15 min read
Cyprus MiCA transition ended 1 July 2026. Check if your CASP is authorised, pending, or must wind down after the 27 Feb 2026 CySEC deadline.

Reviewed by Gregoris Philippou, Managing Partner
Cyprus Bar Association (since 2013)
What ended on 1 July 2026 was the grandfathering window that let Cyprus crypto-asset service providers (CASPs) keep operating on their old national registration while they moved onto the EU regime. The Markets in Crypto-Assets Regulation (Regulation (EU) 2023/1114, "MiCA") itself did not change on that date. What changed is that the legal cover for operating without full MiCA authorisation expired. From 1 July 2026, lawful crypto-asset activity in or from Cyprus rests on a CySEC MiCA authorisation, or on a MiCA application filed by 27 February 2026 that is still under assessment.
The MiCA transitional period was a time-limited bridge, not a permanent status. Under Article 143(3) of MiCA, CASPs that were already providing services in compliance with national law before 30 December 2024 could continue for a transitional period of up to 18 months, ending 1 July 2026, or until MiCA authorisation was granted or refused, whichever came first (Regulation (EU) 2023/1114). Cyprus adopted the full 18-month period. The purpose of the bridge was to give incumbent providers time to prepare a full MiCA application, not to defer authorisation indefinitely.
30 December 2024 is the reference date for grandfathering because that is when MiCA's rules on crypto-asset service providers became fully applicable across the EU (ESMA, Markets in Crypto-Assets Regulation hub). Only firms that were lawfully providing crypto-asset services under national law before that date could rely on the Article 143 transitional regime, and only those firms could use the simplified authorisation route. If a business began providing crypto-asset services after 30 December 2024, it never had transitional cover and needed full MiCA authorisation from the outset.
A Cyprus national CASP registration is not, and never converted automatically into, a MiCA authorisation. The national CASP register was created under the Cyprus anti-money-laundering framework to bring virtual-asset providers into scope for AML supervision. It was an AML registration, not a prudential and conduct licence. MiCA authorisation is a separate, substantive approval covering governance, capital, custody, conduct and disclosure. Being on the national register bought transitional time; it did not, on its own, carry any firm past 1 July 2026. Firms that assumed the register would roll forward are now the firms most exposed.
Whether your Cyprus crypto business is still legally authorised after 1 July 2026 depends on one question with three answers: are you MiCA-authorised, pending, or neither? Use the branches below to place your firm. Each branch carries a different legal status and a different set of immediate obligations. The two dates that decide everything are the 27 February 2026 filing cut-off and the 1 July 2026 end of the transitional period.
| Your position | Status | What it means now |
|---|---|---|
| Full MiCA authorisation granted by CySEC | Authorised (green) | Operate normally within the scope of your authorisation; activate passporting |
| Application filed by 27 February 2026, still under assessment | Pending (amber) | Continue only until CySEC decides, or 1 July 2026, whichever came first; prepare a contingency wind-down |
| No application filed, or application withdrawn or refused | Unauthorised (red) | Cease crypto-asset services and execute a wind-down plan filed with CySEC |
If CySEC has granted your firm full MiCA authorisation, you are legally authorised and may provide the crypto-asset services listed in that authorisation. This is the only branch that gives a durable, forward-looking right to operate. Your task now is not survival but perimeter management: confirm every service you actually provide falls inside the authorisation, put EEA passporting notifications in place if you serve clients in other member states, and keep governance, capital and custody arrangements aligned with what you told CySEC. Authorisation is a licence to run the described business, not a blanket permission for anything crypto.
If you filed a MiCA application with CySEC by 27 February 2026 and it is still under assessment, you sit in the amber branch: conditionally able to continue, but on a clock. CASPs that applied by the deadline could continue their activities until the application was approved or rejected, or in any event until the end of the transitional period on 1 July 2026, whichever occurred first (CySEC press release, reported by the Cyprus Business News). Read that carefully: the transitional cover for pending applicants was itself capped at 1 July 2026, and MiCA builds in no automatic extension for a file still under assessment on that date. ESMA confirmed the point in its December 2025 Statement on the end of the transitional periods under MiCA, stating that a pending application is not equivalent to authorisation and directing CASPs that are not yet authorised to keep orderly wind-down plans ready for implementation in case they are not authorised by the end of the transitional period (ESMA, ESMA75-113276571-1631). A firm still in assessment on 1 July 2026 therefore cannot lean on its pending status to keep trading: any continued operation rests on a specific written direction from CySEC to that firm, not on a general entitlement, and the firm should assume it must be ready to wind down if authorisation has not arrived.
If you did not file a MiCA application by 27 February 2026, or your application was withdrawn or refused, your firm is in the red branch and may no longer provide crypto-asset services. CASPs that did not apply for authorisation by the deadline are required to submit a wind-down plan, as crypto-asset services are no longer permitted after the end of the transitional period (CySEC press release). This is not a soft deadline. Continuing to provide crypto-asset services from this branch is unauthorised activity, with the supervisory and criminal-law consequences that follow under the Cyprus AML and investment-services framework.
Cyprus ran two decisive dates: an application cut-off of 27 February 2026 and a transitional end of 1 July 2026. The first decided who could stay in the game while CySEC assessed them; the second decided the outer limit for everyone. Missing the first pushed a firm straight into wind-down. Reaching the second without an authorisation ended transitional operation regardless of how far an application had progressed.
27 February 2026 was the deadline for CASPs operating under the Cyprus national framework to apply to CySEC for authorisation under MiCA. CySEC confirmed this in a press release titled "MiCA licence applications due by 27 February 2026" (cysec.gov.cy). Filing by that date was the entry ticket to the assessment window; it preserved the right to keep operating while CySEC reviewed the file. A firm that did not file by 27 February 2026 lost transitional cover and moved into the wind-down obligation, even though the transitional period did not formally end until months later.
1 July 2026 was the hard end of the MiCA transitional period in Cyprus, being 18 months from the 30 December 2024 reference date. Across the EU, member states could shorten or decline to apply the Article 143 transition, and the periods actually ranged from 5 to 18 months; Cyprus adopted the full 18-month period ending 1 July 2026 (Harneys Regulatory Blog). After 1 July 2026, transitional operation is no longer available in Cyprus. A firm relies from that date on an actual authorisation, not on the passage of the calendar.
For a pending applicant, three events could end transitional operation, and the first to occur governed. CySEC approval converts the firm to Branch 1 and lets it operate on the authorisation. CySEC rejection ends transitional operation immediately and triggers wind-down. The 1 July 2026 hard stop ends transitional operation for anyone still pending on that date. The rule is symmetrical and unforgiving: you operate on transitional cover only until the earliest of these three, never beyond it.
A pending MiCA application does not, by itself, let you do anything after 1 July 2026, because the transitional cover for pending applicants was capped at that date. During the transitional window a pending applicant that had filed by 27 February 2026 could continue existing crypto-asset services, but that permission was time-limited and conditional, not a licence. The value of a pending application was continuity while CySEC assessed the file, not a new legal status of its own.
Pending status is not authorisation, and treating it as one is the most dangerous mistake a Cyprus CASP can make now. A pending application means CySEC has your file and is assessing it; it means the firm has not yet met the MiCA bar. During assessment the firm operated on transitional cover, not on any approval. If that cover has expired, pending status confers no right to onboard clients, market services, or hold client assets in the ordinary course. ESMA has been explicit that a pending application is not equivalent to authorisation (ESMA, Statement on the end of the MiCA transitional periods, December 2025).
You could keep operating only until the earliest of CySEC's decision or 1 July 2026. There is no automatic extension built into MiCA that lets a pending applicant trade on beyond the transitional end simply because the regulator has not finished its review. Where an assessment genuinely runs on, the operating position depends entirely on CySEC's specific direction to that firm, not on any general entitlement. Any firm in this situation should hold written confirmation from CySEC of exactly what it may and may not do, rather than infer permission from silence.
During assessment CySEC can request whatever it needs to satisfy the MiCA authorisation standard, and delay in responding can itself sink an application. Typical requests cover governance and fit-and-proper documentation for directors and shareholders, the business plan and financial projections, custody and safekeeping arrangements, ICT and cyber-resilience policies, AML/CFT systems, complaints handling, and proof of initial capital and own funds. The operative timetable is not a separate step-by-step "accelerated protocol" but the two published dates themselves: the 27 February 2026 filing cut-off and the 1 July 2026 transitional end, which CySEC fixed through its public communications. The assessment runs against the standard MiCA authorisation requirements, so the practical schedule a firm should plan around is CySEC's own information requests during review, not a published fast-track calendar; delay in responding to any request narrows an already fixed window.
The CySEC MiCA authorisation process assesses whether a firm meets MiCA's governance, capital, custody, conduct and disclosure standards for the specific crypto-asset services it wants to provide. CySEC is the competent authority for CASPs in Cyprus, and authorisation is granted service-by-service against the MiCA framework. For firms that were already authorised under national law on 30 December 2024, a lighter procedural route was available.
The simplified authorisation procedure under Article 143(6) of MiCA was available to entities that were already authorised under applicable national law on 30 December 2024 to provide crypto-asset services (Goodwin, MiCA grandfathering analysis). The route does not lower the substantive MiCA standard; it streamlines the procedure by letting the authority rely on information it already holds from the prior national authorisation. Firms that qualified could reuse existing documentation and avoid duplicating what the regulator had already reviewed. Firms that were only registered for AML purposes, rather than authorised to provide services under national law, generally could not rely on Article 143(6).
CySEC expects a complete file evidencing real substance in Cyprus, not a paper presence. Applicants generally need to show a Cyprus-resident senior management team, a physical office, qualified compliance and risk functions, and decision-making that actually happens in Cyprus. This is the same establishing economic substance in a Cyprus company expectation that runs through Cyprus regulated-entity practice, and it aligns with beneficial-ownership transparency under the UBO register and beneficial ownership compliance regime. On capital, MiCA sets minimum own-funds requirements by service class under Article 67 and Annex IV of Regulation (EU) 2023/1114. Class 1 (EUR 50,000) covers firms authorised for reception and transmission of orders, execution of orders, placing of crypto-assets, transfer services, advice and portfolio management. Class 2 (EUR 125,000) adds custody and administration of crypto-assets and the exchange of crypto-assets for funds or for other crypto-assets. Class 3 (EUR 150,000) adds operating a trading platform for crypto-assets. A CASP must hold, at all times, the higher of the fixed minimum for the most demanding class of service it provides or one quarter of its preceding year's fixed overheads.
The national CASP register does not map cleanly onto MiCA authorisation classes, and that mismatch is a common source of trouble. National registration was defined for AML purposes around virtual-asset activities, while MiCA authorisation is granted against a specific statutory list of crypto-asset services. A firm registered nationally for a broad description of activity may find that only some of what it does fits the MiCA services it applied for. The practical task is to re-map each real activity onto the correct MiCA service and confirm the authorisation, or application, covers all of them.
If you missed the 27 February 2026 deadline, your firm must wind down its crypto-asset activity in an orderly way and stop providing services. CASPs that did not apply for authorisation by the deadline are required to submit a wind-down plan to CySEC, because crypto-asset services are no longer permitted after the transitional period ended (CySEC press release). Wind-down is a supervised, structured exit, not simply switching off the platform.
Submitting a wind-down plan to CySEC is the first obligation for any firm that did not apply in time. The plan sets out how the firm will stop new business, return or transfer client assets, meet continuing AML and reporting duties, and eventually close or repurpose. ESMA reinforced this by publishing a Statement on the end of the MiCA transitional periods calling for timely wind-down of non-authorised CASP activity (ESMA, December 2025). A firm should treat the plan as a binding roadmap that CySEC will hold it to, and engage the regulator early rather than present a closure after the fact.
Stopping onboarding, marketing and new services is immediate, not phased, once a firm is in wind-down. From the point the firm loses its right to operate, it must not take on new clients, promote crypto-asset services, launch new products, or expand existing relationships. The permitted activity narrows to what is strictly necessary to run off the existing book in an orderly way: honouring withdrawals, settling open positions, and returning assets. Continuing to market or onboard during wind-down is unauthorised activity and undermines the entire orderly-exit premise.
The core of any wind-down is returning client assets or transferring them to an authorised provider, cleanly and with a clear audit trail. Clients must be able to withdraw their crypto-assets and funds, or have them migrated to a firm that holds MiCA authorisation, without loss or unreasonable delay. Segregation must be maintained throughout, and every movement documented. The firm's own insolvency or commercial difficulty does not dilute the duty to safeguard and return what belongs to clients; if anything, it raises the supervisory scrutiny on how assets are handled.
Compliance obligations do not switch off during wind-down; several of them intensify. Ceasing to onboard new clients ends new business, not the firm's legal duties on the existing book. AML, sanctions, client-asset and reporting obligations all continue until the firm has fully closed out, and breaches during wind-down are still breaches.
Anti-money-laundering (AML), counter-terrorist-financing (CFT), sanctions-screening and Travel Rule obligations continue in full throughout wind-down. The Travel Rule, implemented in the EU through the recast Transfer of Funds Regulation, requires originator and beneficiary information to travel with crypto-asset transfers, and it applies to transfers you process while running off the book. Sanctions screening on every counterparty remains mandatory. A firm cannot treat the loss of its operating right as the end of its financial-crime duties; those duties are owed to the system, not to the firm's commercial future.
Client-asset segregation and safekeeping duties continue unbroken during wind-down, and getting them wrong is where firms attract the most serious liability. Client crypto-assets and funds must stay segregated from the firm's own assets, be protected from the firm's creditors, and be accounted for precisely at all times. The safekeeping standard that applied while authorised applies while winding down. Firms structuring or restructuring the corporate vehicle around a regulated crypto business should keep this segregation intact through any Cyprus holding company structure reorganisation rather than commingle in the course of a group tidy-up.
Record-keeping and reporting to CySEC continue throughout wind-down and beyond closure. The firm must maintain complete records of transactions, client instructions, asset movements and communications, and it must report to CySEC as the regulator directs during the run-off. Statutory retention periods survive the firm's operational end, so records cannot be destroyed simply because the platform has stopped. A clean, complete record set is also the firm's best protection if a client or the regulator later questions how assets were handled.
A third-country (non-EU) firm generally cannot serve Cyprus clients with crypto-asset services after the deadline, because MiCA requires authorisation to provide those services in the EU. The only narrow gateway is genuine reverse solicitation, and regulators read it strictly. For any firm that wants a real, ongoing Cyprus or EU client base, the durable answer is an authorised EU entity, not reliance on an exemption designed for isolated, client-initiated contact.
Reverse solicitation covers only a service provided at the client's own exclusive initiative, and its limits are narrow by design. If a Cyprus client, entirely on their own initiative, approaches a non-EU firm for a specific service, that single service may fall outside the authorisation requirement. The exemption is construed strictly and cannot be manufactured. It rests on Article 61 of MiCA, which ESMA frames not as a positive right but as a prohibition on third-country firms soliciting clients in the EU, subject only to the narrow case where the client requests a specific service on their own exclusive initiative. In its Guidelines on reverse solicitation under MiCA (final report December 2024, published February 2025), ESMA takes a broad, technology-neutral view of what counts as solicitation, applies a substance-over-form assessment case by case, and makes clear that standard disclaimers or contractual clauses cannot by themselves prove a service was client-initiated. A single reverse-solicited service also does not open the door to marketing further services to that client.
Reverse solicitation cannot be used to market, to solicit, or to build an ongoing relationship, and any of those steps defeats it. A non-EU firm that advertises to Cyprus users, runs campaigns, offers new product categories to an existing reverse-solicited client, or cultivates a continuing book is providing services into the EU and needs authorisation. Regulators look at substance over labels: a "client-initiated" flow that is in fact fed by marketing is not reverse solicitation. Treating the exemption as a business model is a compliance trap.
Setting up an authorised EU entity is the durable route because it gives a lawful, scalable right to serve Cyprus and EEA clients that reverse solicitation can never provide. A firm that authorises a CASP in Cyprus can passport across the EEA and build an ongoing client base openly. That means committing to real substance, capital and governance, but it replaces a fragile exemption with a stable licence. For most serious operators the choice is not whether to authorise but where, and Cyprus remains a competitive base for a regulated crypto business.
MiCA authorisation only covers the specific crypto-asset services named in it, so the honest question is whether your authorisation matches everything you actually do. Authorisation is granted service-by-service against a statutory list. A firm authorised for custody is not thereby authorised to operate a trading platform or to give advice. Any activity outside the authorised set is unauthorised, even if the firm holds a MiCA licence for something else.
Mapping your business to the MiCA list of crypto-asset services means matching each real revenue line to a defined service, not to a marketing description. Article 3 of Regulation (EU) 2023/1114 defines ten crypto-asset services, and each authorised firm must hold cover for every one it provides: providing custody and administration of crypto-assets on behalf of clients; operating a trading platform for crypto-assets; exchange of crypto-assets for funds; exchange of crypto-assets for other crypto-assets; execution of orders for crypto-assets on behalf of clients; placing of crypto-assets; reception and transmission of orders for crypto-assets on behalf of clients; providing advice on crypto-assets; providing portfolio management on crypto-assets; and providing transfer services for crypto-assets on behalf of clients (EUR-Lex, Regulation (EU) 2023/1114). The mapping exercise routinely surfaces services a firm forgot it offered, such as an informal advisory function or a transfer service bundled into the platform.
MiCA's crypto-asset services span, among others, custody and administration of crypto-assets, operating a trading platform, exchange of crypto-assets for funds or for other crypto-assets, execution of orders, placing of crypto-assets, reception and transmission of orders, advice, portfolio management, and transfer services. Each is a distinct service with its own conduct and capital implications. A single consumer-facing app can touch several of these at once. The authorisation, or the pending application, must name every one that the firm actually performs; a gap between activity and authorisation is a live compliance exposure.
Group structures, outsourcing and white-label arrangements do not move the authorisation obligation off the firm that faces the client. If a Cyprus entity provides the regulated service to clients, that entity needs the authorisation, regardless of where processing, liquidity or technology sit in the group. Outsourcing a function does not outsource the regulatory responsibility for it. White-label arrangements, where one firm's authorised service is offered under another brand, need careful structuring so it is clear who is authorised for what. Getting the entity and contractual perimeter right at the design stage avoids a later finding of unauthorised activity.
What a Cyprus CASP should do now depends on which branch of the decision tree it sits in, and each branch has a concrete checklist. The common thread is to act on the firm's actual status, document decisions, and engage CySEC rather than wait. Below is the practical action list per position.
If your firm is authorised, activate EEA passporting where you serve clients in other member states and tidy the service perimeter so nothing you do falls outside the authorisation. Passporting lets a MiCA-authorised Cyprus CASP provide services across the EEA on the strength of the single authorisation, subject to notification. Before relying on it, confirm each host-state notification is filed and each service is covered. The perimeter check, matching real activity to authorised services, is the single most valuable housekeeping step for an authorised firm.
If your firm is pending, prepare for CySEC follow-ups and build a contingency wind-down you can trigger instantly. Assign a named owner to CySEC correspondence, keep the full application evidence current, and treat every information request as urgent. In parallel, draft the wind-down plan now rather than after a refusal, so that an adverse decision does not catch the firm improvising. Holding both a live application and a ready wind-down is the only prudent posture while the outcome is uncertain.
If your firm is unauthorised, execute the wind-down cleanly and, if the business case survives, plan a proper re-entry through fresh authorisation. Run off the existing book, return or transfer client assets, and keep every continuing obligation live until closure. Re-entry is not a reopening of the old permission; it is a new authorisation built on real substance, capital and governance. Firms rebuilding for re-entry often start by learning how to register a Crypto-Asset Service Provider in Cyprus from the ground up rather than reviving the lapsed structure.
MiCA authorisation sits on top of the ordinary Cyprus company, tax and substance rules, and a regulated crypto business has to satisfy all of them at once. The licence answers "may you provide the service"; the corporate and tax framework answers "how is the vehicle owned, staffed and taxed". A durable Cyprus CASP gets both right together, because a licence without substance, or a structure without a licence, fails.
Corporate substance and economic presence expectations for a Cyprus CASP are high and are checked, not assumed. A regulated crypto business needs genuine local decision-making, qualified staff, an office, and functions actually performed in Cyprus, mirroring the establishing economic substance in a Cyprus company standard. Substance is what supports both the regulatory authorisation and the tax residence of the company. A thin, mailbox presence undermines both at the same time, so the substance you build for CySEC also serves your tax position.
CASP activity sits within the ordinary Cyprus company and tax rules that apply to any trading company, with crypto treated according to its character. A Cyprus CASP is typically a company that you would open a company in Cyprus to hold, and its profits are taxed under the general corporate framework set out in the overview of taxes in Cyprus. How specific crypto flows are characterised for tax is a distinct question addressed in our guide to cryptocurrency taxation in Cyprus. Founders should map the regulatory and tax questions together, not in sequence.
Choosing the right structure for a regulated crypto business means aligning the licensed operating entity, any holding layer, and the founders' personal position from the start. The operating CASP holds the authorisation and the substance; a Cyprus holding company structure can sit above it for ownership and treasury; and founders relocating to Cyprus should consider their own Cyprus tax residency and non-dom status. Getting the structure right early avoids costly reorganisation once the firm is authorised and regulated, when moving pieces around draws supervisory attention.
Philippou Law Firm advises Cyprus crypto-asset businesses across the full MiCA picture: placing your firm correctly in the authorised, pending or wind-down branch, preparing and pursuing a CySEC MiCA authorisation, drafting and executing a compliant wind-down, and structuring the operating entity, holding layer and founders' tax position around a regulated crypto business. Our advocates combine regulatory, corporate and tax expertise so the licence and the structure fit together. If you are unsure whether your Cyprus CASP is still legally authorised after 1 July 2026, contact us for a confidential assessment and a clear next-step plan.
This article is general information, not legal advice. Cyprus and EU crypto-asset regulation is fast-moving; verify the current position and obtain tailored advice before acting.
Company registration
from €1,050
A complete, working Cyprus company on a fixed fee, agreed in writing before we start.
Fixed fee, written into your engagement letter before you pay. A Cyprus-admitted lawyer replies within 24 hours.
Book a free 30-minute consultation with a partner.
Book free consultation
Managing Partner
Managing Partner with a distinguished career in corporate and commercial law, trust law, tax law, property law, litigation, and immigration law. First-Class LL.B. from the University of Leicester and LL.M. from the University of Cambridge.
View profile
VideoCorporate nominee services in Cyprus place a regulated local professional on the public company register in your place, as nominee director, nominee shareholder or company secretary, and provide the registered office address that every Cyprus company must have by law.

How to set up a family office in Cyprus in 2026: single vs multi-family thresholds, trust, PTC, foundation and holdco structures, real costs and tax treatment.

Closing a Cyprus company in 2026: compare strike-off (Form HE60) and members' voluntary liquidation, tax clearance, Registrar filings, cost, timeline and
Related Services
“Fabulous service from everyone at Philippou Law. We moved here in July and had our immigration sorted with Nikolas and Laura, our tax residency, non-dom and the opening of our business was seamlessly done by Cleo, and we are also buying our house with them, where Maria and Elpida have been wonderful. Honestly I would not go anywhere else. Many thanks all.”
Free Consultation
Book a free, no-obligation consultation with one of our experienced lawyers. As one of the most established law firms in Paphos, we're here to help you navigate the legal landscape of Cyprus with confidence.
No fees. No obligations. Speak with a qualified lawyer today.