5 min read

Written by
Colossus Digital
Published on
Aug 5, 2026
Introduction
More than a month after the end of MiCA’s (Markets in Crypto-Assets Regulation) transitional period, many institutions are still reassessing whether their crypto counterparties meet the new regulatory standard. As of August 2026, authorisation is no longer a future milestone, it is the baseline for operating in the European Economic Area. That grace period is over now.
Who an institution can legally work with, and how custody gets structured, both depend on the answer to a much blunter question than a month ago: is your counterparty actually authorised, or not.
What has changed after 1 July
ESMA laid out what happens next in its Public Statement of 23 June 2026. Any CASP without full MiCA authorisation by 1 July 2026 has to wind down its EU activity in an orderly manner:
No onboarding of new EU clients, no marketing, no solicitation
Services limited to selling, transferring, reallocating, or closing positions clients already hold
Custody of client assets can continue, but only for as long as the exit genuinely requires
Clients need to be told, clearly and repeatedly, how the wind-down will work
There’s one line in the statement that matters more than the rest for institutional infrastructure specifically: MiCA prohibits CASPs from outsourcing or delegating custody to entities that aren’t themselves authorised CASPs, and that applies in a business-to-business context too. Working with an unauthorised sub-provider doesn’t get anyone around the rule.
What this means for Institutions like Banks, Funds, Asset managers
For banks, asset managers, funds and other institutional investors, the end of the MiCA transitional period is more than a regulatory milestone, it marks a shift in how digital-asset counterparties should be assessed. Authorisation is no longer an indicator of future readiness; it is now a prerequisite for participating in the regulated European crypto market. Institutions can no longer rely on the assumption that providers operating under legacy national registration regimes will eventually become compliant. Instead, due diligence should begin with verifying whether every CASP and other critical service provider within the operational chain holds the necessary MiCA authorisation or is otherwise legally permitted to provide the relevant services.
This also broadens the scope of operational risk management. Compliance is no longer limited to selecting a regulated primary counterparty; institutions should understand how custody, outsourcing and transaction execution are structured across their entire digital-asset infrastructure. A provider may appear compliant at first glance, but if critical services are delegated to unauthorised entities, the institution could still face regulatory, operational and reputational risks. As digital assets become increasingly integrated into institutional portfolios, counterparty due diligence should extend beyond financial strength and technical capability to include governance, licensing status and the resilience of the underlying operating model.
Ultimately, MiCA raises the standard for institutional participation in the European digital-asset market. Institutions that proactively review their counterparties, reassess custody arrangements and align their internal governance with the new regulatory framework will be better positioned to scale digital-asset activities with confidence. In this new environment, regulatory compliance is no longer simply a legal requirement, it has become a key component of institutional trust, operational resilience and long-term market access.
IN SHORT...
Authorisation is now the baseline: Institutions should verify that every crypto counterparty holds the required MiCA authorisation before entering or maintaining a business relationship.
Counterparty due diligence becomes more critical: Assessments should extend beyond financial strength to include licensing status, governance and regulatory compliance across the entire service chain.
Custody structures require closer scrutiny: Institutions should understand where assets are held, who controls private keys and whether any custody or safeguarding functions rely on unauthorised third parties.
Operational and regulatory risk are now closely linked: A compliant primary provider may still expose an institution to risk if key services are delegated to entities that do not meet MiCA requirements.
Infrastructure decisions become strategic: Institutions should favour custody and execution models that support regulatory compliance, operational resilience and long-term scalability.
What about firms still waiting for authorisation?
Not every unauthorised CASP is in the same position, and the deadline itself wasn’t uniform to begin with. Article 143 of MiCA let each EU member state set its own transitional window, from 6 months to the full 18. Netherlands, Finland, Poland, Latvia, Hungary and Slovenia chose the shorter end, while France, Malta, Luxembourg and Italy took the full 18 months, closing 30 June 2026.
Whatever a firm’s home state chose, 1 July 2026 was the hard outer limit everywhere in the EU. There’s also a shortcut most firms don’t get: MiCA’s simplified procedure under Article 143(6) applies only to entities that were authorised under national law before 30 December 2024, not merely registered, and most national VASP regimes, including Italy’s OAM register, count as registration.
That means most firms are going through the full authorisation process, which realistically takes six to ten months once pre-filing engagement and follow-up requests are factored in. Firms still waiting should treat their actual status with their national competent authority as the only reliable read on where they stand, not the fact that a filing exists somewhere.
Why this matter beyond retail
Most of the attention surrounding the 1 July deadline has focused on retail investors moving assets before exchanges lost their ability to operate in the EU. However, MiCA makes no distinction between retail and institutional clients in this respect. For institutions, the key question is whether every provider delivering a regulated crypto-asset service within their operating model is appropriately authorised. If not, the institution is exposed to regulatory and operational risk today, not at some point in the future.
That’s really the point of the deadline: a counterparty relationship that was fine to tolerate under a “we’re getting there” registration was never actually fine, it was just tolerated because the regime wasn’t fully in force yet.
What being a regulated entity actually means
CASP authorisation replaces something bigger than a rebrand. VASP registration under AML/CFT rules was largely a compliance checkbox; CASP authorisation under MiCA is a full financial services licence, closer to what banks and investment firms hold. In practice, that means initial capital requirements, governance and “fit and proper” standards applied to directors individually, rules on segregating client assets, complaints handling, conflicts of interest controls, outsourcing restrictions, and DORA-aligned ICT risk management, with directors personally accountable for breaches, not just the entity.
For institutional capital, that’s the piece that was missing. Banks, asset managers, and ETF issuers don’t commit meaningfully to a market without a supervised, accountable counterparty structure behind it, the same baseline they’d expect from any regulated financial provider. MiCA authorisation gives the industry exactly that: a certification institution can actually rely on, not a self-declared registration, backed by capital requirements and personal accountability for the people running the business. For an institution evaluating a counterparty, the question stops being whether a provider is registered somewhere, and becomes whether it’s built into the kind of regulated, controlled ecosystem institutional capital was always going to require before committing at scale.
Architecture, not just authorisation
Meeting MiCA’s requirements is not only about choosing authorised counterparties, it is also about how digital-asset services are architected. The regulation places significant emphasis on accountability, particularly where custody and safeguarding of client assets are concerned. As a result, institutions are increasingly evaluating not only the regulatory status of their providers, but also whether their operating model introduces unnecessary custody or outsourcing risks.
One approach that is gaining traction is the use of non-custodial execution models. Instead of transferring assets or private keys to multiple service providers, institutions retain custody with their chosen authorised custodian while external providers deliver execution or non-custodial staking services without ever taking control of client assets. This creates a clearer separation between custody and execution, reducing operational complexity and helping preserve an unbroken chain of accountability.
Colossus Digital’s Institutional Hub is designed around this principle. Transactions are prepared by the platform but authorised within the institution’s existing custody environment and executed directly on-chain, without Colossus taking possession of client assets or private keys. Rather than replacing an institution’s custody arrangements, the model is intended to integrate with an institution’s existing custody infrastructure, allowing organisations to maintain their established regulated custody relationships while accessing non-custodial staking services.
As institutional adoption of digital assets continues to grow, this distinction is becoming increasingly relevant. Under MiCA, the regulatory status of a provider remains fundamental, but the way custody, execution and operational responsibilities are distributed across the technology stack may become just as important when assessing operational resilience and counterparty risk.
Conclusion
MiCA stopped being the framework institutions were preparing for on 1 July. It’s the framework they operate under now. Whether a counterparty holds valid MiCA authorisation now determines whether it can legally hold, move, or safeguard institutional digital assets in the EU at all.
The transition to MiCA is no longer about regulatory preparation; it is about operational resilience. Institutions that review counterparties, custody models and outsourcing arrangements today will be better positioned to scale digital-asset activities within a regulated European market. As crypto infrastructure becomes increasingly institutional, governance and architecture are likely to matter as much as technology itself.
Found this article useful?
If you’re looking to generate yield without moving assets out of your existing custody provider, schedule a call with our team:
Disclaimer
This article is provided for general informational purposes only and does not constitute legal, regulatory, financial, investment or tax advice. The information reflects the authors’ understanding of the Markets in Crypto-Assets Regulation (MiCA), related regulatory guidance and publicly available sources as of the date of publication. Regulatory requirements may evolve, and their application depends on the specific facts and circumstances of each organisation.
Readers should not rely on this article as a substitute for obtaining independent legal or professional advice. Before making any decision relating to MiCA compliance, digital asset custody, outsourcing arrangements or the selection of crypto-asset service providers, organisations should consult their legal, compliance and regulatory advisers.
Any references to third-party companies, products or technologies are provided for illustrative purposes only and do not constitute an endorsement or representation regarding their regulatory status, suitability or compliance with applicable laws.
Nothing in this article should be interpreted as a statement regarding the regulatory status of Colossus Digital or any other market participant. Whether a particular activity requires authorisation under MiCA depends on the specific services provided, the applicable legal framework and the assessment of the relevant competent authorities.
Last updated: August 2026
FAQ
· Does every company operating in the digital asset ecosystem need MiCA authorisation?
No. Under MiCA, authorisation as a Crypto-Asset Service Provider (CASP) is generally required for entities that provide one or more regulated crypto-asset services on a professional basis, such as custody and administration of crypto-assets, execution or transmission of orders, transfers of crypto-assets, or the operation of a trading platform.
By contrast, companies that provide technology, such as software, wallet infrastructure, APIs or MPC (Multi-Party Computation) solutions, may not require CASP authorisation if they are not themselves performing a regulated crypto-asset service. As with all regulatory assessments, the determining factor is the substance of the activities performed, rather than the technology used or the way a company describes its business model.
· Who needs CASP authorisation?
Under MiCA, any entity providing crypto-asset services on a professional basis within the European Union generally requires authorisation as a Crypto-Asset Service Provider (CASP), unless a specific exemption applies. The regulation covers a broad range of activities, including:
· Custody and administration of crypto-assets on behalf of clients.
Operating a crypto-asset trading platform.
Exchanging crypto-assets for funds or for other crypto-assets.
Executing or receiving and transmitting orders on behalf of clients.
Providing portfolio management or investment advice relating to crypto-assets.
Transferring crypto-assets on behalf of clients.
· Does MiCAR prohibit staking?
No. Staking itself isn’t restricted, but if a provider holds client assets or private keys, the staking service counts as ancillary to custody and requires authorisation. This is called custodial staking.
· Why should institutions consider a non-custodial infrastructure for staking and yield generation?
A non-custodial architecture allows institutions to access staking and other yield-generating opportunities while retaining control of their assets and private keys within their existing custody environment. Rather than transferring assets to a third-party provider, transactions are authorised by the institution or its authorised custodian and executed without the infrastructure provider taking possession of client assets.
This approach can help reduce operational complexity, preserve existing custody arrangements and maintain a clear allocation of responsibilities across the service chain. While a non-custodial model does not in itself determine whether MiCA authorisation is required, it can support governance, risk management and custody practices that are better aligned with the expectations of institutional investors and regulated financial institutions.
· Can an unauthorised CASP still provide custody?
Only for as long as strictly necessary to wind down existing positions in an orderly manner. No new clients, no new custody relationships.
· Can institutions continue working with pending applicants?
Only if that firm’s home member state transitional window hasn’t closed yet. Deadlines vary by country, but 1 July 2026 was the hard outer limit everywhere in the EU.
· What does MiCAR mean for Banks?
For banks, MiCAR establishes a harmonised regulatory framework for offering crypto-asset services across the European Union. It raises the standard for counterparty due diligence, governance and operational resilience, requiring banks to assess not only whether their service providers are appropriately authorised, but also how custody, outsourcing and digital asset infrastructure are structured. As more banks expand into digital assets, MiCAR provides a clearer regulatory foundation while increasing expectations around risk management, compliance and client asset protection.
· What does MiCAR mean for Funds?
For funds and asset managers, MiCAR creates a more predictable environment for investing in and offering crypto-asset products. The regulation supports greater institutional participation by introducing common rules for authorised Crypto-Asset Service Providers (CASPs), custody and investor protection across the EU. However, it also means that managers should carefully evaluate counterparties, custody arrangements and operational models to ensure they meet the standards expected by institutional investors and regulators.
· What does MiCAR mean for Family offices?
MiCAR gives family offices greater confidence when allocating capital to digital assets by establishing a regulated ecosystem for crypto-asset services within the EU. While family offices are generally not directly subject to MiCA authorisation requirements, they should ensure that custodians, exchanges and other service providers involved in managing their digital assets operate within the applicable regulatory framework. This makes counterparty selection, custody arrangements and governance increasingly important when building long-term digital asset investment strategies.
Sources

General
5 min read
Aug 5, 2026
MiCA authorisation has become the new institutional standard: what every bank, fund and firm needs to know
Since 1 July 2026, MiCA has become the definitive regulatory framework for crypto-asset services across the EEA. Institutions must now ensure that counterparties, custody arrangements and operational models comply with the new regime. Authorisation, governance and custody architecture have become key considerations for managing regulatory risk and enabling institutional participation in digital assets.

Staking
3 min read
Feb 13, 2026
Operational Continuity for Institutional Staking
Institutional staking has matured rapidly over the last years, becoming a foundational component of digital asset strategies...

Institutional Hub
3 min read
Jan 16, 2026
New Cosmos assets are now available on Institutional Hub
Bringing institutional‑grade security and interoperability to Cosmos staking via the Institutional Hub. Stake from your custody to a validator of choice...


