MiCA has moved beyond transition
The commercial and legal conversation around Markets in Crypto-Assets (MiCA) has changed. For firms entering the EU market, the relevant questions are now how to establish a genuinely governable EU CASP, how to prepare an authorization file that reflects operational reality, and how to maintain the authorized model once the business starts changing. The end of the general transition window that could run to 1 July 2026 makes it particularly important not to design a 2026 strategy around legacy assumptions.
Start with the service and entity map
Before drafting policies, counsel needs to understand the services, customer and transaction flows, legal entities, custody arrangements, outsourced functions and group dependencies. A product label is not a legal classification. The assessment must identify what is actually done, by whom, from where, and with what degree of control.
Substance is an operating question
An EU entity cannot be treated as a filing shell while essential decisions, information and operational capability sit elsewhere. Governance, management capacity, staffing, information access and the ability to oversee outsourced or group functions need to be credible in practice. The authorization narrative must match the organization that will exist after approval.
The file should work as an evidence system
A mature application links governance, controls, outsourcing, ICT, continuity, custody where relevant, records and management approvals. Policies matter, but they are persuasive only when the organization can show owners, procedures, contracts, system records and evidence that the controls can operate.
Authorization is not the end point
Material changes in services, providers, governance or technology can alter the risk and regulatory picture after authorization. CASPs also need to align the MiCA operating model with DORA where applicable. A post-authorization framework should therefore include change-control, outsourcing review, evidence maintenance and a disciplined response process for supervisory questions.
A sensible engagement sequence
The right starting point is a paid legal and regulatory assessment of the business model, jurisdiction and existing material. Only after that review should the scope of a full authorization, remediation or ongoing compliance mandate be fixed. OIKONOMAKIS LAW performs the legal and regulatory workstream; F SOCIETY provides the operational readiness, governance, controls and evidence workstream, with specialist technical providers used where required.
Turning the analysis into a controlled mandate
In a live mandate concerning new authorization and EU market entry, the work cannot stop at high-level advisory language. The legal conclusion should be translated into a controlled workplan covering jurisdiction choice, corporate substance, service mapping and genuine EU management capability. Each material issue receives a factual owner and legal owner, required documents, decision point, dependencies and a completion criterion. This allows the team to distinguish true blockers from parallel workstreams and from tasks requiring a specialist or local counsel. It also provides disciplined change-control when the client alters a business assumption during the project, rather than allowing scope and responsibility to expand informally.
Failure modes to identify before they become regulatory statements
The most expensive problems are not always difficult points of law. They are often misalignment between group structure, contracts, technical flows and the application narrative. Those inconsistencies should be found before they become a filing, supervisory statement, board representation or contractual commitment. The delivery model uses an issue log recording severity, legal implication, business impact, owner and required decision. Where a gap cannot responsibly be closed in time, it should be disclosed internally and managed through an informed decision rather than hidden by drafting that creates a larger problem later.
Evidence, quality control and later review
A strong project file allows an independent reviewer to trace the path from requirement to decision and implementation. Depending on the matter, the record should include board approvals, organizational records, contracts, process maps, control records and evidence tied to application statements. Evidence should not sit in an unstructured folder: it should be linked to a requirement or action and carry an owner, date, version and review status. Before filing, closure or management assurance, a second consistency review should test whether claims, contracts, governance records and operational proof remain aligned.
Cross-border and professional-practice controls
In cross-border work, the language of a deliverable does not determine the governing law. MiCA is common EU law, but Member-State procedure, corporate law and professional-practice questions remain local. Each country therefore passes a separate jurisdiction, practice-rights and professional-conduct gate. OIKONOMAKIS LAW may coordinate the overall matter, while local-law opinions or representation are allocated to appropriately qualified professionals where required. The same distinction applies to marketing: a service that can be delivered into a market is not automatically eligible for every form of paid targeting or personalized solicitation in that jurisdiction.
The supervisory reality after 1 July 2026
The end of the transitional period changes the legal question for legacy operators. ESMA has called on unauthorized CASPs without a lawful basis to continue to stop new EU on-boarding and marketing and to implement orderly wind-down while protecting existing clients. A late or unsuccessful applicant therefore needs a different engagement from a new entrant. Client populations, contracts, custody or asset positions, marketing channels, group entities, pending application status and the lawful basis for any remaining activity need to be mapped before advice is given on next steps.
Third-country groups and reverse solicitation
For non-EU groups, reverse solicitation is a narrow legal concept rather than an acquisition strategy. If an EU-authorized entity is intended to be the regulated access point, the group operating model should demonstrate that the EU entity can control the services for which it is responsible. Outsourcing, delegation, customer journeys, custody and decision rights should not create an arrangement in which the authorized entity is merely documentary while substantive activity continues through unauthorized group entities.
Deeper analysis and implementation
The end of transition changes the legal question
Once transitional arrangements have run their course, the central question is no longer how quickly a legacy provider can assemble an application. It is whether each service is being supplied through an entity that has the regulatory status required for the activity actually performed. The analysis must map the service, customer journey, execution flow, custody or control of assets, group entities and third parties. Commercial labels such as “technology” or “infrastructure” cannot be allowed to substitute for the legal characterization of the real service.
For international groups, the EU entity must also have sufficient substance to operate the regulated business it presents to the competent authority. Senior management, decision-making, access to systems and information, oversight of delegated functions and the ability to challenge third parties are part of the authorization proposition. A European entity that is contractually visible but operationally hollow creates a supervisory problem before the first question from the authority is received.
The application creates a supervisory record
A CASP application is a coordinated set of factual and legal representations about governance, personnel, controls, ICT, continuity, custody, outsourcing and service delivery. Those representations must be internally consistent and capable of remaining true after authorization. A controlled assumptions register is therefore essential: each material proposition should identify its source, owner, supporting evidence and the change that would require re-assessment.
ESMA’s supervisory convergence work has repeatedly emphasized substance, management capability and actual operational flows. The practical implication is that drafting quality cannot repair a defective operating model. Where the application exposes a governance, staffing, contractual or technology gap, the gap should be remediated before the final filing position is locked.
Authorisation as a programme, not a document exercise
A mature engagement separates legal perimeter, corporate structure, governance, prudential and financial information where relevant, AML interfaces, custody, ICT/DORA, outsourcing, client protection, policies, evidence and regulatory correspondence into controlled workstreams. Each workstream has an accountable owner, required inputs, source of truth, open issues and sign-off criteria. Legal counsel does not replace technical specialists, and operational consultants do not issue legal opinions; the workstreams nevertheless have to describe one coherent business.
The appropriate entry product is therefore a paid Legal & Regulatory Assessment. Its output should record perimeter conclusions, jurisdiction, critical assumptions, material gaps, third-party dependencies and a realistic implementation plan. Only after that diagnostic can a full authorisation programme be scoped and priced responsibly.
Primary / official sources for publication verification
Regulation (EU) 2023/1114 (MiCA) — https://eur-lex.europa.eu/eli/reg/2023/1114/oj/eng — EU MiCA framework.
Commission Delegated Regulation (EU) 2025/305 — https://eur-lex.europa.eu/eli/reg_del/2025/305/oj/eng — CASP authorisation application information.
ESMA — MiCA — https://www.esma.europa.eu/esmas-activities/digital-finance-and-innovation/markets-crypto-assets-regulation-mica — Current supervisory material.
