MiCA enforcement watch: 159 non-compliant entities

ESMA's register of non-compliant crypto providers nearly quadrupled in a year — but the enforcement map is wildly uneven. Italy's CONSOB issues virtually all warnings, the Netherlands landed the single highest-profile action against MEXC, and Q2 2026 set an all-time record.

Published: July 2026 · Data as of 16 July 2026 · Reading time: ~6 minutes

Key Takeaways

  • The ESMA register of non-compliant entities grew from 42 to 159 between July 2025 and July 2026 (+279%).
  • Italy's CONSOB accounts for about 98% of all entries — 162 of 164 register rows. The Netherlands' AFM and Slovakia's NBS contribute one each.
  • Q2 2026 was the busiest enforcement quarter on record with 39 new warning decisions, coinciding with the end of MiCA's transitional period on 1 July 2026.
  • The AFM's entry against MEXC Global — for providing crypto services in the Netherlands without a MiCA licence — is the register's most significant single action against a major global exchange.
  • The register's asymmetry raises a hard question: is non-compliant crypto activity concentrated in Italy, or is Italy simply the only country systematically reporting it?

The Other Side of the Licensing Boom

While 294 firms earned CASP authorisations, another list grew in parallel: entities publicly flagged for providing crypto-asset services without authorisation. ESMA's non-compliant entities file — the enforcement mirror of the CASP register — reached 159 unique entities by mid-July 2026.

Non-compliant register growth

The trajectory tracks the licensing calendar with remarkable precision:

Warning decisions per quarter
QuarterNew warning decisions
Q1 202513
Q2 202523
Q3 202531
Q4 202535
Q1 202621
Q2 202639

The Q2 2026 record is no coincidence. With the Article 143 transitional period expiring on 1 July 2026, the space for lawful-but-unlicensed operation shrank to zero — and supervisors moved against firms that stayed in the market without converting.

One Register, Effectively One Regulator

The register's most startling feature is its composition. Of 164 rows, 162 originate from Italy's CONSOB — the Commissione Nazionale per le Società e la Borsa, which has transplanted its long-standing practice of publishing warnings against abusive investment websites into the MiCA framework. The flagged entities are overwhelmingly obscure trading platforms with lookalike domains — often several URL variants per entity — rather than household names.

The remaining two entries carry disproportionate weight:

  • Netherlands (AFM): MEXC Global, flagged for providing crypto-asset services in the Netherlands without the required MiCA licence, in breach of Article 59 — the register's only action against a top-tier global exchange.
  • Slovakia (NBS): one entity flagged by the National Bank of Slovakia.

Reading the Asymmetry

Does crypto non-compliance really cluster 98% Italian? Almost certainly not. The register measures reporting behaviour as much as misconduct:

1. CONSOB industrialised the process. Italy has published blacklists of abusive financial websites for years; extending the pipeline to MiCA-scope entities was procedurally trivial. Other NCAs pursue unlicensed activity through different channels — direct orders, geo-blocking demands, criminal referral — that never surface in this particular file. 2. A single register, 30 supervisory cultures. The file's uneven geography previews a core AMLA-era challenge: EU-level transparency tools are only as complete as the least forthcoming national contributor. As the AMLA framework matures alongside MiCA, convergence in enforcement publication practice will be a metric to watch. 3. The MEXC precedent matters most. One AFM entry against a global exchange signals more market impact than a hundred entries against clone websites. If other major NCAs follow the Dutch approach post-deadline, the register's second year could look very different from its first.

What Firms and Users Should Take From This

  • For consumers: the register is a genuine, official red-flag list — any entity on it has been publicly identified by an EU supervisor. Check it, and the ESMA MiCA register of authorised CASPs, before transferring funds.
  • For platforms: the MEXC action demonstrates that reverse-solicitation defences and offshore structures do not immunise global exchanges serving EU customers without authorisation.
  • For policymakers: 159 entries from three countries is not a picture of EU-wide enforcement. Harmonising what gets published may prove as important as harmonising the underlying rules.

Frequently Asked Questions

What is the ESMA non-compliant entities register? Part of ESMA's interim MiCA register: a public list of entities that national competent authorities have identified as providing crypto-asset services without the required MiCA authorisation.

How many entities are flagged as non-compliant under MiCA? 159 unique entities as of 16 July 2026, up from 42 a year earlier.

Which regulators report non-compliant crypto firms? In practice, almost exclusively Italy's CONSOB (about 98% of entries), with single entries from the Dutch AFM (MEXC Global) and the National Bank of Slovakia.

Does absence from the register mean a platform is safe? No. The register only reflects what NCAs have publicly reported through this channel. Always verify positively that a provider appears in the register of authorised CASPs rather than merely checking the warning list.

Sources

---

Analysis based on ESMA's interim MiCA register (non-compliant entities file), snapshots 11 July 2025 – 16 July 2026. Entity counts are unique names; quarterly series uses each entry's decision date.

Disclaimer: This article is provided for general information and analytical purposes only. It does not constitute legal, regulatory, investment, tax or any other form of professional advice, and it should not be relied upon as such. Inclusion of any entity in the figures above reflects its appearance in ESMA's public register as of the stated date, not any independent finding by MICA Watch. While we strive for accuracy, the underlying registers are updated frequently and figures may have changed since the stated data date. Always verify current information directly with official sources (ESMA, the European Commission, and national competent authorities) before making any decision. MICA Watch accepts no liability for any loss or damage arising from the use of this content.