The Grace Period Is Over: Crypto Services in Cyprus After MiCA
- Jul 17
- 7 min read
On 1 July, the EU's single crypto rulebook fully took over. Within days, CySEC had issued two warnings - one to firms, one to investors. Here is where that leaves Cyprus crypto businesses, and everyone who deals with them.

Two dates in July tell the whole story. On 1 July 2026, the transitional period under the EU's Markets in Crypto-Assets Regulation - the “grandfathering” window that had allowed crypto businesses to keep operating under Cyprus's old national rules - expired. And on 9 July, CySEC issued a circular warning regulated firms to strengthen their anti-money-laundering controls, drawing on new guidance from AMLA, the EU's anti-money-laundering authority, about the risks that emerge precisely as a market like this one restructures.
A day later came a second, less noticed warning - this one aimed at investors rather than firms. Echoing a fresh public statement from ESMA, CySEC reminded the market that clients of unauthorised crypto-asset providers do not benefit from MiCA's safeguards, including its protections for client assets.
Read together, the two warnings describe the same event from opposite sides. The regulator is telling crypto firms that the way they exit the market matters. And it is telling everyone else that who they deal with now matters in a way it did not a month ago.
What actually changed on 1 July?
IN PLAIN TERMS A CASP - a crypto-asset service provider - is any business offering regulated crypto services: operating an exchange or trading platform, holding or administering crypto for clients, executing orders, or advising on crypto-assets. From 1 July 2026, providing these services to EU clients requires authorisation under MiCA. Registration under the old Cyprus national regime is no longer enough - that register existed to bridge firms into MiCA, not as a permanent alternative. |
The mechanics were set well in advance. Under Article 143(3) of MiCA, firms lawfully operating before 30 December 2024 could continue under national arrangements until 1 July 2026, or until their MiCA application was decided - whichever came first. Cyprus adopted that transitional window in full, and CySEC set 27 February 2026 as the deadline for existing providers to lodge a complete authorisation application. Cyprus has been one of MiCA's more active jurisdictions through the transition; KPMG counted roughly a dozen Cyprus firms authorised or in the authorisation pipeline as the period closed.
What is being replaced is worth a sentence, because it explains why the change is structural rather than cosmetic. The old Cyprus framework was an AML-focused national registration regime, built under the island's money-laundering legislation as amended in 2021 - a register, in essence, rather than a full prudential licence. MiCA replaces that patchwork of national regimes across all 27 member states with a single authorisation carrying capital requirements, governance standards, client-asset safeguards, and - the commercial upside - a passport: authorised once, a CASP can notify its way into every other EU market rather than seeking permission country by country.
The three positions a crypto firm can now be in
As of this month, every crypto business touching Cyprus falls into one of three positions, and the differences between them are stark.
Authorised. Firms holding a MiCA authorisation from CySEC - or passporting one in from another member state - continue operating, now under a single rulebook valid across the EU. For them, 1 July changed the compliance framework, not the business.
Caught mid-process, or out of time. This is the position that surprises people. A firm that filed by the February deadline but hasn't yet received a decision cannot simply carry on while it waits: the transitional right to operate ended on 1 July regardless of where an application stands in the queue. A pending application is not permission. And a firm that never filed must submit a wind-down plan and cease ordinary regulated activity - continuing to provide crypto services without authorisation is now unlawful, full stop.
Starting fresh. The February deadline applied only to firms transitioning from the old national regime. A new entrant can apply to CySEC for MiCA authorisation at any time - the difference is that it must wait for the licence before serving a single client, rather than operating while the application is considered.
It is worth being honest about what that application involves, because the bar is materially higher than the old registration ever was. A MiCA authorisation is a full licensing exercise: minimum capital scaled to the services provided, a governance framework with fit-and-proper management, documented safeguarding arrangements for client assets, business continuity and conflicts policies, and an application file complete enough to survive a regulator's first review - incomplete or internally inconsistent files have been a recurring cause of withdrawn applications during the first MiCA review cycle. For a serious operator, none of this is prohibitive. It is, however, a structuring and documentation exercise that begins months before the application is lodged, not weeks.
Why the regulator is talking about money laundering right now
CySEC's 9 July circular is, on its face, an AML notice. Its real subject is the wind-down. Drawing on AMLA's guidance, the regulator's concern is specific: firms exiting a market are exactly where financial-crime controls degrade. Compliance staff leave, monitoring budgets stop, and management attention moves to the next venture - while client assets and transaction flows are still moving through the business.
The circular warns that rapid market exits can reduce transparency over customer relationships and the movement of crypto-assets, creating opportunities for illicit funds to be concealed or moved quickly - including for sanctions evasion. CySEC's expectations for exiting firms are correspondingly concrete: a robust, documented wind-down plan; adequate governance and resources maintained to the end; customer due-diligence records kept current; and suspicious transactions reported throughout - not just while the business was a going concern.
For a firm winding down, in other words, the regulatory obligations do not taper off with the revenue. They persist until the last regulated activity has formally ceased - and the wind-down itself is now a supervised process with its own compliance bar.
Not a crypto company? This still reaches you
The less obvious consequence of 1 July lands on businesses that aren't crypto firms at all. Any company, fund, or family office that uses a crypto custodian, exchange, or payment provider now has a counterparty question it may never have asked before: is this provider actually authorised to be doing what it's doing?
The question has teeth because of what ESMA's statement spelled out: clients of unauthorised providers - EU or non-EU - do not benefit from MiCA's protections, including its client-asset safeguards. A provider quietly winding down is not a neutral counterparty; it is a business whose controls the regulator has publicly flagged as likely to weaken, holding assets whose protection depends on a framework that may no longer apply to it.
Verification is straightforward, which makes not doing it hard to defend: CySEC maintains its own registers, and ESMA maintains a central, public MiCA register of authorised CASPs across the EU. Checking a counterparty against both - and documenting that the check happened - is now simply part of dealing with this asset class, in the same way bank counterparty checks became routine after 2013.
A concrete version of the problem: a family office holds part of its portfolio through a crypto custodian it onboarded in 2023, when a Cyprus national registration was the relevant credential. Nobody has looked at the relationship since, because nothing seemed to change - the platform works, statements arrive, the assets are visible. Whether that custodian filed by February, and whether it has since been authorised, is now the difference between assets held under MiCA's safeguarding regime and assets sitting inside a business that may be legally required to wind down. The uncomfortable part is that the client will not necessarily be told promptly in either case - which is precisely why the verification duty has, in practice, shifted to the client's side of the table.
Who can keep operating - and who must stop
CAN KEEP OPERATING A firm holding a CySEC-issued MiCA authorisation - able to provide services in Cyprus and passport them across the EU A firm authorised as a CASP in another EU member state, passporting into Cyprus under MiCA's notification routes A new entrant - once, and only once, a fresh MiCA application has been granted | MUST STOP AND WIND DOWN A firm registered only under the old Cyprus national CASP regime - that register is being decommissioned, not extended A firm that applied by 27 February but is still awaiting a decision - a pending application is not permission to continue past 1 July A firm that missed the February deadline entirely - wind-down plan required, ordinary regulated activity must cease |
The middle case in the right-hand column deserves emphasis, because it is the one most often misunderstood: filing on time was necessary, but it was never sufficient. The only thing that permits crypto-asset services in Cyprus after 1 July is a granted authorisation.
What to do this quarter
If you run a crypto business:
Establish your position precisely - authorised, pending, or out of time - and if it's either of the latter two, treat the wind-down as a supervised compliance process, not an administrative formality.
If re-entry is the goal, a fresh MiCA application is open at any time - but plan for a standing start, with no right to serve clients until the licence is granted.
Keep AML obligations fully resourced through the wind-down - due diligence current, monitoring active, suspicious-transaction reporting live - because that is exactly where CySEC has said it is looking.
If you deal with crypto providers:
Verify every crypto counterparty against the CySEC and ESMA registers, and document the check.
Map your exposure - which entities hold assets for you, under what agreements, and what happens to those assets if the provider winds down.
Where a counterparty's status is unclear or transitional, move first - renegotiating custody after a wind-down has begun is a far weaker position than before it.
The practical takeaway
The end of the transition did not end crypto in Cyprus - by most counts the island remains one of the EU's more active authorising jurisdictions, and a single MiCA licence now opens the whole bloc. What ended is ambiguity. For eighteen months, “registered” and “authorised” could be used almost interchangeably. As of 1 July, only one of those words means a business is allowed to operate - and both regulators and clients have been told, in the same week, to act accordingly.



Comments