Lifestyle

EU MiCA Transitional Period Ends July 1: Grandfathering Differs by Country, a Pending Application Is Not an Extension

The transitional period in Article 143(3) of the EU's MiCA expired on July 1, 2026. Drawing on ESMA's public statement of June 23, 2026, its statement of April 17, 2026, the list of grandfathering periods decided by each Member State and the official question and answer ESMA_QA_2220, this article sets out what ended, why the grandfathering periods differ from one Member State to another, why a pending application is not an extension, and what ESMA said to providers and to clients.

About 14 min read

Original illustration: a line splits the frame; dashed boxes on the left are providers under old national regimes, sealed boxes on the right are authorised ones; the timeline turns solid at the line
Image: Mokaair (© Mokaair)

The transitional period set out in Article 143(3) of the EU's Markets in Crypto-Assets Regulation (MiCA) expired on July 1, 2026. In its statement of April 17, 2026, the European Securities and Markets Authority (ESMA) wrote that the MiCA transitional period would officially expire across the EU on that date, and in its public statement of June 23, 2026 it set out how crypto-asset service providers (CASPs) without an authorisation should wind down in an orderly manner.

This article was checked on September 17, 2026, the day all four ESMA documents were fetched again and read through: the two statements above, ESMA's list of the grandfathering periods decided by each Member State under Article 143, and the official question and answer ESMA_QA_2220. We have tested nothing ourselves and we give no investment or legal advice; every sentence here is limited to what those four documents print, and figures that move, such as how many firms appear on ESMA's register, are left out entirely.

What ended on July 1: the last day of the old regime's grandfathering

The first subparagraph of Article 143(3) provides that crypto-asset service providers that provided their services in accordance with applicable law before December 30, 2024 may continue to do so until July 1, 2026, or until they are granted or refused an authorisation pursuant to Article 63, whichever is sooner. That subparagraph is what is usually called grandfathering: a provider already operating under the old regime could carry on for the time being, without having to stop and wait for a MiCA licence.

The April 17 statement is explicit: the MiCA transitional period will officially expire across the EU on July 1, 2026, and after that date any entity providing crypto-asset services to EU clients without a MiCA licence will be in breach of EU law and must cease offering such services. A footnote adds that this applies irrespective of whether MiCA has been implemented in a Member State or not. Footnote 4 of the same statement points out that two categories of entities were not permitted to provide services even before July 1: first, entities that did not provide crypto-asset services in accordance with applicable national law before December 30, 2024 and therefore could not rely on the transitional regime; and second, entities active in Member States where the transitional period had already ended before July 1, 2026.

Each Member State decided the length for itself

Why do the countries differ? The second subparagraph of Article 143(3) hands the choice to the Member States: they may decide not to apply the transitional regime provided for in the first subparagraph, or to reduce its duration, where they consider that their national regulatory framework applicable before December 30, 2024 is less strict than this Regulation. The third subparagraph requires Member States to notify the Commission and ESMA by June 30, 2024 whether they have exercised that option and how long the transitional regime is. ESMA itself issued a document listing each country's length, and that is the document used here.

Counting row by row through the version of that list obtained on the day of this check (the PDF's internal modification time is May 19, 2026): the Member State column holds 27 rows, and the lengths come in four values, 18 months in 15 countries, 12 months in 5 (Germany, Ireland, Lithuania, Austria and Slovakia), 9 months in Sweden alone, and 6 months in 6 (Latvia, Hungary, the Netherlands, Poland, Slovenia and Finland). Three European Economic Area (EEA) countries are listed in a separate block: Iceland and Liechtenstein at 18 months, Norway at 12 months. The wording of the April 17 statement is "across the EU"; checking these four documents up to September 17, 2026, we saw no statement of an end date for those three countries.

Two things about this list need care. First, it gives months only, with no start date and no expiry date for any country; a date obtained by adding those months to December 30, 2024 is the reader's own arithmetic, not something ESMA prints. Second, the general footnote itself says that some of these periods were communicated to ESMA by national competent authorities and reflect their expectations at the time, and some of them may not have been incorporated into national law yet. Four further countries, Bulgaria, the Czech Republic, Denmark and Italy, each carry a footnote of their own, and what those footnotes state is an application deadline rather than a length of grandfathering.

Checked September 17, 2026; row by row from that day's version of ESMA's Article 143 list (PDF modified May 19, 2026). Months only, no calendar dates; the three EEA countries form a separate block.
Grandfathering periodEU Member StatesEEA countries listed separately
18 months15 countriesIceland, Liechtenstein
12 months5 countriesNorway
9 months1 country (Sweden)None
6 months6 countriesNone

Grandfathering is not protection: no authorisation, no MiCA safeguards

The phrase most easily misread is "application pending". ESMA's official question and answer ESMA_QA_2220 (answer dated July 4, 2024, on the basis of Article 143(3)) asks exactly that: where an entity has applied but has been neither granted nor refused authorisation by the end of the transition period, can it continue providing services? The answer is that where an entity has not been authorised as a CASP by the end of the transition period applicable in the relevant Member State, they must cease providing crypto-asset services until they are granted authorisation as a CASP under MiCA.

The scope of protection needs separating out too. The June 23 statement reminds clients of unauthorised providers that, whether the entity is an EU or a non-EU one, they do not benefit from MiCA safeguards, including protections for client assets; providers established outside the EU also cannot provide MiCA services to EU clients or solicit EU clients, and this applies in a business-to-business context as well, except under the narrow reverse solicitation regime, where services are strictly provided at the client's own exclusive initiative. The April 17 statement goes further into detail: MiCA protections only apply to the specific authorised legal entity in the EU, not to other companies of the same group and not to non-EU entities; a provider may operate under the same brand across multiple companies or countries, so what matters is which entity the contract shows as actually providing the service.

Four-panel diagram: the old regime before December 30, 2024 could continue, each Member State set its own length, July 1, 2026 is the common limit, no authorisation means services must stop
Four-panel diagram: business under the old regime before December 30, 2024 could continue, each Member State set a grandfathering period of 18, 12, 9 or 6 months, July 1, 2026 is the common outer limit, and a provider without an authorisation when the period ends must stop providing services. · Image: Mokaair (© Mokaair)

How ESMA requires unauthorised providers to wind down

The June 23 statement says that while a number of providers will have obtained authorisation by the deadline, other entities, including significant providers currently servicing EU clients under national regimes, may not be authorised by then. The statement lists three things unauthorised providers must do: immediately stop onboarding new EU clients, refrain from opening new client relationships or accounts, and cease marketing activities and solicitation; limit the provision of services to actions necessary to sell or transfer crypto-assets, reallocate assets or close positions, with custody of clients' crypto-assets continuing only for the period strictly necessary to complete an orderly exit; and communicate clearly, promptly and repeatedly with retail and institutional clients about the measures taken to safeguard their assets and the wind-down plans, communications that should include a deadline by which any residual positions would be closed automatically and information about client protection requirements.

The April 17 statement adds what ESMA expects of a wind-down plan: that it enable an orderly exit without causing undue economic harm to clients, including by arranging the offboarding of clients (for example by transferring their crypto-assets to a provider that holds an authorisation, or to a self-hosted wallet); that providers should give existing clients prior notice before implementing the wind-down plan; and that plans should be operational, credible and immediately executable. ESMA also states that by July 1, 2026, when the transitional period ends across the EU, any unauthorised provider must have implemented its wind-down plan.

The other half of the picture is the providers that are authorised: the April 17 statement expects them to actively manage the migration of existing clients ahead of July 1, 2026, and to onboard existing EU clients before the end of the transitional period; what that same statement expects of the national competent authorities is to verify the existence and adequacy of orderly wind-down plans and ensure they are implemented in a timely manner, to take action against the unauthorised provision of crypto-asset services following the end of the transitional period (in cooperation with other competent authorities where appropriate), and to scrutinise client migration strategies. The June 23 statement says wind-down arrangements should be implemented in compliance with all relevant EU or national conduct laws and with anti-money laundering and countering the financing of terrorism (AML/CFT) obligations, including customer due diligence, transaction monitoring and screening against sanctions lists; within the ESMA cooperation framework, national competent authorities may, where necessary, take coordinated action against unauthorised providers after the transitional period.

What users can do: work out which entity you are dealing with

What ESMA says to clients sits in two places: the June 23 statement invites clients using crypto-asset services in the EU to verify on ESMA's register whether their provider is authorised under MiCA, and to act promptly where this is not the case, including by transferring their crypto-assets to a provider that holds an authorisation, where one is identified, or to a self-hosted wallet. The April 17 statement gives three steps: check that the company you are using is listed as authorised in ESMA's Interim MiCA Register, work out who you are dealing with, and act if you need to. ESMA also states that staying with an unauthorised provider may mean less legal protection and a greater risk of losing access to your assets.

Both statements speak of EU clients. Checking these four documents up to September 17, 2026, we saw nothing about non-EU residents, readers in Taiwan for instance, using EU providers, and no provider named. What follows is an example designed by the editors, not something we tested: someone holds an account on a platform registered in an EU Member State and wants to know whether they are about to be cut off. On ESMA's account, the thing to do is to establish which legal entity the contract is with, and then check that entity's status on the register, rather than going by the brand.

Frequently asked questions

Did the EU only begin regulating crypto-assets after July 1, 2026?

No. What Article 143(3) of MiCA granted was a buffer: crypto-asset service providers that provided their services in accordance with applicable law before December 30, 2024 could continue to do so until July 1, 2026, or until they were granted or refused an authorisation pursuant to Article 63, whichever was sooner. July 1 is the common outer limit of that buffer, not the first day the rules took effect.

A provider has filed its application and it is still under review. Can it keep operating?

Under ESMA's official question and answer ESMA_QA_2220, an entity that has not been authorised as a CASP by the end of the transition period applicable in the relevant Member State must cease providing crypto-asset services until it is granted authorisation as a CASP under MiCA. The same answer also says such an entity should apply as early as possible, so that national competent authorities have time to assess the application without disrupting its services.

Is the deadline the same in every Member State?

No. Counting row by row through the version of ESMA's list obtained on the day of this check, the 27 EU Member States have four lengths of grandfathering between them: 18 months, 12 months, 9 months and 6 months, with July 1, 2026 as the common outer limit. Footnote 4 of the April 17 statement also points out that entities active in Member States where the transitional period had already ended before July 1, 2026 were not permitted to provide crypto-asset services even before that date.

How do I check whether a provider holds a MiCA authorisation?

In both statements ESMA leaves this to clients themselves: verify on ESMA's register whether your provider is authorised under MiCA, and the April 17 statement asks readers to check before they invest or transfer funds. Note that what you check is a legal entity, not a brand. MiCA protections only apply to the specific authorised legal entity in the EU, not to other companies of the same group and not to non-EU entities.

When a provider winds down, are clients told first?

That is what ESMA expects. The April 17 statement says providers should give existing clients prior notice before implementing the wind-down plan; the June 23 statement requires clear, prompt and repeated communication with clients, which should include a deadline by which any residual positions would be closed automatically. Providers set that deadline themselves: checking these four documents up to September 17, 2026, we saw no single date set by ESMA.

Do Iceland, Liechtenstein and Norway also end on July 1?

The documents do not say so. ESMA's list places these three European Economic Area countries in a block separate from the 27 EU Member States (Iceland 18 months, Liechtenstein 18 months, Norway 12 months), while the wording of the April 17 statement is "across the EU". Checking these four documents up to September 17, 2026, we saw no statement of when the transitional period ends in those three countries.

Are users in Taiwan affected?

Both ESMA statements speak of EU clients. Checking these four documents up to September 17, 2026, we saw nothing about non-EU residents using EU providers and no provider named, so this article draws no inference. Taiwan's own regime is a separate subject that this article does not go into; the second link at the end of this article is that story.

Latest travel guides

Sources

Lifestyle