
MiCA is the world's first unified regulatory framework for digital assets, and the transitional clock has now run out. The final grandfathering deadline was July 1, 2026, and it has passed. Every entity providing crypto-asset services to EU customers must now hold MiCA authorization or stop, and this is no longer a future planning exercise; it is the operating reality.
For cross-border payment companies that use stablecoins in settlement flows, this determines which stablecoins you can use, which providers you can work with, and whether your EU payment flows are legal. This piece covers what the deadline actually changed, what authorization requires, and what payment companies should verify now. It is one of several parallel regulatory shifts across global payment markets reshaping compliance in 2026.
The deadline was not a soft target. On 23 June 2026, ahead of the cutoff, ESMA issued a public statement calling on unauthorized crypto-asset service providers to wind down their EU activities in an orderly manner while safeguarding client interests [1]. In practice, unauthorized providers were told to immediately stop onboarding new EU clients, cease marketing and solicitation, and limit activity to what is needed for clients to sell, transfer, reallocate, or close positions.
Three points matter most for payment companies. First, there is no informal grace period after July 1, and ESMA has signalled that enforcement is robust from day one [2]. Second, a pending application is not authorization: only a granted authorization under Article 63 permits continued service, and firms still waiting on an application do not have legal cover [3]. Third, and most relevant to cross-border flows, ESMA reminded providers established outside the EU that they cannot provide MiCA services to EU clients or solicit them, including in a business-to-business context, and that certain services such as custody cannot be outsourced to entities that are not authorized as CASPs [1].
A CASP license under MiCA covers ten enumerated services including custody, trading, exchange, transfer, advisory, and order execution for crypto-assets [4]. Authorization requires establishing a legal entity in an EU member state with genuine management presence, not a brass-plate subsidiary. Minimum capital is EUR 150,000 for most CASP categories. The applicant must submit a business plan, AML and KYC policies, a risk management framework, cybersecurity measures compliant with DORA, a governance structure, and financial statements, and management must pass fit-and-proper assessments [4].
Regulator review typically takes 60 to 90 business days from a complete application, and preparing from scratch runs roughly EUR 50,000 to EUR 120,000 in legal and compliance fees, on top of the capital requirement.
The single most valuable feature of MiCA authorization is passporting: one license from any EU member state covers all 27. A CASP authorized in Lithuania can serve customers in Germany, France, Spain, and every other EU country without additional applications [4]. This replaces the pre-MiCA world where operating in five EU markets meant five separate national registrations under five different regimes.
Authorization has clustered in a handful of jurisdictions, and more than 40 CASP licenses have been issued so far, with the majority coming out of the Netherlands [5]. Germany attracts larger institutions seeking bank-grade regulatory optics; the Netherlands processed applications quickly and drew on and off-ramp specialists; Luxembourg hosts global exchanges; Malta has become home to several large platforms; and Lithuania is the cost-effective entry point for smaller fintechs transitioning from its existing regime.
From March 2026, custody and transfer services involving E-Money Tokens may require both MiCA authorization and a separate payment services license under PSD2, because EMTs are functionally electronic money [6]. This dual requirement can raise compliance costs for providers handling euro-denominated stablecoins, and has drawn industry criticism over its effect on euro stablecoin competitiveness.
Separately, Tether's USDT does not meet MiCA's EMT requirements and has been delisted from major EU exchanges, while USDC and EURC, issued by MiCA-compliant Circle, are the primary compliant options and are positioned to capture the European stablecoin market [2].
If you process stablecoin payments involving EU customers, verify two things now. First, that any stablecoin you use is issued by a MiCA-authorized entity. Second, that every intermediary handling settlement in the chain is itself authorized as a CASP, because a provider still relying on a transitional arrangement no longer has legal cover. With the deadline behind us, the risk is no longer theoretical: an unauthorized provider in your settlement path is an illegal one, and the exposure flows to the businesses relying on it. The move from a compliance countdown to live enforcement is exactly why cross-border payment companies are consolidating stablecoin settlement onto providers whose authorization they can verify.
[1] Norton Rose Fulbright (Regulation Tomorrow). "ESMA public statement on end of MiCA transitional period." June 2026.
[2] Elliptic. "What the end of MiCA's transitional period means for crypto businesses." June 2026.
[3] ESMA. "Markets in Crypto-Assets Regulation (MiCA)." 2026.
[4] Skadden. "MiCA Update: Six Months in Application." 2025.
[5] Sumsub. "MiCA Regulation and EU Crypto Rules: What Changes in 2026." 2026.
[6] Cyfrin. "MiCA Regulation Explained." 2026.

Hong Kong introduced its Virtual Asset Trading Platform (VATP) licensing regime in June 2023. Nine VATPs had been licensed by early 2025 [1]. That was phase one. Phase two is happening now, and the scope is dramatically wider.
In June 2025, the FSTB and SFC jointly published consultation papers proposing two new licensing categories: VA dealing (covering OTC spot trading, brokerage, and block trading beyond exchange matching) and VA custodian services (covering any entity safeguarding private keys or able to transfer client VAs) [2].
Following consultations, they published two additional categories in December 2025: VA advisory services and VA management (portfolio managers investing in virtual assets) [3].
All four regimes are being legislated under the AMLO. Draft legislation is expected in Hong Kong's Legislative Council in 2026 [4].
Unlike MiCA in the EU, Hong Kong's new categories will have a hard commencement date with no grandfathering [3]. Providers are being asked to contact the SFC proactively. An expedited process will be available for entities already licensed under VATP or regulated under the Securities and Futures Ordinance [2].
Penalties: up to seven years imprisonment and HK$5 million fine. The regime applies extraterritorially to overseas entities actively soliciting Hong Kong clients [3]. For companies navigating licensing requirements across multiple jurisdictions simultaneously, Hong Kong's hard commencement model stands in sharp contrast to the EU's extended transitional periods.
If your business touches virtual assets in Hong Kong, assess which of the six categories applies. This includes stablecoin payouts, on-ramp/off-ramp services, and custody. Early engagement with the SFC is not optional.
[1] Fireblocks. "Hong Kong's VATP Licensing: A Strategic Overview." February 2025. https://www.fireblocks.com/blog/hong-kong-virtual-asset-trading-platform-licensing-strategic-overview
[2] Sidley Austin. "Hong Kong Poised to Expand Licensing Regime." July 2025. https://www.sidley.com/en/insights/newsupdates/2025/07/hong-kong-poised-to-expand-licensing-regime-to-cover-virtual-asset-dealers-and-custodians
[3] Sidley Austin. "Hong Kong to Further Enhance Licensing Regime." January 2026. https://www.sidley.com/en/insights/newsupdates/2026/01/hong-kong-to-further-enhance-licensing-regime-for-virtual-assets-to-cover-advisors-and-managers
[4] CoinDesk. "Hong Kong Targets 2026 Legislation for VA Dealer and Custodian Rules." December 2025. https://www.coindesk.com/policy/2025/12/25/hong-kong-regulators-target-2026-legislation-for-virtual-asset-dealer-and-custodian-rules
Disclaimer: Stablecoin-related services are provided exclusively by Tazapay Canada Corp, a FINTRAC-registered Money Services Business. Tazapay Pte. Ltd. (Singapore) does not provide Digital Payment Token services under the Payment Services Act 2019.

For years, Canada's regulatory framework for cross-border payment companies was straightforward. Register as a Money Services Business with FINTRAC, build an AML compliance program, and you were covered. One federal registration, national scope, relatively light-touch compared to the US multi-state licensing grind.
That changed with the Retail Payment Activities Act.
The RPAA created a second layer of federal supervision. Payment service providers performing retail payment activities in Canada must now register with the Bank of Canada, in addition to their FINTRAC MSB registration [1].
The division of responsibility is specific. FINTRAC handles anti-money laundering and counter-terrorist financing: who is moving money, whether transactions are screened against sanctions lists, whether suspicious activity is reported. The Bank of Canada handles operational risk: how the PSP manages end-user funds, how it responds to cybersecurity incidents, whether it has adequate business continuity planning, and whether it reports breakdowns and incidents to the regulator [2].
These are genuinely different regimes. A company can be fully compliant with FINTRAC and still fail the Bank of Canada's RPAA requirements if it lacks a documented operational risk management framework or a fund safeguarding plan. Canada's dual registration is one of five major regulatory shifts happening simultaneously across global payment markets in 2026.
The RPAA applies to any individual or entity that meets all four criteria [3]: performs one or more payment functions not incidental to another service, performs those functions in connection with an electronic funds transfer in Canadian or foreign currencies, has a place of business in Canada regardless of where customers are, or is based outside Canada but directs payment services at Canadian end users.
In practice, this captures fintechs, payment processors, remittance companies, digital wallets, prepaid card programs, merchant acquirers, and most companies facilitating electronic fund transfers. Banks, credit unions, and securities firms are excluded.
For virtual asset businesses, the requirements layer further. You need FINTRAC MSB registration with the virtual currency permission, plus RPAA registration if you perform retail payment activities involving electronic funds transfers [4].
The Bank of Canada opened a 15-day registration window from November 1 to November 15, 2024. PSPs that submitted applications during that window could continue operating while the Bank reviewed applications. On September 8, 2025, the Bank published its PSP registry and began active supervision [5].
As of October 2025, Canada accounts for roughly 84% of all registered or in-review PSP entities, with international applicants from the US, UK, and other jurisdictions making up the rest [6].
PSPs that missed the window or that plan to start operating now must apply at least 60 days before commencing retail payment activities. Operating without registration after September 8, 2025 is a serious violation carrying fines up to $10 million CAD per violation and potential criminal liability for officers [7].
Beyond registration itself, every PSP must build and maintain three operational frameworks [2]:
Operational Risk Management. A written framework covering identification, assessment, mitigation, and monitoring of operational risks across all business lines, technology systems, and third-party relationships. This includes business continuity planning and periodic testing.
End-User Fund Safeguarding. If your PSP holds end-user funds at rest (not just in transit), you must implement a safeguarding framework. Methods include holding funds in trust, segregated accounts, or covered by a guarantee or insurance. The Bank of Canada expects legal opinions on safeguarding arrangements during periodic assessments [8].
Incident Response and Reporting. Documented procedures for detecting, responding to, and reporting operational incidents and breakdowns. Material changes to your business must be notified to the Bank before they take effect.
The first PSP annual report under the RPAA was due March 31, 2026, covering the previous calendar year [4].
If you operate in Canadian payments in any capacity, assess both regimes. The dual-registered MSB + RPAA entity is now the baseline for fintechs operating in Canada. Planning should account for the full compliance build: $100,000 to $200,000 CAD in Year 1 including legal, consulting, and internal staffing costs [7].
Companies already registered as FINTRAC MSBs should not assume they are covered. RPAA registration is a separate process with separate requirements, and FINTRAC compliance does not satisfy the Bank of Canada's operational risk expectations.
For a broader view of how Canada's dual registration fits into the global licensing landscape across five jurisdictions, including the US, EU, Hong Kong, and Singapore, see our complete licensing guide.
[1] Bank of Canada. "About Retail Payments Supervision Mandate." https://www.bankofcanada.ca/core-functions/retail-payments-supervision/about-retail-payments-supervision-mandate/
[2] Bank of Canada. "Supervisory Framework: Registration." https://www.bankofcanada.ca/core-functions/retail-payments-supervision/supervisory-framework-registration/
[3] ComplyFactor. "Retail Payment Activities Act (RPAA) Compliance Guide." January 2026. https://complyfactor.com/retail-payment-activities-act-rpaa-compliance-guide-complete-psp-registration-requirements-canada/
[4] 7Baas. "Canada 2025 MSB & PSP Rules: FINTRAC & RPAA Updates." November 2025. https://7baas.com/canada-2025-msb-psp-fintrac-rpaa-regulations/
[5] NCFA Canada. "Update on Retail Payments Supervision and PSP Registry." August 2025. https://ncfacanada.org/update-on-retail-payments-supervision-and-psp-registry/
[6] NCFA Canada. "Bank of Canada's PSP Registry Goes Live Under RPAA." October 2025. https://ncfacanada.org/bank-of-canadas-psp-registry-goes-live-under-rpaa/
[7] Canada-MSB. "RPAA Canada 2026: Bank of Canada Registration." May 2026. https://canada-msb.com/guide/rpaa/
[8] ComplyFactor. "RPAA Registration Guide." April 2026. https://complyfactor.com/rpaa-registration-guide/
Disclaimer: Stablecoin-related services are provided exclusively by Tazapay Canada Corp, a FINTRAC-registered Money Services Business. Tazapay Pte. Ltd. (Singapore) does not provide Digital Payment Token services under the Payment Services Act 2019.