Skip to main content

MiCAR (EU)

What the European crypto-asset regulation is, why the EU created it, which tokens it distinguishes, whom it obliges and what it expressly does not govern. Explained for companies that want to use stablecoins.

The European Markets in Crypto-Assets Regulation (MiCAR) governs who may issue crypto-assets in the EU and offer services related to them. For a company that wants to pay or be paid in stablecoins, it is the framework against which providers and tokens can be checked. This article explains what the regulation is, why it exists and where its limits lie.

One Common Framework Instead of National Rules

Before MiCAR, most crypto-assets in the EU were not covered by common rules. Where rules existed, they were national. The European Commission saw several problems in this when it presented its proposal in 2020 as part of its digital finance package. Diverging rules invited providers to pick the most lenient location and distorted competition. Providers found it hard to scale their business across borders. Consumers and investors were exposed to substantial risks without uniform protection.

Stablecoins raised a further concern. In the Commission's assessment, they pose additional challenges for financial stability and monetary policy once they are widely used. The regulation was therefore meant to do two things: support innovation and fair competition, and protect consumers, market integrity and stability. One example of the second aim is a ceiling. For a foreign-currency stablecoin such as a US dollar token, thresholds apply to its use as a means of payment within a currency area. If they are exceeded, its issuer must stop issuing new tokens.

Four years passed between proposal and application:

DateStep
2020Commission proposal as part of the digital finance package
30 June 2022provisional agreement between Parliament and Council
20 April 2023approval by the European Parliament
16 May 2023adoption by the Council
9 June 2023publication in the Official Journal of the EU
30 June 2024rules for stablecoins (ARTs and EMTs) apply
30 December 2024regulation fully applicable
1 July 2026end of the longest transitional period for existing service providers

As a regulation, MiCAR applies directly in all member states. Unlike a directive, it does not first have to be transposed into national law.

Three Kinds of Crypto-Assets

The regulation defines a crypto-asset broadly. It means a digital representation of a value or of a right that can be transferred and stored electronically. The technology used is distributed ledger technology (DLT) or something similar. That covers a euro stablecoin as well as Bitcoin or a token that gives access to a service. Within this set, MiCAR distinguishes three categories, and the issuer's obligations depend on the category:

For the holder, the category has tangible consequences. Whoever holds an e-money token has a claim against the issuer and can redeem it at any time at par value, free of charge. The issuer of an ART must hold a reserve that is legally segregated from its own estate. Its creditors cannot reach that reserve in insolvency. The white paper of an ART must be approved by the supervisor. The white paper of another crypto-asset, by contrast, is only notified. According to the European Securities and Markets Authority (ESMA), no authority has reviewed it. How stablecoins work economically and how issuers keep their value stable is explained in the stablecoin fundamentals.

Whom the Regulation Obliges

MiCAR addresses two groups. The first are issuers and offerors: anyone who issues crypto-assets in the Union, offers them to the public or seeks their admission to trading. The second are crypto-asset service providers (CASPs). The regulation lists ten such services. They include custody for clients, operating a trading platform and exchanging crypto-assets for funds or for other crypto-assets. Executing and transmitting orders, advice, portfolio management and transfers on behalf of clients are on the list as well.

Anyone who wants to provide one of these services in the EU needs authorisation. Institutions that are already supervised, such as banks, investment firms or electronic money institutions, can offer them under certain conditions without a separate MiCAR authorisation. An authorisation is valid throughout the Union. After notifying its home authority, a provider may operate in all other member states without a physical presence there. Providers already active under national law before 30 December 2024 could continue without MiCAR authorisation until 1 July 2026 at the latest.

As a rule, those who merely use crypto-assets are not among the addressees. A company that accepts a stablecoin, pays with it or holds a balance for itself provides no service to clients and issues no token. The regulation protects it as a client but places no obligations on it. Where the line runs for custody and what an authorised custodian owes is covered in Custody & Safekeeping.

What MiCAR Expressly Does Not Govern

Not every token falls under the regulation. The main exclusions concern assets that already have their own rules, and some types of institutions:

The regulation names further exclusions, for instance for funds.

Who Supervises

Issuers and service providers are authorised and supervised primarily by national authorities, which each member state designates. In Germany, this is the Federal Financial Supervisory Authority (BaFin). In ESMA's register, it is listed as the competent authority for German service providers. If the regulation classifies an ART or an e-money token as significant, the European Banking Authority (EBA) steps in. It supervises the issuer of a significant ART itself. For a significant e-money token of an electronic money institution, it monitors certain additional obligations.

ESMA keeps a central register. It lists authorised service providers, issuers of ARTs and e-money tokens, white papers for other crypto-assets and entities that provide services without authorisation. For a company, it is the first place to check a provider.

One Offer, Three Checks

A plastics processor with revenue of around 90 million euros receives an offer from a payment service provider. A large customer in the Netherlands could settle its invoices in a euro stablecoin in future. The provider would convert the amounts into euros immediately and credit the company's business account. Before signing, the commercial management wants to know what it is getting into. MiCAR offers no recommendation for this, but it does provide three points that can be verified.

The first concerns the token. If ESMA's register lists its issuer as an issuer of e-money tokens, an authorised institution stands behind it. The holder has a claim to redemption at par against that institution. The second concerns the provider. It needs authorisation as a crypto-asset service provider or must be entitled to offer these services as an already supervised institution. If it is based in another member state, the EU-wide authorisation makes that no obstacle. The third concerns the company itself. It accepts payments and has them converted; it provides no service and therefore needs no authorisation.

For the finance function, the model is deliberately simple. Because the provider converts immediately, hardly any token balance builds up. That sidesteps a question MiCAR answers clearly: neither the issuer nor a service provider may pay interest on e-money tokens. How quickly the provider credits the euros and who is liable for a disruption during conversion is not in the register but in the contract. Know your customer (KYC) checks at the start of the relationship take time and belong in the project plan.

Where the Regulation Does Not Help

ESMA's register is not updated in real time. According to ESMA's own notice, new information from national authorities does not appear immediately. A withdrawn authorisation remains listed with the date of withdrawal. Anyone who only looks at the name will miss the end date.

Providers outside the EU need no MiCAR authorisation if a client in the EU approaches them exclusively on its own initiative. As soon as such a provider solicits clients in the EU, through whatever channel, that exemption no longer applies. A company working with such a platform relies on a condition it can hardly verify itself. The information that has to accompany transfers between providers, known as the travel rule, is covered in the cross-cutting article on compliance and reporting.

Authorisation as Master Data

MiCAR makes part of the question of trust something that can be looked up. The token category, the issuer, the authorised service provider and the competent authority can be checked in the register and the white paper. Such information belongs where a company already keeps its business partners. A concrete building block is a field in the supplier and customer master data of the ERP system (enterprise resource planning). It records the register entry and the date of the check for each crypto service provider. Because the ESMA register is not real-time and authorisations can be withdrawn, the field needs a follow-up date. Without it, every department checks the provider again, or none does.

Sources & Date

  • •ESMA, Interactive Single Rulebook – Markets in Crypto-Assets Regulation (MiCA), consolidated text – (wording of Articles 2, 3, 4, 16, 23, 36, 48, 49, 50, 58, 59, 61, 65, 93, 117, 143 and 149; read on 15 September 2026)
  • •European Parliament, Legislative Train Schedule – Proposal for a regulation on markets in crypto-assets – (reasons for and aims of the Commission's 2020 proposal in the digital finance package; legislative steps up to publication on 9 June 2023)
  • •ESMA – Markets in Crypto-Assets Regulation (MiCA), Interim MiCA Register – (authorised service providers with their competent authority, issuers of ARTs and EMTs, white papers, non-compliant entities; notice that information is not displayed immediately and that white papers have not been reviewed by any authority)

As of: 15.09.2026

←Back to Regulation overview