MiCA’s Transition Is Over. What Crypto Platforms in Germany Need to Show Now

The EU’s maximum MiCA transition period ended on July 1. For crypto platforms serving German users, the key test is now whether the provider is authorised under MiCA or lawfully passporting an EU licence.

By


The European Union’s maximum transition period under the Markets in Crypto-Assets Regulation ended on July 1, 2026. For crypto platforms serving users in Germany, the regulatory test is now much clearer: the provider must either hold a MiCA authorisation or lawfully passport an authorisation granted in another EU member state.

The grandfathering window has closed

Under Article 143 of MiCA, firms that were already lawfully providing crypto-asset services before December 30, 2024 could, where national transition rules allowed it, continue operating until July 1, 2026 or until their MiCA application was approved or refused, whichever came first.

That transitional route has now expired. ESMA has told national regulators that firms reaching the end of their transition period without authorisation must stop providing crypto-asset services until a licence is granted.

What this means in Germany

BaFin is responsible for authorising crypto-asset service providers in Germany. Once authorised, a firm can use MiCA’s passporting framework to provide covered services across the EU after completing the required notification process.

For users, the practical check is the legal entity itself. Authorised providers appear in BaFin’s company database and in ESMA’s MiCA register. A German-language website, a regulatory logo or a statement claiming supervision is not proof of authorisation on its own.

Recent BaFin warnings show the distinction

BaFin issued several warnings in early September involving websites offering, or suspected of offering, crypto-asset services without permission. One of them, 37mh(.)com, had claimed to be supervised by BaFin; the regulator said that claim was false.

BaFin did not say that these websites had previously operated under MiCA’s transitional regime, so the warnings should not be read as evidence of a post-grandfathering enforcement sweep. They are better understood as a reminder that unauthorised platforms still exist even after the transition period has ended.

The post-transition framework is therefore simpler than before: users should verify whether the specific legal entity behind a platform is authorised under MiCA, rather than relying on the provider’s own claims. For firms, the era of relying on legacy national permissions is effectively over.