Skip to content
Skip article header Engineering

ESMA CASP Register: What the Data Shows After the MiCA Deadline

A data study of the ESMA CASP register built from our own raw-CSV parse: 295 active authorization records as of 20 July 2026, 70% custody-authorized, the parsing error that undercounted custody by 17 records, the June 2026 authorization spike and what happened to firms that missed the deadline.

12 min read 43 views
Skip key takeaways

Key takeaways: the ESMA CASP register after the MiCA deadline 5

The headline counts from our own raw-CSV parse of the ESMA CASP register, dated 20 July 2026, the custody correction we caught, the June 2026 authorization wave and where conversion from pre-MiCA registrations stands.

See our MiCA compliance software development services

The ESMA CASP Register is the only primary source for how many crypto firms actually hold a MiCA authorization, and most of the numbers circulating about it right now are secondary trackers quoting each other. We downloaded the register ourselves, parsed the raw file with our own methodology and caught our own parsing error along the way, so this is a data study built from the file, not from someone else's summary of it.

In short: 295 authorized CASP records sit active in the ESMA register as of 20 July 2026, about 292 unique firms once duplicate and shared-LEI rows are cleaned up. 70% of them (207 records) hold custody authorization, the exact subsegment ESMA's new Common Supervisory Action is built to test. A quarter of the entire active register, 72 records, was authorized in June 2026 alone, weeks before supervision even started. Along the way our first parser undercounted custody by 17 records because Cyprus and Estonia file services as free text instead of letter codes, a correction we walk through below.

What we did: the methodology

ESMA publishes the Interim MiCA Register as a public CSV, updated weekly, published as CASPS.csv at https://www.esma.europa.eu/sites/default/files/2024-12/CASPS.csv. It lists every authorized Crypto-Asset Service Provider by competent authority, home member state, LEI, legal and commercial name, address, website, authorization notification date, authorization end date where applicable, MiCA service codes and passporting countries. We downloaded the file on 20 July 2026 and computed every number in this article directly from that raw CSV, not from a secondary tracker or a vendor dashboard.

Two methodology notes worth stating up front, because they change how a reader should compare our numbers to anyone else's. First, the register moves weekly, so every count below is a snapshot dated 20 July 2026, not a permanent figure. Second, a register row is an authorization record, not necessarily a distinct firm, a handful of firms hold two records (a shared LEI in one case is actually a register data error covering two different firms, and one active record has no LEI at all), so we state record counts as records and give the deduplicated firm count alongside them.

The headline numbers

The register held 297 total records on 20 July 2026. Two carry an authorization end date and count as terminated, leaving 295 active authorization records. Deduplicating by LEI where the identifier is reliable brings that down to roughly 292 unique active firms, since a few entities show up under two records and one pair of records (FLOWDESK EUROPE SAS and APLO SAS, both French, both authorized in June 2026) shares a single LEI because of a register data error rather than a genuine merger, while one Bulgarian custody record (Belayer OOD) carries no LEI at all. Every one of the 295 active records has a website filled in, which is a small but useful signal that the register is being kept current at the field level, not just the headline count.

That 295 figure also sits inside a longer growth curve that public trackers have reported at different dates: roughly 243 active records as of the 26 June register update, 280 as of 3 July (repeated again around 15 July per casptracker.eu), and 295 active on our 20 July snapshot. These are not conflicting numbers, they are the same register measured on different days as authorizations kept landing after the 1 July 2026 deadline.

CASPs by country

Germany holds the largest population of authorized CASPs by a wide margin, followed by France and the Netherlands. The full country breakdown of active records as of 20 July 2026:

Country Active CASP records
Germany 61
France 31
Netherlands 27
Malta 22
Cyprus 21
Spain 13
Luxembourg 13
Ireland 12
Austria 11
Czechia 11
Liechtenstein 11
Italy 9
Latvia 8
Croatia 6
Lithuania 6
Norway 6
Slovakia 6
Finland 5
Denmark 4
Estonia 3
Slovenia 3
Bulgaria 2
Belgium 1
Iceland 1
Portugal 1
Sweden 1

Germany's lead is a broker and exchange story more than a custody story. Of its 61 records, only 15 hold custody authorization, the smallest custody share of any of the larger jurisdictions. France, by contrast, leads the custody subsegment outright with 24 custody records against its 31 total, a pattern worth keeping in mind when the custody table below reshuffles the ranking.

Custody: the subsegment ESMA is now testing

207 of the 295 active records (70.2%) carry custody authorization, MiCA service "a", providing custody and administration of crypto-assets on behalf of clients, which works out to about 206 unique custody firms after dedupe. That is the population directly in scope for ESMA's custody-focused Common Supervisory Action, and it is worth pairing with our custody CSA preparation guide if your platform sits inside it. Custody authorization by country, corrected numbers:

Country Custody CASP records
France 24
Malta 21
Cyprus 20
Netherlands 20
Germany 15
Spain 11
Luxembourg 10
Austria 9
Czechia 9
Liechtenstein 9
Latvia 8
Italy 7
Lithuania 6
Slovakia 6

Custody authorizations arrived in the same two waves visible in the overall register: 57 custody records date from June 2026 and 25 from December 2025, the two clusters we look at in more detail below. Firms building or buying custody infrastructure for this segment sit squarely in the MiCA compliance software development conversation, since custody policy, segregation and reporting all have to be engineered, not just documented.

How we caught our own parsing error

Our first pass at the custody number came back at 190 records, 64% of the active register, counted by matching the service-code prefix "a." in the register's service field. That number was wrong, and we are showing the correction rather than quietly fixing it, because the reason it was wrong says something useful about the register itself.

CySEC in Cyprus and the Estonian authority record services as plain free text, without the letter prefix the rest of the register uses. A prefix match against "a." simply never matches those rows, so it silently drops every Cypriot and Estonian custody record that uses the free-text format. Re-parsing by matching the actual service description text, "custody and administration", case-insensitively, recovered 17 missed custody records under the strict prefix definition, all of them from Cyprus and Estonia. That correction alone moved the custody count from 190 to 207, the figure used everywhere else here, and it recovered some sizable names: Revolut Digital Assets (Europe), eToro (Europe), XTB, Trading 212 Markets, Lightyear Europe, AS LHV Pank, Lightspark Payments Europe and NAGA X all showed up only after the text-match fix.

The lesson generalizes past custody. The register mixes at least three formatting conventions across national competent authorities, "a. service | b. service" with letter prefixes and pipe separators, plain service text with pipe separators and no letters, and slash-separated service text. A handful of Malta and Ireland rows also deviate from the clean "a. " convention without having actually been missed, which is why we phrase the correction narrowly: 17 records were missed under a strict prefix match, and they happen to be exclusively Cypriot and Estonian, but formatting inconsistency in the register is broader than just those two jurisdictions. Anyone parsing the register programmatically should match on service description text, not on letter prefixes.

The June 2026 authorization spike

The monthly authorization series, built from the active records' notification dates and running December 2024 through July 2026, shows two clear waves rather than a smooth ramp. One methodology note before the table: this series counts active records only, terminated authorizations are excluded and two records have unparseable notification dates, a Latvian custody record with a malformed date and a Belgian record with the field left empty, so the series is built on the 293 active records with a clean date.

Month Authorization records
2024-12 4
2025-01 7
2025-02 2
2025-03 3
2025-04 7
2025-05 11
2025-06 9
2025-07 8
2025-08 6
2025-09 12
2025-10 15
2025-11 22
2025-12 44
2026-01 8
2026-02 14
2026-03 14
2026-04 12
2026-05 17
2026-06 72
2026-07 6

June 2026 alone accounts for 72 authorization records, 24% of the 295 active records, about 70 unique LEIs once the June rows are deduplicated. December 2025 (44 records) was the first wave, the last month before several national transitional windows closed early; June 2026 was the second and much larger wave, the final month before the EU-wide 1 July 2026 deadline. Inside that June wave, 57 of the 72 records (55 unique LEIs) carry custody authorization, which means most of the custody population's newest members are also its least tested, authorized weeks before ESMA's supervisory activity even began. A firm assembling a compliance stack under that kind of deadline pressure is exactly the population risk-based sampling is designed to find first. Compliance systems that were finished the week the deadline hit are also the ones least likely to have survived a real incident yet, a point our DORA guidance for crypto firms covers from the operational-resilience side.

An independent tracker corroborates the shape of the wave from a different snapshot: KuCoin's own analysis of the register, based on a 283-record snapshot, found 36 authorizations between 23 June and 1 July 2026, 13 of them on 30 June alone and one on 1 July itself. Different snapshot date, different total, same last-minute wave.

From AMLD5 registrations to MiCA authorizations

Before MiCA, most EU crypto firms operated under national AMLD5 registration regimes rather than a license, and industry estimates put that pre-MiCA population at more than 1,200 registered VASPs EU-wide. Against that baseline, industry trackers estimated roughly 210 CASP authorizations around the 1 July 2026 cliff, a conversion rate under 18% (Zitadelle AG, Bleap, Debia, attributed estimates rather than our own count). Layering the register's own dated snapshots on top of that baseline gives a fuller picture: 243 active records on 26 June, 280 on 3 July, 295 active on our 20 July snapshot, a post-cliff catch-up rather than a single conversion event.

Estonia is the sharpest national example of the drop-off. The country's FIU reported 641 licensed virtual asset service providers back in 2021, a population it had already been actively winding down for years; that fell to 36 valid licences at the start of 2026, and the register shows just 3 CASP register entries for Estonia as of 20 July 2026, none of which are former VASPs from that original 641. Estonia's old license records were formally canceled on 1 July 2026.

Lithuania shows the same pattern at a smaller scale. Industry estimates (ASD Labs) put pre-MiCA AMLD5-registered VASPs in Lithuania at several hundred, against 4 MiCA licences by March 2026 and 6 CASP register entries by 20 July 2026; Lithuania's own transitional period closed earlier than the EU-wide deadline, on 1 January 2026.

The broader pattern across both national examples and the EU-wide series is the same: a large pre-MiCA registered population, a much smaller initial conversion, and an authorization count that kept climbing for weeks after the formal deadline as firms cleared the backlog.

Enforcement is already running

Authorization is only half the register story. ESMA maintains a second, parallel list of non-compliant entities, the NCASP register, which held 164 flagged records as of 20 July 2026. Italy's Consob accounts for 162 of them (161 records plus one duplicate under a spelling variant of the authority's name), with the Netherlands' AFM and Slovakia's NBS each flagging one. Most of the flagged entities are offshore websites unlawfully serving EU clients, and the volume shows enforcement against unauthorized operators running in parallel with authorization, not waiting for it to finish.

For firms that missed the 1 July 2026 deadline outright, ESMA has published two statements setting out what has to happen next (our MiCA compliance checklist covers the authorization-side obligations these statements sit alongside). The first, dated 17 April 2026, requires any unauthorized CASP to have implemented an "operational, credible, and immediately executable" wind-down plan by 1 July 2026, covering an orderly transfer of client crypto-assets to an authorized CASP or a self-hosted wallet. The second, dated 23 June 2026, sets three specific obligations for unauthorized providers still active after the deadline: stop onboarding new EU clients and cease marketing immediately, limit any remaining activity to exit actions only (custody of client crypto-assets can only continue for the period strictly necessary to complete an orderly exit) and communicate clearly, promptly and repeatedly with clients about the wind-down timeline. AML and CFT obligations continue throughout, and any CASP receiving migrating clients has to run full customer due diligence on them, not treat the transfer as pre-cleared.

National penalties for continuing to operate without authorization vary sharply by member state. France applies a two-year prison sentence and a EUR 30,000 fine under Articles L. 54-10-4 and L. 572-23 of its Monetary and Financial Code, alongside the AMF's power to blacklist unauthorized providers and block website access. Poland sits at the other extreme: draft provisions of an implementing act envisage penalties up to PLN 20 million or 8 years imprisonment, but that act is not in force. The Sejm passed a re-submitted bill 241-200 on 15 May 2026, short of the supermajority needed to override a veto, and President Nawrocki vetoed it for a third time on 11 June 2026. As of the 1 July deadline, Poland was the only EU member state without a functioning domestic MiCA licensing regime, leaving roughly 2,000 local firms in limbo pending new legislation. Underneath all of that sits an EU-wide floor set by MiCA Article 111, national regimes have to allow administrative fines of at least EUR 5,000,000 or 5% of total annual turnover for legal entities and EUR 700,000 for natural persons for CASP infringements specifically, plus the power to prohibit activity and remove a firm from the register, and national law is free to set higher amounts than that floor.

A MiCA authorization doesn't buy blanket immunity either. KuCoin EU Exchange GmbH received its FMA authorization in Austria in November 2025, then in February 2026 the FMA barred it from onboarding new customers over gaps in its AML and sanctions-officer staffing, a restriction that sits alongside, not instead of, its authorization.

How Pharos Production helps

The transitional period is over, and ESMA's first coordinated supervisory review is aimed directly at the custody population this article quantifies. We build and audit the compliance systems that sit behind a MiCA authorization, custody segregation, transaction monitoring, incident reporting and the record-keeping that has to survive a supervisory review, not just an application. If your platform is part of the 70% of the register that holds custody authorization, or you are still building toward an authorization of your own, our MiCA compliance software development team can walk through what the data above means for your specific jurisdiction and service mix. The other 30%, CASPs authorized for services other than custody, sit outside this specific supervisory action's focus, though the same register data shows they share the same June 2026 authorization wave profile documented above.

Sources: ESMA Interim MiCA Register (CASPS.csv) and NCASP register (NCASP.csv), downloaded and parsed directly 20 July 2026; ESMA public statements ESMA75-113276571-1679 (17 April 2026) and ESMA75-113276571-1710 (23 June 2026); AMF France provider reminders; public reporting on Poland's vetoed implementing act (CoinDesk, 1 July 2026); Estonia's Financial Intelligence Unit (fiu.ee); KuCoin's register analysis; industry attrition estimates from Zitadelle AG, Bleap and ASD Labs, cited with attribution where used.

FAQ

Last updated:

Quick answers to common questions about custom software development, pricing, process and technology.

  • Copy link Copies a direct link to this answer to your clipboard.

    295 active authorization records sit in the ESMA CASP register as of 20 July 2026 (297 total records, 2 terminated), about 292 unique firms once duplicate and shared-LEI records are cleaned up. The register updates weekly, so the count moves.

  • Copy link Copies a direct link to this answer to your clipboard.

    Germany leads with 61 active records, ahead of France (31) and the Netherlands (27). France leads specifically in custody authorizations though, 24 custody records against Germany's 15, since Germany's cohort is dominated by brokers and exchanges without custody authorization.

  • Copy link Copies a direct link to this answer to your clipboard.

    207 of the 295 active records (70%) carry custody authorization as of 20 July 2026, about 206 unique custody firms after dedupe. That figure is corrected from an earlier internal parse that undercounted custody at 190 because Cyprus and Estonia record services as free text rather than letter-coded prefixes.

  • Copy link Copies a direct link to this answer to your clipboard.

    ESMA statements dated 17 April and 23 June 2026 require an unauthorized CASP to implement an orderly wind-down plan: stop onboarding new EU clients, limit activity to exit actions only (custody can continue only for the period strictly necessary to complete the exit, per ESMA's 23 June statement) and communicate clearly with clients about the timeline. The enforcement section of this article covers the national penalty examples for firms that keep operating without authorization.

  • Copy link Copies a direct link to this answer to your clipboard.

    72 authorization records, 24% of the 295 active records, landed in June 2026 alone, the final month of the transitional period before the EU-wide 1 July 2026 deadline. December 2025 (44 records) was the first wave.

    Firms authorized in that last-minute window, including 57 of the custody-authorized records, had the least time to prove their compliance systems in live operation before ESMA's supervisory activity began.

I work with startup founders who need a dedicated software development team but don’t want to gamble on hiring, random outsourcing, or opaque delivery.
Most founders face the same problem sooner or later.
Early technical and team decisions lock the product into tech debt, slow delivery, missed milestones and constant re-hiring. By the time this becomes visible, fixing it is already expensive.

As a CTO and software architect, I help founders design, build and run dedicated development teams that work as a true extension of the startup. Not as a black-box vendor.

My focus is on complex products where mistakes are costly:

  • Web3 and blockchain platforms
  • FinTech and regulated products
  • High-load startup systems
  • MVP → scale transitions

We don’t do body-shopping.
We don’t sell generic outsourcing.

Instead, we help founders:

  • build the right team structure from day one
  • keep technical ownership and transparency
  • scale delivery without losing control
  • avoid vendor lock-in and hidden risks

Teams are aligned with the product roadmap, business goals and long-term architecture. Not just short-term velocity.

Dmytro Nasyrov, Founder and CTO at Pharos Production
Dmytro Nasyrov Founder & CTO Let's work together!

Your business results matter

Achieve them with minimized risk through our bespoke innovation capabilities

Your contact details
Please enter your name
Please enter a valid email address
Please enter your message
* required

We typically reply within 4 hours. Prefer email? [email protected]

What happens next?

  1. Contact us

    Contact us today to discuss your project. We're ready to review your request promptly and guide you on the best next steps for collaboration

    Same day
  2. NDA

    We're committed to keeping your information confidential, so we'll sign a Non-Disclosure Agreement

    1 day
  3. Plan the Goals

    After we chat about your goals and needs, we'll craft a comprehensive proposal detailing the project scope, team, timeline and budget

    3-5 days
  4. Finalize the Details

    Let's connect on Google Meet to go through the proposal and confirm all the details together!

    1-2 days
  5. Sign the Contract

    As soon as the contract is signed, our dedicated team will jump into action on your project!

    Same day