EU VASPs After MiCA: Authorization Rates and Illicit Exposure
Key takeaways
- MiCA's grandfathering period — the window that let firms already operating under national rules keep going — ended on July 1, 2026, dividing the European Economic Area (EEA)'s crypto service providers into those that gained authorization and those that did not. This analysis compares the two groups on licensing, risk ratings, and direct exposure to illicit funds.
- Roughly one in five of the EEA's crypto service providers — 281 of 1,343 — had gained MiCA authorization when the grandfathering period ended on July 1, 2026. The remaining 1,062 must now exit, restructure, or move their customers to an authorized firm.
- Firms that did not gain authorization are far more likely to be high risk: 12% carry a High or Severe TRM risk rating, against 2% of authorized firms. Every Severe rating belongs to a firm that did not gain authorization.
- Most firms in both groups barely touch illicit funds directly. A small number of unauthorized firms are the exception: they send 1% to 12% of their volume straight to illicit addresses. No authorized firm sends more than 1%.
- Authorization clustered in jurisdictions that built licensing capacity early. Germany, Luxembourg, Cyprus, Malta, and Ireland took most of their operating firms through to full MiCA authorization. Where registers had grown largest under looser national regimes, MiCA became an opportunity to reset them: Lithuania authorized eight firms from a register of more than 400, and Poland none from over 1,800.
{{horizontal-line}}
The pre-MiCA licensing landscape
Europe is one of the largest crypto markets in the world. In 2025, USD 459 billion in crypto asset value flowed to users across the EU-27, of which TRM identified roughly USD 152 million as illicit. That activity reaches users through service providers — exchanges, payment firms, custodians, brokers. Prior to the Markets in Crypto-Assets Regulation (MiCA) entering into force in December 2024, each member state ran its own crypto registration or licensing regime. These regimes varied in how robustly they analyzed the financial crime controls of registered crypto asset service providers (CASPs). TRM observed 383 firms offering crypto services under Lithuanian registration and 241 under Polish registration. Poland's register listed over 1,800, but most never ran observable crypto services. Slovenia had three, and Belgium two. A registration obtained in the most permissive jurisdiction conferred the same nominal legitimacy as authorization in the strictest, and firms chose accordingly. These counts reflect crypto services TRM could identify as operating rather than entries on a register, so jurisdictions without a public register — Czechia among them — are undercounted.

MiCA replaced that patchwork with one standard for authorization. Firms already operating under national law before December 30, 2024 were given a transitional window under Article 143(3) to obtain it. That window closed on July 1, 2026. From that date, a firm without MiCA authorization cannot lawfully provide crypto asset services in the EU.
The result is a market that is split in two. Of 1,343 operating EEA firms, 281 obtained a MiCAR CASP license as of July 1, 2026; the other 1,062 did not. What happens to those 1,062 firms and their customers is the subject of this analysis: which are leaving, what they carry, and how their risk compares with the firms absorbing them.
Customer migration and supervisory risk
The EU's Anti-Money Laundering Authority (AMLA) has set out what it expects to happen next. In an advisory note on the end of the MiCAR transitional period, it identifies three changes: unauthorized VASPs will leave the market, large volumes of customer relationships will move or be terminated, and crypto activity will concentrate among fewer authorized CASPs. Together, AMLA says, these will have a material impact on how the market functions.
AMLA's note groups the risks by who bears them. As unauthorized firms wind down, compressed timelines strain their AML controls, and their exit reduces transparency over where funds and customers go. Authorized CASPs taking on those customers face sudden changes in their own risk profile and pressure on transaction monitoring. Supervisors lose visibility over the transfers between the two.
AMLA asks supervisors to prioritize oversight of exit planning and customer transfers, and to coordinate across borders as customers move. Both are now measurable in advance: the firms most likely to displace customers can be identified before the transfers happen, and 30 of them are rated High or Severe.
TRM tags every EEA entity with its country of supervision and licence status. That makes the two groups directly comparable: 281 entities that obtained a MiCAR license, and over 1,200 that held a national license and did not, which potentially creates challenges for both authorized CASPs and supervisors.
Conversion rates and home authorization
Germany authorized 55 firms; France and the Netherlands 29 each. Malta and Cyprus authorized 20 and 19 — each more than Italy, which authorized 9 of the 145 firms operating there. Malta, Cyprus, Ireland, and Luxembourg together hold 63 of the bloc's 272 identified home authorizations, from registers of just 101 operating firms.
Lithuania authorized eight firms from a register of more than 400, and Poland none from over 1,800. Poland, Greece, and Portugal issued no authorizations of their own.

Supervisory responsibility is concentrating faster than market presence. Germany's BaFin authorized 55 of the 57 licensed firms operating there. Italy hosts 37 and authorized nine; Spain hosts 34 and authorized 12. Passporting lets firms operate bloc-wide while accountability for supervising them sits with a handful of regulators — the condition behind AMLA's warning about uneven AML/CFT standards and regulatory arbitrage.

Risk profiles of the two cohorts
Two questions follow. Are the firms that lost their license riskier than the firms that kept one? And does illicit money actually move through them?
TRM's risk ratings answer the first: yes. 12% of unauthorized firms carry a High or Severe rating, against 2% of authorized firms. Every Severe rating belongs to a firm that did not gain authorization.

Illicit money reaches both groups at similar rates overall — 0.09% of offboarding volume transacted directly to illicit or high-risk counterparties, against 0.07% for licensed firms. In both groups the largest exposures are to high-risk exchanges and gambling services — USD 19.0 billion and USD 15.3 billion for unauthorized firms, against USD 14.2 billion and USD 13.4 billion for authorized.
The most significant divergence was exposure to sanctions risk. Unauthorized firms sent USD 5.0 billion directly to sanctioned counterparties, three times the USD 1.7 billion from authorized firms. Although exposure appears broadly similar across the two groups, the risk is more concentrated among offboarding firms. Half show no measurable illicit exposure, while a small number route 1% to 12% of their volume directly to illicit addresses. As a result, exposure is roughly four times higher for offboarding firms.
Half of all offboarding firms send nothing measurable at all.

HTX, a designated exchange, and Huione Pay, named under US special measures, both held national registrations and never obtained MiCA authorization. So did entities captured by EU Russian-ban measures.
The two groups also differ in composition: exchanges make up 42% of the unauthorized group against 29% of the authorized, and payment firms 16% against 9%. Authorized firms skew toward financial and investment services — 25% and 21%, against 9% and 7%. The High-Risk Exchange category appears only among firms that did not gain authorization.

License volume and jurisdiction risk
Across the 23 jurisdictions with licensed firms carrying measurable volume, there is no identified correlation between the number of authorizations a regulator issued and the illicit exposure of the firms it supervises. The jurisdictions that authorized the most firms are not supervising the riskiest ones.

A CASP license from a high-volume authorizer carries the same weight as one from a selective authorizer. For a financial institution screening counterparties, the number of licenses a jurisdiction has issued says nothing useful about the firms inside it. Entity-level exposure is what separates them.
Onboarding customers from exiting firms
The risk in this migration is concentrated, not general. Most unauthorized firms carry a Low risk rating and negligible direct illicit exposure, which is why AMLA asks firms not to apply blanket de-risking to their customers. The minority that does carry risk is identifiable before the transfer: a receiving CASP can tell a Low-rated payment institution winding down cleanly from an entity carrying 5% direct illicit exposure and a Severe rating. That makes entity-level screening the proportionate response.
{{horizontal-line}}
Frequently asked questions (FAQs)
1. What changed on July 1, 2026?
The MiCAR transitional period — the grandfathering arrangement under Article 143(3) of Regulation (EU) 2023/1114 — ended across the EU. Firms operating under national law before December 30, 2024 could continue providing crypto asset services until that date. After it, a MiCA CASP authorization is required.
2. Does a large offboarding cohort mean a large volume of illicit activity is now unsupervised?
No. Most offboarding entities carry a Low risk rating, and half send nothing measurable to illicit counterparties. The elevated risk is concentrated in a minority of the group, including entities already subject to sanctions or other public measures.
3. Are licensed CASPs uniformly low-risk?
No. Exposure varies among licensed firms, and four of 90 rated licensed entities sit at Medium risk or above. Authorization makes a high-risk rating much less common, but it does not rule one out.
4. Should a firm de-risk counterparties that did not obtain MiCAR authorization?
AMLA's advisory note directs that customers transitioning from unauthorized VASPs be assessed individually under a risk-based approach and not subject to blanket de-risking. On-chain exposure data lets a firm make that assessment on evidence rather than on licence status alone.
5. Which jurisdictions hold the largest offboarding populations?
The jurisdictions that built the largest registers under pre-MiCA national regimes — Lithuania, Poland, and Estonia foremost — authorized the smallest share of them, and so hold the largest offboarding populations.




















