On 23 June 2026, the European Securities and Markets Authority (ESMA) published a public statement (ESMA75-113276571-1710) clarifying its expectations of crypto-asset service providers (CASPs) following the end of the transitional period under the Markets in Crypto-Assets Regulation (MiCAR) on 1 July 2026. The statement builds on ESMA’s earlier statement of 17 April 2026 and is addressed, in particular, to entities that will not hold MiCAR authorization by the deadline but continue to service EU clients under national regimes.
Table of Contents
Background
Under the MiCAR transitional regime, Member States were permitted to allow crypto-asset service providers that were already lawfully providing services under national law to continue operating for a limited period after MiCAR’s application date, pending the grant (or refusal) of MiCAR authorization. This period ends across the Union on 1 July 2026[1] at the latest, irrespective of whether the relevant Member State has already aligned its national law with MiCAR. ESMA notes that, while a number of providers have obtained MiCAR authorization by this date, other entities, including significant providers currently servicing EU clients, have not.
Wind-down obligations of unauthorised CASPs
ESMA expects unauthorised CASPs to wind down their EU activities in an orderly manner while safeguarding client interests and limiting risks to market integrity. In particular, the statement sets out three categories of obligation:
- No further client acquisition. This means that unauthorized CASPs must immediately stop onboarding new EU clients, must refrain from opening new client relationships or accounts, and must cease all marketing activity and client solicitation directed at the EU market.
- Services are restricted to wind-down activities. This means that unauthorized CASPs must limit any activities to actions necessary to sell or transfer crypto-assets, reallocate client assets, or close open positions. Custody of client crypto-assets may only continue for the period strictly necessary to complete an orderly exit. It does not provide a basis for continued operation of the business.
- Client communication. This means unauthorized CASPs must communicate clearly, promptly and repeatedly to both retail and institutional clients the measures they take to safeguard client assets and the wind-down timeline. Communications must set out a deadline by which any residual client positions will be closed automatically, together with information on the client protections that apply (or, by implication, no longer apply) during the wind-down.
AML/CFT obligations during wind-down
ESMA emphasizes that wind-down arrangements must be implemented in compliance with all relevant EU and national conduct laws, in particular AML/CFT obligations. Unauthorized CASPs are expected to maintain effective AML/CFT controls throughout the wind-down process, including:
- customer due diligence measures;
- transaction monitoring;
- screening against restrictive measures and sanctions lists;
- suspicious transaction and activity reporting;
- record-keeping requirements; and
- compliance with applicable transfer-of-funds and crypto-asset transfer traceability obligations (the “Travel Rule”).
Challenges when transferring clients to authorized CASPs
One solution that unauthorized CASPs may seek to wind-down their unauthorize business or to set it up in a compliant way in partnership with an authorized CASP, is the transfer of clients to the authorized CASP. For these cases, ESMA clarifies that the receiving CASP must carry out all necessary onboarding procedures in the ordinary course, including customer due diligence and any other AML/CFT checks required under the applicable legal framework. A transfer from an unauthorized entity does not, therefore, substitute for standard onboarding by the authorized recipient. Identifying a bulk of clients when transferring, is a major task that in practice may be the proverbial nail in the cofffin for such projects, especially if the clients have not previously been properly identified in accordance with AML legislation. Unfortunately, current practice shows that clients rarely cooperate during the identification process required under AML. It is also apparent that European regulators do not take a very consistent approach to the transfer of clients.It remains to be seen whether the ESMA statement will bring more harmonization in practice.
The end of reverse solicitation (and now really)
ESMA reiterates that CASPs established outside the EU may not provide MiCAR services to EU clients, or solicit EU clients, including in a business-to-business context, except where services are provided strictly at the client’s own exclusive initiative under the narrow reverse solicitation regime (as further specified in ESMA’s Guidelines on reverse solicitation under MiCA). ESMA also reminds market participants that MiCAR prohibits CASPs from outsourcing or delegating certain services, in particular custody, to entities that are not authorised as CASPs. Structuring arrangements around unauthorized third parties or affiliates does not, therefore, provide a route to continued EU market access. ESMA will work closely with national regulators to ensure enforcement of this rule.
ESMA’s statement confirms that the end of the MiCAR transitional period on 1 July 2026 is being treated as a firm deadline, with ESMA and national regulators already engaged with affected entities and coordinated supervisory action available under the ESMA cooperation framework. Market participants, irrespective of their status of being not yet authorized or just not authorized, should take this seriously and work against a checklist to comply. In particular, it is advisable to involve the relevant regulators at an early stage.
———————————–
[1] Many countries made use of the option to shorten the deadline. In Germany, the deadline ended on 31 December 2025.
