On 1 July 2026, the Markets in Crypto-Assets Regulation transitional period ends. Crypto-asset service providers that were operating before 30 December 2024 and have not yet obtained CASP authorisation must stop providing services to EU clients after that date, or face operation without a licence. There is no extension.
Key points
- Grandfathering ends on 1 July 2026. Unauthorised CASPs cannot serve EU clients after this date.
- Reverse solicitation is a narrow carve-out, not a general exemption. Using it broadly invites supervisory scrutiny.
- Applications submitted before 1 July may still be processed, but you cannot onboard new EU clients while waiting.
- The practical filing window for a realistic authorisation by Q3 2026 has already closed. The window now is for an orderly application and a clear compliance position.
What grandfathering was
MiCA entered into force on 29 June 2023 and applied fully from 30 December 2024. To avoid an overnight cliff for existing operators, Article 143 created a transitional regime: firms that were providing crypto-asset services in an EU member state before MiCA’s application date, under existing national law, could continue providing those services until they received a decision on their CASP application or until 1 July 2026, whichever came first.
The intention was to give established operators 18 months to get through the authorisation process. In practice, the queues at national competent authorities lengthened considerably once the volume of applications became apparent in early 2025. That compression is now visible in pending-application lists across Lithuania, Malta, and Cyprus.
What changes on 1 July 2026
After 1 July 2026, no transitional cover remains. A CASP operating in the EU without authorisation is operating unlawfully, regardless of how long it has been in business, regardless of whether an application is pending, and regardless of any national notification it made before MiCA applied.
The practical consequences: supervisory action by the national competent authority (NCA) of the member state where the CASP has its registered office or principal place of business, potential prohibition orders, and reputational damage from enforcement announcements. Several NCAs have already published lists of entities operating without MiCA authorisation. Appearing on those lists carries consequences that extend beyond the regulatory proceeding itself.
The reverse solicitation carve-out
Article 61 of MiCA provides that the regulation does not apply to crypto-asset services provided exclusively at the own exclusive initiative of a client. This is what is commonly called reverse solicitation.
The carve-out is real but narrow. It applies to a specific transaction initiated by a specific client on their own initiative. It does not apply to: onboarding new EU clients after 1 July 2026, offering new services or new asset classes to existing clients, any general marketing directed at EU persons, or any platform feature that functions as an ongoing solicitation.
The European Securities and Markets Authority has been clear that reverse solicitation is not a business model. Firms using it as a general exemption from authorisation are exposed to the same supervisory risk as firms making no claim at all. The narrower the reliance, the more defensible the position; but any firm with significant EU client volume should not be planning around this carve-out as its primary compliance solution after 1 July.
Applications pending as of 1 July
An application submitted before 1 July 2026 does not preserve the right to continue serving EU clients while the NCA processes it. Grandfathering cover ends on 1 July regardless of application status. The only exceptions are firms that have already obtained a positive decision from their NCA, or firms that received a formal transitional confirmation under applicable national law that extends beyond the MiCA deadline.
This means the question for firms with pending applications is not whether to file but what to do with EU clients in the gap between 1 July and authorisation. The practical answer is to segment the client base, suspend active EU client onboarding, and continue servicing only existing EU clients under a carefully documented reverse-solicitation position where applicable. That is not a permanent solution but it is the compliance position that survives scrutiny better than the alternatives.
Jurisdictions where authorisation can still complete in 2026
The realistic timeframe for a full CASP authorisation filing and a positive decision depends heavily on the NCA. Lithuania’s LB has been processing applications on a six-to-nine month timeline for well-prepared files. Malta’s MFSA is broadly similar. Cyprus’s CySEC has been running longer on complex applications.
For a firm starting the process in June 2026, no EU jurisdiction can realistically deliver a decision before August at the earliest, and Q4 2026 is a more realistic target for most well-resourced files. The practical filing window for a pre-deadline authorisation closed several months ago. That said, an application in process at a credible NCA, with a well-prepared file and a documented compliance transition plan, is a materially different position than no application at all.
What we file
For operators who came to us in Q1 and Q2 2026, the filing strategy depended on jurisdiction, activity scope, and client base. We have been placing applications primarily in Lithuania and Malta for clients with significant EU retail exposure, and Cyprus for institutional and professional-client books.
The critical document package for a CASP application is well-understood: organisational structure, AML/CFT framework, safeguarding arrangements, business continuity plan, ICT governance documentation, and governance manuals that satisfy Article 68 MiCA requirements. The bottleneck is not the list of documents but the depth of each one. NCAs are asking detailed questions at validation stage, and files that arrive underspecified are being returned for completion rather than being processed.
For clients approaching us now, the focus is on building a defensible compliance position for the gap period and getting an application into the right NCA’s queue as quickly as possible. The timeline is not comfortable. But it is workable if the file is prepared properly.
Running an EU-facing CASP without MiCA authorisation?
We file CASP applications in Lithuania, Malta, and Cyprus. If you need to understand your options before 1 July, book a call. We will tell you what is realistic for your timeline and what the file needs to contain.
Related
- MiCA / CASP Licensing: Full authorisation route, NCA selection, and the application package we build
- Crypto Licensing (VASP / MiCA): Pre-MiCA and MiCA-era licensing across EU and offshore jurisdictions
- Back to Blog: More posts from Tomberg & Partners