Skip to content
ONLINE
--:--:-- UTC
Writing
5 min read5 sources

Crypto supervision after the licensing rush

MiCA's transitional periods end by 1 July 2026 and the GENIUS Act has made stablecoin issuers enforcement chokepoints. The licence was the easy part. Supervisors now want evidence that controls actually work.

Shuja Abrar · Blockchain Consultant & Engineer

  • regtech
  • mica
  • stablecoins
  • travel rule
  • digital asset compliance
On this page
  1. 01The licence was the easy part
  2. 02The Travel Rule is still uneven
  3. 03Stablecoins changed the supervision question
  4. 04Where newer regimes can skip ahead
  5. 05What firms should do before July
  6. Sources (5)

Two dates now sit at the top of most digital asset compliance calendars. In December, ESMA reminded the market that the transitional periods under MiCA end, at the latest, on 1 July 2026, and said it expects crypto-asset service providers that are not yet authorised to have orderly wind-down plans ready. In the United States, the GENIUS Act, signed on 18 July 2025, created the first federal framework for payment stablecoins and started a clock on the regulations that will implement it.

Both point in the same direction. The period in which the main question was whether a firm could get licensed is ending. What replaces it is supervision, and supervision asks a harder question: can the firm show that its controls work, with evidence, on demand?

01The licence was the easy part

MiCA gave the EU a single authorisation regime for crypto-asset service providers, with a passport across member states. The transition into it was anything but uniform. Each member state chose how long firms operating under national rules could continue without MiCA authorisation, and those choices ranged from a few months to the full eighteen. For more than a year the same service could be authorised in one country, grandfathered in a second and unlawful in a third. ESMA's interim register became the only reliable way to tell which was which, and ESMA itself has told investors to check it.

Authorisation is a point-in-time judgement on documents: a programme of operations, governance arrangements, policies. Supervision is continuous. Once a firm is authorised, supervisors look at how client assets are actually safeguarded, how complaints and conflicts are actually handled, and how anti-money laundering obligations are actually met, including the Travel Rule, which has applied to crypto-asset transfers in the EU since 30 December 2024 under the recast Transfer of Funds Regulation.

The practical difference is that a policy document no longer settles anything. A supervisor will ask for a sample of transfers and check whether the originator and beneficiary data was really sent and received, what happened to transfers where it was missing, and how long the exceptions took to resolve.

02The Travel Rule is still uneven

The FATF's sixth targeted update on virtual assets, published in June 2025, found that 85 of 117 surveyed jurisdictions had passed legislation implementing the Travel Rule, up from 65 a year earlier. That is progress, but it still leaves a large part of the world without the rule in force, and it leaves every compliant firm with the same operational question: what do you do with a transfer to or from a counterparty that cannot send or receive the data?

The answer has to be designed, not improvised. It covers counterparty due diligence on other service providers, the treatment of transfers to and from self-hosted wallets, the choice among competing messaging protocols that do not always interoperate, and a clear rule for when a transfer is held, returned or allowed with enhanced monitoring. The FATF also flagged the growing use of stablecoins by illicit actors, including North Korea, and the risks from decentralised arrangements that fall outside any one supervisor's reach.

03Stablecoins changed the supervision question

Chainalysis' 2026 report, published last month, estimates that illicit addresses received at least $154 billion in 2025, driven heavily by sanctioned entities, and that stablecoins accounted for 84% of illicit transaction volume. Illicit activity was still below 1% of total on-chain volume, which is worth repeating whenever the headline figure is quoted without it.

The concentration in stablecoins changes where supervision bites. A dollar stablecoin has an issuer, and the issuer can freeze. The GENIUS Act builds on this. Permitted issuers are treated as financial institutions under the Bank Secrecy Act, must hold reserves backing the coins one to one in cash, deposits and short-dated Treasuries, must publish the composition of those reserves monthly, and must have the technical ability to block, freeze or reject transactions when lawfully ordered.

For a supervisor, the object of scrutiny shifts from the token to the issuer's operations. How quickly does the issuer act on a lawful order? Who approves a freeze? How are false positives unwound? Is the screening that feeds those decisions tuned, tested and documented? These are questions about process and evidence, not about blockchain design.

04Where newer regimes can skip ahead

Jurisdictions building frameworks now have the advantage of watching others make mistakes. Pakistan, for example, established a Virtual Assets Regulatory Authority by ordinance in July 2025 to license and supervise service providers in line with FATF standards. A regulator in that position does not need to copy MiCA's text. It needs to copy the controls that turned out to matter and design supervision around data from the start.

That means requiring licensees to report in machine-readable formats rather than PDFs, giving the supervisor its own on-chain analytics capability rather than relying on firms' self-reporting, making the Travel Rule a condition of licensing from day one rather than a later add-on, and setting explicit expectations for how blockchain analytics vendors are selected, tuned and validated. A newer regime that starts this way will be easier to supervise than an older one that tries to retrofit it.

05What firms should do before July

Map every service you provide against its authorisation status in every member state where you have clients, and treat anything that relies on a transitional period as a deadline rather than a status. Test the wind-down plan ESMA expects instead of simply writing it: can you actually return client assets in an orderly way within the time the plan assumes?

Build evidence of control effectiveness now. Sample your own Travel Rule completeness, measure how long screening alerts take to close and how often they are escalated, and rehearse a freeze from lawful order to executed block, with timestamps.

Treat blockchain analytics as a model with its own risk. Vendor labels, risk scores and thresholds should be documented, tested against known cases and reviewed when they change. A supervisor who asks why a transfer was allowed will not accept that the tool scored it low without knowing why.

Finally, report on all of this to the board in the same terms a supervisor will use. The firms that come through the next two years comfortably will not be the ones with the longest policies. They will be the ones that can show, quickly and with data, that their policies are what actually happens.

All writing