A Markets in Crypto-Assets Regulation (MiCA) license lets a firm serve the whole EU from one Member State, but it does not take local supervisors out of the picture. September’s developments show where cross-border firms still face local requirements, inside the EU and beyond it.
This edition is for crypto-asset service providers (CASPs), investment firms and fund managers in the Baltics and across the EU.
At a glance
- EU AML/CFT: the European Commission adopted Delegated Regulation C(2026) 6179, extending the anti-money laundering and countering the financing of terrorism (AML/CFT) central contact point standards to CASPs. A host Member State may require a contact point where, among other criteria, the value of services provided by a CASP’s local establishments exceeds EUR 3 million per financial year, or where the money laundering and terrorist financing (ML/TF) risk justifies it.
- MiCA review: the European Banking Authority (EBA) identified four priorities: multi-issuer stablecoin schemes with third-country issuers, the scope and classification of crypto-assets, crypto-asset lending, and reporting. 39 electronic money tokens (EMTs) had been issued as of 1 September 2026.
- Latvia: Latvijas Banka licensed SIA IBC INVEST as an investment firm. This was the third license in 2026, making it the 13th licensed investment firm in Latvia. It also registered SIA “Finterra” as an alternative investment fund manager (AIFM), bringing the total to 31 registered and three licensed managers.
- United Kingdom: the Financial Conduct Authority (FCA) published final perimeter guidance and opened its authorization gateway. The regime takes effect on 25 October 2027, and existing firms that apply by 28 February 2027 can continue operating while their application is assessed.
- ESMA: the European Securities and Markets Authority (ESMA) set a new Union Strategic Supervisory Priority (USSP) on digital innovation, covering artificial intelligence (AI) and tokenization, which applies from 2027. ESMA’s 2027 priorities also cover MiCA convergence, Digital Operational Resilience Act (DORA) oversight, the Retail Investment Strategy and T+1 settlement.
Quick Navigation
- European Commission extends central contact point requirements to CASPs
- EBA identifies four priorities for the MiCA review
- Latvia issues its third investment firm license of 2026 to IBC INVEST
- Latvia registers Finterra as an alternative investment fund manager
- FCA clarifies the scope of the UK cryptoasset regime
- ESMA makes digital innovation a supervisory priority for 2027
- ESMA outlines its 2027 supervisory priorities
- FCA opens UK cryptoasset authorization gateway
European Commission extends central contact point requirements to CASPs
Date: 8 September 2026 | Source: European Commission
Link
The European Commission adopted a Delegated Regulation (C(2026) 6179) that extends the regulatory technical standards on central contact points in Commission Delegated Regulation (EU) 2018/1108 to CASPs. Until now, these standards applied only to electronic money issuers and payment service providers operating in a host Member State through establishments other than branches.
A host Member State may require a CASP headquartered in another Member State to appoint a central contact point where, among other criteria, the cumulative value of the services and activities of its establishments in the host territory is expected to exceed EUR 3 million per financial year, or exceeded that amount in the previous financial year. It may also do so where this is commensurate with the ML/TF risk. The contact point must:
- facilitate the implementation of the CASP’s AML/CFT policies and procedures in the host state
- oversee compliance and inform the head office of breaches
- represent the CASP before the host supervisor and financial intelligence unit (FIU)
The act follows an EBA consultation and cost-benefit analysis. It enters into force twenty days after publication in the Official Journal, subject to scrutiny by the Parliament and the Council.
Why it matters
A MiCA authorization allows cross-border services within the EU, but local AML/CFT requirements still matter. For CASPs operating through establishments other than branches, a host-state contact point can mean additional local compliance responsibilities. CASPs providing only advice on crypto-assets fall outside the definition used in this act.
What we recommend for cross-border CASPs
- CASPs authorized in Lithuania or Latvia that serve other Member States through agents, physical points or local entities that are not branches should calculate the value of services provided in each country and identify where a host-state request is likely.
- Prepare a central contact point job description and reporting line that can be put in place on request.
- Reflect this possibility in the group AML/CFT policy and in the MiCA passport notifications.
EBA identifies four priorities for the MiCA review
Date: 24 September 2026 | Source: EBA
Link
The EBA published its response to the European Commission’s targeted consultation on the review of MiCA, identifying four priorities:
- Multi-issuer stablecoin schemes. The framework for schemes involving third-country issuers should be strengthened because the EBA assesses their risks as significant to very significant. Separately, the reserve requirements for issuers, notably the minimum amount of reserves held as deposits, should be reviewed.
- Scope and classification. The Commission should clarify the scope and classification of crypto-assets because uncertainty about classification creates avoidable costs and delays in launching products.
- Crypto-asset lending. The EBA encourages regulation of crypto-asset lending, including where CASPs facilitate access to decentralized lending protocols, because of the risks to consumers.
- Reporting. The reporting framework for issuers and service providers should be reviewed to improve supervision and risk monitoring.
The EBA notes that 39 EMTs had been issued as of 1 September 2026.
Why it matters
For stablecoin issuers and distributors, the review may change reserve requirements, while clearer classification rules could reduce uncertainty for firms developing products that sit between MiCA and other EU financial rules. Crypto-asset lending may also come within scope, but the EBA recommendations do not themselves create new obligations.
What we recommend for CASPs, crypto lenders and stablecoin issuers
- CASPs offering or intermediating lending, earn or staking-like yield products, or providing access to decentralized finance (DeFi) lending protocols, should document the legal analysis of these activities under current MiCA and national law. They should also prepare for these products to be brought expressly within scope.
- EMT issuers and CASPs distributing stablecoins issued under multi-issuer schemes with non-EU issuers should assess how changes to reserve requirements and stricter requirements for multi-issuer schemes would affect liquidity and redemption arrangements.
- Track the Commission’s MiCA review report and any legislative proposal, and align product classification memos with the EBA and ESMA positions on scope.
Latvia issues its third investment firm license of 2026 to IBC INVEST
Date: 17 September 2026 | Source: Latvijas Banka
Link
The Supervision Committee of Latvijas Banka issued an investment firm license to SIA IBC INVEST. The license covers reception and transmission of orders, execution of orders on behalf of clients, dealing on own account, portfolio management, and placing of financial instruments without a firm commitment. It also covers two ancillary services: safekeeping of financial instruments and services related to underwriting.
This is the third investment firm license Latvijas Banka has issued in 2026, bringing the number of licensed investment firms in Latvia to 13. Latvijas Banka encouraged applicants to use its licensing guide and pre-licensing consultations.
Why it matters
Latvia’s fintech strategy for 2025–2027 targets a 30% increase in the number of fintech companies in the country, and Latvijas Banka continues to authorize new firms.
What we recommend for investment firms and applicants in Latvia
- Firms considering a Markets in Financial Instruments Directive II (MiFID II) license in Latvia should note the pace of authorizations in 2026 and use the pre-licensing consultation to prepare their application. They should focus on the initial capital for the requested services, safeguarding of client instruments and the conflicts framework for own-account dealing.
- Existing Latvian investment firms should review the competition and confirm that their own permissions cover the services they plan to add.
Latvia registers Finterra as an alternative investment fund manager
Date: 23 September 2026 | Source: Latvijas Banka
Link
The Supervision Committee of Latvijas Banka registered SIA “Finterra” as an AIFM on 22 September 2026. The company may provide alternative investment fund management services and supplementary services as provided in the Law on Alternative Investment Funds and their Managers.
Latvia now has 31 registered and three licensed AIFMs. Latvijas Banka directed applicants to the registration procedure and required documents on its website, where registration applications are submitted electronically.
Why it matters
For sponsors of smaller funds, registration may be an option where the applicable conditions are met. The choice between registration and a full license matters when planning how far the fund will grow and where it will raise capital.
What we recommend for fund managers and sponsors in Latvia
- Sponsors planning sub-threshold fund structures in Latvia should use the registration route where assets under management remain below the Alternative Investment Fund Managers Directive (AIFMD) thresholds. If the strategy anticipates leverage or growth that would take assets under management beyond the thresholds, they should plan for a full license.
- Registered managers should monitor the thresholds and the marketing rules that apply to sub-threshold managers, since registration does not confer a marketing passport.
FCA clarifies the scope of the UK cryptoasset regime
Date: 16 September 2026 | Source: FCA (UK)
Link
The FCA published final perimeter guidance on how the UK cryptoasset regime applies to different business activities: issuing qualifying stablecoins, operating a cryptoasset trading platform, dealing and arranging deals, safeguarding cryptoassets and arranging staking. The guidance clarifies “adding value” activities, staking arrangements and the distinction between asset types.
The FCA confirmed that authorization applications open on 30 September 2026 and that the regime takes effect on 25 October 2027. The Government has laid a final amending statutory instrument with limited exclusions, including for UK qualifying stablecoins and a technical-services exclusion from the arranging activity. The FCA will consult in October 2026 on targeted updates to the guidance. Pre-application meetings and webinars are available to prospective applicants.
Why it matters
The guidance helps firms serving UK customers determine which activities may require FCA authorization. For businesses operating in both the EU and the UK, this affects the scope of their UK application and how they organize compliance across the two regimes.
What we recommend for EU CASPs operating in the UK
- EU CASPs serving UK customers should use the guidance to map each of their services against the UK regulated activities. They should then decide whether to seek UK authorization, restructure the UK offering or withdraw before 25 October 2027.
- Groups with both MiCA and UK authorization plans should align governance, safeguarding and conflicts arrangements so that a single control framework satisfies both regimes. They should also book pre-application meetings early.
ESMA makes digital innovation a supervisory priority for 2027
Date: 23 September 2026 | Source: ESMA
Link
ESMA announced a new USSP on digital innovation, effective from 2027. The priority will focus on how supervised entities use AI and tokenization, with flexibility to cover other emerging technologies. It runs alongside the existing USSP on cyber and operational resilience launched in 2025. ESMA is also concluding the priority on environmental, social and governance (ESG) disclosures, launched in 2023.
ESMA will work with national competent authorities to ensure supervisors have the expertise and capacity to oversee the use of new technologies. Supervised entities, including investment firms, fund managers, trading venues and CASPs, should expect more supervisory attention to the governance, risk management and client-facing use of AI and tokenized instruments.
Why it matters
The priority helps direct national supervisory resources, so firms using AI or tokenization can expect these activities to receive more attention from 2027. This makes the governance and risk controls around their use relevant to supervisory reviews.
What we recommend for firms using AI and tokenization
- List the AI tools used in client onboarding, suitability and appropriateness assessments, trading, surveillance and customer communication. Document the governance, testing and human oversight arrangements for each.
- Firms issuing or servicing tokenized financial instruments should review how they classify the instruments under MiFID II and MiCA, and how custody, settlement and investor disclosure are handled. Lietuvos bankas and Latvijas Banka are expected to align their 2027 supervisory work programs with the USSP.
ESMA outlines its 2027 supervisory priorities
Date: 28 September 2026 | Source: ESMA
Link
ESMA published its 2027 priorities, describing 2027 as the year in which many Savings and Investments Union initiatives move into the delivery phase. ESMA will:
- strengthen supervisory convergence with national competent authorities on CASPs under MiCA
- advance the oversight of critical information and communication technology (ICT) third-party service providers under DORA, together with the other European Supervisory Authorities (ESAs)
- support the implementation of the Retail Investment Strategy and continue its simplification work, including on the retail investor journey
Other priorities include implementing the European Single Access Point, transitioning to T+1 settlement, reviewing the impact of the clearing reforms under the European Market Infrastructure Regulation (EMIR) 3 and deploying AI-based supervisory tools.
Why it matters
For CASPs, closer convergence on MiCA aims to make supervision more consistent across Member States. For investment firms and fund managers, work on the Retail Investment Strategy and T+1 settlement is relevant to how they serve retail investors and organize post-trade operations.
What we recommend for CASPs, investment firms and fund managers
- CASPs authorized in the Baltic states should expect peer reviews, common supervisory actions and Q&A-driven convergence on MiCA topics such as reverse solicitation, custody segregation and conflicts of interest. They should keep their policies aligned with ESMA guidance as it is issued.
- Investment firms and fund managers should plan for Retail Investment Strategy changes to inducements, value-for-money and disclosure rules, and for T+1 operational changes.
FCA opens UK cryptoasset authorization gateway
Date: 30 September 2026 | Source: FCA (UK)
Link
The FCA opened the authorization gateway for cryptoasset firms. Firms that want to carry on regulated cryptoasset activities in the UK from 25 October 2027 can now apply. The FCA stresses that authorization is not automatic: applicants must demonstrate compliance with standards on consumer protection, safeguarding of assets, market integrity and financial resilience.
Existing firms that apply by 28 February 2027 benefit from transitional arrangements. They can continue providing cryptoasset services, including taking on new customers, while their application is assessed, even if a decision is not reached before the regime takes effect. Pre-application meetings and webinars are available.
Why it matters
For existing cryptoasset firms intending to remain in the UK market, applying by 28 February 2027 is important for business continuity: it allows services and new business to continue while the application is assessed. This transitional protection does not guarantee authorization.
What we recommend for CASPs serving UK customers
- CASPs with UK customers that intend to remain in the UK market should aim to apply well before 28 February 2027 to secure transitional protection. They should prepare a UK-specific regulatory business plan, safeguarding arrangements and evidence of financial resilience.
- Firms that will not apply should plan an orderly withdrawal from UK customers before 25 October 2027 and update terms, marketing and geo-restrictions accordingly.
Our view
The UK application deadline is the only deadline in this edition that firms can act on now: applications filed by 28 February 2027 preserve transitional protection. The EU changes come later. The central contact point rules still need publication, the Commission is assessing responses to its MiCA review consultation, which closed on 30 September, and ESMA’s new priority applies from 2027. We expect the ESMA priorities and the central contact point rules to become part of day-to-day supervision in the Baltics in 2027, while any MiCA amendments would follow a separate legislative process.
In Latvia, interest from crypto-asset businesses keeps growing, and we are receiving inquiries about MiCA licensing in Latvia. Latvijas Banka continues to issue MiCA licenses, and we will cover the latest authorizations in next month’s edition.
How ECOVIS ProventusLaw can help crypto and investment businesses
ECOVIS ProventusLaw advises crypto-asset businesses, investment firms and fund managers on EU licensing, regulatory compliance and cross-border operations.
Our services related to the developments covered in this edition include:
- Gap assessments, compliance reviews and remediation – reviewing existing authorizations and operations against current requirements and supervisory priorities, and addressing identified gaps.
- MiCA authorization and CASP regulatory compliance – licensing strategy, regulatory perimeter assessments, EU passporting and ongoing compliance.
- Token classification and MiCA white papers – legal analysis of token offerings, stablecoins, tokenized assets and related regulatory requirements.
- MiFID II investment firm licensing – authorization applications, scope of permitted activities, governance and regulatory documentation.
- Investment fund management and AIFM licensing – fund structures, manager registration and licensing, and regulatory requirements.
- AML/CFT compliance – host-state requirements including central contact points, risk assessments, internal policies, controls and compliance arrangements for financial institutions and crypto businesses.
- Regulatory compliance and risk management – preparation for supervision, governance, DORA and ICT risk management, regulatory reporting and internal controls.
If your plans involve a license application, a question about the regulatory perimeter or a new regulatory proposal, we can help you assess the work required before the regulator asks.
Why ECOVIS ProventusLaw
ECOVIS ProventusLaw is one of the most experienced financial regulatory law firms in the Baltics, with a long track record of advising financial institutions and early participants in the cryptocurrency market.
Our teams operate across Lithuania, Latvia and Estonia, providing clients with a single point of contact for regulatory and compliance matters throughout the Baltic region. Through the ECOVIS International network, present in more than 90 countries, we also support businesses operating across multiple jurisdictions.
As an early legal advisor to crypto businesses in the Baltics, ECOVIS ProventusLaw has developed extensive experience across all stages of crypto and financial services operations. We have advised on more than 40 end-to-end licensing projects, from initial business structuring and regulatory applications to ongoing supervision and compliance.
Our highly qualified and experienced regulatory and compliance teams within the Banking and Finance and FinTech departments work together to provide coordinated legal and operational support, including licensing, AML/CFT, sanctions, internal controls and regulatory risk management.
LT
RU
CN
DE