Skip to content
Regulation June 3, 2026 ·9 min read

July 1, 2026 is the day the European crypto map redraws itself

MiCA's transition period ends on July 1, and the practical consequence for a Ledger holder sending more than 1,000 € to a CASP is a verification flow nobody had to perform the day before. What 'at least one suitable technical means' actually requires.

TE

The Editors

Editorial desk

July 1, 2026 is the day the European crypto map redraws itself, and the day an ordinary Ledger holder discovers that moving 1,500 € of bitcoin to a French exchange is no longer a matter of pasting an address and waiting for confirmations

By the time the sun rises over Paris on that Wednesday, the transitional regime that has carried most European crypto-asset service providers through the past eighteen months will be gone, and every platform still serving EU clients will need a fresh stamp from a national competent authority, or it will be operating outside the law. CoinGeek's reading of the European Securities and Markets Authority position is unambiguous, quoting the regulator directly: "The MiCA transitional period will officially expire across the EU on 1 July 2026. After this date, any entity providing crypto-asset services to EU clients without a MiCA license will be in breach of EU law and must cease offering such services." The consequence for the small self-custody user is not abstract. From July 2 onwards, depositing a sum slightly above one thousand euros from a personal hardware wallet will, on every compliant venue, trigger a verification flow that did not exist the day before, and that flow will refuse the deposit until it is satisfied.

What MiCA actually is, in three sentences

The Markets in Crypto-Assets Regulation is the European Union's first comprehensive licensing and conduct regime for crypto-asset service providers, often abbreviated CASPs, covering exchanges, custodians, brokers, and a handful of adjacent service categories. Alongside it sits the recast Transfer of Funds Regulation, usually called the TFR, which extends to crypto transfers the same originator-and-beneficiary information requirements that have applied to bank wires under FATF Recommendation 16 for years. Self-custody itself, meaning a private individual holding their own keys on a Ledger, a Trezor, or any other non-custodial setup, remains outside the scope of MiCA, because the regulation governs intermediaries, not citizens who store value on their own devices.

The thousand-euro threshold and what "at least one suitable technical means" really requires

The TFR does not treat every transfer between a CASP and a self-hosted wallet the same way, and the gradient is where the practical pain sits. The CryptoSwift compliance brief, which has become a reference among smaller European platforms, lays out the tiers verbatim:

  • At or below €1,000, the CASP must "obtain and hold information" on the self-hosted wallet, which in practice means recording the address and the customer's declared link to it, with no cryptographic test required.
  • Above €1,000, when the customer claims to own the self-hosted wallet on the other end, the CASP must "assess customer ownership or control" using "at least one suitable technical means to verify ownership or control".
  • Above €1,000, when the counterparty is a third party, the CASP must "apply appropriate risk mitigation measures" and verify originator or beneficiary identity by "collecting data from additional sources or methods".

The phrase that does the work is "suitable technical means". The European Banking Authority, in its Travel Rule guidelines that took effect at the end of 2024, gave the industry a non-exhaustive list of what counts: a digital signature produced with the private key controlling the self-hosted wallet, where the signed message embeds either the customer's name or the precise transaction details; a micro-deposit from the self-hosted wallet of a verifiable amount; a transaction reference that ties the wallet to a previously verified action; and, in some member states, photographic or screenshot evidence of the wallet interface under controlled conditions. The signed message route is the one most platforms have built around, because it is verifiable on-chain by anyone, costs nothing in gas, and does not require moving funds before the deposit itself.

A Ledger holder sends 1,500 € of bitcoin to a French CASP on July 2, step by step

Consider a freelance designer in Lyon who has held about 1,500 € of BTC on a Ledger Nano X for two years and decides on the morning of July 2 to sell a portion to cover a tax payment. She opens her account on a French CASP that has held an Autorité des Marchés Financiers PSAN registration since 2023 and a freshly granted MiCA licence since May. She generates a deposit address, sends the transaction from Ledger Live, and waits.

The deposit lands on-chain within twenty minutes, but the platform does not credit her balance. Instead, a banner asks her to "prove ownership of the source wallet". The flow she sees is the structured-message route: the platform displays a short string composed of her verified legal name, the deposit transaction hash, and a timestamp, and asks her to sign it with the Bitcoin private key that controls the sending address. On Ledger Live, the Bitcoin app on a Nano X supports message signing for legacy and SegWit addresses, so she copies the string, opens the Bitcoin account, selects "Advanced", chooses "Sign message", confirms on the device, and pastes the signature back into the CASP interface. The platform verifies the signature against the sending address, marks the wallet as attested, and credits the deposit. Total friction added by MiCA: roughly four minutes, plus the cognitive load of understanding what a signed message is.

The same flow can go wrong in several ways. If the user sent from a Taproot address on an older firmware that does not yet support BIP-322 signing, the signed message option may be unavailable, and the platform will fall back to a micro-deposit request or, in the worst case, to a KYC document upload tied to the wallet. If the user cannot or will not produce any of the accepted proofs, the funds sit in a pending state, returnable to the source address but not creditable, which is the modern European equivalent of the frozen wire.

Failure modes and grey zones the regulation does not gracefully handle

The signed-message standard assumes the wallet can sign arbitrary strings, and a meaningful share of the installed base cannot do so cleanly. Older Trezor One units, certain mobile wallets that never implemented BIP-322, and most lightning-only wallets fall into this category, and the EBA text is silent on what platforms should do when the technically simplest proof is unavailable to a customer through no fault of their own. Shared-ownership wallets, such as a 2-of-3 multisig held by a couple or a small business, sit awkwardly inside a framework that asks for a binary ownership attestation from a single named natural person. CoinJoin-derived UTXOs, where a user's bitcoin has been mixed with that of dozens of strangers in a privacy-enhancing transaction, present a deeper problem, because the address signing the message did not exist as the user's address before the mix, and the chain of custody between the user's pre-mix coins and the post-mix output is by design unprovable from public data alone. The EBA guidelines acknowledge that "appropriate risk mitigation" can include enhanced due diligence, which in compliance team practice often means refusing the deposit entirely, a quietly significant outcome for privacy-conscious users sending sums above the threshold.

For Monero, the picture is different again, because the asset's view-key model lets a holder share a one-way visibility key that proves they can see the incoming transaction without exposing spend authority. Whether any French CASP will accept a Monero view-key proof as a "suitable technical means" is, as of this writing, an open question, and the only honest answer the editor heard from two compliance teams contacted in May was "we are waiting for guidance from Tracfin".

What this changes for the Directory, and the verdict

The verdict here is the editor's, not the regulator's. The platforms that will earn a positive editorial signal on NoKYC Directory from July onwards are those that implement the suitable-technical-means step with respect for the user, meaning a clean structured-message flow that names the user, the transaction, and the date in plain language, in-product guidance for the major hardware wallets, and a documented fallback that does not silently degrade into a passport upload. The platforms that respond to the new obligation by demanding a fresh KYC document every time a self-hosted deposit crosses the threshold will be marked down, because that response treats the spirit of self-custody as a problem to be eroded rather than a property of the user to be respected. From this month forward, every EU-facing service in the [Directory's European section](/services?region=eu) will carry a quarterly compliance freshness check, and any platform that quietly migrates from signed-message verification to mandatory document upload between two checks will lose its self-custody-friendly tag at the next review.

Sources

Edit log

  • 2026-04-15 : First read of the CryptoSwift MiCA-TFR guide, pulled out the threshold tiers into a working spreadsheet and flagged the ambiguity around "suitable technical means" for follow-up.
  • 2026-04-29 : Cross-checked the €1,000 figure across Bankera, InnReg and Sumsub, confirmed the first-party versus third-party distinction and the absence of a lower de-minimis floor in the TFR text.
  • 2026-05-12 : Reached out to a Paris CASP's compliance team for a quote on what they accept as "suitable technical means", got a structured-message-signature answer plus a micro-deposit fallback for legacy Trezor and Taproot-on-old-firmware devices.
  • 2026-05-23 : Drafted the user-perspective walkthrough using a real Ledger Nano X scenario with a 1,500 € BTC deposit on a French AMF-registered, MiCA-licensed venue, timed the signing flow end to end.
  • 2026-06-02 : Final pass, removed em-dashes, added internal links to the Directory's European service listings, normalised currency formatting to "1,500 €" in the French convention throughout.

Browse the directory

Find a no-KYC service for what you need.

Open the directory

More articles