TL;DR
MiCA is the world's first unified regulatory framework for digital assets, and the transitional clock has now run out. The final grandfathering deadline was July 1, 2026, and it has passed. Every entity providing crypto-asset services to EU customers must now hold MiCA authorization or stop, and this is no longer a future planning exercise; it is the operating reality.
For cross-border payment companies that use stablecoins in settlement flows, this determines which stablecoins you can use, which providers you can work with, and whether your EU payment flows are legal. This piece covers what the deadline actually changed, what authorization requires, and what payment companies should verify now. It is one of several parallel regulatory shifts across global payment markets reshaping compliance in 2026.
What the end of the transitional period changed
The deadline was not a soft target. On 23 June 2026, ahead of the cutoff, ESMA issued a public statement calling on unauthorized crypto-asset service providers to wind down their EU activities in an orderly manner while safeguarding client interests [1]. In practice, unauthorized providers were told to immediately stop onboarding new EU clients, cease marketing and solicitation, and limit activity to what is needed for clients to sell, transfer, reallocate, or close positions.
Three points matter most for payment companies. First, there is no informal grace period after July 1, and ESMA has signalled that enforcement is robust from day one [2]. Second, a pending application is not authorization: only a granted authorization under Article 63 permits continued service, and firms still waiting on an application do not have legal cover [3]. Third, and most relevant to cross-border flows, ESMA reminded providers established outside the EU that they cannot provide MiCA services to EU clients or solicit them, including in a business-to-business context, and that certain services such as custody cannot be outsourced to entities that are not authorized as CASPs [1].
What CASP authorization requires
A CASP license under MiCA covers ten enumerated services including custody, trading, exchange, transfer, advisory, and order execution for crypto-assets [4]. Authorization requires establishing a legal entity in an EU member state with genuine management presence, not a brass-plate subsidiary. Minimum capital is EUR 150,000 for most CASP categories. The applicant must submit a business plan, AML and KYC policies, a risk management framework, cybersecurity measures compliant with DORA, a governance structure, and financial statements, and management must pass fit-and-proper assessments [4].
Regulator review typically takes 60 to 90 business days from a complete application, and preparing from scratch runs roughly EUR 50,000 to EUR 120,000 in legal and compliance fees, on top of the capital requirement.
The passporting advantage
The single most valuable feature of MiCA authorization is passporting: one license from any EU member state covers all 27. A CASP authorized in Lithuania can serve customers in Germany, France, Spain, and every other EU country without additional applications [4]. This replaces the pre-MiCA world where operating in five EU markets meant five separate national registrations under five different regimes.
Where companies are getting licensed
Authorization has clustered in a handful of jurisdictions, and more than 40 CASP licenses have been issued so far, with the majority coming out of the Netherlands [5]. Germany attracts larger institutions seeking bank-grade regulatory optics; the Netherlands processed applications quickly and drew on and off-ramp specialists; Luxembourg hosts global exchanges; Malta has become home to several large platforms; and Lithuania is the cost-effective entry point for smaller fintechs transitioning from its existing regime.
The EMT and PSD2 overlap
From March 2026, custody and transfer services involving E-Money Tokens may require both MiCA authorization and a separate payment services license under PSD2, because EMTs are functionally electronic money [6]. This dual requirement can raise compliance costs for providers handling euro-denominated stablecoins, and has drawn industry criticism over its effect on euro stablecoin competitiveness.
Separately, Tether's USDT does not meet MiCA's EMT requirements and has been delisted from major EU exchanges, while USDC and EURC, issued by MiCA-compliant Circle, are the primary compliant options and are positioned to capture the European stablecoin market [2].
What this means for payment companies
If you process stablecoin payments involving EU customers, verify two things now. First, that any stablecoin you use is issued by a MiCA-authorized entity. Second, that every intermediary handling settlement in the chain is itself authorized as a CASP, because a provider still relying on a transitional arrangement no longer has legal cover. With the deadline behind us, the risk is no longer theoretical: an unauthorized provider in your settlement path is an illegal one, and the exposure flows to the businesses relying on it. The move from a compliance countdown to live enforcement is exactly why cross-border payment companies are consolidating stablecoin settlement onto providers whose authorization they can verify.
Sources
[1] Norton Rose Fulbright (Regulation Tomorrow). "ESMA public statement on end of MiCA transitional period." June 2026.
[2] Elliptic. "What the end of MiCA's transitional period means for crypto businesses." June 2026.
[3] ESMA. "Markets in Crypto-Assets Regulation (MiCA)." 2026.
[4] Skadden. "MiCA Update: Six Months in Application." 2025.
[5] Sumsub. "MiCA Regulation and EU Crypto Rules: What Changes in 2026." 2026.
[6] Cyfrin. "MiCA Regulation Explained." 2026.





