CySEC warns that crypto-asset services in Cyprus must now comply with MiCA, while unauthorised providers face an EU-wide wind-down.
CySEC has warned that crypto-asset services in Cyprus may now be provided only under MiCA, as European regulators press unauthorised firms to stop onboarding EU clients and wind down their activities without delay.

Cyprus moves to the full MiCA authorisation regime
The Cyprus Securities and Exchange Commission has reminded investors that the transitional period under the Markets in Crypto-Assets Regulation ended on 1 July 2026.
Crypto-asset services in Cyprus may now be provided only in accordance with MiCA. Firms that previously operated under national arrangements can no longer rely on the transitional regime to continue serving clients without the appropriate authorisation.
The transition allowed certain providers that were already operating lawfully before MiCA became fully applicable to continue temporarily under existing national rules. That period was designed to give firms time to apply for authorisation or make alternative arrangements, but it did not make those businesses authorised under MiCA. FXTrustScore previously examined how the MiCA deadline is changing crypto access for EU traders, as national registrations and transitional permissions give way to a single authorisation regime.
CySEC issued its warning on 10 July, following a statement from the European Securities and Markets Authority setting out how unauthorised crypto-asset service providers should withdraw from the EU market while protecting their clients.
Unauthorised providers must begin an orderly wind-down
ESMA expects crypto-asset service providers without MiCA authorisation to take immediate steps to end their EU activities. Unauthorised firms should stop onboarding new EU clients, opening new accounts and marketing or soliciting their services within the region. Their remaining activities should be limited to those required to sell or transfer crypto-assets, reallocate client holdings or close existing positions.
Providers may continue holding clients’ crypto-assets only for the period strictly necessary to complete an orderly exit. ESMA also expects firms to communicate clearly and repeatedly with affected customers, explaining what will happen to their assets and the timeframe for transferring or closing their positions.
Where residual positions will be closed automatically, clients should be informed of the relevant deadline and the measures being taken to protect their interests. Anti-money laundering controls, sanctions screening and transaction monitoring must also remain in place throughout the wind-down process.
These requirements are intended to prevent clients from being left without access to their assets or adequate information when a provider loses the right to continue operating.
CySEC warns clients to verify their provider
CySEC has reinforced ESMA’s warning that clients using an unauthorised provider do not benefit from MiCA safeguards, including the protections that apply to the handling of client assets.
Investors and other users have been advised to check whether their provider appears in ESMA’s register of authorised crypto-asset service providers. The register also includes information on entities identified as providing crypto-asset services without the required compliance status.
Clients who discover that their provider is not authorised have been urged to act promptly. Depending on their circumstances, this could involve moving their holdings to an authorised provider or transferring them to a self-hosted wallet, where control and responsibility for securing the assets pass directly to the user.
The legal company serving the customer is especially important. A well-known platform may operate through several entities, and the authorisation held by one part of the group does not necessarily extend to every client, service or jurisdiction.
Offshore platforms remain within the EU regulatory perimeter
ESMA has also addressed crypto platforms established outside the European Union. Third-country firms cannot actively provide MiCA-regulated services to EU clients or solicit business within the region without the required authorisation. This restriction also applies where services are offered to businesses or institutional customers rather than retail users.
A narrow exception exists where a client approaches an overseas provider entirely on their own initiative. However, the reverse-solicitation provision cannot be used as a general route for offshore platforms to market their services, maintain an active EU client base or avoid the MiCA authorisation regime.
ESMA and national regulators are monitoring significant cross-border providers that have continued serving EU clients without authorisation. Where necessary, authorities may coordinate enforcement action, working alongside the European Banking Authority and the EU’s Anti-Money Laundering Authority. The cross-border focus is significant because many crypto platforms provide services digitally without maintaining a substantial physical presence in every country where their clients are located. Online availability does not give a provider the right to serve EU users.
MiCA authorisation does not cover every crypto product
MiCA created a common regulatory framework for crypto-assets and related services that were not already covered by existing EU financial-services legislation. It does not replace the rules governing products that qualify as financial instruments. Crypto CFDs, options, futures and certain other derivatives may instead fall under MiFID II and established product-intervention measures.
A platform authorised as a crypto-asset service provider should therefore not be assumed to hold permission to offer leveraged crypto derivatives. The regulatory treatment depends on the product being offered, the service provided and the legal entity operating the account.
This is particularly relevant as some firms combine spot crypto services, custody, token trading and leveraged products within the same platform. Each activity may sit within a different regulatory framework and carry different protections.
Clients should establish not only whether the platform appears on the MiCA register, but also whether its authorisation covers the specific service they intend to use.
What the change means for crypto firms
The end of the transitional period moves MiCA from implementation into active supervision. Firms that have not obtained authorisation must now concentrate on closing or transferring existing client relationships rather than continuing normal business. Marketing campaigns, new account registrations and attempts to expand within the EU could attract closer regulatory scrutiny.
Providers transferring clients to another company must also ensure that the receiving firm is properly authorised and completes the necessary onboarding and customer-verification procedures. Assets cannot simply be moved between group entities without regard to regulatory status and client consent.
For authorised firms, obtaining a MiCA licence is only the beginning of the supervisory process. They must continue meeting requirements concerning governance, custody, operational resilience, record keeping, communications and the management of client assets.
The first phase of MiCA focused heavily on applications and transitional arrangements. The next will test whether authorised providers are applying the framework effectively in practice.
What investors should check
Clients should verify the name of the legal entity holding their account rather than relying solely on the platform’s trading name. They should then confirm that the entity appears in the ESMA register and that its authorisation covers the relevant crypto-asset service.
Any message stating that a provider is closing an EU account or transferring assets should be checked carefully through the platform’s official website or established support channels. Regulatory change can also create opportunities for impersonation, phishing and fraudulent transfer requests.
MiCA authorisation provides a regulatory framework, but it does not remove the volatility, technology and custody risks associated with crypto-assets. Users must still assess the product itself, understand how their assets are held and consider what access or recovery arrangements are available if the provider experiences financial or operational problems.
EU regulators prepare for coordinated supervision
The end of the transition gives national authorities a clearer basis for acting against providers operating without permission. CySEC’s announcement indicates that Cyprus will participate in the wider European effort to identify unauthorised cross-border firms and protect clients during any required wind-down. Enforcement could involve restrictions on marketing, demands to stop serving local users or coordinated measures involving several national regulators.
Supervision of authorised providers is also intensifying. ESMA has launched a common supervisory exercise examining the digital operational resilience of crypto-asset custody services, including governance, storage and key management, transaction controls, incident response and reliance on third-party providers.
Together, these developments show that the implementation phase is giving way to closer examination of how crypto platforms operate, protect client assets and manage technology-related risks.
FXTrustScore will continue monitoring action by CySEC, ESMA and other European regulators as the MiCA authorisation regime is applied across the market.
Readers can follow further developments through the FXTrustScore Market News Hub, covering the financial and regulatory changes affecting platforms, brokers, traders and investors.