Missed the MiCA Licensing Deadline? What Now for Crypto Businesses in Greece

Missed the MiCA Licensing Deadline? What Now for Crypto Businesses in Greece

The transitional period has closed. For crypto-asset businesses operating in or from Greece, MiCA is no longer a horizon to plan for. It is the operating reality, and the questions that matter have changed.

The regulation of crypto-assets in Europe has moved decisively from principle to practice. Regulation (EU) 2023/1114 on Markets in Crypto-Assets, universally known as MiCA, created the first harmonised, pan-European rulebook for a market that had, until recently, been governed by a patchwork of divergent national regimes. In Greece, that framework was given domestic force by Law 5193/2025.

With the transitional window for legacy operators now expired, the question is no longer whether to become authorised, but what happens to a firm that missed it. This article sets out where the law stands today: the architecture of MiCA, its transposition into Greek law, the obligations that now bind service providers, the enforcement machinery, and what a firm without a licence can, and cannot, still do.

The architecture: a single rulebook built on a taxonomy of tokens

MiCA’s central achievement is classification. Rather than regulating “crypto” as an undifferentiated whole, it sorts crypto-assets into categories and attaches obligations to each. Understanding which category an asset falls into is the first analytical step in almost every matter.

Asset-referenced tokens (ARTs) seek to maintain a stable value by reference to a basket of assets or currencies, and carry the most demanding prudential and reserve requirements. E-money tokens (EMTs) reference a single official currency and are regulated in close alignment with the e-money regime. A residual category of other crypto-assets captures utility tokens and comparable instruments under lighter, disclosure-based rules.

Equally important is what MiCA excludes. Crypto-assets that qualify as financial instruments remain governed by MiFID II; deposits and insurance products remain within their existing regimes; and unique, non-fungible tokens fall outside the core framework. Correct characterisation is decisive, because it determines which regulator, which rulebook and which liabilities apply. A token marketed as a “utility” asset that in substance confers investment rights may be a financial instrument, with all the consequences that follow.

The Greek transposition: Law 5193/2025 and the split of authority

As a Regulation, MiCA is directly applicable in Greece without transposition. What Law 5193/2025 does, enacted in April 2025 as part of a broader capital-markets reform, is supply the domestic scaffolding the Regulation leaves to Member States: designating competent authorities, defining their powers, and establishing the sanctions for infringement.

The supervisory architecture is split along functional lines. The Hellenic Capital Market Commission (HCMC) is the competent authority for the authorisation and ongoing supervision of Crypto-Asset Service Providers (CASPs) and for conduct of business. The Bank of Greece holds prudential responsibility over issuers of asset-referenced and e-money tokens, and coordinates with the HCMC where crypto activity intersects with the banking and payments system.

By its Decision 8/1059/30.07.2025, the HCMC established the procedure for CASP authorisation, operationalising the standard forms published at EU level under Implementing Regulation (EU) 2025/306. The framework provides for acknowledgement of receipt within five business days, a completeness assessment within twenty-five, and a final decision within forty business days of a complete file being accepted. Timelines that reward a well-prepared dossier and penalise an incomplete one.

The point most firms get wrong: when grandfathering actually ended

Article 143(3) of MiCA permitted firms lawfully providing crypto-asset services before 30 December 2024 to continue operating under prior national arrangements for a limited transitional, or “grandfathering,” period while pursuing authorisation. Crucially, the length of that period was a national choice, capped at an outer limit of 1 July 2026.

Greece did not adopt the maximum window. According to ESMA’s published list of grandfathering periods under Article 143(3), Greece elected a twelve-month transitional period, which closed on 30 December 2025, alongside Germany and Ireland. Firms that assumed the July 2026 EU outer limit applied to them in Greece have been operating on a mistaken premise since the turn of the year.

The legal consequence is stark. Article 59 of MiCA prohibits the provision of crypto-asset services in the Union without CASP authorisation; the transitional rule merely deferred that prohibition, and it now applies in full. A pending application is not authorisation. Only an authorisation granted under Article 63 provides a lawful basis to serve clients.

What a firm without a licence can still do

For a firm in Greece that lacks authorisation today, permissible activity is confined to an orderly wind-down. It may not onboard new clients, open new accounts, or market its services. Client crypto-assets must be returned to clients or transferred to a licensed party, and custody is tolerated only to the limited extent, and for the limited time, necessary to complete that process.

Where no realistic path to authorisation exists, the cleaner outcome is frequently a negotiated transfer of the client base and associated assets to an already-licensed provider. Such an arrangement must itself be structured with care as to asset segregation, data protection and client communication. Going silent with the regulator is, in every case, the worst available option. The better posture is to speak to the HCMC about how it wants the wind-down handled, and to move early.

What changes once you are licensed

Authorisation is a starting point, not a finish line. Supervisors do not stop watching once a licence is granted, and in the months since the regime took full effect, several licensed firms across the EU have already faced supervisory action over anti-money-laundering failures.

The continuing obligations are demanding. Governance and fit-and-proper standards apply to qualifying shareholders, directors and key executives, who are assessed for suitability and integrity. Prudential and own-funds requirements, drafted with bank-like structures in mind, must be met and their application to crypto-native businesses carefully documented. Client crypto-assets must be strictly segregated from a firm’s own, an operational and sometimes on-chain discipline with real cost implications. And CASPs remain subject to the full weight of AML and counter-terrorist-financing law: risk-based customer due diligence, transaction monitoring, sanctions screening, suspicious-activity reporting to the Hellenic financial-intelligence authority, and compliance with the Transfer of Funds Regulation, the Travel Rule. In parallel, the Digital Operational Resilience Act (DORA) imposes ICT risk-management and incident-reporting duties.

Three areas are consistently under-resourced. Transaction monitoring, because illicit typologies evolve faster than static rules. Counterparty and on-chain risk, including exposure to high-risk providers, unhosted wallets and cross-chain bridges. And governance, meaning the ability to evidence why a decision was taken, and how alerts are calibrated over time, to a supervisor after the fact. A firm that historically ran compliance through a single officer will, in practice, need a properly resourced function.

Investor protection and market integrity

MiCA places investor protection at the centre of the framework, and Law 5193/2025 reinforces it. Issuers offering crypto-assets to the public must generally publish a white paper, a structured information document comparable in function to a prospectus, setting out the issuer, the rights and risks attaching to the asset, and where relevant its redemption and reserve arrangements. Materially misleading white papers now carry civil and, in defined circumstances, criminal exposure. The regime also extends the market-abuse concepts familiar from securities law, prohibitions on insider dealing and market manipulation, into crypto-asset markets for the first time, and mandates the segregation of client funds against provider insolvency.

Supervision, sanctions and reverse solicitation

Law 5193/2025 equips the HCMC with broad enforcement powers: substantial administrative fines, suspension or withdrawal of authorisation, and public disclosure of infringements. Article 107 introduces sanctions for the professional provision of services without a licence, and the law protects investors and whistleblowers.

Two features of the current environment deserve attention. Enforcement across the EU is uneven: some regulators move quickly, while others have left applicants without an answer for months. This inconsistency has real consequences for firms passporting cross-border, and it is not a basis on which to relax domestic compliance. Second, ESMA now maintains a public register of non-compliant entities, signalling a shift from reactive enforcement toward proactive market transparency, sharpened by the fact that on-chain activity is visible to supervisors in near real-time.

A specific caution on reverse solicitation. Firms outside the EU sometimes hope to keep serving Greek and EU clients on the basis that the client approached them, unprompted. The exemption is genuinely narrow and available only in exceptional circumstances. Any local marketing, or the presence of staff suggesting the firm solicited EU clients, will defeat it. It should never be treated as a substitute for authorisation, and reliance on it warrants specific legal advice beforehand, not after.

The wider regulatory perimeter

MiCA does not operate in isolation. Firms must simultaneously account for DORA’s operational-resilience regime; the AML package and the new EU Anti-Money Laundering Authority (AMLA); the DAC8 directive and the Crypto-Asset Reporting Framework for tax transparency, which in Greece align with quarterly transaction reporting to the tax authority; the tension between the Travel Rule and data protection under the GDPR; and, increasingly, the EU AI Act where firms deploy automated decision-making. Each layer adds cost and complexity. The prevailing direction anticipates a gradual convergence of crypto activity with the standards of traditional finance, not a relaxation of them.

The bottom line

Grandfathering in Greece closed on 30 December 2025. Enforcement is uneven but tightening, and licensing is achievable but operationally demanding, even for firms with nothing to hide. The advice converges on a few points. Determine honestly whether your activity is in scope and what your authorisation status is. Resource compliance as an operating function, not a nominal appointment. Take legal and regulatory advice early, because the cost of correct structuring at the outset is invariably lower than the cost of remediation under supervision. And whether you are pursuing authorisation or managing a wind-down, engage the regulator rather than going quiet.

For firms with no realistic path to a licence, arranging a clean transfer of clients and assets to a licensed partner is a far better outcome than drifting into non-compliance.

How we can help

The Digital Assets, Fintech & Regulatory practice at Tsamichas Law Firm advises founders, boards, issuers and investors across the full MiCA lifecycle in Greece and the EU: scoping and asset classification, CASP authorisation before the HCMC, white-paper review, governance and AML/CFT frameworks, DORA readiness, cross-border passporting, and the structuring of client-base transfers and orderly wind-downs. Whether you are pursuing authorisation, assessing your current status, or planning entry into the Greek market as an EU gateway, we help you navigate the framework with confidence.

Share this post

Βook your appointment.

We succeed together fighting for Right and Justice.

Call Us

+30 210 363 8590