#
The EEA operates a single, EEA-wide harmonised crypto-asset licensing regime under Regulation (EU) 2023/1114 (MiCA), which is a directly-applicable Regulation across the 27 EU Member States and, following incorporation into the EEA Agreement, across Iceland, Liechtenstein and Norway. A CASP authorisation granted by any one EEA competent authority passports across the entire bloc. The Article 143 grandfathering/transitional regime for pre-existing national VASP registrations formally expired on 1 July 2026 for EU Member States, with the EEA EFTA states (Iceland, Liechtenstein, Norway) running separate, shorter or longer national grandfathering windows (18 months for Iceland and Liechtenstein, 12 months for Norway) that were not perfectly synchronised with the EU timeline. Post-expiry, ESMA and NCAs are actively supervising wind-down of unauthorised providers.
What has changed, and what constitutes this cycle's lead development across the entire EEA baseline, is the expiry of the Article 143(3) transitional grandfathering period on 1 July 2026. That grandfathering period had permitted firms already providing crypto-asset services before MiCA's application date to continue operating while their licence applications were processed. With its EU-wide expiry, providers offering crypto-asset services to EEA clients without a MiCA licence are now in breach of EU law and must either cease services or wind down in an orderly manner. ESMA and national competent authorities have moved into active supervision of this wind-down, with ESMA publicly calling on unauthorised providers to exit the market. This is a shift from a phased-onboarding posture to an authorisation-or-exit enforcement posture, and it is the most consequential licensing-perimeter event to have occurred in the EEA baseline to date.
The EEA EFTA states are not moving in lockstep with the EU, nor with each other, on this transition. Iceland has set a national grandfathering period of eighteen months; Liechtenstein and Norway have each set twelve-month periods. These national timelines were communicated to ESMA but, at the time of this reporting cycle, were not yet fully incorporated into national law in all three states. The practical effect is that a provider operating across the EEA cannot treat the bloc as a single compliance clock: the EU-wide door closed on 1 July 2026, while Iceland's window runs longer than Liechtenstein's or Norway's, and none of the three EFTA timelines is synchronised with the EU's expiry date or with each other. This divergence is material enough that it has been flagged as a candidate for splitting the EEA jurisdiction record into EU and EFTA components in a future research pass, though that split has not been made this cycle.
A further consequence of the transition's completion is a tightened restriction on third-country access. Providers based outside the EEA are prohibited from providing MiCA-regulated services to, or soliciting, EEA clients, except under the narrowly-construed reverse-solicitation exemption, which applies only where the client acts at its own exclusive initiative. ESMA's post-transition statement reinforces this boundary explicitly, signalling that reverse solicitation is not being treated as a broad safe harbour but as a narrow, fact-specific exception.
Outlook
The near-term trajectory for EEA crypto licensing is active enforcement rather than further legislative change: the core MiCA authorisation framework is settled hard law, and the open questions concern implementation and compliance outcomes rather than the rules themselves. The most consequential unresolved item is visibility into actual post-expiry enforcement outcomes -- wind-down compliance rates and any EFTA-state-specific enforcement actions against unauthorised providers were only partially observable as of this cycle's retrieval date. Confirmation of full incorporation of the most recent MiCA Level 2 and Level 3 technical standards into the EEA Agreement for Iceland, Liechtenstein and Norway also remains outstanding beyond ESMA's reverse-solicitation compliance table. Continued divergence between EU and EFTA transitional timelines will likely keep this module at an amber traffic-light status until the EFTA states' national incorporation processes are confirmed complete and enforcement data from the EU-wide expiry becomes fuller.
Crypto Licensing
The end of MiCA's transitional and grandfathering period on 1 July 2026 requires crypto-asset service providers operating in or serving the EEA to hold full authorisation under Regulation (EU) 2023/1114. This is a categorical, in-force requirement applying to the entire CASP population rather than a subset, and it is corroborated at high confidence from ESMA, the bloc's primary crypto-markets supervisory authority. Before this date, CASPs already operating under national permissions in Member States could continue trading under grandfathered arrangements; from 1 July 2026 that grandfathering ends, and any CASP without full MiCA authorisation is operating outside the regulatory perimeter.
The practical significance of this milestone is structural rather than incremental: it converts MiCA from a framework with a live-but-partial population of authorised firms operating alongside grandfathered incumbents into a framework where authorisation is the sole lawful basis for CASP activity in the EEA. Market-level evidence of this shift has already appeared this cycle in the stablecoin space, where EU-regulated exchanges have begun restricting or delisting non-MiCA-authorised stablecoins for EEA users, indicating that the authorisation boundary is being actively enforced at the exchange layer.
One material gap remains open this cycle: the exact date on which MiCA is formally incorporated into the national law of the EEA/EFTA states, Iceland, Liechtenstein, and Norway, through the EEA Joint Committee process is unverified. This keeps this module's traffic-light assessment at amber rather than green despite the otherwise-settled EU-core position.
Outlook
Watch for confirmation of the EEA Joint Committee's MiCA incorporation date for Iceland, Liechtenstein, and Norway, the key gap in this cycle's licensing picture. Watch also for enforcement data on the practical effect of the transitional-period end, including any supervisory actions against CASPs found operating without full authorisation after 1 July 2026.
Sources and findings (4)
- T2 · European Securities and Markets AuthorityEuropean Securities and Markets Authority — Under Article 62(1) of MiCA, legal persons or other undertakings intending to provide crypto-asset services in the EEA must submit an application for authorisation as a crypto-asset service provider (CASP) to the competent authority of their home Member State.retrieved M5bindingin force
- T4 · CoinDeskCoinDesk — A MiCA CASP authorisation issued by one EEA competent authority permits the provision of crypto-asset services across the entire European Economic Area, comprising the 27 EU Member States plus Iceland, Liechtenstein and Norway.retrieved M4bindingin force
- T1 · European Securities and Markets AuthorityEuropean Securities and Markets Authority — The MiCA Article 143(3) grandfathering period officially expired across the EU on 1 July 2026; any entity providing crypto-asset services to EEA clients without a MiCA licence is now in breach of EU law and must cease offering such services or wind down in an orderly manner.retrieved M5bindingin force
- T1 · European Securities and Markets AuthorityEuropean Securities and Markets Authority — The EEA EFTA states applied their own national MiCA grandfathering periods distinct from the EU timeline: 18 months for Iceland and Liechtenstein and 12 months for Norway, with some of these periods communicated to ESMA but not yet fully incorporated into national law at the time of reporting.retrieved M4bindingin force