All articles
Sanctions & Compliance

EU Crypto Regulations: MiCA and the Travel Rule Explained

The EU's MiCA regulation and Travel Rule are reshaping crypto compliance in Europe. Learn what these regulations require, who they apply to, and how to comply.

NexusCore Investigations Team2026-07-2011 min read
EU Crypto Regulations: MiCA and the Travel Rule Explained

The European Union has become one of the world's most active regulators of cryptocurrency. Two regulatory frameworks — the Markets in Crypto-Assets (MiCA) regulation and the Travel Rule (based on FATF recommendations) — are reshaping how crypto businesses operate in Europe. This article explains what these regulations require, who they apply to, and how to comply.

MiCA: Markets in Crypto-Assets

MiCA is the EU's comprehensive regulatory framework for crypto-assets. It was adopted in 2023 and is being phased in through 2024-2026. MiCA applies to:

  • Crypto-asset service providers (CASPs): Exchanges, wallet providers, custody providers, advisory services, and trading platforms
  • Token issuers: Entities that issue crypto-assets (including stablecoins and utility tokens)

Key Requirements of MiCA

Authorization

CASPs must obtain authorization from their national competent authority (NCA) to operate in the EU. The authorization process requires demonstrating:

  • Fitness and propriety of management
  • Adequate capital and insurance
  • Robust AML/CFT controls (including KYC and KYT)
  • Cybersecurity measures
  • Business continuity plans
  • Conflicts of interest policies

Consumer Protection

MiCA requires CASPs to:

  • Provide clear, fair, and not misleading information to customers
  • Disclose risks associated with crypto-assets
  • Have procedures for handling complaints
  • Protect customer assets (segregation of customer funds from the CASP's own funds)

Stablecoin-Specific Rules

MiCA imposes additional requirements on stablecoin issuers (referred to as "asset-referenced tokens" and "e-money tokens"):

  • Reserve requirements: Stablecoin issuers must maintain reserves that fully back the issued tokens
  • Reserve composition: Reserves must be held in high-quality, liquid assets
  • Disclosure: Issuers must disclose the composition and management of reserves
  • Redemption rights: Holders must have the right to redeem tokens for the underlying assets

Market Integrity

MiCA prohibits:

  • Market abuse (insider dealing, market manipulation)
  • Unauthorized public offers of crypto-assets
  • Misleading advertising of crypto-assets

Supervision and Enforcement

MiCA establishes the European Securities and Markets Authority (ESMA) and the European Banking Authority (EBA) as supervisors, with national competent authorities as the primary supervisors. Non-compliance can result in fines, suspension of services, and loss of authorization.

The Travel Rule

The Travel Rule is based on the Financial Action Task Force (FATF) Recommendation 16, which requires financial institutions to include information about the sender and recipient in fund transfers. For crypto, the Travel Rule means that CASPs must exchange identifying information about the originator and beneficiary of crypto transactions.

What the Travel Rule Requires

When a CASP sends crypto on behalf of its customer to another CASP's customer, the sending CASP must transmit to the receiving CASP:

  • Originator information: The sender's name, account number (wallet address), and physical address (or other identifying information like a national ID number or date of birth)
  • Beneficiary information: The recipient's name and account number (wallet address)

The receiving CASP must:

  • Verify that the beneficiary information matches its customer
  • Monitor for suspicious patterns
  • Report suspicious activity
  • Take freezing action if required by sanctions

Thresholds

The EU has implemented the Travel Rule with no de minimis threshold — all transactions between CASPs are subject to the Travel Rule, regardless of amount. (This is stricter than the FATF recommendation, which allows a threshold of USD/EUR 1,000 for "unhosted wallet" transactions.)

Unhosted Wallets

A key issue in the Travel Rule is transactions to/from unhosted wallets (self-custody wallets not controlled by a CASP). The EU requires CASPs to:

  • Collect and verify information about the unhosted wallet owner for transactions above EUR 1,000
  • Implement enhanced scrutiny for transactions to/from unhosted wallets
  • Be able to identify the originator and beneficiary of such transactions

Technical Implementation

The Travel Rule requires CASPs to exchange information securely. Several messaging protocols have been developed for this purpose:

  • TRP (Travel Rule Protocol): A protocol for exchanging Travel Rule information
  • IVMS 101: A data model for the originator and beneficiary information
  • OpenVASP / TRP / Sygna Bridge: Interoperability solutions for Travel Rule messaging

CASPs must implement one or more of these protocols to exchange Travel Rule information with other CASPs.

How to Comply

For CASPs

  1. Obtain MiCA authorization from your national competent authority
  2. Implement KYC procedures for all customers
  3. Implement KYT procedures for all transactions
  4. Implement Travel Rule messaging with other CASPs
  5. Maintain records of all transactions and Travel Rule information
  6. Report suspicious activity to your Financial Intelligence Unit
  7. Comply with sanctions screening (OFAC, EU, UK, UN)
  8. Maintain adequate capital and insurance
  9. Implement cybersecurity measures
  10. Train staff on compliance procedures

For Token Issuers

  1. Prepare a whitepaper that meets MiCA's disclosure requirements
  2. Obtain authorization if issuing asset-referenced or e-money tokens
  3. Maintain reserves as required
  4. Disclose reserve composition regularly
  5. Provide redemption rights to holders

Impact on the Crypto Industry

MiCA and the Travel Rule are reshaping the European crypto industry:

  • Increased compliance costs: CASPs must invest in compliance infrastructure
  • Market consolidation: Smaller CASPs may struggle with compliance costs, leading to consolidation
  • Improved consumer protection: The regulations provide stronger protections for consumers
  • Greater institutional adoption: Clear regulation encourages institutional participation
  • Innovation in compliance tech: The regulations drive innovation in KYC, KYT, and Travel Rule technology

Comparison with Other Jurisdictions

  • United States: No equivalent comprehensive federal framework; regulation is fragmented across the SEC, CFTC, FinCEN, and state regulators
  • UK: The UK is developing its own crypto regulatory framework, partly inspired by MiCA
  • Singapore: The Payment Services Act regulates crypto businesses with a focus on AML/CFT
  • UAE: The VARA (Virtual Assets Regulatory Authority) in Dubai provides a comprehensive framework

Conclusion

MiCA and the Travel Rule are the most significant crypto regulations in the European Union. MiCA provides a comprehensive framework for CASPs and token issuers, with authorization, consumer protection, stablecoin, and market integrity requirements. The Travel Rule requires CASPs to exchange originator and beneficiary information for all transactions. Compliance requires significant investment in KYC, KYT, Travel Rule messaging, and overall compliance infrastructure. For crypto businesses operating in the EU, understanding and complying with these regulations is not optional — it is the cost of operating in the world's most regulated crypto market.

Share this article