MiCA regulation in the Netherlands: what crypto businesses must do

Scales of justice against a European Union flag, with glowing blue discs on each pan

MiCA, Regulation (EU) 2023/1114 on markets in crypto-assets, is the single EU rulebook for issuing crypto-assets and providing crypto-asset services. Its stablecoin provisions have applied since 30 June 2024 and the rest, including the licensing regime for crypto-asset service providers, since 30 December 2024. For the MiCA regulation in the Netherlands, the Autoriteit Financiële Markten (AFM) grants the licence, De Nederlandsche Bank (DNB) supervises stablecoin issuers and the prudential position of licensees, and the transitional regime for firms previously registered with DNB ended on 30 June 2025.

What MiCA regulates, and what it replaced

Before MiCA, a crypto business in the European Union faced twenty-seven answers to the same question. Some member states applied bespoke registration regimes, some applied existing financial legislation by analogy, and some applied almost nothing. A firm that wanted to serve customers across the Union either built a separate compliance structure in each country or accepted regulatory risk it could not price.

MiCA replaces that with one regime. It sets rules for the public offering and admission to trading of crypto-assets, for issuers of the two categories of stablecoin, for the authorisation and conduct of crypto-asset service providers, and for market abuse in relation to crypto-assets. It does not cover crypto-assets that already qualify as financial instruments under MiFID II, which remain under the existing securities framework, nor does it cover deposits, insurance products, pension products or central bank digital currency.

The European Securities and Markets Authority page on the markets in crypto-assets regulation.

The European Securities and Markets Authority (ESMA) and the European Banking Authority (EBA) develop the technical standards and guidelines that fill out the regime, and they publish registers of authorised firms and of white papers. National authorities do the licensing and day-to-day supervision. For the position under Dutch law before MiCA, and for the concepts the regulation builds on, see our guide to understanding cryptocurrency laws.

The timetable that still matters

MiCA entered into force on 29 June 2023 and applied in two stages. Titles III and IV, covering asset-referenced tokens and e-money tokens, have applied since 30 June 2024. Everything else, including Title II on other crypto-assets and Title V on service providers, has applied since 30 December 2024.

The regulation allowed member states to grant firms already providing crypto services under national law a transitional period, running at most until 1 July 2026, during which they could continue while applying for authorisation. Member states were free to shorten it, and the Netherlands did. Firms holding a DNB registration under the Dutch anti-money-laundering framework could continue to serve Dutch customers only until 30 June 2025. Since then, offering crypto-asset services in the Netherlands requires a MiCA licence.

The practical consequence for businesses is that MiCA is no longer a forthcoming regime to prepare for. It is the applicable law, the transitional route is closed, and a firm operating without authorisation is operating unlawfully rather than early.

How MiCA classifies crypto-assets

Digital assets alongside regulatory documents, illustrating the classification of crypto-assets under MiCA.

Everything in MiCA follows from classification, and getting it wrong at the outset invalidates the rest of the analysis. The regulation defines a crypto-asset as a digital representation of value or of a right that can be transferred and stored electronically using distributed ledger technology or similar technology, and then divides that universe into three categories.

Category

What it is

Core obligation on the issuer

E-money tokens (EMTs)

A token that purports to maintain a stable value by referencing a single official currency, for example a euro-denominated stablecoin.

The issuer must be authorised as a credit institution or an electronic money institution, publish a white paper, hold the funds received in safeguarded form and redeem at par at any time, at the holder's request.

Asset-referenced tokens (ARTs)

A token that references any other value, right or combination of them, such as a basket of currencies, commodities or crypto-assets.

The issuer needs specific authorisation, must maintain a segregated reserve of assets, must have own funds and governance arrangements, and must give holders a permanent right of redemption.

Other crypto-assets

Everything else within scope, including utility tokens and the major unbacked crypto-assets.

No authorisation to issue, but the offeror or the person seeking admission to trading must draw up a white paper, notify it to the competent authority, publish it, and act honestly, fairly and professionally.

Two classification questions arise constantly. The first is whether the token is in fact a financial instrument, in which case MiCA does not apply and the prospectus and MiFID regimes do; ESMA has issued guidelines on how to conduct that assessment, and it is a legal analysis rather than a technical one. The second is whether a token that presents itself as a utility token in fact references a value and therefore falls into one of the stablecoin categories. Both questions should be answered in writing, with reasons, before the token is offered.

The CASP licence: who needs one and what it involves

A crypto-asset service provider is a person whose occupation or business is providing one or more crypto-asset services to third parties on a professional basis, and MiCA lists those services exhaustively. They are: custody and administration of crypto-assets on behalf of clients; operation of a trading platform; exchange of crypto-assets for funds; exchange of crypto-assets for other crypto-assets; execution of orders on behalf of clients; placing of crypto-assets; reception and transmission of orders; providing advice on crypto-assets; providing portfolio management; and providing transfer services for crypto-assets on behalf of clients.

Providing any of them in the Union without authorisation is prohibited. Authorisation is granted by the competent authority of the member state in which the firm has its registered office, and that office must be in a member state with at least one director resident in the Union and effective management there. A shell in one country and operations in another does not satisfy the regime.

What an application has to demonstrate

The application is a substantial file rather than a form. It must set out the programme of operations describing each service the firm intends to provide, the governance arrangements and the identity, experience and repute of the management body, the identity of shareholders with qualifying holdings, the internal control mechanisms and risk management procedures, and the arrangements for business continuity. It must show that the firm meets the prudential safeguards, which are set by reference to a minimum capital figure that varies by service class or to a quarter of the preceding year's fixed overheads, whichever is higher, and which can be satisfied by own funds or an insurance policy meeting the regulation's conditions.

Service-specific requirements sit on top. A custodian must have a custody policy, must segregate client assets from its own, and is liable to clients for loss of a crypto-asset attributable to an incident within its control. A trading platform must have operating rules, transparent admission criteria, pre- and post-trade transparency and orderly trading systems. A firm executing orders must have a best execution policy. A firm giving advice or managing portfolios must assess suitability and must have staff with the necessary knowledge and competence.

Conduct obligations then apply across the board: acting honestly, fairly and professionally in the best interests of clients, fair and clear communications that are not misleading, identification and management of conflicts of interest, a complaints handling procedure, and rules on outsourcing that leave responsibility with the licensed firm.

The licence is not a formality that follows from a completed form. It is an assessment of whether a business can be run to financial services standards, and firms that treat the application as a documentation exercise rather than an operational one are the ones that spend a year in correspondence with the regulator.

Stablecoins: the strictest part of the regime

MiCA treats stablecoins as the category with systemic potential and regulates them accordingly. An e-money token may only be issued by a credit institution or an authorised electronic money institution. It must be issued at par against the funds received, holders must have a right of redemption at any time and at face value, and no interest may be paid on holdings. An asset-referenced token requires its own authorisation, granted only to a legal person established in the Union or to an authorised credit institution.

ART issuers must maintain a reserve of assets that is segregated from their own assets, kept separate from the reserves of other tokens, held in custody with a qualifying custodian and invested only in highly liquid financial instruments with minimal risk. They must publish the amount and composition of the reserve, have a clear redemption policy, and hold own funds calculated by reference to the reserve. Both categories are subject to enhanced requirements where the token becomes significant by reference to thresholds in the regulation, at which point supervision of ART issuers moves to the European Banking Authority.

There is one further restriction that catches business models rather than tokens. A token referencing a currency that is not an EU currency, used widely as a means of exchange, becomes subject to caps on transaction volumes, and issuance must be suspended if those caps are exceeded. Any business planning a payment product built on a non-euro stablecoin needs to model that constraint before it builds.

White papers, marketing and market abuse

The crypto-asset white paper is MiCA's central disclosure document, and it is a regulated instrument rather than a marketing brochure. It must describe the offeror or issuer, the project, the crypto-asset and the rights and obligations attached to it, the underlying technology, and the risks, and it must include a statement on the principal adverse environmental and climate impacts of the consensus mechanism. The information must be fair, clear and not misleading, and the management body must state that the white paper complies with the regulation.

For most crypto-assets the white paper is notified to the competent authority rather than approved by it, which is a meaningful difference from a prospectus: there is no clearance to hide behind, and liability for incorrect or misleading information rests with the offeror and its management body. Holders who suffer loss as a result of a misleading white paper have a right to claim damages, and the regulation does not permit that liability to be excluded.

Marketing communications must be identifiable as such, must be consistent with the white paper, and must state where the white paper can be found. Retail purchasers in a public offering generally have a withdrawal right exercisable within a fixed short period, without charge and without giving a reason, unless the asset is admitted to trading.

Title VI applies a market abuse regime modelled on the one for financial instruments: a duty on issuers to disclose inside information as soon as possible, a prohibition on insider dealing and on unlawful disclosure of inside information, and a prohibition on market manipulation. Persons professionally arranging or executing transactions must have systems to detect and report suspicious orders and transactions. Firms coming from an unregulated environment tend to underestimate this part, and it is where the first enforcement actions in any new regime usually land.

The MiCA regulation in the Netherlands: AFM, DNB and what changed on 30 June 2025

De Nederlandsche Bank guidance on crypto-assets and supervision in the Netherlands.

MiCA is directly applicable, but it leaves the designation of competent authorities and the enforcement machinery to national law. In the Netherlands that is done by the Uitvoeringswet verordening cryptoactiva, which slots the regime into the Wet op het financieel toezicht and divides the work between the two supervisors.

The AFM is the licensing authority for crypto-asset service providers and carries out most of the ongoing supervision of the conduct requirements, including the white paper obligations. DNB supervises issuers of asset-referenced and e-money tokens, exercises ongoing prudential supervision of licensed service providers, and assesses proposed acquisitions of qualifying holdings in them. Both authorities have the enforcement powers that apply across Dutch financial supervision, including instructions, penalty payments, administrative fines and withdrawal of a licence, and the AFM maintains a public register of authorised firms.

The end of the transitional regime on 30 June 2025 was the decisive Dutch date. Firms that had held a DNB registration under the anti-money-laundering framework could rely on it only until then, and the Dutch legislature chose not to use the full transitional period the regulation permitted. A firm still operating on the basis of the old registration is not in a grace period.

MiCA sits on top of the Wwft, it does not replace it

A MiCA licence does not discharge a firm's obligations under the Wet ter voorkoming van witwassen en financieren van terrorisme (Wwft). Crypto-asset service providers remain obliged entities: they must carry out customer due diligence, establish the source of funds where the risk profile requires it, monitor transactions on a risk basis, and report unusual transactions to the Financial Intelligence Unit Nederland. The Dutch regime requires reporting of unusual transactions rather than suspicious ones, which is a lower threshold than in several other jurisdictions and a recurring source of error for firms arriving from outside the Netherlands.

The two regimes are assessed separately and a firm can be compliant with one and in breach of the other. Our complete guide to money laundering rules in the Netherlands sets out the customer due diligence and reporting obligations in detail.

What MiCA does not cover

Three exclusions are commercially important, and each is narrower than it first appears.

Non-fungible tokens. MiCA does not apply to crypto-assets that are unique and not fungible with other crypto-assets. That exclusion is assessed by substance rather than by label: issuing a large series or collection of tokens is treated as an indicator that the individual items are in fact fungible, and fractionalised interests in a unique asset are not themselves unique. An NFT that confers rights resembling a financial instrument, or that functions as a means of payment, is analysed under the applicable regime rather than left outside regulation. Our article on NFT ownership rights in the Netherlands covers what an NFT does and does not convey under Dutch civil law.

Fully decentralised arrangements. Where a crypto-asset service is provided in a fully decentralised manner without any intermediary, MiCA does not apply. In practice very few arrangements meet that description. A front-end interface, a governance token concentrated in a small group, a foundation that maintains the protocol, or a team that can upgrade the contracts all point towards an identifiable person providing a service. Labelling a project as decentralised finance is not an analysis, and the European Commission has been asked to report on whether dedicated rules are needed.

Taxation. MiCA is a regulatory instrument and says nothing about how crypto-assets are taxed; that remains national. In the Netherlands, holdings by private individuals are generally dealt with under the rules on income from savings and investments, and businesses are taxed under the ordinary corporate rules, but the applicable rates, thresholds and the deemed return methodology change from year to year and are currently under reform. We do not advise on tax structuring: the position should be confirmed with a tax adviser or checked against the current guidance of the Belastingdienst before it is relied on. Note separately that, since 1 January 2026, reporting obligations for crypto-asset service providers under the EU directive on administrative cooperation feed transaction data to national tax authorities, so the practical assumption that holdings are invisible no longer holds.

The rules that sit alongside MiCA

MiCA compliance on its own is not compliance. Four further instruments bear directly on a licensed crypto business, and each has its own timetable and its own supervisor.

The recast Transfer of Funds Regulation, Regulation (EU) 2023/1113, has applied since 30 December 2024 and brings the travel rule to crypto. Information on the originator and the beneficiary must accompany a transfer of crypto-assets, the receiving provider must check that it is present, and transfers involving self-hosted wallets attract additional verification duties above a threshold. This is an operational requirement affecting transaction systems, not a policy document, and it is one of the first things a supervisor will test.

The Digital Operational Resilience Act, Regulation (EU) 2022/2554, has applied since 17 January 2025 and covers crypto-asset service providers and issuers of asset-referenced tokens. It requires an ICT risk management framework, classification and reporting of major ICT-related incidents, digital operational resilience testing, and a register of contractual arrangements with ICT third-party providers, together with specific contractual terms in those arrangements. Firms that have outsourced their core platform will find that DORA reaches into contracts they signed years ago.

The EU anti-money-laundering package tightens the picture further. The new Anti-Money Laundering Regulation applies from 10 July 2027 and will apply directly rather than through national implementation, and a new EU authority in Frankfurt will take on direct supervision of certain higher-risk cross-border firms, crypto included. Until then the Wwft continues to govern.

Finally, the ordinary rules do not stop applying because a business is built on distributed ledger technology. The GDPR governs personal data, including the tension between immutability and the right to erasure, which needs to be addressed in the system design rather than in the privacy statement. Consumer protection law applies to retail customers. Contract and property law determine what a token holder actually owns, which is frequently less than the marketing suggests. Our IT law guides deal with those overlapping regimes.

A practical route to authorisation

Firms that get through the process efficiently, whether applying under the MiCA regulation in the Netherlands or elsewhere in the Union, tend to follow the same sequence.

Begin with a written classification analysis. Establish, service by service and token by token, whether each activity is a crypto-asset service within MiCA, whether any token is a financial instrument, an ART or an EMT, and which member state will be the home state. This determines the whole application and every later requirement, and it is the document a regulator will ask for first.

Then close the governance gap before applying. Most refusals and most delays concern people and control rather than technology: a management body without demonstrable financial services experience, a compliance function that reports to the commercial side, shareholders whose ultimate ownership cannot be evidenced, or an outsourcing arrangement that leaves the firm unable to exercise control. Fixing these takes months, so identify them at the start rather than in response to a supervisor's question.

Build the operational framework in parallel with the application: custody and asset segregation policies, conflicts of interest policy, complaints procedure, best execution where relevant, business continuity, the ICT risk framework required by DORA, the travel rule implementation, and the Wwft customer due diligence and transaction monitoring arrangements. These are tested as working procedures, not as documents, so the systems should be operating before the licence is granted.

Finally, treat the prudential position as a live constraint. Own funds must be maintained continuously, not merely evidenced at application, and the calculation moves with the firm's fixed overheads. Where a technical audit of smart contracts forms part of the risk framework, commission it early: the remediation, not the audit, is what takes time.

What authorisation is worth commercially

The commercial argument for MiCA is passporting. A firm authorised in one member state may provide the services covered by its licence throughout the Union, by establishing a branch or by providing services cross-border, after a notification procedure through its home supervisor. One authorisation, one supervisor, one set of rules across the single market, in place of a licence in each country.

The second effect is access to counterparties. Banks, payment institutions and institutional investors have historically kept their distance from unregulated crypto firms, largely because their own supervisors expected them to. A licence changes the conversation about banking relationships, custody arrangements and distribution partnerships, and it is often the practical reason a firm applies.

There is a corresponding cost, and firms should price it honestly. Authorisation brings ongoing capital requirements, reporting, audits, a compliance function and supervisory engagement. For a small operator that cost can exceed the value of the regulated activity, and the right answer may be to narrow the service offering, to operate as a tied agent of an authorised firm, or to restructure so that the regulated activity sits with a partner. That decision is easier taken deliberately at the outset than after an application has stalled.

What MiCA gives retail customers

The regulation is written for firms, but it creates rights that individual holders can rely on, and those rights are worth knowing before a dispute rather than after one.

The first is disclosure. Any crypto-asset offered to the public in the Union or admitted to trading must have a published white paper, and the offeror is liable in damages to a holder who suffers loss because that white paper was incomplete, unfair, unclear or misleading. That liability cannot be excluded by contract, and it applies whether or not the competent authority reviewed the document. Where an asset is promoted without a white paper, that in itself is a strong indicator that the offering is outside the regime and the promoter outside supervision.

The second is protection of client assets. A custodian must hold clients' crypto-assets separately from its own, must keep a register of positions per client, and is liable to the client for the loss of a crypto-asset or of the means of access where the loss is attributable to an incident within its control. The liability is limited to the market value of the asset lost. This is a material improvement on the previous position, in which a customer of a failed platform was an unsecured creditor with a contractual claim and little else.

The third is redemption. Holders of e-money tokens and asset-referenced tokens have a statutory right to redeem at any time, at par for EMTs and in accordance with the redemption policy for ARTs, and no interest may be offered on either. A product marketed as a stablecoin that pays a yield, or that limits redemption to certain windows or certain holders, is not operating within the regime.

The fourth is the withdrawal right. A retail holder who buys a crypto-asset other than an ART or EMT directly from an offeror, where the asset is not admitted to trading, may generally withdraw within a short fixed period without charge and without giving a reason. Firms must tell purchasers about that right.

Finally, every authorised service provider must operate a complaints procedure that handles complaints free of charge and in a timely way, and must publish it. Where a complaint is not resolved, the ordinary Dutch routes remain open, including the financial services complaints institute for participating firms and the civil courts. None of this makes a crypto-asset a safe investment, and MiCA does not purport to: the regulation governs conduct and disclosure, not the value of the asset.

Enforcement, penalties and the risk of operating outside the regime

MiCA requires member states to give their supervisors a common set of powers and to provide for administrative penalties that are effective, proportionate and dissuasive. For legal persons the regulation sets minimum maximum fines that member states must at least make available, expressed both as a fixed amount and as a percentage of total annual turnover, with the higher figure applying, and the percentages rise with the seriousness of the infringement. For individuals, including members of a management body, fines and temporary bans from holding management functions are available.

Alongside fines, supervisors can order a firm to cease conduct, suspend or prohibit the marketing of a crypto-asset, suspend trading, require a firm to publish corrective information, and withdraw an authorisation. They can also publish decisions naming the firm, which for a business dependent on banking relationships is frequently the more damaging consequence.

In the Netherlands these powers are exercised through the enforcement framework of the Wet op het financieel toezicht, which gives the AFM and DNB the ability to issue instructions, impose orders subject to a penalty payment, impose administrative fines and withdraw a licence, with decisions open to objection and then to appeal before the administrative courts. Separately, providing crypto-asset services without the required authorisation is not merely an administrative matter: the prohibition is enforceable through the economic offences legislation, and a firm operating without a licence also exposes its directors personally.

The practical risks extend beyond regulators. Contracts entered into while unauthorised can be challenged, banks close accounts when they discover the position, and an unlicensed history is the first thing a supervisor examines when a later application is made. The cost of regularising a position early is consistently lower than the cost of defending one.

Frequently asked questions about MiCA regulation

The questions below come up most often from businesses and investors working out what the regulation means in practice.

Does MiCA apply to NFTs and DeFi?

This is a point that requires a bit of nuance. MiCA generally doesn't cover NFTs that are genuinely one-of-a-kind and non-fungible, like a unique piece of digital art. However, the moment NFTs are issued in a large, interchangeable series, they risk being reclassified as regulated crypto-assets under the new rules.

When it comes to Decentralised Finance (DeFi), the regulation primarily targets any project with identifiable, centralised control elements. While a truly decentralised, autonomous protocol might currently sit outside MiCA's direct reach, it's a space the EU is watching very closely for future regulation.

What is the timeline for MiCA implementation?

MiCA's rollout occurred in two primary phases, allowing the industry time to adapt. This structured approach was intended to ensure a smoother transition for all parties involved.

  • Stablecoin Rules: The provisions for Asset-Referenced Tokens (ARTs) and E-Money Tokens (EMTs) began in mid-2024.

  • Broader Rules: The remaining regulations, which include other crypto-assets and Crypto-Asset Service Providers (CASPs), came into effect at the end of 2024.

What are the penalties for Non-Compliance?

The penalties for not complying with MiCA are severe—they're designed to be a powerful deterrent. Authorities have the power to impose hefty fines, which can be as high as €5 million or a significant slice of a firm’s annual turnover.

But it's not just about the money. Regulators can also issue public warnings, revoke a firm’s authorisation to operate, and even enforce personal bans on members of the management team. This really underscores how important it is to have a proactive and thorough compliance plan in place.

How Law & More can help

We advise crypto and blockchain businesses on classification of tokens and services under MiCA, on applications to the AFM for a crypto-asset service provider licence, on white papers and marketing materials, on the contractual and data protection questions that arise around distributed ledger systems, and on the anti-money-laundering obligations that run alongside the regulation. We also act for firms in supervisory correspondence and enforcement matters. If you are assessing whether your activities fall within MiCA, or preparing an application, please contact us.

Need Legal Assistance?

Contact Law & More for expert guidance on your legal matters. Our multilingual team is ready to help.

Related articles

Many businesses in the Netherlands use CCTV cameras to protect their property and staff. However,

An online review in the Netherlands is lawful as long as it reports a genuine

Discover how timely legal support can strengthen your defense against assault and violence charges.

When your reputation is on the line, especially online, understanding your rights is the first

Businesses across the Netherlands are increasingly using AI tools to improve their operations. Many face

Withdrawing your statement in a criminal case is possible in the Netherlands, but a statement

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.