RegulationJuly 28, 2026

MiCA deadline today: knowledge requirements for crypto staff become binding

From 28 July 2026 the ESMA guidelines on staff knowledge and competence are legally binding for all 280 authorised CASPs. Ten hours of annual training for those who inform, twenty for those who advise — plus a per-employee file the competent authority may inspect.

Article image for: MiCA deadline today: knowledge requirements for crypto staff become binding

What changes today

From today, 28 July 2026, the ESMA guidelines on the knowledge and competence of staff at crypto-asset service providers are legally binding. They flow from Article 81(7) of MiCA (Regulation (EU) 2023/1114) and apply to all 280 CASPs holding an authorisation in the EU and the EEA. Until yesterday they were recommendations. From today they are testable obligations a competent authority can enforce.

The guidelines themselves are not new. ESMA published them on 28 January 2026 under reference ESMA35-24871704-2922, following a final report in July 2025 (ESMA35-1872330276-2380). The industry therefore had exactly six months to prepare. The question answered today is who actually used that time.

Ten hours to inform, twenty to advise

The core of the guidelines is a split. Staff who only inform clients — customer support, onboarding, KYC, technical support explaining how a product works — fall into the first tier. They must complete a minimum of ten hours of demonstrable continuing professional development each year. Staff who make personalised investment recommendations or manage portfolios fall into the second tier and must reach twenty hours annually.

The distinction lies not in the job title but in what someone actually says to a client. A support agent who answers ‘should I buy in now?' on live chat with an opinion is, in ESMA's eyes, an adviser. Many platforms will need to revise their scripts and internal instructions, not just their training budget.

The paperwork behind the requirement

The training itself is only half the story. ESMA requires a file for every member of staff: an initial competence assessment at hiring or on a change of role, evidence of completed certified training naming the provider and date, the assessment result including the score achieved, documentation of the annual update, and evidence of supervision during the first months in a new role. That file must be available to the competent authority on demand.

One detail is widely underestimated: training must be delivered through structured programmes with a certified final assessment. An internal course assembled by a compliance department, with no external assessment, will in many cases not satisfy that standard. Platforms that solved this with a home-made e-learning module are running a real risk from today.

Not every country is ready

On 7 July, exactly twenty-one days before the deadline, ESMA published a compliance table making it visible country by country who had already adopted the guidelines. France (AMF, declared on 26 March), Germany (BaFin), the Netherlands (AFM), Ireland, Italy (CONSOB) and Malta were green. Cyprus, Hungary and Latvia were in progress, targeting 30 September; Greece is aiming for 31 December and the Czech Republic for 1 July 2027. Denmark (Finanstilsynet) is partially compliant. Poland and Romania are recorded as non-compliant, in both cases because no competent authority has yet been designated.

That produces an uncomfortable picture. A Polish investor falls under the same regulation as a Dutch one, but the enforcement chain behind that regulation is not yet complete in their country. A day later, on 8 July, ESMA also launched a common supervisory action on digital operational resilience in CASP custody services, running from the second half of 2026 through the first half of 2027.

Fines up to 15 million euros

Article 111 of MiCA lets competent authorities choose, for breaches, between a fine of up to 15 million euros or 12.5 per cent of annual turnover, whichever is higher. On top of that an authority can suspend an authorisation temporarily, impose corrective measures with a deadline, or withdraw the authorisation permanently.

The silence from the big names is striking. Kraken, Bitvavo, Coinbase EU, OKX and Bybit EU had issued no public statement on this deadline as of mid-July. That may mean it is already handled internally and there is nothing to report. It may also mean they see what is coming and would rather not comment.

What it means for you

As a user you will notice little of this in the short term, and that is precisely the point: good rules are invisible. Over a longer horizon there are two effects worth watching. The first is that the quality of customer service at authorised platforms should improve, and that when you get a concrete answer to a concrete question you may now expect the person on the other end to have been assessed.

The second is that compliance costs money, and smaller platforms carry that cost less easily. The consolidation wave we saw in the European custody market this month gets an additional nudge here. If you live in Poland or Romania, it is worth checking whether your platform obtained its authorisation in another EU country and operates in yours by passporting — in that case supervision from that other country applies, and an enforcement chain does exist.

Sources: ESMA, MiCA (Regulation (EU) 2023/1114), AFM, BaFin, AMF, CONSOB, Finanstilsynet, KNF. Last checked: 28 July 2026.

#mica#esma#regulering#casp#compliance