FIRMCY Insights

The same customers, fewer CASPs

Regulator commentary · all insights
The same customers, fewer CASPs

The firms leaving the market deserve more of your attention than the ones staying.

CySEC issued Circular C790 on 7 July 2026, six days after the MiCA transitional period ended on 1 July. Since that date, providing crypto-asset services in the EU requires authorisation as a MiCAR-compliant crypto-asset service provider. The circular relays an advisory note published by AMLA, the EU's Authority for Anti-Money Laundering and Countering the Financing of Terrorism, on the ML/TF risks arising as that transition completes.

Read the addressee list before deciding this is somebody else's circular. C790 goes to crypto-asset service providers, but also to CIFs, UCITS management companies and internally managed UCITS, AIFMs and internally managed AIFs, internally managed AIFLNPs, the companies whose sole purpose is managing them, and small AIFMs under Law 81(I)/2020.

CySEC expects significant structural change in the EU crypto-asset sector: unauthorised VASPs exit, and the customer relationships they held are either terminated or transferred to a smaller number of authorised CASPs. Fewer firms, and fewer places for those customers to go.

The risks split by which side of the line a firm sits on.

For unauthorised VASPs winding down, AMLA flags two. The first is weakened AML/CFT controls during the exit itself, because compressed timelines for ceasing activities may strain the framework at a critical juncture — particularly, the note says, for entities previously identified as having deficiencies. The mitigation, where national law provides for wind-down plans, is a structured and well-documented implementation of them, with governance, resources and enhanced monitoring maintained until all regulated activities have ceased. The second is concealment of illicit flows: abrupt exits can reduce transparency over asset flows and customer relationships, creating opportunities for concealment, the rapid movement of illicit funds, and sanctions evasion. Against that, keep customer due diligence information current and keep reporting suspicious transactions to the end of the process, not to the announcement of it.

For authorised CASPs receiving the migration, also two. Risk exposure can change suddenly, because business models and customer portfolios shift after authorisation decisions, producing materially different risk profiles, including a possible concentration of higher-risk customers among firms that continue or are newly authorised. And transaction monitoring capacity comes under pressure, since rapid inflows can strain systems and compliance resources. The answer in the circular is capacity and integration: monitoring systems able to handle increased volumes of crypto-asset transfers, scalable controls, adequate staffing, effective due diligence, and integration of incoming customer risk information.

One sentence in C790 is worth quoting to whoever proposes the shortcut. Customers of unauthorised VASPs should not be subject to blanket de-risking solely on the basis of their origin. They should be assessed individually under a risk-based approach, with enhanced due diligence where higher risks are identified.

CySEC also points to the FATF report Understanding and Mitigating the Risks of Off-shore VASPs, and expects regulated entities to identify and assess the risks arising from relationships, transactions or business activities involving unauthorised VASPs, then mitigate them. That expectation is not confined to crypto firms, and CySEC frames it as enhancing the risk-based approach under the Prevention and Suppression of Money Laundering Activities Law, L.188(I)/2007. If a client's counterparty or source of funds runs through a provider that has just left the EU market, that is a relationship you are expected to have assessed.

Not legal advice. Verify against the primary source before acting.

Sources

Published 16 August 2026 · Regulator commentary
Drafted with AI assistance. Reviewed, edited and approved before publication by a named person at Ioannou & Sharpe LLC, who takes editorial responsibility for its content. Approved by the firm's editorial reviewer.

Screen against the current lists in seconds

FIRMCY screens names against all of the lists above — plus a worldwide PEP database and adverse media — with fuzzy matching and an audit-ready report for every check. New organisations get 100 free credits, no card required.

Start screening free Free PEP & sanctions check FATF high-risk countries Weekly AML briefing Live on Telegram ↗
© 2026 Ioannou & Sharpe LLC · VAT CY60007091D · Griva Digeni, Limassol Center, Block B, 3rd Floor, Office 304, 3095 Limassol, Cyprus · [email protected]
Not legal advice. FIRMCY publishes this analysis for general informational purposes; verify against the primary sources before acting.