MiCA Review 2026: What MiCA v2 May Change
The European Commission's MiCA review consultation, launched 20 May 2026 under Articles 140 and 142, with responses due 30 September 2026. What the questionnaire actually asks across stablecoins, CASP prudential and reporting rules, DeFi, staking, lending and perpetual futures, what it stays silent on and what each area would change in the systems we build.
Key takeaways: MiCA review 2026 and what MiCA v2 may change 6
What the European Commission's MiCA review consultation actually asks across stablecoins, CASP rules and DeFi, what it leaves untouched, the numbers gap between the consultation's register footnote and today's count and where industry and Brussels diverge on direction.
- The European Commission opened the MiCA review on 20 May 2026 The European Commission opened the MiCA review on 20 May 2026, weeks before the transitional period ended; responses are due 30 September 2026, extended from 31 August.
- The legal basis is Article 140 and Article 142 The legal basis is Article 140 (application report due 30 June 2027) and Article 142 (report on developments not addressed in MiCA, including DeFi, staking, lending and NFTs).
- The questionnaire's four parts put stablecoin multi-issuance and third-country equivalence The questionnaire's four parts put stablecoin multi-issuance and third-country equivalence, CASP prudential alignment and reporting, DeFi decentralization criteria, staking and lending and perpetual futures classification on the table.
- The consultation never mentions reverse solicitation or crypto-assets without an identifiable issuer The consultation never mentions reverse solicitation or crypto-assets without an identifiable issuer, the two hottest interpretive fights of 2026, both outside its questionnaire.
- The consultation's own footnote counted around 170 register entries when drafted The consultation's own footnote counted around 170 register entries when drafted; by 20 July 2026 the register held 295 active CASPs, with June 2026 alone adding almost a quarter of that total.
- Industry's stated ask is simplification and supervisory convergence Industry's stated ask is simplification and supervisory convergence, while press-reported plans point toward perimeter expansion to non-EU stablecoin issuers and other new areas.
The European Commission's MiCA review opened before the regulation's own ink had fully dried. MiCA applied in full from 30 December 2024, the transitional period that let firms keep operating under national licenses while they converted to full Crypto-Asset Service Provider authorization closed on 1 July 2026, and on 20 May 2026 the Commission launched its consultation package asking whether the regulation is still fit for purpose. Barely a year into full application, and days before the last grandfathering window shut, Brussels formally opened the question of what MiCA review 2026 changes. This article separates what the consultation actually asks, straight from the primary text, from what press and industry speculate about a future "MiCA v2", clearly labeled as speculation wherever it appears.
In short: the European Commission opened the MiCA review consultation under Articles 140 and 142 of the regulation, with responses due 30 September 2026 (extended from an original 31 August 2026 deadline printed in the consultation document itself). The questionnaire's four parts put stablecoin multi-issuance and third-country equivalence, CASP prudential and reporting rules, DeFi decentralization criteria, staking, lending and borrowing plus the MiCA-or-MiFID classification of perpetual futures on the table. It never mentions reverse solicitation or crypto-assets without an identifiable issuer, the two hottest interpretive fights of 2026, which we cover in dedicated articles. We build compliance and custody platforms for CASPs, and we read this consultation as an engineering roadmap rather than a policy document.
What the consultation actually is
The Commission runs two tracks in parallel: a public consultation with a general questionnaire, and a targeted consultation with technical and legal questions aimed at industry, financial institutions, academia and public authorities. Both launched together. The consultation document itself states "You are invited to reply by 31 August 2026", but the Commission extended that deadline in June, and the official consultation page now states responses are due by 30 September 2026, 23:59 CEST. Both dates matter for readers checking against older bookmarks or cached PDFs: 31 August was the original printed deadline, 30 September is the one that governs now.
The legal basis sits in MiCA's own review clauses, quoted here directly from the consultation document's footnotes:
Article 140(1): "By 30 June 2027, having consulted EBA and ESMA, the Commission shall present a report to the European Parliament and the Council on the application of this Regulation accompanied, where appropriate, by a legislative proposal. An interim report shall be presented by 30 June 2025, accompanied, where appropriate, by a legislative proposal."
That interim report never appeared: as of July 2026 the Commission has not published it, and this consultation now feeds the main application report due 30 June 2027.
Article 142(1): "By 30 December 2024 and after consulting EBA and ESMA, the Commission shall present a report to the European Parliament and the Council on the latest developments with respect to crypto-assets, in particular on matters that are not addressed in this Regulation, accompanied, where appropriate, by a legislative proposal."
The questionnaire itself has four parts, running to 86 numbered questions in total. Part 1 covers scope and definitions under Title II. Part 2 covers the requirements applying to asset-referenced tokens and e-money tokens and their issuers under Titles III and IV, including the multi-issuance model of global tokens and interaction with third-country regimes, reserve requirements, redemption rights and crisis management. Part 3 covers whether the current legal framework for crypto-asset service providers under Titles V and VI is still appropriate, though the consultation is explicit that supervision of CASPs itself sits outside its scope, handled instead in a separate market integration and supervision package. Part 4 covers topics beyond MiCA's initial scope entirely: DeFi, staking, lending and borrowing, NFTs plus the legal certainty of crypto-assets and other on-chain assets.
What is on the table, part by part
Part 1 asks about the boundary between crypto-assets and financial instruments under MiFID II: how hybrid tokens, wrapped assets, tokenized fund interests and tokenized money-market instruments should be classified.
Part 2 asks, through Question 41, about third-country equivalence regimes for stablecoins: what an equivalence regime should let EU issuers do abroad and what it should let third-country issuers do in the EU, on top of questions about the multi-issuance model for global tokens, reserve requirements, redemption rights and interest or remuneration on stablecoin holdings.
Part 3 covers several distinct threads for CASPs. Question 48 asks point-blank for "evidence of non-EU authorised crypto asset services providers continuing to offer their services in the EU", how they promote those services and what tools supervisors or enforcement authorities have or should have to stop non-authorised providers. Questions 45 to 47 ask whether the Article 3(16) services list is still adequate, what should be added or removed and whether an appropriateness test should apply to reception and transmission, execution and placing services. Question 49 asks whether the CASP prudential regime, currently the higher of a permanent minimum capital figure or one quarter of the prior year's fixed overheads under Article 67, should align more closely with investment-firm prudential standards. Question 52 covers CASP reporting directly, with a table asking about direct holdings of crypto-assets by CASPs, large derivative exposures, leveraged contract volumes and counterparty risk.
Part 4 is where the questionnaire reaches furthest beyond MiCA's current text. It quotes Recital 22's decentralization limb, "where crypto-asset services are provided in a fully decentralised manner without any intermediary", and asks which factors should be used to assess the degree of decentralization and whether risks to users of fully decentralized protocols warrant action. A dedicated section on staking, lending and borrowing of crypto-assets, activities the consultation itself describes as "currently not addressed in MiCA regulation", asks whether they should become regulated services. Questions 69 to 71 cover DLT-based prediction markets. Question 72 asks, verbatim, "Should perpetual futures on crypto-assets and services towards such perpetual futures be governed by MiCA or MiFID", with answer options for MiFID, MiCA or neither, and Question 73 asks what substantive requirements should apply. A separate section covers tokenized deposits, and the questionnaire closes Part 4 by naming NFTs and the legal certainty of on-chain assets, where national law still diverges on issuance, holdings and transfers of tokens.
What the consultation does not touch
Most coverage of this review lists what the questionnaire includes. Fewer sources state precisely what it excludes, and that gap is itself informative. A full-text search of the consultation document turns up zero occurrences of the phrases "reverse solicitation" and "identifiable issuer". The questionnaire does not reopen Article 61's reverse-solicitation mechanics, and it does not touch the crypto-assets-without-an-issuer question ESMA answered through Q&A 2552 in February 2026. The closest adjacency is Question 48's request for evidence of non-EU providers still serving EU clients, and Questions 45 to 46 on the CASP services list, but neither question uses either term. CASP supervision itself is also explicitly out of scope here, sitting instead in the separate supervision package. Any claim that "the consultation targets reverse solicitation evasion" is inference from adjacent questions, not something the text itself says. We give both topics dedicated treatment in separate articles: crypto-assets without an identifiable issuer and ESMA's Q&A 2552, and reverse solicitation under Article 61.
The numbers gap: the register outran the consultation draft
The consultation document's own footnote to Question 48 states: "Currently, there are around 170 CASPs listed in the ESMA register (including both authorised CASPs and other entities that have notified... their intention to provide crypto-asset services). These authorisations or notifications come from 18 different Member States." Skadden's 10 June 2026 analysis cited approximately 227 CASPs across 25 EEA countries, which is Skadden's own register snapshot at the time they wrote it, not a figure the consultation text itself contains. When we parsed the raw ESMA register CSV on 20 July 2026 for our own CASP register study, we counted 295 active authorizations across 26 countries, with custody authorization held by 70% of that population.
These are three different date-stamped snapshots of the same growing register, not conflicting counts of the same thing: around 170 when the consultation was drafted, roughly 227 at Skadden's 10 June writing, 295 active as of our 20 July parse. Nearly a quarter of all current authorizations, 72 records, landed in June 2026 alone, the final month of the transitional period, a spike we cover in full in our ESMA CASP register data study. Whatever a v2 package eventually becomes, it will regulate a market that scaled considerably while Brussels was still consulting on it. Any v2 impact assessment built on spring 2026 register data is already working from register-entry counts roughly 40% below today's.
Industry positioning: simplification vs expansion
Industry's own ask, at least as voiced by Bitpanda's public affairs team, points toward less complexity rather than more. Michał Truszczyński, a public affairs specialist at Bitpanda, put the current reading burden this way in comments to Notabene: "MiCA itself has 150 pages. The 47 implementing acts beneath it run to 2,000-3,000 pages. Add TFR and DORA, and you're looking at 5,000 to 10,000 pages of compliance reading in an industry that moves at pace." His point was not that the rules are wrong, but that the volume itself is the burden: before MiCA, Bitpanda held 17 separate national licenses and registrations, now replaced by a single MiCA license. The ask from industry, in his framing, is not a new framework but simplification and supervisory convergence across national competent authorities.
Press reports from 8 to 10 July 2026, originating with Cointelegraph and echoed by several other outlets, describe unnamed Commission staff preparing amendments that would extend authorization obligations to non-EU stablecoin issuers whose tokens circulate in the EU, and would bring tokenized payments and deposit-like products more clearly into scope. Some of these reports use the informal label "MiCA 2.0" for this potential package, attributed to how EU officials reportedly refer to it internally, not an official Commission term. The same reports say formal consideration is planned for 2027, and legal experts quoted in them do not expect an actual legislative proposal before 2028. That tension, industry asking for less reading and fewer overlapping regimes while the Commission's own questionnaire and the leaked amendment plans point toward a wider perimeter covering lending, staking, perpetual futures and non-EU stablecoin issuers, is the real tension this article traces.
Enforcement backdrop: the cost of getting v1 wrong
The review is happening against an enforcement backdrop that makes the stakes concrete. On 6 November 2025 the Central Bank of Ireland fined Coinbase Europe Limited EUR 21,464,734, reduced from EUR 30,663,906 under a settlement discount, over anti-money-laundering and counter-terrorist-financing transaction-monitoring failures. Three coding errors left 5 of 21 monitoring scenarios not fully screening transactions during 2021-2022, more than 30 million transactions worth over EUR 176 billion went improperly monitored, and remediation took nearly three years and produced 2,708 suspicious transaction reports. The Irish Times described it as the fourth-largest fine the Central Bank of Ireland has ever issued and the first against a crypto firm. This is an Irish AML enforcement action under Irish law, not a MiCA sanction, and it should be read as the enforcement climate CASPs now operate in rather than as an example of MiCA penalties themselves.
MiCA's own sanction ceilings under Article 111 are separate and lower for CASPs specifically: up to EUR 700,000 for natural persons, and up to EUR 5,000,000 or 5% of annual turnover for CASP legal persons. A 12.5%-of-turnover tier does exist in MiCA, but it applies only to ART and EMT issuer infringements, not to CASPs. On the enforcement side of the register, ESMA's non-compliant entities list, snapshotted 20 July 2026 alongside our register study, names 164 unauthorized operators, 162 of them flagged by Italy's Consob alone. We give that population its own full treatment in a dedicated article on reverse solicitation, since it sits closest to the offshore-enforcement question Part 3 of the consultation raises.
What MiCA v2 would change in the engineering roadmap
We read this consultation less as a policy document and more as a list of build implications. Nothing here is a proposal yet, the questionnaire asks questions, and any of the following depends on whether a v2 package actually materializes and in what form.
| Consultation area | What it would change in the systems we build |
|---|---|
| CASP reporting (Question 52) | Regulatory reporting on holdings, exposures and leverage becomes a first-class subsystem with lineage and reconciliation, not an export script bolted onto the ledger |
| Prudential alignment (Question 49) | Capital calculation engines and fixed-overheads tracking move fully into the compliance stack rather than living in a quarterly spreadsheet |
| Staking, lending and borrowing (Part 4) | Yield-bearing features need license-aware feature flags and segregated accounting built in from day one, not retrofitted after a perimeter change |
| DeFi decentralization factors (Part 4) | DeFi gateway features need audit trails that can prove exactly what the platform connects a user to and how |
| Perpetual futures classification (Question 72) | Derivative product lines need architecture where product classification lives in configuration, not hard-wired into the matching engine, so a classification flip does not force a rebuild |
Of everything in the questionnaire, the CASP reporting questions would change our clients' architectures the most, in our experience. In the platforms we build, regulatory reporting usually starts life as an export script bolted onto the ledger. If a v2 package eventually mandates recurring reports on holdings and exposures along the lines Question 52 asks about, that script becomes a supervised data product with lineage, reconciliation and an audit trail behind it, and teams that model it that way from the start will not feel the transition as sharply.
Custody is where we expect any review of this scale to bite hardest in practice regardless of which specific questions turn into rules: 70% of active CASPs, 207 of 295 in our 20 July 2026 snapshot, have custody in their service set, and ESMA's own custody-focused Common Supervisory Action is already probing how that service is actually run day to day, a review we cover separately in our custody CSA preparation guide. Whatever prudential or reporting tightening a future v2 brings lands on the largest single service population in the register.
We also treat today's unregulated features, staking, lending, yield programs, as tomorrow's licensed activities by default. In practice that means license-aware feature flags, segregated accounting and per-jurisdiction kill switches built around exactly the services Part 4 of the consultation asks about. Retrofitting that separation after a perimeter change lands is an order of magnitude more expensive than designing it in from the start. On the perpetual futures question specifically, the honest engineering answer to "MiCA or MiFID" is to build so that it does not matter: product classification should live in configuration, because a classification flip at the level-1 text can otherwise force a rebuild of the entire trading stack.
Timeline outlook and what to do before 30 September 2026
The sequence from here is long and each step depends on the one before it. The consultation closes 30 September 2026. Article 140's application report is due to the European Parliament and the Council by 30 June 2027. Press reports place formal consideration of amendments in 2027, and legal experts quoted in that same coverage do not expect an actual legislative proposal before 2028, after which a trilogue negotiation and transition periods would still need to run before anything applies. Read plainly, that puts any binding v2 changes several years out at minimum, and every step in that chain is attributed forward-looking commentary rather than a confirmed date.
The practical advice for now does not depend on that timeline resolving. The consultation is targeted at CASPs and their vendors, not just at law firms and industry associations, so responding to it directly is on the table for any firm with a view on its own product surface. Responses are submitted through the Commission's EU Survey online questionnaire linked from the consultation page, and only responses received through that questionnaire are taken into account. Respondents may answer only the questions relevant to them, and responses are published according to the privacy options each respondent selects in the questionnaire. The deadline is 30 September 2026, 23:59 CEST. Inventorying which questionnaire items touch your own architecture, custody, reporting, staking or derivatives, is worth doing regardless of when or whether a v2 package lands. And date-stamp your own register-based market analyses, because as this article shows, the underlying numbers move on a weekly basis, not a yearly one.
How Pharos Production helps
We build MiCA compliance and custody platforms with this review's likely direction already in view: reporting pipelines designed as data products rather than scripts, prudential capital tracking that plugs into the compliance stack rather than a spreadsheet, and feature architecture where licensing status and product classification live in configuration rather than being hard-wired. If your platform sits inside the areas this consultation is asking about, our MiCA compliance software development practice can walk through what a v2 direction would mean for your specific architecture, whatever form it eventually takes.
Sources: European Commission targeted consultation document on the review of MiCA (published 20 May 2026, deadline extended to 30 September 2026 23:59 CEST); Regulation (EU) 2023/1114 (MiCA) Articles 111, 140 and 142; European Commission news release on the consultation launch (20 May 2026); Skadden "Fit for Purpose?" (10 June 2026); Notabene, "What the End of MiCA Grandfathering Means for Crypto Firms in Europe" (Bitpanda/Truszczyński quote); Central Bank of Ireland press release on the Coinbase Europe enforcement action (6 November 2025); The Irish Times (6 November 2025); press reporting on non-EU stablecoin issuer amendments, 8-10 July 2026; our own ESMA CASP register raw-CSV analysis dated 20 July 2026.
FAQ
Quick answers to common questions about custom software development, pricing, process and technology.
Type to filter questions and answers. Use Topic to narrow the list.
Showing all 7
No matches
Try a different keyword, change the topic or clear filters
-
A targeted plus public consultation the European Commission launched on 20 May 2026 under Articles 140 and 142 of MiCA to assess whether the regulation remains fit for purpose. Responses are due by 30 September 2026, extended from an original 31 August 2026 deadline printed in the consultation document.
-
No. There is no legislative proposal. The consultation feeds the Article 140 report due by 30 June 2027, and press reports say officials are informally discussing a potential future amendment package, with formal consideration planned for 2027.
-
Yes. Part 4 of the questionnaire asks whether staking and lending and borrowing should become regulated services and which factors should define the degree of decentralization for DeFi.
-
That is an open question the consultation itself asks. Question 72 offers three answer options: governed by MiFID, governed by MiCA or governed by neither.
-
No. Neither phrase appears in the consultation document. Its closest question, Question 48, asks for evidence of non-EU providers still serving EU clients.
We cover both topics in dedicated articles.
-
The Article 140 report is due 30 June 2027. Press-cited experts do not expect a legislative proposal before 2028, so any applied changes are plausibly several years further out still, after a trilogue and transition period.
-
295 active authorizations in the ESMA register as of 20 July 2026, per our own parse of the raw register data, up from the roughly 170 register entries the consultation document itself cited when it was drafted.
I work with startup founders who need a dedicated software development team but don’t want to gamble on hiring, random outsourcing, or opaque delivery.
Most founders face the same problem sooner or later.
Early technical and team decisions lock the product into tech debt, slow delivery, missed milestones and constant re-hiring. By the time this becomes visible, fixing it is already expensive.As a CTO and software architect, I help founders design, build and run dedicated development teams that work as a true extension of the startup. Not as a black-box vendor.
My focus is on complex products where mistakes are costly:
- Web3 and blockchain platforms
- FinTech and regulated products
- High-load startup systems
- MVP → scale transitions
We don’t do body-shopping.
We don’t sell generic outsourcing.Instead, we help founders:
- build the right team structure from day one
- keep technical ownership and transparency
- scale delivery without losing control
- avoid vendor lock-in and hidden risks
Teams are aligned with the product roadmap, business goals and long-term architecture. Not just short-term velocity.