
{"id":201844,"date":"2026-07-21T14:19:58","date_gmt":"2026-07-21T14:19:58","guid":{"rendered":"https:\/\/mycryptomania.com\/?p=201844"},"modified":"2026-07-21T14:19:58","modified_gmt":"2026-07-21T14:19:58","slug":"fewer-than-300-made-the-cut-ivan-nevzorov-on-mica-casp-licensing-and-whats-next-for-crypto-firms","status":"publish","type":"post","link":"https:\/\/mycryptomania.com\/?p=201844","title":{"rendered":"Fewer Than 300 Made the Cut: Ivan Nevzorov on MiCA, CASP Licensing, and What\u2019s Next for Crypto Firms"},"content":{"rendered":"<p>Of the more than 3,000 companies that were legally serving crypto clients across the EU as recently as this June, fewer than 300 hold the right to do so today, according to CASP Tracker.<\/p>\n<p>The reason is the Markets in Crypto-Assets Regulation (MiCA), which took full effect across the European Union on 1 July 2026: from that date, only a company holding <a href=\"https:\/\/sb-sb.com\/services\/crypto\/casp-license\/?utm_source=CryptoPotato&amp;utm_medium=ivan-pr\">Crypto-Asset Service Provider (CASP) authorisation<\/a> \u2014 granted by a regulator in one EU member state and passported across the rest of the bloc \u2014 can serve EU clients. Companies that previously operated under national Virtual Asset Service Provider (VASP) registrations had exactly until that date to convert. Most didn\u2019t.<\/p>\n<p>We talked to Ivan Nevzorov, CEO at <a href=\"https:\/\/sb-sb.com\/\">SBSB Fintech Lawyers<\/a>, about what\u2019s actually left for them now \u2014 and why the shortcuts most of them reach for first usually aren\u2019t the ones that hold up.<\/p>\n<p><a href=\"https:\/\/cryptopotato.com\/wp-content\/uploads\/2026\/07\/sbsb_lawyers_sponsored.jpg\"><\/a><\/p>\n<p><strong><em>Let\u2019s start with the obvious one. A company still doesn\u2019t have a CASP licence today \u2014 what happens to it now?<\/em><\/strong><\/p>\n<p><strong>Ivan Nevzorov:<\/strong> Look, here\u2019s the thing people don\u2019t want to hear: the deadline\u2019s already passed. From July 1st, every day you keep serving EU clients without authorisation is a day you\u2019re in breach of MiCA \u2014 a minimum \u20ac5 million fine under Article 111, and in France it can mean criminal liability for whoever\u2019s responsible. So the answer everyone expects to hear, \u201cjust go get licensed,\u201d isn\u2019t actually on the table anymore for a company operating today. You can\u2019t file an application, keep the lights on for months while it gets reviewed, and call that compliance.<\/p>\n<p>Which really leaves two paths. One, you wind down, because the business can\u2019t meet the new standard. Two, you relocate \u2014 move your base to a friendlier jurisdiction. Though that one only keeps you legal if you stop marketing into the EU completely and let clients come to you on their own, what\u2019s called reverse solicitation. Keep advertising to EU users from outside the bloc, and you\u2019re breaking the exact same rule, just from a different address.<\/p>\n<p>We\u2019ll come back to relocating, because it\u2019s genuinely its own conversation. Let\u2019s start with winding down, since that\u2019s where most of these companies actually are right now \u2014 and honestly, it\u2019s painful to watch, because most of them didn\u2019t do anything wrong. They just didn\u2019t get there in time, and for a lot of them, the reasons had nothing to do with how good their compliance actually was.<\/p>\n<p><strong><em>Winding down sounds like the more straightforward path, at least. Is it actually?<\/em><\/strong><\/p>\n<p><strong>Ivan Nevzorov:<\/strong> Not as straightforward as people think, and there\u2019s a right way and a wrong way to do it. The wrong way is switching off the app and disappearing \u2014 the client assets sitting in those accounts don\u2019t vanish, and holding them is a regulated activity in itself. To the regulator, that company hasn\u2019t gone anywhere. It\u2019s still operating without a licence, only now it\u2019s also stopped answering its clients. The right way is one of two things: an orderly wind-down, or transferring your clients to a CASP that\u2019s already authorised.<\/p>\n<p>ESMA\u2019s actually spelled out what an orderly wind-down has to look like: stop onboarding, stop any marketing into the EU, restrict yourself to settling what\u2019s already open. And transferring clients sounds simpler on paper, but being on the CASP register only tells you a firm\u2019s allowed to take clients \u2014 it doesn\u2019t tell you they\u2019re actually set up to onboard a few thousand new ones at once. A lot of the firms that got authorised fastest didn\u2019t build a crypto compliance function from zero \u2014 they already held a MiFID or e-money licence and just converted it, lighter scrutiny attached. Good for them, but it also means some of these brand-new CASPs are banks running crypto as a side product, not specialists who can absorb a wave of migrating clients. Every single one of those clients still needs full AML and KYC re-verification before the new CASP can touch their money. That\u2019s months of work for a team that does it every day. Longer for a team that doesn\u2019t.<\/p>\n<p><strong><em>You\u2019d think the bigger platforms would have this solved by now. Is that actually the case?<\/em><\/strong><\/p>\n<p><strong>Ivan Nevzorov:<\/strong> Less than people think, and Binance is actually a fair example of why. A platform with years of European operating history and enormous legal and compliance resources still ran into real MiCA licensing problems \u2014 the same wall a lot of much smaller companies are hitting. That tells you something worth sitting with: this isn\u2019t a gap you close just by throwing money or headcount at it. If a company at that scale couldn\u2019t get it fully sorted before the deadline, a smaller operator shouldn\u2019t assume they\u2019ll just muscle through it either.<\/p>\n<p><strong><em>Let\u2019s rewind for a second \u2014 only a couple hundred companies actually made it through while that was still possible. What was going wrong for the rest?<\/em><\/strong><\/p>\n<p><strong>Ivan Nevzorov:<\/strong> Honestly, it\u2019s rarely the paperwork. A technically correct application just gets you in the room \u2014 it doesn\u2019t win you the decision. We saw one filing get rejected over how the share capital was deposited, and that requirement isn\u2019t even written into MiCA, anywhere. The regulator just invented a formality that isn\u2019t in the text. That\u2019s the pattern I keep seeing: whatever reason they put on paper is almost never the real one. The real reason comes to you informally, if it comes at all, and it\u2019s about how they read the company \u2014 do you actually understand your own risk model, who\u2019s accountable for what, who your clients really are. A compliance policy copied from a template answers none of that. It\u2019s the first thing I flag when someone walks into SBSB with one.<\/p>\n<p>And the second thing people underestimate completely: where you filed mattered almost as much as what you filed. This wasn\u2019t one process across the EU \u2014 it was twenty-seven versions of it, moving at completely different speeds, with completely different appetites for saying no. Germany\u2019s BaFin wasn\u2019t shy about it: its first-ever MiCA enforcement action was rejecting Ethena\u2019s application and then forcing the company to wind down its German operation and redeem its tokens. Italy\u2019s regulator went the other way \u2014 it spent most of the transition period without having authorised anyone at all, so filings there just sat. Same regulation, wildly different odds depending on the door you knocked on. A few countries never even built the door \u2014 Poland\u2019s the loudest example, it went into the deadline with no authority issuing CASP licences at all \u2014 but that\u2019s the extreme end of a spectrum the whole market was sitting on.<\/p>\n<p><strong><em>Let\u2019s talk about the companies actually going through the licensing process, then \u2014 a first application in a market they haven\u2019t touched yet, or a return down the line after an orderly exit. What does a strategy that actually works look like, in practice?<\/em><\/strong><\/p>\n<p><strong>Ivan Nevzorov:<\/strong> Honestly, it starts before you\u2019ve touched a single form. You go talk to the regulator first, find out exactly what they expect from a business like this one, and only then do you build the structure around that answer \u2014 the AML policy, the governance, the documentation. MiCA\u2019s a directive, which means every country implements it a little differently, so a compliance package that worked in one member state gets rechecked before you dare reuse it somewhere else. People skip that step constantly, and it costs them.<\/p>\n<p>At SBSB, a full mandate for us looks like this: company formation, the application itself, handling the regulator correspondence, and then the parts most founders genuinely can\u2019t build alone \u2014 banking relationships, payment infrastructure, penetration testing through our partners, licensed compliance software. And staffing matters just as much. Regulators check AML certifications early, so get that sorted before the application goes in, not after you\u2019ve already filed.<\/p>\n<p><strong><em>How should a company actually choose which EU market to apply in \u2014 Germany, Austria, the Netherlands, Estonia?<\/em><\/strong><\/p>\n<p><strong>Ivan Nevzorov:<\/strong> I don\u2019t give every client the same answer, honestly, and if anyone tells you there\u2019s one magic jurisdiction, they\u2019re oversimplifying it for you. But the differences between regulators are real, and by now they\u2019re well documented. Germany\u2019s BaFin gives you the heaviest signature in Europe \u2014 corporate clients respect it \u2014 but you pay for it: a German entity, at least two qualified directors actually present in the country, capital paid up at filing, and a documentation pack that runs to hundreds of pages, with the formal filing in German. France is the opposite story: the AMF had been licensing crypto firms under its own national regime for five years before MiCA existed, so firms already registered there got a genuinely streamlined path, and the regulator\u2019s crypto unit knows what it\u2019s looking at. Luxembourg, Ireland, and Malta became the hubs the big exchanges actually picked: Coinbase went through Luxembourg, Kraken through Ireland, OKX and Crypto.com through Malta. That\u2019s not a coincidence; it\u2019s where the process was mature enough to handle a file that size.<\/p>\n<p>But here\u2019s what I actually tell clients: the regulator\u2019s speed shouldn\u2019t decide it \u2014 your own capacity should. Every serious regulator now checks for the same thing: a real office, real staff on the ground, a credible plan for that specific market. Pick the jurisdiction where you can honestly show that, not whoever\u2019s got the shortest queue \u2014 a fast process with no substance behind your application just gets you a fast rejection. And yes, Germany leads on raw licence numbers right now, but a good chunk of that is banks and brokers converting a licence they already had, not crypto-native firms getting freshly approved. \u201cGermany has the most CASPs\u201d and \u201cGermany\u2019s the easiest place for a crypto company\u201d are two different claims, and people mix them up constantly. I don\u2019t think any single country\u2019s lead holds for long anyway \u2014 regulator capacity is finite everywhere. We\u2019ve watched this movie before, it\u2019s basically what happened with Cura\u00e7ao\u2019s gaming licence reform. Once the volume outpaces what the regulator can actually process, the process itself becomes the bottleneck.<\/p>\n<p><strong><em>Let\u2019s come back to relocating, the third path you mentioned earlier. For companies thinking globally, how should they weigh an EU licence against licences elsewhere \u2014 Latin America, Asia, offshore?<\/em><\/strong><\/p>\n<p><strong>Ivan Nevzorov:<\/strong> Look, the safest position is full compliance everywhere you operate \u2014 better banking terms, full market access, nothing sitting in a grey area. But that takes a budget most startups just don\u2019t have. So in practice, most of them end up running from a business-friendly base \u2014 El Salvador, Panama, the UAE, Singapore, Mexico, these come up constantly \u2014 and serving EU clients only through reverse solicitation, sometimes with geo-blocks stacked on top for the riskier markets.<\/p>\n<p>But notice what those two options really are: one\u2019s too expensive for most, and the other cuts you off from actively winning EU clients at all. Which is why the question I hear constantly right now is: can\u2019t I just operate under someone else\u2019s licence? And here\u2019s where MiCA catches people off guard. In payments, under the Second Payment Services Directive, PSD2, there\u2019s a proper agent model \u2014 an unlicensed company can work the market on behalf of a licensed one, and the industry uses it everywhere. MiCA has nothing like that. Articles 59 and 60 draw a hard line around who\u2019s allowed to provide crypto services at all, so the classic white-label \u2014 an unlicensed provider serving clients in its own name under someone else\u2019s licence \u2014 formally doesn\u2019t work.<\/p>\n<p>What nobody forbids, though, is supplying a licensed CASP with technology or marketing. That\u2019s fully legal, and the entire market has rushed into the gap between those two points \u2014 KvarnX, Bitpanda, Bit2Me are all running their own versions of it, and Spain\u2019s regulator has even given the grey-label approach a cautiously positive read, with real limits attached. The catch is what role you\u2019re actually playing: the licensed partner holds every wallet, every bank account, every client transaction. You\u2019re the technology behind their offer, not the provider in front of the client. For a lot of companies that\u2019s a perfectly good way back into the EU market. Just be honest with yourself about which side of that line your business model actually needs to be on.<\/p>\n<p><strong><em>Last one \u2014 once a company has the CASP licence, what does the ongoing workload actually look like?<\/em><\/strong><\/p>\n<p><strong>Ivan Nevzorov:<\/strong> Getting the licence is honestly the easy part to talk about. Staying licensed is where companies actually get tested. I\u2019ve watched a licence get pulled by an EU regulator within months of being granted, because the business just didn\u2019t follow through on what it promised in the application. What actually matters, once you\u2019re authorised, is exactly what you signed up for on paper \u2014 active risk assessment, ongoing AML monitoring, reporting to the regulator on time, every single time.<\/p>\n<p><strong><em>Has that gap between paperwork and practice actually cost one of your clients?<\/em><\/strong><\/p>\n<p><strong>Ivan Nevzorov:<\/strong> This one\u2019s a bit different \u2014 no regulator pulled anything here, and it\u2019s actually from outside crypto. But it\u2019s the same underlying lesson, so it\u2019s worth telling. We had a client at SBSB who did everything right on paper: MSB registration, their API \u2014 Authorised Payment Institution \u2014 licence, connected to a banking-as-a-service partner, targeting the European market. Business plan solid, AML policy solid, source-of-funds checks all cleared. Where it fell apart was the economics nobody had stress-tested. The marketing spend needed to actually hit their projected client volume ran well above what they\u2019d budgeted. The partner bank\u2019s own compliance screening filtered out a chunk of the high-risk client segment their whole model was built around. And the tariffs the bank actually offered were thinner than what they\u2019d planned for. Nothing illegal happened anywhere in that chain. The business just didn\u2019t survive contact with the market it was built for. They made the call to sell, and we\u2019ve already found a buyer \u2014 sold it, more or less, at this point.<\/p>\n<p>One thing that\u2019s genuinely changed the economics here is AI in compliance monitoring. Transaction monitoring that used to eat up a whole team can run with a fraction of the people now \u2014 cheaper for the company, and from what regulators have signalled, easier for them to work with too. None of that replaces the basic requirement, though. The licence is the easy part. Staying licensed \u2014 that\u2019s the job.<\/p>\n<p><strong><em>If you had to give one piece of advice to a company still sitting on this decision \u2014 wind down or relocate, transfer or hold \u2014 what would it be?<\/em><\/strong><\/p>\n<p><strong>Ivan Nevzorov:<\/strong> Pick your strategy and start moving \u2014 this week, not this quarter. The window between now and the first wave of regulatory checks is the only asset these companies have left, and it\u2019s shrinking: we flagged back in May that the first checks would land around the third quarter of this year, and the Netherlands has already shown how this plays out \u2014 their central bank fined Kraken \u20ac4 million and Crypto.com \u20ac2.85 million under the old registration regime, and OKX \u20ac2.25 million just last year, for something that happened two years earlier.<\/p>\n<p>A company that uses these months to actually execute \u2014 transfer the clients, close out the obligations, or get the relocation structure in place \u2014 walks into that first check with a story of action behind it. A company that\u2019s still weighing its options in September walks in with an explanation for why it did nothing. Given the choice, I know which conversation I\u2019d rather have with a regulator.<\/p>\n<p><strong>Disclaimer<\/strong><em><strong>:<\/strong>\u00a0The above article is sponsored content; it\u2019s written by a third party. CryptoPotato doesn\u2019t endorse or assume responsibility for the content, advertising, products, quality, accuracy, or other materials on this page. Nothing in it should be construed as financial advice. Readers are strongly advised to verify the information independently and carefully before engaging with any company or project mentioned and to do their own research. Investing in cryptocurrencies carries a risk of capital loss, and readers are also advised to consult a professional before making any decisions that may or may not be based on the above-sponsored content.<\/em><\/p>\n<p><em>Readers are also advised to read CryptoPotato\u2019s\u00a0<a href=\"https:\/\/cryptopotato.com\/disclaimer\">full disclaimer<\/a>.<\/em><\/p>\n<p>The post <a href=\"https:\/\/cryptopotato.com\/fewer-than-300-made-the-cut-ivan-nevzorov-on-mica-casp-licensing-and-whats-next-for-crypto-firms\/\">Fewer Than 300 Made the Cut: Ivan Nevzorov on MiCA, CASP Licensing, and What\u2019s Next for Crypto Firms<\/a> appeared first on <a href=\"https:\/\/cryptopotato.com\/\">CryptoPotato<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>Of the more than 3,000 companies that were legally serving crypto clients across the EU as recently as this June, fewer than 300 hold the right to do so today, according to CASP Tracker. The reason is the Markets in Crypto-Assets Regulation (MiCA), which took full effect across the European Union on 1 July 2026: [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-201844","post","type-post","status-publish","format-standard","hentry","category-discovery"],"_links":{"self":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts\/201844"}],"collection":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=201844"}],"version-history":[{"count":0,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts\/201844\/revisions"}],"wp:attachment":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=201844"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=201844"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=201844"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}