Build1 publisher2 min readPublished
MiCA's transitional window shut with roughly 17% of Europe's crypto firms authorised
Article 143(3) ran out on 1 July 2026, so from that date Article 59 applies to EU client business without exception, and the register that decides who sits inside the perimeter is still being revised week by week.
The Engineer · Build desk

What happened
- MiCA's Article 143(3) transitional window, up to 18 months of trading under national law while an application ran, expired EU-wide on 1 July 2026, and Article 59 has applied without exception since.
- Of more than 1,200 entities holding national VASP registrations across the EU and EEA before MiCA, about 210 held full CASP authorisation at the cutoff, a conversion rate of roughly 17%.
- ESMA's 31 July register update, the fourth revision since the deadline, listed 321 authorised CASPs, 41 e-money token issuers and 167 entities on the non-compliant register.
- Latvia, Hungary, the Netherlands, Poland and Slovenia ran six-month national transitional periods that closed in mid-2025, ahead of the EU-wide backstop date.
- ESMA published a statement on 23 June 2026 calling on unauthorised crypto-asset service providers to wind down in an orderly manner while safeguarding client interests.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- constraint A firm mid-application has to stop onboarding, marketing and trading with EU clients until a grant lands, and a hearing already booked with the regulator changes none of that.
- exposure An exchange that planned to the 1 July headline date but trades in Poland or the Netherlands has been outside its perimeter since mid-2025, because the earliest national deadline is the one that governs it.
- precedent The non-compliant register has named about a fifth of the firms missing from the authorised list, so more notification cycles like CONSOB's three are the likely next move by national authorities.
Two authorisation counts a month apart appear in the same guide, and the gap between them is 111 [1]. E-money token issuers are listed separately, at 41, so they do not account for it [5]. Either national competent authorities granted that many in four weeks, or the earlier figure counted something narrower than the register does. ESMA revises the register weekly [16]. Any number pulled from it needs the date it was pulled.
An earlier snapshot in the same guide, attributed to Elliptic, put the register at 213 authorised CASPs across 23 jurisdictions: Germany 55, the Netherlands 26, France 19, Malta 15, Ireland and Cyprus 12 each [6]. Those five sum to 127. That is 59.6% of 213, and it matches the roughly 60% top-five concentration reported next to it [4]. The snapshot is internally consistent, and it was taken before the total passed 320, so it describes which regulators cleared applications first [7].
The Yahoo Finance analysis quoted in the guide said "the other 83% either missed the window, are mid-process with no legal standing to continue operating, or have quietly exited" [8]. Those three groups need different work. One has to finish an application, one has to stop serving EU clients while it waits, and one has already stopped.
The guide also gives ESMA's position as reported by Yahoo Finance: "There is no intermediate status after July 1. A firm is either authorized under MiCA or it is in breach of EU law." [9] For an unauthorised firm the exposure runs on two fronts at once, to enforcement action by its national competent authority and to counterparties and clients reading it as operating outside its regulatory perimeter, and neither front clears until authorisation is granted or the firm winds down [15].
The guide's other claim is that the AML and travel-rule systems firms are racing to build now get rebuilt the moment inter-CASP data exchange starts, unless they are built on reusable credentials from the start [14]. The material behind that claim does not include a schema, an interface or a date. Two things would have to hold for the rebuild to bite. The wire format has to be set by someone other than you, so your internal representation is not the one that ships. And your onboarding evidence has to be re-presentable to a counterparty CASP, not merely filed as a local record that a check was run. If a KYC store already keeps issuer, subject and validity as separate fields, building for reuse costs little now and a great deal once a counterparty format is fixed.
What to watch
- Whether ESMA's next register revisions keep adding authorisations at July's pace or the total flattens near 321.
- Whether the non-compliant register grows toward the roughly 880 pre-MiCA registrants absent from the authorised list, and which national authorities file those notifications.
- Publication of an inter-CASP data exchange format or schema; until one exists the reusable-credentials claim cannot be tested.