Introduction
Among the top 100 VASPs, 44% are regulated in at least one jurisdiction while holding a warning or facing enforcement action in another, a pattern that on-chain analytics cannot detect.[1] Within a single provider group, one legal entity may be authorised in a Member State, another may operate under a transitional regime, a third may be expressly prohibited, and others may have no identifiable regulatory basis.
On 30 September 2026, VASPnet submitted a response to the European Commission’s targeted consultation on the review of Regulation (EU) 2023/1114 (MiCA). In our response to Question 4, we argued that regulatory arbitrage and cross-border enforcement remain serious concerns because regulatory status varies by legal entity and jurisdiction, and current regulatory data does not identify those entities consistently.
Supervisory and enforcement authorities, as well as regulated firms, must therefore establish which legal entity is providing a crypto-asset service, whether it is permitted to provide that service and from which jurisdiction it operates. That requires reliable entity identification. On-chain data alone cannot provide it: a wallet address does not reliably establish the legal identity or regulatory status of the counterparty VASP.[2]
This article summarises the issues addressed in VASPnet’s consultation response. Question numbers follow the Commission’s consultation questionnaire.
Banks and payment firms hold the data supervisors lack
The Commission asked what tools supervisors and enforcement authorities should have to stop non-authorised providers from offering services to EU customers (Question 48.1). We proposed a reporting regime for payment institutions, e-money institutions and credit institutions. It would require them to list their CASP payment counterparties, the regulatory status of each and the cumulative payment value.
Supervisors and enforcement authorities would gain a view of the activity that firms conduct with providers outside the authorised perimeter. Payment data shows this activity regardless of how the provider describes itself.
The regime depends on entity-level data. A reporting firm needs to name the specific CASP legal entity it pays and state the status of that entity. Brand-level reporting would not be comparable across institutions.
The MiCA register covers authorised CASPs only
In reply to the Commission’s open question on issues not raised in the consultation (Question 86), we raised how the MiCA register can be used alongside regulatory information on providers outside MiCA.
The ESMA register established under Article 109 lists MiCA-authorised CASPs. Regulated firms conducting counterparty due diligence need a wider view. Many providers accessible to EU counterparties appear neither on that register nor on the non-exhaustive register of non-compliant entities under Article 110. Member States also present their non-compliant entity registers inconsistently.
The gap extends beyond the EU. Only 28% of the jurisdictions VASPnet tracks publish a dedicated warnings and actions list that clearly identifies crypto-asset activity.[3]
We suggested that Articles 59, 60, 63 and 109 may benefit from the registering of two groups, and from making information on them available. The first is third-country firms identified as offering services to EU users. The second is the entities within EU CASP groups. Each entry would state the entity’s regulatory basis and status, so that a listing does not imply authorisation.
This would complement the existing MiCA register and add to the information it already holds. Registration under this proposal would identify entities. It would not grant them authorisation.
Group structures require entity-level assessment
The Commission asked how important it is for EU users to access global stablecoins through EU-based, licensed issuers and CASPs (Question 28), what risks multi-issuance models create (Question 29) and whether oversight of multi-function groups should be enhanced (Question 51.1).
Global stablecoin arrangements, trading venues and multi-function crypto groups distribute activities across several legal entities. An issuer, distributor, exchange or custodian within one group may hold a different permission, or none, in each jurisdiction where it operates.
Authorisation held by an EU entity provides a regulatory anchor and says little about the wider group. A firm can also claim to be regulated without stating which activities it is authorised to perform, which creates a regulatory halo effect.
On equivalence (Questions 40 and 41), assessments should rest on comparable regulatory outcomes and on current, machine-readable entity-level data, because jurisdiction-level assessment cannot show whether a particular entity falls within an equivalent regime.
On the list of crypto-asset services in Article 3(16) (Questions 45 and 57), we recommended that competent authorities and CASPs describe authorised activities using MiCA service categories, publish them in structured form at legal-entity level and use recognised identifiers where available.
VASPnet made the same recommendation on legal entity identifiers in its response to FATF’s consultation on Recommendation 16.
Reverse solicitation needs supervision and enforcement
The Commission asked whether respondents have evidence of non-EU providers continuing to offer services in the EU (Question 48). Several providers, in third countries and in the EU, continue to offer services to EU users. ESMA guidance on reverse solicitation clarifies the difference between direct and reverse solicitation and the narrow scope in which reverse solicitation applies.[4] Continued availability of services from non-EU providers remains a supervisory and enforcement challenge.
MiCA authorisation is concentrated. As of 14 July 2026, VASPnet counted 289 MiCA-authorised CASPs, and about 55% of them sit in five countries. Of 78 leading centralised exchanges VASPnet reviewed, 20 hold at least one MiCA authorisation.[5]
Many regulated VASPs operate under regimes that VASPnet assesses as materially less comprehensive than MiCA. VASPnet’s proprietary data shows that 77% of regulated VASPs sit under a tier 4 regime.[6] The difference between these regimes and MiCA, combined with the narrow scope of reverse solicitation, calls for supervision and enforcement as well as guidance to maintain a level playing field for EU CASPs.
A consistent and accessible view of authorised, non-authorised and restricted providers would also reduce the risk that firms rely on brand recognition, or on authorisation held by another entity in the same group.
DeFi requires a multi-factor control assessment
The Commission asked which criteria should be used to assess the degree of decentralisation of a DeFi application (Question 61) and how MiCA should account for risks from fully decentralised protocols (Question 62.1). We recommended a multi-factor assessment of whether an identifiable person or group retains control, including administrator keys, upgrade rights, governance concentration and past centralised governance. Counterparty due diligence then needs an assessment of the legal entity or natural person where an identifiable regulated counterparty exists, and a separate protocol-level assessment where none does.
Conclusion: what this means for financial institutions
Banks, payment institutions and e-money institutions that bank CASPs need to run counterparty due diligence at legal-entity level. Four data points are needed for each counterparty: the entity that is providing the service, the activities it is authorised to perform, its competent authority and its current regulatory status. Brand-level checks and group-level assumptions leave gaps in each of these.
The review gives the Commission the opportunity to require competent authorities to publish this information. Structured, comparable and current entity data would serve supervisors and obliged entities at the same time. It would also lower the administrative burden, because information collected at authorisation could be reused across supervisory, reporting and compliance processes.
VASPnet tracks the authorisation status, jurisdiction and permitted activities of CASPs and VASPs across 128 regulators in 87 countries. Our platform helps banks and other financial institutions identify fiat-to-crypto payment flows and the regulatory status of the providers behind them.
[1] VASPnet, “Registered somewhere, active everywhere: what the FATF’s oVASP report means for compliance teams,” 30 April 2026.
[2] VASPnet, Response to FATF’s consultation on the Guidance on implementation of Recommendation 16, 21 August 2026.
[3] VASPnet, “Registered somewhere, active everywhere: what the FATF’s oVASP report means for compliance teams,” 30 April 2026.
[4] ESMA, Guidelines on reverse solicitation under MiCA, 26 February 2025, ESMA35-1872330276-2030.
[5] VASPnet, VASPdata, July 2026.
[6] VASPnet, VASPdata, April 2026. Tier 4 is a VASPnet proprietary classification denoting jurisdictions with relatively weak or non-existent virtual asset supervision.