Team
Author
Isabella Rivera
For Reading
11 minutes
Updated
27-07-2026
A magnifying glass checking a crypto exchange entry in an authorisation register

How to Check Whether a Crypto Exchange Is MiCA-Licensed in 2026

A “MiCA licensed” badge is not enough. The reliable check is to match the company serving your account with an active entry in the official EU register, then confirm that its authorisation covers the service you intend to use.

This guide shows how to do that, what to look for, and how the process works in practice using J2TX as an example. It reflects the regulatory position on 27 July 2026 and is general information, not legal advice.

Why This Matters After 1 July 2026

MiCA—the EU Markets in Crypto-Assets Regulation—has applied in full since 30 December 2024. Some providers that were already operating under national law could temporarily continue under a “grandfathering” regime while applying for MiCA authorisation. That transition ended across the EU on 1 July 2026.

After that date, a company generally needs a MiCA authorisation or a qualifying Article 60 notification to provide regulated crypto-asset services in the EU. A pending application, an old national registration, or a claim that the company is “in the process” is not the same as authorisation.

In its June 2026 statement on the end of the transition, ESMA said unauthorised providers must stop onboarding and marketing to EU clients and limit activity to what is necessary for an orderly exit.

How to Check a Provider in 60 Seconds

1. Open the official ESMA MiCA page

Go to ESMA’s Markets in Crypto-Assets Regulation page and find Interim MiCA Register. Use the file labelled Crypto-asset service providers—not the separate white-paper, token-issuer, or non-compliant-entity files.

ESMA currently publishes the register as a downloadable CSV. Open it in a spreadsheet application so you can search and filter the records.

Start with the brand name. If there is no exact match, find the company name in the platform’s terms, privacy notice, account statement, or footer and search that legal entity instead.

For example, a customer may know a platform as “Example Exchange,” while the EU account agreement names “Example Digital Assets Europe S.A.” The second name is the one likely to appear in the register.

3. Match the country and regulator

Check the provider’s home Member State and the competent authority that authorised it. These details should agree with the regulatory disclosure on the provider’s website.

A similar company name in a different country is not enough. Large groups often use several subsidiaries, and an authorisation held by one entity does not automatically cover accounts contracted with another.

4. Check the authorisation date and withdrawal information

Confirm the authorisation or notification date. Also check whether the record contains an effective withdrawal date. ESMA keeps withdrawn authorisations in the file, so appearing in a search result does not by itself prove the authorisation is still active.

5. Read the permitted services

Review the service fields rather than stopping at the company name. MiCA distinguishes between services such as:

Finally, check the national regulator’s own register. ESMA says its file is updated weekly, so a national entry may contain newer information.

Brand-versus-entity confusion is one of the main reasons people conclude that a platform is missing.

The name on an app icon or website header may be a trading name used by a corporate group. Your actual service provider should be identified in the terms you accepted, the privacy notice, transaction receipts, or account documentation. That entity may have a country suffix or a completely different legal name.

Use this three-way match:

  1. the legal entity named in your account agreement;
  2. the legal entity and approved website shown in the regulator’s record; and
  3. the legal entity in ESMA’s CASP file.

If only the brand matches, keep checking. Do not assume that another group company’s licence covers your account.

Being Listed Does Not Necessarily Mean Every Product Is Covered

The ESMA file is a register of authorised crypto-asset service providers, not a universal approval mark for every token, feature, yield product, or group company.

An entry must therefore be read together with its service scope. A provider authorised for exchange and transfer services is not automatically authorised to operate a trading platform or provide portfolio management. Products may also fall under another EU regime or outside MiCA’s scope.

The joint European Supervisory Authorities specifically advise consumers to check which services a firm is allowed to provide. Their warning on crypto-assets also stresses that MiCA protection is more limited than protection for many traditional financial products.

What to Do If the Provider Is Missing

Do not rely on one unsuccessful brand search. Work through these checks:

  1. Confirm the exact contracting entity. Find it in the terms, privacy notice, account statement, or support documentation.
  2. Search spelling variants and the LEI. A Legal Entity Identifier, when available, is more precise than a brand.
  3. Check the national register. Use the competent authority named by the provider. National records can be updated before ESMA’s weekly file.
  4. Ask support for evidence. Request the legal entity name, home regulator, MiCA authorisation or Article 60 notification basis, authorisation number, and a link to the regulator’s record.
  5. Do not treat an old VASP registration as a MiCA licence. A national AML registration used during the transition did not provide MiCA authorisation or MiCA protections.
  6. Clarify withdrawals now. Check whether withdrawals are available, which networks are supported, what limits apply, and whether you need to complete any account checks.
  7. Consider an authorised CASP or self-custody. If the provider cannot demonstrate current authorisation, assess moving to a verified provider or a self-hosted wallet. Self-custody removes provider-custody risk but makes you responsible for keys, backups, networks, and transaction accuracy.

ESMA tells clients of unauthorised providers to act promptly, including by transferring assets to an authorised CASP or a self-hosted wallet where appropriate. Contact the provider first if you encounter withdrawal difficulties, save your account records, and never share a seed phrase with “support.”

What MiCA Protects—and What It Does Not

MiCA imposes rules on authorised providers, including governance, prudential safeguards, clear and non-misleading information, complaints handling, conflicts of interest, and orderly wind-down planning.

For custody, MiCA requires client crypto-assets to be identified and segregated from the provider’s own holdings. The regulation also requires procedures for returning assets and makes the custodian liable for losses caused by incidents attributable to it, subject to the rules and limits in Article 75. You can read these requirements in the official MiCA text.

MiCA does not:

Crypto-assets generally do not benefit from bank deposit-guarantee or investor-compensation schemes. Authorisation materially improves the regulatory framework around a provider, but it is not a guarantee against loss.

Worked Example: J2TX

Here is what a user can verify, rather than relying on a “MiCA licensed” banner:

FieldOfficial record
Legal entityJ2TX Ltd
Home Member StateCyprus
Competent authorityCyprus Securities and Exchange Commission (CySEC)
Licence numberCASP006/22 (sometimes shortened to 006/22)
MiCA register date16 March 2026
LEI213800186TP6OZSHUV17
Approved domainwww.j2tx.com

CySEC lists J2TX Ltd in its MiCAR – CASPs → Authorised (Article 63) section. The current J2TX record on CySEC’s website authorises these eight services:

To reproduce the check yourself:

  1. Open ESMA’s official MiCA page.
  2. Download Crypto-asset service providers.
  3. Search for J2TX Ltd or the LEI 213800186TP6OZSHUV17.
  4. Match Cyprus, CySEC, the authorised services, approved domain, and date.
  5. Open the CySEC record and confirm that it remains in the Article 63 authorised section.

The important evidence is the current entry, the legal entity, the regulator, and the service scope—not the design of a licence badge or the year-like suffix in an authorisation number.

FAQ

Is a VASP registration the same as a MiCA licence?

No. A VASP registration was a national registration, commonly focused on anti-money-laundering and counter-terrorist-financing obligations. It did not make the provider MiCA-authorised. After the transition, verify the entity in ESMA’s authorised CASP register or confirm that a qualifying financial entity has made the required Article 60 notification.

Can one MiCA licence cover the whole EU?

Yes, a MiCA authorisation can be used across the EU through the passporting process. The provider tells its home regulator which Member States and services it intends to cover under Article 65. Passporting does not expand the licence: only the authorised services are covered.

What if I cannot find the brand name?

Find the legal entity in your account terms, privacy notice, statement, or transaction confirmation. Search that name and, if available, its LEI. Then match the approved domain, home country, regulator, and service scope.

Does MiCA protect my crypto if a company fails?

MiCA requires custodians to segregate client assets from their own estate and maintain return procedures. That is an important protection, including in insolvency, but it is not a deposit guarantee. Recovery can still depend on the custody arrangement, the facts of the failure, and applicable insolvency law.

Is USDT banned in Europe?

MiCA does not contain a token-specific sentence that “bans USDT.” It sets rules for stablecoins, including e-money tokens that reference one official currency. ESMA required CASPs to restrict trading and acquisition services involving non-MiCA-compliant stablecoins, while noting that mere custody and transfer can remain possible. Availability therefore depends on the token’s regulatory status and the service being offered. See ESMA’s stablecoin guidance.

Can a non-EU exchange still serve EU customers?

Generally, it cannot actively offer or solicit MiCA-regulated services to EU clients without the required EU authorisation. MiCA has a narrow reverse-solicitation exception when a service is provided strictly at the client’s own exclusive initiative, but ESMA says this exception must be interpreted restrictively and cannot be used to bypass authorisation.

How often is the ESMA register updated?

ESMA says the interim register is published at weekly intervals. Information reported by a national authority may therefore appear in that authority’s register before it reaches the ESMA file. For a high-stakes decision, check both and save the date of your search.

Keep Reading