MiCA Compliance: What EU Crypto Regulation Actually Requires
MiCA — the Markets in Crypto-Assets Regulation, formally Regulation (EU) 2023/1114 — is the European Union's single rulebook for crypto-assets that fall outside existing financial services law. Before it, a firm offering an on-ramp in Germany faced a different regime than the same firm in Ireland. MiCA replaces that patchwork with one authorization that works across the bloc, and one set of obligations attached to it.
Scope of this page: this is an educational explainer about the MiCA framework itself. It does not assert the licensing or authorization status of any particular provider, including this site. Whether a given service is MiCA-authorized is a question of fact — check the public register maintained by ESMA and the relevant national regulator before relying on any provider's claim.
Timeline
MiCA entered into force in June 2023 and applied in two stages. The stablecoin provisions — covering asset-referenced tokens and e-money tokens — became applicable on 30 June 2024. The rules for crypto-asset service providers followed on 30 December 2024. Member states were permitted to run a transitional "grandfathering" window for firms already operating under national regimes, with an outer limit of 1 July 2026; the length varies by country, so a provider legal in one member state may still be mid-transition in another.
Who Needs Authorization
MiCA regulates the intermediary, not the token. A firm becomes a crypto-asset service provider (CASP) when it does any of the following for third parties on a professional basis:
- Operating a trading platform for crypto-assets
- Exchanging crypto-assets for funds or for other crypto-assets — the legal description of a fiat on-ramp and an off-ramp
- Custody and administration of crypto-assets on behalf of clients
- Execution, reception and transmission of orders, and placing of crypto-assets
- Advice, portfolio management, and transfer services
Authorization comes from a national competent authority — BaFin, the AMF, the Central Bank of Ireland, and their counterparts — and then passports across the EU and EEA. That passport is the commercial point of MiCA: one licence, thirty markets.
What Authorization Obliges
| Obligation | What It Means In Practice |
|---|---|
| Client asset segregation | Your crypto is held apart from the firm's own balance sheet |
| Prudential capital | Minimum own funds scaled to the services offered |
| Governance and fit-and-proper | Named, vetted management with defined responsibility |
| Disclosure | Clear pricing, execution policy, and risk warnings |
| Complaints and conflicts | A formal complaints procedure and conflict-of-interest policy |
| Market abuse rules | Insider dealing and manipulation prohibited, as in securities markets |
The Stablecoin Rules
MiCA treats stablecoins as its own category and splits them in two. E-money tokens reference a single official currency; asset-referenced tokens reference a basket, another asset, or a combination. Both require an authorized issuer, a published white paper, and reserves that are segregated, custodied, and redeemable at par on demand. Tokens that reach "significant" scale come under direct European Banking Authority supervision rather than national supervision alone.
This is the provision with the most visible market effect: exchanges serving EU users have delisted or restricted stablecoins whose issuers did not meet the requirements, which is why the EU stablecoin landscape looks different from the global one.
What MiCA Does Not Cover
- Financial instruments. If a token is a transferable security, MiFID II applies instead.
- Genuinely unique NFTs sit outside scope — but a large fungible series marketed as an investment can be pulled back in, and substance beats labelling.
- Central bank digital currencies and central bank activity.
- Fully decentralized services provided without any intermediary. In practice most "DeFi" front ends have an identifiable operator, and the boundary here is still being tested.
What It Means If You Are the Customer
A MiCA-authorized provider is not a guarantee that you will make money or that the provider cannot fail. What it changes is the floor: your assets should be segregated, the pricing should be disclosed, there is a named regulator to complain to, and someone has been assessed as fit to run the firm. Expect more identity verification and source-of-funds questions, not less — that is the same rulebook working.
Verify, do not trust the badge. "MiCA compliant" printed on a website is marketing until you can match the legal entity to an entry in a national regulator's public register. Check the entity name — not the brand — and confirm which services the authorization actually covers.
Regulatory detail moves, and national implementation differs across member states. Treat this page as an orientation to the framework rather than legal advice, and confirm current requirements with the relevant competent authority or a qualified adviser. For the practical side of moving money, see the on-ramp and off-ramp guides, or compare platform models in exchange solutions.