The Markets in Crypto-Assets Regulation is often described as the European Union’s comprehensive crypto law. That description is useful, but incomplete.
MiCA creates a harmonised market framework for cryptoasset issuers and service providers. It regulates authorisation, governance, prudential safeguards, customer protection, custody, disclosures and market abuse. It does not, by itself, form the EU’s entire response to crypto-related financial crime.
Traceability of cryptoasset transfers is addressed through the recast Transfer of Funds Regulation. Customer due diligence and suspicious activity obligations sit within the anti-money laundering framework. Operational resilience is reinforced through DORA, while DAC8 introduces expanded tax-transparency requirements.
Together, these measures create a connected regulatory architecture governing who may provide crypto services, how customer assets must be protected, what information must accompany transfers and how firms should identify, manage and report financial-crime risk.
For FinCrime teams, the strategic issue is therefore broader than MiCA compliance. It is whether the institution can connect regulatory authorisation, customer identity, wallet ownership, transaction behaviour, sanctions exposure and on-chain activity within one defensible control environment.
Key Takeaways
- MiCA Creates a Harmonised EU Crypto Regulatory Framework
- Crypto Regulation Extends Beyond MiCA Alone
- CASP Authorisation Is Now Central to EU Market Access
- Stablecoins Face Enhanced Regulatory Scrutiny
- MiCA Strengthens Customer Asset Protection and Governance
- Crypto Market Abuse Is Now Subject to Dedicated Controls
- The Travel Rule Expands Crypto Transaction Traceability
- Self-Hosted Wallets Remain a Significant Risk Consideration
- AML Obligations Require Connecting Identity With On-Chain Activity
- Blockchain Analytics Is Becoming Essential to Crypto Compliance
- DORA Connects Operational Resilience With Financial Crime Risk
- DAC8 Expands Crypto Tax Transparency
- Authorisation Does Not Eliminate Counterparty Risk
- DeFi and Emerging Crypto Models Continue to Challenge Regulatory Perimeters
- EU Crypto Regulation Is Moving From Implementation to Active Supervision
Listen the podcast
Watch the video
Why EU crypto regulation matters now
The original MiCA legislation was adopted in 2023 following several years of rapid cryptoasset growth, market failures and regulatory fragmentation. Before the regulation, firms could face materially different registration, consumer-protection and supervisory requirements across EU member states.
The stablecoin provisions applying to asset-referenced tokens and e-money tokens became operational on 30 June 2024. Most of the remaining MiCA regime, including the authorisation requirements for cryptoasset service providers, applied from 30 December 2024.
Existing providers in some member states were permitted to continue temporarily under national transitional arrangements. That final transition ended across the European Union on 1 July 2026.
After that date, a business providing regulated cryptoasset services to EU clients must generally be authorised under MiCA or be an eligible financial institution operating through the relevant notification procedure. An unauthorised provider cannot continue ordinary EU-facing activity merely because it was previously registered under a national regime.
This marks an important transition from legislative design to supervisory enforcement. The key questions are no longer whether MiCA will apply or when firms should begin preparing. They concern the quality of authorisation decisions, consistency between national supervisors and the ability of firms to demonstrate that their operational controls work in practice.
What MiCA actually regulates
MiCA applies to the issuance, public offering and admission to trading of cryptoassets that are not already governed by other EU financial-services legislation. It also regulates a defined range of cryptoasset services.
These services include custody and administration, operating a trading platform, exchanging cryptoassets for funds or other cryptoassets, executing and transmitting orders, placing cryptoassets, providing advice, managing portfolios and transferring cryptoassets on behalf of clients.
Bitcoin is not excluded from the framework in the manner sometimes suggested. There is no central Bitcoin issuer to which issuer-specific obligations can be applied. However, exchanges, custodians, trading platforms and other businesses providing regulated services involving Bitcoin can fall directly within the CASP regime.
Cryptoassets that qualify as financial instruments remain subject to securities legislation rather than MiCA. Genuinely unique and non-fungible assets may also fall outside the regulation, although substance takes priority over labels. Large collections or fractionalised structures may not be treated as genuinely unique simply because they are marketed as NFTs.
MiCA should therefore be understood as a perimeter framework. Firms must first determine what the token represents and which legal regime applies before deciding which disclosure, licensing and conduct obligations are relevant.
Authorisation and the EU passport
A core feature of MiCA is the cryptoasset service provider authorisation.
Applicants must provide information on ownership, governance, management suitability, internal controls, prudential safeguards, business continuity, technology, complaints handling and the services they intend to offer. Firms holding client cryptoassets or funds face additional safeguarding and record-keeping obligations.
Once authorised, a CASP may provide approved services across the European Union through the freedom to provide services or through branches. It is not generally required to establish a separate physical presence in every host member state.
This passport creates significant commercial value. It also increases the importance of supervisory consistency. Weak authorisation standards in one jurisdiction could expose customers and markets throughout the Union.
MiCA authorisation should not be treated as a quality guarantee or a substitute for due diligence. It confirms that a specific legal entity has been authorised to provide specified services. It does not automatically cover every company operating under the same brand, including non-EU affiliates.
Banks, counterparties and customers therefore need to identify the legal entity actually providing the service and confirm its status through the EU register.
Third-country firms face a particularly narrow route into the market. A non-EU provider may serve a client who initiates the relationship entirely on their own exclusive initiative, but the reverse-solicitation exemption cannot be manufactured through advertising, affiliates, influencers or other forms of EU-directed promotion.
Stablecoins receive enhanced scrutiny
MiCA distinguishes between two principal types of regulated stablecoin.
An e-money token seeks to maintain a stable value by referencing one official currency. An asset-referenced token refers to another value, right or combination of assets, which may include several currencies, commodities or other cryptoassets.
The regulatory treatment reflects the potential for stablecoins to operate as payment and settlement instruments. Issuers face authorisation, governance, disclosure, reserve-management and redemption requirements. Reserve assets must be managed and safeguarded under defined standards, with liquidity capable of supporting redemption.
Issuers and service providers are also prohibited from granting interest or equivalent remuneration linked to the length of time a holder retains an asset-referenced or e-money token. This is intended to limit the development of stablecoins as deposit-like products outside the conventional banking framework.
Tokens classified as significant receive heightened oversight. The European Banking Authority directly supervises issuers of significant asset-referenced tokens and shares defined supervisory responsibilities for significant e-money tokens.
This does not eliminate stablecoin risk. Reserve quality, concentration, redemption pressure, operational dependency and exposure to non-EU issuers remain material. MiCA provides a control framework, but firms must still assess the particular token, issuer, reserve structure and transaction purpose.
Customer assets, governance and operational resilience
The failures of several global crypto businesses demonstrated that customers may not understand whether their assets are segregated, lent, pledged or exposed to the insolvency of the provider.
MiCA requires CASPs holding client cryptoassets or access credentials to protect customers’ ownership rights and prevent the assets from being used for the provider’s own account. Custodians need procedures for recording positions and returning assets or access mechanisms to clients.
Providers are also subject to prudential safeguards. Depending on the services offered, permanent minimum capital requirements range from €50,000 to €150,000. Firms must maintain safeguards equal to at least the higher of the relevant minimum requirement or one quarter of the previous year’s fixed overheads.
These requirements are important but should not be mistaken for deposit insurance. Cryptoassets remain exposed to price volatility, technology failures and risks that may not be recoverable through a compensation scheme.
DORA adds a separate layer of operational-resilience requirements. Since January 2025, in-scope financial entities, including authorised CASPs, have been required to manage ICT risk, report major incidents, test resilience and oversee critical technology suppliers.
For FinCrime teams, operational resilience and financial crime are closely connected. An outage, private-key compromise, cyberattack or third-party failure can create conditions for theft, sanctions evasion and concealment of unauthorised transfers.
White papers and market integrity
MiCA requires issuers or offerors of many cryptoassets to prepare a white paper explaining the project, rights attached to the token, technology, risks and environmental information.
The white paper is a regulatory disclosure, not an endorsement by a competent authority. The offeror or issuer remains responsible for its content, and publication in the ESMA register does not mean that the asset has been approved as safe or suitable.
From December 2025, standardised machine-readable formatting requirements strengthened the ability of authorities and market participants to compare disclosures. This can support supervision and automated analysis, but it does not ensure that the underlying business model is legitimate.
MiCA also introduces a market-abuse regime covering insider dealing, unlawful disclosure of inside information and market manipulation involving cryptoassets admitted to trading or for which admission has been requested.
Trading platforms and professionally arranging or executing transactions require systems capable of detecting and reporting suspicious orders and activity. These controls must reflect the distinctive characteristics of crypto markets, including continuous trading, cross-platform liquidity and interaction between on-chain and off-chain venues.
A manipulation scheme may involve coordinated wallets, social-media promotion, thin liquidity, related accounts and rapid movement across exchanges. Traditional securities-surveillance rules cannot simply be transferred without adaptation.
The Travel Rule and transaction traceability
MiCA establishes who may provide crypto services. The Transfer of Funds Regulation determines what information must accompany regulated cryptoasset transfers.
CASPs must collect and transmit information concerning the originator and beneficiary. Relevant data can include names, account identifiers and distributed-ledger addresses. Receiving providers must detect missing or incomplete information and decide whether to execute, reject, return or suspend the transfer based on the circumstances and associated risk.
The requirement applies without the minimum transaction threshold historically associated with some wire-transfer controls. This reflects the ease with which cryptoassets can be divided into smaller amounts and moved rapidly across several addresses.
Self-hosted wallets are not prohibited. Where a CASP is involved, however, transfers to or from self-hosted addresses remain within the risk framework. For transfers exceeding €1,000, the provider must take appropriate measures to assess whether the address is owned or controlled by its customer.
Ownership verification should not be treated as the complete risk decision. A customer may control an address that interacts with mixers, scam infrastructure, sanctioned actors or high-risk services. Firms still need transaction monitoring, blockchain analysis and an understanding of the customer’s economic purpose.
The Travel Rule creates a significant implementation challenge because blockchain settlement and identity-data transmission are technically separate processes. Firms need interoperable messaging arrangements, reliable counterparty identification, privacy safeguards and procedures for transfers involving providers in jurisdictions with different requirements.
AML obligations extend beyond transaction messaging
Cryptoasset service providers are financial-sector obliged entities under the EU AML framework. They must apply customer due diligence, identify beneficial owners, understand the purpose of relationships, monitor transactions and report suspicious activity.
The EBA’s crypto-specific risk-factor guidance requires firms to consider matters such as product anonymity, self-hosted wallets, geographic exposure, transaction patterns, use of privacy-enhancing technologies and connections with higher-risk providers.
The new EU AML package will further harmonise these expectations. It brings the wider crypto sector within the single AML rulebook and allows the Anti-Money Laundering Authority to participate in the supervision of the highest-risk cross-border financial entities, including relevant CASPs.
The principal challenge is connecting identity with on-chain behaviour. A customer may pass onboarding checks while controlling several wallets, transacting through decentralised services or acting on behalf of another person.
Financial institutions therefore need more than sanctions screening against isolated addresses. They require entity resolution, exposure analysis, behavioural monitoring and procedures for investigating indirect relationships without treating every connection as equivalent.
DAC8 and tax transparency
Crypto regulation is also expanding into taxation.
DAC8 entered into application on 1 January 2026, extending administrative-cooperation and automatic-information-exchange requirements to cryptoasset transactions. Reporting providers must identify relevant users and collect information concerning reportable transactions for transmission through national tax authorities.
The framework is intended to reduce the opacity created when individuals hold or transfer cryptoassets through providers outside the conventional banking-reporting environment.
MiCA authorisation and DAC8 reporting serve different purposes. A provider can be properly authorised while still having customers who misuse cryptoassets to conceal income, gains or offshore holdings. Tax transparency therefore forms another layer of the broader control environment.
Where the framework remains incomplete
MiCA is comprehensive within its defined perimeter, but the crypto market continues to evolve beyond the categories anticipated during its design.
Fully decentralised services without an identifiable intermediary can present difficult questions about responsibility and enforcement. NFTs may resemble investment or fractionalised products despite being labelled unique. Lending, staking and decentralised-finance models can combine activities covered by several legal regimes or remain partly outside MiCA.
Non-EU platforms can continue attempting to reach European customers through websites, applications, affiliates and common branding. Enforcement depends on identifying where promotion ends and genuine client initiative begins.
The European Commission began reviewing MiCA’s operation in 2026, reflecting developments in stablecoins, tokenisation, decentralised finance and the international regulatory environment. This does not mean that the existing framework has failed. It demonstrates that crypto regulation cannot remain static while products and distribution models continue to change.
What a resilient control stack looks like
The first layer is regulatory-perimeter analysis. Institutions should determine what each token and service represents rather than relying on marketing terminology.
The second layer is counterparty verification. Firms should confirm the specific legal entity, authorisation status, approved services and jurisdiction involved in each relationship.
The third layer is integrated customer and wallet intelligence. KYC information should be connected with wallet ownership, blockchain exposure, device activity, source of funds and transaction purpose.
The fourth layer is Travel Rule governance. Firms need reliable identity-data transmission, counterparty due diligence and procedures for incomplete or inconsistent information.
The fifth layer is market and transaction surveillance. Controls should identify coordinated wallets, circular trading, layering, rapid chain-hopping and relationships with scams, sanctions targets and laundering services.
The sixth layer is operational resilience. Private-key security, incident response, outsourcing and recovery arrangements should be connected to fraud, AML and sanctions escalation.
Finally, institutions need continuous regulatory intelligence. MiCA authorisation is a starting point, not the conclusion of the EU’s digital-asset regulatory development.

What this means for financial crime leaders
The European Union has moved further than many jurisdictions in building an integrated framework for cryptoasset markets. The achievement lies not in MiCA alone, but in the interaction between authorisation, consumer protection, market surveillance, transfer traceability, AML controls, operational resilience and tax reporting.
Financial crime leaders should avoid treating these obligations as separate compliance projects. The same transfer may engage MiCA custody rules, Travel Rule data requirements, AML monitoring, sanctions controls and DAC8 reporting.
The strongest programmes will connect legal-entity authorisation with the actual customer, wallet and transaction. They will understand where cryptoassets came from, who controls the destination and whether the stated economic purpose is consistent with both on-chain and off-chain evidence.
EU regulation does not make cryptoassets risk-free, nor does it remove the distinctive challenges created by self-hosted wallets, decentralised services and cross-border providers. It creates a clearer accountability structure for the institutions that issue, trade, safeguard and transfer them.
The next phase is therefore about effectiveness. Regulators and institutions must demonstrate that formal authorisation produces better governance, stronger protection of customer assets and earlier detection of illicit finance.
Europe has established the regulatory architecture. Its long-term credibility will depend on whether that architecture can adapt as quickly as the market and the criminal networks seeking to exploit it.
What Financial Institutions Should Consider
- Confirm the Regulatory Status of Crypto Counterparties
- Identify the Specific Legal Entity Providing Crypto Services
- Strengthen Crypto Customer and Beneficial Ownership Due Diligence
- Integrate KYC With Wallet and Blockchain Intelligence
- Implement Robust Travel Rule Governance
- Strengthen Self-Hosted Wallet Risk Assessments
- Monitor Direct and Indirect Blockchain Exposure
- Apply Risk-Based Crypto Transaction Monitoring
- Strengthen Crypto Sanctions Screening
- Detect Chain-Hopping and Layering Activity
- Monitor Mixers and Privacy-Enhancing Technologies
- Identify Coordinated Wallet and Market Manipulation Activity
- Strengthen Stablecoin Issuer and Reserve Risk Assessment
- Connect Cybersecurity Incidents With FinCrime Monitoring
- Strengthen Crypto Counterparty Due Diligence
- Prepare for Continued EU Regulatory Evolution
- Maintain Continuous Crypto Regulatory Intelligence
- Build an Integrated Digital-Asset Control Framework
Download the briefing
Europe’s Crypto Rulebook: A Briefing on the EU’s Digital-Asset Regulatory Architecture




The European Union’s crypto regulatory framework marks a significant shift from fragmented national oversight towards a more integrated system of authorisation, market conduct, transfer traceability, operational resilience and financial-crime accountability.
MiCA is central to that architecture, but it is not the complete framework. Effective oversight also depends on the crypto Travel Rule, AML obligations, DORA, DAC8 and the developing role of AMLA. Together, these measures seek to connect the legal status of the service provider with the identity of the customer, the ownership of the wallet, the economic purpose of the transaction and the risks visible on-chain.
The real test will now be implementation. Formal authorisation alone will not prevent fraud, sanctions evasion, market manipulation or money laundering. Supervisors and institutions must demonstrate that governance, customer-asset protection, transaction monitoring and cross-border cooperation produce measurable improvements in detection and disruption.
Financial-crime teams should therefore avoid treating MiCA compliance as a standalone licensing exercise. The strongest programmes will integrate regulatory-perimeter analysis, customer due diligence, wallet intelligence, Travel Rule controls, blockchain analytics and operational-resilience planning within one connected control environment.
Ultimately, Europe has established one of the world’s most comprehensive crypto regulatory architectures. Its long-term credibility will depend on whether it remains proportionate, internationally interoperable and capable of adapting as quickly as digital-asset markets and the criminal networks seeking to exploit them.