work. Chaired by Verena Ross until 31 October 2026 (she has chosen not to seek a second mandate, and ESMA is in the process of selecting a successor).
- European Banking Authority (EBA) — directly supervises issuers of significant asset-referenced tokens and e-money tokens; runs the prudential rule-making for stablecoin reserves and capital; coordinates with ECB on monetary-stability concerns. Chaired by François-Louis Michaud since 16 April 2026 — he succeeded José Manuel Campa, who left at the end of January 2026. Full profile: Who is the EBA.
- European Central Bank (ECB) — has consultation rights on significance designations and on monetary-stability assessments for stablecoins.
National level
The actual day-to-day authorisation of CASPs and ordinary ART/EMT issuers is done by national competent authorities (NCAs):
- 🇩🇪 Germany — BaFin. Highest count of CASP authorisations of any Member State — 55 of the 194 in the ESMA MiCA Register as of 30 April 2026.
- 🇫🇷 France — AMF handles CASP authorisation and supervision; ACPR (alongside the Banque de France) supervises ART and EMT issuers on prudential grounds. The three EMT issuers authorised in France to date — Circle France, Schuman Financial and Société Générale-Forge — were all licensed via ACPR.
- 🇮🇹 Italy — CONSOB and the Bank of Italy split the supervision; Italy started later than most major EU peers — no Italian CASPs in the ESMA MiCA Register as of 30 April 2026, with CONSOB’s main 2025 steps focused on setting fee schedules (€20,000 application fee, Resolution 23700/2025) and the first CONSOB authorisation phase opening in April 2026.
- 🇮🇪 Ireland — Central Bank of Ireland. Authorised Kraken under a 12-month grandfathering window.
- 🇪🇪 Estonia — Finantsinspektsioon. Estonia chose the full 18-month grandfathering window for existing operators.
- 🇳🇱 Netherlands — AFM (conduct) + DNB (prudential). Chose the shortest grandfathering window of just 6 months.
Significance criteria
For ART and EMT, an issuer becomes significant (and therefore moves under direct EBA supervision) if it meets at least three of seven criteria — combining quantitative thresholds (number of holders, market capitalisation, daily transactions, reserve size, jurisdictions where the token is offered, etc.) and qualitative indicators set out in Article 43 (for ART) and Article 56 (for EMT), with details in Commission Delegated Regulation (EU) 2024/1506. The largest globally-relevant stablecoins are designed to fall into this category.
Penalties (Article 111)
MiCA leaves the choice of administrative-fine architecture partially to Member States, but it sets minimum levels that every NCA must be empowered to impose. The structure does not run on a single ladder — it depends on which category of breach is at stake. The headline figures:
Legal persons (Article 111(3) and 111(5)):
| Breaches | Minimum maximum fine |
|---|---|
| Issuer obligations for ordinary crypto-assets — Articles 4-14 | At least €5,000,000 or 3% of total annual turnover, whichever is higher |
| Issuer obligations for ART (selected provisions of Articles 16-47) and EMT (Articles 48-55) | At least €5,000,000 or 12.5% of total annual turnover, whichever is higher |
| CASP authorisation and conduct obligations — Articles 59, 60, 64 and 65-83 | At least €5,000,000 or 5% of total annual turnover, whichever is higher |
| Public disclosure of inside information — Article 88 | At least €2,500,000 or 2% of total annual turnover, whichever is higher |
| Insider dealing, market manipulation, unlawful disclosure — Articles 89-92 | At least €15,000,000 or 15% of total annual turnover, whichever is higher |
Natural persons (Article 111(2)):
| Breaches | Minimum maximum fine |
|---|---|
| General issuer/CASP obligations | At least €700,000, or twice the profit gained / loss avoided |
| Public disclosure of inside information — Article 88 | At least €1,000,000 |
| Market-abuse breaches — Articles 89-92 | At least €5,000,000, or three times the profit gained / loss avoided |
Member States may go higher, and they choose how to apportion fines between administrative and criminal penalties (Italy and a handful of others layer additional national tariffs). Beyond fines, NCAs have the power to withdraw a CASP authorisation, prohibit individuals from holding management positions, suspend trading in a token, and order public statements identifying the breach — sanctions that in practice often hit harder than the monetary fine.
How MiCA overlaps with other EU regimes
- GDPR — applies in parallel. CASPs hold customer KYC and transaction data; data protection obligations sit on top of MiCA. See our GDPR pillar.
- AML / CTF (AMLR / AMLD6) — every CASP is also an “obliged entity” under EU anti-money-laundering rules. CASP authorisation under MiCA does not replace AML registration / supervision; the two regimes apply together.
- DORA — operational resilience for financial entities, including CASPs (DORA explicitly lists CASPs as in-scope). See our DORA pillar.
- MiFID II — crypto-assets that qualify as financial instruments stay under MiFID. The boundary between “MiCA crypto-asset” and “MiFID financial instrument” is set by ESMA guidelines and remains an active area of supervisory clarification.
- EU Travel Rule (Transfer of Funds Regulation, Regulation (EU) 2023/1113) — applies to transfers of crypto-assets between CASPs from 30 December 2024.
What’s actually happening as of May 2026
- The CASP authorisation race is largely played out. As of 30 April 2026, the ESMA MiCA Register listed 194 authorised CASPs — BaFin (Germany) leading with 55, followed by the Netherlands (25), France (13), Malta (12), Cyprus (12), Ireland (11, including Kraken via Payward) and Austria (9); Luxembourg authorised Coinbase. Italy started later — no Italian CASPs in the register, with CONSOB’s first authorisation phase opening April 2026 and the national transitional deadline set for 30 June 2026. National grandfathering windows are closing through 2025–2026, with the last (1 July 2026 absolute maximum) approaching.
- The stablecoin market re-formed around MiCA-authorised issuers. USDT was removed from major EU exchanges in late 2024 / early 2025; USDC, EURC and a small number of other authorised stablecoins now dominate EEA on-ramps. Full timeline and the EBA significance test: MiCA stablecoins register.
- Significant designations under Articles 43 and 56 are being made on a rolling basis by the EBA. The first significance decisions affect the largest issuers active in the EEA.
- First enforcement actions by NCAs have been announced or are pending — primarily for unauthorised activity during the grandfathering window or for breaches of the white-paper rules. A dedicated klarproof MiCA enforcement registry is forthcoming.
What this means for you
If you issue a stablecoin (ART or EMT) intended for EU users:
- Authorisation is not optional. EMTs must come from a credit institution or an authorised e-money institution; ARTs require a separate MiCA authorisation. Plan a multi-month application cycle.
- Reserve composition, segregation and monthly disclosure are continuous obligations, not one-off.
- If your token is large enough to meet three of the seven significance criteria — assume EBA will eventually take over supervision and budget for the higher prudential bar.
If you operate a CASP (exchange, custody, broker, advisor, transfer service):
- Pick your home NCA strategically. BaFin, AMF, Central Bank of Ireland and Luxembourg’s CSSF are the big established hubs; smaller NCAs may approve faster but offer less institutional weight.
- Track your national grandfathering deadline carefully. Operating beyond the deadline without authorisation is unlawful — the absolute backstop is 1 July 2026.
- A MiCA authorisation is not a complete licence. You also need AML/CTF registration, GDPR compliance for customer data, and (where applicable) DORA operational-resilience controls.
If you are a retail user or a custodian of crypto-assets for clients:
- Use only MiCA-authorised CASPs for EEA business. The ESMA MiCA Register is the authoritative public source.
- Stablecoins available in the EEA should now be EMTs from authorised issuers. Holding non-authorised stablecoins (USDT) within an EEA-licensed CASP is no longer possible by default.
TL;DR
MiCA is the EU’s first comprehensive crypto regulation, applied in two waves: stablecoins (ART, EMT) since 30 June 2024, all other crypto services and issuers since 30 December 2024. Existing operators can continue under national rules through transitional periods that end no later than 1 July 2026. Three regulated categories of crypto-assets (ART, EMT, other); 10 regulated services from custody and exchange to advisory and portfolio management; CASP authorisation is by a single national regulator and passports across the EEA. Stablecoin issuers face the strictest regime — authorisation, 1:1 reserve, redemption at par; significant issuers go under direct EBA supervision. Penalties run up to €15M or 15% of turnover for the most serious legal-person breaches (market abuse — Articles 89-92), with €5M minima for natural persons in the same category. Real-world impact in 2025: USDT removed from major EU exchanges; Coinbase, Bitpanda and Kraken authorised in different Member States; the rest of the market still working through the authorisation pipeline.
Sources
- Regulation (EU) 2023/1114 — full text on EUR-Lex — official source of MiCA
- ESMA’s MiCA hub — coordinating role, technical standards, MiCA Register
- EBA’s supervisory role under MiCA — direct supervision of significant issuers
- European Commission — summary of the crypto-assets regulation
- ESMA list of MiCA grandfathering periods (Article 143(3)) — Member State by Member State
- ESMA Chair Verena Ross to step down at the end of her current term
- François-Louis Michaud takes up role as EBA Chair (April 2026)
- Coindesk — Bitpanda secures MiCA license from BaFin (January 2025) — the early CASP authorisation race
- aosphere — Member State Implementation of MiCA tracker — grandfathering periods country by country
- ESMA Databases and Registers (MiCA Register) — pan-EU register of authorised CASPs and stablecoin issuers; the country-by-country counts cited above were taken directly from the official
CASPS.csvsnapshot (last update 30 April 2026) - CONSOB — MiCAR CASP regime — Italian fee schedule and authorisation phases
- AMF — MiCA Regulation: AMF now accepting applications for authorisation as a CASP — French CASP authorisation