Are You in Scope for MiCA in 2026?

A practical scope-check for the EU's MiCA regulation — who counts as an issuer or CASP, which tokens are covered, which aren't, and what non-EU firms need to know.

"We're not based in the EU, so MiCA isn't our problem" is the single most expensive assumption a token issuer can make in 2026. MiCA doesn't care where your entity is incorporated — it cares who you're selling to and what you're selling. Get either answer wrong and a non-EU company can find itself needing EU authorisation it never planned for, or discover its token was excluded from scope entirely and it spent months preparing a white paper it never needed.

Here's the actual scope test — not the version everyone runs at the pitch deck stage, the one that holds up.

MiCA doesn't ask where you're incorporated — it asks three questions

The Markets in Cryptoasset Regulation entered into force in June 2023 as the EU's first bloc-wide legal framework for cryptoassets, replacing a patchwork where individual member states regulated tokens inconsistently (or not at all). It catches three categories of market participant, and you only need to fall into one of them:

You're issuing a token. MiCA defines an issuer as the legal person who "offers to the public any type of cryptoassets" or "seeks the admission of such cryptoassets to a trading platform." Note the wording: the issuer may be whoever created the token, but doesn't have to be — offering it to the public is what triggers the definition, not minting it.

You're providing a cryptoasset service. This is the Cryptoasset Service Provider (CASP) category, and it's broader than most founders assume. Custody, portfolio management, exchanging crypto for fiat or for other crypto, operating a trading platform, executing or transmitting client orders, even giving advice on cryptoassets — any of these, done "on a professional basis," puts you in CASP territory. You also need to be authorised under Article 63 MiCA, or already regulated as a credit institution, investment firm, or similar, to formally qualify.

You're trading on a MiCA-regulated platform. The narrowest category: anyone admitted to trade, or who has requested admission to trade, on a platform operated by an authorised CASP.

If none of the three apply to what you're actually doing, MiCA doesn't apply to you — full stop. Most founders don't get this far before assuming the worst. But if one does apply, which one matters, because the compliance obligations attached to each are different.

The token itself decides how strict the rules get

MiCA doesn't treat all cryptoassets the same. It splits them into three buckets, and the strictness scales with the risk:

E-Money Tokens (EMTs) — a stablecoin pegged to a single fiat currency, like USDT tracking the US dollar. These can only be issued by an authorised credit institution or e-money institution. There's no separate MiCA authorisation route for EMTs — you need the underlying licence first.

Asset-Referenced Tokens (ARTs) — a stablecoin referencing something other than a single fiat currency (a basket of currencies, a commodity, another asset, or some combination). ARTs need their own MiCA authorisation, and — with narrow exceptions for small-scale or qualified-investor-only ARTs — only an EU legal entity can get it.

Everything else — mostly utility tokens, defined as cryptoassets that provide "digital access to a good or service supplied by the issuer." These carry the lightest obligations, on the theory that a token redeemable for an existing product is lower-risk than one redeemable for a future promise. MiCA actually treats those two sub-cases differently: access to something that already exists is low-risk, access to something that doesn't exist yet reads as investment risk, and gets treated accordingly.

The stricter a token's classification, the more it looks like MiCA is watching for systemic risk rather than individual investor protection — which tracks, since EMTs and ARTs are the tokens most likely to see genuine mass adoption.

What falls outside MiCA entirely

This is where a lot of founders either panic unnecessarily or relax when they shouldn't.

NFTs are excluded — Article 2(3) carves out non-fungible tokens specifically. But read the fine print: fractionalised or interchangeable NFTs can still get pulled into scope, because MiCA looks at what the token actually does, not what the white paper calls it. A "limited edition NFT collection" that's functionally fungible doesn't get to keep the NFT exemption just because of the name.

Security tokens are excluded too — but for a completely different reason. If your token represents equity, debt, or a fund interest, you're dealing with MiFID II and the Prospectus Regulation, not MiCA — the two regimes are mutually exclusive, and a token is never regulated under both. (We cover that side of the line — STOs, US Reg D/Reg CF/Reg A+ exemptions, the new single EU prospectus threshold — in a separate guide if that's closer to what you're building.)

Also excluded: deposits, funds (unless they qualify as an EMT), insurance and reinsurance products, pension products, and securitisation positions. And under Article 2(2), if a token simply can't be transferred to other holders — by design, not by choice — it falls outside MiCA's reach regardless of category.

Non-EU firms: the exposure is real, and reverse solicitation won't save you

The part that catches non-EU teams off guard: MiCA reaches you the moment you offer cryptoasset services to EU customers or stand up an EU branch or entity to do it — regardless of where you're incorporated. There's no "we're a Cayman company, this doesn't apply to us" exit.

The one real exemption is reverse solicitation — where an EU client, entirely on their own initiative, requests a service from a non-EU firm. ESMA has made this exemption deliberately narrow: any promotion, advertisement, or sponsorship aimed at EU clients — including through social media, apps, or affiliates like influencers — counts as solicitation and kills the exemption. Even if a genuine reverse-solicitation client places an order, you can only market that same token type back to them within the confines of that original transaction, not open the relationship up more broadly. Treat reverse solicitation as the narrow exception it is, not a compliance strategy.

The upside for firms that do get authorised: MiCA authorisation passports across all 27 member states. Get it once, operate everywhere. Skip it, and you're not just non-compliant in one country — you're locked out of the entire bloc.

The five-minute scope check

Before you spend weeks on a white paper or months on legal opinions, run through this:

  1. Are you offering a token to the public, or seeking its admission to a trading platform? → You may be an issuer.
  2. Are you providing custody, exchange, portfolio management, advice, or order execution for cryptoassets, on a professional basis? → You may be a CASP.
  3. Is your token a stablecoin referencing a single fiat currency? → Likely an EMT — you need a credit/e-money licence, not a MiCA cryptoasset authorisation.
  4. Is your token a stablecoin referencing something else, or a combination? → Likely an ART — EU entity required, MiCA authorisation required.
  5. Is your token a security, a genuine NFT, or otherwise excluded under Article 2? → You're probably outside MiCA, but confirm the token's actual function, not its marketing description.
  6. Are any of your customers or prospective customers in the EU, regardless of where you're incorporated? → MiCA's reach follows the customer, not your cap table.

Two "yes" answers in the wrong combination — say, a utility token that quietly behaves like an ART, or a "reverse solicitation" relationship that started with a targeted ad — is how founders end up in scope by accident.

Once you know your answer, jurisdiction is the actual lever

A scope check isn't just an academic exercise — it points you toward one of two real strategies, and both are jurisdiction decisions before they're compliance decisions.

Strategy 1: stay outside MiCA's reach. If you're not targeting EU customers and don't need EU market access, the simplest move is keeping the token-issuing and treasury entity in a jurisdiction built for that job — no EU branch, no EU-directed marketing, and real discipline around the reverse-solicitation line above. BVI and Cayman remain the standard choices here: common-law predictability, tax neutrality, and no EU nexus to accidentally trip.

Order a BVI Limited Company · Order a Cayman Islands ELC · Order a Panama IBC

Strategy 2: get authorised properly. If EU customers are the point — not an accident — the entity has to be EU-domiciled for an ART, and authorisation is worth having for a CASP even where it isn't strictly mandatory yet, because it's what unlocks passporting across all 27 member states. Which member state you pick doesn't change MiCA's substantive rules (they're harmonised across the bloc), but it changes who reviews your application and how long that takes. Lithuania currently runs the fastest CASP authorisations in the EU — the Bank of Lithuania has processed more CASP and e-money licences than any other national regulator, often in 4–6 months for a well-prepared application — though it's not a jurisdiction we currently offer. Among the EU entities we do set up:

  • Cyprus — the option we position specifically for MiCA-driven EU market access: competitive tax treatment, English-language process, and a reputation as one of the more cost-effective CASP jurisdictions.
  • Malta — the longest continuous crypto-supervisory track record in the EU; several major exchanges hold their MiCA authorisation there, which counts for something with banking partners and institutional counterparties.
  • Ireland — common-law, English-speaking, and increasingly the choice for teams whose counterparties care about institutional-grade regulatory reputation.

Order a Cyprus Limited Company · Order a Malta Limited Company · Order an Ireland Limited Company

Neither strategy is free of trade-offs, and picking wrong is expensive in both directions — an EU entity you didn't need is ongoing overhead with no upside, and an offshore structure that turns out to need EU authorisation anyway means starting the clock late.

How Otonomos helps

Whether the right move is structuring to stay outside MiCA's reach, or building the EU entity and authorisation pathway properly from day one, that's a jurisdiction and entity-structuring question before it's a compliance-paperwork question — which is exactly where we come in. We structure the entity stack — EU or otherwise — around what your token actually does and who you're actually selling to, not what the pitch deck says. Browse the full jurisdiction catalog or talk to us about which structure fits.

Talk to Otonomos about your MiCA scope before you draft anything: Book a free call


Sources: Rachael Muldoon, Partner, Charles Russell Speechlys, "MiCA Fundamentals: A Guide", The Otonomist, Mar 2025; Otonomos Helpdesk, "Security Token Regulations Demystified (2026 Update)"; jurisdiction/timeline comparisons cross-checked against independent 2026 MiCA CASP-licensing guides (Bank of Lithuania processing times, MFSA/Malta and Cyprus market positioning) current as of Aug 2026. Otonomos jurisdiction pricing and positioning verified live against the otonomos.com order pages, Aug 2026.


Did this page help you?