If a firm sits outside the EU and took on EU clients while grandfathering was in place, its end raises an immediate question, what to do with those clients. The instinct is to reach for a workaround, and two come up repeatedly. Keep the clients and treat their arrival as reverse solicitation, or keep them and hand the regulated part to a firm that holds a licence, through a referral or a white-label arrangement. Both are narrower than they look, and most firms that rely on them are buying a little time rather than solving the problem. What follows is why, and then the one answer that holds, a licence of the firm’s own, built or bought, and in the right Member State.
Where things stand
MiCA, the EU’s Markets in Crypto-Assets Regulation, is now the single rulebook for crypto-asset services across the Union. It replaced a patchwork of national regimes and gave firms already operating under those regimes a transitional period to continue serving clients while they applied for authorisation. That period has now ended.
Firms that provided crypto-asset services under national law before 30 December 2024 could continue to do so until 1 July 2026, until their home regulator granted or refused authorisation, or until the earlier date their Member State chose to set, whichever came first. Member States did not choose alike. In Germany, the transitional permission lapsed on 31 December 2025[1]. In the Netherlands, Finland, Poland, and several other countries, it ended a full year before the headline date, at the end of June 2025[2]. The 1 July 2026 date quoted as the end of MiCA grandfathering was only ever the outer edge of the window. Most firms were working to an earlier one.

In a statement on 23 June 2026, ESMA set out in some detail what an orderly wind-down looks like for a firm that reaches 1 July 2026 without a licence[3]. The core of it is straightforward. Stop onboarding EU clients and opening new accounts or relationships, pause marketing and solicitation, and keep serving existing clients only so they can sell, transfer, reallocate, or close positions, holding their assets in custody for as long as that genuinely takes. A firm established outside the EU still cannot provide MiCA services to EU clients or solicit them, business-to-business included, and custody cannot be delegated to an entity that is not itself an authorised crypto-asset service provider, or CASP[4].
Two further points are easy to miss. The first is that keeping clients informed is itself part of the obligation: clearly, promptly, and more than once, covering how their assets are being protected, the timeline for moving or closing positions, and the date on which any residual positions are automatically closed. The second is that anti-money-laundering and counter-terrorist-financing controls continue unchanged while a firm winds down, including customer due diligence, transaction monitoring, sanctions screening, suspicious-activity reporting, and record-keeping. The exit changes what the business does, not the standard to which it is held.
So the firms that spent the transitional period on growth rather than authorisation arrive at the same question, and most reach for one of two answers. The first is the reverse solicitation exemption. The second is a referral, distribution, or white-label arrangement with a firm that holds a licence.
The register shows how many firms are in that position. More than 300 now hold a CASP authorisation across the EU and EEA, against more than 1’200 entities that held national registrations before MiCA[5]. Germany has the most entries, but a large share of them are banks and brokerages that notified narrow permissions under Article 60 rather than crypto-native firms that went through a full authorisation. Supervision has moved on as well. On 8 July ESMA opened the first coordinated supervisory action under MiCA, on the operational resilience of authorised CASPs, with custody at its centre and third-party dependencies expressly in scope[6].
Reverse solicitation
Reverse solicitation is the exemption firms reach for first, and Article 61 MiCA draws it narrowly. Where a client established in the Union approaches a third-country firm on its own exclusive initiative, that firm needs no authorisation to provide the requested service to that client[7]. The exemption is per client and per service. It helps to see what it does not touch. MiCA runs on two tracks. One, in Title II, governs offering a token to the public, and turns on a published white paper rather than a licence. The other, in Title V, governs providing services around crypto-assets, which is what a CASP licence authorises[8]. Reverse solicitation sits in the second track only. A firm outside the EU can still publish a compliant white paper and offer a token to EU buyers without being a CASP at all.
This is not a new idea. The same exemption exists under MiFID II, and ESMA has read it narrowly from the start, as an exception and not a route around the rules[9]. Its guidelines[10] are easiest to read through examples.

Underneath the examples sit a few principles[11]. The first is that solicitation is read broadly, by any means, from web advertising to an influencer post. So ‘the client came to us’ is no answer if your own marketing is what put you in front of them. The test is factual, not contractual. A disclaimer, or a clause in which the client ‘confirms’ it approached you, does not change what happened. ‘Same type’ is granular, separating asset-referenced, e-money, and utility tokens, different technologies, and liquid from illiquid. And a third party’s approach is your own, which is why an EU-regulated firm cannot route clients to a third-country firm on its behalf. Geoblocking, if you rely on it, means blocking EU IP addresses and keeping the application out of EU app stores.
There is also the practical question of proof. Because the exemption turns on the client acting first, it is the provider that has to be able to show it, client by client[12]. For a single counterparty who genuinely came unprompted, that is a simple record to keep. Across a whole book of clients, and for any firm with a real marketing presence in the EU, it is harder to stand behind, because the same outreach that builds the business is what a regulator would weigh against the claim. None of this makes the exemption a trap. It makes it what it is, a rule for the occasional client rather than a basis for serving a market.
The most common way that record is lost now is the wind-down itself. A firm that writes to its EU clients about closing positions is complying with ESMA requirements. A firm that uses the same message to explain how the relationship might continue has, in writing, solicited precisely the clients whose unprompted approach it may later need to prove[13].
The exemption fits the client who genuinely turned up alone, wanted one thing, and got that one thing. It is the door a client uses to leave with their assets, and building a growth plan on it means building on the exit.
The back door
If reverse solicitation will not carry the business, the obvious next move is to keep the client relationship and hand the regulated part to a firm that holds a licence. This is the live question for the second half of 2026, and it deserves a serious answer, because MiCA does not resolve it cleanly.
Start with what is settled. A licence authorises its holder. It does not extend to a third party’s business through a contract. ESMA’s June statement makes two points that land directly here. A non-EU firm cannot provide MiCA services to EU clients, business-to-business included, and custody cannot be delegated to a firm that is not itself an authorised CASP[14]. The reverse solicitation Guidelines say the same from the other side, telling EU firms not to redirect clients to a third-country firm, including one within their own group, and the AMF restated the position when the French transitional period ended[15]. A model in which the unauthorised firm continues to perform the regulated work while the licensed CASP lends its name is not a structure. It is an unauthorised activity with a co-signatory.
The harder line runs between genuine introduction and regulated service provision. A clean referral, where the licensed CASP actually onboards the client, maintains the relationship, provides the service, and handles compliance, is different from a ‘referral’ in which the introducing firm still takes orders, gives advice, or controls assets. The label on the contract does not decide this, any more than a disclaimer decides reverse solicitation. What decides it is who performs the regulated act. Reception and transmission of orders is itself a crypto-asset service. So is advice. So is custody. An introducer that does any of them has not introduced a client; it has provided a service it is not authorised to provide. The same test decides a white-label arrangement. Putting the unauthorised firm’s brand on a licensed CASP’s service changes nothing if the unauthorised firm is still the one taking orders, holding assets, or dealing with the client. A brand is not a licence, and the regulated activity has to sit, in substance, with the firm authorised to carry it.
MiCA makes this harder than MiFID II does, because MiFID II has a tied-agent regime[16] and MiCA has no equivalent. The familiar model here is the tied agent, an unauthorised firm acting under an investment firm’s licence, which German practice knows as operating under a Haftungsdach. MiCA provides nothing like it for crypto services. There is no bound-agent status for a firm to occupy. That does not put partnership out of reach, but it does mean the partnership has to be cut differently. Firms building these arrangements should expect regulators to look through form to substance, and should treat any migration of clients from the winding-down entity to the licensed one as a full onboarding event, with the entire KYC and CDD stack, not a portfolio transfer[17].
CASP as a service
There is a version of the arrangement that works, and the difference is allocation rather than labelling. The licensed CASP is the provider. It onboards the client, holds the contract, controls the assets, runs compliance, and answers to its supervisor. The other firm supplies what is not regulated in itself: the brand, the technology, the introduction, and the front end, provided it runs the front end for the CASP and in its name. Operated on its own account, a front end through which clients place orders is reception and transmission of orders, which is a service in itself. Sold as a package it is marketed as CASP as a service, or crypto as a service, and for a firm outside the EU that has neither an authorisation of its own nor an EU entity, it is what remains, because in it the firm is a supplier to a CASP rather than a provider of services to EU clients.
The limits come from the licensed side. Outsourcing under Article 73(1) MiCA must not delegate the CASP’s responsibility, alter its relationship with clients or its obligations towards them, alter the conditions of its authorisation, or put the activity beyond the reach of its supervisor, whose access extends to the premises of the service provider[18]. ESMA’s supervisory briefing puts the same test in operational terms: letter-box entities are not permitted, responsibility for anti-money-laundering compliance stays with the CASP whatever the contract says, and an arrangement performing more outside the Union than within it will be assessed critically[19]. Neither ESMA nor any national authority has addressed these models by name, so the analysis rests on those conditions and on the letter-box test rather than on settled practice, and the burden of showing that the allocation is real sits with the parties. Custody is the hard stop, because it can sit only with a firm that is itself authorised, and it reaches further than the label suggests: whoever generates, holds, or can use the keys controls the assets, which is why the supervisory action opened in July examines key and storage management alongside third-party dependencies[20].
Two things follow. The first is supervisory. A firm that plugs into a partner’s licence becomes part of that partner’s third-party dependencies, and those are being examined across the Union under the action opened in July. The second is commercial, and it is what the sales deck leaves out. The regulated relationship belongs to the partner, and with it the client, along with a share of the margin and the freedom to change pricing, scope, or asset coverage without asking.
The diligence follows from the same point. Whether the partner is authorised rather than pending or grandfathered. Whether the services on its authorisation cover what is actually being sold. Whether it has notified the Member States where the clients sit, since the passport works by notification and not automatically. And whether it appears on the register of entities reported as operating without authorisation, which is patchy enough that absence proves little, while presence ends the conversation[21]. Done properly, the model buys time and access on someone else’s permission, which makes it a bridge to an authorisation rather than an alternative to one.
The licence
The reason a licence is worth its cost is that it is the only route that does not depend on a factual defence you have to be ready to run. The workarounds keep you in the market on someone else’s permission, or on a narrow reading of a client’s intent. Authorisation puts you in the market as of right.
A CASP authorisation is granted by one home regulator and, once granted, is recognised across all 27 Member States and the wider EEA, which brings in Norway, Iceland, and Liechtenstein[22]. Entering a new market is a notification, not another licence. On that footing, a firm markets, solicits, and onboards EU clients as a matter of course, and answers to a single supervisor under one rulebook. The authorisation also sits in an entity that is itself worth something. It can be passported, extended service by service as the business grows, capitalised, and valued cleanly in a financing or a sale. A licence is an asset on the balance sheet, not only a permission to trade.

Two routes are regularly overlooked. A firm that already holds an EU authorisation as a credit institution or an investment firm can provide several crypto-asset services on a notification rather than a full CASP authorisation, under Article 60. The notification goes in at least 40 working days before the services start, and it reaches only as far as what the firm is already authorised to do. This ‘top-up’ is much of the reason Germany leads the authorisation count, since many credit institutions can provide crypto-asset services on that basis. And during the transitional window, firms that already held a national authorisation could use a simplified transitional procedure[23]. That route has now closed for latecomers, which is why the ordinary route matters again.
For a firm based outside the EU and EEA, one fact should be stated without softening. MiCA has no third-country equivalence regime and no passport for crypto-asset services. A licence held at home does not reach into the Union, and a branch will not do, because MiCA requires both the registered office and the place of effective management to sit in a Member State. An authorised entity established within the EU or EEA, with genuine substance supporting its operation, offers a practical solution. Which Member State is the right home is a real decision rather than a formality. Regulators across the Member States differ in depth, in speed, in cost, and in how they approach crypto business, and the answer turns on the firm itself, its clients, and its timeline rather than on a template. What none of them will accept is a nameplate. The entity needs real people, real governance, and real capital, which is what regulators are now checking for[24].
Building this is a project measured in months, not weeks. It needs an EU entity with fit-and-proper management, a compliance and AML function, a programme of operations, and capital held inside the company. It is more work than a disclaimer or a contractual clause, and it is the one form of EU access a firm owns rather than borrows or defends.
A licence can also be bought. A firm with the capital can acquire an authorised CASP, or a large enough stake in one, and step into a licence that already exists. The threshold that matters is 10%. Acquire that much of the capital or voting rights, or enough to exert significant influence[25], and the purchase stops being a private transaction. It constitutes a change of control that the home regulator must clear in advance. Before the deal can be completed, the buyer notifies the authority and waits for an assessment of up to 60 working days, in which the authority weighs the buyer itself, its reputation, its financial standing, the people who would run the business, and any money-laundering risk, against the same test that applies to buyers of investment firms under MiFID II[26]. If the authority does not oppose within that period, the acquisition is deemed approved, which makes the timetable manageable but not the file. Clearing it is not the end of the matter. The buyer becomes a qualifying shareholder within the regulated perimeter, and any subsequent increase beyond 20%, 30%, or 50% is assessed again. It is a genuine set of obligations to take on, and one worth understanding before signing rather than after.
A licence also travels with the company rather than its assets, so this is a purchase of the entity itself. A CASP authorisation attaches to a specific legal entity and to the services on its licence, not to a business line or a book of assets, so it cannot be sold on its own or carried across in a sale of assets. Acquiring one therefore means buying the company that holds it, as a share deal rather than an asset deal. Buy the shares and the authorised entity carries on and keeps its licence, while only its ownership changes, which is why the regulator runs the change-of-control assessment above rather than a fresh authorisation. In practice a live authorised CASP rarely comes to market and is priced accordingly, so for many firms building stays the more realistic route and buying is the option where a suitable entity and the capital line up. What comes with it is everything the entity is, its licence perimeter, its record, and its liabilities, so the diligence weighs as much as the price. A buyer from outside the EU draws closer scrutiny still, on its beneficial ownership, the source of its funds, and how its group is supervised[27].
Below that line, the picture is very different. A stake under 10% that carries no significant influence, and is not aggregated with the holdings of others acting in concert, is not a qualifying holding at all, so none of that follows, no notification, and no clearance[28]. That makes a minority position a genuinely lighter instrument, a way to take exposure to a licensed business, or a foothold with an option to go further, without stepping into the regulated fold. The limits are real. Influence can arise below 10% through board seats or veto rights, and the moment a holder reaches for control, the full assessment applies. A minority stake buys a position, not the running of the business, and not the licence.
For most firms, the shape of the answer is not really in doubt. The workarounds buy a little more time, a partnership under another firm’s licence buys access on terms someone else sets, a licence holds, and what is left to settle is practical, whether to build the licence or buy one, and in which Member State. Two dates belong in that plan. The Commission has proposed moving authorisation and supervision of CASPs from national authorities to ESMA, which is in negotiation and changes nothing today, but it shortens the half-life of the question of which supervisor to choose[29]. And the EU anti-money-laundering regulation applies directly from 10 July 2027, so a project starting now should be built to that standard rather than retrofitted to it[30]. Those questions turn on the specific firm rather than a template, and they are worth working through carefully before a firm settles on a route.
Where to start
If you are weighing up your route into the EU, we are happy to walk you through the options.
[1] KMAG (Kryptomรคrkteaufsichtsgesetz, Art. 1 Finanzmarktdigitalisierungsgesetz), section 50: the transitional permission lapses at the latest at the end of 31 December 2025. Some secondary sources cite 30 December 2025; the statutory text governs.
[2] ESMA, list of national transitional periods under Art. 143(3) MiCA, esma.europa.eu.
[3] ESMA, Public Statement on the end of the MiCA transitional period, 23 June 2026, ESMA75-113276571-1710 (building on the statement of 17 April 2026, ESMA75-113276571-1679). The Statement requires unauthorised CASPs to stop onboarding, marketing and solicitation, to limit services to an orderly exit, to communicate clearly, promptly and repeatedly with clients (including a deadline for automatic closure of residual positions), and to maintain AML and CFT controls throughout the wind-down.
[4] ESMA (fn. 3): a third-country firm may not provide crypto-asset services to, or solicit, clients established in the Union, business-to-business included, save under the narrow reverse solicitation exemption; custody may not be delegated to an entity that is not itself an authorised CASP.
[5] ESMA publishes the MiCA register in interim files under Arts 109 and 110 MiCA. As at 24 July 2026 it showed more than 300 authorised CASPs across 26 EU and EEA home States, against more than 1’200 entities that held national registrations before MiCA. The register is updated at regular intervals.
[6] ESMA, Common Supervisory Action on CASPs’ digital operational resilience for custody, 8 July 2026. The scope covers governance arrangements, key and storage management, transaction controls, incident detection and response, smart contract risks and dependencies on third-party providers. National competent authorities examine a risk-based sample from the second half of 2026 into the first half of 2027, with a consolidated report to ESMA’s Board of Supervisors in the second half of 2027. It is the first coordinated supervisory action under MiCA.
[7] Art. 61(1) MiCA.
[8] Offers of crypto-assets to the public are governed by Title II MiCA (in particular Arts 4, 6, 8 and 9), which requires a notified and published white paper but no authorisation, and which applies to offerors inside or outside the Union. Art. 61 concerns Title V services only.
[9] ESMA, Final Report on the draft Guidelines on reverse solicitation under MiCA, 17 December 2024, ESMA35-1872330276-1899: the exemption is to be construed narrowly and may not be used to circumvent MiCA. The MiCA provision mirrors Art. 42 MiFID II (Directive 2014/65/EU).
[10] ESMA, Guidelines on the reverse solicitation exemption under MiCA, 26 February 2025, ESMA35-1872330276-2030.
[11] ESMA Guidelines (fn. 10): solicitation is read broadly and by any means, including through third parties and influencers (section 5, Guidelines 1 and 2); the client’s own exclusive initiative is a factual test that disclaimers cannot displace, and same-type offers are confined to the initiating transaction (section 5, Guideline 3); ‘same type’ follows a granular taxonomy (section 5, Guideline 4); geoblocking means blocking EU IP addresses and app-store non-availability.
[12] The exemption applies only where the service is provided at the client’s own exclusive initiative (Art. 61(1) MiCA); the assessment is factual, and disclaimers or contractual wording cannot override contrary facts (ESMA Guidelines (fn. 10), section 5, Guideline 3; Final Report (fn. 9)). The evidential burden of establishing that initiative accordingly rests with the provider, consistent with ESMA’s settled approach to reverse solicitation under Art. 42 MiFID II (Directive 2014/65/EU).
[13] The two obligations meet in the same message: ESMA (fn. 3) requires clear, prompt and repeated communication with clients during wind-down, while the Guidelines (fn. 10) treat solicitation as capable of occurring by any means. A wind-down notice that also markets continued access is solicitation in writing, and is evidenced as such.
[14] ESMA (fn. 3).
[15] ESMA Guidelines (fn. 10), section 5, Guideline 2, para 22: an EU credit institution, investment firm or payment service provider should not redirect clients to crypto-asset services provided by a third-country firm, whether or not that firm belongs to the same group. The AMF restated the position on 23 June 2026, at the end of the French transitional period: firms established outside the EU may not provide crypto-asset services to EU clients apart from the reverse solicitation exemption, and CASPs may not outsource custody to unauthorised firms.
[16] MiFID II (Directive 2014/65/EU), Art. 29, provides for tied agents; MiCA contains no equivalent regime.
[17] ESMA (fn. 3): on a transfer of clients to an authorised CASP, the receiving CASP must carry out its own onboarding, customer due diligence and AML/CFT checks.
[18] Art. 73(1)(a) to (d) MiCA, Regulation (EU) 2023/1114 (CELEX 32023R1114): outsourcing must not result in the delegation of the CASP’s responsibility, alter its relationship with clients or its obligations towards them, alter the conditions of its authorisation, or prevent the exercise of supervisory functions, including access to the premises of the service provider.
[19] ESMA, Supervisory Briefing on the authorisation of CASPs under MiCA, 31 January 2025, ESMA75-453128700-1263: letter-box entities are not permitted; responsibility for AML compliance remains with the CASP; arrangements under which more functions are performed outside the Union than within it, and intra-group outsourcing, are to be assessed critically; the entity must be able to operate autonomously, with sufficient personnel in the authorising Member State.
[20] ESMA (fn. 3): custody may not be delegated to an entity that is not itself an authorised CASP. Only a firm authorised under Art. 59 MiCA may provide custody and administration of crypto-assets on behalf of clients. Key and storage management falls within the scope of the supervisory action at fn. 6.
[21] Art. 65 MiCA: cross-border provision operates by notification through the home authority, and the ESMA register records the services covered by each authorisation and the Member States notified. The register of entities reported as providing crypto-asset services without authorisation is maintained under Art. 110 MiCA; reporting practice varies between national authorities, so absence from it is not evidence of authorisation.
[22] Arts 59, 63 and 65 MiCA. MiCA is incorporated into the EEA Agreement, so a CASP authorisation extends across the EEA, including Norway, Iceland and Liechtenstein; cross-border provision is by notification under Art. 65.
[23] Art. 60 MiCA: certain already-authorised financial entities (among them credit institutions and investment firms) may provide equivalent crypto-asset services by notifying their competent authority rather than by a full CASP authorisation. Art. 143(6) MiCA provided a simplified transitional procedure for firms authorised under national law before 30 December 2024, now closed to new entrants.
[24] Arts 59 and 62 MiCA: a CASP must have its registered office in the Member State where it carries out at least part of its business and its place of effective management in the Union; a branch of a third-country firm cannot be authorised. Minimum capital by service class is set in Art. 67 and Annex IV (EUR 50’000, 125’000 or 150’000); governance and fit-and-proper requirements are in Art. 68.
[25] A qualifying holding is a direct or indirect holding representing at least 10% of the capital or voting rights, or one making it possible to exercise significant influence over management: Art. 3(1) no. 36 MiCA, referring to Arts 9 and 10 of Directive 2004/109/EC. Prior notification is required on acquisition of a qualifying holding and on reaching or crossing 20%, 30% or 50%, or acquiring control: Art. 83(1) MiCA.
[26] Arts 83 and 84 MiCA. The competent authority has 60 working days from written acknowledgment to assess the proposed acquisition, extendable where it requests further information, and may oppose only on the grounds in Art. 84(1), namely the reputation and financial soundness of the proposed acquirer, the fitness of the persons who will direct the business, the target’s ability to continue complying with Title V, and money-laundering or terrorist-financing risk; absent opposition within the period, the acquisition is deemed approved. Detailed information requirements: Commission Delegated Regulation (EU) 2025/414. The regime mirrors Arts 11 to 13 MiFID II.
[27] A third-country acquirer faces closer scrutiny of its beneficial ownership, the source of its funds (including any crypto-asset financing) and the scope of group supervision: Commission Delegated Regulation (EU) 2025/414 (fn. 26).
[28] A holding below 10% is a qualifying holding only where it enables the exercise of significant influence over the CASP’s management (Art. 3(1) no. 36 MiCA); board representation, veto rights or a shareholders’ agreement may cross that line. Holdings of persons acting in concert are aggregated and indirect holdings count (Art. 3(1) no. 36 MiCA, referring to Arts 9, 10 and 12(4) and (5) of Directive 2004/109/EC). The circumstances giving rise to a qualifying holding are addressed in the Joint EBA/ESMA Guidelines, EBA/GL/2024/09. Whether a given stake reaches the threshold is fact-specific.
[29] Market integration and supervision package, 4 December 2025, under the Savings and Investments Union: the Commission proposes transferring authorisation, ongoing supervision and enforcement for CASPs from national competent authorities to ESMA, leaving entities that notify under Art. 60 MiCA with their national authorities. A legislative proposal in negotiation, not in force.
[30] Regulation (EU) 2024/1624 (AMLR) applies from 10 July 2027, with no crypto-specific carve-out and without the occasional-transaction threshold for crypto-assets. Regulation (EU) 2023/1113 governs transfers of funds and crypto-assets. AMLA has been operational since 1 July 2025, with direct supervision of selected obliged entities from 2028.
