MiCA Deadline Leaves 1,062 EU Crypto Firms Unlicensed as Risk Splits Deepen

Daily Feed
MiCA Deadline Leaves 1,062 EU Crypto Firms Unlicensed as Risk Splits Deepen

MiCA’s July 1 deadline left 1, 062 EEA crypto firms without authorization, exposing how uneven Europe’s crypto licensing rollout still is: TRM Labs says only 281 of 1, 343 identified crypto service providers across the EEA had secured authorization by then.

  • 1, 062 firms missed the cutoff
  • Risk was concentrated in the unauthorized cohort
  • Authorization varied wildly by country
  • Offboarding may be the next compliance mess

The Markets in Crypto Assets Regulation (MiCAR) is the EU’s attempt to drag crypto out of the patchwork era and into one common licensing regime. For firms already operating before Dec. 30, 2024, Article 143(3) allowed a temporary grandfathering period. That runway ended on July 1.

Here’s the key distinction: TRM Labs is counting identified operating providers across the EEA, while the European Securities and Markets Authority, or ESMA, publishes a separate Interim MiCA Register: Overview and Implementation Details. Those numbers move at different speeds, cover different snapshots, and should not be mashed together like they mean the same thing. They don’t.

TRM’s July 1 dataset shows what happened when the transition period ran out: firms without MiCA authorization now have to either secure approval, restructure, wind down, or transfer customers to an authorized provider. AMLA, the EU’s Anti-Money Laundering Authority, has warned that compressed exits can strain anti-money laundering controls and make it harder to track where customers and funds move. In plain English: this is not just a licensing problem. It is a customer-migration problem with real compliance risk attached.

The headline number is rough, but the more useful question is who got through the gate and who didn’t. TRM says 12% of unauthorized firms carried a High or Severe risk rating, compared with 2% of authorized providers. Every firm assigned a Severe rating in TRM’s dataset sat in the unauthorized group.

That does not mean every unlicensed firm is a villain in a hoodie. It does mean the riskiest tail of the market was far more likely to be left outside the authorized perimeter. In crypto compliance, the tail often wags the dog.

TRM also found that the direct illicit exposure was still small for most firms in both groups. Unauthorized firms recorded 0.09% of outgoing volume directly involving illicit or high-risk counterparties, while licensed firms recorded 0.07%. That is a gap, but not some giant smoking crater that proves the whole market is rotten.

The bigger concern is concentration. A small subset of firms appears to carry much of the actual risk. TRM’s point is not that licensed providers are clean and unlicensed ones are dirty. It is that the unauthorized cohort is riskier on average, while most firms in both buckets barely touch illicit funds directly.

Direct sanctions exposure was more pronounced. TRM says unauthorized firms sent $5 billion directly to sanctioned counterparties, versus $1.7 billion for authorized firms. Unauthorized firms also sent $19 billion to high-risk exchanges and $15.3 billion to gambling services, compared with $14.2 billion and $13.4 billion respectively for authorized firms.

Those labels matter. In this context, sanctioned counterparties are entities subject to legal restrictions. High-risk exchanges and gambling services are counterparty categories TRM treats as elevated-risk because they can be linked to weak controls, sanction evasion, or other compliance headaches. “Direct” exposure here means TRM measured transactions involving those counterparties, not some broad accusation of criminal intent.

TRM identified 30 unauthorized providers with High or Severe risk ratings. It also found that unauthorized firms were more likely to be exchanges and payment firms: exchanges made up 42% of the unauthorized cohort versus 29% of the authorized group, while payment firms accounted for 16% versus 9%. TRM said the High-Risk Exchange category appeared only among firms that failed to gain authorization.

That lines up with a simple reality: the more customer flow, custody, and counterparty exposure a business handles, the more likely it is to trip regulatory alarms. Crypto loves to pretend compliance is a side quest. It is not.

The geography is just as revealing as the risk split. Before MiCA, TRM identified 383 operating firms under Lithuania’s old system and 241 in Poland. Poland’s official register had more than 1, 800 entries. Yet TRM found no MiCA authorizations there. Lithuania produced eight authorizations from a previous register of more than 400 providers.

Greece and Portugal also issued no home authorizations in TRM’s dataset. That is not a rounding error. That is a sign that Europe’s transition to MiCA is moving at very different speeds depending on where a firm started.

Germany, by contrast, looks like the adult in the room. TRM says BaFin authorized 55 of the 57 licensed providers operating in Germany. France and the Netherlands had 29 authorizations each, followed by Malta with 20, Cyprus with 19, and Italy with nine home authorizations despite 145 firms operating there. Spain hosted 34 licensed firms but authorized only 12.

The phrase home authorization means the approval a firm receives from its own supervisory base, which becomes the anchor for MiCA passporting. Once authorized, a firm can serve customers across the EU from that base, rather than chasing separate licenses in every market.

That passporting model is the whole point of MiCA for serious firms. It cuts friction, broadens market access, and gives compliant operators a cleaner way to scale. MiCA takes hold as EU crypto licensing hits 230 and smaller firms feel the squeeze, and Luxembourg authorization for B2C2 in May is a good example: it allowed regulated over-the-counter, or OTC, spot crypto trading across all 27 EU member states and three additional EEA markets.

That’s the carrot. One license, broad reach, less regulatory nonsense. If you are trying to build a real business instead of playing hide-and-seek with supervisors, that matters.

ESMA’s register helps show how quickly the authorization count was still shifting around the deadline. In May, the register contained 204 authorized CASPs, including 51 approved during the first five months of 2026. By July 3, it had expanded to 300 authorized crypto-asset service providers after 57 additional firms were added around the July 1 deadline, including Standard Chartered and FalconX.

Those counts are not contradictory. They are snapshots taken at different times, and ESMA says the interim register is updated at weekly intervals. If anything, the moving totals underline how messy the transition period was right up to the wire.

TRM also dug into a point that matters more than a lot of licensing vanity metrics: a jurisdiction issuing many authorizations does not automatically mean the firms under that supervisor are riskier, or safer, on the basis of counts alone. TRM found no identified correlation across 23 jurisdictions between the number of authorizations issued and the illicit exposure of firms supervised there.

That is a useful reality check. A busy regulator is not necessarily sloppy. A quiet regulator is not necessarily strict. Counting licenses is not the same thing as measuring risk.

Some jurisdictions are starting to look like licensing hubs. Malta, Cyprus, Ireland, and Luxembourg together accounted for 63 of 272 home authorizations identified by TRM, even though only 101 operating firms came from their previous registers. Whether that reflects efficient supervision, strategic business decisions, or firms shopping for the smoothest route to passporting is a fair question. Probably a bit of all three.

There is also a harder, less glamorous problem waiting in the wings: offboarding. If unauthorized firms have to exit, their customers do not magically vanish. They have to be moved, rechecked, or closed out. That is where AMLA’s warning becomes real. A compressed exit schedule can create blind spots around know-your-customer checks, sanctions screening, and source-of-funds verification.

There is a devil’s-advocate argument worth taking seriously. MiCA should improve market quality. It should also concentrate more activity inside a smaller number of authorized firms. That is good if it means stronger oversight and fewer cowboys. It is less great if it turns a handful of large operators into systemically important choke points. Centralization can be efficient. It can also become a future headache with better branding.

The cleanest reading of the data is simple. MiCA is doing what serious regulation is supposed to do: forcing the market to sort the operators from the pretenders. It is not making crypto pure. Nothing does. But it is making the European market harder for shameless garbage to survive in, and that is progress worth having.

Key takeaways

  • Why does the July 1 deadline matter?
    It ended the MiCA grandfathering window under Article 143(3), so firms without authorization could no longer rely on the temporary transition to keep serving covered crypto services.
  • Are unauthorized firms all bad actors?
    No. TRM says most firms in both groups showed little direct illicit exposure. The real problem is concentrated in a smaller, higher-risk subset.
  • Did authorization eliminate risk?
    No. Authorized firms still had measurable exposure, including $1.7 billion sent directly to sanctioned counterparties. Authorization reduces risk; it does not erase it.
  • Which countries moved fastest?
    Germany stood out, with BaFin authorizing 55 of 57 licensed providers operating there. Malta, Cyprus, Luxembourg, and Ireland also took a sizable share of home authorizations.
  • What’s the biggest practical headache now?
    Offboarding customers from unauthorized firms without losing control of AML and sanctions checks. That is where a lot of the real compliance pain will show up.

Further reading

A few useful references on MiCA, licensing, and the EU’s latest crypto compliance grind:

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog