
REDPRESSWIRE – Europe had more than three thousand registered crypto firms before MiCA. Three weeks after the transitional period closed, the EU register showed 294 authorised providers. Most of the attrition happened at the licensing gate, before any supervisor brought a single enforcement case.
Since 1 July 2026, a crypto-asset service may be supplied to clients in the European Union only by a firm holding a CASP authorisation, by a regulated financial institution that has notified its intention to provide such services, or by a firm passporting an authorisation obtained elsewhere in the Union. The transitional window under Article 143(3) of MiCA closed on that date and could not be extended by national law.
As at 21 July 2026, the ESMA register listed 294 authorised providers across 26 home states. Germany accounted for 59, France for 31, the Netherlands for 28, Malta for 22, and Cyprus for 21. Czechia had eleven and Slovakia six. Poland had none. Set against a pre-MiCA population estimated at more than three thousand registered virtual asset service providers, including more than fourteen hundred in Poland alone, roughly nine in ten of the firms trading in 2024 hold no authorisation today. Practitioner estimates of the eventual attrition run from about 75% to 80%. A registration regime was replaced by an authorisation regime, and most of the population could not clear the new threshold.
Czechia: Eleven Authorisations from 251 Files
The Czech National Bank (CNB) assessed 251 applications and notifications by 1 July 2026, of which 204 were filed under the transitional regime, and authorised eleven firms. It received the highest number of applications in the European Union. Here, the supervisor’s own report explains the gap: The CNB received 245 CASP applications during 2025, of which 210 arrived by 31 July 2025 and 205 in July alone, so the files could only be worked in the second half of the year.
By the end of 2025, it had closed 184 first-instance proceedings and discontinued 171 of them:
- 117 for incompleteness
- 28 because the administrative fee was never paid
- 17 on withdrawal
- 7 for other procedural defects (mainly missing translations)
- 2 because the applicant was a natural person
In 13 further cases, the filing arrived by e-mail without a recognised electronic signature and had no effect as an application at all. Only eleven files were complete enough to reach substantive assessment, and the first six authorisations followed on 11 February 2026. Eleven files reached the merits and eleven firms were authorised. Almost no application was refused on substance, because almost no application got that far.
Further research shows that the composition of the applicant pool explains the rest. Around thirty thousand entities had registered the relevant Czech free trade category, of which roughly five thousand were legal persons, yet only 188 preserved the right to trade during the transition. The CNB records that many applications came from ready-made companies with no trading history, a virtual registered office, and an incorporation date shortly before 30 December 2024, whose purpose was to obtain an authorisation for onward sale. Only a very small share presented a real and transparent business model, ownership structure, and funding. Services involving non-fungible assets sit outside MiCA and under a separate Czech permitting regime supervised by the Financial Analytical Office.
Slovakia: Licence Tourism Named as Ground of Refusal
Slovakia shortened its transition to 12 months, expiring virtual currency trade authorisations on 30 December 2025. The National Bank of Slovakia (NBS) rejected "licence tourism" and nominee structures, imposing strict substance requirements including physical premises and resident key executives. Demonstrating active enforcement, NBS published public warnings naming entities like PEKRAT press & change s.r.o. and Swipelux s.r.o. as unauthorised operators.
The Rulebook That Firms Are Now Measured Against
MiCA has been filled in by extensive delegated and implementing regulations governing complaints handling, service continuity, record-keeping, conflicts of interest, and qualifying holdings. Joint EBA and ESMA guidelines set suitability standards for management bodies. ESMA guidelines of 28 January 2026 fix criteria for assessing staff knowledge and competence. Guidelines of December 2024 govern when a crypto-asset is in fact a financial instrument under MiFID II. A firm that assembled its file against the bare text of the regulation in early 2025 is now measured against several hundred pages of detail that did not exist when it started.
What Supervisors Will Actually Enforce
Article 111(1)(d) of MiCA subjects infringements of Articles 59, 60, 64, and 65–83 to administrative penalties covering authorisation, governance, safeguarding, conflicts, complaints, outsourcing, custody, and order execution. For this block, Member States must provide for maximum fines of at least EUR 700,000 for natural persons and at least EUR 5 million or 5% of total annual turnover for legal persons. Competent authorities can also impose temporary management bans or mandatory licence withdrawals under Article 64.
Three requirements will generate most early findings:
- Own funds: Must at all times be at least the higher of the class minimum (EUR 50k, 125k, or 150k) and 1/4 of the previous year’s fixed overheads.
- Safeguarding: Client funds and crypto-assets must be strictly segregated.
- Operational resilience & Travel Rule: Transfer data, incident reporting, and ICT risk sit inside the same perimeter.
Why a Thin Enforcement Record Is the Trap
ESMA reported over 970 administrative sanctions in 2024 exceeding EUR 100 million, though none were under MiCA yet as states only notified sanction regimes by 30 June 2025. The apparatus is new, but the ESMA register of non-compliant entities reached 164 entries by mid-July 2026.
Adjacent sectors show the pattern: In 2025 inspections of payment service providers, the CNB identified mismatches between granted authorisations and actual activities as the most frequent deficiency, followed by client fund protection flaws and incomplete AML due diligence records.
What This Means in Practice
For unauthorised firms, the position is settled. The CNB confirmed that unauthorised provision infringes MiCA and triggers penalties exceeding CZK 100 million. ESMA has outlined orderly exit requirements: stop onboarding, open no new accounts, cease marketing, and confine activity strictly to closing client positions while maintaining AML controls.
For authorised firms, regulators are comparing application filings against actual daily operations. Five steps should be taken immediately:
1. Days 1–15: Map actual products, agreements, APIs, and asset flows against services listed in the authorisation.
2. By Day 30: Document governance accountabilities for AML, compliance, ICT risk, and reporting.
3. By Day 60: Trace real transactions end-to-end, from onboarding and sanctions screening to execution and reconciliation.
4. By Day 75: Assemble a supervisory file with documented proof (minutes, logs, tickets) for every material requirement.
5. By Day 90: Conduct a simulated inspection and establish a unified remediation plan.
Firms without authorisation have limited options: passporting under Article 65 (requires real substance), merging with a licensed entity (triggers change-of-control approval), or a controlled voluntary wind-down.
Expert Commentary & Strategic Roadmap
Most of what firms are being told at this point is basic remediation advice. The deeper constraints deciding whether a crypto business in this region is viable require strategic structuring. Based on practical market experience by financial legal advisors at COREDO, several critical operational factors must be addressed:
- Banking Access First: A provider unable to hold a segregated client account at a credit institution cannot satisfy its safeguarding obligation. Open banking discussions before applying for a licence. If an institution declines, request the refusal in writing to demonstrate compliance efforts to regulators.
- Prudential Safeguards: Capital requirements can be met via own funds, insurance policies, or comparable guarantees. Utilizing insurance models or holding capital in non-EUR currencies (converted at central bank rates) can prevent unnecessary capital locks for international groups.
- Stablecoin & Payment Licensing: Transfers of e-money tokens may constitute payment services. Settle product classification early to avoid discovering post-submission that a separate Payment Institution (PI) authorisation is required.
- Pre-Licensing Meetings: Arrive at supervisory meetings with a fully written legal analysis and clear transactional flows. Delegations should include key risk, compliance, and technology officers rather than external advisers alone.
- M&A Due Diligence: When acquiring an authorised entity, inspect the full supervisory correspondence file, verify specific service boundaries in the authorisation, and factor in the change-of-control approval timeline.
About COREDO
COREDO is a legal and financial consulting firm operating in the European Union since 2016. The company provides legal, financial, and corporate services, helping small and medium-sized enterprises navigate financial licensing, corporate structuring, and regulatory compliance across 15 European jurisdictions.
Forex · Capitals Wire

