Uneven enforcement kicks in as EU crypto firms lose MiCA’s transition cushion.
As MiCA's grace period expires, lawyers warn unauthorized crypto firms risk multimillion-euro fines while national regulators enforce rules inconsistently.

The European Union’s crypto industry has entered a new enforcement era after the transition period under the Markets in Crypto-Assets (MiCA) regulation officially ended, according to Cointelegraph. Crypto companies that have not secured MiCA authorization can no longer legally serve EU clients and are now expected to wind down operations or face significant fines and other enforcement measures.
Lawyers and industry executives told Cointelegraph that the immediate challenge is not the rulebook itself but how consistently national regulators across the bloc will apply it. While MiCA was designed to create a single EU-wide framework, supervisory approaches are expected to diverge in the early enforcement phase.
Compliance costs versus the price of non-compliance
Becoming MiCA-compliant is not cheap. Nicola Massella, partner at Storm Partners, estimated implementation costs for many crypto companies at between 350,000 euros ($400,000) and 600,000 euros ($690,000). Brickken CEO Edwin Mata said costs can climb as high as 2 million euros ($2.3 million) depending on a firm’s size, services and how prepared it already was.
Still, experts say the financial risk of operating without authorization far outweighs those compliance costs. Eckehard Stolz, managing director of Amina EU, said MiCA penalties for certain violations start at 5 million euros or 5{d19616a33d455f7215be86882b84de16bc0d6d703bafb84e8d0ba56683c22428} of annual turnover. Massella noted that the European Banking Authority proposed on June 26 raising penalties further, to as much as 12.5{d19616a33d455f7215be86882b84de16bc0d6d703bafb84e8d0ba56683c22428} of annual turnover for some stablecoin-related breaches.
National regimes can carry their own steep penalties. The Czech National Bank told Cointelegraph that its Financial Market Digitization Act allows it to fine companies operating crypto services without authorization up to 118.5 million Czech koruna (roughly $5.6 million), 5{d19616a33d455f7215be86882b84de16bc0d6d703bafb84e8d0ba56683c22428} of annual turnover if that figure is higher, or twice the unlawful benefit obtained — whichever amount is greatest.
Who actually enforces MiCA
Although MiCA sets a single EU rulebook, day-to-day supervision falls to national competent authorities (NCAs), which are responsible for authorizing, supervising and enforcing the rules for crypto firms in their jurisdictions. The European Securities and Markets Authority (ESMA) coordinates supervision across member states and maintains the public register of authorized crypto-asset service providers, while the EBA directly oversees significant stablecoin issuers.
“At the EU level, ESMA plays an important coordination and supervisory-convergence role, especially to avoid regulatory arbitrage between member states,” Ivo Grlica, founder of GrlicaLaw and G Lab Advisors, told Cointelegraph. “National regulators are only the first line of MiCA enforcement, but the legal consequences can spread into national courts and criminal-law systems if the underlying conduct causes harm,” he added.
Uneven enforcement expected early on
Because NCAs differ in resources, experience and supervisory priorities, MiCA enforcement is unlikely to be uniform in its initial stages. “ESMA made clear it expects NCAs to act against unauthorized providers from July 1,” Stolz said, noting that how aggressively each regulator moves “will depend on local resourcing and priorities.”
Peter Bidewell, vice president of institutional product adoption at Parfin, warned that differing supervisory approaches could open the door to regulatory arbitrage, undermining MiCA’s core goal of harmonizing crypto rules across the bloc. Grlica said he expects enforcement to become more systematic over time as regulators identify unauthorized providers and share information across member states, making it progressively harder for firms with a history of non-compliance to secure MiCA authorization later.
Several national regulators, including authorities in the Czech Republic, Bulgaria, Luxembourg and Italy, have already issued notices confirming the end of the transition period and urging unauthorized providers to wind down their EU operations. Cointelegraph reported that it contacted France’s Autorité des marchés financiers, the Netherlands’ Authority for the Financial Markets and Germany’s BaFin about their enforcement plans, but none had responded by publication.
Read more: Late MiCA Licensing Rush Sees 36 Crypto Firms Approved Before EU Deadline
Leave a Reply