Source: OJ L 150, 9.6.2023, pp. 40–205

Current language: EN

Article 64 Withdrawal of authorisation of a crypto-asset service provider


Summary What does Article 64 of the MiCA regulation say?

This article is the counterpart to Article 63, which deals with the granting of authorisation for crypto-asset service providers.

Article 64 sets out the full regime for withdrawal of that authorisation, covering both mandatory and discretionary grounds.

It draws a clear distinction between situations where competent authorities must withdraw authorisation and those where they may do so, and it also sets out procedural obligations that apply when a withdrawal takes place, including consultation requirements, notification to ESMA, and obligations on the service provider itself to protect clients during the transition.

Important points:

  • Competent authorities are required to withdraw authorisation in mandatory circumstances, such as serious infringement of the regulation, obtaining authorisation by false statements, or failing to operate for nine consecutive months.
  • Competent authorities may withdraw authorisation in discretionary circumstances, including breaches of anti-money laundering rules or loss of a related payment institution authorisation where the situation is not remedied within 40 calendar days.
  • Establish, implement and maintain procedures for the timely and orderly transfer of clients' crypto-assets and funds to another crypto-asset service provider in the event authorisation is withdrawn.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. Competent authorities shall withdraw the authorisation of a crypto-asset service provider if the crypto-asset service provider does any of the following:

      1. has not used its authorisation within 12 months of the date of the authorisation;

      2. has expressly renounced its authorisation;

      3. has not provided crypto-asset services for nine consecutive months;

      4. has obtained its authorisation by irregular means, such as by making false statements in its application for authorisation;

      5. no longer meets the conditions under which the authorisation was granted and has not taken the remedial action requested by the competent authority within the specified timeframe;

      6. fails to have in place effective systems, procedures and arrangements to detect and prevent money laundering and terrorist financing in accordance with Directive (EU) 2015/849;

      7. has seriously infringed this Regulation, including the provisions relating to the protection of holders of crypto-assets or of clients of crypto-asset service providers, or market integrity.

    1. Competent authorities may withdraw authorisation as a crypto-asset service provider in any of the following situations:

      1. the crypto-asset service provider has infringed the provisions of national law transposing Directive (EU) 2015/849;

      2. the crypto-asset service provider has lost its authorisation as a payment institution or its authorisation as an electronic money institution, and that crypto-asset service provider has failed to remedy the situation within 40 calendar days.

    1. Where a competent authority withdraws an authorisation as a crypto-asset service provider, it shall notify ESMA and the single points of contact of the host Member States without undue delay. ESMA shall make such information available in the register referred to in Article 109.

    1. Competent authorities may limit the withdrawal of authorisation to a particular crypto-asset service.

    1. Before withdrawing an authorisation as a crypto-asset service provider, competent authorities shall consult the competent authority of another Member State where the crypto-asset service provider concerned is:

      1. a subsidiary of a crypto-asset service provider authorised in that other Member State;

      2. a subsidiary of the parent undertaking of a crypto-asset service provider authorised in that other Member State;

      3. controlled by the same natural or legal persons who control a crypto-asset service provider authorised in that other Member State.

    1. Before withdrawing an authorisation as a crypto-asset service provider, competent authorities may consult the authority competent for supervising compliance of the crypto-asset service provider with the rules on anti-money laundering and counter-terrorist financing.

    1. EBA, ESMA and any competent authority of a host Member State may at any time request that the competent authority of the home Member State examine whether the crypto-asset service provider still complies with the conditions under which the authorisation was granted, when there are grounds to suspect it may no longer be the case.

    1. Crypto-asset service providers shall establish, implement and maintain adequate procedures ensuring the timely and orderly transfer of their clientscrypto-assets and funds to another crypto-asset service provider when an authorisation is withdrawn.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod