A Frankfurt-based compliance lead told us last spring that she’d stopped trying to explain MiCA to clients as «one law.» It technically is. A single regulation, no transposition needed, binding word-for-word in all 27 member states. But in reality, the regulator you’re dealing with specifically affects the process the most. BaFin came out of the gate having already run a national crypto custody license for years under the Banking Act, so it treats MiCA less like new territory and more like an upgrade to a system it already knew how to police aggressively. The AMF in France built its whole rollout around a hard transitional deadline, which produced something closer to a licensing conveyor belt than an open-ended review process. Malta‘s MFSA, meanwhile, spent the better part of a decade building a reputation as the crypto-friendly jurisdiction of choice for exchanges, and old habits, even under a new EU-wide rulebook, don’t just evaporate.
What follows goes jurisdiction by jurisdiction — Germany, France, Malta — looking at enforcement history and market posture rather than just the statute itself, then closes on Poland, where domestic legislative gridlock shows how much can still go wrong even when a regulation is legally «directly applicable» from day one.
Why «One Regulation» Doesn’t Mean «One Regime»
MiCA harmonizes the substance, not the enforcement. Reserve composition, redemption rights, whitepaper disclosure, and the split between e-money tokens and asset-referenced tokens are, on paper, identical whether an issuer sits in Frankfurt, Paris, or Valletta. What the regulation can’t touch, by its own design, is who actually enforces those rules day to day — and that’s exactly where the divergence between member states shows up. Each country designates its own regulator, and each of those institutions brings its own supervisory habits, staffing, political relationships, and risk appetite to an otherwise identical rulebook.
That’s not a footnote. It’s arguably the single most important variable in any legal risk assessment of a stablecoin issuer’s EU exposure. Two issuers can hold functionally identical MiCA authorizations, backed by identical reserve structures and near-identical whitepapers, and still carry meaningfully different real-world risk simply because of which national authority signed off and how that authority has behaved when things went sideways before.
🇩🇪 Germany: BaFin’s Enforcement-First Approach
BaFin didn’t start from zero when MiCA arrived. Germany already ran a crypto custody licensing regime under Section 1(11) of the Banking Act, so when MiCA’s stablecoin provisions became applicable EU-wide on June 30, 2024, followed by the broader CASP licensing regime on December 30 that year, BaFin’s job was mostly translation — sorting custody licensees it already understood into MiCA’s new categories, rather than building supervisory infrastructure from scratch.
That prior experience shaped its posture from day one: less exploratory, more assertive. BaFin came into MiCA already comfortable exercising hard supervisory powers over crypto firms, and it hasn’t shown much patience for testing that authority slowly.
The Ethena Case as a Study in Enforcement Speed
The clearest evidence of that posture came in spring 2025, when BaFin moved against Ethena GmbH, the entity behind the USDe synthetic dollar product. On March 21, 2025, it prohibited any new public offering of USDe, froze the entity’s reserves, and installed a special representative to oversee the wind-down. Roughly three weeks later, on April 14, 2025, it ordered the business dissolved entirely — not a quiet remediation process, but a full public shutdown executed in weeks.
For legal teams assessing counterparty risk on a German-domiciled issuer, that timeline tells you two things at once. BaFin has both the legal authority and institutional will to move fast against a product it deems non-compliant, rather than letting a compliance dialogue drag on for months. But it also means a counterparty relying on a German-authorized token faces genuine tail risk of an abrupt shutdown with limited notice — a materially different risk profile than in a jurisdiction where enforcement is slower and gives the market more runway to unwind.
A Genuinely Competitive Domestic Market
Heavy enforcement hasn’t suppressed market development in Germany, which cuts against the common assumption that the two move in opposite directions. AllUnity, reportedly backed by DWS along with other partners, launched a BaFin-regulated euro stablecoin, EURAU, in July 2025. Monerium’s EURe and SGForge’s EURCV and USDCV sit alongside it, giving Germany a genuinely competitive field of MiCA-compliant euro tokens rather than one dominant issuer. Circle’s USDC and EURC also operate under the same regime for German-facing activity, with additional EBA scrutiny once an issuer crosses the «significant» token threshold.
The reserve rules track MiCA’s baseline: full backing in high-quality, low-risk assets, with EBA technical standards specifying exact composition and capital add-ons for significant issuers under Article 43. Redemption is structured at par in the reference currency, built directly into the approved whitepaper rather than left to a separate contract. What actually distinguishes Germany, then, isn’t the substance of these rules — that’s EU-wide — it’s the credibility standing behind them. A regulator willing to freeze an entire product line within days sends a different signal than one that writes guidance letters and waits.
🇫🇷 France: First-Mover Licensing Meets a Hard Deadline
The AMF didn’t wait around for MiCA’s official applicability date. It started taking CASP applications on July 1, 2024, a full six months before the December 30, 2024 deadline that most other EU regulators treated as their actual starting gun. Part of why France could move that fast comes down to homework already done: the AMF had 74 companies registered under its old national DASP regime by mid-2024, so it wasn’t building a supervisory relationship with these firms from a standing start.
The Transitional Cliff Edge
Here’s where France diverges hard from Germany’s smoother, more gradual migration. Firms that held «simple,» «enhanced,» or optional pre-MiCA registration got an eighteen-month window to keep operating under that old status while they worked toward full authorization. That window ran out on June 30, 2026. Anyone without a completed CASP license by July 1 simply loses the right to serve French investors — there’s no grace period built in, no routine extension, nothing soft about the date itself.
The AMF repeated its deadline warnings to DASPs publicly throughout early 2026, and that pattern itself is worth reading carefully: regulators don’t usually keep reissuing the same warning unless a meaningful chunk of covered entities still hasn’t finished the CASP process. That points to a real bottleneck, whether in AMF processing capacity, applicant readiness, or both. It’s a risk that doesn’t really exist in Germany, where BaFin’s migration path had no comparable cliff edge. In France, an entity’s legal basis to operate hinges on a binary date — license granted before July 1, 2026, or gone overnight as a matter of law. Confirming a French counterparty’s live CASP status, rather than its historical DASP registration, is now a mandatory step in due diligence rather than a nice-to-have.
Where DORA and MiCA Intersect
The AMF’s CASP application package is also unusually granular. Applicants submit a core Article 62 application, a fit-and-proper form for every member of the management body, and a cybersecurity self-assessment tied directly to DORA, the EU’s Digital Operational Resilience Act. That explicit linkage matters because operational resilience testing and governance documentation — often owned by IT security rather than legal — become part of the same licensing file. Treating the MiCA application and the DORA compliance program as separate projects, on separate timelines, is a good way to discover the gap only once the AMF flags the inconsistency.
🇲🇹 Malta: The Regulatory Hub Strategy
If Germany represents enforcement rigor and France represents deadline-driven urgency layered onto institutional maturity, Malta represents deliberate positioning as the jurisdiction of choice for large international operators. The MFSA has marketed itself, in substance if not always in language, as the preferred European base for exchanges seeking a single EU passport under MiCA — a subtly different mission than BaFin’s or the AMF’s greater emphasis on domestic retail protection.
Gemini’s Choice and What It Reveals
The clearest evidence is Gemini, the exchange founded by the Winklevoss twins, which received a «Class 3» Virtual Financial Assets Service Provider license from the MFSA covering six services: transfer, custodian and nominee services, VFA placement, order transmission and reception, own-account dealing, and order execution. Gemini’s own public statement was notable for what it revealed about competitive dynamics between EU regulators: the exchange had reportedly also weighed Dublin before settling on Malta, citing the MFSA’s more proactive posture as the deciding factor — a direct admission that regulatory posture, not just legal substance, still functions as a competitive variable, something a single directly applicable regulation was supposed to eliminate.
Gemini formally registered as a MiCA-authorized CASP with the MFSA in August 2025, making Malta its base for operations across more than thirty markets globally. That single license now functions as an EU-wide passport under MiCA’s mutual recognition framework — precisely the efficiency MiCA was designed to deliver, which is also exactly why the choice of licensing jurisdiction carries outsized strategic weight for a multinational platform.
Institutional Memory From the Blockchain Island Era
Malta’s structure reflects this positioning institutionally. The MFSA has published a detailed MiCA Rulebook giving applicants a clearer, more predictable roadmap than the case-by-case, enforcement-heavy posture seen in Germany. That’s not incidental — Malta built a reputation as a self-styled «blockchain island» under its pre-MiCA Virtual Financial Assets Act years before MiCA existed, actively courting crypto business as economic strategy, and the shift to MiCA has largely preserved that reputation rather than disrupted it. Choosing Malta today means buying into an institutional culture that predates MiCA and has consistently prioritized predictability over the kind of headline enforcement BaFin showed with Ethena.
A Practical Comparative Framework
For teams assessing where to domicile EU crypto operations, or assessing risk on an existing counterparty, the distinction between these three jurisdictions maps onto genuinely different risk-and-opportunity profiles rather than cosmetic variation.
| Jurisdiction | Core strength | Core risk | Signature case |
| Germany | Fast, credible enforcement; deters bad actors | Compressed remediation timelines for counterparties | Ethena shutdown, March–April 2025 |
| France | Mature licensing pipeline, first-mover experience | Hard June 30, 2026 transitional cliff | AMF’s early CASP intake, July 2024 |
| Malta | Predictable, applicant-friendly process | Less public crisis-response data to assess | Gemini’s MFSA license, August 2025 |
Germany’s certainty cuts both ways: BaFin’s willingness to shut down non-compliant products fast protects against fraud, but it also means real exposure if BaFin later flags a gap in a counterparty’s own program. France rewards firms that treat licensing as a fixed-deadline project rather than an open dialogue — and punishes procedural delay regardless of underlying merit. Malta offers predictability that’s attracted major exchanges, though its smaller domestic market means there’s simply less public data on how the MFSA behaves under real crisis pressure, unlike BaFin’s now well-documented Ethena precedent.
🇵🇱 The Poland Problem: When «Directly Applicable» Doesn’t Mean Applied
Poland is worth closing on because it shows the limits of MiCA’s claim to direct applicability better than any of the three jurisdictions above. As an EU regulation rather than a directive, MiCA is technically binding without domestic transposing legislation — in theory, it just applies automatically once the relevant dates arrive. Poland’s experience shows why that distinction matters less in practice than the treaty text implies.
Poland’s own supplementary law — needed to designate the KNF as the competent national authority and give it actual enforcement powers, including the ability to freeze crypto and cash accounts and suspend transactions for up to 96 hours — got caught in a real standoff between the president and parliament. President Karol Nawrocki vetoed the bill in December 2025, again in February 2026 on the grounds the revised text was «practically identical» to what he’d already rejected, and a third time on June 11, 2026. A Sejm attempt to override the second veto failed in April 2026, falling short of the required majority by a vote of roughly 243 to 191. By the time of the third veto, Poland was the only EU member state still lacking domestic MiCA implementation, even though the regulation’s substantive rules had already been in force EU-wide since December 30, 2024.shuftipro+3
The transitional grandfathering period for Polish crypto firms registered before that date ended on July 1, 2026, under MiCA’s Article 143(3), and that deadline can’t be extended by Polish law or by the KNF — it’s fixed by the regulation itself. Without a designated competent authority, the KNF has no legal basis to process CASP applications, so Polish firms have had no domestic path to MiCA authorization even as the deadline passed. Foreign CASPs licensed elsewhere in the EU can still passport services into Poland; Polish firms, absent the missing law, cannot access that same passporting right themselves. As of mid-July 2026, the standoff remains unresolved, with the government and president disagreeing over the scope of KNF’s supervisory and account-freezing powers rather than over the principle of implementing MiCA at all.
The lesson generalizes well beyond Poland’s specific politics. A regulation’s direct applicability under EU law doesn’t guarantee that a national authority actually has statutory enforcement powers on the books the moment the substantive rules take effect. For counterparties dealing with Polish entities during this gap, the operative supervisory framework has been unsettled in a way a simple «does MiCA apply here» checklist would never surface — the real question is which domestic authority can actually act, under what specific powers, right now, not which EU regulation formally governs the sector in the abstract.
What This Means for Cross-Border Work
«MiCA-compliant» is a necessary but no longer sufficient risk indicator and treating it as sufficient tends to produce an incomplete legal opinion. The relevant questions have shifted one level down from the regulation to the regulator: which national authority actually supervises this entity, what has that regulator’s track record looked like when something went wrong, and — in France’s case — is the authorization genuinely current, or still riding a transitional registration approaching a hard expiration.
Germany, France, and Malta all implement the identical MiCA text as formal EU law, yet a German-domiciled issuer, a France-facing provider mid-transition ahead of the June 2026 deadline, and a Malta-licensed exchange each carry a distinguishable risk profile shaped almost entirely by the domestic regulator behind the shared rulebook. That’s not a transitional artifact that smooths out as MiCA matures — it’s a structural feature of how EU financial regulation actually works, and any cross-border legal opinion now has to address that divergence explicitly, jurisdiction by jurisdiction, rather than assume it away on the strength of a single regulation’s text.
Sources:
Germany (BaFin)
-
BaFin press release: «Ethena GmbH: BaFin prohibits new business with USDe token», 21 March 2025
-
BaFin follow-up: «Ethena GmbH: BaFin orders winding-up of business in Germany», 15 April 2025
-
AllUnity’s own press release confirming BaFin EMI licence grant, 2 July 2025
France (AMF)
-
AMF press release: «AMF now accepting applications for authorisation as a CASP», 2 August 2024
-
AMF reminder to DASPs on the 1 July 2026 deadline, 5 February 2026



