290 firms, one deadline: the wave of MiCA authorisations before 1 July 2026
We pulled ESMA's own public register of crypto-asset service providers (CASPs) authorised under MiCA. Of the 290 firms authorised before the 1 July 2026 transitional deadline, 98.6% cleared authorisation in the 18 months before it — almost an entire industry, newly licensed, now meeting DORA, MiCA surveillance and AML obligations for the first time, all at once.
1. It's a brand-new industry
Of the 290 firms, 286 were authorised in 2025 or 2026 — 147 in 2025 and 139 already in the first half of 2026. Only four predate that. These are, overwhelmingly, firms that cleared authorisation in the last stretch before the deadline and now face the full stack of EU obligations at once, with no prior run at any of it.
2. Spread across 25 countries — no single market dominates
Germany, France and the Netherlands are each the largest individual markets, but together they still account for well under half the cohort — 40%. The other 60% spans 22 more countries, starting with two much smaller states punching well above their size: Malta (22) and Cyprus (21) each come within single digits of France and the Netherlands' own totals, then the tail continues through Spain, Ireland, Luxembourg and 17 more.
3. The obligations are stacking, right as authorisation lands
Newly-authorised or not, every firm here faces several regimes at once, with overlapping 2026 timelines:
- DORA — an annual Register of Information, already in force, machine-validated by regulators;
- MiCA Article 92 — a working market-abuse surveillance system, required from authorisation (the transitional window closed 1 July 2026);
- AML/CFT — a full programme under the new EU AML rulebook;
- The Cyber Resilience Act — for any firm shipping a wallet app or device, vulnerability reporting from September 2026.
A firm authorised in the first half of 2026 is meeting all of this for the first time, with no prior filing cycle to have learned from — and most of this cohort is exactly that.
Why it matters
The narrative around crypto regulation tends to focus on the big exchanges. The quieter story is 290 firms, most of them newly authorised, now carrying institution-grade obligations with whatever compliance resourcing they had on day one — the deadline behind them, the workload very much not. How that cohort copes is a real test of whether MiCA's regime works in practice, not just on paper.
Run the checks this cohort now needs
See the compliance tools →Figures are computed directly from ESMA's public interim MiCA CASP register (CASPS.csv), pulled September 2026, and describe the population, not any firm's compliance status. Reproduce the findings freely with attribution to CleanDesk (cleandeskhq.com) and a link to the source register.