EU rules: MiCA, DAC8 and the travel rule

Last reviewed: October 2026

On this page
  1. MiCA: licensing and investor protection
  2. Authorization and the EU passport
  3. The transition period
  4. Checking a provider
  5. DAC8: tax reporting
  6. The Transfer of Funds Regulation (the travel rule)
  7. Sources
  • The Markets in Crypto-Assets Regulation (MiCA) has applied in full since 30 December 2024. Crypto-asset service providers need an authorization from the authority in their home EU country, and can then serve customers in the whole EU.
  • Providers that already operated under national law could continue only until 1 July 2026 at the latest. Several countries chose an earlier end date.
  • The tax directive DAC8 has applied since 1 January 2026. Providers collect data on their EU-resident users, and tax authorities exchange it.
  • The Transfer of Funds Regulation has applied to crypto transfers since 30 December 2024 (the “travel rule”).

Three EU laws apply in every member state: one on licensing (MiCA), one on tax reporting (DAC8) and one on transfers (the Transfer of Funds Regulation). Each country adds its own supervisor, tax rules and deadlines, which are on the country pages. This page is general information, not legal or tax advice.

MiCA: licensing and investor protection

According to the European Commission, MiCA covers the issuing of crypto-assets, and the services provided in respect of crypto-assets, that are not covered by other EU financial services legislation. It entered into force in June 2023 and applies in full since 30 December 2024. It sets rules in four areas:

  • Investor protection: prospective customers and holders of crypto-assets must be informed about the characteristics, functions and risks.
  • Organization: organizational, operational and prudential requirements for issuers of crypto-assets and for crypto-asset service providers.
  • Market integrity: rules to prevent market manipulation and insider trading.
  • Money laundering: crypto-asset service providers are on the list of obliged entities under the EU anti-money-laundering framework.

Authorization and the EU passport

A company that wants to provide crypto-asset services applies for authorization to the competent authority of its home member state. Once authorized, it may provide crypto-asset services throughout the EU, either by establishing itself, including through a branch, or by providing services across borders. It does not need a physical presence in the host country when it serves customers across borders.

Some financial firms follow a shorter route. A credit institution may provide crypto-asset services if it notifies its home authority at least 40 working days before it first provides them.

The transition period

Under Article 143(3) of MiCA, firms that provided crypto-asset services under national law before 30 December 2024 could continue until 1 July 2026 or until a decision on their authorization, whichever came first. The regulation also allows a simplified authorization procedure for firms that were already authorized under national law on 30 December 2024 (Article 143(6)). Each member state chose how long its own transition lasted, up to the maximum.

CountryEnd of the national transition, as we read it
Netherlands30 June 2025
GermanyAt the latest the end of 31 December 2025
Portugal1 July 2026, or earlier on a decision

Checking a provider

The European Securities and Markets Authority (ESMA) publishes an interim MiCA register in five files: white papers for crypto-assets other than stablecoins, issuers of asset-referenced tokens, issuers of e-money tokens, authorized crypto-asset service providers, and non-compliant entities. It is updated weekly. ESMA warns that the white papers in its register have not been reviewed or approved by any competent authority. Your own country’s authority also publishes its list, which is linked on the country pages.

DAC8: tax reporting

Council Directive (EU) 2023/2226, known as DAC8, widens the EU’s automatic exchange of tax information to crypto-assets. Its rules on due diligence and reporting by crypto-asset service providers reflect the OECD’s Crypto-Asset Reporting Framework (CARF).

  • From 1 January 2026, providers collect data on reportable crypto-asset transactions of all EU-resident users.
  • Who: all crypto-asset providers based in the EU, irrespective of their size, report transactions of clients resident in the EU.
  • When: the European Commission says reporting is due within nine months after the end of the first year covered, so between 1 January and 30 September 2027. Each country sets its own earlier deadline for providers.
  • Also covered: the directive extends reporting by financial institutions to e-money and central bank digital currencies.

For the national deadlines, see the Netherlands, Germany and Portugal.

The Transfer of Funds Regulation (the travel rule)

Regulation (EU) 2023/1113 extends the travel rule to crypto-asset transfers. It has applied in full throughout the EU since 30 December 2024. Crypto-asset service providers must send information about the sender and the recipient with each transfer. For transfers above €1,000 to or from a self-hosted (unhosted) wallet, the provider must verify that the wallet is owned or controlled by its customer, and it may also do this for smaller transfers if the risk requires it.

Sources

This page is general information, not legal or tax advice. Rules and rates change, so check the official sources above before you act.