Post-Grandfathering Crisis: Over 1,000 Crypto Firms Face MiCA Enforcement
2026-09-29
Only 281 of 1,343 crypto firms operating across the European Economic Area held a MiCA license when the EU's final transition deadline passed on July 1, 2026, according to blockchain intelligence firm TRM Labs. That left 1,062 firms outside the regulatory perimeter, required to wind down, restructure, or transfer their customers elsewhere.
Now, with the grandfathering period closed, ESMA's 2027 work programme confirms the next phase: active supervision, a centralized surveillance system, and enforcement against anyone still operating without authorization.
Key Takeaways
TRM Labs found that only 281 of 1,343 EEA crypto-asset service providers secured MiCA authorization by the July 1, 2026 deadline, leaving 1,062 firms unauthorized and required to exit the market or transfer customers.
Unauthorized firms carry materially higher risk: 12% received a High or Severe risk rating versus 2% of authorized firms, and they sent roughly $5 billion directly to sanctioned counterparties, about three times the $1.7 billion recorded among licensed firms.
ESMA's 2027 work programme shifts the regulator's focus from writing MiCA's rules to supervising compliance, centered on five priorities and a new centralized surveillance system called MIDAS, expected to be operational in 2027.
What Was the MiCA Grandfathering Period, and Why Did It End?
MiCA's grandfathering period, formally the transitional regime under Article 143(3), let crypto firms that were legally operating before December 30, 2024, continue serving EU clients under their existing national registrations while they applied for full MiCA authorization.
Individual member states could set shorter national transition windows, but none could extend grandfathering beyond the EU-wide final cutoff of July 1, 2026.
That two-stage structure explains why the story unfolded gradually rather than all at once. Some countries ended their national transition periods earlier, prompting firms to seek authorization sooner, while other jurisdictions ran their transition windows all the way to the July 2026 deadline. Once that date passed, there was no remaining legal basis anywhere in the EU for a firm to keep operating on a pre-MiCA national license.
How Many Crypto Firms Actually Got Licensed?
The numbers show a licensing regime that converted a minority of pre-existing crypto firms into authorized operators. Based on TRM Labs' dataset:
Authorization rates varied sharply by country. Germany authorized 55 firms and ranked as the most active licensor; France and the Netherlands each authorized 29.
At the other extreme, Poland issued zero home authorizations despite a previous national register that had exceeded 1,800 entries, and Lithuania converted only 8 firms out of a prior register of more than 400. Greece and Portugal also issued no home authorizations in TRM's dataset.
Some of that gap reflects inactive or defunct registrations rather than a wave of sudden closures TRM noted that most entries on Poland's old register showed no observable crypto activity. But even accounting for that, the conversion rate from "registered under the old system" to "authorized under MiCA" was low across most of the EU.
What Happens to Unauthorized Crypto Firms Now?
Firms that missed the deadline must wind down their EU operations in an orderly manner rather than shutting down abruptly, according to ESMA's public statements issued in April and June 2026. Specifically, unauthorized crypto-asset service providers (CASPs) are expected to:
Immediately stop onboarding new EU clients and cease all marketing or solicitation activity.
Limit remaining services to actions necessary to sell, transfer, or close out client positions custody can continue only for as long as strictly needed to complete an orderly exit.
Communicate clearly and repeatedly with clients, including a stated deadline after which any remaining positions will be closed automatically.
Maintain full AML/CFT controls throughout the wind-down, including transaction monitoring, sanctions screening, and suspicious activity reporting.
ESMA also reiterated that firms established outside the EU cannot provide MiCA-covered services to EU clients or solicit them, including in business-to-business contexts, except under the narrow reverse solicitation exemption.
National competent authorities, working alongside ESMA, the European Banking Authority, and the EU's Anti-Money Laundering Authority, are now coordinating to monitor whether unauthorized cross-border firms are actually complying with these wind-down expectations.
Why Does the Risk Profile of Unauthorized Firms Matter?
The firms that failed to get licensed aren't a random cross-section of the market; they skew meaningfully riskier than the firms that did get authorized. TRM Labs' analysis found that 12% of unauthorized firms carried a High or Severe risk rating, compared with just 2% of authorized providers, and every firm rated Severe belonged to the unauthorized group.
Unauthorized firms also sent an estimated $5 billion directly to sanctioned counterparties, roughly three times the $1.7 billion recorded among authorized firms.
That risk wasn't evenly spread, either. About half of unauthorized firms showed no measurable direct illicit exposure at all, while a smaller number sent between 1% and 12% of their volume directly to illicit addresses, a concentration that pulled up the group's overall risk profile disproportionately.
For anyone whose funds sit with a firm that didn't make MiCA's cut, that's the practical reason ESMA is treating the wind-down phase as a supervisory priority rather than a formality.
What Should Crypto Users Check Right Now?
If you hold assets with a European crypto provider, the first step is confirming whether that provider actually secured MiCA authorization. ESMA maintains a public register of authorized CASPs, and clients of firms not listed there do not benefit from MiCA's investor protections, including safeguards over client assets. If your provider isn't authorized:
Check the ESMA Register directly rather than relying on a firm's own claims about its licensing status.
Act promptly if your provider isn't listed options include transferring assets to an authorized CASP or moving them to a self-hosted wallet.
Watch for wind-down communications from your provider, including any stated deadline for closing out residual positions automatically.
Contact the provider first if you're experiencing difficulties, since ESMA and national regulators expect firms to handle the bulk of client communication directly.
What Is ESMA's 2027 Work Programme, and What Changes Next?
ESMA's 2027 work programme marks a deliberate shift from writing MiCA's rules to enforcing them, a change ESMA Chair Verena Ross described to the European Parliament as moving "from rulemaking towards supervision and convergence."
With most of MiCA's foundational rulebook now in place, the regulator's 2027 priorities center on five areas: operational resilience, outsourcing risk management, liquidity monitoring, reverse solicitation, and asset classification.
Two elements of the programme are especially relevant for the post-grandfathering environment:
MIDAS, a centralized crypto market surveillance system, is scheduled to have its first phase operational in 2027, giving supervisors real-time visibility into trading patterns and potential market abuse across the bloc. A second, more advanced phase is targeted for the fourth quarter of 2027, subject to board approval.
Supervisory findings feeding into the EU's formal MiCA review, scheduled for June 2027, meaning the enforcement experience gathered from this transition period will likely shape amendments to the regulation itself.
ESMA has also already published detailed guidelines instructing national regulators on how to detect and prevent market abuse under MiCA, covering insider trading, market manipulation, and unlawful disclosure of inside information, with specific attention to features unique to crypto markets like heavy social media influence and cross-border trading activity.
Separately, ESMA launched a review in July 2026 of a sample of already-authorized crypto custodians, examining custody controls, private-key management, incident response, and risks tied to third-party service providers a sign that authorization itself isn't the end of scrutiny for firms that did make the cut.
What This Means for the Broader Crypto Market
The practical effect of MiCA's transition is a consolidation of the European crypto market into a smaller number of authorized, more heavily supervised firms. TRM Labs noted that MiCA's passporting system already allows a CASP authorized in one member state to serve customers across the entire bloc, a structure that has let firms including Coinbase, Bitpanda, and Kraken operate from a single regulatory base while serving customers EU-wide.
For a crypto investor or trader, the near-term implication isn't that European crypto access disappears, it's that the field of legally operating providers narrows, and using an authorized one carries real regulatory protections that using an unauthorized one does not.
As enforcement moves from a paper deadline to active supervision backed by systems like MIDAS, that distinction is likely to matter more, not less, over the course of 2027.
FAQ
How many crypto firms lost MiCA authorization access?
TRM Labs identified 1,062 EEA crypto firms that remained unauthorized after the July 1, 2026 deadline, out of 1,343 firms in its dataset, leaving only 281 with MiCA authorization at that point.
What happens if my crypto exchange didn't get a MiCA license?
Unauthorized firms are required to wind down EU operations in an orderly manner: stop onboarding new clients, cease marketing, limit services to closing out positions, and communicate a clear deadline to clients. You should check the ESMA Register and consider moving assets to an authorized provider or a self-hosted wallet.
What is MIDAS in the context of MiCA?
MIDAS is ESMA's centralized crypto market surveillance system, designed to give supervisors real-time visibility into trading activity and potential market abuse across the EU. Its first phase is expected to be operational in 2027.
Is the MiCA grandfathering period over everywhere in the EU?
Yes. While individual member states could end their national transition periods earlier, none could extend grandfathering beyond the EU-wide final deadline of July 1, 2026.
Why do unauthorized firms carry more risk than authorized ones?
TRM Labs found that 12% of unauthorized firms carried a High or Severe risk rating compared with 2% of authorized firms, and unauthorized firms sent roughly three times more value directly to sanctioned counterparties than authorized firms did.
Disclaimer: The views expressed belong exclusively to the author and do not reflect the views of this platform. This platform and its affiliates disclaim any responsibility for the accuracy or suitability of the information provided. It is for informational purposes only and not intended as financial or investment advice.
Disclaimer: The content of this article does not constitute financial or investment advice.




