256 of 289 EU27 CASPs Have Trading-Related Permissions
The ESMA interim MiCA register dated July 24 contained 312 rows for authorized crypto-asset service providers. FM Intelligence deduplicated the file by Legal Entity Identifier, producing 308 unique entities across the European Economic Area.
The register includes Iceland, Liechtenstein and Norway. Removing 19 entities from those non-EU EEA states leaves 289 authorized CASPs in the EU27. The scope adjustment matters because the underlying sanctions regulations apply directly in EU member states, while the ESMA register covers the wider EEA.

FM Intelligence classifies an entity as trading-related when its combined authorization contains at least one of four MiCA services: operating a trading platform, exchanging crypto-assets for funds or other crypto-assets, executing orders, or receiving and transmitting orders. On this basis, 256 EU27 entities, or 88.6%, have a trading-related permission.
This is a screening population, not an exposure count. A permission does not establish that the service is active, retail-facing or connected to a sanctioned party. It does indicate where firms are more likely to maintain relationships with external venues, custodians, liquidity providers, payment companies or settlement providers.
The difference between permission categories is material. Only 20 entities across the EEA register were authorized to operate a trading platform, but 175 held a crypto-to-funds exchange permission, 157 held execution permission and 87 held reception and transmission permission. Treating the review as relevant only to venue operators would therefore understate the potential operating perimeter.
Five Home States Hold 57.4% of Authorized CASPs
The EU27 population is concentrated in a small group of home states. Germany has 63 authorized CASPs, followed by France with 30, the Netherlands with 29, and Malta and Cyprus with 22 each.
Together, these five jurisdictions account for 166 of 289 authorized entities, or 57.4%. Germany alone represents 21.8% of the EU27 population.
The concentration has two operational implications. First, supervisory communication and remediation queries may cluster around five national competent authorities. Second, passporting means the commercial impact will not remain within those home markets. An entity authorized in one country may serve clients or maintain counterparties across several member states.
The figures count legal entities, not brands or corporate groups. A group with several authorized subsidiaries can therefore appear more than once. Conversely, one legal entity may operate several customer-facing brands. Group-level controls may allow some review work to be reused, but the legal-entity assessment still needs to match the authorization and ownership record.
Review Workload Reaches 2,849 Actions in the Base Scenario
No public dataset reports how many material venues, custodians, liquidity providers, payment companies or settlement relationships each authorized CASP maintains. FM Intelligence therefore uses conditional scenarios rather than a point forecast presented as an observed fact.
Each scenario begins with one ownership and governance dossier for every EU27 CASP, producing a baseline of 289 dossiers. The relationship component applies to the 256 trading-related entities.
|
Scenario |
Assumed relationships per trading-related CASP |
Governance dossiers |
Relationship reviews |
Total review actions |
|
Narrow relationship set |
5 |
289 |
1,280 |
1,569 |
|
Base relationship set |
10 |
289 |
2,560 |
2,849 |
|
Wide relationship set |
20 |
289 |
5,120 |
5,409 |
The base scenario produces 2,849 review actions: 289 governance dossiers plus 2,560 material-relationship reviews. The narrow and wide cases create a range from 1,569 to 5,409 actions.

These scenarios are not probabilities. They do not estimate the number of unique counterparties, affected clients, wallets, staff hours, compliance costs or sanctions breaches. A centralized group review could reduce duplicated work. Indirect ownership chains, several legal entities behind one brand, nested payment routes and incomplete vendor records could increase it.
The model is a capacity-planning estimate for the initial control exercise. FM Intelligence would revise it if regulators or market participants disclose observed relationship counts, remediation volumes or completion rates.
Three August Dates Divide Transaction and Governance Controls
The legal timetable separates transaction restrictions from ownership and governance requirements.
|
Effective date |
Observed regulatory change |
Primary control task |
|
August 13, 2026 |
Transaction restrictions begin for A7 Nigeria, A7 Africa and PilotFinance |
Map named entities, aliases and indirect transaction paths |
|
August 23, 2026 |
Transaction restrictions begin for 11 further crypto-linked services |
Complete the second cohort review and block prohibited relationships |
|
August 25, 2026 |
Russia- and Belarus-related ownership, control and governing-body restrictions extend across MiCA-defined crypto services |
Refresh ownership, control, residency and board records |
The Council of the European Union adopted the Russia package on July 23. The timetable in Council Regulation (EU) 2026/1848 places three crypto-linked services in the August 13 cohort and 11 in the August 23 cohort.
The later cohort comprises Rapira; Aifory Pro, identified with Sooty Ltd.; ABCeX, identified with Nueva Cryptologia S.A.S. DE C.V.; WhiteBird; NoOnecrypto Inc.; Tradex, identified with Brightum LLC; Monease Ltd.; BitPapa; Exnode and Exnode Pay, identified with Arvix; HTX, identified as Huobi Global SA; and EXMO Ltd.
The legal-entity mapping is more important than the consumer-facing brand. A screening process that checks only a current trading name may miss a legal entity, historic name, affiliate or payment route. The prohibition also covers direct and indirect participation in transactions, so the relevant relationship set can extend beyond the party named on a client transfer.
From August 25, the ownership, control and governing-body restriction concerning Russian nationals and residents expands from entities providing wallet, account or custody services to entities providing any MiCA-defined crypto-asset service. Council Regulation (EU) 2026/1846 introduces the corresponding expansion for Belarusian nationals and residents from the same date.
This control cannot be implemented through a sanctions-name file alone. It requires current shareholder chains, voting and control rights, residency records and board appointments, each with an effective date. The main data risk is a mismatch between frequently refreshed onboarding records and less frequently refreshed corporate-governance records.
The Country-Level Mechanism Remains at Zero
The Russia package also adds Article 5bc to Regulation 833/2014. It creates a mechanism under which the EU can prohibit transactions with crypto service providers or exchange and transfer platforms established in a third country that systematically and persistently fails to prevent services that reduce the effectiveness of EU sanctions.
The accompanying Annex LVII was empty when the regulation was published. The observed number of jurisdictions subject to this country-level mechanism was therefore zero at publication.
This boundary prevents a misleading inference. The Council's references to platforms in Georgia, Panama, the United Arab Emirates, the Marshall Islands, Kyrgyzstan and Belarus do not create a prohibition on every crypto provider established in those jurisdictions.
The forward risk is still operationally relevant. A firm that stores only entity-level screening results may be unable to implement a future country-level restriction quickly. Venue, custodian, liquidity and payment-partner records should therefore include establishment country as a structured field. The observable trigger for escalation is a future Council decision adding a jurisdiction to Annex LVII.
Retail Exit Processing Is Not an Automatic Exemption
The regulation allows national competent authorities to authorize transactions strictly necessary for qualifying EU, EEA or Swiss citizens and residents to withdraw funds or close accounts with entities added to the relevant transaction-ban annexes. The application generally must be made within three months of the applicable restriction date, and funds must move to a qualifying credit or financial institution.
This is a discretionary authorization route, not an automatic retail exemption. A broker or platform should not assume that its standard withdrawal workflow remains sufficient after a restriction starts. Client status, account closure, destination institution and the absence of a continuing relationship can all affect the assessment.
For compliance planning, the sequence is therefore distinct: map and stop prohibited transaction paths for the August 13 and August 23 cohorts, complete the expanded ownership and governance review by August 25, and maintain a controlled route for authorized wind-down activity. Combining all three tasks into one list-screening update would omit the governance and retail-exit components.
Methodology: FM Intelligence analyzed Council Regulations (EU) 2026/1848 and 2026/1846, the Council's July 23 announcement and ESMA's July 24 interim MiCA registers. The authorized-CASP file contained 312 rows and 308 unique LEIs. FM Intelligence excluded 19 entities based in Iceland, Liechtenstein and Norway to produce an EU27 population of 289. Trading-related status requires at least one permission for a trading platform, crypto exchange, order execution, or reception and transmission of orders. The conditional projection adds one governance dossier per EU27 CASP to five, 10 or 20 assumed material relationships for each of 256 trading-related CASPs. It does not estimate breaches, users, wallets, hours or costs. Register reporting lag and inconsistent service descriptions create data-quality uncertainty; undisclosed relationship structures create scenario uncertainty.

