MiCA Article 143(3) grandfathering period end dates by EU Member State — CASP authorization deadline July 2026
Back to blog

MiCA Grandfathering Ends July 1, 2026: What CASPs Must Do Before the Deadline

Article 143(3) was never a grace period. It was a countdown. Less than six weeks remain as of publication. Eleven EU Member States have already closed their grandfathering windows — some as early as June 2025, Germany and Ireland by December 2025. Here is what the provision actually allows, what ESMA requires, and the sprint you need to run if you are not yet authorized.

Table of contents

You have been operating as a crypto exchange in the EU since 2023 under national registration. MiCA (MICAR) passed. You submitted an Article 143(3) notification, kept operating, and figured you would deal with the full CASP authorization eventually.

That eventually is now. July 1, 2026 is the hard stop for most EU jurisdictions. If you do not have full MiCA authorization by then, you shut down or face substantial fines and personal executive liability under MiCA Article 111.

The deadline has passed. MiCA grandfathering ended on 1 July 2026. As of that date, all transitional periods across all 27 EU Member States have expired — there is no further runway and no extension mechanism inside the regulation. Any CASP that did not receive full MiCA authorisation by that date must immediately cease EU client-facing services. National competent authorities (NCAs) across the EU are now empowered to issue fines, suspend operations, and initiate wind-down orders; ESMA has confirmed it is coordinating with NCAs — alongside the EBA and AMLA — to monitor and act against unauthorised CASPs that continue operating. This article explains what unauthorised CASPs must do now, what a compliant wind-down requires, and what the remaining options are.

This article is part of Compliora's MiCA grandfathering cluster. See also: MiCA grandfathering period enforcement risks for unlicensed CASPs after July 2026; the complete Article 143(3) deadline and CASP wind-down guide; and a deep-dive on why grandfathering ends July 1 2026 and what that means for your authorisation timeline.

What Article 143(3) MiCA Grandfathering Actually Is

Article 143(3) of MiCA allows crypto-asset service providers that were lawfully operating under national frameworks before December 30, 2024 to continue operations in their home Member State while applying for full CASP authorization. It is a transition mechanism — not permanent permission.

"Crypto-asset service providers that were allowed to provide crypto-asset services in accordance with the national law of a Member State before 30 December 2024 may continue to provide crypto-asset services in that Member State while their application for authorisation is being assessed, provided that they submit a complete application within 18 months from 30 December 2024 or notify the competent authority within 6 months."

— Regulation (EU) 2023/1114, Article 143(3)

Break that into operational terms:

  1. You had to be authorized or registered nationally before December 30, 2024. If you launched in January 2025, you do not qualify.
  2. You had to notify your national competent authority within 6 months — deadline was June 30, 2025.
  3. You must submit a complete CASP application within 18 months — deadline is June 30, 2026 for most jurisdictions.
  4. Your national regulator decides whether you can keep operating while they assess your application. It is not automatic or EU-wide.

Common misread: Most CASPs read this as "we have until mid-2026 to apply." Technically true. Practically dangerous — filing a complete application on June 29 leaves you zero runway if the regulator finds it incomplete.

What Grandfathering Does NOT Give You

No EU passporting rights. This is the part most operators miss.

If you are grandfathered in France, you can operate in France. You cannot passport into Germany, Spain, Italy, or any other Member State. MiCA's single passport only activates after full CASP authorization.

If you have been onboarding customers EU-wide under the assumption that Article 143(3) gives you pan-European coverage, you are non-compliant right now. Each jurisdiction where you operate without local authorization or full CASP approval is a separate enforcement risk.

No regulatory equivalence. National frameworks varied widely pre-MiCA. MiCA's requirements — especially on custody (Article 70), conflicts of interest (Article 73), and client asset segregation (Article 76) — are materially different from what most national regimes required.

Grandfathering does not grandfather your compliance program. ESMA's supervisory guidance makes this explicit: competent authorities should monitor whether grandfathered CASPs are actively moving toward MiCA standards during the interim. If your first real MiCA compliance work starts when you file the application in May 2026, you are filing incomplete.

Country-by-Country Deadline Variation: Who Already Cut Off Early

MiCA allows Member States to shorten the 18-month transition window — to 12 or even 6 months. Many did, and the result is that for a significant portion of the EU, grandfathering has already ended.

Jurisdiction / Regulator Window End Date Status
Netherlands (DNB / AFM) 6 months June 30, 2025 Ended
Latvia (FCMC) 6 months June 30, 2025 Ended
Hungary (MNB) 6 months June 30, 2025 Ended
Slovenia (ATVP) 6 months June 30, 2025 Ended
Finland (FIN-FSA) 6 months June 30, 2025 Ended
Poland (KNF) 6 months June 30, 2025 Ended
Lithuania (Bank of Lithuania) 6 months June 30, 2025 Ended
Sweden (Finansinspektionen) ~9 months September 2025 Ended
Germany (BaFin) 12 months December 31, 2025 Ended
Ireland (Central Bank) 12 months December 31, 2025 Ended
Greece (HCMC) 12 months December 31, 2025 Ended
France (AMF) 18 months July 1, 2026 6 weeks left
Spain (CNMV) 18 months July 1, 2026 6 weeks left
Italy (CONSOB) 18 months July 1, 2026 6 weeks left
Malta, Luxembourg, Estonia, and most others 18 months July 1, 2026 6 weeks left

If you were operating in any jurisdiction whose window has already closed and you have not filed a complete CASP application — or your regulator has not explicitly permitted continued operations during review — you are already non-compliant. This includes Germany and Ireland, whose 12-month windows closed on December 31, 2025.

Sweden: Finansinspektionen Moved Earlier Than Most

Sweden's Finansinspektionen (FI) ended its grandfathering window in September 2025 — not June, not July 2026. FI published guidance in Q1 2025 making this clear. FI has been aggressive: they published a public list of entities that notified under Article 143(3) and a separate list of those that submitted applications. If you are not on the second list and you are still operating in Sweden, you are visible.

What ESMA Requires: Wind-Down Plans Must Be "Operational, Credible, and Immediately Executable"

In December 2025, ESMA published a statement on MiCA transitional measures setting out expectations for grandfathered CASPs. The core requirement: CASPs not yet authorized must have orderly wind-down plans in place — ready to execute without causing undue economic harm to clients — before the end of their transitional period.

ESMA also explicitly warned that national competent authorities should treat "last-minute" applications for authorization with considerable caution — applying the same standard as any other application, even if that means the applicant CASP must wind down while the application is assessed. Filing in late June 2026 does not guarantee a bridge to operate during review.

What "Operational, Credible, and Immediately Executable" Means in Practice

Operational

  • Detailed step-by-step process for customer notification
  • Timeline for returning client assets — MiCA requires segregated custody, and your plan must show how you execute returns
  • Process for terminating service agreements, API access, wallet connections
  • Staff responsibilities during wind-down
  • IT shutdown procedures, especially for hot wallets and custodial infrastructure

Credible

  • Financially realistic — if you hold €50M in client assets, your wind-down budget must account for operational costs during asset return
  • Legally sound — must comply with national insolvency and consumer protection law
  • Timeline-tested — "we will return all assets in 48 hours" is not credible for a platform with 100,000 users

Immediately Executable

  • No dependencies on "we will figure it out later"
  • Pre-drafted customer communications
  • Pre-negotiated terms with liquidity providers or custodians if needed
  • Board pre-approval for contingent execution — if your plan requires board sign-off to activate, get that sign-off now

ESMA's guidance also states that competent authorities should review these plans before July 1. Some regulators — AMF and BaFin among them — are asking for draft wind-down plans alongside CASP applications. File your application in June without one and expect requests for additional information that delay assessment.

The wind-down requirement flips the risk model. Pre-MiCA, if you lost national authorization, you had runway to appeal or restructure. MiCA's design assumes no continued operations post-deadline without authorization. If your application is denied on June 15, 2026, you have two weeks to execute a full business shutdown. Most CASPs have not built this infrastructure.

Penalties for Non-Compliance: MiCA Article 111 Penalty Structure

MiCA Article 111 sets the administrative penalty structure. The amounts depend on the type of breach and whether the entity is a legal or natural person. Operating without authorization after the grandfathering period ends is a breach of Article 59 — the most direct enforcement trigger:

Legal entities (companies)

€5M
or 5% of total annual turnover — whichever is higher (Article 111(3)(a) and (c)), plus at least twice any profit gained from the breach.

Natural persons (directors, officers)

€700K
Personal fines on directors and compliance officers individually responsible for the breach.

Which cap applies: Operating without authorisation is a breach of Article 59, which sits in Article 111(1), point (d). For that category the maximum administrative fines are at least €5,000,000 or 5% of total annual turnover for legal persons (Article 111(3)(a) and (c)) and €700,000 for natural persons (Article 111(2)(d)) — in each case plus at least twice any profit gained. MiCA’s highest turnover-based cap is 12.5%, and it is reserved for other breach categories (points (b) and (c)); there is no “€15M / 10%” figure in Article 111.

Operational penalties include cease-and-desist orders (immediate shutdown), a ban on providing crypto-asset services in the EU, withdrawal of any national permissions still held, and public disclosure of the breach — naming the entity and the individuals responsible.

Some jurisdictions (France, Netherlands) already have personal liability frameworks for financial services breaches. MiCA gives regulators a new hook. Expect personal fines on directors up to €700,000 (the MiCA Article 111 ceiling for natural persons), temporary bans from holding management roles in regulated entities, and criminal referral where the breach involved fraud or client asset misappropriation.

Enforcement Likelihood Is High

Post-FTX, post-Celsius, EU regulators have political cover to be aggressive. MiCA was sold as the framework that prevents another FTX in Europe. If dozens of CASPs keep operating post-July 1 without authorization, that narrative collapses. Expect coordinated enforcement sweeps in Q3 2026, pressure on payment rails to cut off non-compliant entities (Visa, Mastercard, SEPA), and domain seizures in jurisdictions with precedent for this approach.

6-Week Action Checklist for CASPs Not Yet Authorized

Week 1

Regulatory Status Audit

✓ Deliverable: Know exactly where you stand in every jurisdiction you operate
  • List every EU Member State where you have active customers
  • Confirm whether you are grandfathered in each — some jurisdictions interpret "lawfully operating" differently
  • Identify which jurisdictions ended grandfathering early (NL, LV, HU, SI, FI, SE) — if you are still operating there without authorization, you are already non-compliant
  • For jurisdictions where you ARE grandfathered: confirm your exact application deadline with the national regulator directly
  • Download your national regulator's CASP application template (AMF, BaFin, CNMV, etc.)
Week 2

Gap Analysis Against MiCA Requirements

✓ Deliverable: A compliance gap matrix showing what you have vs what MiCA requires
  • Custody (Art. 70): client assets segregated? Insurance or equivalent guarantee covering loss or theft? Written custody policy?
  • Conflicts of interest (Art. 73): written policy identifying conflicts; procedures for managing them (Chinese walls, client disclosure)
  • Client asset protection (Art. 76): segregated fiat and crypto accounts, daily reconciliation, insolvency ring-fencing
  • Complaints handling (Art. 80): public procedure, written log, annual complaints report to regulator
  • Outsourcing (Art. 68): written agreements with audit rights for any outsourced functions (KYC, AML, custody)
  • Governance (Art. 65): at least two natural persons in management; fit-and-proper per EU standards (no relevant criminal record, demonstrated competence)
Weeks 3–4

Draft Wind-Down Plan

✓ Deliverable: A 10–15 page operational wind-down plan
  • Section 1 — Triggering events: application denied / pending past July 1 without continued-operations permission / voluntary withdrawal
  • Section 2 — Customer communication: pre-drafted email template, in-app notification, website banner; notification within 24 hours of trigger
  • Section 3 — Asset return process: fiat and crypto return procedures, 30/60/90 day timelines, fee allocation, wallet address verification
  • Section 4 — Operational shutdown: trading halt date, API termination, staff timeline, GDPR-compliant data retention and deletion
  • Section 5 — Financial provisions: estimated wind-down cost (staff, infrastructure, transaction fees), funding source (reserve account, credit line)
  • Section 6 — Legal notifications: template letter to competent authority, notifications to payment processors, bank partners, third-party custodians
Week 5

Application Package Assembly

✓ Deliverable: Complete CASP application ready to file
  • Application form (regulator's template)
  • Programme of operations — business plan, services offered, target markets, revenue model
  • Organisational structure — org chart, management CVs, ownership structure
  • Compliance policies: AML/CFT (Art. 78), conflicts of interest (Art. 73), custody (Art. 70), complaints handling (Art. 80), outsourcing (Art. 68)
  • Financial statements (last 2 years, audited if required by regulator)
  • Capital adequacy calculation per Article 67 — see FAQ below for applicable amounts
  • IT and cybersecurity documentation — system architecture, incident response plan
  • Wind-down plan (if the regulator requests it alongside the application)
Week 6

File and Notify

✓ Deliverable: Submitted application + confirmation receipt
  • Submit via your regulator's portal — most have online submission systems
  • Request written confirmation of receipt
  • Pay application fee — France approximately €5,000, Germany approximately €10,000; confirm the exact amount with your regulator
  • Notify bank partners, custodians, and auditors
  • Assign an internal owner to handle regulator queries — do not let requests for information sit unanswered

Post-filing: expect questions. Regulators rarely approve on first submission. Median time to first request for additional information is 4–6 weeks.

What If You Cannot Make July 1?

Three options, none easy:

Option 1: Wind down before July 1. If you know you cannot get authorized in time, execute your wind-down plan voluntarily. Better to control the process than have it forced on you.

Option 2: Restrict to non-EU markets. If you have customers in the UK, Switzerland, or UAE, you can continue operating there. Exit EU markets cleanly — return assets, terminate accounts. This avoids MiCA but means losing EU revenue.

Option 3: Acquire or merge. Some CASPs are buying authorized entities or merging with competitors further along in the authorization process. Expensive, complex, requires regulatory approval of the transaction itself — and requires several months of lead time you likely no longer have.

FAQ

What happens if my CASP application is still pending on July 1, 2026?

You can continue operating only if you submitted a complete application by the deadline AND your national competent authority explicitly allows continued operations during the review period. Most regulators will allow this, but it is not automatic. If your application is incomplete or late, you are subject to Article 111 penalties regardless of pending status.

Can I passport into other EU countries while grandfathered?

No. Grandfathering under Article 143(3) is jurisdiction-specific — you can only operate in the Member State where you were originally authorized or registered. The MiCA passport (right to operate EU-wide with one authorization) only activates after full CASP authorization is granted.

Do I need a wind-down plan if I am confident my application will be approved?

Yes. ESMA's guidance requires it regardless of your confidence level. Your national regulator will likely ask for it as part of the application review or as a condition of continued operations. Think of it as regulatory hygiene — like having an incident response plan even if you do not expect a breach.

What is the difference between MiCA CASP authorization and national registration?

National registration (pre-MiCA) was each Member State's own framework: France had PSAN, Germany had KWG, the Netherlands had DNB crypto registration. Requirements varied; no automatic EU passport. MiCA CASP authorization is the unified EU framework: one authorization, valid across all 27 Member States with passporting. National registrations become obsolete after July 1, 2026.

What if I only operate in one country — do I still need CASP authorization?

Yes, if you provide crypto-asset services as defined in MiCA Article 3(1)(16). Even single-country operations require CASP authorization after grandfathering ends. The only exemptions are in Article 4 — for example, services provided to fewer than 150 clients, or fully decentralized protocols with no legal entity. If you run a centralized exchange, custodian, or brokerage, you need authorization regardless of geography.

What is the minimum capital requirement for a CASP?

MiCA Article 67 and Annex IV set three tiers based on services offered:

  • €50,000 — advice on crypto-assets, portfolio management (without custody)
  • €125,000 — operation of a trading platform for crypto-assets
  • €150,000 — custody and administration of crypto-assets on behalf of clients; execution of orders; exchange services; placing of crypto-assets

Where a CASP provides multiple services, the highest applicable minimum applies. Capital must be held in cash or highly liquid assets — not simply authorized capital on paper.

Can I apply for CASP authorization in multiple countries?

No. You apply in your home Member State — where your registered office is located. Once authorized there, you passport into other Member States by notifying your home regulator, who notifies the host regulator. You cannot select the most favorable regulator if your entity is incorporated elsewhere.

Screen Your CASP Operations Against MiCA Requirements

Paste your product description and get a structured analysis: which MiCA articles apply, what you are missing, what the penalties are. Takes ~10–15 minutes.

Run MiCA Assessment →
Link copied to clipboard