On 23 June 2026, the European Securities and Markets Authority issued a public statement on unauthorised crypto-asset service providers.1 The statement addresses the end of the transitional period under the Markets in Crypto-Assets Regulation on 1 July 2026.2 That date has now passed. CASPs operating under national grandfathering regimes without MiCA authorisation are, from 1 July, operating without a legal basis. ESMA acknowledges that significant providers servicing EU clients under national regimes may not be authorised by the deadline. Its response is not an extension. It is a wind-down instruction. Unauthorised CASPs must take immediate steps to exit EU activities in an orderly manner while safeguarding clients and market integrity. The expectation applies irrespective of whether a Member State has adjusted its national law to MiCA.3 The statement builds on ESMA's 17 April 2026 statement on the end of MiCA transitional periods and carries a direct consumer warning alongside the firm-facing commands.
The statement reduces to three obligations. First, an immediate freeze at the perimeter: unauthorised CASPs must “immediately stop onboarding new EU clients”, refrain from opening new relationships or accounts, and cease marketing and solicitation. Second, a service restriction that converts the business into an exit facility: services are limited to actions necessary to sell or transfer crypto-assets, reallocate assets or close positions, and “custody of clients' crypto-assets can only continue for the period strictly necessary to complete an orderly exit.” Third, a communication duty owed to retail and institutional clients alike: clear, prompt and repeated communication on asset safeguards and wind-down plans, including a stated deadline after which residual positions will be closed automatically. The auto-close deadline is the operationally demanding element, because it forces every unauthorised CASP to design, disclose and defend a forced-liquidation mechanism for clients who do not act.
AML/CFT does not wind down
Exit does not relax financial crime obligations. Effective AML/CFT controls must run through the entire wind-down: customer due diligence, transaction monitoring, screening against restrictive measures and sanctions lists, suspicious transaction and activity reporting, record-keeping, and compliance with transfer of funds and crypto-asset transfer traceability obligations.4 The logic is threat-driven: a closing venue processing concentrated outflows on a public deadline is an attractive laundering window, and ESMA has closed the argument that a departing firm owes a diminished standard. Where client books migrate, the receiving MiCA-authorised CASP must perform full onboarding, including its own customer due diligence and AML/CFT checks; no diligence travels with the client. Migration is therefore a re-papering event on both sides, and transferring CASPs should timetable for the receiving firm's onboarding capacity.
The third-country reminder and the custody outsourcing trap
ESMA reminds CASPs established outside the EU that they cannot provide MiCA services to EU clients or solicit them, and states expressly that this applies in a business-to-business context. The only surviving route is service strictly at the client's own exclusive initiative under the narrow reverse solicitation regime, on which ESMA has issued guidelines.5 The statement then adds the sentence with the longest structural reach: MiCA prohibits CASPs from outsourcing or delegating certain services, notably custody, to entities that are not authorised as CASPs. Read together, the two reminders dismantle the offshore sub-custody model. An authorised EU CASP cannot hold client assets through an unauthorised non-EU custodian, and a non-EU platform cannot recharacterise EU order flow as B2B infrastructure provision. Custody chains touching EU clients must now be authorised end to end.
The consumer warning and the enforcement posture
“ESMA reminds clients of unauthorised CASPs, whether EU or non-EU entities, that they do not benefit from MiCA safeguards, including protections for client assets” — ESMA Public Statement, 23 June 2026
Clients are invited to verify their provider's status in the ESMA Register and, where the provider is unauthorised, to act promptly by transferring crypto-assets to an authorised CASP or to a self-hosted wallet.6 The self-hosted wallet option is a concession to urgency: better client-controlled wallets than assets stranded on an unauthorised venue. On enforcement, ESMA and national competent authorities are directly engaged with the entities concerned and will coordinate to monitor whether significant unauthorised cross-border CASPs wind down without delay, working with the EBA and AMLA.7 Within the ESMA cooperation framework, NCAs may take coordinated action after the transitional period. The architecture is deliberate: a firm that delays cannot arbitrage between Member State regulators, because the response is designed to arrive from all of them at once.
What firms and clients should do now
Unauthorised CASPs still active in the EU should treat the statement as their compliance specification: freeze onboarding and marketing today, restrict services to exit transactions, publish the client communication plan with the automatic close-out deadline, and keep the AML/CFT stack fully operational to the last transfer. Firms with pending applications should engage their NCA on interim status, not assume tolerance. Authorised CASPs receiving migrating books should scale onboarding and due diligence capacity now, and audit their own outsourcing chains, particularly custody, for unauthorised links. EU clients of unauthorised platforms should verify status in the ESMA Register and move assets without waiting for the platform's deadline.
Notes
1. ESMA, Public Statement: ESMA calls on unauthorised crypto-asset service providers to wind down orderly, while also safeguarding clients' interests, as MiCA transitional period ends, 23 June 2026, ref. ESMA75-113276571-1710.
2. Under Article 143(3) of Regulation (EU) 2023/1114 (MiCA), providers operating under national law before 30 December 2024 could continue until 1 July 2026 or until authorisation was granted or refused, whichever came first; Member States could shorten the period. 1 July 2026 ends the longest available window.
3. The statement applies irrespective of whether the provisions of national law have been adjusted to MiCA in a Member State: an unadjusted national regime confers no continuing permission after the transitional period.
4. Traceability obligations arise under the recast Transfer of Funds Regulation (EU) 2023/1113, which extends payment-style originator and beneficiary information requirements to crypto-asset transfers.
5. ESMA Guidelines on reverse solicitation under MiCA confirm the exemption is narrow: service at the client's own exclusive initiative only; solicitation by any means, including via third parties or marketing new product types, defeats it.
6. The ESMA Register lists CASPs authorised under MiCA across all Member States and is the authoritative public verification source for provider status.
7. EBA is the European Banking Authority; AMLA is the EU Anti-Money Laundering Authority in Frankfurt, which will directly supervise selected high-risk crypto entities.
(Source: https://www.bank.lv/images/ESMA75-113276571-1710-Public-Statement.pdf)




