The transition period is over
For crypto-asset businesses in the EU, 1 July 2026 was the end of the road. That date was the outer limit of the transitional regime under Article 143(3) of the Markets in Crypto-Assets Regulation (MiCA). Firms that were lawfully providing crypto-asset services before MiCA applied could keep operating under national rules for a limited window – and every one of those windows has now closed.
Sweden closed earlier than most. Finansinspektionen applied a short transitional period that expired at the end of September 2025, which means Swedish firms have already been living under the full MiCA regime for months. What changes now is the wider picture: the passporting map is settling, unauthorised competitors are being pushed out, and supervision is turning from onboarding to enforcement.
What MiCA actually requires
MiCA has applied in full to crypto-asset service providers since 30 December 2024, with the rules on asset-referenced tokens and e-money tokens applying from 30 June 2024. If your business provides crypto-asset services in the EU, you now need authorisation as a CASP from a national competent authority – in Sweden, Finansinspektionen.
Services that require authorisation
The regulated services include custody and administration of crypto-assets, operating a trading platform, exchanging crypto-assets for funds or for other crypto-assets, execution of orders, placing, reception and transmission of orders, advice on crypto-assets, portfolio management and transfer services. If you touch any of these on a professional basis, you are in scope.
What authorisation brings with it
An authorised CASP has to meet prudential requirements, governance and fit-and-proper standards for management, safeguarding of client assets, complaint-handling procedures, conflict-of-interest rules, outsourcing requirements, ICT and operational resilience obligations, and detailed disclosure and marketing rules. Firms issuing tokens or admitting them to trading must publish a compliant white paper.
Why this is not just a crypto problem
MiCA overlaps with regimes that reach far beyond exchanges. The Transfer of Funds Regulation extends the “travel rule” to crypto transfers. Anti-money-laundering obligations apply in full. And CASPs are financial entities under DORA, which means ICT risk management, incident reporting and third-party risk registers are not optional extras – they are part of the licence you hold.
That is the part firms most often get wrong. They treat authorisation as the finish line, when in practice it is the start of a supervised relationship in which the regulator expects evidence, not intentions.
Practical example: a fintech adding a crypto feature
A Swedish payments company wants to let business customers hold and convert a stablecoin balance inside its app. It assumes that because the underlying wallet is provided by a partner, it stays outside MiCA. That assumption is usually wrong. If the company is the one holding the customer relationship, exchanging assets or transmitting orders, it is providing crypto-asset services, whatever the technical arrangement behind it.
The correct sequence is to map the service against the MiCA list, decide whether the partner is authorised and whether you can rely on their licence, and if not, either restructure the arrangement or apply for authorisation. Doing that analysis before launch costs a fraction of what it costs afterwards.
Common mistakes companies make
Assuming a non-EU licence travels. MiCA applies to services provided in the EU. Reverse solicitation is interpreted narrowly and is not a business model.
Relying on a partner’s licence without a contract that supports it. If you carry the customer relationship, supervisors will look at you.
Treating marketing as unregulated. Communications must be fair, clear and not misleading, and identifiable as marketing.
Forgetting DORA. An authorised CASP inherits a full ICT resilience regime, including contractual requirements for critical ICT providers.
Recommended actions
Confirm your authorisation status and the exact services covered by it. Check that your passporting notifications match the markets you actually serve. Review your white papers and marketing communications against the disclosure rules. Test your safeguarding of client assets against the segregation requirements. Align your ICT risk framework and incident reporting with DORA. And build a register of your third-party providers before you are asked for one.
Frequently asked questions
We applied for authorisation before the deadline – can we keep operating?
That depends on the national rules under which your application was filed and on your competent authority. This is exactly the point at which to get a clear written position rather than assume.
Does MiCA apply to NFTs?
Unique and non-fungible crypto-assets are largely outside MiCA, but the label matters less than the substance. A large series of near-identical NFTs may be treated as fungible in practice.
What are the consequences of operating without authorisation?
National competent authorities can order the activity to stop, impose administrative fines and public censure, and withdraw authorisations. The reputational and banking consequences usually arrive first.
Conclusion
MiCA has moved from a compliance project to a licensing reality. The firms that will do well in the next phase are the ones that treat their authorisation as something that must be maintained – with governance, records and resilience that survive a supervisory visit. The ones still hoping the transitional period stretches a little further have already run out of road.
Lawgent advises fintechs, crypto businesses and their technology providers on MiCA, DORA and financial regulation – from scoping and authorisation to the governance that keeps the licence intact. Book a free first hour and we will map your exposure.