MiCA authorisation is the administrative licence that every crypto-asset service provider needs in order to operate in Spain. It is granted by the Spanish securities regulator, the CNMV, under Regulation (EU) 2023/1114. Since 1 July 2026 only authorised entities may provide services.
The transitional period ended on 30 June 2026. Coverage has focused on investors and on checking whether their platform is still authorised. The other side of the change has received less attention. A provider that did not obtain authorisation cannot simply close down. It has specific obligations towards its clients, and the CNMV has set them out.
If you need a MiCA lawyer in Spain for your business, request a free initial assessment.
On 1 July 2026 the MiCA Regulation became fully applicable in Spain. From that date only crypto-asset service providers that have obtained authorisation may operate in the country. The transitional period available to entities already active ended on 30 June 2026.
The CNMV announced this in a statement of 15 June 2026. The notice was addressed to two different audiences. To investors, so that they could check whether their platform was authorised. And to providers themselves, to remind them what they must do if they do not make it in time.
The CNMV’s public register lists the providers authorised to operate in Spain, both Spanish entities and branches and foreign entities providing services here. Among the Spanish names are banks such as BBVA, CaixaBank, Kutxabank and Openbank, as well as Cecabank, Renta 4, Prosegur Custodia de Activos Digitales and crypto-native firms such as Criptan Trade and Bitcoinforme.
Any legal person providing crypto-asset services on a professional basis in Spain needs authorisation. The MiCA Regulation lists those services. They include custody, exchange for funds or for other crypto-assets, execution of orders, placing, advice and portfolio management.
Two nuances avoid common mistakes.
The CNMV register reflects both routes. That is why it lists Spanish companies alongside entities from Luxembourg, the Netherlands, Ireland or Germany that provide services here under a passport.
A provider that did not obtain authorisation before 30 June 2026 must have an effective migration plan for its clients. It is not a recommendation. The CNMV frames it as a duty and sets out its minimum content.
This is the point general coverage has missed. Ceasing the activity does not extinguish the obligations towards clients. On the contrary, it makes them concrete.
The plan must allow clients to recover their positions without being trapped. The CNMV sets out three elements.
There is an accepted alternative. The provider can agree with another authorised entity to transfer its client portfolio. That agreement must offer adequate protection and favourable terms. And each client decides whether to accept the transfer, because consent is individual and cannot be presumed.
Take a Spanish exchange and custody platform with 12,000 clients. It applied to the CNMV in 2025 and on 30 June 2026 its application was still pending, with no decision. Since 1 July it cannot provide services.
Its situation is not an ordinary closure. It must enable the withdrawal of crypto-assets to external addresses and the transfer of cash balances. It must inform affected clients in a way they can understand. It must keep its anti-money laundering controls running throughout the process, because mass withdrawals are precisely the moment of greatest exposure. And if it negotiates a transfer to an authorised competitor, it needs each client’s consent.
In crypto compliance projects, the recurring mistake lies in planning. The authorisation application gets all the attention and the fallback scenario is not prepared. When the decision does not arrive in time, the entity improvises its migration plan under regulatory pressure and with clients complaining.
The CNMV authorises and supervises crypto-asset service providers in Spain. The Bank of Spain supervises issuers of asset-referenced tokens and e-money tokens. That is the realm of stablecoins.
The distinction matters when choosing whom to deal with. An exchange and custody platform deals with the CNMV. An issuer of a token referenced to a currency deals with the Bank of Spain. A project that does both falls under both supervisors.
At European level, ESMA keeps the public register of providers authorised across the Union, under Article 109(5) of the MiCA Regulation. The CNMV refers to that register for cross-border checks. In addition to MiCA, an authorised provider must comply with the DORA Regulation, which we explain in our guide on DORA for crypto-asset service providers.
Providing crypto-asset services in Spain without authorisation since 1 July 2026 means carrying out a reserved activity without the required licence. The consequence is not limited to an administrative penalty.
The impact is felt on several fronts at once. Clients lose the protection offered by the MiCA Regulation, and the CNMV expressly warns of this. The contracts signed are open to challenge as to their validity. Banks and payment providers review the business relationship. And in any investment or sale process, the lack of authorisation shows up immediately in due diligence.
Does your entity work with crypto-assets and need to put its regulatory position in order? At Innovatech Legal we analyse how your business fits within MiCA. We also prepare the application to the CNMV and document contingency plans.
You can consult the CNMV’s official register of providers (in Spanish) and the text of the MiCA Regulation on EUR-Lex.
No. The transitional period ended on 30 June 2026. Since 1 July only providers that already hold authorisation may operate in Spain. A pending application does not allow you to provide services. The entity must activate its client migration plan while it waits for the CNMV’s decision.
It must allow clients to move the crypto-assets held in custody to other addresses and to transfer their funds to cash accounts. The whole process needs security measures and compliance with anti-money laundering rules. Alternatively, the entity can agree a transfer to another authorised provider, always with each client’s individual consent.
No. The MiCA Regulation provides for the European passport. An entity authorised in another Member State can provide services in Spain without obtaining a new CNMV authorisation. It must, however, complete the relevant notification procedure. The CNMV’s public register lists both Spanish entities and those operating here through this route.
Not as regards their issuance. The CNMV authorises and supervises crypto-asset service providers. The issuance of asset-referenced tokens and e-money tokens, which is where stablecoins fit, falls to the Bank of Spain. A project that issues a token and also provides services is subject to both supervisors.
Do you know whether your entity needs CNMV authorisation or can operate under the European passport? Request a free initial assessment and receive an analysis of your position, the gaps identified and a clear action plan.
Marta Suárez-Mansilla is Managing Partner of Innovatech Legal and a Spanish lawyer (abogada), Madrid Bar (ICAM), working in technology law. She completed Harvard Law School's Copyright course and BerkeleyX's Blockchain programme, and has advised technology companies for more than eight years.
