Cryptoassets Regulatory Intelligence cryptoassets.gi
EEA v13.3.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 1 failing29 sources retrieved model claude-sonnet-5 · 2026-08-05

European Economic Area (Bloc)

EEA schema crypto-v2.0.0 trajectory: not yet assessedregulatedoverlaps: FIM, WPM

Last updated · 8 categories · 31 sourced findings · 34 sources in the cumulative register

8Categoriesbaseline.
31Findings.claims[]
11Tier-1 sourcesrun_metadata.t1_source_count
Confidence mix (sums to 8 rendered categories; click to filter)
No categories moved this cycle.

Jurisdiction lead brief

Lead Signal

The defining development in the EEA crypto-regulatory environment this cycle is the expiry, on 1 July 2026, of the Article 143(3) transitional grandfathering period built into the Markets in Crypto-Assets Regulation. For firms operating across the twenty-seven EU Member States, the phased grace period that allowed crypto-asset service providers to continue operating without a MiCA authorisation while national competent authorities processed licence applications has now formally closed. ESMA has issued a public statement calling on unauthorised providers to cease services to EEA clients or wind down their business in an orderly manner, and national competent authorities, coordinated by ESMA and the European Banking Authority, are now in an active enforcement posture rather than a transitional one. This converts the EEA's crypto licensing perimeter from a phased onboarding exercise into a binary authorisation-or-exit regime: a CASP authorisation under Article 62(1) MiCA, once granted by any single Member State's competent authority, continues to passport across the full EEA, including Iceland, Liechtenstein and Norway, but firms without that authorisation no longer have any lawful basis for continued service provision to EEA clients. The practical corollary is a tightened restriction on third-country solicitation: providers based outside the EEA are now confined to the narrowly-construed reverse-solicitation exemption, available only where a client acts at its own exclusive initiative, reinforced explicitly in ESMA's post-transition statement. Layered onto the EU-wide expiry is a genuine timing divergence among the EEA EFTA states. Iceland has set an eighteen-month national grandfathering window, while Liechtenstein and Norway have each set twelve-month windows -- periods communicated to ESMA but not yet, at the time of this reporting cycle, fully incorporated into national law. That divergence means the EEA licensing perimeter is not moving as a single bloc: EU-domiciled unauthorised providers face an already-closed door, while EFTA-domiciled providers retain a residual, non-synchronised runway. This is this cycle's lead signal because it marks the transition from a mature-but-still-settling regime into one now subject to live enforcement scrutiny, with material consequences for market structure as unauthorised providers exit or restructure across the bloc.

8 of 8 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

The EEA operates a single, EEA-wide harmonised crypto-asset licensing regime under Regulation (EU) 2023/1114 (MiCA), which is a directly-applicable Regulation across the 27 EU Member States and, following incorporation into the EEA Agreement, across Iceland, Liechtenstein and Norway. A CASP authorisation granted by any one EEA competent authority passports across the entire bloc. The Article 143 grandfathering/transitional regime for pre-existing national VASP registrations formally expired on 1 July 2026 for EU Member States, with the EEA EFTA states (Iceland, Liechtenstein, Norway) running separate, shorter or longer national grandfathering windows (18 months for Iceland and Liechtenstein, 12 months for Norway) that were not perfectly synchronised with the EU timeline. Post-expiry, ESMA and NCAs are actively supervising wind-down of unauthorised providers.

Standing sub-brief627 words · last cycle 2026-08-25

Crypto Licensing

The EEA's crypto-asset service provider licensing perimeter is built on Article 62(1) of Regulation (EU) 2023/1114 (MiCA), which requires any legal person or undertaking intending to provide crypto-asset services in the EEA to submit an authorisation application to the competent authority of its home Member State before commencing service provision. Once granted by any single competent authority, that authorisation carries passporting effect across the entire EEA -- the twenty-seven EU Member States plus Iceland, Liechtenstein and Norway -- allowing an authorised CASP to provide services throughout the bloc without needing separate national licences. This single-authorisation, EEA-wide passporting architecture is the structural backbone of the regime and has not changed this cycle.

Periodic update · new data 2026-09-14

Crypto Licensing

The end of MiCA's transitional and grandfathering period on 1 July 2026 requires crypto-asset service providers operating in or serving the EEA to hold full authorisation under Regulation (EU) 2023/1114. This is a categorical, in-force requirement applying to the entire CASP population rather than a subset, and it is corroborated at high confidence from ESMA, the bloc's primary crypto-markets supervisory authority. Before this date, CASPs already operating under national permissions in Member States could continue trading under grandfathered arrangements; from 1 July 2026 that grandfathering ends, and any CASP without full MiCA authorisation is operating outside the regulatory perimeter.

The practical significance of this milestone is structural rather than incremental: it converts MiCA from a framework with a live-but-partial population of authorised firms operating alongside grandfathered incumbents into a framework where authorisation is the sole lawful basis for CASP activity in the EEA. Market-level evidence of this shift has already appeared this cycle in the stablecoin space, where EU-regulated exchanges have begun restricting or delisting non-MiCA-authorised stablecoins for EEA users, indicating that the authorisation boundary is being actively enforced at the exchange layer.

One material gap remains open this cycle: the exact date on which MiCA is formally incorporated into the national law of the EEA/EFTA states, Iceland, Liechtenstein, and Norway, through the EEA Joint Committee process is unverified. This keeps this module's traffic-light assessment at amber rather than green despite the otherwise-settled EU-core position.

Outlook

Watch for confirmation of the EEA Joint Committee's MiCA incorporation date for Iceland, Liechtenstein, and Norway, the key gap in this cycle's licensing picture. Watch also for enforcement data on the practical effect of the transitional-period end, including any supervisory actions against CASPs found operating without full authorisation after 1 July 2026.

Sources and findings (4)
  1. T2 · European Securities and Markets AuthorityEuropean Securities and Markets Authority — Under Article 62(1) of MiCA, legal persons or other undertakings intending to provide crypto-asset services in the EEA must submit an application for authorisation as a crypto-asset service provider (CASP) to the competent authority of their home Member State.retrieved M5bindingin force
  2. T4 · CoinDeskCoinDesk — A MiCA CASP authorisation issued by one EEA competent authority permits the provision of crypto-asset services across the entire European Economic Area, comprising the 27 EU Member States plus Iceland, Liechtenstein and Norway.retrieved M4bindingin force
  3. T1 · European Securities and Markets AuthorityEuropean Securities and Markets Authority — The MiCA Article 143(3) grandfathering period officially expired across the EU on 1 July 2026; any entity providing crypto-asset services to EEA clients without a MiCA licence is now in breach of EU law and must cease offering such services or wind down in an orderly manner.retrieved M5bindingin force
  4. T1 · European Securities and Markets AuthorityEuropean Securities and Markets Authority — The EEA EFTA states applied their own national MiCA grandfathering periods distinct from the EU timeline: 18 months for Iceland and Liechtenstein and 12 months for Norway, with some of these periods communicated to ESMA but not yet fully incorporated into national law at the time of reporting.retrieved M4bindingin force

#

MiCA establishes three principal harmonised crypto-asset categories for the EEA: asset-referenced tokens (ARTs), e-money tokens (EMTs), and 'other' crypto-assets (which include most utility tokens), each with its own authorisation and disclosure track. NFTs are generally out of scope unless fungible-like/part of a series or collection. ESMA has issued guidelines to delineate crypto-assets that separately qualify as MiFID II financial instruments (and hence fall outside MiCA's Title II regime), creating a boundary-classification exercise that NCAs and market participants must perform case-by-case.

Standing sub-brief390 words · last cycle 2026-08-25

Token Classification

The EEA's token classification taxonomy under MiCA remains settled and stable this cycle, with no material change to the underlying rules. Asset-referenced tokens (ARTs) must be authorised by their home Member State's competent authority before being offered to the public or admitted to trading, and issuers must be EEA-based legal persons or undertakings -- a gate that keeps ART issuance within the EEA's own regulatory perimeter. E-money tokens (EMTs) must be issued by a credit institution or an electronic money institution authorised under the Electronic Money Directive, with the EMT definition drawn broadly to capture any crypto-asset referencing a single fiat legal-tender currency, a design choice intended to prevent regulatory arbitrage around the electronic-money framework.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and findings (4)
  1. T2 · EUR-LexEUR-Lex — Issuers of asset-referenced tokens (ARTs) must be a legal person or certain undertaking based in the EEA and hold authorisation from their home Member State's competent authority before offering ARTs to the public or seeking admission to trading.retrieved M4bindingin force
  2. T2 · European Commission / EUR-LexEuropean Commission / EUR-Lex — To avoid regulatory arbitrage with the Electronic Money Directive, e-money tokens (EMTs) must be issued either by a credit institution or by an electronic money institution authorised under Directive 2009/110/EC, and the EMT definition is drawn broadly to capture all crypto-assets referencing a single fiat currency that is legal tender.retrieved M4bindingin force
  3. T2 · Joint European Supervisory Authorities (EBA, EIOPA, ESMA)Joint European Supervisory Authorities (EBA, EIOPA, ESMA) — Unique, non-fungible crypto-assets such as virtual real estate, domain names and authenticity-verification items are generally excluded from MiCA's scope, but NFTs issued as part of a large series or collection may still fall within scope.retrieved M3bindingin force
  4. T2 · European Securities and Markets AuthorityEuropean Securities and Markets Authority — ESMA has issued guidelines under Article 2(5) of MiCA on the conditions and criteria for qualifying a crypto-asset as a financial instrument under MiFID II, to delineate the boundary between MiCA's 'other crypto-assets' regime and MiFID II-regulated instruments.retrieved M3bindingin force

#

MiCA does not create a bespoke authorisation or licensing regime for underlying on-chain activities such as DeFi protocols, staking, mining or node/validator operation as such; it regulates issuers and intermediaries (CASPs) rather than protocols. EBA and ESMA's joint Article 142 MiCAR report (2025) found DeFi to remain a niche phenomenon in the EU/EEA and identified risks (ML/TF exposure, information asymmetries, procyclicality) without recommending new legislation. Where a regulated entity (e.g. a CASP or credit institution) engages with DeFi, existing frameworks such as DORA apply to that regulated entity's own ICT risk management, not to the DeFi protocol itself.

Standing sub-brief379 words · last cycle 2026-08-25

On-Chain Activity Regime

On-chain activity in the EEA remains a supervisory monitoring area rather than a licensing one. The EBA/ESMA joint Article 142 report describes EEA DeFi activity as still a niche phenomenon, with EEA DeFi total value locked at approximately four percent of global crypto-asset market value; EU adoption sits above the global average but below other developed economies. No new legislation is recommended in that report, and the analytical posture -- monitoring rather than binding rulemaking -- continues to characterise EBA and ESMA's approach to protocol-level activity. Consistent with that posture, EBA and ESMA jointly define staking as the process of immobilising crypto-assets to support Proof-of-Stake or PoS-like consensus mechanisms in exchange for validator privileges and block rewards -- a definitional factsheet rather than a binding rule, reflecting that staking itself remains outside any bespoke authorisation regime.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and findings (4)
  1. T2 · European Securities and Markets AuthorityEuropean Securities and Markets Authority — EBA and ESMA's 2025 joint report found that DeFi remains a niche phenomenon, with value locked in DeFi protocols representing only 4% of all crypto-asset market value globally, and that EU adoption, while above the global average, is lower than in other developed economies.retrieved M3non-binding
  2. T2 · European Banking Authority / European Securities and Markets AuthorityEuropean Banking Authority / European Securities and Markets Authority — EBA/ESMA define staking as the process of immobilising crypto-assets to support Proof-of-Stake (PoS) or PoS-like consensus mechanisms in exchange for the granting of validator privileges that can generate block rewards.retrieved M2non-binding
  3. T2 · European Securities and Markets AuthorityEuropean Securities and Markets Authority — Where regulated financial entities (credit institutions, CASPs, ART issuers) adopt or integrate DeFi activities, they may need to ensure compliance with operational resilience and ICT risk management requirements under DORA, even though DORA does not itself regulate the DeFi protocols.retrieved M3bindingin force
  4. T1 · Publications Office of the European Union / EUR-LexPublications Office of the European Union / EUR-Lex — No bespoke EEA-wide licensing or authorisation regime exists for crypto-asset mining, node operation, or validator activities as standalone activities under MiCA.retrieved M2non-bindinga fact about the regime

#

MiCA Titles III and IV impose a comprehensive EEA-wide stablecoin regime covering asset-referenced tokens (ARTs) and e-money tokens (EMTs): mandatory issuer authorisation, a segregated reserve of assets with minimum liquidity/composition rules, permanent holder redemption rights, disclosure/audit obligations, and an EBA-administered 'significance' designation triggering enhanced supervision for the largest ARTs/EMTs.

Standing sub-brief457 words · last cycle 2026-08-25

Stablecoin Regime

The EEA's stablecoin regime is the most comprehensively populated module in this baseline and remains fully in force with no material change this cycle. Issuers of both asset-referenced tokens (ARTs) and e-money tokens (EMTs) must hold authorisation from their home Member State's competent authority before offering such tokens to the public or seeking admission to trading anywhere in the EEA. ART issuers must maintain a reserve of assets covering liabilities to token holders at all times under Article 36 MiCA, together with own funds at least equal to the highest applicable regulatory minimum. EBA's regulatory technical standards operationalising Article 36(4) require reserve deposits held with credit institutions and referencing official currencies to be no lower than thirty percent of the referenced amount for standard ARTs and EMTs, rising to sixty percent for those designated significant, with minimum shares required to mature within one or five working days to ensure redemption liquidity is genuinely available rather than merely notional.

Periodic update · new data 2026-09-14

Stablecoin Regime

MiCA's stablecoin rules took full effect alongside the broader 1 July 2026 transitional-period end, and this cycle's evidence shows the regime is being actively enforced rather than operating as a formal baseline awaiting practical application. Several EU-regulated exchanges have restricted or delisted non-MiCA-authorised stablecoins, including USDT, for EEA users following the transitional-period end, a market-level enforcement consequence flowing directly from the authorisation requirement.

Underpinning this enforcement activity is a standing structural safeguard: reserves backing authorised e-money-token and asset-referenced-token issuance must be bankruptcy-remote and held with qualifying custodians, per MiCA and its accompanying ESMA technical standards. This reserve-segregation requirement is designed to insulate token holders from issuer insolvency risk, and its continued operation alongside active delisting enforcement indicates that both the authorisation gate and the underlying prudential safeguards are functioning together. The reserve-requirement claim traces to a Tier 4 secondary tracker rather than a primary ESMA technical-standard publication, a sourcing gap worth flagging.

The overall trajectory for the stablecoin regime this cycle is tightening: enforcement is visibly active, the population of exchanges willing to carry non-compliant stablecoins for EEA users is shrinking, and the reserve-segregation architecture continues to apply without exception to authorised issuers.

Outlook

Watch for further exchange-level delisting activity as the transitional-period end continues to work through the market, and for any supervisory enforcement action taken directly against stablecoin issuers rather than only against the exchange layer. Watch also for primary-source ESMA confirmation of the reserve-custody technical standards currently evidenced only through secondary trackers this cycle.

Sources and findings (6)
  1. T1 · European Banking AuthorityEuropean Banking Authority — Issuers of asset-referenced tokens and e-money tokens are required to hold the relevant authorisation from their home Member State's competent authority before offering such tokens to the public or seeking admission to trading in the EEA.retrieved M5bindingin force
  2. T2 · EUR-LexEUR-Lex — Under Article 36 of MiCA, issuers of asset-referenced tokens must maintain at all times a reserve of assets covering liabilities to token holders and hold own funds at least equal to the highest of the applicable regulatory minimums.retrieved M5bindingin force
  3. T2 · European Banking AuthorityEuropean Banking Authority — EBA regulatory technical standards under Article 36(4) of MiCAR require deposits with credit institutions in the reserve of assets referencing official currencies to be no lower than 30% (or 60% for significant ARTs/EMTs) of the amount referenced, with minimum percentages of the reserve maturing within 1 or 5 working days to ensure redemption liquidity.retrieved M4bindingin force
  4. T1 · European Securities and Markets AuthorityEuropean Securities and Markets Authority — Holders of asset-referenced tokens have a permanent right of redemption at all times against the issuer, redeemable either in funds equivalent to the market value of the referenced assets or by delivery of the referenced assets, while e-money token issuers must redeem tokens at par value upon a holder's request at any moment.retrieved M5bindingin force
  5. T1 · Publications Office of the European Union / EUR-LexPublications Office of the European Union / EUR-Lex — Issuers of asset-referenced tokens must publicly disclose the amount of tokens in circulation and the value and composition of the reserve of assets, and must publish a summary and the full audit report on the reserve of assets on their website.retrieved M4bindingin force
  6. T2 · European Banking AuthorityEuropean Banking Authority — EBA classifies an ART or EMT as 'significant' if at least three quantitative/qualitative criteria under Article 43(1) MiCAR are met, including more than 10 million holders, token value/market capitalisation or reserve size above EUR 5 billion, or average daily transactions above 2.5 million transactions and EUR 500 million, triggering EBA's direct supervisory role.retrieved M4bindingin force

#

MiCA provides EEA-wide harmonised consumer protections for crypto-asset holders and CASP clients — mandatory white papers, marketing-communication conduct rules, suitability requirements for advice/portfolio management, custody segregation, and complaint handling — but the Joint ESAs have repeatedly warned that these protections are narrower than those for traditional financial products, notably the absence of any investor-compensation scheme equivalent.

Standing sub-brief412 words · last cycle 2026-08-25

Consumer Protection

Binding consumer protection obligations under MiCA are in force across the EEA and were not materially altered this cycle, though the trajectory here is best described as stable-but-flagged rather than simply settled. CASPs must not deliberately or negligently mislead clients about the advantages of crypto-assets, must warn clients of the risks involved, and must prominently publish pricing, cost and fee policies and climate or environmental impact information on their websites -- disclosure duties intended to give retail clients a baseline of information before engaging with a CASP's services. Where a CASP provides advice on crypto-assets or portfolio management of crypto-assets, ESMA's suitability guidelines require the CASP to give suitable recommendations or make suitable investment decisions for clients, aligned with the pre-existing MiFID II suitability framework rather than inventing a separate crypto-specific standard.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and findings (5)
  1. T2 · EUR-LexEUR-Lex — CASPs must not deliberately or negligently mislead clients about the real or perceived advantages of crypto-assets, must warn them of the risks involved, and must make pricing, cost/fee policies and the climate/environmental impact of each crypto-asset prominently available on their website.retrieved M4bindingin force
  2. T2 · Joint European Supervisory Authorities (EBA, EIOPA, ESMA)Joint European Supervisory Authorities (EBA, EIOPA, ESMA) — The Joint ESAs warn that MiCA provides some consumer protection for specific crypto-assets and services (e.g. comprehensive information, transparent complaint-handling), but these protections are not as extensive as those for traditional financial products, and consumers do not benefit from an equivalent to investor-compensation schemes.retrieved M4bindingin force
  3. T2 · European Securities and Markets AuthorityEuropean Securities and Markets Authority — ESMA Guidelines on suitability require CASPs providing advice on crypto-assets or portfolio management of crypto-assets to give suitable recommendations or make suitable investment decisions for clients, aligned with MiFID II requirements so that dual-regulated firms face similar standards.retrieved M4bindingin force
  4. T1 · European Securities and Markets AuthorityEuropean Securities and Markets Authority — MiCA prohibits CASPs from outsourcing or delegating certain services, notably custody, to entities that are not themselves authorised as CASPs.retrieved M4bindingin force
  5. T1 · Publications Office of the European Union / EUR-LexPublications Office of the European Union / EUR-Lex — Issuers of asset-referenced tokens and CASPs must establish and maintain effective and transparent procedures for the prompt, fair and consistent handling of complaints received from token holders and other interested parties, including consumer associations.retrieved M3bindingin force

#

Direct taxation (income tax, capital gains) of crypto-assets remains a national Member State (and, separately, national EFTA-state) competence not harmonised at EEA level. The EU has, however, harmonised cross-border tax-information reporting via DAC8 (Council Directive (EU) 2023/2226), which extends automatic exchange of information to crypto-asset service providers from 1 January 2026. Separately, the CJEU's Hedqvist ruling (Case C-264/14) held that exchange of bitcoin for traditional currency is VAT-exempt under the EU VAT Directive (2006/112/EC) as a currency transaction — but the EU VAT Directive itself is outside the scope of the EEA Agreement, so Norway, Iceland and Liechtenstein apply their own distinct national VAT/consumption-tax regimes not bound by this EU case law.

Standing sub-brief442 words · last cycle 2026-08-25

Tax Treatment

Tax treatment is this cycle's other genuinely material-change module, driven by the correction of a previously misstated DAC8 timeline. Council Directive (EU) 2023/2226 (DAC8) extends the EU's administrative tax-cooperation framework to crypto-assets, requiring crypto-asset service providers to collect and report detailed user and transaction information to national tax authorities, who then share that data across EU Member States. Data-collection and due-diligence obligations under DAC8 began on 1 January 2026. However, this cycle corrects an earlier conflation of that data-collection start date with the date of the first actual cross-border exchange of the collected information: national tax authorities share collected information with EU counterparts within nine months of the end of the relevant calendar year, meaning the first cross-border exchange, covering the 2026 reporting year, is due by 30 September 2027, not from 1 January 2026 as previously reported. This is a compliance-deadline-versus-commencement-date distinction with real practical significance -- CASPs' reporting obligations to national authorities began in January 2026, but the resulting cross-border information-sharing among tax administrations will not actually occur until more than a year and a half later.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and findings (4)
  1. T4 · CoinDeskCoinDesk — DAC8 extends the EU's administrative cooperation framework on taxation to crypto assets, requiring crypto-asset service providers to collect and report detailed information on users and transactions to national tax authorities, who then share the data across EU Member States.retrieved M5bindingin force
  2. T1 · EUR-LexEUR-Lex — Under Amending Directive (EU) 2023/2226, crypto-asset service providers must comply with detailed reporting and due diligence obligations, and national authorities automatically share the information received from service providers with EU counterparts within 9 months of the end of the calendar year, with the first exchange taking place from 1 January 2026.retrieved M4bindingin force
  3. T1 · Court of Justice of the European UnionCourt of Justice of the European Union — The CJEU held in Skatteverket v Hedqvist (Case C-264/14) that transactions exchanging bitcoin for traditional currency for consideration constitute a VAT-exempt currency transaction under Article 135(1)(e) of the EU VAT Directive (2006/112/EC); this ruling binds EU Member States but the EU VAT Directive itself is not incorporated into the EEA Agreement and therefore does not directly bind Norway, Iceland or Liechtenstein.retrieved M4bindingin force
  4. T1 · EUR-LexEUR-Lex — Substantive taxation of crypto-asset capital gains and income remains within the exclusive competence of individual EU Member States and, separately, of the EEA EFTA states, and is not harmonised at EEA level by MiCA or DAC8, which address only cross-border information exchange.retrieved M3non-bindinga fact about the regime

#

Regulation (EU) 2023/1113 (the recast Transfer of Funds Regulation, or crypto 'Travel Rule') requires full originator and beneficiary information to accompany every crypto-asset transfer within, into, or out of the EEA involving a CASP, with no de-minimis threshold (unlike the €1,000 threshold applicable to certain fiat transfers). CASPs must additionally verify ownership/control of self-hosted wallets for transfers over €1,000, and third-country (non-EEA) providers cannot solicit or serve EEA clients outside a narrowly-construed reverse-solicitation exemption.

Standing sub-brief367 words · last cycle 2026-08-25

Cross-Border Transfer

The EEA's cross-border transfer regime for crypto-assets, built on Regulation (EU) 2023/1113, remains fully in force and stable this cycle, with no material change to its core obligations. CASPs must obtain, hold and share originator and beneficiary information for crypto-asset transfers, extending the pre-existing fiat-transfer 'travel rule' into the crypto-asset space with no de-minimis threshold -- meaning the information-accompaniment obligation applies to transfers of any value rather than only to transfers above a minimum size, a notably stricter design choice than found in some non-EEA travel-rule regimes. Beneficiary CASPs must additionally verify, for transfers to self-hosted addresses over EUR 1,000, whether the beneficiary owns or controls that address before making the crypto-assets available to them, adding a control-verification step specifically for transfers outside the CASP-to-CASP channel. CASPs must retain records of originator and beneficiary transfer information for five years, a period that individual Member States may extend by a further five years, giving supervisors and law enforcement a substantial retrospective evidentiary window.

Periodic update · new data 2026-09-14

Cross-Border Transfer

A sectoral ban on transactions with Russian and Belarusian crypto-asset service providers and decentralised crypto platforms takes effect from 24 May 2026 under the EU's 20th sanctions package. This development is noted here for cross-border-transfer disambiguation purposes: the effective date has now passed relative to this cycle's observation date, meaning EEA-serving crypto-asset service providers should treat the ban as an in-force obligation rather than a forthcoming one. The full anti-money-laundering and sanctions-architecture analysis of this development is owned by the financial-integrity consumer under its D1 and D5 domains; this brief limits itself to the crypto cross-border-transfer nexus rather than duplicating that analysis.

One open interpretive question flagged this cycle is whether the sanctions package's provisions targeting decentralised platforms are enforceable against protocols that lack a clear EU establishment, a structural ambiguity inherent to applying entity-based sanctions architecture to non-custodial, decentralised infrastructure. This cycle's evidence does not resolve that question, and it remains a live gap for cross-border-transfer compliance planning.

Outlook

Watch for regulatory or judicial clarification on the enforceability of sanctions provisions against decentralised platforms lacking EU establishment, and for the practical compliance response of EEA-serving crypto-asset service providers now that the 24 May 2026 effective date has passed.

Sources and findings (4)
  1. T1 · Publications Office of the European Union / EUR-LexPublications Office of the European Union / EUR-Lex — Under Regulation (EU) 2023/1113, crypto-asset service providers must obtain, hold and share originator and beneficiary information with their transfer counterparts and make it available to competent authorities on request, extending the fiat-transfer 'travel rule' to crypto-asset transfers.retrieved M5bindingin force
  2. T2 · EUR-LexEUR-Lex — For transfers over €1,000 from a self-hosted address, the beneficiary CASP must assess whether the beneficiary owns or controls that address before making the crypto-assets available.retrieved M4bindingin force
  3. T1 · Publications Office of the European Union / EUR-LexPublications Office of the European Union / EUR-Lex — Crypto-asset service providers must retain records of originator/beneficiary transfer information for a period of five years, with an option for Member States to extend this to a further five years.retrieved M3bindingin force
  4. T1 · European Securities and Markets AuthorityEuropean Securities and Markets Authority — CASPs established outside the EEA cannot provide MiCA-regulated services to EEA clients or solicit them, in a business-to-business or business-to-consumer context, except where services are strictly provided at the client's own exclusive initiative under the narrowly-construed reverse solicitation regime.retrieved M4bindingin force

#

Crypto subscribes to the FIM consumer's aml_ctf baseline module for substantive AML/CFT obligations. This crypto DR baseline therefore does not duplicate KYC/CDD, SAR/STR, sanctions-screening or record-keeping claims here; those are administered under the FIM aml_ctf module, which covers Regulation (EU) 2023/1113 (crypto Travel Rule) and Directive (EU) 2015/849 (AMLD) as they apply to CASPs. This module is emitted as a shell for schema completeness only.

Absence reason not determinableNo sub-brief exists and the JID records no gap or review marker explaining why. The renderer will not invent a reason.

no periodic updates on record for this sub-brief

No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

Blocking. 1 failing check(s).

schema_validpass
min_quoted_text_presentwaived — floor 0%
egress_verifiedpass
every_practical_object_has_source_idn/a — no subject in this jurisdiction
source_tier_integrity_okFAIL
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct89.66
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for European Economic Area (Bloc)
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: module cards load OPEN; standing positions render in full; sub-briefs and jurisdiction briefs load as a clamped teaser with an explicit “read full” control carrying the true word count; earlier updates stay collapsed behind a counted summary. No text is hidden without disclosing how much of it there is.

Sentinel-fed modules receive no special rendering treatment. sentinel_feed is an attribution chip only: it does not suppress content, does not generate an absence reason code, and does not exclude the module from any count, filter, search index or export on this page.

Family taxonomy is renderer-level presentation config, not a JID field. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; per-module RAG traffic light; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-09-27. A year-precision row is never promoted into a tighter band.

Orphan deltas: 0 cycle_delta row(s) target non-module objects and are listed in the rail rather than attached to a card.

Envelope: baseline resolved at jurisdiction_json.baseline; 8 module(s), 31 finding(s), 34 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.