Myth 1: Being Registered Before December 2024 Means You're Covered Until July
Many mistakenly believe that VASP registration before December 30, 2024 guarantees grandfathering protection until July 1, 2026. In reality, MiCA Article 143(3) clearly states that a service provider must hold a granted authorization by July 1, 2026, not merely have applied for one. Each EU member state set its own application deadline for grandfathering, and the majority have already closed. According to ESMA's published list: Czech Republic set its deadline at July 31, 2025; Bulgaria on October 8, 2025; Germany, Lithuania, Ireland, Austria, and Slovakia all had 12-month periods from December 30, 2024, placing their deadlines around end of 2025. A VASP registered before December 30, 2024 but without an application filed before its member state's specific deadline cannot rely on grandfathering protection. Moreover, pre-MiCA VASP registrations were national AML designations, not financial services licenses with cross-border effect. The grandfathering regime did not change this; a VASP registered in Poland under a 6-month period had no legal basis to solicit users in Austria. Cross-border activities during the transitional period required either a full MiCA CASP authorization, complete absence of solicitation (reverse solicitation), or multiple domestic VASP licenses. For most, those windows have passed.
Myth 2: Applying Is Just a Matter of Submitting the Paperwork
In some jurisdictions, the problem isn't missing a deadline—it's that there is no authority to submit to. Poland is the clearest case. The country's grandfathering period was six months from December 30, 2024, with an implied deadline around June 2025. But deeper than a missed date: in December 2025, the Polish president vetoed the bill enacting MiCA into national law, leaving no designated National Competent Authority (NCA). No NCA means no state body to receive, process, or issue CASP applications. The KNF (Polish financial regulator) has stated that registered Polish VASPs may operate until July 1, 2026, but if no NCA is established by then, those businesses must cease crypto-asset services on July 2. This hard deadline is embedded in EU regulation and cannot be extended by national law or KNF decision. Meanwhile, foreign service providers holding authorizations from other EU member states can passport into Poland by notifying KNF, while Polish-registered VASPs cannot passport out, cannot apply domestically, and face a hard stop. Romania reflects a comparable legislative delay. To assess if a platform is in the 'gap zone,' check: Is it registered in a member state that hasn't enacted MiCA implementing legislation? Did it miss its member state's CASP application deadline? Is it currently operating without a pending authorization application? If any answer is 'yes,' grandfathering protection is already lapsed or will lapse on July 1.
Myth 3: The Reverse Solicitation Escape
A popular plan among European founders is to de-register locally, stop marketing to EU users, let users come unsolicited, and claim the reverse solicitation exemption. However, MiCA Article 61's reverse solicitation exemption is narrow: it applies only when a client established in the EU approaches a third-country firm entirely on its own exclusive initiative, with no prior solicitation from the firm or anyone acting on its behalf. ESMA's Final Report on Reverse Solicitation identifies many factors that constitute solicitation: maintaining a website in a local EU language not customary in international finance (e.g., Hungarian, Czech, Slovak) is a strong indicator of targeted marketing; any commercial arrangement—affiliates, referral partners, third-party platforms—that promotes services to EU audiences; SEO ranking in German or French search results; country-code domains; participating in EU-facing conferences. The presence or absence of an EU legal entity is not decisive. Providing crypto-asset services to EU clients without authorization after July 1 is unauthorized financial services, subject to criminal liability in several member states (e.g., Poland). Some NCAs, like the AFM in the Netherlands and BaFin in Germany, are proactively reaching out to entities they identify as in breach. Attempting to rely on reverse solicitation as a primary post-July strategy is extremely risky.
| Counts as Solicitation | Reverse Solicitation Exemption Conditions |
|---|---|
| App available in any localized EU App Store | User navigates directly to URL with no prior contact |
| Influencer partnerships where audience includes EU users | User contacts platform after independent discovery with no promotional activity |
| Website available in a local EU language or country-code domain (.pl, .ro) | User explicitly and independently initiates the service relationship, supported by factual records |
| Geo-targeted social content or paid digital placements reaching EU users | No localized UX, no marketing materials, no promotional activity preceded the contact |
The Arithmetic of 'Pending': Submission Does Not Equal Approval
For service providers who have applied but not yet received authorization, the picture is nuanced. A pending application does not grant the right to operate past July 1, 2026. The regulation requires authorization to be granted, not merely filed. If an application is complete, submitted in a well-resourced jurisdiction, and moving through review, authorization may arrive before the deadline. But if the application is incomplete, filed recently, or sitting in a congested pipeline, it may not. There is no general right of continued operation while review is underway past the hard deadline. Direct communication with the NCA about specific timelines is essential. Also, Iceland and Liechtenstein adopted 18-month grandfathering periods through EEA integration, placing their windows in line with the EU's July 2026 cliff—the structural deadline applies throughout the EEA.
Restructuring: What It Actually Involves
For service providers in blocked jurisdictions, one path to business continuity is restructuring to a member state with a functioning CASP authorization pipeline. Malta, Austria, Ireland, and Lithuania are among jurisdictions where applications are being processed. Restructuring requires more than just the authorization application itself. Practical requirements include: establishing a legal entity with genuine governance and operational presence (not a shell); having share capital paid up in a formal credit institution (an EMI or PI account is insufficient); passing KYC. The firm must ensure complete cessation of prior EU activities before relying on a non-EU licensing position. Under MiCA, third-country firms are broadly prohibited from providing crypto-asset services in the EU while maintaining an operational footprint. Existing EU clients must be handled with extreme care: ESMA's Final Report explicitly prohibits EU-regulated entities (including group companies) from soliciting or redirecting EU clients to third-country firms. Simply redirecting users to the non-EU entity's website constitutes a breach. For service providers who cannot secure authorization before July 1, operations must pause on that date; license application can continue during the pause. Banks are already reaching out to VASP-only clients, informing them that banking services will stop after July 1 unless proof of a CASP application or license is provided. Business interruption is real but may be short for those with credible applications already filed. The greater risk is for those who haven't filed at all and are trying to compress a multi-month process into weeks.
Conclusion: What MiCA's Grandfathering Regime Actually Says
This article decodes the widespread misreading of MiCA's transitional rules. On the timeline: July 1, 2026, is the date by which authorization must be held, not acted upon. For most EU member states, the real application deadline passed between June and December 2025. Service providers who didn't file by their jurisdiction's specific deadline cannot use grandfathering protection. On passporting: A pre-MiCA VASP registration never granted cross-border solicitation rights; it was a national AML designation. The transitional periods confirmed that restriction. On the legislative gap: Where implementing legislation wasn't enacted, no NCA exists to receive CASP applications. Service providers in those jurisdictions face a structural problem: they cannot apply domestically, cannot passport out, and will lose the right to operate on July 1. On reverse solicitation: The exemption is not a fallback strategy; it applies only to third-country firms with no EU-directed commercial activity. EU-based VASPs cannot invoke it. Even third-country firms must ensure residual activities (SEO, affiliates, conferences) don't constitute solicitation. On what comes next: Authorization processes take months. Pending applications do not extend operational rights past July 1. Service providers without a filed application today are not three months away from a solution. The realistic question is whether restructuring into a functioning jurisdiction, with full operational requirements, is viable within the available window. Next week, this series will examine the actual duration of CASP application processes.

