Skip to content
Blueprints / BP-16 · CASPs, neobanks & brokers

Migrating Off a Lapsed VASP Registration Onto a Licensed CASP Rail

Your national registration has lapsed under MiCA - move the clients, the balances and the Travel Rule wiring onto an authorised provider's rail, keep your brand, and keep serving EU clients.

Maturity
Emerging
Model
VASP cliff
Proven stack
BitGo Europe GmbH · Zodia Custody Europe · Boerse Stuttgart Digital
Last verified
August 2026

Reviewed by Rado Patus, Offer Owner at Protofire

Trusted across 60+ networks and 95+ protocols
325 of 3,000+

authorised CASPs on the ESMA register at 12 Aug 2026, against more than 3,000 pre-MiCA registered VASPs in Europe.

209 crypto-native and 116 from traditional finance. Estimates put 75-80% of the old population out of registration. The transitional period ended 1 July 2026 with no extension.

01. The opportunity

A firm holds a national crypto registration, a client base and a working product, and the registration stops being a basis for serving EU clients. Three options remain: obtain its own authorisation, stop, or provide the same service under an authorised provider's authorisation. This pattern is the third. Clients are re-onboarded to an authorised provider, their balances are migrated into segregated sub-accounts on that provider's infrastructure, the transfer-information wiring is re-pointed, and the firm keeps the customer relationship and the front end while the regulated act belongs to the provider.

The pressure behind it is dated and specific. MiCA's transitional period ended on 1 July 2026 with no extension, and ESMA's public statement of 23 June 2026 told unauthorised providers to stop onboarding EU clients immediately, cease marketing, and have wind-down plans already implemented. A large majority of the pre-MiCA population is expected to lose registration, and national regimes closed ahead of the cliff - Lithuania's on 31 December 2025, Poland's on 30 June 2026. For a firm with an EU client base worth keeping, this is a regulated way to go on serving those clients on an authorised provider's rail while keeping its own brand and front end.

02. The regulatory position

MiCA. The transitional period ended 1 July 2026 with no extension, and ESMA's public statement of 23 June 2026 required unauthorised providers to stop onboarding EU clients immediately, cease marketing, and have wind-down plans already implemented, stating that a plan on paper would not suffice. What matters under MiCA is who provides the service: MiCA regulates the person providing it, so if an authorised provider genuinely onboards the clients, holds their assets and owes them the duties, a firm that introduces clients and operates a front end is not itself providing a crypto-asset service. Whether that holds on the facts is unsettled, undocumented by any supervisor, and needs an opinion per jurisdiction. A white label that leaves the firm in the service position is still unauthorised activity. Art. 60's notification route does not help: it is for entities already authorised under other financial-services regimes, and a lapsed national crypto registration does not qualify. TFR 2023/1113 obligations move with the service and the wiring must be re-pointed; national AML registration, wind-down and consumer rules survive independently; DORA binds the provider and probably not the migrating firm.

03. Who's already done this

Nobody has said so publicly.

What is documented is the other half. The rails exist, they are authorised, and one of them is marketed at exactly this situation:

  • BitGo Europe GmbH holds a BaFin crypto-asset service provider authorisation dated 12 May 2025, extended in September 2025 to add regulated trading, passported across 30 EEA states. On 17 June 2026 it launched a service for firms displaced by expiring national regimes: integrate the wallet system, clients are identified by BitGo, assets sit in segregated custody accounts, and you keep your brand and front end. No client of that service has been named.
  • Zodia Custody Europe holds a CSSF crypto-asset authorisation with EU passporting and, since June 2026, a CSSF payment institution licence covering e-money token custody and transfer. Its shareholders include Northern Trust, SBI Holdings, National Australia Bank and Emirates NBD. It publishes no product for displaced firms, so the option rests on what the licence permits rather than on an offer.

The one named client transfer of 2026 went the other way: MEXC announced on 12 August 2026 that it is exiting the Netherlands and referring its clients there to Kraken, which holds a Central Bank of Ireland MiCA authorisation from June 2025. That is the wind-down route, not this one - MEXC stops serving those clients rather than continuing to.

04. Does this fit you?

It fits a firm whose registration has lapsed, with an EU client base worth keeping, that can accept the regulated service becoming somebody else's, on their fee schedule and their risk appetite, and that has a brand and front end worth preserving.

It does not fit you if you already hold your own authorisation; you are the absorbing side. It does not fit if you are leaving the EU, in which case winding down is the honest answer. And it does not fit if you intend to keep holding client assets or issuing client instructions yourself, which is still unauthorised activity whatever it is called.

Two limits belong in view from the start. Identification cannot be inherited: every client re-onboards with the provider and some never will, so attrition is a certainty to forecast. And this route does not cure the past: activity since your registration lapsed is a separate exposure that belongs with counsel before anything is designed.

05. The stack, layer by layer

Most of these layers can be rented from a named vendor, and usually should be. The part that matters is the one layer you have to own yourself.

Yours

Client relationship, brand and front end

The clients, the interface they recognise, the firm's own historic records, and whatever national AML obligations survive the change. This is what the pattern exists to preserve, and it is also where the perimeter question concentrates: the more the front end behaves like the service, the harder the legal analysis becomes.

Rented

The authorisation, custody, execution and onboarding

An authorised provider onboards the clients under its own licence, holds their assets in segregated custody, and executes and transfers on their behalf. The regulated duties genuinely move. What no provider supplies is the client consent, the cutover reconciliation, or any opinion on whether the firm's continuing role is lawful.

BitGo Europe GmbHZodia Custody EuropeBoerse Stuttgart Digital
Ours

The migration itself, and the evidence it leaves behind (built and operated by Protofire)

The perimeter pack counsel opines on, a dated reconstruction of what was provided since the registration lapsed, the book profile, consent and its audit trail, sub-account mapping, transfer-information switchover with a live overlap, and a cutover reconciliation that survives a supervisor reading it a year later. No product exists for this layer; it is built.

Yours, never rentableRented from a named vendorBuilt and run by Protofire

06. Why this stack

The numbers behind the pressure are dated and specific. The ESMA register held 325 authorised providers on 12 August 2026 - 209 crypto-native, 116 from traditional finance - against more than 3,000 pre-MiCA registered firms in Europe, Poland alone accounting for over 1,400. Estimates put 75 to 80 per cent of the old population out of registration. Lithuania's regime closed on 31 December 2025, Poland's on 30 June 2026, and the transitional period ended on 1 July 2026 with no extension.

The build itself is well understood: an authorised rail, client re-onboarding, balance migration into segregated sub-accounts, transfer-information re-pointing, and a reconciliation across the cutover. Two parts carry the difficulty. The reconciliation layer has no vendor - no product reconciles a lapsing firm's ledger against a provider's sub-account structure, so it is built. And the legal characterisation is the harder one to settle: MiCA regulates the person providing the service, so what has to be established is whether an authorised provider genuinely provides it, or whether the firm still does under a different label.

Request the full blueprint

This is the short version. The full blueprint is a single document your counsel and board can read cold, and a third-party-risk function can lift wholesale. Leave your work email and your personal link arrives in your inbox.

What is inside
  • The regulatory position, stated article by article
  • Proven options at each layer, with the vendors that hold up
  • The risk table with a named owner for each risk
  • The division of labour: what is rented, built, and operated
  • The third-party-risk pack a DORA governance function can lift
  • The delivery path, step by step, with the monitoring and incident model

FAQ

Is it lawful under MiCA to keep serving EU clients on an authorised provider's rail after a VASP registration lapses?

It depends on identity rather than activity. MiCA regulates the person providing the service, so if an authorised provider genuinely onboards the clients, holds their assets and owes them the duties, a firm that introduces clients and operates a front end may not itself be providing a crypto-asset service. Whether that holds on the facts is unsettled, undocumented by any supervisor, and needs an opinion per jurisdiction. A white label that leaves the firm in the service position is unauthorised activity with extra steps.

What changed on 1 July 2026 for unauthorised crypto providers in the EU?

MiCA's transitional period ended on 1 July 2026 with no extension. ESMA's public statement of 23 June 2026 required unauthorised providers to stop onboarding EU clients immediately, cease marketing, and have wind-down plans already implemented, stating that a plan on paper would not suffice. At 12 August 2026 there were 325 authorised CASPs on the ESMA register against more than 3,000 pre-MiCA registered VASPs, with estimates putting 75 to 80 per cent of the old population out of registration.

In a VASP-cliff migration, what is rented and what has to be built?

The firm keeps its clients, brand, front end and historic records, which is what the pattern exists to preserve. It rents the regulated core from an authorised provider such as BitGo Europe, Zodia Custody Europe or Boerse Stuttgart Digital, which onboards the clients under its own licence, holds their assets in segregated custody, and executes and transfers on their behalf. No product exists for the migration itself, so it is built: the perimeter pack counsel opines on, client consent and its audit trail, sub-account mapping, the transfer-information switchover, and a cutover reconciliation a supervisor can read a year later.

Already evaluating this for your institution?

When you are ready, we scope a business case on your own numbers: the costed build, the controls, the SLA and the ROI your board needs to approve it. Or talk it through first.

Run this pattern in production, or tried to and stopped? .

Related readingMiCA & Travel-Rule compliance stackCrypto custody approachesManaged on-chain operations

Protofire 2026. All rights reserved

Message us on Telegram