If your crypto business sits outside the EU — in the US, UK, UAE, Singapore, or anywhere else — and EU residents use your product, you have probably heard that reverse solicitation lets you serve them without a MiCA licence. That is technically true and practically misleading. As the MiCA transitional period ends on 1 July 2026, regulators are treating reverse solicitation as a compliance risk to police, not a doorway to walk through. (For the deadline mechanics, see our guide to the MiCA grandfathering period ending.)
This guide explains what reverse solicitation actually is under Article 61 of MiCA, why ESMA's 2025 guidelines gutted it as a growth channel, the specific things that quietly disqualify you, and how to figure out whether your setup is exposed.
The short answer: a non-EU firm may provide a crypto-asset service to an EU client only when that client approached the firm entirely on their own initiative, with no prior marketing, advertising, or outreach of any kind. The moment you promote, target, or even passively make your service available to EU users, the exemption is gone — and you need a CASP licence.
What reverse solicitation means under MiCA
MiCA does not contain a general third-country regime. Unlike some EU financial frameworks, there is no equivalence mechanism that lets a non-EU firm "passport in" from abroad. The only carve-out is Article 61: a crypto-asset service may be provided to an EU client where it is initiated at the client's own exclusive initiative. This is the reverse solicitation (or "reverse enquiry") exemption.
It exists to cover a genuinely narrow scenario — an EU person seeks out a foreign provider entirely on their own — not to give offshore platforms a quiet back door into the world's second-largest crypto market. ESMA and national regulators have been explicit that the exemption is the exception, to be read restrictively, and that it cannot be used by EU-based firms at all to avoid authorisation. If you want sustained EU access, the alternative is the licensed path — see CASP licence requirements.
Why ESMA's 2025 guidelines changed everything
On 26 February 2025 ESMA published its final guidelines on reverse solicitation, which took effect roughly two months later (27 April 2025). They were mandated by Article 61(3) to clarify two things: when a third-country firm is deemed to be soliciting EU clients, and what supervisory practices regulators should use to detect attempts to circumvent the exemption. In practice they did something blunter — they made the exemption almost impossible to rely on for any business that actually wants EU customers.
"Solicitation" is interpreted broadly and is technology-neutral
Under the guidelines, virtually any promotion, advertisement, or offer that reaches EU clients counts as solicitation. That includes your website, your mobile app, push notifications, social media posts, paid search and SEO, email, and influencer content. It does not matter whether the activity was aimed specifically at the EU — if it reaches EU audiences, it is likely caught.
Anyone acting on your behalf counts too
Solicitation is not limited to what your company does directly. It captures partners, affiliates, referral programs, and influencers acting on your behalf — even where there is no formal contract or obvious payment between you. Outsourcing your EU marketing to a third party does not insulate you; it simply moves where the breach happens.
The "same type" trap kills follow-on marketing
Even if a client genuinely initiated the first transaction, you cannot then market further services to them — not even of the "same type" — outside that original context. And ESMA construes "same type" very narrowly, using a granular taxonomy by asset and service category and risk. Different e-money token reference currencies, different technologies, liquid versus illiquid assets, meme coins versus asset-referenced tokens — these are treated as different types. In other words, the exemption attaches to one specific service, once, and does not roll over into a customer relationship.
Disclaimers do not save you. A "not available to EU residents" banner on a site that is in English, accepts EUR, has no geo-blocking, and is fully usable from Germany will not hold up. ESMA's position is clear: disclaimers cannot override facts. Regulators look at what your service actually does and who actually uses it, not at the legal language in your footer.
What quietly disqualifies you
Most firms that think they are "fine on reverse solicitation" are not. These are the everyday signals that regulators read as you targeting the EU:
- An English-language website with a EUR payment or pricing option, accessible from EU member states
- No effective geo-blocking or client filtering for EU IPs and residents
- A
.eudomain, EU-specific subdirectories, or EU contact details - Allowing EU residents to register, complete KYC, and trade — even passively, without "targeting" them
- Airdrops or token campaigns with no country restrictions
- Affiliate or referral partners who bring in EU users
- Social media, ads, or influencer content that EU audiences see
Regulators are actively looking for these. ESMA expects national authorities to use marketing and social-media monitoring tools, look for EU indicators such as domains and contact details, share intelligence with tax and law-enforcement bodies, and act on complaints and whistleblowers. They do not need a prior suspicion of wrongdoing to monitor — surveillance is the baseline expectation.
What is at stake after 1 July 2026
The MiCA transitional period expires across the EU on 1 July 2026. After that date, providing crypto-asset services to EU clients without authorisation — and without a watertight reverse-solicitation basis — is a breach of Article 59, and the administrative penalties sit in Article 111. For a firm (legal person), the maximum fines are up to €5 million or 5% of total annual turnover, whichever is higher, plus at least twice any profit gained. Individual directors and officers face fines up to €700,000 and a possible temporary ban from management roles. Member States may apply criminal penalties instead. The exposure is not only financial:
| Exposure | What it looks like in practice |
|---|---|
| Regulatory action | Public warnings, blacklists of unauthorised providers, cease-and-desist orders, website-blocking, and bans on EU operations |
| Financial penalties | Article 111 administrative fines: up to €5M or 5% of annual turnover for the firm, up to €700K for individuals, plus at least twice any profit gained |
| Criminal exposure | In some Member States, operating without authorisation carries criminal liability. France, for example, provides for up to two years' imprisonment and a €30,000 fine |
| Commercial collapse | Payment processors and banks de-risk you, EU users cannot lawfully use the service, and access dries up |
Should you rely on reverse solicitation?
For a one-off, genuinely unsolicited interaction, the exemption is real and you can document it. As a market-entry or growth plan for the EU, it is not viable — and treating it as one is exactly what regulators are now hunting for. If EU clients are part of your business model, the honest options are narrower than they look:
| Path | When it fits |
|---|---|
| Genuine reverse solicitation | Rare, client-initiated, no follow-on marketing, fully documented. Not a strategy. |
| Geo-block the EU | You do not want EU clients. Real geo-blocking + client filtering + neutral website. Keep records. |
| Establish an EU entity + CASP licence | You want sustained, lawful EU access with passporting across all member states. |
Before you decide: the threshold question is not "can I use reverse solicitation" — it is whether MiCA applies to your activity and your users at all. That depends on which services you provide, which tokens you handle, and how EU users reach you. Start with does MiCA apply to my crypto project, then map your exposure.
A quick self-check
Run your own setup against these. If you answer "yes" to any of them and you are serving EU residents, reverse solicitation almost certainly does not cover you:
- Do EU residents reach your product without being, demonstrably, the ones to initiate contact?
- Is your site, app, or marketing visible to EU audiences in any language they read?
- Do you accept EUR, or list EU-relevant pricing?
- Do affiliates, referrers, or influencers bring you any EU users?
- Can an EU resident register and transact without a hard geo-block?
Not sure if MiCA applies to you?
Compliora analyses your project against MiCA, MiFID II, PSD2, and AIFMD and returns a structured report — what is in scope, where the exposure sits, and what the licensed path would require. An AI-powered research tool to use before you talk to a lawyer, not a substitute for legal advice.
Run a MiCA Assessment →Frequently asked questions
Can a US or UK crypto exchange take EU customers without a MiCA licence?
Only through genuine reverse solicitation — an EU client who reaches out entirely on their own, with no marketing, ads, or EU-facing availability beforehand. If EU users can simply find, register, and trade on your platform, that is not reverse solicitation, and you need authorisation.
Does a "no EU residents" disclaimer protect me?
No. ESMA's position is that disclaimers cannot override facts. If your service is in practice accessible to and used by EU residents, the disclaimer is irrelevant. Regulators assess actual conduct, not footer text.
Is reverse solicitation a viable way to grow in the EU?
No. It is an exception for isolated, client-initiated cases, not a market-entry channel. Any follow-on marketing — even for the same type of service — breaks it. For sustained EU access the realistic route is an EU entity with a CASP licence, which also unlocks passporting across all member states.
What happens after 1 July 2026?
The MiCA transitional period ends EU-wide. From that date, serving EU clients without authorisation, and without a defensible reverse-solicitation basis, is a breach of EU law — exposing the firm to penalties under Article 111, bans, website-blocking, loss of banking and payment rails, and in some Member States criminal liability.