blue and yellow star flag

MiCA Regulation Explained: EU Rules for Crypto-Assets and Service Providers

How Europe's single crypto rulebook works in plain language: who needs a licence, what changed once the transition period ended, and where the exemptions are.

The Markets in Crypto-Assets Regulation, usually shortened to MiCA (sometimes MiCAR), is the EU’s crypto law: a single rulebook for crypto companies and the first comprehensive digital-asset regulation to cover an entire economic bloc. It defines which cryptocurrencies and tokens count as crypto-assets, what a company must do before offering them to the public, and which firms need a licence to provide services such as custody, exchange or trading. Because the same text applies in every EU and EEA country, a permit granted in one member state is valid across the bloc.

MiCA at a glance Summary
Full name Markets in Crypto-Assets Regulation, Regulation (EU) 2023/1114; also abbreviated MiCAR
Legal form EU regulation: applies directly in every member state; national law only names the supervisor and sets penalties
Status Fully in force; the transitional period for firms licensed under old national regimes has ended
Who it applies to Companies offering crypto-assets to the EU public, stablecoin issuers, and crypto-asset service providers (CASPs) serving EU clients
What it does not cover Security tokens, deposits and e-money, unique NFTs, central bank digital currencies
Main benefit One licence, the MiCA passport, is valid in every EU and EEA country
Who supervises National financial regulators in each country; ESMA and the European Banking Authority at EU level

What Is the Markets in Crypto-Assets Regulation?

MiCA stands for Markets in Crypto-Assets. It was adopted by the European Parliament and the Council after several years of negotiation, and its goals are consumer and investor protection, market integrity, financial stability and a level playing field that still leaves room for innovation. It is a regulation rather than a directive: the text applies directly and word-for-word in every member state, and national parliaments only fill the gaps it leaves open, such as naming the supervisor and setting penalties.

Before MiCA, crypto regulation in Europe was a patchwork: Germany required a full financial-services licence, while most other member states ran lighter registration regimes for virtual-asset service providers, or VASPs, and a permit in one country meant nothing in the next. The only common layer was anti-money-laundering law, which covered customer checks but said nothing about capital, governance or investor disclosure. The MiCA framework replaced that with one set of rules and one passport.

MiCA Timeline: Is the Regulation Already in Force?

Yes, in full. The stablecoin rules applied first; the CASP licensing regime became effective six months later. Countries could then grant crypto firms already operating under national law a transitional period of up to eighteen months, often called grandfathering, to obtain a MiCA licence or wind down. That window has now closed across the entire EU and implementation is complete: old national registrations were not converted automatically, and serving EU clients without a licence is a breach of EU law.

Check the register before you trust a provider

ESMA maintains a public register of every authorised CASP in the EEA. Regulatory protections apply only to the EU-authorised entity itself, not to affiliates or a non-EU parent.

MiCA Scope: What the Regulation Covers and What It Leaves Out

MiCA regulates crypto-assets, defined in Article 3 as digital representations of value or rights that can be transferred and stored electronically using distributed ledger technology such as a blockchain. That definition drives token classification: it is deliberately wide, but several categories are carved out because they already sit under other EU laws, above all MiFID II for financial instruments, or because they are not tradable assets.

Category Under MiCA? Which rules apply
Payment and utility tokens, including memecoins Yes General offer and white paper rules
Asset-referenced tokens (ART) Yes Stablecoin rules, strictest tier
E-money tokens (EMT) Yes Stablecoin rules, aligned with e-money law
Crypto-asset services Yes CASP licensing and conduct rules
Security tokens and other financial instruments No MiFID II and prospectus rules
Deposits, e-money, insurance and pension products No Banking, e-money and insurance law
Unique, non-fungible NFTs Generally no Case by case; fractionalised or serial NFTs may fall in
Central bank digital currencies No Outside scope
Fully decentralised services with no intermediary No Outside scope, under review

Whether a project is «fully decentralised» is judged on substance, not on its documentation: where a company or foundation retains control over how the service is provided, supervisors are likely to see an intermediary.

Who Needs to Comply with MiCA?

MiCA looks at what a company does for others, not at what it calls itself:

Your activity How MiCA sees you What that means
Selling or listing a token to the EU public Offeror Publish and notify a white paper
Issuing a token pegged to a currency or assets Stablecoin issuer Regulator’s approval before launch
Custody, exchange, trading or advice for clients Crypto-asset service provider MiCA licence (CASP authorisation)
Bank or investment firm adding crypto services Already regulated entity Notification, no new licence
Software, mining, running nodes, no intermediary role Outside MiCA No obligation
Holding crypto with the company’s own money Investor, not a provider No obligation; see holding crypto through a company
Non-EU firm marketing to EU residents In scope Needs an EU-authorised entity

Third-country firms and reverse solicitation

A third-country firm, meaning any company established outside the EU, may not provide crypto-asset services to EU clients or solicit them, even business-to-business. The only exception, set out in Article 61, is reverse solicitation: a client approaching the firm entirely on their own initiative. Supervisors read that exception narrowly. EU-targeted advertising, influencer campaigns, EU-language or geo-targeted web content and apps in EU stores all count as solicitation, so serving the European market in practice means licensing an EU entity.

MiCA Rules for Crypto-Asset Service Providers

A crypto-asset service provider, or CASP, is a legal person providing one or more of the ten services listed in the regulation to clients on a professional basis. In practice that means crypto exchanges, custodial wallet providers, brokers and crypto advisers. The services fall into four groups: holding client assets (custody), running markets (trading platforms, exchange for cash or other crypto), handling orders (execution, transmission, placing tokens for an offeror) and serving clients directly (advice, portfolio management, transfers).

CASP authorisation and the MiCA passport

A CASP is licensed by the financial regulator of the country where it is established. Once granted, the permit extends to every other EU and EEA country through the MiCA passport: the firm notifies its home regulator of the countries it wants to serve and may start there after a short waiting period, without a second application. Application files, national fees and processing times vary by country; the practical steps for obtaining a CASP authorisation are covered on our MiCA licensing page.

MiCA requirements for ongoing compliance

Authorisation is only the entry ticket. Once licensed, a crypto firm must keep meeting a standing set of MiCA requirements on organisation and conduct. The table is a short compliance checklist:

Requirement What MiCA expects
Capital requirements Own funds of €50,000, €125,000 or €150,000 depending on the services offered, or a quarter of the previous year’s fixed overheads if higher; insurance can cover part of the amount
Management and owners Directors and major shareholders must be of good repute and suitably qualified; the firm must be managed from the EU
Client assets Client crypto and money are held separately from the firm’s own assets; client cash must sit with a bank or similar institution
Governance and resilience Internal controls, business-continuity plans and IT security, with the EU’s digital-resilience rules (DORA) on top
Client information Clear, fair and non-misleading disclosure of risks, pricing and conflicts of interest, plus a public complaints procedure
Market abuse Insider dealing and manipulation rules apply to crypto-assets admitted to trading; platforms must monitor for abuse and may not list privacy coins with built-in anonymisation

MiCA and anti-money-laundering rules

MiCA does not contain the anti-money-laundering rules themselves. Customer checks and reporting come from separate EU legislation, and the Travel Rule regulation adopted alongside MiCA requires identifying information to accompany every crypto transfer. A European CASP therefore answers to two bodies of law, often to two different authorities, and MiCA compliance never replaces an anti-money-laundering programme.

MiCA Rules for Token Issuers

Issuers face a lighter regime than service providers unless the token is a stablecoin; obligations scale with the risk to buyers and the payment system.

MiCA white paper requirements

MiCA replaced the unregulated ICO era with a disclosure regime. Before a public offer, the offeror must be a legal person, draft a crypto-asset white paper covering the project, the rights attached to the token, the technology, the risks and the environmental impact of the consensus mechanism, and notify it to the national supervisor at least twenty working days before publication. The supervisor does not pre-approve the white paper but can halt the offer. Marketing communications must match the document, retail buyers get a fourteen-day right to withdraw, and the offeror is liable for misleading information.

Several offers are exempt: tokens distributed for free, such as airdrops, offers to fewer than 150 persons per country, offers below €1 million over twelve months, and offers aimed only at qualified investors. Tokens with no identifiable issuer, such as Bitcoin, need no white paper at all, although services built around them remain regulated.

Stablecoin rules for ART and EMT issuers

An ART issuer needs a licence from its national regulator and an approved white paper. It must hold a segregated reserve that fully backs the tokens, give holders a permanent right of redemption, and keep own funds of at least €350,000, two per cent of the average reserve or a quarter of fixed overheads, whichever is highest. EMT issuers follow the electronic money rules, must redeem at par at any time and may not pay interest on holdings. Tokens large enough to be classed as significant come under direct supervision by the European Banking Authority. The practical consequence is visible on every EU crypto exchange: stablecoins whose issuers did not obtain EMT status have been delisted for European users.

Who Supervises MiCA and What Happens If You Ignore It

Day-to-day supervision sits with national competent authorities: the regulator of the country where a firm is established grants, refuses and withdraws CASP licences. The European Securities and Markets Authority (ESMA) coordinates national regulators, issues technical standards and runs the EU-wide register of authorised providers; the European Banking Authority does the same for ART and EMT issuers and directly supervises significant stablecoins.

MiCA penalties and fines

The regulation sets minimum penalties every country must be able to impose: fines in the millions of euros or a share of annual turnover, public statements naming the offender, orders to stop, and withdrawal of the licence. Operating without a licence is itself an infringement, and ESMA publishes a list of non-compliant entities alongside the register of authorised ones.

Supervision may move to ESMA

The European Commission has proposed transferring the licensing and supervision of all CASPs from national regulators to ESMA as part of a wider capital-markets package. Until the proposal is adopted and phased in, applications continue to go to national authorities.

What the EU Crypto Regulation Means for a Startup

For a company with a real product, MiCA is mostly good news. On the plus side:

  • One licence opens the whole EEA digital-asset market, and clients can verify it in the ESMA register instead of trusting marketing claims.
  • Banks and payment providers are far more willing to work with a MiCA-compliant firm than with an unregulated one.

On the cost side:

  • Minimum capital, a compliance function, audited accounts and documented IT controls are fixed costs from day one.
  • The management team must pass a fit-and-proper assessment, and the firm must be run from inside the EU.

The framework is still evolving: the Commission is reviewing decentralised finance (DeFi), staking, lending and NFTs, so expect further obligations.

Frequently Asked Questions

This guide was prepared by the Eesti Firma team, including Co-founder and Chief Legal Officer Ilja Nikiforov, and is intended solely for informational purposes. None of the provided content constitutes legal, tax, or investment advice. While every effort has been made to ensure accuracy at the time of publication, laws and regulations may change. For personalized legal assistance, please contact Eesti Firma directly.