The EU crypto regulatory framework has now moved decisively from implementation to supervision and enforcement. With the MiCA transitional period ending across the EU on 1 July 2026, regulators are increasingly focused on how authorised CASPs actually operate: custody, operational resilience, client-asset protection, advice, crypto lending, sanctions compliance and exposure to DeFi.
At the same time, FATF is highlighting growing risks linked to stablecoins, unhosted wallets, offshore VASPs and decentralised finance, while European supervisors are increasing scrutiny of ICT and AI-related risks.
This month’s RegRally focuses on the developments most relevant to CASPs, crypto businesses, investment firms, issuers and financial institutions operating with digital assets.
Quick Navigation
- Latvia issues its 10th MiCA licence to Nodu Digital
- ESMA launches EU-wide supervisory action on CASP custody and operational resilience
- ESMA clarifies MiCA rules on crypto advice, lending and token distributions
- ESMA sets deadlines for the EU move to T+1 settlement
- European Supervisory Authorities highlight AI-driven ICT risks for financial entities
- FATF identifies growing risks around stablecoins, unhosted wallets and offshore VASPs
- FATF calls for a functional approach to DeFi regulation
- EU sanctions package introduces new crypto-specific restrictions
- Latvia issues investment firm licence following pre-licensing cooperation
- MiCA transitional period has ended: unlicensed CASPs must wind down
Latvia issues its 10th MiCA licence to Nodu Digital
Date: 9 July 2026 | Source: Latvijas Banka
Link
Latvijas Banka issued Nodu Digital SIA both a MiCA licence for crypto-asset services and a payment institution licence. The CASP authorisation covers the exchange of crypto-assets for funds and the provision of crypto-asset transfer services on behalf of clients.
Nodu Digital became the 10th company authorised under MiCA by Latvijas Banka. Once authorised in one EU Member State, a CASP can provide its authorised services across the EU through the cross-border notification mechanism.
Why it matters
The decision illustrates the growing importance of combining crypto-asset and payment regulatory analysis for businesses operating crypto payment models. For businesses whose model involves both fiat payment services and crypto-asset services, the regulatory perimeter may require parallel authorisation strategies.
Recommended actions
- Determine whether the proposed business model requires both CASP and PI authorisation.
- Map the regulatory perimeter before preparing the licensing application.
- Use Latvijas Banka’s pre-licensing consultations to resolve classification and authorisation questions early.
- Consider whether the business model can benefit from EU-wide cross-border provision following MiCA authorisation.
ESMA launches EU-wide supervisory action on CASP custody and operational resilience
Date: 8 July 2026 | Source: ESMA
Link
ESMA launched a Common Supervisory Action (CSA) with national competent authorities focusing on the digital operational resilience of CASPs providing custody services.
The supervisory exercise will examine how CASPs manage risks associated with distributed ledger technology, including:
- governance arrangements;
- private key and storage management;
- transaction controls;
- incident detection and response;
- smart contract risks; and
- dependencies on third-party providers.
National competent authorities will conduct the exercise on a risk-based sample of authorised CASPs from H2 2026 to H1 2027, with ESMA’s consolidated report expected in H2 2027.
Why it matters
This is a clear indication that MiCA supervision is moving beyond licensing documentation towards testing the operational substance of CASP business models.
Custody arrangements, key management and third-party dependencies are likely to receive particular supervisory attention.
Recommended actions
CASPs providing custody services should:
- review key-management and wallet-storage arrangements;
- verify segregation and transaction-control mechanisms;
- test incident detection and response procedures;
- document smart-contract risk controls;
- map critical third-party dependencies, including custody technology and blockchain infrastructure providers; and
- assess their framework against both MiCA custody requirements and DORA.
ESMA clarifies MiCA rules on crypto advice, lending and token distributions
Date: 10 July 2026 | Source: ESMA
Link
ESMA published a new batch of Q&As providing important clarifications on MiCA.
Three Q&As are particularly relevant to CASPs and crypto businesses.
Crypto-asset advice – Q&A 2882
ESMA clarified that the concept of advice on crypto-assets under MiCA is broader than investment advice under MiFID II. Certain introductory or referral activities recommending a crypto-asset service to a potential investor may therefore constitute advice requiring authorisation. A general reference to a CASP that is equally accessible to all investors does not, by itself, constitute advice.
Crypto-asset lending – Q&A 2883
ESMA confirmed that CASPs may offer crypto-asset lending as an unregulated service, subject to specific conditions. In particular, clients must provide prior, express and specific consent to the use of their assets. Consent embedded only in general terms and conditions is not sufficient.
The service must also include fair, clear and non-misleading risk disclosures and adequate collateral arrangements. MiCA safeguarding requirements do not apply to assets that have been lent.
Primary token offerings – Q&A 2417
ESMA clarified that an issuer transferring crypto-assets directly from an issuance smart contract to purchasers’ wallets in a primary offering does not, by that activity alone, provide custody or transfer services requiring CASP authorisation.
Why it matters
These clarifications affect the regulatory perimeter of referral models, crypto lending products and token issuance structures.
Recommended actions
- Review referral, affiliate and introduction arrangements to determine whether they could constitute crypto-asset advice.
- Redesign crypto lending consent flows so that client consent is standalone, prominent and specific.
- Review risk disclosures and revenue-sharing arrangements for lending products.
- For token issuances, document the precise role of the issuer and determine which activities fall within the CASP perimeter.
ESMA sets deadlines for the EU move to T+1 settlement
Date: 20 July 2026 | Source: ESMA – T+1 settlement preparations
Link
ESMA published a statement on preparations for the EU’s transition to a T+1 settlement cycle, scheduled for 11 October 2027.
Two key deadlines apply:
- 7 December 2026 – requirements relating to the exchange of allocations and confirmations, including timing requirements and the default use of international communication standards;
- 11 October 2027 – requirements aimed at optimising the settlement layer, including earlier submission of settlement instructions and broader use of CSD functionalities.
ESMA stresses that preparation must cover the entire trading and settlement chain, including clients, brokers, custodians, CSDs, CCPs, trading venues, vendors and outsourcing providers.
Why it matters for crypto and investment businesses
The transition is particularly relevant for investment firms and businesses with exposure to tokenised or traditional securities, where post-trade processes may involve multiple regulated and outsourced providers.
Recommended actions
- Map the complete post-trade chain and identify dependencies.
- Confirm vendor and custodian readiness for the December 2026 deadline.
- Review Standard Settlement Instructions and reference-data quality.
- Identify operational changes required before the 2027 transition.
European Supervisory Authorities highlight AI-driven ICT risks for financial entities
Date: 31 July 2026 | Source: ESMA – ESA statement on ICT risks from frontier AI
Link
The European Supervisory Authorities published a joint statement on ICT risks arising from frontier AI models.
The statement is particularly relevant to CASPs given the increasing supervisory focus on digital operational resilience. AI-enabled cyber tools can accelerate vulnerability discovery and exploitation, target shared infrastructure and exploit single points of failure.
The ESAs recommend strengthening ICT risk management through three areas:
- Prevention – comprehensive IT asset inventories, secure-by-design architecture, proactive patching and supply-chain controls.
- Detection – continuous vulnerability scanning, behavioural monitoring and more frequent testing.
- Management – resilience testing against AI-enhanced attack scenarios, dependency mapping and clear management-body accountability.
Why it matters
For CASPs, AI-related cyber risks may directly affect private keys, custody infrastructure, smart contracts and critical third-party services.
Recommended actions
CASPs should:
- include AI/ML components in ICT asset inventories;
- update vulnerability-management and monitoring processes;
- test resilience against AI-enhanced attack scenarios;
- map dependencies on critical ICT providers; and
- ensure management bodies receive appropriate information on AI-related cyber risks.
FATF identifies growing risks around stablecoins, unhosted wallets and offshore VASPs
Date: 16 July 2026 | Source: FATF – Seventh Targeted Update on Virtual Assets and VASPs
Link
The FATF’s Seventh Targeted Update on Recommendation 15 reports continued global progress in implementing requirements for virtual assets and VASPs.
According to the report, 83% of surveyed jurisdictions have now passed Travel Rule legislation, compared with 73% in 2025.
However, significant gaps remain in supervision and enforcement.
For the crypto sector, FATF highlights several emerging risks, including:
- industrialised virtual-asset-enabled fraud;
- misuse of stablecoins, which now feature in most identified on-chain illicit activity;
- P2P transactions involving unhosted wallets;
- offshore VASPs operating outside effective oversight; and
- risks associated with DeFi.
Why it matters
The report provides a useful benchmark for the risk-based AML/CTF and sanctions controls expected from CASPs.
Recommended actions
CASPs should:
- reassess stablecoin-related risks in their ML/TF risk assessments;
- review exposure to unhosted-wallet and P2P transactions;
- assess offshore VASP counterparties;
- test the quality and completeness of Travel Rule information; and
- update transaction-monitoring scenarios to reflect current crypto-specific typologies.
FATF calls for a functional approach to DeFi regulation
Date: 21 July 2026 | Source: FATF
Link
FATF published its Targeted Report on Regulatory Challenges from Decentralised Finance (DeFi), updating its earlier guidance.
The report promotes a functional, risk-based approach: regulators should look beyond the label “decentralised” and determine whether identifiable natural or legal persons exercise sufficient control or influence over a DeFi arrangement.
Relevant indicators include governance token concentration, administrative privileges, control over protocol upgrades, and significant economic benefits.
The FATF also highlights risks arising from interactions with DeFi protocols, including chain-hopping, cross-chain bridges, decentralised exchanges, mixers and governance manipulation.
Why it matters
Calling a protocol “decentralised” does not necessarily remove it from the regulatory perimeter. CASPs and financial institutions interacting with DeFi arrangements need to understand who actually controls or influences the protocol and what risks arise from the interaction.
Recommended actions
CASPs integrating DeFi protocols should:
- conduct and document a control analysis for each relevant protocol;
- assess governance-token concentration and administrator privileges;
- identify protocol-level and counterparty risks;
- reflect DeFi exposure in the business-wide risk assessment; and
- verify that appropriate due diligence and control measures can be applied before interacting with a protocol.
EU sanctions package introduces new crypto-specific restrictions
Date: 23 July 2026 | Source: European Commission – 21st sanctions package against Russia
Link
The EU’s 21st package of sanctions against Russia introduces several measures directly relevant to the crypto-asset sector.
The package creates a new mechanism that allows third-country legal entities that provide crypto-asset services used to circumvent EU sanctions to be designated. Systematic failure to prevent sanctions circumvention may trigger designation.
The package also introduces transaction bans involving additional third-country crypto platforms and crypto-linked firms, with more than 20 crypto-asset service financial institutions added.
In addition, restrictions on the ownership, control or board membership of companies providing crypto-asset services by Russian and Belarusian nationals have been extended.
Why it matters
Crypto businesses need to consider sanctions risk not only when screening direct customers but also when assessing counterparty platforms, liquidity providers, ownership structures and management.
Recommended actions
CASPs should:
- rescreen counterparties and crypto platforms against updated sanctions lists;
- review liquidity-provider relationships;
- refresh ownership and management nationality checks;
- assess third-country crypto counterparties for sanctions-evasion risk; and
- update sanctions representations and contractual clauses where necessary.
Latvia issues investment firm licence following pre-licensing cooperation
Date: 23 July 2026 | Source: Latvijas Banka – C Capital Markets licence
Link
Latvijas Banka issued an investment firm licence to SIA C Capital Markets, a subsidiary of AS Citadele banka, for the placing of financial instruments on a non-firm-commitment basis and related ancillary services.
The licence was issued less than one month after the official application was submitted, following pre-licensing cooperation with the regulator.
Latvia now has 12 licensed investment firms.
Why it matters for crypto businesses
Although the licence concerns an investment firm rather than a CASP, the case provides a useful indication of the potential efficiency of well-prepared licensing processes in Latvia.
For businesses considering MiCA, investment firm or combined regulatory structures, early regulatory dialogue can help resolve issues before the formal application is submitted.
Recommended actions
Applicants considering Latvian authorisation should:
- use the pre-licensing consultation process;
- establish the regulatory perimeter before filing;
- prepare a complete and internally consistent application package; and
- resolve governance, ownership, business-model and operational questions before formal submission.
MiCA transitional period has ended: unlicensed CASPs must wind down
Date: 2 July 2026 | Source: Lietuvos bankas – End of MiCA transitional period
Link
The EU-wide MiCA transitional period ended on 1 July 2026.
Unlicensed CASPs that are no longer entitled to rely on transitional arrangements must wind down their EU-facing activities in an orderly manner. During the wind-down process, firms must address client communications, positions and assets while maintaining applicable AML/CTF and Travel Rule controls.
Third-country CASPs cannot simply continue providing services to EU clients without an appropriate regulatory basis, and custody cannot be delegated to unlicensed providers.
Lietuvos bankas has also established a dedicated Investment and Crypto-Asset Firms Supervision Division, signalling a more specialised supervisory approach.
Why it matters
The end of the transitional period marks an important shift: operating in the EU crypto market now requires businesses to have a clear legal basis under MiCA or to cease the relevant activities.
Recommended actions
CASPs and crypto businesses should:
- confirm that all EU-facing crypto-asset services are provided through appropriately authorised entities;
- review whether any activities remain dependent on transitional arrangements;
- ensure orderly wind-down procedures are operational where authorisation has not been obtained;
- maintain AML/CTF and sanctions controls throughout any wind-down; and
- review outsourcing and custody arrangements to ensure that critical services are not being provided by unlicensed entities.
What crypto businesses should focus on now
The regulatory focus is shifting from “Are you licensed?” to “How are you operating?”
For CASPs and other businesses active in the crypto-asset market, the developments covered in this edition point to several immediate priorities:
- MiCA: confirm that all EU-facing activities have the appropriate regulatory basis.
- Custody: prepare for supervisory scrutiny of key management, wallet segregation, incident response and third-party dependencies.
- AML/CTF: strengthen controls around stablecoins, unhosted wallets, offshore VASPs and DeFi.
- Sanctions: review crypto counterparties, ownership structures, liquidity providers and sanctions-evasion risks.
- DORA: test ICT resilience against increasingly sophisticated and AI-assisted attacks.
- Business models: reassess referral, advisory, lending and other activities against the latest ESMA interpretations.
- DeFi: do not rely on the “decentralised” label; assess actual control and influence over the protocol.
- Licensing strategy: where authorisation is still required, use regulatory pre-licensing dialogue to resolve the perimeter and prepare a coherent application.
The direction of travel is clear: crypto regulation is becoming increasingly operational, risk-based and supervisory in practice.
Need assistance?
Our legal and regulatory specialists assist crypto-asset businesses with:
- MiCA licensing and regulatory perimeter analysis
- CASP authorisation and cross-border EU expansion
- AML/CTF and Travel Rule compliance
- Sanctions and crypto-asset sanctions screening
- DORA and ICT risk management
- Crypto custody and client-asset arrangements
- DeFi regulatory analysis
- Crypto lending and business-model structuring
- Token issuance and white-paper requirements
- Internal policies, procedures and compliance documentation
If you have questions about the regulatory developments covered in this edition or would like to assess your crypto-asset business model against the current EU regulatory framework, our team will be happy to assist you.
LT
RU
CN
DE