What Article 61 Actually Allows
Under MiCA, Article 59 is the rule: to provide crypto-asset services to clients in the Union, you must be authorised as a CASP by an EU or EEA regulator, and that authorisation then passports across all 30 EEA states. Article 61 is the only exception, and it is a narrow one. A non-EU firm may serve an EU client without a CASP licence only where that client initiated the specific service at their own exclusive initiative. Article 61(2) goes further and bars the firm from using that first contact to market new types of crypto-assets or services to the same client.
The regulator does not care what your client contract says. It looks at whether the enquiry would have happened without your EU-facing marketing, infrastructure and domains. A pre-signed client declaration claiming reverse solicitation is worthless against the facts of your site, paid traffic, influencers and affiliate structure — and a single investigation covers all of it at once, so partial compliance across different jurisdictions does not help.
Definition: reverse solicitation
Definition
Reverse solicitation, in the Article 61 sense, is the provision of a crypto-asset service to an EU client by a non-EU firm that holds no CASP authorisation, where the client initiated that specific service at their own exclusive initiative. It covers the service the client asked for and the relationship that flows from it. Article 61(2) prohibits using the client’s first contact to market new types of crypto-assets or services to them. Marketing of the same type is allowed only in the context of the original transaction.
Scope: the EU and the EEA
Article 61 covers the full MiCA passport area: all 30 EEA states, with Iceland, Liechtenstein and Norway brought in by EEA Joint Committee Decision No 41/2025 and subject to each state completing its domestic implementation. The United Kingdom, Switzerland and Gibraltar sit outside the MiCA passport and require local authorisation for local clients. Article 61 governs only when a non-EU firm may serve EU and EEA clients.
What Defeats the Exception
ESMA, the European securities regulator, has told national regulators to read Article 61 narrowly. Two features make it operationally narrow in practice. The first is a long, deliberately open-ended list of marketing activities that defeat the exception outright. If you do any of these into the EU, the exception is gone, regardless of how the individual client says they found you:
- Targeted advertising into the EU, including geo-targeted impressions and retargeting. Naming a Member State is not required; geo-targeting alone is enough.
- EU-language websites, sign-up flows, terms or onboarding interfaces. English is treated as customary in international finance and is a weaker signal on its own, but it is no safe harbour once combined with other indicators.
- EU country-code domains (.fr,.de,.it,.nl,.pl and the rest) and country sub-directories such as /fr/ or /de/ paths on a.com.
- EU-targeted SEO: regional link building, geographic targeting, anything designed to surface your site to EU users for EU queries.
- Sponsorship of EU or Member-State events: conferences, trade-show booths, hackathons, sporting sponsorships.
- EU-based influencers. Payment is a strong indicator but is not required; the test runs through the influencer’s audience.
- Affiliate or referral programmes that route EU traffic into your onboarding flow. The architecture is what is scrutinised, not the wording of the affiliate contract.
- App-store availability in EU Member States.
- Push notifications cross-selling new or trending products to existing clients.
- Bundling extra services around a single client request, and EU-regulated intermediaries redirecting clients to a non-EU group affiliate.
The second feature is Article 61(2): you cannot use a reverse-solicited client’s first contact to market new types of crypto-assets or services to them, and even same-type marketing is allowed only in the context of the original transaction. The two together mean you cannot acquire EU clients through marketing, and you cannot use the one client who did come to you as a beachhead for selling more. The test throughout is factual, not what you call it: a signed client declaration carries no weight against contrary facts, because Article 61 applies notwithstanding any contractual clause or disclaimer that says otherwise.
The Time Limit and the Same-Type Rule
The most misunderstood part of Article 61 is the so-called one-month rule. ESMA uses one month as an illustration, not a statutory ceiling, and it deliberately declined to fix any fixed period because the answer depends on the facts. The one month does not cap the original service relationship, which can continue. What it limits is further marketing to a client who has already been reverse-solicited: after enough time has passed, you can no longer plausibly say that further contact is at the client’s own initiative.
So any further marketing to that client has to clear two limbs. New types of crypto-assets or services are prohibited at all times, even in the days immediately after the first contact. The same type is permitted only in the context of the original transaction. Whether two products are the same type is assessed case by case, on their category and the risks attached to them, and the line has to be drawn granularly enough that the exception cannot be used to sidestep the Article 59 licensing requirement. Utility tokens, asset-referenced tokens and e-money tokens are treated as different types, as are assets on different technologies and liquid versus illiquid assets.
Where you are in any doubt, the clean position is to stop taking new EU clients or to geo-block EU access, including blocking EU IP addresses and removing your app from EU app stores. Geo-blocking does not cure past conduct, but paired with a documented internal policy it is a credible forward-looking posture.
Why It Is Not a Market-Entry Route
Put the two features together and Article 61 is structurally unsuitable as a way into the EU market for any firm that wants sustained EU-client business. The drafting was designed to prevent exactly that use. As soon as you build any EU-facing infrastructure, a translated site, an EU domain, paid traffic, an influencer deal, an affiliate scheme, EU-targeted SEO or an EU app listing, the exception is gone. As soon as you use a reverse-solicited client to expand into new products, Article 61(2) is breached.
An offshore licence remains genuinely useful for non-EU client bases, token-issuance vehicles, holding structures and fund domiciliation. It simply does not provide a route to a recurring book of EU clients. That book has to run through a separately authorised EU or EEA CASP. The penalties for getting this wrong are not trivial: under MiCA Article 111, unauthorised provision of crypto-asset services exposes a company to administrative fines of at least EUR 5 million and individuals to at least EUR 700,000, Member States can set higher figures, and several apply criminal sanctions on top.
How Regulators Enforce It
Enforcement runs through the national regulator in each Member State, with ESMA pressing them to converge on a consistent approach. The investigative pattern is the same everywhere, even where the procedural pathways differ. A regulator does not look at the form of your client contract; it looks at your entire EU-facing footprint and asks whether the client’s contact would have happened without it.
The evidence chain is predictable. The regulator reviews the site for language coverage, EU country-code domains and Member-State references; the marketing for EU-targeted creative; the social and influencer activity for EU audiences; the sponsorships and event presence; the affiliate and referral architecture, down to tracking pixels and revenue-share terms; and the timing of onboarding against the marketing calendar. Only then does it ask whether the client really came of their own initiative.
The regulators most active here include the French AMF, which aligned formally with the ESMA Guidelines and has long held that a firm cannot manufacture reverse-solicited status with pre-drafted client declarations; Germany’s BaFin; Italy’s CONSOB, the most visible enforcer, which orders the blocking of unauthorised crypto sites on a rolling basis under its blocking powers; the Netherlands’ De Nederlandsche Bank, which has imposed multi-million-euro fines on non-EU crypto firms operating without registration; Luxembourg’s CSSF; and Cyprus’s CySEC. The procedural tool varies, from a public warning to an order to cease, a monetary penalty or a criminal referral, but the assessment of what defeats Article 61 is shared across all of them.
The Compliant Route: An EU CASP Licence
If you want to serve EU clients on an ongoing basis, the answer is not a cleverer reading of Article 61. It is an EU-incorporated company authorised as a CASP, which passports across all 30 EEA states. We form that company, prepare and file the application, and deal with the regulator directly until the licence is in hand. There are two practical structures, plus a disciplined fallback for firms with only incidental EU contact.
EU CASP authorisation
You form an entity in an EU Member State, apply for CASP authorisation under Article 63 of MiCA, and passport under Article 65. The authorising regulator expects real substance in the country, so paper-only structures do not get authorised. MiCA tiers the minimum capital by the services you want: EUR 50,000 for the lighter permission set, EUR 125,000 once you add custody and exchange services, and EUR 150,000 to run a trading platform, with a parallel test tied to a quarter of your fixed annual overheads. We handle entity formation, the application file, the regulator liaison and the post-authorisation compliance, with one point of contact throughout. Common entry points include Lithuania, Cyprus and Malta; the right choice depends on language, processing time, infrastructure and banking access, which we work through with you before you commit.
EEA passport via the EFTA states
MiCA was brought into the EEA Agreement by EEA Joint Committee Decision No 41/2025, so Iceland, Liechtenstein and Norway can authorise CASPs that passport on the same Article 65 basis, once each state has completed its domestic implementation. The substantive requirements track MiCA. This route suits operators with a specific preference for the EFTA states; we confirm the in-force position before recommending it.
Dual-jurisdiction structuring
Operators with both offshore and EU client bases often pair an offshore operating company with an EU CASP-authorised affiliate. The offshore entity serves non-EU clients; the EU affiliate serves EU clients via passport; an intercompany agreement covers any shared technology, treasury or compliance. It keeps the offshore efficiency for non-EU revenue while giving you a fully compliant EU pathway. Where a firm genuinely has only incidental, non-recurring EU contact, a disciplined reliance on Article 61 can remain workable, but only with no EU-targeted marketing of any kind, rigorous documentation of each client’s initiative and strict adherence to the Article 61(2) limit. It does not scale, and we will tell you plainly when it is not enough.
How We Deliver It
We are a formation and licensing firm, not an introducer. We assess where your current EU activity sits against Article 61, recommend the right structure, then form the company and obtain the licence ourselves. We work through a controlled network of vetted in-country lawyers, accountants and licensed specialists, alongside our own in-house work, and we never hand a client to an unverified third party. One accountable relationship, start to finish.
- Assessment. We review your website, marketing, SEO, social and influencer activity, sponsorships, affiliate architecture and client communications against the solicitation indicators and the Article 61(2) limit, and tell you in writing whether your EU activity is inside or outside the exception, with a fix where it is outside.
- Recommendation. We pick the right structure for your business: which Member State, which capital class, which timeline, or an EFTA or dual-jurisdiction route where that fits better.
- Delivery. Company formation, application preparation, regulator liaison and post-authorisation compliance, with supporting banking arranged in parallel so you are operational at authorisation.
Banking, as a supporting step
An EU CASP is only operational once it can bank. As part of the engagement we arrange banking for your authorised entity through a licensed EU credit institution or EMI suited to crypto-asset activity, and run that placement alongside the licence application so the two land together. More on banking and payments →
Frequently Asked Questions
What is reverse solicitation under MiCA Article 61?
It is a narrow exception to the rule, in Article 59 of MiCA, that crypto-asset services to clients in the Union must be provided by an authorised CASP. The exception applies only where an EU client initiates the service at their own exclusive initiative. ESMA’s Guidelines, applicable from 27 April 2025, read it restrictively: any EU-targeted marketing defeats it, and Article 61(2) bars a firm from using that first contact to sell the client new types of crypto-assets or services. It is not a route to build a recurring EU client base.
Can a non-EU crypto firm use reverse solicitation to enter the EU market?
No, not as a strategy. Article 61 tolerates the genuinely unsolicited inbound enquiry; it does not support a book of EU clients served from offshore. As soon as you build any EU-facing infrastructure, EU-language pages, EU country-code domains, paid traffic, influencers, affiliates, EU-targeted SEO or app-store listings, the exception is gone. Sustained EU business requires an EU-incorporated, CASP-authorised entity that passports across the EEA. We form that entity and obtain the licence for you.
What activities defeat the Article 61 exemption?
ESMA gives an illustrative, non-exhaustive list of solicitation indicators: targeted advertising into the EU, EU-language websites, EU country-code top-level domains and country sub-directories, EU-targeted SEO, sponsorship of EU events, EU-based influencers, affiliate or referral programmes that route EU traffic, app-store availability in EU Member States, push notifications cross-selling new products, and bundling beyond what the client asked for. The test is not your stated intent but whether the client’s contact was genuinely at their own initiative. Contractual disclaimers do not override the facts.
Is there a one-month rule, and what does it limit?
The one month is an ESMA example, not a statutory ceiling. It limits the marketing of further transactions or further crypto-assets to a client who has already been reverse-solicited; it does not limit the original service relationship itself, which can continue. Marketing of new types of crypto-assets or services to that client is prohibited at all times under Article 61(2). Marketing of the same type is allowed only in the context of the original transaction.
Does reverse solicitation apply to the EEA states outside the EU?
Yes, conditionally. MiCA was brought into the EEA Agreement by EEA Joint Committee Decision No 41/2025, so Iceland, Liechtenstein and Norway sit within the MiCA passport regime and the Article 61 framework, subject to each state completing its domestic implementation. The United Kingdom, Switzerland and Gibraltar sit outside the MiCA passport and require local authorisation for local clients.
What replaces reverse solicitation for serving EU clients?
An EU-incorporated CASP authorisation under Article 63 of MiCA, which passports across all 30 EEA states under Article 65. We form the entity, prepare and file the application, deal with the regulator directly, and stand behind the outcome. We deliver CASP licensing in Lithuania, Cyprus, Malta, Poland, Switzerland and other European jurisdictions, and arrange supporting banking. Book a free consultation for a recommendation on the right jurisdiction for your business.
Serving EU clients? Get it right from the start.
If you want a recurring EU client base, Article 61 will not carry it. We form your EU company, file the CASP application, deal with the regulator directly and arrange the banking. One accountable firm, end to end. Tell us about your business and we will recommend the right route.
Banking & Payments
A company and a licence still need a bank account
Banking is one of our three core services. We help high-risk and regulated businesses open the bank and payment accounts that others refuse: we work directly with EU EMIs, payment institutions and crypto-aware banks, confirm appetite before you apply, and make the introduction. Take it with your company and licence, or on its own.
Related Services
- Crypto Licensing Overview: our CASP, VASP and MiCA licensing work across Europe
- Lithuania CASP Licence: a fast, cost-effective EU MiCA route
- Cyprus CASP Licence: MiCA authorisation with English-language regulatory infrastructure
- Malta CASP Licence: an established MiCA route under the MFSA
- European Company Formation: EU and EEA entity formation for MiCA passporting
- Banking & Payments: account access for your authorised EU entity
- Crypto Exchanges: the full licensing, formation and banking stack for exchange operators