LEGAL NODES

Get MiCA Compliant with Legal Nodes

Book a call to get started
Schedule free discovery call
400+ companies already use Legal Nodes

The transitional period under the EU's Markets in Crypto-Assets Regulation ended on 1 July 2026. If you provide crypto-asset services to clients in the EU without the required MiCA authorization or another valid basis under the Regulation, you are no longer operating in a transitional grey zone — you are operating in breach of EU law.

First published in 2023, this is a different article from the one most founders read at that time, or even in 2024. MiCA is no longer something to prepare for. It is a live authorization regime, supervised by national regulators, with a public register of who is authorized and who is not.

This guide is an up-to-date overview of MiCA — what it applies to, who has to comply, how the issuer and service-provider regimes differ, and where the framework actually stands as of August 2026.

This piece is brought to you by the team at Legal Nodes, including our Web3 legal expert Ilona Maklakova

Please note: none of this information should be considered as legal, tax, or investment advice. Whilst we've done our best to make sure this information is accurate at the time of publishing, laws and practices may change. Talk to usto discuss your project and MiCA compliance.

What is the Markets in Crypto-Assets regulation?

The Markets in Crypto-Assets Regulation, Regulation (EU) 2023/1114 (MiCA), is the EU's harmonized framework for crypto-asset issuance, public offers, admission to trading, and crypto-asset services. It is a Regulation, not a directive, so it applies directly in all 27 Member States without national transposition.

MiCA entered into force on 29 June 2023. Under Article 149, Titles III and IV — the asset-referenced token and e-money token regimes — applied from 30 June 2024, and the rest of the Regulation applied from 30 December 2024.

MiCA primarily covers crypto-assets that do not already qualify as financial instruments or as certain other products regulated under existing EU financial-services legislation. Article 2(4) puts financial instruments, deposits, funds, securitisation positions, insurance products and pension products outside MiCA entirely. On top of that, MiCA builds two dedicated regimes for stablecoin-type assets: asset-referenced tokens and e-money tokens.

In practice, that means a security token that is a transferable security under MiFID II does not become a MiCA product. It stays in the existing financial-services framework. ESMA (European Securities and Markets Authority) published guidelines on the conditions and criteria for the qualification of crypto-assets as financial instruments on 17 December 2024, and they are the starting point for that assessment.

MiCA's trigger is activity in the Union. Under Article 2(1), it applies to persons engaged in the issuance, offer to the public and admission to trading of crypto-assets, or that provide crypto-asset services, in the Union. Where you are incorporated is not the test. A third-country firm cannot serve EU clients without authorization, save for the narrow exception in Article 61, where the client initiates the service at its own exclusive initiative — and that exception fails the moment you solicit, market or advertise in the Union.

What does MiCA apply to?

Before you classify your token, ask whether it is in scope at all. A crypto-asset is defined in Article 3(1)(5) as a digital representation of a value or of a right that can be transferred and stored electronically using distributed ledger technology or similar technology. But Article 2(3) excludes crypto-assets that are unique and not fungible, and Article 2(4) excludes financial instruments, deposits, funds and the rest of the list above.

Only once your asset survives that gate do MiCA's three buckets matter:

The third bucket is where most founder projects sit. If your token is not an EMT or an ART, and it is not a financial instrument under MiFID II, Title II is your regime.

Where NFTs sit

MiCA does not apply to crypto-assets that are unique and not fungible with other crypto-assets. That is Article 2(3), and it is narrower than it sounds. Assigning a unique identifier to a token does not, on its own, make it non-fungible. If you issue what is effectively a large series of interchangeable tokens, or you fractionalize an NFT, expect the asset to be assessed on its economic characteristics rather than its label. And an NFT that behaves like a utility token or a financial instrument is treated accordingly.

Where DeFi and DAOs sit

MiCA does not exempt DAOs, DeFi protocols or dApps as categories. The statutory concept, set out in Recital 22, is narrower: crypto-asset services provided in a fully decentralized manner without any intermediary fall outside the Regulation.

In practice, that is a high bar, and decentralization is a spectrum rather than a switch. If you operate a front-end interface, control upgrade keys, run a treasury, or take a fee, you should assume a regulator will look for the intermediary before accepting that there isn't one. If you offer an interface to EU-based users, get the analysis done rather than assumed.

Who has to comply with MiCA?

MiCA regulates two distinct populations, and a business can sit in both.

Issuers, offerors and persons seeking admission to trading. If you issue an ART or an EMT, you are in Title III or Title IV. If you publicly offer a Title II crypto-asset or seek its admission to trading, Articles 4 and 5 apply to you. None of this makes you a crypto-asset service provider.

Crypto-asset service providers (CASPs). Under Article 3(1)(15), a CASP is a legal person or other undertaking whose occupation or business is the provision of one or more crypto-asset services to clients on a professional basis.

Read more: a practical MiCA guide for CASP founders.

Article 3(1)(16) lists 10 crypto-asset services:

  • Custody and administration of crypto-assets on behalf of clients
  • Operation of a trading platform for crypto-assets
  • Exchange of crypto-assets for funds
  • Exchange of crypto-assets for other crypto-assets
  • Execution of orders for crypto-assets on behalf of clients
  • Placing of crypto-assets
  • Reception and transmission of orders for crypto-assets on behalf of clients
  • Providing advice on crypto-assets
  • Providing portfolio management on crypto-assets
  • Providing transfer services for crypto-assets on behalf of clients

If what you do appears on that list and you do it for clients on a professional basis, you need authorization under Article 63 — or you need to be one of the existing financial entities that may provide crypto-asset services under Article 60 after notifying your competent authority at least 40 working days in advance.

Who supervises and enforces MiCA?

MiCA is supervised and enforced primarily by designated national competent authorities (NCAs). Under Article 93, each Member State designates its competent authorities and notifies EBA (European Business Association) and ESMA; where several are designated, one acts as the single point of contact for cross-border cooperation. Your NCA is the body that grants, refuses or withdraws your authorization and that supervises you day to day.

ESMA and EBA perform EU-level functions. ESMA maintains the public registers of white papers, authorized CASPs and non-compliant entities, and drives supervisory convergence. EBA carries particular responsibility for significant ARTs and significant EMTs.

Because MiCA is a Regulation, Member States do not transpose it. What they do is stand up the supervisory machinery — and that has not gone evenly.

As of August 2026, at least one Member State has not completed that step. The Polish Financial Supervision Authority has published a statement confirming that no national body has been designated as the competent authority for most crypto-asset activities in Poland, with the consequence that authorization proceedings cannot be opened there. If your structuring plan assumed a Polish CASP license, that plan needs revisiting.

Penalties sit with the NCAs. Under Article 111(3), maximum administrative fines for a legal person are EUR 5,000,000 and, additionally, a share of total annual turnover: 3% for breaches of Articles 4 to 14, 12.5% for breaches of the ART and EMT provisions in Articles 16 to 55, and 5% for breaches of the CASP provisions in Articles 59, 60, 64 and 65 to 83.

What are the key points of MiCA?

One authorization, but passporting has mechanics

MiCA replaced the patchwork of national VASP and CASP registration regimes for the services MiCA covers. It did not sweep away everything else: Member States still run their own regimes for activities outside MiCA, and AML, payments, securities, lending, gambling and tax obligations are unaffected.

Once authorized, you can serve clients across the EU. But it is not automatic. Under Article 65, you first notify your home competent authority of the Member States you intend to serve, the services you intend to provide, and your intended start date. Your home authority passes that to the host Member States, ESMA and EBA within ten working days.

What this means in practice is a short but real waiting period. You may start providing services in the new Member State once your home authority tells you the communication has been made, or at the latest from the 15th calendar day after you submitted the notification.

What authorization requires of your structure

Under Article 59(2), an authorized CASP must have:

  • A registered office in a Member State where it carries out at least part of its crypto-asset services
  • Its place of effective management in the Union
  • At least one director resident in the Union

Beyond that, Title V sets governance, prudential, conflicts, complaints-handling, outsourcing and wind-down requirements, plus service-specific duties. You must act honestly, fairly and professionally in your clients' best interests, and your marketing communications must be fair, clear and not misleading.

Where you hold client crypto-assets or funds, Article 70 requires you to safeguard them and to keep them segregated from your own. If you are advice-only, that obligation does not bite in the same way — but the governance, conduct and disclosure requirements still do.

If you reach at least 15 million active users in the Union on average in one calendar year — calculated as the average of the daily number of active users over the previous calendar year — you are a significant CASP under Article 85, and you must notify your competent authority within two months of reaching that number.

ICT resilience runs through DORA

MiCA does not set out CASP ICT requirements in full. It routes them. Article 68(7) and (8) require you to maintain resilient and secure ICT systems, ICT business continuity plans and ICT response and recovery plans as required by the Digital Operational Resilience Act, Regulation (EU) 2022/2554 (DORA), and to safeguard the availability, authenticity, integrity and confidentiality of data under the same Regulation.

DORA has applied since 17 January 2025. For a relevant MiCA-authorized CASP, that means ICT risk management, incident handling and reporting, resilience testing, and contractual arrangements with ICT third-party providers are current obligations, not a future work stream.

Rules for offering Title II tokens

If you offer a Title II crypto-asset to the public in the Union, Article 4(1) requires you to be a legal person, to draw up a crypto-asset white paper in accordance with Article 6, to notify it under Article 8, to publish it under Article 9, and to keep your marketing communications compliant with Article 7.

A crypto-asset white paper is a MiCA disclosure document. It is not a prospectus under the Prospectus Regulation, and calling it one invites the wrong compliance analysis.

You do not need authorization to issue a Title II token. What you need is the disclosure, and an entity behind it.

Article 4(2) exemptions from the white paper and publication requirements:

  • The offer is made to fewer than 150 natural or legal persons per Member State, where those persons act on their own account
  • Over 12 months from the start of the offer, total consideration across the Union does not exceed EUR 1,000,000
  • The offer is addressed solely to qualified investors and the crypto-asset can only be held by such qualified investors

Article 4(3) exclusions — Title II does not apply where:

  • The crypto-asset is offered for free (and it is not free if you take personal data, fees, commissions, or other benefits in return)
  • The crypto-asset is automatically created as a reward for maintaining the distributed ledger or validating transactions
  • The offer concerns a utility token providing access to a good or service that exists or is in operation
  • The holder may use the crypto-asset only in exchange for goods and services in a limited network of merchants with contractual arrangements with the offeror

These are narrower than they look, and several carry their own conditions and notification thresholds. Treat the list as the start of an analysis, not the end of one.

Some retail buyers also get a right of withdrawal, but it is narrower than a general cooling-off period. Under Article 13, retail holders who purchase a Title II crypto-asset directly from the offeror, or from a CASP placing it on the offeror's behalf, generally have 14 calendar days to withdraw without fees or giving reasons. The right does not apply where the asset was already admitted to trading before the purchase, and it cannot be exercised after the end of a time-limited subscription period.

Read more: a practical MiCA guide for token issuers.

Tokens with no issuer

Some crypto-assets have no identifiable issuer or offeror. MiCA handles this through admission to trading. Under Article 5(2), where a crypto-asset is admitted to trading on the initiative of the platform operator and no compliant white paper has been published, the operator must meet the Article 5(1) requirements itself.

That is a defined set of disclosure and admission obligations. It is not a transfer of general liability for the asset to the exchange.

Stablecoins: two regimes, not one

MiCA does not impose a blanket ban on algorithmic stablecoins. No provision prohibits them. What MiCA does is classify. An ART, under Article 3(1)(6), is a crypto-asset that is not an EMT and purports to maintain a stable value by referencing another value or right or a combination of them. An EMT, under Article 3(1)(7), references the value of one official currency.

So an asset that tries to hold a stable value purely through a supply-adjustment mechanism, without referencing any asset, may fall outside both definitions and be assessed as a Title II crypto-asset instead. Classification follows the asset's actual characteristics, not its marketing.

Asset-referenced tokens. Under Article 16(1), you may only offer an ART to the public or seek its admission to trading in the Union if you are the issuer and you are either established in the Union and authorized under Article 21, or a credit institution complying with Article 17. Article 16(2) exempts an issuer where, over 12 months, the average outstanding value of the ART never exceeds EUR 5,000,000 and the issuer is not linked to a network of other exempt issuers, or where the offer is addressed solely to qualified investors and the ART can only be held by such investors. A white paper is still required in both cases. [UPDATED: both limbs of Article 16(2) were incomplete — the "not linked to a network of other exempt issuers" condition and the "can only be held by" restriction are statutory, and dropping them made the exemption look wider than it is.]

ART issuers must constitute and maintain a reserve of assets under Article 36, legally and operationally segregated from the issuer's own estate. That reserve is subject to an independent audit every six months under Article 36(9).

E-money tokens. There is no separate "EMT authorization" in the same sense. Under Article 48(1), you may only offer an EMT to the public or seek its admission to trading if you are the issuer and you are already authorized as a credit institution or as an electronic money institution, and you have notified and published a crypto-asset white paper under Article 51.

EMTs are also deemed to be electronic money under Article 48(2), and Titles II and III of the E-Money Directive apply unless MiCA says otherwise. Article 49 requires you to issue EMTs at par value on receipt of funds, to redeem them at any time at par value on the holder's request, and not to charge a redemption fee.

The practical takeaway is that "backed 1:1" is not a single MiCA rule. ARTs are governed by a reserve-of-assets regime; EMTs are governed by an e-money architecture with par-value issuance and redemption. Both ARTs and EMTs can additionally be classified as significant by EBA, which brings heightened supervision.

Where MiCA stands in 2026

‍

The current position. Article 143(3) allowed providers that were operating lawfully under national law before 30 December 2024 to continue until 1 July 2026, or until they were granted or refused authorization under Article 63, whichever came first. Member States could shorten that window or not apply it at all. Firms operating under it were never MiCA-authorized CASPs — they were running out a clock.

That clock has stopped. ESMA confirmed the position in a statement on the end of transitional periods under MiCA on 17 April 2026, and again in a public statement on 23 June 2026, in which it stated that unauthorized providers must stop onboarding new EU clients and limit activity to what is necessary for clients to sell or transfer their crypto-assets.

If you provide in-scope crypto-asset services in the EU today, you need MiCA authorization under Article 63, or another valid basis under Articles 59 and 60 — or you need to be within the narrow reverse-solicitation exception in Article 61. There is no fourth option.

The Transfer of Funds Regulation

Regulation (EU) 2023/1113 — the recast Transfer of Funds Regulation, and the EU's implementation of the FATF travel rule — has applied since 30 December 2024. Articles 14 and 16 require the originator's and the beneficiary's CASP to ensure that transfers of crypto-assets are accompanied by prescribed originator and beneficiary information, to detect missing or incomplete information, and, for transfers above EUR 1,000 involving a self-hosted address, to take adequate measures to assess whether that address is owned or controlled by their client.

Keep it separate from MiCA in your compliance mapping. Different instrument, different obligations, same supervisor in most Member States.

Your MiCA self-assessment

Work through these in order. Each one changes what you have to do next.

  1. Is your asset in scope at all, or is it a financial instrument, deposit, fund, or genuinely unique and non-fungible?
  2. If it is in scope, is it an EMT, an ART, or another crypto-asset?
  3. Are you an issuer or offeror, a service provider, or both?
  4. If you provide services, do any of the 10 services in Article 3(1)(16) describe what you do?
  5. Do your users sit in the EU — and if you say no, would a regulator agree, given your interface, marketing and payment rails?
  6. Do you hold client crypto-assets or funds?
  7. Do you have a registered office in a Member State where you provide services, effective management in the Union, and at least one EU-resident director?

How to read the results. A yes to 4 and 5 means you need authorization now, not a plan to get it. A yes to 6 raises the prudential and safeguarding bar considerably. A no to 7 means your structure needs work before an application is worth filing. And if you answered "it depends" to 1 or 2, that is the question to resolve first — every other answer flows from it.

Commonly asked questions about MiCA

Does MiCA apply to my company if we are incorporated outside the EU? If you provide crypto-asset services in the Union, yes. Article 2(1) turns on activity in the Union, not on where you are registered. The only carve-out is Article 61, where an EU client approaches you entirely on its own initiative — and it does not survive any solicitation, marketing or advertising into the Union.

Do I need a MiCA license to launch a utility token? Not for the issuance itself. A public offer of a Title II crypto-asset requires a legal person and a compliant white paper under Article 4(1), not an authorization — unless one of the Article 4(2) exemptions or Article 4(3) exclusions applies.

Are algorithmic stablecoins banned in the EU? No. MiCA contains no such prohibition. Whether an algorithmic design is an ART depends on whether it purports to maintain a stable value by referencing another value or right under Article 3(1)(6). If it does not reference assets, it is assessed under Title II.

Can I still rely on my old national VASP registration? No. The maximum transitional window under Article 143(3) closed on 1 July 2026.

Does MiCA cover NFTs? Not where they are genuinely unique and not fungible (Article 2(3)). Large fungible series and fractionalized NFTs are a different analysis, and an NFT with utility-token or financial-instrument characteristics is treated on those characteristics.

What happens if we operate without authorization? Your NCA can impose administrative penalties under Article 111 and you can be listed on ESMA's public register of non-compliant entities. ESMA's June 2026 statement also expects unauthorized firms to stop onboarding EU clients and to wind down in an orderly way.

How do I check whether a provider is authorized? Through the registers ESMA maintains under MiCA, published on the ESMA MiCA page.

Conclusion about MiCA in 2026

MiCA has stopped being a forecast. The definitions are settled, the guidelines are out, the registers are live, and the transitional period is gone. What remains is execution: classifying your asset correctly, deciding which regime you are in, and building the structure the authorization actually requires.

The mistakes that cost the most are the early ones. A token classified wrongly at design stage, or an entity set up in a Member State that cannot process your application, is expensive to unwind after you have users.

That is the kind of cross-border structuring problem Legal Nodes is built to solve. Through a single point of contact, we help founders classify their assets, choose a workable Member State, and put the entity, governance and disclosure documents in place that a MiCA application depends on. If you are offering tokens or crypto-asset services into the EU, get in touch to pressure-test your setup against the rules as they now stand.

Disclaimer: the information in this article is provided for informational purposes only. You should not construe any such information as legal, tax, investment, trading, financial, or other advice.

TABLE OF CONTENTS