
Only 281 of 1,343 crypto service providers active across the European Economic Area (EEA) obtained the Markets in Crypto-Assets (MiCA) authorisation before the EU’s final transition period expired on July 1. This means that more than 1,000 firms can no longer legally continue doing business in EEA countries under the bloc’s licensing regime.
Key Numbers
- 281 of 1,343 EEA crypto firms secured MiCA authorisation by July 1
- 12% of unauthorised firms carry High or Severe risk ratings, against 2% of authorised providers
- Unauthorised firms sent $5 billion directly to sanctioned counterparties, about three times the $1.7 billion recorded among authorised firms
- Germany authorised the most firms (55); Cyprus authorised 19
According to blockchain intelligence firm TRM Labs, 1,062 firms in its dataset missed the deadline. They must now exit the EU market, restructure, or transfer customers to an authorised provider.
From National Registers to One EU Framework
Crypto firms previously operated under separate national registration systems, each with different requirements. MiCA replaced them with a single EU-wide authorisation framework.
Firms trading legally before December 30, 2024, could continue operating under a grandfathering provision while their application was assessed. July 1 marked the final cut-off across the bloc.
Authorisation Rates Vary Sharply by Country
Germany led with 55 approvals, followed by France and the Netherlands with 29 each. Malta approved 20 firms and Cyprus 19, a stronger showing than Italy, which issued only nine home authorisations despite hosting 145 operating firms.
Together, Cyprus, Malta, Ireland and Luxembourg accounted for 63 of the 272 home authorisations TRM identified, out of just 101 previously registered firms, a far higher conversion rate than larger markets managed. Lithuania converted only eight of over 400 previously registered firms, and Poland authorised none of its 1,800-plus registered crypto firms.
Passporting lets a MiCA licence granted in one member state cover services across the whole EEA. B2C2 used this route after securing Luxembourg authorisation in May, thus gaining rights to offer regulated OTC crypto trading in all 27 EU states, plus three more EEA markets. Coinbase, Bitpanda and Kraken run on the same principle, operating from different regulatory bases while serving customers bloc-wide.
Cyprus’s Role in the New Regime
In Cyprus, CySEC is the national authority responsible for issuing MiCA authorisations and overseeing investment firms. Locally authorised providers include Revolut Digital Assets Europe. The firm is based in Limassol and holds CySEC licence CASP001/25, covering custody, trading and crypto-to-crypto exchange.
CySEC has already flagged a concerning side effect of the transition. Customers who want to leave unauthorised firms are targeted by impersonation fraud, with scammers posing as regulators or exiting providers to pressure victims into moving funds.
Unauthorised Firms Carry Higher Risk
TRM’s data shows the risk gap runs deeper than licensing numbers alone suggest. Every firm rated Severe fell into the unauthorised group. Crypto exchanges represented 42% of unauthorised firms, compared to 29% of authorised ones. Meanwhile, regulated financial and investment firms were more concentrated among authorised providers.
What Happens to Customers Now
The EU’s Anti-Money Laundering Authority offers unauthorised firms three options: leave the market, transfer clients, or wind down. It has asked national supervisors to make the oversight of these exits a priority. At the same time, the European AMLA body is warning that compressed timelines can strain anti-money laundering controls and obscure where funds move.
TRM identified 30 unauthorised providers with High or Severe ratings, giving supervisors a starting point for screening incoming customers. Most departing firms, however, carried Low risk ratings and negligible illicit exposure, and TRM cautions against treating every migrating customer as high-risk.
Regulators are now shifting their focus to firms that did get licensed. In July, the European Securities and Markets Authority began reviewing a sample of MiCA-authorised crypto custodians, examining custody controls, private-key management and incident response.
Full details of TRM Labs’ analysis are available in its report. The current EU-wide list of MiCA-authorised firms can be checked on ESMA’s register.