← Back to blog

MiCA and Crypto Payments in 2026: What European Businesses Need to Know

Crypto Payments in Europe 2026: The MiCA Shift — Cryptadium

We break down what MiCA means for European businesses in 2026 — CASP licensing, the ESMA register, EMT/ART stablecoin rules and the EU crypto Travel Rule.

The Markets in Crypto-Assets Regulation (MiCA) created a common framework for crypto-assets and crypto-asset service providers across the European Union. For online merchants, MiCA in 2026 is especially relevant: on 1 July 2026, the last remaining transitional arrangements expired. Since then, firms providing crypto-asset services to EU clients can no longer rely on national grandfathering regimes.

For merchants, this does not mean that every company accepting digital assets needs its own MiCA licence. The practical question is who provides the regulated crypto service, which asset is used and under what authorisation the provider operates. That distinction matters for e-commerce, SaaS, fintech and other businesses using crypto payment infrastructure.

What changed under MiCA in 2026

MiCA is Regulation (EU) 2023/1114. It establishes uniform rules for certain crypto-assets, their issuers and crypto-asset service providers. The regime was introduced in stages: rules for asset-referenced tokens and e-money tokens have applied since 30 June 2024, and the rest of the framework since 30 December 2024.

The key 2026 milestone was not the launch of MiCA itself, but the end of the transitional arrangements. Under Article 143(3), providers already operating under national law before 30 December 2024 could continue until 1 July 2026, or until they were granted or refused MiCA authorisation, whichever came first. Member States were also allowed to set shorter periods, and many did. ESMA made clear that firms operating only under a grandfathering regime were not authorised CASPs under MiCA.

What changed on 1 July 2026? The transition from national regimes to the EU authorisation framework is now complete: only providers holding MiCA authorisation may provide crypto-asset services in the EU. For a business choosing a crypto provider, regulatory status is now both easier to verify and more important to check before onboarding.

MiCA does not replace every national rule. Tax, accounting, consumer law, data protection and other obligations may still depend on the countries where the business and its customers operate.

Does MiCA apply when a business accepts crypto payments?

Accepting crypto as payment for your own goods or services does not, by itself, make a merchant a CASP. MiCA applies to crypto-asset services provided to clients on a professional basis, such as custody and administration, exchange, execution of orders and transfer services, as well as to public offers and admission to trading of certain crypto-assets.

For a merchant, the payment flow should be separated into roles. The buyer sends a crypto-asset. The merchant sells a product or service. A third-party provider may generate the payment request, monitor the blockchain, exchange the asset, transfer funds or provide custody. Some of those activities fall within the MiCA perimeter when they are performed professionally for clients.

This is why the phrase “MiCA-compliant payments” can be misleading without context. MiCA does not give merchants an EU-wide licence to accept cryptocurrency. The relevant question is which entity performs the regulated service and whether it is authorised to provide that service in the EU.

→ For the technical side of the payment flow, see “Understanding Crypto Payment Gateways: How They Work and Why Businesses Need Them”.

How to verify a crypto-asset service provider (CASP) under MiCA

A crypto-asset service provider, or CASP, is a legal person or other undertaking whose business is to provide one or more crypto-asset services to clients on a professional basis and that is allowed to do so under MiCA. CASP authorisation matters to merchants because payment infrastructure can include regulated activities even when the merchant itself is not a CASP.

Before connecting a provider, a business should check the exact legal entity, the Member State that granted authorisation and the services covered. A generic statement such as “MiCA ready” or “licensed in Europe” is not enough. What matters is whether the provider holds the required authorisation for the service being used.

The ESMA MiCA register is the main public verification tool at EU level. It covers authorised CASPs, issuers of asset-referenced and e-money tokens, crypto-asset white papers and a list of non-compliant entities, that is, firms identified as providing crypto-asset services without the necessary authorisation. For each CASP, the register shows the competent authority, the authorised services and the host Member States in which the provider intends to operate. National competent authorities, such as the CNMV in Spain, also publish their own registers.

For merchants, the due-diligence step is straightforward: find the provider in the official register, confirm that its authorised scope matches the service you intend to use, and make sure it does not appear on the list of non-compliant entities.

Regulatory status is only one part of vendor risk. Operational security, custody terms and fraud controls matter as well.

→ We cover those issues in “Fraudsters in Crypto Processing: How to Protect Your Business and Work Safely”.

Stablecoins under MiCA: what matters for business payments

Stablecoins are common in business payments because they reduce exposure to short-term price volatility. MiCA, however, does not use the term “stablecoin”. It classifies tokens by what they reference.

An e-money token (EMT) is a crypto-asset that aims to maintain a stable value by referencing the value of one official currency. An asset-referenced token (ART) is a crypto-asset that is not an EMT and aims to maintain a stable value by referencing another value or right, or a combination of them, which may include one or more official currencies. Tokens that meet neither definition fall into the category of other crypto-assets.

Under EU stablecoin regulation, the analysis therefore depends not on how widely a token is used, but on its classification, the issuer's status and the services performed by the provider. This also has practical consequences: EU providers may not offer to the public, or admit to trading, EMTs and ARTs whose issuers are not authorised under MiCA, so a stablecoin that is popular elsewhere may be restricted or unavailable through EU-authorised CASPs.

Stablecoin payments raise one more question: the interplay between MiCA and payment services rules. E-money tokens are treated as electronic money, so some services involving them, such as transfers or custody on behalf of clients, can also qualify as payment services under PSD2. Following EBA guidance published in June 2025, CASPs providing such services were expected to comply with PSD2 after a transitional period that ended on 1 March 2026, either by holding the relevant payment licence themselves or by working with an authorised payment service provider. When choosing a provider for EMT payments, a merchant should therefore check both its MiCA authorisation and, where relevant, its payment-services authorisation.

Price stability, depeg risk and treasury management are separate operational questions rather than the core subject of MiCA.

→ We cover those risks in “Crypto Processing in Volatile Markets: Business Protection Strategies”.

What European businesses should check before using crypto payment infrastructure

Before going live, a European business should map the payment flow and identify every party involved. The aim is not to turn the merchant into a regulatory specialist, but to make the model transparent enough to verify. A practical review should cover five points:

  1. Identify the actual service provider. Check the legal entity, not only the brand or website.
  2. Verify authorisation where MiCA requires it. Use the ESMA register and confirm the authorised service scope. For EMT transfers or custody, also check payment-services authorisation under PSD2.
  3. Define the service being used. Custody, exchange, transfers and merchant payment tools do not receive identical regulatory treatment.
  4. Identify the crypto-asset. If a stablecoin is involved, check whether it is an EMT or ART and whether its issuer is authorised under MiCA.
  5. Check additional rules. MiCA is not the entire EU crypto compliance framework. Depending on the transaction, AML obligations, sanctions requirements, the EU Transfer of Funds Regulation, tax reporting, accounting, consumer protection and data rules may also apply.

The last point is important: the EU crypto Travel Rule should not be described as “part of MiCA”. It comes from the recast Transfer of Funds Regulation (EU) 2023/1113, which operates alongside MiCA. Tax reporting is similarly separate: under DAC8, since 1 January 2026 CASPs have been collecting data on their EU clients' transactions, which they will report to tax authorities for the first time in 2027.

Once the legal and compliance model is clear, a company can assess the technical infrastructure it needs. Cryptadium provides B2B crypto-processing infrastructure for fintech and financial businesses, including API integration, payment automation, transaction monitoring and reporting tools.

Using a payment processor does not, by itself, settle a merchant's compliance obligations. Which rules apply depends on the entity, service, asset and jurisdiction involved. A stronger approach is to combine regulatory due diligence with clear contracts, transparent payment flows and auditable transaction records.

For European businesses, the main lesson is simple: MiCA does not create one rule for every crypto payment. In 2026, the key questions are who provides the crypto service, whether that provider is authorised, which asset is used and what other rules apply to the transaction.

This material is provided for informational purposes and does not constitute legal, tax or regulatory advice.