MiCA enforcement · First-year case tracker
First MiCA Enforcement Actions 2026 — Case Tracker
MiCA's first operational year has produced a working enforcement case base. Authorisation refusals across multiple NCAs, the first withdrawal proceedings, several administrative fines, multiple public warnings against unauthorised operators, and a handful of criminal referrals. The case base is small but the patterns are visible — and the operational lessons for compliant operators are real.
MiCA enforcement covers the supervisory and administrative-sanction framework operated by National Competent Authorities under Articles 64, 109 and following of Regulation (EU) 2023/1114, plus criminal-investigation referrals to national prosecutors where regulatory non-compliance discloses criminal conduct. The framework operates across authorisation refusals, conditional grants, withdrawal proceedings, administrative fines, public warnings, and criminal referrals.
Quick facts
| Parameter | Value |
|---|---|
| Supervision and enforcement framework | Articles 64 (withdrawal), 85 (designation), 88 (NCA cooperation), 89 (information requests), 92-94 (ESMA direct powers), 109 (sanctions), plus national implementing legislation |
| Authorisation refusals (first 12 months) | Estimated 60-100 across all NCAs — actual numbers not centrally published |
| Withdrawal proceedings | Single-digit across all NCAs; principal grounds AML or governance |
| Administrative fines | Modest in volume; range EUR 50k-2m typical; Article 109 caps higher of EUR 5m, 3% turnover, or twice gain made |
| Public warnings | Numerous across NCAs against unauthorised operators serving EU customers |
| Criminal referrals | Limited but present where regulatory non-compliance discloses fraud or market manipulation |
| Most common enforcement grounds | AML deficiency, governance gaps, ICT/DORA gaps, unauthorised operation, marketing compliance violations |
| Significant-CASP designation threshold | 15 million active EU users averaged over the preceding calendar year, or ESMA discretion on cross-border systemic importance |
| NCA information powers (Article 89) | Document production, on-site inspections, individual interviews, banking-record access; non-cooperation triggers Article 109 sanctions |
| ESMA direct powers over designated CASPs | Information requests (Art 92), on-site inspections (Art 93), binding decisions (Art 94) where home NCA action is inadequate |
| ESMA register | Updated regularly with enforcement actions across the EU |
The first operational year of MiCA enforcement
MiCA went operational on 30 December 2024 for CASP authorisation provisions, with transitional arrangements running through July 2026. The first twelve months of operational supervision have produced a working enforcement case base across all 27 EU member states.
The case base is not yet large in absolute terms. Most enforcement activity has involved authorisation refusal during the application review process rather than withdrawal of granted authorisations. Withdrawal proceedings are slow and substantively demanding. Administrative fines are modest in volume and quantum. Public warnings against unauthorised operators are the most common public enforcement signal.
The patterns are visible, and the supervisor focus is consistent across NCAs. The compliance lessons are operational.
Authorisation refusals — the most common enforcement
Authorisation refusal is the most common MiCA enforcement output in the first year. Practitioner estimates put EU-wide refusal volume at 60-100 across all NCAs in the first twelve months. Actual aggregate numbers are not centrally published (ESMA does not publish refusal data), but the practitioner case base across major jurisdictions supports the estimate.
The principal refusal grounds:
AML deficiency. Inadequate AML framework, weak customer due-diligence procedures, MLRO substance insufficient, FIU reporting framework not operational, sanctions screening inadequate. The most common refusal ground across all NCAs.
Governance gaps. Inadequate board composition, key-person fit-and-proper concerns, weak internal control framework, inadequate risk management governance. The second most common refusal ground.
ICT and DORA gaps. DORA framework not operational at filing, ICT third-party risk management inadequate, incident reporting infrastructure not in place, resilience testing framework absent. Increasingly common as supervisor expectations on DORA mature.
Substance inadequacy. Shell-company arrangements without genuine operational presence, key personnel non-resident or part-time, lack of host-state operational headcount, corporate-services-provider-driven jurisdictional choice. Particularly common ground for refusal in Estonia, Lithuania, and other CEE jurisdictions with substance discipline.
Beneficial ownership concerns. Opaque beneficial ownership and prior regulatory enforcement history against beneficial owners, plus group-structure concerns that prevent effective supervision. Recurring refusal ground.
The refusal patterns are consistent across NCAs. The supervisor focus is consistent. The operational lesson for new applicants: address the common refusal grounds in filing-preparation, not after the first information request.
Withdrawal proceedings — slow but real
Authorisation withdrawal under Article 64 is procedurally slow. The process requires:
Supervisor decision to commence proceedings. Based on identified non-compliance, ongoing supervisor concerns, or specific triggering events.
Notification to the CASP. Written notification of proceedings with reasons. The CASP has the opportunity to make representations.
Remediation opportunity. Where the supervisor identifies specific non-compliance, the CASP typically has opportunity to remediate. The remediation period varies by issue but typically runs months.
Formal withdrawal decision. Where remediation fails or is inadequate, the supervisor issues formal withdrawal with reasons. The decision is enforceable subject to appeal rights.
Appeal procedures. National administrative law procedures govern appeal rights and timing.
The first twelve months of operation have produced single-digit formal withdrawal proceedings across the EU. Several proceedings are in progress. The principal grounds are AML deficiency and governance failures, alongside unaddressed ICT gaps.
The slow procedural framework means withdrawal proceedings are an extreme outcome. Most CASPs facing supervisor concerns address them through remediation engagement before formal withdrawal proceedings commence. The operational lesson: treat supervisor concerns as early signals, not as late-stage enforcement risk.
Administrative fines — modest but increasing
Administrative fines under Article 109 and national implementing legislation are modest in the first year. The typical range is EUR 50k-2m per case. Larger fines are expected as enforcement matures.
Common fine grounds:
Unauthorised CASP operation. Operating CASP services without authorisation, typically during the transition period or by non-EU operators serving EU customers.
Marketing compliance violations. Breach of Article 74 marketing rules including misleading marketing, inadequate risk disclosure, or unauthorised promotional activity by non-licensed operators.
AML deficiency at registered or authorised operators. Where AML supervisory inspection identifies specific failings, administrative fines under AML implementing legislation are typical.
Reporting failures. Late or incomplete regulatory reporting to NCAs. Smaller individual fines but cumulative across multiple periods.
Conditions-of-authorisation breaches. Where authorisation was granted with specific conditions and the operator fails to meet the conditions, fines apply.
The fine framework is operational but the quantum is modest relative to other EU regulatory regimes. The framework is likely to mature toward higher quantum as enforcement coordination strengthens.
Public warnings — the operational enforcement layer
Public warnings against unauthorised operators are the most frequent MiCA enforcement signal. The warnings operate under Article 109 and national implementing legislation. The structure:
Warning publication. NCAs publish warnings on their websites listing operators offering CASP services in the member state without proper authorisation. The warnings include operator name, identified non-compliance, and reference to applicable regulation.
ESMA coordination. ESMA aggregates national warnings into an EU-wide framework. Warnings published by one NCA become visible across the EU.
Banking and counterparty impact. Banks routinely screen against warning lists during onboarding due diligence. Payment processors similarly. Warning-listed operators face account closure or refusal across multiple banking relationships.
Customer trust impact. Public warnings affect customer trust directly. Sophisticated customers screen against warning lists. Media coverage of warning lists amplifies the reputational impact.
The first year has produced numerous public warnings across most NCAs. Common targets: non-EU operators serving EU customers without authorisation, and EU operators in transitional limbo continuing to serve customers without progressing toward authorisation. Clearly fraudulent operators also appear on the lists.
Public warnings produce more operational damage than administrative fines in most cases. The reputational and banking impact is more lasting than fine quantum.
Criminal referrals
Where MiCA-supervisory investigation discloses conduct that may constitute criminal offence, NCAs refer to national prosecutors. The first year has produced limited but real criminal referrals.
Common referral grounds:
Fraud. Where supervisor investigation discloses misrepresentation to customers, misappropriation of client assets, or operational fraud.
Market manipulation. Where supervisor investigation discloses market manipulation under MiCA Title VI Articles 88-92.
Money laundering. Where AML deficiency or operational pattern discloses money laundering risk that warrants criminal investigation.
Unauthorised operation. Where ongoing unauthorised CASP operation continues despite supervisor warning and the conduct may constitute criminal regulatory non-compliance under national law.
Criminal proceedings operate under national criminal law procedures and timelines. The MiCA-supervisory framework feeds the referrals; the criminal proceedings operate separately and slowly.
The operational lesson: MiCA enforcement and criminal exposure can overlap. Operators that treat supervisor engagement as purely regulatory miss the criminal-exposure dimension where conduct warrants it.
NCA cooperation and cross-border supervision (Article 88)
The enforcement case base sits on a supervision framework, and Article 88 is the part that determines who supervises what. The article governs cooperation between EU National Competent Authorities for CASP supervision. It reads dry and bureaucratic. In operational reality it decides who supervises a CASP authorised in one member state but operating in another, what host NCAs can demand, and how disputes between home and host supervisors resolve. It shapes passport viability more than the headline Article 65 passport rules do.
Five operational components:
Home-state primacy. The home NCA (supervisor of the member state where the CASP is authorised under Article 63) has primary supervisory responsibility across all the CASP’s EU activity, including passport activity in other member states. The benefit: a single supervisor relationship and a single reporting framework, with coherent supervisory dialogue. The risk: the home supervisor’s specific concerns and enforcement actions carry EU-wide consequences. Choosing a home state badly produces supervisor-relationship risk that compounds across the whole passport scope.
Host-state role. The host NCA’s role is limited but real. Host NCAs receive notification of passport activity under Article 65, receive supervisory information from the home NCA, and can engage on host-state-specific matters — host-state AML obligations, consumer protection, market integrity. Under Article 88(4), where the home NCA’s action is inadequate and there is genuine risk to host-state customers or markets, the host NCA can take precautionary measures. The measures are temporary and require coordination with the home NCA and notification to ESMA. Operators that treat passporting as full host-state immunity face supervisory surprise.
Information sharing. Routine sharing operates through ESMA register notifications (authorisation grants, withdrawals, material changes, enforcement actions — effectively real-time), bilateral NCA channels for supervisor-specific exchange, ESMA-coordinated channels for designated CASPs and cross-border systemic issues, and EBA channels for ART/EMT issuers and designated CASPs under Articles 117-122. The practical reality: supervisor concerns about a CASP travel across the EU within days. The strategy of choosing a soft home-state supervisor to minimise oversight does not work — host NCAs share, ESMA coordinates, and concerns that arise in passport activity feed back to the home NCA quickly.
Joint examinations. Article 88(3) and the ESMA coordination framework support joint examinations of CASPs operating across multiple member states — typically for material cross-border activity (AML framework in a host-state customer base, conduct in host-state trading) or group-wide CASP examinations (group governance, intra-group flows, group-wide risk management). The mechanics are demanding (formal coordination, joint examination plan, joint reporting, clear allocation of supervisor responsibilities), but the framework is operational. Group-wide CASP structures face group-wide supervisory engagement; choosing a home-state supervisor does not insulate group-affiliated entities elsewhere.
ESMA mediation. Where home and host NCAs disagree on a matter affecting a CASP, ESMA can mediate under Article 31 of the ESMA Regulation. The framework runs three levels: voluntary mediation (NCAs request it; non-binding but strong soft-law pressure), ESMA-initiated mediation (where it identifies a dispute affecting EU-wide coherence), and binding mediation (in specific circumstances where bilateral resolution fails). Recent ESMA practice under similar provisions in MiFID and AIFMD guides how the framework operates. Home-host supervisor disputes are not theoretical — operators caught in them face prolonged uncertainty until resolution.
The practical implication: enforcement in one jurisdiction has EU-wide consequences. Operators facing supervisor concerns in their home state face heightened scrutiny in passport jurisdictions. Operators with affiliated entities across multiple member states face cross-entity supervisor engagement. Member-state-by-member-state isolation strategy does not work.
Supervisory powers and information requests (Article 89)
When a supervisor’s attention turns to a CASP, Article 89 is the toolkit it reaches for. The powers are broad — broader than many operators realise until the first substantial information request lands.
Information powers. NCAs can require production of documents, electronic records, accounting records, internal communications, customer records, transaction records, and any other information relevant to their supervisory mandate. The scope covers operator records and, with appropriate process, third-party records held by counterparties and banking partners, as well as technology vendors.
On-site inspection powers. NCAs can conduct on-site inspections at operator premises. Reasonable notice typically applies but can be dispensed with where there is risk of evidence destruction. Documents may be sealed pending review and electronic systems imaged for forensic analysis, and staff may be interviewed.
Individual interview powers. NCAs can require named individuals to provide statements covering both factual matters within the individual’s knowledge and the individual’s own conduct. Rights of legal representation apply, but the core obligation to attend and respond remains. Statements taken may be used in subsequent Article 109 enforcement, including against the individual personally — so careful preparation with counsel matters.
Banking and telecommunications access. Via court order in most member states (direct authority in some), NCAs can access operator banking records and counterparty banking records relevant to the matter. Telecommunications metadata faces higher process thresholds but remains available in appropriate cases.
The standard information-request workflow runs: initial letter (scope, required information, deadline — usually 14-30 days), acknowledgement (request an extension here if the timeline is unrealistic, rather than defaulting), internal review (identify responsive documents, conduct privilege review), production (with index and privilege log), follow-up requests (2-6 iteration rounds depending on complexity), and closure or escalation to formal Article 109 enforcement.
Two disciplines decide how the engagement unfolds. First, produce exactly what is requested — no more, no less. Over-production expands the supervisor’s information set, can raise new concerns outside the original scope, and signals organisational anxiety. Second, manage legal professional privilege carefully. Privilege protects communications with external legal counsel on legal-advice matters; it does not protect internal compliance communications or internal audit findings, and it does not reach the underlying business facts. Operators that produce privileged materials without proper review lose privilege protection — those materials become available in subsequent enforcement. The discipline is to classify documents for privilege at creation, not at production.
Senior-management interviews carry a personal-risk dimension. Statements can support individual sanctions under Article 109 — fines up to EUR 700,000 and bans from management positions. The individual’s interests can diverge from the institution’s; where they do, the individual needs separate counsel from institutional counsel. The first information request is not the time to start building this discipline.
Administrative sanctions (Article 109)
Article 109 is the article that gives MiCA real teeth. Without it the core obligations in Articles 67, 68, 75, 76, 80 and 82 would be aspirational. With it they are operationally binding. The formal powers:
Administrative fines. Three calculation methods, applied at the higher of: the floor of EUR 5 million (legal entities) or EUR 700,000 (individuals); the percentage cap of 3% of total annual turnover (legal entities only); or the disgorgement-plus calculation of twice the gain made or loss avoided through the breach. For revenue-generating operators the turnover-based cap can exceed the floor. For market-abuse violations with large gains, the disgorgement-plus calculation can exceed both other measures. The provision exists to keep breach economics from making sanctions a cost of doing business.
Individual sanctions. Article 109 reaches individuals, not just operating entities. Senior managers face personal fines up to EUR 700,000 and temporary or permanent bans from holding management positions in MiCA-authorised entities.
Public statement powers. NCAs can publicly name breaching entities and identify the breach. Sanctions decisions are published in the ESMA register, with reputational consequences beyond the financial penalty.
Supervisory measures. Beyond fines and bans — restriction of services, suspension of trading on operated platforms, prohibition orders, cease-and-desist orders.
Article 109 is implemented through member-state national law. The ceiling is harmonised, but procedural frameworks, detailed fine-calculation methodology, the scope of “senior managers” caught by individual liability, and public-disclosure timing all vary by member state. For multi-jurisdictional CASPs the variations matter for sanctions-defence strategy.
Sanctions calculations incorporate aggravating and mitigating factors. Aggravating: duration of breach, materiality of customer harm, prior regulatory record, failure to cooperate, senior-management involvement, material gains. Mitigating: self-identification and proactive engagement, active cooperation, prompt remediation, no prior issues, customer-protection measures during the breach period, and reform of compliance infrastructure. The eventual outcome often differs by 50-200% based on these factors even within the same framework — operators with genuine remediation infrastructure and cooperative engagement frequently achieve materially better outcomes than confrontational defence.
Effective defence rests on a few things: documentation that predates the engagement (board minutes, internal-audit findings, training records, governance evidence — reactive documentation has limited credibility), genuine remediation evidence, procedural-law expertise, and a clear individual-versus-entity strategy where individual sanctions are possible. Conflicted joint representation produces worse outcomes for both. And the underlying conduct can trigger parallel criminal frameworks in member states — market-abuse and AML proceedings, plus fraud or misappropriation prosecutions, can run alongside the administrative track, so sanctions strategy must account for both.
ESMA direct supervisory powers (Articles 92-94)
For CASPs designated under Article 85, MiCA adds a layer of direct ESMA supervisory power under Articles 92-94 that operates alongside (and in specified cases instead of) home NCA supervision. This is the most underappreciated consequence of designation.
Article 92 information requests. ESMA can request, directly from designated CASPs, operational information (trading volumes, customer numbers, geographic distribution, product mix), governance information, financial information (capital, segregated client-asset reconciliation, prudential metrics), AML metrics, ICT/DORA information, and conflict-of-interest framework data. Designated CASPs respond to ESMA directly; the home NCA receives copies but the supervisory channel is direct ESMA-to-CASP. Dual supervision starts at the moment of designation.
Article 93 on-site inspections. ESMA notifies the home NCA of an inspection plan; the home NCA can join or observe, and ESMA proceeds with or without home NCA participation. Scope is broad — operations, governance, financials, AML, ICT, conflicts of interest. Where the home NCA is running its own inspection cycle, ESMA coordinates timing to minimise duplication, and joint inspections are possible by agreement. The operational implication is dual inspection cycles, requiring inspection-readiness planning for both supervisor angles.
Article 94 binding decisions. ESMA has binding-decision authority in specified circumstances — where home NCA action is inadequate to address EU-wide concerns or where the matter is cross-border-systemic. This is escalation-based, not a general ESMA-direct-supervision authority. ESMA notifies the home NCA of a proposed decision, the home NCA can respond, the CASP receives notification and a right to make representations, and ESMA issues the decision in writing with reasons. Binding decisions are directly enforceable against the CASP without home NCA implementation, with appeal rights to the EU Court of Justice through Article 263 TFEU. This is the most operationally serious feature of the regime; use cases will develop over 2026-2028.
The result is a dual-supervisor reality for designated CASPs. The home NCA retains primacy under Article 88 as principal day-to-day supervisor; ESMA operates directly alongside. Where a designated CASP also issues ART or EMT tokens above the relevant thresholds, EBA’s coordination role adds a third supervisor. Operators approaching designation thresholds should plan governance, reporting, and supervisor-engagement frameworks before the threshold crosses — and weigh home-state choice with ESMA-coordination behaviour in mind, since home NCAs that work cleanly with ESMA produce smoother dual-supervisor operations.
ESMA MiCA Q&A — the interpretive layer
Sitting underneath all of this is the ESMA MiCA Q&A. It is technically non-binding interpretive guidance. In practice it is binding: NCAs across the EU apply Q&A guidance in supervisory engagement as if it were, and operators that diverge from Q&A interpretation face supervisory engagement and potential Article 109 sanctions for inadequate compliance. It is the most important interpretive source for ongoing MiCA compliance after the regulation text and the Level 2 Technical Standards.
ESMA published the first MiCA Q&A in December 2024 alongside the application date, with updates 4-6 times per year since. The cumulative document has clarified ambiguous areas across several topic clusters:
Authorisation (Article 63). When an application is “complete” — substantive documentation across all schedule requirements, not procedural form submission (NCAs typically need 2-4 information-request rounds before the 5-month statutory clock starts). ESMA endorsed informal pre-application engagement 4-12 weeks before formal filing, and expects a single comprehensive multi-service application rather than sequential filings.
Passporting (Article 65). “Complete notification” requires substantive operator documentation (host-state business plan, customer-protection arrangements, complaint-handling infrastructure, AML cooperation with the host-state FIU) before the 15-working-day clock for host-state servicing starts. Host states cannot impose separate authorisation but retain consumer-protection enforcement, marketing-conduct supervision, complaint-handling oversight, and AML cooperation, and can require local-language consumer-facing materials.
Market abuse (Title VI). The inside-information definition for crypto-assets covers issuer-specific information, technology-development information (protocol upgrades, vulnerability disclosure, forks), partnership and licensing arrangements, and regulatory-engagement information. Crypto-specific manipulation patterns are all in scope: wash trading, spoofing, layering, pump-and-dump, and cross-venue and social-media-coordinated manipulation. Confirmed or strongly-suspected cases are reported to NCAs within 24-48 hours for clear cases.
Custody segregation (Article 75). Separate operator and customer addresses and accounting separation, plus cryptographic separation where technically feasible. Operators keep primary responsibility for segregation regardless of sub-custodian arrangements, and segregated customer crypto-assets sit outside the operator insolvency estate, with return procedures targeting reasonable timeframes (typically 30-90 days).
White-paper notification (Title II), conflicts of interest (Article 72), and significant-CASP designation (Article 85) are also covered. On Article 85, ESMA clarified the active-user definition (substantive interaction during the measurement period, not just registered accounts) and addressed cross-entity aggregation — operators structuring across multiple legal entities to stay below the per-entity threshold may face aggregation if the entities are operationally unified. Substance over form.
ESMA Q&A complements EBA Q&A, which covers banking and prudential aspects including own funds (Article 67) and recovery and resolution (Article 84). Operators need both. The compliance discipline is to treat Q&A as substantively binding, maintain monitoring infrastructure for the 4-6 annual updates, reference relevant Q&A in compliance documentation, and watch for superseded guidance — the document is cumulative, and older answers can be updated by newer ones.
Significant-CASP designation (Article 85)
Article 85 designation was theoretical through most of 2024. It went operational in 2025-2026: the first designations landed, the ESMA register populated, and the operational regime for designated CASPs became concrete. The framework creates a two-tier supervisory landscape — standard CASPs (over 95% by entity count) under home-NCA supervision, and a small number of significant CASPs (initial designations fewer than 10 entities) under a supervisory college with ESMA participation, but holding a substantial market share by user base.
The thresholds. The primary trigger is customer base: an average of 15 million active EU users over the preceding calendar year. ESMA’s RTS defines “active user” as a customer who completed at least one crypto-asset service transaction with the CASP in the calendar quarter — static account holders without activity do not count, and the averaging across quarters smooths volatility. ESMA can also designate on discretion where activity has material cross-border systemic importance — for example a trading venue with material price-discovery influence on a key crypto-asset, or custody for a material portion of an issuer’s outstanding token supply. Industry estimates put 4-8 platforms at or near the threshold across the EU in 2026 — primarily the largest centralised exchanges and one or two pan-EU custody platforms.
What changes. The home NCA remains the licensing authority — authorisation, withdrawal, and sanctioning powers under Articles 63 and 64 stay with the home NCA. What changes is the supervisory-engagement layer. ESMA joins the dialogue through the supervisory college, which the home NCA chairs; the operating arrangements (quarterly college meetings, joint supervisory data review, coordinated host-NCA engagement, a structured information-exchange protocol) were specified in ESMA’s 2025 RTS. Designated CASPs file quarterly regulatory data packs that feed the college’s ongoing assessment, and an annual systemic-risk review covers the CASP. Enhanced governance expectations follow: board composition with substantive independent membership and separated risk and audit functions, all resting on a three-lines-of-defence model with an evidence trail. Heightened reporting and own-funds requirements proportionate to operational scale apply alongside.
What it does not do. Designation is not a licence downgrade and not a back-door to a more permissive licence. The authorised service set, the Article 67 own-funds methodology, the Article 66 conduct rules, and the Article 75 custody-safeguarding rules all continue to apply. The CASP keeps its full EU passport. The designation reflects scale, not a sanction.
The AMLA distinction. A common misreading is that ESMA designation under Article 85 and AMLA direct supervision under the AMLR are the same regime. They are not. Article 85 is consumer-protection and market-conduct supervision, triggered by the 15-million-active-EU-user threshold, with the home NCA chairing a college and ESMA participating. AMLA direct supervision is AML/CFT supervision, triggered by operating in at least six member states with above-threshold customer count or transaction value in each, with AMLA replacing national AML supervisors for directly-supervised entities. A CASP can be a designated CASP under MiCA without being AMLA-supervised, or the reverse, or both.
For the 4-8 platforms within reach, the practical message is to model the regime now. The supervisory-college engagement is a working pattern that takes 6-12 months to build, and the operational uplift typically requires 12-18 months of lead time. ESMA’s RTS encourages early-stage engagement before formal designation. Operators that plan for it strategically face better outcomes than operators that react post-designation.
Patterns and lessons
The first-year case base produces visible patterns:
AML is the most-tested aspect. The most common refusal ground and the most frequent administrative fine ground, it is also one of the most common supervisor inspection focuses. AML framework strength is the single most important compliance investment.
Governance discipline matters. Board composition, key-person fit-and-proper, internal controls, and risk management governance produce supervisor scrutiny disproportionate to their visibility in compliance budgets.
DORA framework is increasingly tested. Early enforcement focused on the core CASP framework. The 2026 enforcement cycle is increasingly testing DORA implementation as supervisor expectations on DORA mature.
Substance discipline is non-negotiable. Shell-company arrangements and non-resident senior personnel, along with corporate-services-provider-driven jurisdictional choice, produce refusals across multiple NCAs. The substance bar is real.
Public warnings affect operations more than fines. The reputational and banking impact of public warnings is consequential. Operators facing public warning find banking, customer trust, and counterparty relationships compromised faster than administrative fines would produce.
Cross-NCA visibility is operational. Enforcement actions in one member state produce EU-wide consequences through the coordination framework.
Practical takeaways
MiCA enforcement is operational and consequential. Three principles for compliant operators:
Invest in AML framework strength. The most-tested aspect of CASP compliance. The most common refusal ground. The most frequent administrative fine ground. AML investment pays back across multiple supervisor angles.
Build governance discipline alongside operational compliance. Supervisor focus on governance is consistent across NCAs. Strong governance discipline reduces refusal risk and supports clean supervisor dialogue across the operational life of the authorisation.
Treat supervisor concerns as early signals. Enforcement proceedings are extreme outcomes. Most supervisor concerns surface through information requests and supervisory dialogue, or through inspection findings. Addressing concerns early produces clean remediation; ignoring early signals produces escalation to formal enforcement.
The enforcement case base will grow through 2026-2028 as supervisors complete initial authorisation review and shift focus to ongoing supervision. The patterns visible in the first year will sharpen. Compliant operators that learn from the case base position themselves cleanly for the maturing enforcement framework.
For corrections, updates, or counsel referrals on MiCA enforcement, email [email protected].
Pitfalls and nuances
1 Treating enforcement as remote risk
MiCA enforcement is operational. Supervisor inspections, information requests, and follow-up engagement happen routinely. Operators that treat enforcement as remote risk underinvest in compliance infrastructure and find themselves in supervisor dialogue without the operational discipline to manage it cleanly.
2 Underestimating public warning impact
Public warnings are reputationally consequential. Banks deny accounts to warning-listed operators. Payment processors decline relationships. Counterparties refuse business. Customer trust collapses. Public warning can produce more operational damage than administrative fines.
3 Ignoring cross-NCA enforcement coordination
Enforcement actions in one member state surface across the EU through Article 88 information sharing and ESMA coordination. Operators experiencing enforcement in one jurisdiction face supervisor scrutiny across passport jurisdictions. The enforcement landscape is EU-wide, not member-state-isolated.
4 Filing for authorisation without learning from refusal patterns
The first-year refusal case base is informative. Common refusal grounds — AML deficiency, governance gaps, ICT/DORA gaps, inadequate substance — show where supervisor scrutiny concentrates. Operators that file without addressing the common refusal grounds face avoidable supervisor concerns.
Frequently asked questions
How many CASP authorisation refusals have NCAs issued?
Aggregate numbers are not centrally published. Practitioner estimates put EU-wide refusal volume at 60-100 in the first twelve months of MiCA operation. Refusals concentrate in AML deficiency, governance gaps, and inadequate substance.
Have any CASP authorisations been formally withdrawn?
Single-digit cases across the EU in the first twelve months. Withdrawal proceedings are slow and substantive — they require formal supervisor decision, applicant notification, opportunity to remedy, and appeal rights. Several proceedings are in progress.
What administrative fines have been issued?
Modest volume; range EUR 50k-2m typical. Most relate to unauthorised CASP operation, marketing compliance violations under Article 74, or AML deficiency at registered or authorised operators. Larger fines are likely as enforcement matures.
How many public warnings have been issued?
Numerous. Most NCAs maintain public warning lists for unauthorised operators serving member-state customers in violation of Article 59 authorisation requirements. ESMA aggregates warnings into a coordinated EU-wide framework.
Have any criminal cases emerged from MiCA enforcement?
Limited but present. Where MiCA-supervisory investigation discloses fraud, market manipulation, money laundering, or other criminal conduct, NCAs refer to national prosecutors. Several criminal investigations are in progress, mostly involving alleged fraud or market manipulation.
What is a significant CASP under Article 85?
A CASP designated under Article 85 — meeting the 15 million active EU users threshold, or ESMA discretion on systemic importance. A supervisory college with ESMA participation forms; the home NCA stays the licensing authority.
What can NCAs compel under Article 89 information powers?
Document production, on-site inspections, individual interviews, and banking-record access under Article 89. Refusal triggers Article 109 sanctions, and substantial non-cooperation can trigger Article 64 withdrawal.
Can ESMA issue binding decisions on designated CASPs?
In specified circumstances under Article 94 — particularly where home NCA action is inadequate or the matter is cross-border-systemic. Decisions are directly enforceable, with appeal to the EU Court of Justice.
Get matched
Working through a crypto-licensing decision?
Get an editorial shortlist of firms matched to your business — customer market, model, jurisdiction, and stage. Free, and not influenced by sponsorship.
Get a firm shortlist →Sources cited
- Regulation (EU) 2023/1114 (MiCA), Articles 64, 85, 88, 89, 92-94 and 109 — regulation
- ESMA Regulation (EU) No 1095/2010, Article 31 (binding mediation) — regulation
- ESMA — CASP register and enforcement coordination — regulator
- ESMA — MiCA Questions and Answers — regulator
- EBA — Significant CASP designation methodology — regulator
- Various national NCA enforcement publication pages — regulator