The Dutch Authority for the Financial Markets
|
| |
|
|
|
|
The Markets in Crypto-Assets Regulation (MiCAR) has come into effect on December 30, 2024. With this newsletter, the AFM wants to inform the sector about important news and developments regarding MiCAR supervision. Want to subscribe to the AFM MiCAR newsletter? |
|
|
|
|
|
MiCAR Transitional Period Ended |
The transitional period officially concluded across the EU on 1 July 2026. CASPs that have not obtained a MiCAR authorisation are no longer permitted to provide crypto-asset services within the EU. ESMA calls on unauthorised crypto-asset service providers to wind down orderly, while also safeguarding clients’ interests, as all MiCAR transitional periods have ended in the EU. Unauthorised CASPs are expected to stop onboarding new clients, cease marketing and solicitation, and limit services to those necessary for clients to transfer assets or close positions, while continuing to safeguard client assets and comply with AML/CFT obligations. Where clients are transferred to a MiCAR-authorised CASP, the onboarding CASP should carry out all necessary onboarding procedures, including customer due diligence and any other AML/CFT checks required under the applicable legal framework. AMLA also informs about potential ML/TF risks arising from the end of the MiCAR transitional period along with possible mitigation measures. |
| |
| MiCAR is fully and directly applicable across all EU Member States. Clients of unauthorised CASPs, whether EU or non-EU entities, do not benefit from MiCAR safeguards, including protections for client assets. Clients using crypto-asset services in the EU are invited to verify whether their service provider is authorised under MiCAR in the ESMA Register or the AFM crypto register and act promptly where this is not the case, including by transferring their crypto-assets to an authorised CASP, where one is identified, or to a self-hosted wallet. Clients experiencing difficulties should contact their service provider in the first instance. We also note that clients of unauthorised service providers may be approached by various CASPs seeking to attract them as customers, sometimes by offering incentives or benefits that may appear particularly attractive. Consumers are encouraged to assess such offers carefully and critically, paying close attention to the applicable terms and conditions before making any decisions. They should also remain vigilant for scams and false claims of MiCAR authorisation. |
|
|
|
|
|
Regulatory Checks for Client Onboarding |
The AFM reminds authorised CASPs that, where they are onboarding clients transferred under winding-down plans implemented by unauthorised service providers, they remain responsible for carrying out all applicable regulatory checks prior to establishing a business relationship, including those required under anti-money laundering and counter-terrorist financing legislation. |
| |
Cooperation with Unauthorised Third Parties |
Authorised CASPs should carefully assess whether EU clients may be exposed to unauthorised third parties through existing business relationships or operational arrangements. Such exposures may adversely affect the protection of clients’ rights and interests. Authorised CASPs are therefore encouraged to review the regulatory status of business partners, outsourcing providers, liquidity providers and other parties involved in the provision of crypto-asset services, and to consider the implications of any continued cooperation with unauthorised entities. CASPs should also exercise caution when considering new cooperation arrangements and client migration initiatives involving entities that do not hold a MiCAR authorisation. The AFM considers such arrangements to constitute a material change to a CASP’s authorised business model. Accordingly, CASPs should notify the AFM and provide supporting documentation, including the rationale, legal assessment and relevant contractual arrangements. |
|
|
|
|
|
New Business Models and Service Offerings |
The AFM reminds that CASPs considering the introduction of new business models, products, services, or other material changes to their existing activities, should ensure that these developments are supported by a thorough risk assessment prior to implementation. Such assessments should consider, among other things, operational, market, liquidity, conduct, outsourcing, ICT and compliance risks, as well as the potential impact on clients and the CASP’s control framework. CASPs remain responsible for ensuring that their governance, risk management, and operational arrangements remain adequate and effective as their business evolves. The AFM also reminds CASPs of the previously shared Good Practice for Notifications of Material Changes. |
| |
ESMA published a new set of Q&As, including a clarification that the perimeter of advice on crypto-assets under MiCA is broader than the perimeter of advice under MiFID II. In another Q&A, ESMA clarifies that where an issuer, in the context of the primary issuance of its token, sends the issued crypto-assets to the wallet/account of the persons having purchased them, they are not conducting transfer services or custody services on behalf of another person. ESMA also provided guidance on crypto-asset lending services offered by CASPs, clarifying that adequate collateral should be required and that fees should be fair, proportionate, and reflective of operational cost. The AFM expects CASPs to take note of and follow ESMA’s Q&As, making any necessary adjustments where required. |
|
|
|
|
|
Consultation on MiCAR Review |
On 30 May 2026, the European Commission (EC) launched the targeted consultation on the review of MiCAR. This consultation is intended for a more specialised audience, such as digital assets industry representatives (CASPs, crypto-asset issuers) and public authorities (e.g. NCAs, central banks, ministries of finance). The targeted consultation is meant to help the EC put together the report on MiCAR application and the latest developments in crypto-asset markets. The deadline to submit responses is 30 September 2026. In parallel with the targeted consultation, the EC has also launched a broader public consultation aimed at a general audience, including consumers. |
| |
ESMA Launches Custody Resilience CSA |
ESMA launches a Common Supervisory Action (CSA) focusing on the digital operational resilience of CASPs, with a specific emphasis on custody services. The CSA will assess the maturity of CASPs’ digital operational resilience frameworks in relation to custody activities. It will focus on risks inherent to DLT, including governance arrangements, key and storage management, transaction controls, incident detection and response, smart contract risks, and dependencies on third-party providers. The exercise will run from the second half of 2026 to the first half of 2027. The AFM takes part in the CSA. |
|
|
|
| |
|
|
Frontier AI: New Cybersecurity Reality |
Recent developments in frontier AI models such as Anthropic’s Mythos demonstrate how quickly the cybersecurity landscape is evolving. In testing environments, some of these models have shown the ability to identify vulnerabilities, chain multiple weaknesses, and execute full penetration testing workflows at a scale and speed not previously seen. Some industry assessments suggest that AI-assisted analysis conducted over several weeks can deliver results comparable to months of traditional testing by an experienced security team. For CASPs and other financial institutions, the implications are clear: the window between vulnerability discovery and exploitation is shrinking. While these capabilities can strengthen defensive security operations, they may also provide thread actors with new tools to conduct cyberattacks. Organizations should therefore prioritise effective patch management, robust monitoring capabilities and exploration of responsible AI-use. |
|
|
|
|
|
The AFM is committed to promoting fair and transparent financial markets. As an independent market conduct authority, we contribute to a sustainable financial system and prosperity in the Netherlands.
|
| |
|
|
|
|
|