Ivan Nevzorov on MiCA, CASP Licensing, and What’s Next for Crypto Firms

Coinbase


spsp

Of the more than 3,000 companies that were legally serving crypto clients across the EU as recently as this June, fewer than 300 hold the right to do so today, according to CASP Tracker.

The reason is the Markets in Crypto-Assets Regulation (MiCA), which took full effect across the European Union on 1 July 2026: from that date, only a company holding Crypto-Asset Service Provider (CASP) authorisation — granted by a regulator in one EU member state and passported across the rest of the bloc — can serve EU clients. Companies that previously operated under national Virtual Asset Service Provider (VASP) registrations had exactly until that date to convert. Most didn’t.

We talked to Ivan Nevzorov, CEO at SBSB Fintech Lawyers, about what’s actually left for them now — and why the shortcuts most of them reach for first usually aren’t the ones that hold up.

Let’s start with the obvious one. A company still doesn’t have a CASP licence today — what happens to it now?

Ivan Nevzorov: Look, here’s the thing people don’t want to hear: the deadline’s already passed. From July 1st, every day you keep serving EU clients without authorisation is a day you’re in breach of MiCA — a minimum €5 million fine under Article 111, and in France it can mean criminal liability for whoever’s responsible. So the answer everyone expects to hear, “just go get licensed,” isn’t actually on the table anymore for a company operating today. You can’t file an application, keep the lights on for months while it gets reviewed, and call that compliance.

Which really leaves two paths. One, you wind down, because the business can’t meet the new standard. Two, you relocate — move your base to a friendlier jurisdiction. Though that one only keeps you legal if you stop marketing into the EU completely and let clients come to you on their own, what’s called reverse solicitation. Keep advertising to EU users from outside the bloc, and you’re breaking the exact same rule, just from a different address.

We’ll come back to relocating, because it’s genuinely its own conversation. Let’s start with winding down, since that’s where most of these companies actually are right now — and honestly, it’s painful to watch, because most of them didn’t do anything wrong. They just didn’t get there in time, and for a lot of them, the reasons had nothing to do with how good their compliance actually was.

Winding down sounds like the more straightforward path, at least. Is it actually?

Ivan Nevzorov: Not as straightforward as people think, and there’s a right way and a wrong way to do it. The wrong way is switching off the app and disappearing — the client assets sitting in those accounts don’t vanish, and holding them is a regulated activity in itself. To the regulator, that company hasn’t gone anywhere. It’s still operating without a licence, only now it’s also stopped answering its clients. The right way is one of two things: an orderly wind-down, or transferring your clients to a CASP that’s already authorised.

ESMA’s actually spelled out what an orderly wind-down has to look like: stop onboarding, stop any marketing into the EU, restrict yourself to settling what’s already open. And transferring clients sounds simpler on paper, but being on the CASP register only tells you a firm’s allowed to take clients — it doesn’t tell you they’re actually set up to onboard a few thousand new ones at once. A lot of the firms that got authorised fastest didn’t build a crypto compliance function from zero — they already held a MiFID or e-money licence and just converted it, lighter scrutiny attached. Good for them, but it also means some of these brand-new CASPs are banks running crypto as a side product, not specialists who can absorb a wave of migrating clients. Every single one of those clients still needs full AML and KYC re-verification before the new CASP can touch their money. That’s months of work for a team that does it every day. Longer for a team that doesn’t.

You’d think the bigger platforms would have this solved by now. Is that actually the case?

Ivan Nevzorov: Less than people think, and Binance is actually a fair example of why. A platform with years of European operating history and enormous legal and compliance resources still ran into real MiCA licensing problems — the same wall a lot of much smaller companies are hitting. That tells you something worth sitting with: this isn’t a gap you close just by throwing money or headcount at it. If a company at that scale couldn’t get it fully sorted before the deadline, a smaller operator shouldn’t assume they’ll just muscle through it either.

Let’s rewind for a second — only a couple hundred companies actually made it through while that was still possible. What was going wrong for the rest?

Ivan Nevzorov: Honestly, it’s rarely the paperwork. A technically correct application just gets you in the room — it doesn’t win you the decision. We saw one filing get rejected over how the share capital was deposited, and that requirement isn’t even written into MiCA, anywhere. The regulator just invented a formality that isn’t in the text. That’s the pattern I keep seeing: whatever reason they put on paper is almost never the real one. The real reason comes to you informally, if it comes at all, and it’s about how they read the company — do you actually understand your own risk model, who’s accountable for what, who your clients really are. A compliance policy copied from a template answers none of that. It’s the first thing I flag when someone walks into SBSB with one.

And the second thing people underestimate completely: where you filed mattered almost as much as what you filed. This wasn’t one process across the EU — it was twenty-seven versions of it, moving at completely different speeds, with completely different appetites for saying no. Germany’s BaFin wasn’t shy about it: its first-ever MiCA enforcement action was rejecting Ethena’s application and then forcing the company to wind down its German operation and redeem its tokens. Italy’s regulator went the other way — it spent most of the transition period without having authorised anyone at all, so filings there just sat. Same regulation, wildly different odds depending on the door you knocked on. A few countries never even built the door — Poland’s the loudest example, it went into the deadline with no authority issuing CASP licences at all — but that’s the extreme end of a spectrum the whole market was sitting on.

Let’s talk about the companies actually going through the licensing process, then — a first application in a market they haven’t touched yet, or a return down the line after an orderly exit. What does a strategy that actually works look like, in practice?

Ivan Nevzorov: Honestly, it starts before you’ve touched a single form. You go talk to the regulator first, find out exactly what they expect from a business like this one, and only then do you build the structure around that answer — the AML policy, the governance, the documentation. MiCA’s a directive, which means every country implements it a little differently, so a compliance package that worked in one member state gets rechecked before you dare reuse it somewhere else. People skip that step constantly, and it costs them.

At SBSB, a full mandate for us looks like this: company formation, the application itself, handling the regulator correspondence, and then the parts most founders genuinely can’t build alone — banking relationships, payment infrastructure, penetration testing through our partners, licensed compliance software. And staffing matters just as much. Regulators check AML certifications early, so get that sorted before the application goes in, not after you’ve already filed.

How should a company actually choose which EU market to apply in — Germany, Austria, the Netherlands, Estonia?

Ivan Nevzorov: I don’t give every client the same answer, honestly, and if anyone tells you there’s one magic jurisdiction, they’re oversimplifying it for you. But the differences between regulators are real, and by now they’re well documented. Germany’s BaFin gives you the heaviest signature in Europe — corporate clients respect it — but you pay for it: a German entity, at least two qualified directors actually present in the country, capital paid up at filing, and a documentation pack that runs to hundreds of pages, with the formal filing in German. France is the opposite story: the AMF had been licensing crypto firms under its own national regime for five years before MiCA existed, so firms already registered there got a genuinely streamlined path, and the regulator’s crypto unit knows what it’s looking at. Luxembourg, Ireland, and Malta became the hubs the big exchanges actually picked: Coinbase went through Luxembourg, Kraken through Ireland, OKX and Crypto.com through Malta. That’s not a coincidence; it’s where the process was mature enough to handle a file that size.

But here’s what I actually tell clients: the regulator’s speed shouldn’t decide it — your own capacity should. Every serious regulator now checks for the same thing: a real office, real staff on the ground, a credible plan for that specific market. Pick the jurisdiction where you can honestly show that, not whoever’s got the shortest queue — a fast process with no substance behind your application just gets you a fast rejection. And yes, Germany leads on raw licence numbers right now, but a good chunk of that is banks and brokers converting a licence they already had, not crypto-native firms getting freshly approved. “Germany has the most CASPs” and “Germany’s the easiest place for a crypto company” are two different claims, and people mix them up constantly. I don’t think any single country’s lead holds for long anyway — regulator capacity is finite everywhere. We’ve watched this movie before, it’s basically what happened with Curaçao’s gaming licence reform. Once the volume outpaces what the regulator can actually process, the process itself becomes the bottleneck.

Let’s come back to relocating, the third path you mentioned earlier. For companies thinking globally, how should they weigh an EU licence against licences elsewhere — Latin America, Asia, offshore?

Ivan Nevzorov: Look, the safest position is full compliance everywhere you operate — better banking terms, full market access, nothing sitting in a grey area. But that takes a budget most startups just don’t have. So in practice, most of them end up running from a business-friendly base — El Salvador, Panama, the UAE, Singapore, Mexico, these come up constantly — and serving EU clients only through reverse solicitation, sometimes with geo-blocks stacked on top for the riskier markets.

But notice what those two options really are: one’s too expensive for most, and the other cuts you off from actively winning EU clients at all. Which is why the question I hear constantly right now is: can’t I just operate under someone else’s licence? And here’s where MiCA catches people off guard. In payments, under the Second Payment Services Directive, PSD2, there’s a proper agent model — an unlicensed company can work the market on behalf of a licensed one, and the industry uses it everywhere. MiCA has nothing like that. Articles 59 and 60 draw a hard line around who’s allowed to provide crypto services at all, so the classic white-label — an unlicensed provider serving clients in its own name under someone else’s licence — formally doesn’t work.

What nobody forbids, though, is supplying a licensed CASP with technology or marketing. That’s fully legal, and the entire market has rushed into the gap between those two points — KvarnX, Bitpanda, Bit2Me are all running their own versions of it, and Spain’s regulator has even given the grey-label approach a cautiously positive read, with real limits attached. The catch is what role you’re actually playing: the licensed partner holds every wallet, every bank account, every client transaction. You’re the technology behind their offer, not the provider in front of the client. For a lot of companies that’s a perfectly good way back into the EU market. Just be honest with yourself about which side of that line your business model actually needs to be on.

Last one — once a company has the CASP licence, what does the ongoing workload actually look like?

Ivan Nevzorov: Getting the licence is honestly the easy part to talk about. Staying licensed is where companies actually get tested. I’ve watched a licence get pulled by an EU regulator within months of being granted, because the business just didn’t follow through on what it promised in the application. What actually matters, once you’re authorised, is exactly what you signed up for on paper — active risk assessment, ongoing AML monitoring, reporting to the regulator on time, every single time.

Has that gap between paperwork and practice actually cost one of your clients?

Ivan Nevzorov: This one’s a bit different — no regulator pulled anything here, and it’s actually from outside crypto. But it’s the same underlying lesson, so it’s worth telling. We had a client at SBSB who did everything right on paper: MSB registration, their API — Authorised Payment Institution — licence, connected to a banking-as-a-service partner, targeting the European market. Business plan solid, AML policy solid, source-of-funds checks all cleared. Where it fell apart was the economics nobody had stress-tested. The marketing spend needed to actually hit their projected client volume ran well above what they’d budgeted. The partner bank’s own compliance screening filtered out a chunk of the high-risk client segment their whole model was built around. And the tariffs the bank actually offered were thinner than what they’d planned for. Nothing illegal happened anywhere in that chain. The business just didn’t survive contact with the market it was built for. They made the call to sell, and we’ve already found a buyer — sold it, more or less, at this point.

One thing that’s genuinely changed the economics here is AI in compliance monitoring. Transaction monitoring that used to eat up a whole team can run with a fraction of the people now — cheaper for the company, and from what regulators have signalled, easier for them to work with too. None of that replaces the basic requirement, though. The licence is the easy part. Staying licensed — that’s the job.

If you had to give one piece of advice to a company still sitting on this decision — wind down or relocate, transfer or hold — what would it be?

Ivan Nevzorov: Pick your strategy and start moving — this week, not this quarter. The window between now and the first wave of regulatory checks is the only asset these companies have left, and it’s shrinking: we flagged back in May that the first checks would land around the third quarter of this year, and the Netherlands has already shown how this plays out — their central bank fined Kraken €4 million and Crypto.com €2.85 million under the old registration regime, and OKX €2.25 million just last year, for something that happened two years earlier.

A company that uses these months to actually execute — transfer the clients, close out the obligations, or get the relocation structure in place — walks into that first check with a story of action behind it. A company that’s still weighing its options in September walks in with an explanation for why it did nothing. Given the choice, I know which conversation I’d rather have with a regulator.

Disclaimer: The above article is sponsored content; it’s written by a third party. CryptoPotato doesn’t endorse or assume responsibility for the content, advertising, products, quality, accuracy, or other materials on this page. Nothing in it should be construed as financial advice. Readers are strongly advised to verify the information independently and carefully before engaging with any company or project mentioned and to do their own research. Investing in cryptocurrencies carries a risk of capital loss, and readers are also advised to consult a professional before making any decisions that may or may not be based on the above-sponsored content.

Readers are also advised to read CryptoPotato’s full disclaimer.

SPECIAL OFFER (Exclusive)

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!



Source link

Ledger

Be the first to comment

Leave a Reply

Your email address will not be published.


*