MiCA in practice: what the EU rulebook asks of a payments provider
The transitional period closed on 1 July 2026. Here is what MiCA authorisation actually covers, and what to ask a provider before you move money through them.
For most of the last decade, a business that wanted to accept crypto payments in Europe had to work out the rules country by country. A provider registered in one member state might be unregulated in the next. Diligence meant reading national regimes that had little in common with each other.
Regulation (EU) 2023/1114 — MiCA — replaced that patchwork with one rulebook for the whole EU. It arrived in two stages: the rules for asset-referenced and e-money tokens applied from 30 June 2024, and the rules for crypto-asset service providers followed on 30 December 2024.
The date that matters now is more recent. Article 143(3) let member states give firms already operating under a national regime a transitional period of up to eighteen months. That window closed on 1 July 2026. From then on, providing crypto-asset services to clients in the EU without MiCA authorisation is a breach of the regulation, not a grey area.
What authorisation actually covers
MiCA does not authorise a company in general terms. It authorises specific services from a closed list, and a provider may only carry out the ones named in its authorisation.
The list covers custody and administration of crypto-assets on behalf of clients, operating a trading platform, exchanging crypto-assets for funds, exchanging crypto-assets for other crypto-assets, executing orders on behalf of clients, placing crypto-assets, receiving and transmitting orders, providing advice, portfolio management, and providing transfer services on behalf of clients.
This matters more than it first appears. Two firms can both describe themselves as MiCA authorised and be permitted to do quite different things. A provider authorised for transfers and exchange is not thereby authorised to hold your assets in custody.
One authorisation, the whole single market
Once a national competent authority grants authorisation, the provider can passport those services across the EEA without seeking permission again in each country. For a business selling across Europe, that is the practical change: coverage becomes a question of what a provider is authorised to do, rather than where it happens to be incorporated.
The corollary is that the authorising regulator matters. Supervision stays with the home state, so the standard applied at authorisation follows the provider everywhere it operates.
What to ask a provider
Authorisation is a floor, not a recommendation. MiCA is explicit that approval by a regulator is not an endorsement of the firm or of any crypto-asset it handles. Some questions worth asking:
- Which services is it authorised for? Ask for the list, not the label.
- **Who is the competent authority, and is the firm in that authority's public
register?** Registers are the primary source; a logo on a website is not.
- How are client assets held? MiCA requires client crypto-assets and funds
to be segregated from the provider's own, so that they are identifiable if the firm fails.
- What happens in an incident? Custody obligations include liability for loss
of client crypto-assets, within limits the regulation sets out.
- Is the same entity doing everything? Payment services and crypto-asset
services are different authorisations under different regimes. A provider moving both fiat and crypto may need both.
The warnings are part of the regime
Article 81(9) requires providers to warn clients and prospective clients about specific risks: that value can fluctuate, that partial or total loss is possible, that crypto-assets may be illiquid, and that they fall outside both investor compensation schemes and deposit guarantee schemes.
These are not boilerplate. They describe what is genuinely different about holding a crypto-asset compared with money in a bank account, and a provider that treats them as decoration is telling you something about how it reads the rest of the regulation. We set ours out in full on our risk warning page.
Where we stand
Coinsonnet is a trading name of Spectro Finance AS (under the transformation), in Tallinn. We are pre-launch and are not yet providing crypto-asset services. Applications for authorisation as a crypto-asset service provider and as a payment institution are with the regulator.
We will provide services once those authorisations are granted, and not before. When they are, the services we are permitted to carry out will be the ones named in the authorisation, and we will say which they are — because that, rather than the word "regulated", is the thing worth knowing.