ESMA orders unauthorised crypto providers to exit EU by 1 July
ESMA's 23 June statement sets binding exit conditions for unauthorised crypto-asset service providers, with B2B solicitation and custody delegation to non-authorised entities explicitly prohibited from 1 July 2026.

ESMA's public statement ESMA75-113276571-1710, published 23 June 2026, sets out how unauthorised crypto-asset service providers must exit EU activity as the MiCA transitional period expires on 1 July 2026.
The document is operational rather than interpretive. ESMA says it is clarifying expectations for how unauthorised crypto-asset service providers must "wind down activities while also protecting investors" after the end of the transitional period. It adds that some firms, including "significant providers currently servicing EU clients under national regimes", may still be unauthorised by that date.
For those providers, the instruction starts with customer acquisition. Paragraph 3 says firms should "immediately stop onboarding new EU clients, refrain from opening new client relationships or accounts, and cease marketing activities and solicitation."
Service continuation is narrowed to exit functions. ESMA says unauthorised providers may "limit the provision of services to actions necessary to sell or transfer crypto-assets, reallocate assets, or close positions". On custody specifically: "Custody of clients' crypto-assets can only continue for the period strictly necessary to complete an orderly exit." Residual activity is permitted only where it helps clients leave, not where it preserves an ongoing EU business.
Client communications must carry a hard end-point. Paragraph 3 says communications should include "a deadline by which any residual positions would be closed automatically" and information on client protection requirements. That ties wind-down messaging to actual closure mechanics, creating an attestation burden for legal, operations and customer teams.
The financial-crime controls remain in place during exit. In paragraph 4, ESMA says CASPs should maintain effective AML/CFT controls throughout the wind-down, including customer due diligence, transaction monitoring, screening against restrictive measures and sanctions lists, suspicious transaction and activity reporting, record-keeping, and compliance with transfer-of-funds and crypto-asset traceability obligations.
Two points in paragraph 6 carry the sharpest implications for group structures. First, CASPs established outside the EU cannot provide MiCA services to EU clients or solicit EU clients, and ESMA says this "also applies in a business-to-business context". Second, MiCA prohibits outsourcing or delegating certain services — "notably custody" — to entities that are not authorised as CASPs. Firms relying on intra-group service arrangements or third-country custody entities will need to unwind those structures by the deadline.
ESMA also addresses consumers directly. It invites clients using crypto-asset services in the EU to check whether a provider is authorised in the ESMA Register and, where it is not, to transfer crypto-assets to an authorised CASP or to a self-hosted wallet. No separate grace period beyond 1 July 2026 is offered.
The enforcement posture is explicit. ESMA says National Competent Authorities may "take coordinated action against unauthorised CASPs after the transitional period" within its cooperation framework. The consultation has not disclosed the number of providers still operating under national transitional regimes as of the statement date.
The open question is how quickly NCAs will move against firms that have not completed their wind-down by 1 July 2026, and whether coordinated enforcement actions will be announced in the weeks immediately following the deadline.
Permanent link to this Atlas analysis
Related Atlas analysis
Continue with coverage connected by market, topic and operating context.
- European UnionESMA tests crypto custody resilience in 2026–27 supervisory sweepESMA's July 2026 Common Supervisory Action directs national authorities to test custody-layer resilience controls at authorised CASPs through mid-2027.
- European UnionESMA targets €1bn in savings with single EU reporting frameworkESMA's 2 July final report proposes consolidating MiFIR, EMIR and SFTR into one framework, projecting €250m to €1.0bn in annual net savings for firms and authorities.
- NetherlandsDutch government proposes online gambling reforms with advertising and bonus bansThe Dutch government proposes a stricter online gambling policy, including advertising and bonus bans, following rising gambling participation and addiction rates.
Continue with Atlas
Move from this development into the relevant research, comparison and workflow.