A crypto platform can be incorporated in the EU, hold an old anti-money-laundering registration, or publish a MiCA white paper without being authorized to provide every crypto-asset service across the Union. The reliable starting point is the legal entity and the official register—not a logo in the footer.
Quick answer: search the European Securities and Markets Authority (ESMA) MiCA register for the platform’s exact legal entity, then confirm the home-state authority, authorization status, permitted services, and website domains. Cross-check the national competent authority when a record is unclear.
Information date: 31 July 2026. Regulatory records change; repeat the check immediately before opening or funding an account.
What MiCA authorization means
The EU Markets in Crypto-Assets Regulation (MiCA) creates a common framework for crypto-asset issuers and crypto-asset service providers (CASPs). Covered services include activities such as custody, operating a trading platform, exchanging crypto-assets for funds or other crypto-assets, executing orders, placing crypto-assets, transfer services, advice, and portfolio management.
A CASP applies to the competent authority in an EU member state. An authorized provider can use the MiCA passporting framework to offer authorized services across the EU, subject to the regulation’s procedures. Authorization applies to a legal entity and a defined service scope—not automatically to every company in a group or every product shown on a global website.
Why 2026 is a key verification year
MiCA entered into force in June 2023 and its main CASP regime became applicable in stages. Member states could provide limited transitional arrangements for firms that already operated under national law. ESMA’s 2026 statement addressed the end of those periods, which could not extend beyond 1 July 2026.
A platform that once relied on a national transition should not be assumed authorized today. Look for its current MiCA record and the national authority’s current notice.
How to check an exchange step by step
1. Find the legal entity
Open the platform’s terms of service, account agreement, or regulatory disclosure. Record:
- full legal name;
- company or registration number;
- registered address;
- the entity that contracts with customers in your country; and
- official website domains and app publisher.
A brand may use different entities for EU, UK, US, and other customers. Searching only the brand name can return the wrong company.
2. Open ESMA’s official MiCA page
Use the register links on ESMA’s MiCA hub. ESMA’s central information includes authorized crypto-asset service providers, crypto-asset white papers, issuers of asset-referenced and e-money tokens, and non-compliant entities. Avoid unofficial “MiCA exchange lists” that may be incomplete or outdated.
3. Search for the exact entity
Compare legal name, identifier, home member state, competent authority, and authorization date. Similar names do not prove a match. If the company number or address differs, investigate before depositing.
4. Check the permitted services
Authorization is not a blank approval of every activity. Confirm that the record covers the service you intend to use—custody, exchange, trading platform, transfer, advice, or another category.
A provider may also offer products governed by other laws or outside MiCA’s scope. MiCA authorization for spot crypto services does not automatically authorize derivatives, securities, lending, deposit-taking, or every yield product.
5. Verify domains and warnings
Scammers impersonate authorized firms. Compare the domain, app publisher, email addresses, and contact details against the official record and national authority. A genuine license number copied onto a fake website is still fraud.
Search ESMA’s non-compliant-entity data and the warning list of the relevant national authority. Absence from a warning list is not proof of authorization; use both positive and negative checks.
6. Cross-check the national competent authority
ESMA compiles data supplied by national authorities. When a listing is recent, ambiguous, or not yet reflected, open the regulator’s own register or contact it through an official domain. Do not use a phone number supplied by the platform for this verification.
Claims that do not equal MiCA authorization
| Claim | Why it is insufficient |
|---|---|
| “Registered company in the EU” | Company incorporation is not CASP authorization |
| “VASP registered” | An older AML registration may have a narrower scope and may no longer support new EU business |
| “MiCA compliant” | Self-description is not an entry in the official CASP register |
| “White paper listed by ESMA” | ESMA notes that listed white papers are the issuer’s responsibility and are not approved by a competent authority merely because they appear in the register |
| “Partner of a licensed bank” | A partner’s status does not automatically cover the platform |
| License number in website footer | The number may belong to another entity or be copied by an impersonator |
What authorization does not guarantee
MiCA authorization provides a regulatory framework; it does not guarantee profit, prevent every cyberattack, or make a token safe. Users still face:
- crypto price volatility;
- operational outages and account restrictions;
- phishing and device compromise;
- token smart-contract and bridge risk;
- product-specific legal exclusions;
- custody and insolvency risk; and
- losses from leverage or poor execution.
Authorization is one due-diligence layer. Also review custody terms, withdrawal controls, financial disclosures, and whether a reserve report is being overstated. Our proof of reserves vs audit guide explains that distinction. For venue structure, see the CEX vs DEX comparison.
What to do if no authorization appears
- Recheck the legal entity and spelling.
- Search the home-state regulator’s official register.
- Ask the platform, in writing, which entity serves your country and under what authorization.
- Verify the answer independently with the regulator.
- Do not deposit while the status remains unclear.
- If funds are already held, review withdrawal options and preserve account records. Avoid rushed transfers prompted by unsolicited “regulator” messages.
A missing record does not, by itself, prove criminal conduct. The service may be out of scope, serve a non-EU customer through another entity, or have a data-timing issue. It does mean you should not repeat the claim that it is MiCA-authorized without official confirmation.
Frequently asked questions
Does MiCA cover every crypto token?
No. MiCA has defined scopes and exclusions, and some tokenized instruments can fall under existing financial-services law instead. Product classification may require legal analysis.
Can one EU authorization cover all member states?
MiCA provides a passporting mechanism for authorized services, but the exact entity, services, notifications, and host-state information still need to be checked.
Is a listed crypto-asset white paper approved by ESMA?
No. ESMA expressly states that white papers in its register have not been reviewed or approved merely by being listed; responsibility remains with the offeror or issuer.
Does MiCA protect non-EU customers?
Not automatically. The contracting entity, customer location, product, and applicable terms determine which protections and authorities are relevant.
This is general information, not legal advice or a finding about any named platform. Check current ESMA and national-authority records.