Go to app

Regulatory Requirements and Timelines

Published 7/8/2026, 7:48:20 PM

As of July 2026, the European Securities and Markets Authority (ESMA) has fully implemented the Markets in Crypto-Assets (MiCA) custody framework, creating a significant "compliance squeeze" for smaller providers. The transition from a legislative proposal to a strict enforcement regime has introduced high fixed capital requirements and complex technical mandates that disproportionately burden firms with smaller balance sheets.

Regulatory Requirements and Timelines

The transitional "grandfathering" period for most EU member states concluded on July 1, 2026. All Crypto-Asset Service Providers (CASPs) must now hold a full MiCA authorization to operate within the EU [Source: https://www.esma.europa.eu/systems-resources/standard-documents/regulatory-technical-standards-rts-casp-capital-requirements].

Requirement CategoryKey Mandates
Capital FloorsMinimum €125,000 base capital + 25% of preceding year's fixed overheads.
SafekeepingMandatory asset segregation (separate wallet addresses for clients vs. CASP assets).
Technical StandardsStandardized JSON schema for order books and iXBRL for white papers.
LiabilityCASPs are liable for "attributable" incidents (e.g., hacks) unless using permissionless DLT they don't control.

The "Squeeze" on Smaller Providers

The regulatory framework imposes fixed costs that do not scale with revenue, creating a high barrier to entry and survival for startups:

Advantages for Large Providers

Larger, established custody providers are better positioned to capture market share due to:

  • Economies of Scale: Large CASPs can more easily absorb the high fixed costs of compliance and maintain dedicated legal and technical teams.
  • EU Passporting: A single MiCA license allows large firms to operate across all 27 EU member states, providing a competitive edge over smaller firms that previously operated under single-country registrations.
  • Liability Management: Some larger firms have been observed using "lowly financed subsidiaries" to isolate the liability risks associated with custody services.

Current Enforcement Posture

ESMA’s June 2026 enforcement statement mandates that any entity without a license must cease new client onboarding immediately. National Competent Authorities in France, Austria, and Italy are currently advocating for even stricter measures, including direct ESMA supervision for "significant" CASPs and mandatory pre-authorization cybersecurity audits.

In summary, while MiCA provides a clear legal framework for the EU, the high capital floors and technical reporting standards have effectively squeezed smaller providers, favoring larger entities capable of managing the significant fixed costs of compliance. The market is currently trending toward consolidation as the July 1, 2026, deadline has passed.