MiCA regulation in 2026: the EU crypto compliance guide to 2028
What the MiCA regulation, the crypto Travel Rule, the AMLR with AMLA's draft due diligence standards and eIDAS 2.0 ask of a crypto business in the EU from 2026 to 2028, with articles, a cheat sheet and a plan.

In short
Under the MiCA regulation, crypto-asset services in the EU now need a CASP authorisation, or one of the Article 60 routes for banks and other listed firms: the transitional period for existing firms ended on 1 July 2026 at the latest.[1][2] Three more rules shape how a crypto-asset service provider (CASP) onboards and pays out.
- The crypto Travel Rule has applied since 30 December 2024 to transfers involving an EU CASP, with no minimum amount.[4]
- The Anti-Money Laundering Regulation (AMLR) applies from 10 July 2027, and the Anti-Money Laundering Authority (AMLA) announced its final draft due diligence standards on 1 October 2026.[6][8]
- Under eIDAS 2.0, firms required by law or contract to use strong user authentication for online identification, other than micro and small enterprises, accept the EU Digital Identity Wallet at the user's request by a working date of 24 December 2027.[12][13]
The MiCA regulation (Markets in Crypto-Assets, Regulation (EU) 2023/1114) is the licence. It does not write the know your customer (KYC) rules: those come from the EU anti-money laundering framework, the Transfer of Funds Regulation and, for digital identity, eIDAS 2.0.[1][4][6][12] Depending on its services, status and transfers, a crypto business serving EU customers may need all four, with dates from December 2024 to 2028.
PDF guide
The same rules, the regulatory clock, the cheat sheet and the readiness plan in a printable A4 guide. Download the PDF guide
EU crypto regulation at a glance
| Rule | What it asks of a crypto business | Applies from |
|---|---|---|
| MiCA | An authorisation to provide crypto-asset services in the EU, passported to other member states[1] | 30 December 2024; transitional period over by 1 July 2026[1] |
| Travel Rule (TFR) | Originator and beneficiary information with every in-scope crypto transfer, plus ownership checks on self-hosted wallets above EUR 1,000[4] | 30 December 2024[4] |
| AMLR | One directly applicable rulebook for customer due diligence, ongoing monitoring and record keeping[6] | 10 July 2027[6] |
| eIDAS 2.0 | Accept the EUDI Wallet at the user's request where strong user authentication for online identification is required; micro and small enterprises are excluded[12] | 24 December 2027 (working date)[12][13] |
The regulatory clock, 2024 to 2028
- 30 December 2024MiCA and TFRThe CASP regime and the crypto Travel Rule apply.[1][4]
- 17 January 2025DORADigital operational resilience rules apply to authorised CASPs.[14]
- 1 January 2026DAC8Crypto tax reporting data is collected for 2026.[15]
- 1 July 2026MiCA transition endsThe latest end of the transitional period in any member state.[1][2]
- 1 October 2026AMLA announcementAMLA says its final draft due diligence standards have been submitted.[8]
- 24 December 2026EUDI WalletsEach member state provides at least one wallet (working date).[12][13]
- 1 January 2027DAC8Tax residence self-certification due for existing users.[15]
- 10 July 2027AMLR appliesOne EU rulebook for customer due diligence.[6]
- 24 December 2027Wallet acceptanceFirms that must use strong user authentication for online identification accept it on request (working date).[12][13]
- 2028AMLA supervisionDirect supervision of up to 40 cross-border financial groups.[11]
Top: already in force. Bottom: still to come. The two eIDAS dates are working dates computed from the entry into force of the first wallet implementing acts on 24 December 2024; a strict reading could tie them to later acts.
MiCA regulation: the licence is now mandatory
Article 59(1) of MiCA is short: "A person shall not provide crypto-asset services, within the Union, unless that person is" an authorised CASP or a bank, investment firm, e-money institution or other financial firm allowed to do so under Article 60.[1] The only exception is narrow: a third-country firm may serve an EU client who approaches it at the client's "own exclusive initiative", and soliciting EU clients ends it (Article 61).[1]
Firms already operating under national law had a grace period, which each member state could shorten or skip (Article 143(3)).[1]
Article 143(3)Regulation (EU) 2023/1114
"Crypto-asset service providers that provided their services in accordance with applicable law before 30 December 2024, may continue to do so until 1 July 2026 or until they are granted or refused an authorisation pursuant to Article 63, whichever is sooner."
Source: EUR-Lex, Regulation (EU) 2023/1114[1]
The European Securities and Markets Authority (ESMA) lists the period each country chose, noting that some may not yet be in national law.[2]
| Transitional period | Countries in ESMA's list |
|---|---|
| 6 months | Latvia, Hungary, Netherlands, Poland, Slovenia, Finland[2] |
| 9 months | Sweden[2] |
| 12 months | Germany, Ireland, Lithuania, Austria, Slovakia, Norway[2] |
| 18 months | Belgium, Bulgaria, Czechia, Denmark, Estonia, Greece, Spain, France, Croatia, Italy, Cyprus, Luxembourg, Malta, Portugal, Romania, Liechtenstein[2] |
All of these periods had ended by 1 July 2026. ESMA lists authorised CASPs in its interim register.[16]
What MiCA asks of you
- Passporting: once authorised, a CASP may serve clients "throughout the Union" without a physical presence in each country.[1] It notifies its home authority and may start in a host country when it receives that authority's communication, or at the latest on the 15th calendar day after submitting its notice (Articles 59(7) and 65(4)).[1]
- Anti-money laundering in the application: the file describes the controls, policies and procedures "to identify, assess and manage risks, including money laundering and terrorist financing risks" (Article 62(2)(i)).[1]
- Custody: the client agreement covers communication, "including the client’s authentication system", and client holdings are kept separate from the firm's own, including on the ledger (Article 75(1)(d) and 75(7)).[1]
- Strong authentication: authorised CASPs are financial entities under the Digital Operational Resilience Act (DORA), which requires "strong authentication mechanisms" and protection of cryptographic keys (Article 9(4)(d)).[14]
For breaches of the CASP rules (Articles 59, 60, 64 and 65 to 83), Article 111(3) requires that supervisors can impose maximum fines on a company of at least EUR 5,000,000 and of at least 5% of total annual turnover; member states may go higher.[1]
Stablecoins have their own regime: an e-money token may be offered to the public in the EU only by an issuer authorised as a credit institution or an e-money institution, after notifying and publishing a white paper, or by others with that issuer's written consent (Article 48(1)).[1] In January 2025 ESMA said trading platforms are expected to stop offering trading in such tokens when the issuer is not authorised in the EU, restricting existing services by the end of January 2025, with a "sell only" window until the end of the first quarter of 2025 while custody and transfers could continue.[3]
What your customers notice: more questions, custody terms that explain how they log in, and fewer stablecoins.
The crypto Travel Rule: identity travels with every transfer
Regulation (EU) 2023/1113, the Transfer of Funds Regulation (TFR), has applied since 30 December 2024.[4] The European Banking Authority's Travel Rule Guidelines apply from the same day.[5] For crypto there is no threshold: transfers "should be subject to the same requirements regardless of their amount and of whether they are domestic or cross-border transfers" (recital 30).[4]
| Who | Information that travels with the transfer | Article |
|---|---|---|
| Originator | Name; distributed ledger address and crypto-asset account number where used; address with country, official personal document number and customer identification number, or date and place of birth; LEI where available[4] | Art. 14(1)[4] |
| Beneficiary | Name; distributed ledger address and crypto-asset account number where used; LEI where available[4] | Art. 14(2)[4] |
The data goes "in advance of, or simultaneously or concurrently with, the transfer", in a secure manner (Article 14(4)).[4] The originator's CASP may not start or execute the transfer before it has done all of this (Article 14(8)).[4]
1The customer asks to send crypto
Collect the beneficiary's name and the destination address.[4]
The destination belongs to another CASP
Exchange the data with that CASP
Originator and beneficiary information before or with the transfer, Article 14(4).[4]
Self-hosted wallet
Obtain and hold the information. Above EUR 1,000, assess whether the customer owns or controls the address, Article 14(5).[4]
2Release the transfer
Only after the checks are complete, Article 14(8).[4]
3The receiving CASP checks completeness
Missing data: reject or return the transfer, or request the data before releasing it, Article 17.[4]
Outbound; Article 16(2) mirrors it for incoming transfers.
For a transfer from a self-hosted address, the beneficiary's CASP takes "adequate measures to assess whether that address is owned or controlled by the beneficiary" above EUR 1,000 (Article 16(2)), and it must act on counterparties that repeatedly fail to send data (Article 17).[4]
What your customers notice: questions about who they are paying, and requests for evidence on whether they own or control a wallet.
The AMLR: one EU rulebook for customer due diligence
Regulation (EU) 2024/1624, the AMLR, applies from 10 July 2027.[6] CASPs are obliged entities as financial institutions (Article 3(2) with Article 2(1), point (6)).[6] See the AMLR page.
When due diligence applies
Business relationships always trigger customer due diligence (CDD). For occasional crypto transactions, CASPs apply full CDD from EUR 1,000, single or linked, and below EUR 1,000 they must still identify and verify the customer (Article 19(3)).[6] AMLA's draft standards on linked transactions say a CASP providing exchange for funds, exchange between crypto-assets or transfer services (MiCA Article 3(1)(16)(c), (d) and (j)) must at least consider a one-month window, and that three or more transactions in 12 months point to a business relationship.[9]
The data points of Article 22(1)
For a natural person, the AMLR lists what must be obtained; identity is then verified by the Article 22(6) means.[6] AMLA's draft adds attribute rules, for example verifying at least one nationality when a customer declares several (draft Article 5).[7]
| Data point | AMLR reference |
|---|---|
| All names and surnames | Art. 22(1)(a)(i)[6] |
| Place and full date of birth | Art. 22(1)(a)(ii)[6] |
| Nationalities, or statelessness and refugee or subsidiary protection status | Art. 22(1)(a)(iii)[6] |
| National identification number, where applicable | Art. 22(1)(a)(iii)[6] |
| Usual place of residence, or a postal address if there is no fixed address with legitimate residence in the EU | Art. 22(1)(a)(iv)[6] |
| Tax identification number, where available | Art. 22(1)(a)(iv)[6] |
The document number and expiry date are not on this list. They appear in AMLA's draft as features a document needs to count as "equivalent" to an identity card or passport (draft Article 6(1)).[7]
Remote onboarding under AMLA's draft standards
AMLA's final report on the draft regulatory technical standards (RTS) on CDD is dated 30 September 2026.[7] On 1 October 2026 AMLA said the drafts "have now been submitted" to the European Commission.[8] They are not law yet: once adopted and published in the Official Journal, they are proposed to apply six months after entry into force.[8]
Article 22(6) gives two default means: an identity document with reliable and independent sources where relevant, or an eID at assurance level substantial or high.[6] Draft Article 7 adds a third path: when a person "cannot reasonably be expected" to show a document face to face and "does not have access" to a qualifying eID, the firm verifies the document remotely under five safeguards.[7]
1The customer cannot reasonably show a document face to face
Assessed case by case, and justified.[7]
The customer has an eID at level substantial or high
Verify with the eID
Article 22(6)(b); collect any missing attribute from another reliable source.[6][7]
Remote document verification
Draft Article 7: five safeguards, and be able to justify why it was used.[7]
2Screen, assess risk and keep the evidence
Time-stamped copies that allow checks after the fact.[7]
The order draft Article 7 sets when a face-to-face document check is not reasonable. A document shown face to face remains a default route under Article 22(6)(a).
The five safeguards of draft Article 7(2): proof that the presenter is the document holder, a secure channel, images of enough quality, stopping on technical failure or doubt, and time-stamped copies stored securely.[7] Firms "shall be able to justify why the customer could not be verified" through the Article 22(6) means (draft Article 7(3)).[7]
Watch out
AMLA rejected an "eIDAS-first" reading. Its feedback says the Article 22(6) means "are still the default option", and that firms may keep existing remote onboarding tools that meet the Article 7 requirements.[7]
What else changes on 10 July 2027
- Beneficial owners: verify them through reliable sources and consult the central registers in addition (Article 22(7)).[6]
- Refresh cycles: update customer information at least every year for higher-risk customers and every five years for the others (Article 26(2)).[6]
- Politically exposed persons: the draft standards ask firms to determine status before the relationship or the occasional transaction, outside the Article 44 cases (draft Article 17(1)(a)).[7] The AMLR itself makes PEP status a due diligence measure (Article 20(1)(g)).[6]
- No anonymity: no anonymous crypto-asset accounts and no accounts that allow anonymisation, "including through anonymity-enhancing coins" (Article 79(1)).[6]
Supervision changes too. In its first selection AMLA will pick up to 40 credit and financial institutions or groups, CASPs included, that operate in at least six member states and have a high residual risk profile, with selection starting by 1 July 2027.[10] AMLA says it takes over their direct supervision in 2028.[11]
What your customers notice: a digital ID option, address and tax number questions, and periodic re-verification. More in AMLR for crypto.
eIDAS 2.0: the EUDI Wallet joins onboarding
Regulation (EU) 2024/1183 creates the European Digital Identity Wallet. Each member state must provide at least one wallet within 24 months of the entry into force of the wallet implementing acts (Article 5a(1)).[12] The first of those acts was published on 4 December 2024 and, under the 20-day rule, entered into force on 24 December 2024: a working date of 24 December 2026.[13]
Wallets are issued under a scheme at assurance level high (Article 5a(11)), which clears the bar of the AMLR eID route: assurance level substantial or high.[12][6] They let the user share only the attributes requested, with selective disclosure (Article 5a(4)(a)).[12]
Private relying parties that must use strong user authentication for online identification by law or contract, "including in the areas of" banking and financial services, shall accept the wallet "only upon the voluntary request of the user" within 36 months, a working date of 24 December 2027 (Article 5f(2)).[12][13] Micro and small enterprises are excluded in the same article.[12]
- Register as a relying party in the member state where you are established (Article 5b(1)), and keep other routes: wallet use is voluntary (Article 5a(15)).[12]
The dates and their legal basis are in EUDI Wallet deadlines 2026 and 2027, and the relying-party steps on the EUDI Wallet page.
Obligations cheat sheet
| Obligation | Source article | Applies from |
|---|---|---|
| Hold a CASP authorisation | MiCA Art. 59(1), 143(3)[1] | 1 July 2026 at the latest[1] |
| Strong authentication and key protection | DORA Art. 9(4)(d)[14] | 17 January 2025[14] |
| Send originator and beneficiary data with each in-scope transfer | TFR Art. 14(1), 14(2), 14(4)[4] | 30 December 2024[4] |
| Assess self-hosted wallet ownership above EUR 1,000 | TFR Art. 14(5), 16(2)[4] | 30 December 2024[4] |
| Collect tax data on users | DAC8[15] | 1 January 2026[15] |
| CDD on occasional transactions from EUR 1,000 | AMLR Art. 19(3)[6] | 10 July 2027[6] |
| Collect the Article 22(1) data and verify identity | AMLR Art. 22(1), 22(6)[6] | 10 July 2027[6] |
| Verify beneficial owners beyond the register | AMLR Art. 22(7)[6] | 10 July 2027[6] |
| Refresh customer data every 1 or 5 years | AMLR Art. 26(2)[6] | 10 July 2027[6] |
| No anonymous crypto-asset accounts, or accounts that allow anonymisation, including through anonymity-enhancing coins | AMLR Art. 79(1)[6] | 10 July 2027[6] |
| Remote document checks with five safeguards | Draft RTS Art. 7[7] | Proposed: six months after entry into force (draft Art. 29)[7][8] |
| Accept the EUDI Wallet on request | eIDAS Art. 5f(2)[12] | 24 December 2027 (working date)[13] |
Readiness checklist by quarter
October to December 2026
- Confirm your MiCA authorisation and the host member states you notified.[1]
- Collect DAC8 tax residence self-certifications from existing users before 1 January 2027.[15]
- Close Travel Rule gaps: counterparty reachability, the EUR 1,000 self-hosted wallet check and time-outs.[4]
January to March 2027
- Map each Article 22(1) data point to a source, including address and tax number.[6]
- Add an eID route where you have volume, and record why the document route was used.[7]
- Rank existing customers by risk and set refresh cycles of 1 and 5 years.[6]
April to June 2027
- Test remote document checks against the five draft Article 7 safeguards.[7]
- Add a beneficial owner source next to the central register.[6]
July to December 2027
- Switch policies to the AMLR on 10 July 2027.[6]
- Register as a relying party and test EUDI Wallet acceptance before 24 December 2027.[12]
- Track the Official Journal: the AMLA standards can still change before adoption.[8]
How Didit helps crypto businesses with the AMLR, MiCA and the Travel Rule
- Both AMLR routes: 14,000+ document types, NFC chip reading, passive and active liveness and face match, at $0.33 for a full KYC check, plus MitID, BankID Sweden, iDIN, Finnish Trust Network, Smart-ID and Mobile-ID in the same workflow, with a fallback to the document route. EUDI Wallet acceptance is coming soon. See eID verification.
- AML screening against 1,300+ lists for $0.20, and daily re-screening for $0.07 per person per year.
- Business verification with beneficial owners.
- Transaction monitoring with real-time rules for fiat and crypto, wallet screening inside it, case management and report preparation for the financial intelligence unit, which you file.
- A Travel Rule exchange in the IVMS 101 format over the open Travel Rule Protocol, with an email fallback, and self-hosted wallet ownership proof by message signing on EVM, Solana, Bitcoin and Tron wallets.
- Questionnaires, audit logs and a PDF report per session. Prices are on the pricing page.
Didit provides
- Identity checks by eID or by document, with the evidence
- Sanctions, PEP and watchlist screening, refreshed daily
- Travel Rule data exchange and wallet ownership proof
- Transaction rules, cases and report preparation
Stays with you
- The MiCA licence and the risk assessment
- The choice of route and its justification
- The decision to onboard, hold or reject
- Reports to the financial intelligence unit
Run onboarding and transfer checks in one workflow
Verify people and companies, screen wallets and exchange Travel Rule data under your own brand.
Key takeaways
- MiCA's transitional period ended by 1 July 2026 at the latest: crypto-asset services in the EU now need an authorisation or an Article 60 route, with only a narrow Article 61 exception.[1]
- The crypto Travel Rule applies to in-scope transfers with no minimum amount, plus an ownership check on self-hosted wallets above EUR 1,000.[4]
- The AMLR applies from 10 July 2027; under AMLA's draft standards, remote document checks are a justified fallback when the customer cannot reasonably show a document face to face and has no qualifying eID.[6][7]
- Firms required by law or contract to use strong user authentication for online identification, other than micro and small enterprises, accept the EUDI Wallet on request by the working date of 24 December 2027.[12][13]
PDF guide
Keep the clock, the AMLR data points, the cheat sheet and the quarterly plan on your desk. Download the PDF guide
Frequently asked questions
What is the MiCA regulation?
MiCA, Regulation (EU) 2023/1114, is the EU rulebook for crypto-asset issuers and crypto-asset service providers. It applies from 30 December 2024, and its stablecoin titles from 30 June 2024.[1] It sets authorisation, governance, conduct and custody rules, while the KYC rules come from the anti-money laundering framework.[1][6]
Can a crypto firm still serve EU customers without a MiCA licence?
Generally not. A MiCA authorisation is required, subject to the Article 60 routes for banks, investment firms, e-money institutions and other listed firms, and the narrow Article 61 exception.[1] The transitional period in Article 143(3) ended on 1 July 2026 at the latest, and earlier in member states that shortened it.[1][2] Article 61 covers only an EU client who approaches a third-country firm at its own exclusive initiative.[1]
What are the MiCA fines for a crypto-asset service provider?
For breaches of the CASP rules (Articles 59, 60, 64 and 65 to 83), Article 111(3) requires that supervisors can impose maximum fines on a company of at least EUR 5,000,000 and of at least 5% of total annual turnover.[1] For the asset-referenced token and e-money token rules the turnover floor is 12.5%, and member states may set higher amounts.[1]
Is there a minimum amount for the crypto Travel Rule in the EU?
No. Recital 30 of the Transfer of Funds Regulation says crypto transfers are subject to the same requirements regardless of their amount.[4] The rules apply where the CASP or intermediary CASP of either party has its registered office in the EU, and not to person-to-person transfers without a CASP or to transfers between CASPs acting on their own behalf.[4]
What must a CASP do for transfers to or from a self-hosted wallet?
It obtains and holds the originator and beneficiary information and makes sure the transfer can be individually identified.[4] Above EUR 1,000 it takes adequate measures to assess whether its customer owns or controls the address (Articles 14(5) and 16(2)).[4]
When does the AMLR apply to crypto-asset service providers?
From 10 July 2027.[6] CASPs are obliged entities as financial institutions, and they apply full customer due diligence to occasional transactions from EUR 1,000, while still identifying and verifying the customer below that amount.[6]
Does the AMLR make eID mandatory for onboarding?
No. Article 22(6) gives two means: an identity document with reliable and independent sources, or an eID at assurance level substantial or high.[6] Under AMLA's draft Article 7, remote document checks are used when the customer cannot reasonably show a document face to face and has no qualifying eID, and the firm must be able to justify that.[7]
Are AMLA's customer due diligence standards already law?
Not yet. AMLA's final report is dated 30 September 2026, and on 1 October 2026 AMLA announced that the drafts had been submitted to the Commission.[7][8] Once adopted and published in the Official Journal, they are proposed to apply six months after entry into force.[8]
When must crypto firms accept the EUDI Wallet?
Article 5f(2) of eIDAS gives private relying parties that must use strong user authentication for online identification by law or contract, including in banking and financial services, 36 months from the entry into force of the wallet implementing acts, a working date of 24 December 2027.[12][13] Acceptance applies only at the user's request, and micro and small enterprises are excluded.[12]
Will AMLA supervise crypto firms directly?
Some of them. In its first selection AMLA picks up to 40 financial institutions or groups, CASPs included, that operate in at least six member states and have a high residual risk profile.[10] AMLA says it takes over their direct supervision in 2028.[11]
Sources
- Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA), EUR-Lex, Official Journal of 9 June 2023, Articles 48, 59, 62, 65, 75, 76, 111, 143 and 149.
- List of grandfathering periods decided by Member States under Article 143 of MiCA, ESMA.
- Public statement on the provision of certain crypto-asset services in relation to non-MiCA compliant ARTs and EMTs, ESMA, 17 January 2025.
- Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets (TFR), EUR-Lex, Articles 14, 16, 17 and 40, recital 30.
- Travel Rule Guidelines, EBA/GL/2024/11, European Banking Authority, 4 July 2024.
- Regulation (EU) 2024/1624 (AMLR), EUR-Lex, Official Journal of 19 June 2024, Articles 2, 3, 19, 20, 22, 26, 79 and 90.
- Final Report, draft RTS under Article 28(1) AMLR on customer due diligence, AMLA, 30 September 2026, draft Articles 6, 7, 17, 28 and 29.
- AMLA finalises key standards for the private sector, AMLA press release, 1 October 2026.
- Final Report, draft RTS under Article 19(9) AMLR, AMLA, 2026, draft Articles 2(4) and 3(2).
- Regulation (EU) 2024/1620 establishing AMLA (AMLAR), EUR-Lex, Articles 12, 13 and 106.
- Explainer: direct supervision by AMLA, AMLA.
- Regulation (EU) 2024/1183 (eIDAS 2.0), EUR-Lex, Articles 5a, 5b and 5f.
- Commission Implementing Regulation (EU) 2024/2977 on person identification data for EUDI Wallets, EUR-Lex, published 4 December 2024.
- Regulation (EU) 2022/2554 on digital operational resilience (DORA), EUR-Lex, Articles 2, 9 and 64.
- Council Directive (EU) 2023/2226 (DAC8), EUR-Lex, Article 2 and Annex VI.
- Markets in Crypto-Assets Regulation (MiCA), interim MiCA register, ESMA.
The AMLR is nine months away. See how Didit maps the routes, data points and evidence on the AMLR page.
Get your EU onboarding ready for the AMLR
Set up eID and document routes, screening and Travel Rule checks, then test them on your own flows.
Related articles
- Companies House identity verification: Insolvency Service convictions
- Privacy coin regulation after FinCEN drops its mixing rule
- OSC Argosy decisions: KYC risk tolerance and a suspended UDP
- FinCEN verifiable digital credentials: mDLs under the CIP Rule
- Revolut data breach: the reported fake government request
- CIMA AML Rule: Cayman's audit filing duty explained