2026-07-07 | C790Added · Updated
The MiCA transitional period ended on 1 July 2026, requiring firms to obtain MiCAR-compliant authorization as crypto-asset service providers (CASPs) to continue operations. Unauthorised virtual asset service providers must implement robust wind-down plans, maintain adequate AML/CFT governance, and ensure up-to-date customer due diligence until activities cease. Authorised CASPs are required to scale transaction monitoring systems and apply individual risk-based customer due diligence rather than blanket de-risking when onboarding migrating customers. Regulated entities must assess ML/TF risks associated with unauthorised or offshore VASPs and enhance their risk-based approach under the Prevention and Suppression of Money Laundering Activities Law.
TO : Regulated Entities i Crypto Asset Service Providers ii CIFs iii UCITS Management Companies iv Internally managed UCITS v AIFMs vi Internally managed AIFs vii Internally managed AIFLNPs viii Companies with sole purpose the management of AIFLNPs ix Small AIFMs under Law 81(I)/2020 FROM : Cyprus Securities and Exchange Commission DATE : 7 July 2026 CIRCULAR NO. : C790 SUBJECT : ML/TF risks following the end of the MiCA Transitional Period The Cyprus Securities and Exchange Commission (the ‘CySEC’) wishes to draw the attention of all the Regulated Entities that the MiCA transitional period has ended on 1 July 2026. Following this date, firms are required to obtain authorisation as Markets in Crypto-Assets Regulation (MiCAR)-compliant crypto-asset service providers (CASPs) in order to continue providing crypto-asset services within the European Union. CySEC would like to inform the Regulated Entities that the EU’s Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) has published an Advisory note on the money laundering and terrorist financing (ML/TF) risks associated with the end of the transitional period under the MiCAR. In its advisory note, AMLA highlights the ML/TF risks that may arise following the conclusion of this transitional period and outlines mitigating measures that may be adopted by unauthorised virtual asset service providers (VASPs) and authorised CASPs. These measures are intended to support the application of a risk-based approach and contribute to safeguarding the integrity of the EU financial system.
2 The end of the transitional period is expected to result in significant structural changes within the EU crypto-asset sector, as unauthorised VASPs exit the market and customer relationships previously maintained with such providers are either terminated or transferred to a smaller number of authorised CASPs. AMLA emphasises that where customers migrate from unauthorised VASPs to authorised EU CASPs, the latter should conduct appropriate individual risk assessments and apply proportionate customer due diligence measures in line with the risk-based approach, rather than adopt blanket de-risking practices. In particular, the potential ML/TF risks arising from the end of the transitional period along with suggested mitigation measures for unauthorised VASPs and authorised CASPs are: Unauthorised VASPs Unauthorised VASPs are exposed to a risk of weakened AML/CFT controls during exit process, as the compressed timelines for ceasing activities may strain their AML/CFT frameworks at a critical juncture. This risk is particularly relevant for entities previously identified as having deficiencies in their AML/CFT controls. The recommended risk mitigation measure is the implementation of robust wind-down and AML/CFT controls. Where under the applicable national legal framework, wind-down plans are established, firms should implement such plans in a structured and well-documented manner to ensure the orderly cessation of activities. Throughout the wind-down process, and until all regulated activities have ceased, firms should maintain adequate AML/CFT governance, adequate resources and enhanced monitoring. Unauthorised VASPs may also face the risk of illicit flow concealment during the wind-down process. Abrupt market exits may reduce transparency over asset flows and customer relationships, creating opportunities for the concealment and rapid movement of illicit funds, as well as sanctions evasion. The suggested risk mitigation measure is to maintain up-to-date customer information and comply with reporting obligations. Throughout the wind-down process, as provided for under the applicable national legal framework, and until all regulated activities have ceased, firms should ensure compliance with their AML/CFT obligations, including maintaining up-to-date customer due diligence (CDD) information and identifying and reporting suspicious transactions or activities. Authorised CASPs Authorised CASPs may experience sudden changes in their ML/TF risk exposure following the end of the MiCA transitional period. Shifts in business models and customer portfolios following authorization decisions may result in materially different risk profiles. This includes potential concentration of higher-risk customers among continuing or newly authorized
3 CASPs. To mitigate these risks, authorised CASPs should ensure that their transaction monitoring systems are capable of handling increased volumes of crypto-asset transfers. ASPs onboarding new customers from unauthorised VASPs should ensure the scalability of their AML/CFT controls and maintain adequate staffing and system capacity to manage increased workloads. Authorised CASPs may also face increased pressure on their transaction monitoring capacity. Rapid customer inflows may strain transaction monitoring systems and compliance resources and these may require appropriate adjustments to ensure that associated ML/TF risks continue to be managed effectively. To mitigate these risks, authorised CASPs should strengthen their customer onboarding and risk integration processes. In particular, they should apply effective customer due diligence (CDD) measures and ensure the proper integration of incoming customer risk information. VASPs’ customers should not be subject to blanket de-risking solely on the basis of their origin, but assessed individually under a riskbased approach, with enhanced due diligence applied where higher risks are identified. Regulated Entities are reminded that compliance with applicable AML/CFT obligations remains their responsibility throughout the transition period and after the completion of any customer migration or wind-down activities. CySEC also draws the attention of Regulated Entities to the FATF Report Understanding and Mitigating the Risks of Off-shore VASPs, which highlights the ML/TF risks associated with relationships with unauthorised or offshore VASPs. In this regard, Regulated Entities are expected to identify and assess the ML/TF risks arising from relationships, transactions or business activities involving unauthorised VASPs and to apply appropriate risk mitigation measures in accordance with a risk-based approach. The CySEC urges the Regulated Entities to take duly into account and consider the specific money laundering and terrorist financing risks that may arise following the end of the MiCA Transitional Period and enhancing their risk-based approach under the Prevention and Suppression of Money Laundering Activities Law (L. 188(I) 2007) as amended from time to time. Sincerely, Dr George Theocharides Chairman, Cyprus Securities and Exchange Commission