Digital Regulation

Spain closes MiCAR transitional period for crypto-asset service providers

Published on 23rd July 2026

From 1 July, only MiCAR-authorised entities can provide crypto-asset services in Spain

FS_Banking-finance_3D-graph-side-view

The transitional period, known as grandfathering, provided for in the European Union's Markets in Crypto-Assets Regulation ((MiCAR) expired on 30 June. The grandfathering period allowed providers who had offered crypto-asset services in accordance with national law prior to 30 December 2024 to continue their activities on a transitional basis while obtaining authorisation under MiCAR. 

In Spain, this involved being registered in the Bank of Spain’s former register of virtual currency providers, which was designed solely for the purposes of preventing money laundering and not as an authorisation in its own right. Now that this period has ended, only entities that have obtained the relevant authorisation may provide crypto-asset services.

End of grandfathering

An unauthorised provider may not continue to provide crypto-asset services to Spanish clients, nor may it acquire new clients, on the grounds that its application is pending. Authorisation under MiCAR must be obtained. If authorisation is granted in another member state, services may only be provided in Spain under the EU passport once the relevant passporting notification has been completed.

Spain's National Securities Market Commission (CNMV) has indicated in various public communications that providers who do not obtain authorisation by the deadline must have an effective client migration plan in place. Furthermore, the CNMV has urged these providers to maintain efficient and ongoing transparency in reporting on the migration plan and the resources available to clients. In addition to the possibility of liquidating crypto-asset positions into fiat currency, with the consequent risk of loss, the option of entering into agreements with authorised providers to transfer client positions is also provided for.

Third-country firms seeking to use reverse solicitation to circumvent the application of MiCAR is an approach to the Spanish market that is not without risks. This exception has always been interpreted restrictively and does not cover situations in which the provider solicits or promotes services amongst customers within the Union.

EMT: Is a MiCAR licence sufficient?

MiCAR classifies electronic money tokens (EMTs) as electronic money and restricts their issuance to credit institutions or electronic money institutions. A distinction must be made, however, between the issuance of an EMT and the provision of services relating to it: a crypto-assets service provider (CASP) may offer custody and administration of, or transfer, EMTs issued by a third party without becoming an issuer. The key issue is that some of these services may simultaneously constitute to the EU's second Payment Services Directive (PSD2).

In its opinion of 10 June 2025, the European Banking Authority (EBA) considered that transfers of EMTs carried out by a CASP on behalf of its customers should be treated as payment services and that a custodial wallet may constitute a payment account. However, the EBA recommended that the exchange of crypto-assets for funds and the reception and transmission of orders for crypto-assets using EMT should not be treated as payment services. The classification therefore depends on the specific operational flow.

For services that do constitute payments, the provider requires, in addition to its MiCAR authorisation, a PSD2 authorisation as a payment institution or electronic money institution, or an agent arrangement under the licence of an authorised payment service provider. The Bank of Spain expressly reiterated this requirement in March this year.

Obtaining this additional PSD2 authorisation is not, however, necessarily the end of the regulatory analysis. In its June 2025 opinion, the EBA has recommended that the European legislator use the third Payment Services Directive (PSD3) and the Payment Services Regulation (PSR) legislative process to strengthen MiCAR in relation to those services using EMT that constitute payments, by incorporating or referencing the PSD3 and PSR standards within MiCAR in areas such as consumer protection, payment security, the calculation of own funds and the reporting of fraud, adapting them to the technical specificities of distributed ledger technology services. Providers that currently obtain a PSD2 authorisation to operate with EMT must anticipate that authorisation could entail materially stricter obligations once PSD3 and PSR comes into force.

First authorisations for EMT payments in Spain

On 29 June, the first CASP announced that it had obtained authorisation from the Bank of Spain: the first authorisation granted to a Spanish platform to provide EMT-based payment services. A few days later, a second CASP announced that it had received an equivalent authorisation. These authorisations do not make the providers EMT issuers, nor do they constitute a second MiCAR licence: they are authorisations to provide certain payment services using EMT, complementary to the MiCAR authorisation granted by the CNMV.

Osborne Clarke comment

The end of grandfathering marks the definitive transition to a European regime of prudential authorisation and ongoing supervision. 

Businesses using EMTs should analyse their flows specifically to determine whether a payment service subject to PSD2 exists and whether additional authorisation is required. A MiCAR licence is necessary, but may not be sufficient to cover the entire business model. Similarly, operators should monitor developments in the PSD3 and PSR legislative proposal in case the standards required under MiCAR are eventually extended to EMT services that constitute payments.

* This article is current as of the date of its publication and does not necessarily reflect the present state of the law or relevant regulation.

Interested in hearing more from Osborne Clarke?