National regulators take the lead as authorization deadline passes

The European Union’s cryptocurrency industry has entered a new enforcement phase as the transition period under the Markets in Crypto-Assets (MiCA) regulation came to an end on July 1, 2026. Unauthorized crypto companies must now cease EU operations or face enforcement action by national competent authorities (NCAs).

MiCA creates a single EU rulebook for crypto regulation, but day-to-day supervision falls to national regulators in each member state. The European Securities and Markets Authority (ESMA) coordinates across borders and maintains the public register of authorized crypto-asset service providers. The European Banking Authority (EBA) directly oversees significant stablecoin issuers.

Several EU regulators issued notices reminding crypto companies the transition period had ended. The Czech National Bank, which can impose maximum fines of 118.5 million Czech koruna (about $5.6 million) for MiCA violations, joined regulators in Bulgaria, Luxembourg and Italy in signaling enforcement intent. The Czech regulator’s Financial Market Digitization Act grants it authority to sanction companies operating without authorization, conducting unlawful token offerings, or failing to cooperate with supervisors.

“ESMA made clear it expects NCAs to act against unauthorized providers from July 1,” said Eckehard Stolz, managing director of Amina EU.

The compliance burden has been substantial. Many cryptocurrency companies face MiCA implementation costs between 350,000 euros ($400,000) and 600,000 euros ($690,000), with maximum compliance costs reaching 2 million euros ($2.3 million) depending on company size and services offered. Violations carry steep penalties: up to 5 million euros or 5% of annual turnover for certain breaches. The EBA proposed even higher penalties for some stablecoin-related violations, reaching 12.5% of annual turnover.

Enforcement consistency across the 27-member bloc remains uncertain. Ivo Grlica, founder of GrlicaLaw and G LAB Advisors, emphasized ESMA’s coordination role: “At the EU level, ESMA plays an important coordination and supervisory-convergence role, especially to avoid regulatory arbitrage between member states.”

However, Peter Bidewell, vice president of institutional product adoption at Parfin, cautioned that differing supervisory approaches could create opportunities for regulatory arbitrage despite MiCA’s harmonization goals. Eckehard Stolz noted that how aggressively each regulator moves will depend on local resourcing and priorities, suggesting enforcement may not be uniform across the EU.

Grlica underscored the stakes beyond administrative penalties: “National regulators are only the first line of MiCA enforcement, but the legal consequences can spread into national courts and criminal-law systems if the underlying conduct causes harm.”

On June 26, the EBA proposed increased penalties under certain regulatory regimes, signaling tougher enforcement posture. France’s Autorité des marchés financiers (AMF), the Netherlands’ Authority for the Financial Markets (AFM), and Germany’s Federal Financial Supervisory Authority (BaFin) have not yet detailed their specific enforcement plans.

What happens next

Crypto companies operating in the EU must now either hold valid MiCA authorization or exit the bloc. National regulators will pursue enforcement actions against those that remain unauthorized. ESMA will monitor NCAs for supervisory consistency and coordinate cross-border supervision where needed.