What Is the MiCA Regulation? The EU Crypto Rulebook Explained (2026)

The Markets in Crypto-Assets Regulation, known as MiCA, is the European Union's landmark framework for regulating crypto. Formally Regulation (EU) 2023/1114, it replaced a patchwork of national rules with a single set of pan-EU obligations for the firms that issue crypto-assets and the platforms that trade, exchange, and hold them. MiCA is now fully in force, and its transitional period for existing crypto businesses ended on 1 July 2026, so any provider serving EU clients must now hold a MiCA authorization or stop.
With roughly 31 million Europeans holding crypto, MiCA reaches a large market and sets a global benchmark other jurisdictions are watching. This guide explains what MiCA is, who it applies to, the token categories and license classes it creates, the key dates, who enforces it, the penalties for non-compliance, and, crucially, the anti-money-laundering obligations MiCA does not cover but that every crypto firm must still meet.
What Is MiCA and What Does It Aim to Do?

MiCA establishes uniform rules for crypto-assets that were not already covered by existing EU financial services law. Before it, a crypto firm faced 27 different national regimes; under MiCA, a single authorization can passport across the entire European Economic Area. The regulation was built around four core objectives:
Consumer and investor protection: clear disclosures, mandatory white papers, and rules against misleading marketing.
Market integrity: prohibitions on insider dealing, unlawful disclosure, and market manipulation in crypto-assets.
Financial stability: strict reserve, capital, and redemption rules for stablecoins that could reach systemic scale.
Legal certainty: a single, harmonized rulebook that lets authorized firms operate across all EU member states.
Who MiCA Applies To (and Who Is Excluded)

MiCA applies to any person or firm that issues crypto-assets or provides crypto-asset services to clients in the EU. In practice, that captures four
broad groups of actors:
Crypto-asset service providers (CASPs): exchanges, custodians, brokers, and trading platforms.
Issuers of asset-referenced tokens (ARTs): stablecoins backed by a basket of assets or currencies.
Issuers of e-money tokens (EMTs): stablecoins pegged to a single fiat currency.
Offerors and those seeking admission to trading: anyone offering a crypto-asset to the public in the EU.
Just as important is what MiCA leaves out. The regulation does not apply to crypto-assets that already qualify as financial instruments under MiFID II, nor to central bank digital currencies, deposits, or insurance products. Non-fungible tokens are excluded unless they are issued in a large fungible series, and fully decentralized finance without any intermediary currently sits outside the framework.
The Three Token Categories Under MiCA

MiCA does not treat all crypto-assets the same way. It sorts them into three categories, each with its own disclosure, authorization, and reserve requirements, with the heaviest rules reserved for the stablecoins most likely to be used for payments:
Category | Definition | Issuer eligibility | Key requirement |
|---|---|---|---|
Asset-referenced token (ART) | Stablecoin referencing a basket of assets, currencies, or crypto. | Authorized legal entity or credit institution | Own funds from EUR 350,000; full reserve backing; redeemable on demand |
E-money token (EMT) | Stablecoin pegged to a single fiat currency. | Authorized credit or e-money institution | Issued and redeemed at par; e-money rules apply |
Other crypto-assets | Utility tokens and most other crypto not caught above. | Any offeror or admission-seeker | White paper and marketing rules; lighter regime |
Small offerings are treated proportionately: an offer of other crypto-assets below EUR 1 million over 12 months is exempt from the full white-paper regime. Stablecoins that grow large enough to be labeled significant face extra requirements and direct supervision by the European Banking Authority.
CASP Authorization and Capital Classes

To operate legally, a crypto-asset service provider must be authorized by a national regulator and meet minimum capital, governance, and security requirements. MiCA defines ten crypto-asset services and groups them
into three capital classes based on the risk each carries:
Class and minimum capital | Amount | Services covered |
|---|---|---|
Class 1 | EUR 50,000 | Reception and transmission of orders, execution, placing, advice, and portfolio management |
Class 2 | EUR 125,000 | Exchange of crypto for funds or other crypto, and custody and administration |
Class 3 | EUR 150,000 | Operating a crypto-asset trading platform |
In every case a CASP must also hold own funds of at least one quarter of its fixed annual overheads, appoint fit-and-proper management, and submit governance, security, complaint-handling, and conflict-of-interest policies as part of its application. There is no third-country passport, so non-EU firms generally need an EU-authorized entity to serve EU clients.
MiCA Key Dates and Timeline

MiCA rolled out in phases, and it does not stand alone: a cluster of companion regulations took effect around it. The timeline below shows the milestones that matter most for compliance teams:
Date | Milestone |
|---|---|
June 2023 | MiCA enters into force as Regulation (EU) 2023/1114 |
30 June 2024 | Rules for ART and EMT stablecoin issuers begin to apply |
30 December 2024 | Full framework for CASPs applies; the Travel Rule (TFR) applies in parallel |
17 January 2025 | DORA applies, adding ICT and operational-resilience obligations |
23 December 2025 | Machine-readable iXBRL white-paper format enters into application |
1 January 2026 | CARF reporting under DAC8 takes effect for crypto tax transparency |
1 July 2026 | Transition period ends; all EU CASPs must be authorized or cease services |
10 July 2027 | AMLR applies and the new EU authority AMLA takes on AML supervision |
Who Enforces MiCA
MiCA is supervised through a layered structure that splits responsibility between EU-level authorities and national regulators. Knowing which body oversees what helps firms direct applications and manage supervision:
National competent authorities (NCAs): license and supervise most CASPs and issuers in their member state.
ESMA: coordinates supervision, maintains the interim MiCA register, and keeps a public list of non-compliant firms.
European Banking Authority (EBA): directly supervises stablecoin issuers whose tokens are classed as significant.
ECB and AMLA: the ECB advises on monetary-stability risks, while AMLA will lead AML supervision from 2027.
Thresholds decide where oversight sits. A CASP with 15 million or more active annual users in the EU counts as significant, and a stablecoin can be deemed significant when its issuer is a large gatekeeper or its usage crosses set limits, pulling it under EBA supervision.
Penalties for Non-Compliance

MiCA gives regulators real teeth, and the numbers are deliberately large enough to deter non-compliance by even the biggest firms. Member states set administrative penalties within EU-wide minimums, and the ceilings scale with turnover:
CASPs: fines of at least EUR 5 million for legal entities, or up to a set percentage of total annual turnover, whichever is higher.
Individuals: fines of at least EUR 700,000 for the people responsible for a breach.
Stablecoin issuers: even higher turnover-based ceilings apply to ART and EMT issuers given their systemic importance.
Disgorgement: regulators can also impose fines of up to twice the profit gained or loss avoided through the infringement.
Enforcement is already underway. Since the transition period ended, ESMA has made clear that providing crypto-asset services in the EU without a MiCA license breaches EU law, and national regulators have moved to withdraw or refuse authorizations and require orderly wind-down of non-compliant firms.
The Critical Gap: MiCA Is Not an AML Regime

One of the most common and most costly misunderstandings about MiCA is the assumption that a MiCA license makes a firm compliant. It does not. MiCA itself imposes no anti-money-laundering, counter-terrorist-financing, or Travel Rule obligations. Those live in a separate stack of EU rules that apply to crypto firms in parallel, and a CASP must satisfy both. The companion regulations every crypto business needs to plan for are:
Regulation | Applies | What it requires |
|---|---|---|
TFR (Travel Rule) | 30 Dec 2024 | Collecting and transmitting originator and beneficiary data on crypto transfers, regardless of amount |
DORA | 17 Jan 2025 | ICT risk management, incident reporting, and oversight of third-party technology providers |
DAC8 / CARF | 1 Jan 2026 | Reporting of crypto transactions to tax authorities for cross-border transparency |
AMLR and AMLA | 10 July 2027 | Harmonized AML/CFT rules, including customer due diligence and monitoring, under a new EU supervisor |
In other words, MiCA governs authorization and conduct, while the AML and Travel Rule frameworks govern financial-crime controls. A crypto firm that builds one without the other is not compliant.
What a Crypto Firm Must Build to Comply
Meeting MiCA authorization and its companion AML obligations means putting a genuine compliance stack in place, not just filing paperwork. For most crypto-asset service providers, that stack includes several connected controls:
Identity verification at onboarding. KYC-grade identity verification and customer due diligence confirm who every client is before the first transaction, with enhanced due diligence for higher-risk cases.
Sanctions, PEP, and adverse-media screening. Ongoing AML screening against sanctions lists, politically exposed person data, and adverse media keeps prohibited users out.
Ongoing transaction monitoring. Real-time transaction monitoring detects money laundering patterns and triggers a suspicious transaction report when needed.
Travel Rule data exchange. Systems that capture and transmit originator and beneficiary information on every crypto transfer.
Governance and record-keeping. Fit-and-proper management, audit trails, and the data retention regulators expect during supervision.
These are exactly the controls MiCA authorization files and AML supervisors look for, and the ones the incoming AMLR will make even more demanding.
Meet MiCA and AML Requirements with Qoobiss
Qoobiss gives crypto-asset service providers the identity and compliance layer MiCA authorization and EU AML rules require. The crypto compliance platform combines KYC verification, AML screening, and transaction monitoring in one place, while Omnicheck unifies screening and monitoring for ongoing supervision. See how Qoobiss helps crypto firms onboard faster and stay compliant, or get in touch to see it in action.
Frequently Asked Questions
What is the MiCA regulation?
When did MiCA come into effect?
Who does MiCA apply to?
Does MiCA cover stablecoins?
Does MiCA include AML requirements?
What happens now that the July 2026 transition has ended?









