After the MiCA transition: remediation, not preparation
Tokenisation & DLT · 8 July 2026 · Slava Volotovsky
TL;DR
- The CASP transitional period ended on 1 July 2026. Firms providing crypto-asset services without authorisation are now, in general, operating outside the perimeter.
- The realistic options are to cease, to restructure toward the financial-instruments perimeter or an authorised partner, or to complete authorisation while curtailing activity — each with different sequencing risk.
- Perimeter analysis has changed character: it is now the basis for remediation decisions with immediate commercial consequences, not a planning exercise.
For eighteen months, MiCA work was preparation: gap analyses, application files, target operating models. That phase is over. Since 1 July 2026, an entity providing crypto-asset services to clients in scope without a CASP authorisation (or a valid passport from another Member State) is generally not in a grace period — it is in breach, or close enough to it that the distinction offers little comfort.
Law, regulator practice, market practice
Black-letter law. MiCA's transitional regime allowed firms operating under pre-existing national frameworks to continue while seeking authorisation, subject to the end date each Member State applied. That runway has now closed in Luxembourg and in most relevant jurisdictions. The statute is not ambiguous about the consequence: crypto-asset services within scope require authorisation. Separately — and this is the pivot point for restructuring — instruments that qualify as financial instruments under MiFID II fall outside MiCA altogether, into the securities regime.
Regulator practice. Regulators have generally signalled that they distinguish firms with credible, progressing applications from firms that simply continued trading. That distinction is likely to shape enforcement priorities, but it is not a legal defence, and it should not be treated as one. Engagement, candour about current activity, and a documented wind-down or remediation plan tend to be viewed differently from silence.
Market practice. The market has already split. Some firms passported in from other Member States; some restructured into agency or referral models around an authorised CASP; some repositioned their product so that the instrument qualifies as a financial instrument and is handled through the securities perimeter; some are exiting. Counterparties and banks have noticed — authorisation status is now a standard onboarding question, which means the commercial penalty for irregular status arrives faster than any regulatory one.
Who this affects
Three groups, in practice. First, platforms and service providers that missed the deadline — whether because the application stalled or because they assumed the perimeter did not reach them. Second, issuers and distributors whose programmes depend on intermediaries whose status is now uncertain: their counterparty diligence has become a perimeter question. Third, firms whose original perimeter analysis dates from 2024 and was written for a different purpose; an analysis drafted to support an application reads very differently from one drafted to support a cease-or-restructure decision.
Operational implications
The work now runs in a specific order. Inventory the services actually being provided — as performed, not as described in the application file. Re-run the perimeter analysis instrument by instrument, because the financial-instrument route is often the most defensible way to keep an institutional product alive. Decide, per service line: cease, restructure, or complete authorisation with curtailed activity. Then sequence the client-facing steps — migration, contract termination, communications — so that the remediation itself does not create conduct or contractual liability. Firms that do this deliberately in the second half of 2026 will likely be in a materially better position than firms that wait to be asked.
We advise on perimeter and remediation questions of this kind, for platforms, issuers, and their counterparties. A short call generally clarifies scope and feasibility: contact@viekey.eu.

