A Market That Lost Its Licence Overnight
On 1 July 2026 the last of the national transitional periods under the Markets in Crypto-Assets Regulation expired, and with it the right of several thousand firms to serve customers in the European Economic Area. There was no extension anywhere in the bloc and no residual national regime to fall back on. Firms that had not been authorised as crypto-asset service providers were expected to be winding down, not applying.
The scale of the displacement is easy to underestimate because it is spread across business models rather than concentrated in one. Among those affected were native Web3 projects, over-the-counter desks, peer-to-peer platforms that operated on top of other exchanges, payment gateways processing crypto for merchants, issuers of crypto-linked cards, market makers, and retail trading platforms.
What these businesses have in common is that most of them never thought of themselves as regulated financial institutions. Many had operated for years under a light national registration and had built neither the capital position nor the governance apparatus that a MiCA application assumes. For them the regulation did not tighten an existing obligation; it created one from nothing.
The European Securities and Markets Authority was explicit about what compliance now looked like. In statements issued in April and June 2026 it told unauthorised providers to stop onboarding EU clients, open no new accounts, and cease all marketing and solicitation immediately. It also warned already-authorised firms that migrating inherited client books across was not a reason to relax anti-money-laundering checks.
The Numbers
MiCA is now widely described as the most demanding regulatory environment ever built for crypto businesses, and the authorisation statistics support that description rather than contradict it. By late July 2026 something over 300 CASPs were authorised across 26 EEA home states, against a pre-MiCA population of registered and unregistered participants several times larger. Alongside the register sits a warning list of well over a hundred entries.
The composition of the authorised population is as telling as its size. A substantial share of it consists of firms that did not go through the full Title V authorisation process at all, but relied instead on Article 60, which allows credit institutions, investment firms, electronic money institutions, fund managers and certain other regulated entities to provide crypto-asset services by notification rather than by fresh application.
This matters because it changes the composition of the European crypto market. The firms best placed to clear MiCA were the ones that were already licensed for something else, already carried regulatory capital, and already had a compliance function, a risk framework and an audited balance sheet. Incumbency, not innovation, turned out to be the decisive qualification.
The point is illustrated by which firms did not make it. Binance informed EU customers that it would be suspending certain services because it would not hold a MiCA licence by 1 July, having applied for authorisation in Greece and then withdrawn that application with a stated intention to reapply through another member state. When the largest exchange in the world cannot complete the process in time, the barrier is not primarily about willingness to comply.
Where the Displaced Went
The first response of many firms was geographic. Canada, the United States, South Africa, Argentina, El Salvador and Australia have all absorbed businesses that concluded the European authorisation path was too long, too expensive or too uncertain. In several cases the move was not a relocation of the whole business but the creation of a non-EU entity to hold the customer relationships that could no longer be served from inside the bloc.
This has a cost that is easy to miss at the point of decision. Leaving the EU perimeter solves the licensing problem and creates a market-access problem: the customers are still in Europe, and reaching them from outside is precisely what MiCA restricts. A firm that relocates without changing its customer base has moved the entity, not the exposure.
The second response, and the one now shaping the market, was to stay in Europe by borrowing somebody else’s authorisation. Providers that did obtain a licence have found that their permission has commercial value well beyond their own business plan, and a market has developed in which authorised CASPs accommodate the customers of firms that lost the right to operate.
Staying in the Market Without a Licence: The Grey-Label Model
Arrangements of this kind are usually marketed as white-label solutions. That description is misleading, and the distinction is not academic. MiCA neither mentions nor authorises anything resembling the agency model familiar from payments regulation, and the absence is deliberate rather than accidental.
Under the second Payment Services Directive, a payment institution may appoint agents who deal with customers in their own name, subject to registration. Under the second Markets in Financial Instruments Directive, investment firms may appoint tied agents on a comparable basis. MiCA contains no equivalent: no agent regime, no tied-agent register, and no mechanism by which an unlicensed firm can be permitted to perform regulated crypto-asset services under another entity’s authorisation.
The practical consequence is that the quasi-agency structure most firms believe they are buying does not exist in law. An unlicensed partner that onboards clients, decides who is accepted, holds assets or executes transactions is performing the regulated service, whatever the contract calls it. ESMA assesses activity by what is actually done, by whom and for whom, not by how it is labelled.
What MiCA does not prohibit is distribution. There is no rule that the brand a customer sees must belong to the licence holder, and a non-licensed entity may use its own brand provided that the authorised CASP genuinely provides every regulated service behind it. The workable structure is therefore better described as grey label rather than white label: the arrangement is disclosed rather than disguised.
How the Compliant Version Actually Works
The structure now used in practice is narrower than most propositions suggest, and it is worth setting out concretely because the margin for error is small.
The former service provider becomes, in substance, a marketing and introduction business. It transfers its clients to the authorised CASP in exchange for a referral fee, in the same way a marketing agency would, and receives a share of the resulting revenue for that introduction.
On the surface, the customer sees a platform carrying the former provider’s brand. Beneath the surface, the environment sits on the licensed entity’s domain, carries clear references to the licensed entity’s name and authorisation number, and every regulated function belongs to that entity.
Structured this way, the arrangement does not breach any provision of MiCA, and several national regulators have indicated that they regard it as acceptable. But the tolerance is conditional on substance, and two features distinguish the arrangements that hold up from those that do not.
The first is disclosure. Customer-facing material should state plainly that the partner is not a CASP, identify the authorised provider by legal name, name the competent authority and give the authorisation reference. ESMA reminded investors in June 2026 that MiCA protections attach to the specific authorised entity a client deals with, and not to group companies, non-EU affiliates or a shared brand. That disclosure must be complete across every page and every language version; an omission in one localised market is a breach in that market.
The second is how the fee is characterised. A marketing or introduction fee paid by the CASP to the partner is consistent with distribution. A share of the spread on customer transactions points towards the partner participating in the regulated service itself, and invites exactly the opposite characterisation.
Reverse Solicitation: Stricter in Crypto Than in Payments
The other route being widely discussed is reverse solicitation, and here the market’s intuition is frequently wrong. Firms arriving from payments assume the crypto version of the exception works the way they are used to. It does not; it is materially stricter.
ESMA has treated it as a genuinely narrow exception confined to services the client initiated entirely on their own initiative. Any marketing, promotion, advertising or solicitation directed at EU clients removes it. It cannot be used to offer additional categories of service to a client who approached the firm for something else, and it is not cured by a disclaimer on a website.
ESMA has also confirmed that the restriction on third-country firms serving EU clients applies in business-to-business contexts and not only in retail, which closes the argument that institutional dealing sits outside the perimeter. Separately, MiCA prevents CASPs from outsourcing or delegating certain services, custody in particular, to entities that are not themselves authorised.
Taken together, these mean that reverse solicitation is not a business model. It may lawfully describe an occasional inbound relationship. It cannot support a customer acquisition strategy, and a firm that builds one on it should expect the conclusion that the exception was never available in the first place.
Banking and Counterparty Access
The strictness of the EU perimeter has produced a consequence that receives less attention than it deserves, and that clients feel more immediately than any regulatory notice. Non-EU crypto service providers are finding it markedly harder to obtain banking and payment infrastructure.
Bank accounts, payment accounts and e-money accounts have all become more difficult to open for providers operating outside the EU perimeter, because the institution assessing the application must consider whether servicing that client draws it into facilitating unauthorised activity in the Union. Onboarding with OTC desks and trading platforms has tightened for the same reason, and in some cases marketing agencies have declined the work.
The pattern is familiar from other areas of financial regulation: a licensing perimeter is enforced not only by supervisors but by the commercial counterparties who do not wish to be on the wrong side of it. For a firm weighing relocation against grey-label distribution, this is a decisive practical factor and belongs in the analysis at the outset rather than after the move.
The Token Side
The picture on the issuance side is, if anything, more striking than the picture on services, and it divides sharply between the two categories of stablecoin that MiCA regulates.
E-money tokens, which reference a single official currency, have a functioning market. By spring 2026, 17 EMT issuers had been authorised, with France hosting the largest cluster of any member state. Circle secured French authorisation in July 2024, and USDC and EURC were compliant from the first day of the stablecoin regime.
Asset-referenced tokens, which reference a basket of currencies, commodities or other crypto-assets, have no market at all. As at the same date, the number of authorised ART issuers stood at zero. Not a small number, not a slow start: none.
The reason lies in the authorisation architecture rather than in demand. An EMT can be issued by any entity already authorised as a credit institution or an electronic money institution, which means the issuer clears a licensing bar it has usually already cleared and then notifies a white paper. Hundreds of EMIs across Europe are technically in a position to issue an EMT tomorrow.
An ART requires a separate, freestanding authorisation from the national competent authority, with its own application, its own reserve composition and custody requirements, its own governance and capital standards, and its own prudential scrutiny. The stablecoin authorisation gap reflects the stricter prudential bar applied to ARTs, where reserve composition and significance thresholds raise the entry cost materially.
The honest conclusion is that MiCA has over-engineered ART issuance to the point of practical impossibility. A regime that has produced no authorisations in two years of operation is not a demanding regime; it is a closed one. The commodity-backed and multi-currency tokens the category was designed to capture are simply not being issued in Europe.
This has a knock-on effect on the wider token market. Firms designing a token now face a strong incentive to engineer it into the EMT category or into the residual “other crypto-assets” bucket, regardless of what the product economics would otherwise suggest. Regulatory classification is driving product design rather than following it, which is rarely a sign of a well-calibrated framework.
What to Watch Over the Next Twelve Months
The immediate supervisory priority after 1 July 2026 has been the perimeter: identifying firms still serving EU clients without authorisation and pushing them into orderly wind-down. That work shows up in the growth of the warning list and in withdrawn and lapsed authorisations appearing alongside new entrants.
The next phase will be about substance rather than status, and grey-label structures sit directly in its path. Once every provider either holds a licence or has left, the question becomes whether the licensed entities are genuinely running the businesses conducted in their names. ESMA has already signalled that outsourcing must not turn an authorised entity into a letter-box, and expects real decision-making, local management presence and retained control over risk, technology and security.
Three further developments deserve attention.
Practical Conclusions
For firms that lost the right to operate, three routes remain and each has a real cost. Full authorisation is the durable answer but is slow, expensive and, on the evidence of the last two years, achievable mainly by those who were already regulated. Relocation solves licensing but not market access, and now carries a banking penalty. Grey-label distribution preserves the customer base but leaves the business dependent on somebody else’s licence and somebody else’s continuing good standing.
For those choosing the third route, the discipline is straightforward to state and demanding to maintain. Verify the partner’s authorisation and its precise service scope against the official register rather than a summary, remembering that the register changes weekly. Keep the client contract and the client assets with the licensed entity. Disclose the authorised provider prominently in every market and every language. Characterise the fee as introduction, not participation.
For token issuers, the practical guidance is blunter. If the product can be structured as an EMT and the issuer can access an EMI or credit institution licence, that path is open and functioning. If it can only be an ART, plan on the basis that authorisation is currently theoretical, and treat any timetable that assumes otherwise as unrealistic.
Underlying all of this is a single point that firms new to financial regulation tend to learn expensively. MiCA is assessed on operational reality rather than on documentation, and structures designed around what a counterparty will accept rather than what a supervisor will accept do not survive contact with either. The arrangements that last are the ones where the paperwork describes what is actually happening, and where the entity providing the regulated service is visible on the face of it.
Harju maakond
Kesklinna linnaosa
Tuukri tn-19- tuba 315
Estonia
+372 698 21 75
office@sb-sb.com www.sb-sb.com