You knew the date was coming. 1 July 2026 sat on a compliance calendar for months, maybe years, and then it passed, and your business is still here, still serving clients, still moving fiat and crypto across the same rails it always has. Nothing exploded. No regulator called. And that quiet is exactly why this is the moment to get precise about what actually changed, because the absence of an immediate knock is not the same as the absence of exposure.
If you are reading this because your firm was registered as a VASP and never completed a CASP authorization under MiCA, you are not alone. Roughly three-quarters of the market is in a similar position three weeks past the deadline. But "not alone" is not the same as "fine," and the honest answer to what happens next depends on exactly which of a few specific positions your business actually occupies.
This guide walks through what missing the deadline actually means in practice: the wind-down obligation you may have already been required to file, the reverse-solicitation myth that gets repeated in this market as if it were settled law, the enforcement risk that varies sharply by regulator, and the honest range of options left to a business that still wants a legitimate path to EU clients.
Direct Answer
If you missed MiCA's 1 July 2026 backstop without authorization, providing crypto-asset services to EU clients is now a breach of EU law. Unauthorized firms needed a credible wind-down plan filed by 30 March 2026; reverse solicitation is not a general workaround, and at least one regulator, Lithuania, treats continued unlicensed operation as carrying criminal liability.
What Actually Happens If You Missed the MiCA CASP Deadline?
Nothing about your legal position improved by the deadline simply passing quietly. From 1 July 2026 onward, providing crypto-asset services to EU clients without a granted CASP authorization breaches MiCA, Regulation (EU) 2023/1114, full stop, regardless of whether your national regulator has taken any visible enforcement action yet. The absence of a letter, a fine, or a public statement is not the absence of a breach; it is, at most, a lag in enforcement capacity.
What changes in practice depends heavily on which of three positions you actually occupy. A business with a CASP application already submitted and under active review sits in meaningfully better standing than one that never filed anything. A business that filed a credible wind-down plan and is actively offboarding EU clients is in a different, more defensible position again. And a business that has done neither, no application, no wind-down, and is still actively marketing to and onboarding EU clients, carries the most exposure of the three by a wide margin.
| Your position | What it means | Immediate priority |
|---|---|---|
| CASP application filed, under active review | Operating in a supervised queue; not yet authorized but engaged with the process | Push for a realistic timeline; keep the file complete and responsive |
| Wind-down plan filed by 30 March 2026, offboarding underway | Compliant exit path; regulator has visibility into your plan | Execute the wind-down cleanly; document every client transfer |
| Nothing filed, EU clients no longer onboarded but still serviced | Unauthorized, but not actively expanding exposure | File a wind-down plan now, or a CASP application if genuinely viable |
| Nothing filed, still actively marketing and onboarding EU clients | Unauthorized and actively expanding exposure | Stop new EU onboarding today; get a written legal read this week |
What to Consider
- Identify your exact position from the table above, honestly. Businesses regularly overstate how compliant their current posture actually is; a filed application is not an authorization, and "mostly stopped" is not "stopped."
- Silence from your regulator is not clearance. National competent authorities are working through a backlog of roughly 900 unresolved legacy files across the EU; a lack of contact reflects capacity, not a decision in your favor.
- Every week of continued unauthorized activity is a week of accumulating exposure, not a week of the risk fading. Treat the clock as running against you, not in your favor.
- Your banking and payment partners are reading the same public data you are. A bank or EMI that sees your business still listed as unauthorized will act on that information independently of any regulator action.
Final Takeaway: Work out, in writing, which of the four positions above actually describes your business today. That single fact determines everything else in this guide.
Did You Complete the Required Wind-Down Plan by 30 March 2026?
This is the deadline most legacy VASPs never heard about, because it fell three months before the headline 1 July 2026 date and got far less attention. Any business that knew, or should reasonably have known, it would not complete CASP authorization in time needed a credible, immediately executable wind-down plan in place by 30 March 2026: offboarding EU clients, transferring their assets to an authorized CASP or a self-hosted wallet, and giving prior notice of the exit.
A wind-down plan filed on time is not a formality; it is the difference between an orderly, defensible exit and a business that simply stopped serving EU clients with no paper trail explaining why or how. Regulators reviewing a legacy file after the fact will look for exactly this kind of documentation, and its absence is read as a business that either did not understand its obligations or chose to ignore them.
If you did not file a wind-down plan by that date and have also not completed authorization, you are, honestly, in the least defensible of the positions covered in this guide. That does not mean the situation is unrecoverable, but it does mean the honest next step is a wind-down or a fresh application filed now, not a wait-and-see posture that has already cost three and a half months.
Example
A composite mid-sized custody provider, previously VASP-registered in a non-Baltic EU state, correctly assessed in early 2026 that it would not complete CASP authorization in time given its capital position. It filed a wind-down plan on 18 March 2026, twelve days before the deadline, offboarded roughly 40 EU-based clients over the following ten weeks with documented asset transfers to two separately authorized CASPs, and formally ceased EU-facing operations before the 1 July backstop. Its exit drew no regulatory inquiry, precisely because the plan was filed early and executed as described.
What to Consider
- Check whether a wind-down plan was ever actually filed for your business, not just discussed internally. A plan that existed only as an internal decision carries none of the protective value of one submitted to the regulator.
- Document every client transfer if you are winding down now, late. A late wind-down executed with full documentation is still meaningfully better than an undocumented one.
- Prior notice to clients is part of the obligation, not an optional courtesy. Clients moved without notice can themselves raise the profile of your exit with a regulator.
- A late wind-down plan is still better than none. Filing now, three weeks past the backstop, is a materially different position than never filing at all.
Final Takeaway: If no wind-down plan was ever filed and you are not pursuing authorization, file one now. Late and documented beats undocumented and silent.
Can Reverse Solicitation Let You Keep Serving EU Clients Without a License?
This is the single most common myth circulating in this market right now, and it deserves to be debunked plainly rather than hedged. Reverse solicitation, the idea that a business can lawfully serve EU clients if the client, unprompted, initiates the contact themselves, is a real and narrow concept under EU financial services law. It is not, and was never intended to be, a general license substitute for a business that simply did not complete authorization in time.
ESMA interprets reverse solicitation narrowly, and that narrowness is the entire point being missed by businesses leaning on it as a workaround. A client reaching out on their own initiative, with zero prior marketing, advertising, or targeted outreach from your business into the EU, is a genuinely different scenario from a business that maintains an EU-facing website, runs EU-targeted advertising, or has previously solicited EU clients and is now simply waiting for inbound contact to claim the exemption retroactively.
| Scenario | Covered by reverse solicitation? |
|---|---|
| Client contacts you entirely unprompted, no prior marketing or targeting into the EU | Potentially, on a narrow, case-by-case basis |
| Your website is EU-facing, in EU languages, or references EU jurisdictions | No, this is treated as active solicitation |
| You previously advertised or marketed to EU clients before the deadline | No, prior solicitation taints the relationship going forward |
| You continue onboarding new EU clients through any outbound channel | No, this is new solicitation, not passive receipt of inbound contact |
Reality Check
Reverse solicitation is not a workaround, and treating it as one is the single riskiest assumption a legacy VASP can make right now. ESMA reads the exemption narrowly, any EU-facing marketing or prior solicitation taints it, and leaning on it as a general strategy is how a business converts an administrative lapse into something closer to a deliberate breach. Layer on enforcement: at least one national regulator, Lithuania, frames continued unlicensed operation as carrying criminal liability, not merely a civil or administrative penalty. No one can talk a regulator out of that framing after the fact with a reverse-solicitation argument built on a website that was never EU-blind to begin with.
What to Consider
- Audit your own marketing honestly. If your website, app store listing, or advertising has ever targeted EU users, languages, or jurisdictions, reverse solicitation is very unlikely to cover your existing EU book.
- "The client found us" is not the same as "we never solicited." Regulators look at the totality of your outward-facing presence, not just the specific first message in a given relationship.
- Do not build a compliance strategy on an exemption you are hoping applies. If reverse solicitation is your primary plan, get a written opinion from qualified EU counsel before relying on it for a single additional client.
- Treat any adviser who pitches reverse solicitation as a clean, general fix with real skepticism. It is a narrow carve-out, not a license alternative.
Final Takeaway: Stop treating reverse solicitation as your compliance plan. If it is the only thing standing between your business and unauthorized operation, that is the problem to solve, not the solution.
What Enforcement Risk Do You Actually Face for Operating Unauthorized?
Enforcement risk is not uniform across the EU, and pretending otherwise understates the exposure in some member states while overstating it in others. What is consistent everywhere is the underlying legal position: operating as a crypto-asset service provider without CASP authorization is a breach from 1 July 2026 onward, in every member state, without exception.
Where jurisdictions diverge is in framing and consequence. Lithuania is notably explicit: its national approach frames continued unlicensed operation as carrying potential criminal liability, not just administrative sanction. Other member states apply administrative fines, cease-and-desist orders, and public warning notices as their primary tools, at least in the first instance, with criminal referral reserved for more serious or willful cases. The variance matters for risk planning, but it is not a reason to relax in a jurisdiction with a softer public posture; enforcement priorities shift, and a quiet regulator today is not a guarantee of a quiet regulator in six months.
There is also a practical, non-regulatory enforcement channel worth naming: your banking and payment partners. A bank or EMI that identifies your business as an unauthorized crypto-asset service provider operating in the EU has its own independent obligation to act, typically by restricting or terminating the relationship, regardless of whether your national regulator has taken formal action. In practice, this commercial channel often moves faster than the regulatory one.
What to Consider
- Know your specific national regulator's stated enforcement posture, not the EU-wide generality. Lithuania's criminal-liability framing is not universal, but assume any jurisdiction can escalate.
- Your bank may act before your regulator does. Unauthorized status is discoverable through public registers, and financial partners increasingly screen against them directly.
- A quiet enforcement environment is not evidence of safety. It reflects current regulatory capacity and priorities, both of which can change without warning.
- Willful continued operation reads worse than a documented, in-progress remediation. The posture you can demonstrate matters as much as the underlying facts.
Final Takeaway: Do not calibrate your risk tolerance to the quietest regulator in the room. Assume enforcement capacity catches up, and get your file moving before it does.
Is an EU-Authorized Affiliate Structure a Viable Workaround?
One structuring approach some firms are exploring is routing EU client relationships through a genuinely substantive, separately CASP-authorized affiliate, while the original entity continues operating non-EU business under its existing arrangements. The logic is straightforward: if the entity actually serving EU clients holds its own real authorization, with its own capital, governance, and local substance, the EU-facing activity is compliant regardless of the parent or sister entity's status elsewhere.
It is important to be precise about what this is and is not. This is informed industry commentary and a structuring approach some firms are actively exploring, not confirmed ESMA policy or a pre-approved regulatory pathway. A shell affiliate with no genuine substance, no real staff, no real decision-making authority, set up purely to hold a license on paper while the actual business continues as before, does not achieve the same outcome and may draw more scrutiny than doing nothing at all.
Done properly, this is exactly the kind of complex structuring question that benefits from specialist advice rather than a generic guide. It touches jurisdiction selection, capital allocation, transfer pricing between entities, and a genuine assessment of whether the affiliate can meet local-substance requirements in practice, not just on an incorporation certificate.
What to Consider
- Substance is the entire test. A CASP-authorized affiliate needs its own real governance, staff, and decision-making, not a registered address borrowing the parent's operations.
- This is a structuring project, not a document you file once. Treat it as a multi-month undertaking with real cost, not a quick fix ahead of a deadline.
- Get this evaluated by specialists before committing capital to it. The gap between "informed industry approach" and "confirmed regulatory position" is exactly where a poorly executed structure fails.
- Weigh it against a straightforward wind-down or fresh application. For some businesses, the affiliate route is genuinely the right answer; for others, it adds cost and complexity without removing the underlying exposure.
What Should You Do Next If You Are Still Unauthorized?
Start by getting an honest, written answer to where your business actually sits, using the four positions set out earlier in this guide. Everything downstream, whether you file a wind-down plan now, push forward a CASP application, or evaluate an affiliate structure, depends on that single fact, and guessing at it is the most common and most avoidable mistake at this stage.
From there, the honest options are limited but real: complete a CASP application if your business model and capital position still make that viable, file and execute a proper wind-down if it does not, or evaluate a genuine EU-authorized affiliate structure if your situation calls for something more nuanced than either extreme. What is not a real option, three weeks past the backstop, is continuing exactly as before while hoping the reverse-solicitation exemption retroactively covers activity it was never designed to cover.
What to Consider
- Get your exact position confirmed in writing this week, from counsel or a specialist, not from your own read of the regulation.
- Treat every additional week of unauthorized EU activity as adding risk, not reducing it. There is no version of this situation that improves simply by continuing unchanged.
- Compare the realistic cost and timeline of authorization against wind-down before choosing. Capital tiers run from €50,000 to €150,000 depending on your service mix, and honest end-to-end timelines run four to twelve months, so weigh that runway against the cost of an orderly exit.
- Do not let a single adviser's confidence in reverse solicitation or an affiliate structure substitute for your own written risk assessment.
Final Takeaway: Confirm your exact position, then choose one of the three real paths, authorization, wind-down, or a properly built affiliate structure, deliberately. The one path that is no longer available is unchanged business as usual.
Conclusion
Missing the MiCA deadline did not end your business, and it did not, on its own, guarantee enforcement action either. What it did was remove the ambiguity: from 1 July 2026, serving EU clients without CASP authorization is a breach, the wind-down obligation for firms that saw this coming fell three months earlier on 30 March 2026, and the reverse-solicitation exemption that gets cited as a workaround was never built to cover what it is currently being asked to cover.
The businesses that come out of this period cleanly are the ones that get precise about their actual position now, rather than several months from now when a regulator or a banking partner forces the question. Whether that means finishing an authorization, executing a documented wind-down, or building a genuinely substantive affiliate structure, the honest first step is the same: find out, in writing, exactly where you stand.
How BankMyCapital Helps
We are not a bank, an EMI, or a law firm, and nothing here is legal advice. What we do is help you get precise about which of the positions in this guide actually describes your business, read the realistic path from there to either a granted CASP authorization or a properly executed wind-down, and, where it genuinely fits, work through structuring questions like an EU-authorized affiliate model as one option among several, honestly framed rather than oversold. Full detail on the authorization itself, its capital tiers, and its jurisdiction picture lives on our crypto licensing practice, including the dedicated CASP license page.