Published: July 13, 2026 | Reviewed by Xenia Neophytou, Founder and Managing Director of CX Financia. As a Fellow Chartered Certified Accountant (FCCA), CySEC Advanced License Holder, and specialist in MiCA transitions and AML/CFT compliance framework design, Xenia ensures this analysis aligns precisely with current European supervisory realities and CySEC operational expectations. (Ref: Ax)
From application to supervision
Category: Fintech & Licensing Updates
For crypto-asset service providers, the application deadline has passed and the focus has moved to supervision, implementation and evidence. With the transitional period closed on 1 July 2026, the grandfathering arrangements that let firms keep operating under national regimes have ended across the European Union and the wider EEA. A firm is now either authorised, in a live application where its national competent authority has expressly allowed it to continue limited activity, or outside the permitted regime.
The question is no longer whether authorisation can be obtained. It is whether the business can operate under continuous supervision — and show it. For firms navigating this structural shift, securing ongoing support from a dedicated Regulatory Compliance & AML Advisory is critical to defending an operational license.
What supervision looks like now
The compliance environment for a CASP now runs well beyond the foundational rules outlined in our primary brief on Markets in Crypto-Assets (MiCA) Explained. The ESMA register, national competent authority expectations, the Travel Rule under the Transfer of Funds Regulation, the Digital Operational Resilience Act (DORA) and the wider EU AML rules all sit inside the same supervised environment. A licence is central to it, but it does not close it.
The ESMA register has become the public reference point for clients, counterparties, banking partners and regulators. Authorisation status should be checked directly against the ESMA Interim MiCA Register, which is updated regularly using information provided by national competent authorities and the EBA. For firms, banks and counterparties carrying out due diligence, this downloadable list of authorised crypto-asset service providers has become a necessary verification point for onboarding, banking and counterparty checks. The register also includes a public list of non-compliant entities, which underlines the reputational risk of failing to meet requirements. The data should be read carefully: the authorised services, home Member State, competent authority and passporting rights are all explicitly set out within the registry fields.
Two points follow. First, the EU passport — the most valuable feature of MiCA — only becomes available on full authorisation. A firm operating under transitional cover could serve only its home market; authorisation is what opens a market of some 450 million people from a single regulatory home. Second, firms that did not secure authorisation are expected to exit in an orderly way. ESMA’s MiCA Digital Finance Portal has been explicit that unauthorised providers must stop onboarding new EU clients, cease marketing and solicitation, and limit activity to what is needed for an orderly wind-down that protects existing clients. Supervision now reaches both the authorised and the departing.
From authorisation to execution
An application file describes how a firm intends to operate. Supervision tests whether it actually does. The most common weakness we see is not a missing policy but a gap between a well-drafted application and the day-to-day operating model of the business. Once a firm is authorised, that gap stops being a documentation point and becomes a supervisory risk.
In practice, a common weakness is that the application file describes a strong governance structure, but the evidence trail is weak: board minutes record approval but not challenge, outsourcing reviews are not documented, and compliance monitoring has never tested the actual crypto-asset workflows. These are exactly the issues that become visible after authorisation.
For Cyprus firms, navigating the Fintech & Payments Licensing framework marked the end of the preparation stage and the start of the implementation test – the point at which the operating model has to match the file that was submitted.
What CASPs must evidence now
Operational teams should read the areas below alongside the ongoing CASP compliance obligations in Cyprus and the wider MiCAR compliance requirements for CASPs. The aim is not to hold a document for each item, but to show the item working.
A. Governance and substance
Supervisors expect real decision-making inside the authorised entity: an effective board, genuine senior-management involvement, and enough local presence to run the firm rather than to receive instructions from elsewhere. The “letterbox entity” — a licence in one place and the actual business somewhere else — is precisely what supervision is designed to expose.
B. Capital and prudential monitoring
Own funds are not an application formality. They must be monitored continuously against the firm’s prudential class, and they must be qualifying capital — paid-up share capital, share premium or retained earnings — not crypto-assets held on the balance sheet. A firm that treats its capital position as something checked once, at licensing, has already fallen behind.
C. Policies and controls
A policy is evidence only if it operates. Compliance monitoring, risk assessment and internal reporting show whether controls actually work, where they are failing, and what is being done about it. The test a board should apply is simple: can we prove this policy is understood, applied, monitored and challenged?
D. Client-asset safeguarding and custody
Where a firm holds client crypto-assets, it must evidence segregation from its own assets, regular reconciliation, disciplined wallet governance, sound key management and clear, complete records. This is the area where a single control gap can translate directly into client loss, and supervisory attention matches that.
E. Travel Rule and AML/CFT
Originator and beneficiary information must accompany transfers, including CASP-to-CASP flows and transfers involving self-hosted wallets. Behind that sit transaction monitoring, sanctions and PEP screening, and a documented framework as detailed in our guide to the Firm-Wide Risk Assessment: AML Compliance which must reflect the firm’s actual client base rather than a generic template. Verification parameters for these asset transfers are governed directly under the official EU Transfer of Funds Regulation (TFR) standards.
F. DORA and operational resilience
Operational resilience is now part of compliance, not a separate IT concern. ICT risk management, incident classification and reporting, oversight of ICT third-party providers, cyber controls and tested business-continuity arrangements are all supervised. For most CASPs, technology is the business, which makes DORA central rather than peripheral.
G. Client protection and complaints
Disclosures, complaints handling, conflicts-of-interest management and, where relevant, suitability or appropriateness assessments must be built into the client journey rather than bolted on. Client protection is judged by what a customer actually experiences, not by what a manual says should happen.
H. Data, records and supervisory evidence
A CASP must be able to produce clear, accurate and complete records to its regulator at short notice. Data structures and record-keeping specifications can be checked against the technical ESMA Interactive MiCA Single Rulebook parameters. To stay ahead of algorithmic oversight, firms should leverage dedicated Regulatory Reporting Services in Cyprus to eliminate data discrepancies before submission.
If your board wants to know whether these controls work in practice, CX Financia can run a focused MiCA operational readiness review for Cyprus CASPs and EU groups.
Cyprus and the wider EU
Cyprus remains an active MiCA jurisdiction, with CySEC now supervising CASP authorisation and implementation under the EU rules. The ESMA register shows a number of CASPs authorised through CySEC, including established operators. The current status of these active providers can be verified via the official CySEC Crypto Asset Services Providers Registry, while existing Cyprus CASPs were required to apply for MiCA authorisation by 27 February 2026.
For firms already regulated in Cyprus, there is also a route worth understanding. Under MiCA Article 60, an investment firm may provide equivalent crypto-asset services after notifying its competent authority at least 40 working days before it begins — a structurally efficient option where the services line up with existing permissions. It is not a way around substance, but it can shorten the road.
Across Cyprus and the wider Union, the recurring themes are the same: real local decision-making, board minutes that evidence active oversight and genuine challenge, a compliance-monitoring function that is actually implemented rather than just written down, controlled outsourcing to group entities, and AML, Travel Rule and DORA arrangements aligned with real workflows. In our work with regulated firms and crypto-related businesses, the most useful question is rarely whether a firm has a policy. It is whether the firm can prove the policy is understood, applied, monitored and challenged. That single question tends to predict how a supervisory visit will go.
For firms considering a rapid entry setup or a structured shift into the European market, utilizing established Licensed Entities for Sale remains a viable path to acquire ready-made corporate structures that match local substance demands.
MiCA, PSD2 and payment-related activity
Some CASPs operate close to the payments perimeter. Where crypto-asset services overlap with e-money tokens, fiat settlement or payment-like functionality, the MiCA and PSD2 dual licensing analysis becomes especially relevant. A CASP offering EMT-based wallets with fiat on and off ramps, for example, may raise PSD2 payment-institution questions; resolving that early avoids friction between CySEC and the relevant payments authority later. Whether a second authorisation is needed is far cheaper to answer before launch than after a supervisor raises it.
MiCA is still evolving — but current obligations are not on hold
MiCA is being reviewed even as it is enforced. The European Commission’s targeted consultation on the review of MiCA is open until 30 September 2026, examining stablecoins, DeFi, staking, lending and borrowing, NFTs, tokenised assets, the boundary with MiFID II, and CASP prudential and reporting obligations. In July 2026 the European Parliament adopted a position asking the Commission to assess how DeFi, staking, lending and NFTs should be treated. The Commission’s own report is expected in 2027, and any change to the law would follow from there.
The important point for a board is what the review does not do. It does not suspend any current obligation. CASPs must comply with MiCA, the Transfer of Funds Regulation, DORA and AML rules as they stand today while watching where the rules may go. The intended direction is clear, but firms that invested early in real compliance are, if anything, better placed for whatever comes next.
A practical board agenda for the next 90 days
A short, disciplined programme of work will tell a board most of what it needs to know about its supervisory readiness:
- Confirm the firm’s authorisation status, service scope and passporting position, and check they still match the business as run.
- Review whether the current operating model matches the application file, and close any gaps between the two.
- Test governance and local-substance evidence — board minutes should show oversight and challenge, not just decisions.
- Review outsourcing and group arrangements, with particular attention to where substance and control actually sit.
- Test client-asset safeguarding: segregation, reconciliation, wallet governance and key management.
- Review Travel Rule controls for CASP-to-CASP and self-hosted wallet transfers.
- Test DORA incident escalation, ICT third-party oversight and business-continuity arrangements.
- Update client disclosures, complaints handling and conflicts-of-interest procedures.
- Review the compliance-monitoring programme and internal-audit plan, and confirm at least one cycle has actually run.
- Prepare clear management information so the board can see, not just be told, how the firm is performing.
- Assess any MiCA/PSD2 overlap arising from EMT or payment-related activity.
Practical questions CASPs should be asking now
If a CASP is not listed in the ESMA register, can it still serve EU clients?
After the transitional period, authorisation status must be verified against the ESMA register before onboarding or continuing a relationship. Reverse solicitation is narrow and should not be treated as a business model or a substitute for authorisation.
Can a non-EU group company continue supporting an EU CASP?
Yes, but only where the outsourcing is controlled, documented and capable of being supervised. The EU CASP remains responsible for the outsourced activity and cannot become a letterbox entity that simply passes work to the group.
What evidence will supervisors expect after authorisation?
Board minutes, compliance-monitoring reports, AML alerts and their dispositions, Travel Rule records, complaints logs, custody reconciliations, outsourcing reviews, incident registers and staff training records — in each case showing the control operating, not merely existing.
How should CASPs treat self-hosted wallet transfers?
Self-hosted wallets are not outside the rules. CASPs must collect the required originator and beneficiary information and, for transfers above EUR 1,000, take reasonable steps to verify whether the client owns or controls the self-hosted wallet involved.
Should CASPs wait for the MiCA review before updating compliance?
No. The review may lead to future change, but current MiCA, Transfer of Funds Regulation, DORA and AML obligations apply now and are being supervised now.
Compliance is now operational
Compliance is now an operational reality. The question is no longer only whether your firm has a license, but whether you can continuously demonstrate—through records and daily practice—that your governance, controls, client protection, resilience, and reporting frameworks work under active regulatory scrutiny. To successfully align your operating model with ongoing European expectations and defend your business license, partner with the specialists at CX Financia.
Schedule an operational readiness review today through our primary Regulatory Compliance & AML Advisory.
