MiCA is now fully enforceable across the EU. What that means for you.
This is a regulatory-intelligence note, not legal advice and not exchange promotion. Its purpose is simple: help you understand a major change so you are not caught out by it — and make informed choices about where and how you hold crypto.
- MiCA is an EU-wide regulation. The main rules for crypto-asset service providers (CASPs) have applied since 30 December 2024.
- National transitional (grandfathering) regimes could continue only until 1 July 2026. ESMA confirms this window has now closed across the EU.
- After that date, a CASP serving EU clients without MiCA authorisation is in breach unless a narrow exception applies.
- Article 61 (reverse solicitation) is a narrow legal exception — not a general loophole.
- The bigger regulatory exposure sits with providers, not with individual users — but users still face practical risks.
What MiCA enforcement means now
MiCA (the Markets in Crypto-Assets Regulation) is EU-wide law. Its core service-provider rules have been in force since 30 December 2024; what changed on 1 July 2026 is the end of the national transitional regimes that let firms keep operating under old national rules while they sought authorisation.
In practice, the market now splits into three kinds of provider. Knowing which one you are dealing with is the single most useful thing you can do.
Article 61 is not a loophole
MiCA Article 61 preserves a narrow "reverse solicitation" exception: where an EU client approaches a third-country provider entirely on their own exclusive initiative, that provider may serve that specific request without MiCA authorisation.
But ESMA interprets this narrowly, precisely to stop it being used as a workaround. The exception fails if there was any solicitation, advertising, promotion, EU-targeted campaign, referral or affiliate activity, or influencer marketing — including through connected parties. It cannot be created by a disclaimer ("you came to us voluntarily") or by VPN-style access, and it does not let the provider cross-sell new services off the back of the relationship.
A useful self-test: did you approach the provider completely independently, with no EU-directed marketing, referral or nudge involved; is the service exactly the one you requested; and could that be demonstrated if questioned? If any answer is weak, Article 61 is not a safe basis to rely on.
Three kinds of provider — know which you are using
1. MiCA-authorised EU provider
Regulated and supervised in the EU. MiCA investor-protection and conduct rules apply. The lowest-friction, lowest-surprise option for anything operational.
2. Non-authorised provider targeting EU users
The highest-risk category. May be required to restrict, migrate, or terminate EU-facing services. The regulatory exposure sits mainly with the provider — but the disruption lands on you.
3. Third-country provider at your own exclusive initiative
The narrow Article 61 situation. Possible for a genuinely self-initiated, specific request — but accept offboarding risk and no MiCA protection. Not a substitute for authorisation.
What this means for you in practice
Using a non-EU provider is not automatically illegal for you as an individual — the heavier regulatory exposure sits with a provider that serves or solicits EU clients without authorisation. But the practical risks are real: sudden account closure or forced offboarding, withdrawal-only mode, geo-blocking when EU residency is detected, no MiCA investor protection or complaint rights, and KYC / source-of-funds and tax-reporting friction.
Prudent steps
Verify whether your exchange or custodian is MiCA-authorised (via your national regulator or the EU registers). Do this before you assume access is safe.
Assume some non-EU venues will restrict, migrate, or end EU-facing service after 1 July 2026 — plan as if it could happen to yours.
Do not leave more than you need on any single venue, and be ready to move funds out at short notice.
They do not create compliance and can complicate your position. Reverse solicitation is a narrow factual exception, not a switch you can flip.
Avoid dependence on one venue. For holdings you are not actively trading, self-custody removes reliance on any single provider entirely — which is where understanding DeFi pays off.
The wider rulebook: Travel Rule and DAC8
MiCA does not stand alone. The EU Travel Rule (the recast Transfer of Funds Regulation, in force since 30 December 2024) requires sender and recipient information to travel with crypto transfers through regulated providers, with extra checks for transfers to and from self-hosted wallets. In plain terms: expect more identity data to be attached to transfers you make via a regulated provider.
DAC8, the EU’s crypto-asset tax-reporting framework (aligned with the OECD’s CARF), has moved into force and brings crypto activity into automatic tax reporting. Assume that crypto activity on a regulated provider is reported to tax authorities, and keep clean records of your transactions.