Skip to content
SWITALSKI.LAW – home
EN PL

Reverse Solicitation Under MiCA: Why the Exemption Will Not Save Your EU Client Base

Article 61 MiCA covers one service for one client who asked for it. The exemption cannot carry a recurring EU client base.

A dense field of fine grey lines flowing one way, crossed by a single gold line running against them.Illustration generated with AI

KEY TAKEAWAYS

  1. Article 61(1) MiCA disapplies the Article 59 authorisation requirement for one service, requested by one EU client, on that client’s own exclusive initiative, and for nothing beyond it.
  2. The third subparagraph of Article 61(1) MiCA makes contractual clauses and disclaimers legally irrelevant, so a confirmation that the client acted alone does not survive facts showing otherwise.
  3. Article 61(2) MiCA prohibits marketing new types of crypto-assets or services to a client who arrived on their own initiative, and ESMA confines even same-type marketing to the context of the original transaction.
  4. The transitional regime under Article 143(3) MiCA ended on 1 July 2026, and in its statement of 23 June 2026 ESMA required unauthorised providers to stop onboarding EU clients and cease marketing and solicitation immediately.
  5. For a firm with a continuing EU client base, the realistic routes are CASP authorisation in a Member State or a genuine arrangement with an authorised CASP, because the exemption cannot carry recurring business.

Reverse solicitation is not a way back into the EU market. Article 61(1) of Regulation (EU) 2023/1114 (MiCA) exempts a single service, asked for by a single client, on that client’s own exclusive initiative. It does not license a client base, a funnel or a growth plan. Firms that read it as a market-access model usually discover the problem in the wrong order: first the supervisory letter, then the analysis. If your EU revenue is recurring, the decision you actually face is CASP authorisation under MiCA or a partnership with a licensed provider, and this article explains why the third option closed.

What Article 61(1) MiCA actually exempts

The exemption is narrow by construction. Where a client established or situated in the Union initiates, at its own exclusive initiative, the provision of a crypto-asset service by a third-country firm, the authorisation requirement in Article 59 MiCA does not apply to that service, for that client, including the relationship specifically relating to it.

Three limits follow from that wording, and they are limits of the Regulation itself, not of supervisory practice.

The exemption attaches to a client, not to a firm. It cannot be claimed at entity level, and it produces no status that can be shown to a regulator.

It attaches to a service, not to a relationship. The service the client asked for is covered; the next one is a separate question with a separate answer.

It requires exclusivity. Not predominant initiative, not initiative on balance. Any solicitation attributable to the firm removes the basis entirely.

The official heading of Article 61 MiCA is worth noting, because it is more accurate than the market shorthand. The provision is titled provision of crypto-asset services at the exclusive initiative of the client. The phrase “reverse solicitation” appears nowhere in the Regulation.

Solicitation is read broadly and technology-neutrally

ESMA’s Guidelines on reverse solicitation under MiCA (ESMA35-1872330276-2030), published on 26 February 2025 under the mandate in Article 61(3) MiCA, state the test in one line: solicitation is to be construed broadly and in a technology-neutral way. The guidelines are not binding law. They bind supervisors through the comply-or-explain mechanism, which in practice is what a national authority will apply to you.

The catalogue of means is deliberately open. It covers, among others:

  • websites, social media, mobile applications and messaging platforms;
  • banners, pop-ups, retargeted advertising and affiliation campaigns;
  • emails, telephone calls and invitations to complete a response form;
  • road shows, trade fairs, event invitations and sponsorship deals;
  • press releases and brochures.

Two points inside that list decide more cases than the list itself. First, promotion of a general nature, including plain brand advertising addressed to a wide public, may also constitute solicitation. Second, purely educational material is outside the concept, but it stops being educational the moment the audience is directed to the firm’s website, given access to its services, handed service-linked brochures or invited to complete a client profile.

Establishment plays no part in this analysis. A firm with no EU entity, no EU registration and no EU office is fully within the scope of Article 59 MiCA, and its outreach into the Union is assessed on exactly the same terms as that of a firm with an EU presence. What is examined is the conduct and the audience it reaches, not the address from which it originates.

Solicitation by someone else is still your solicitation

Solicitation is attributed to the firm regardless of who performs it. Under the guidelines, it may be carried out by the firm, by a person acting on its behalf under a contract, by a person acting under an informal arrangement, or by an entity with close links to it within the meaning of Article 3(31) MiCA.

Influencers sit squarely inside this. Indicators that a person acts on the firm’s behalf include directing an audience to the firm’s website, supplying the means of access to its services, offering promotional terms or displaying its logo. Any remuneration or benefit, monetary or not, is treated as a strong indication. The absence of remuneration does not settle the question the other way.

There is one narrow carve-out. A genuinely independent review of the firm’s services is not solicitation, but only where the firm did not know about it and did not consent to, encourage or facilitate it. An affiliate programme fails all three tests at once.

The Article 61(2) trap: what you may no longer offer

This is where firms that started lawfully end up unlawful, usually without noticing.

Article 61(2) MiCA states that a client’s own exclusive initiative does not entitle the firm to market new types of crypto-assets or crypto-asset services to that client. ESMA’s reading is narrower still. Marketing of the same type is permitted only in the context of the original transaction. A client who asks to buy a given crypto-asset may be shown assets of the same type at that moment. The same offer, made a month later, is outside the exemption.

The guidelines also refuse to let “same type” do any work. Utility tokens, asset-referenced tokens and e-money tokens are not the same type as one another. E-money tokens referencing different official currencies are not the same type. Liquid and illiquid crypto-assets are not the same type. Assets recorded or transferred on different technologies are not the same type. The categorisation the firm uses must be granular enough that it cannot be used to work around Article 59 MiCA.

In operational terms, this is a product and lifecycle-marketing problem, not a legal one. A retention push notification sent two days after a client-initiated trade, inviting the user back to see what is trending, is given in the guidelines as an example of conduct that defeats the exemption. So is a promotional notification sent two months later. Most platforms run both by default, from systems that no one in the legal function configured.

Why contractual clauses and disclaimers do not work

The point is often attributed to ESMA. It belongs to the MiCA Regulation. The third subparagraph of Article 61(1) MiCA provides that the solicitation rule applies notwithstanding any contractual clause or disclaimer purporting to state otherwise, including a clause stating that the service is deemed to be provided on the client’s own exclusive initiative.

That is Level 1 text. No drafting solves it, and the guidelines simply restate the consequence: the assessment is factual, and contractual arrangements cannot displace contrary facts.

The practical consequence is a reversal of the usual compliance instinct. The tick-box at onboarding produces nothing of evidential value. What has value is the record showing how the relationship began and the absence of any marketing touchpoint before it. The guidelines expect firms to be able to produce records tracking the relationship with the client, and in particular whether the client took the initiative in relation to a new product.

After the transitional period: what changed on 1 July 2026

Article 143(3) MiCA allowed providers that had operated lawfully under national law before 30 December 2024 to continue until 1 July 2026, or until authorisation was granted or refused under Article 63 MiCA, whichever came first. Member States could shorten that period or disapply it, and several did.

It is over, and the supervisory position is on the record. In its statement of 17 April 2026 (ESMA75-113276571-1679), ESMA confirmed that after that date any entity serving EU clients without a MiCA authorisation breaches EU law, and reminded the market that firms established outside the EU may not provide MiCA services to EU clients or solicit them, outside the narrow reverse solicitation exception. The same statement extends the point to business-to-business relationships and records that the restriction applies whether or not a Member State has adjusted its national law.

The public statement of 23 June 2026 (ESMA75-113276571-1710) is sharper. Unauthorised providers must immediately stop onboarding EU clients, open no new relationships or accounts, and cease marketing activities and solicitation. Services are limited to what is needed to sell, transfer, reallocate or close positions, and custody may continue only for the period strictly necessary to complete an orderly exit. Reverse solicitation survives in that document as a footnote, describing the narrow regime under which a strictly client-initiated service remains possible.

That is the correct way to size the exemption. It is what remains after everything else has been prohibited, not a channel that was left open.

Poland as the illustration

Poland shows what the absence of national implementation does and does not change. Three successive vetoes have blocked the Polish crypto-asset act, and on 4 September 2026 the Sejm again failed to override, falling short of the required majority. There is consequently no functioning domestic authorisation route and no designated supervisory framework of the kind the act was to create.

None of that suspends the Regulation. MiCA applies directly, the transitional period expired on the same date as everywhere else, and ESMA has twice said the position holds irrespective of whether national provisions have been aligned. A firm serving Polish clients gains nothing from the legislative deadlock. It simply faces the same requirement with one fewer place to satisfy it.

Weighing authorisation against a partnership, with an EU client base already in place?

Send a brief description of your current EU footprint and the services you provide, and you will get a direct assessment of the realistic route and its sequencing.

Send a brief

The operational test: six signals that decide the outcome

Supervisors do not assess intention. They assess whether the offer was aimed at the Union and whether the firm caused the traffic. The signals below are the ones that carry the analysis in practice, and each of them is something a firm can switch off before it becomes evidence.

Signals that make an offer EU-directed

Supported fiat currencies and payment rails come first. A platform that accepts euro deposits, supports SEPA or offers settlement in the currency of a Member State is making a product decision that reads as market targeting.

Interface and support language come second. The guidelines treat a website, or part of one, in an official EU language as an indicator, unless the firm originates from a jurisdiction using that language or serves a non-EU clientele that does. Integrated translation tools count. So, in practice, does a support function staffed in that language.

Mobile app availability comes third, and is the one most often overlooked. Where the firm’s application remains listed in app stores for EU territories, the precautionary posture the guidelines describe has not been implemented.

Traffic the firm can be shown to have caused

Regional search optimisation is explicitly in scope: country-code domains, EU country subdirectories on a generic domain, geographic targeting configured in SEO tools, and geo-targeted link building from EU sites. Geo-targeted digital advertising on search or social platforms is treated the same way.

Affiliate and influencer activity is attributed to the firm on the tests set out above. The relevant question is not whether the contract prohibits EU promotion, but whether the payout model rewards it. A revenue share that pays on EU signups is an instruction, whatever the agreement says.

Geo-blocking is a control, not a defence

The guidelines present geo-blocking as a precautionary measure a firm may take to avoid breaching the authorisation requirement, alongside refusing new EU accounts. That is its function. It does not prove that past conduct was clean, and it does not cure solicitation that already occurred. A firm that blocks EU IP ranges while its application remains available in EU app stores has bought a partial measure, and partial measures are visible.

The record that decides the case

The burden of showing genuine client initiative sits with the firm, and it is discharged with contemporaneous records rather than with policies. That means being able to reconstruct, per client, how the relationship began, and to show that no attributable marketing touchpoint preceded it. It also means being able to show that each subsequent product the client used was separately initiated by them.

Firms that can do this have usually instrumented it deliberately. Firms that cannot are, on the applicable standard, outside the exemption.

Group structures: where the intragroup carve-out stops

The second subparagraph of Article 61(1) MiCA is expressed without prejudice to intragroup relationships. That reservation concerns relationships within the group. It does not create a channel through which an EU entity may deliver clients to a third-country affiliate.

The guidelines are explicit. Provision of services following solicitation carried out on behalf of a third-country firm by an entity regulated in the EU is still a breach of MiCA, and an EU credit institution, investment firm or payment service provider should not redirect clients to crypto-asset services provided by a third-country firm. Membership of the same group changes nothing.

Three examples from the annex describe structures that are common in practice. An authorised CASP redirecting EU clients who wish to trade an unauthorised asset-referenced token to the group’s non-EU platform or broker. A group using arrangements that do not allow a client to distinguish the offering of the EU regulated entity from that of the third-country entity. A third-country firm using an EU affiliate’s website to display its logo or place a backlink to its own site.

Supervisory attention follows the same line. The April 2026 statement tells investors that MiCA protections apply to the specific authorised EU legal entity, not to other companies of the same group and not to non-EU entities, even where a single brand is used across jurisdictions. It also directs national authorities to scrutinise client migration strategies, including migration involving unauthorised group entities. Both statements add the reminder that certain functions, custody in particular, may not be outsourced or delegated to entities that are not themselves authorised as CASPs.

A shared brand across a regulated and an unregulated entity is therefore not a cost saving. It is the fact pattern ESMA describes.

Four decisions, in order of realism

Authorisation in a Member State

For any firm with recurring EU revenue, this is the only option that produces a stable position rather than a managed exposure. Authorisation is granted by the national authority of the Member State of the registered office, and it carries the right to operate across the Union under the passporting mechanism in MiCA, which is what makes a single application worth the effort.

The practical variables are the ones worth planning around: substance in the chosen Member State, a management body that will withstand fit-and-proper assessment, governance and custody arrangements that match the services applied for, and prudential requirements calibrated to those services. Application timelines are driven far more by the completeness of the first filing than by the jurisdiction chosen, which is why comparisons built on headline processing times tend to disappoint. The licensing process for crypto-asset service providers sets out the procedural sequence in detail.

For a firm that has been serving EU clients without authorisation, one point is worth internalising early. Conduct during the unauthorised period is not invisible to the authority assessing the application.

Partnering with an authorised CASP

Viable, and faster, provided the arrangement is real. The authorised entity must actually provide the service, on its own systems, under its own governance, with its own client relationship and its own onboarding. Where clients are transferred to an authorised CASP, ESMA expects the onboarding entity to carry out the AML/CFT checks required under the applicable framework, including customer due diligence, transaction monitoring, screening against sanctions lists and record-keeping. Budget for that work on the receiving side rather than assuming the migrating book arrives ready.

The constraint that ends most white-label conversations is delegation. Certain functions, custody above all, cannot be outsourced to an entity that is not itself authorised. Where the authorised partner holds the licence while the third-country firm holds the assets and owns the client relationship, the arrangement reproduces the fact pattern the guidelines describe, and the authorisation does not extend to cover it.

Restricting or exiting

Restricting service to non-EU clients is coherent only where EU exposure is genuinely incidental. It means implementing the controls described above and accepting that the exemption will apply to occasional cases, not to a book.

Exiting means an orderly wind-down on the terms ESMA has set: stop onboarding, communicate clearly and repeatedly with clients, limit activity to disposal, transfer and closure, and give a deadline after which residual positions are closed. The sequencing issues that arise in practice are set out in the note on winding down a Polish VASP after the MiCA deadline.

Where to start

Run the operational test before the legal analysis. Fiat rails, interface and support languages, app store territories, paid and organic acquisition, affiliate payouts, lifecycle messaging. If any of those is still configured for the Union, the exemption is unavailable regardless of what the client agreement says, and the only question left is which of the four decisions above you are making.

Law stated as at 17 September 2026. The Polish implementing legislation remains blocked, and a further attempt would change the domestic authorisation route without affecting the obligations described here.

FAQ

Only where a specific EU client requested a specific service on their own exclusive initiative, under Article 61(1) MiCA. The transitional regime in Article 143(3) MiCA expired on 1 July 2026, and ESMA has required unauthorised providers to stop onboarding EU clients and cease marketing and solicitation. Continuing business requires authorisation as a CASP or delivery through an authorised one.

No. The third subparagraph of Article 61(1) MiCA provides that the solicitation rule applies notwithstanding any contractual clause or disclaimer stating otherwise, including one deeming the service to be provided on the client’s own initiative. The assessment is factual, and a clause cannot displace facts showing that solicitation occurred.

Geo-blocking is a precautionary control, not evidence. ESMA’s guidelines describe blocking EU access and refusing new EU accounts as measures a firm may take to avoid breaching the authorisation requirement. They do not cure earlier solicitation, and their effect is undermined where the firm’s mobile application remains available in EU app stores.

Article 61(2) MiCA prohibits marketing new types of crypto-assets or services to that client. ESMA limits even same-type marketing to the context of the original transaction, so a promotional message sent days or weeks later falls outside the exemption. Categories such as utility tokens, asset-referenced tokens and e-money tokens are not the same type as one another.

Article 61(2) MiCA prohibits marketing new types of crypto-assets or services to that client. ESMA limits even same-type marketing to the context of the original transaction, so a promotional message sent days or weeks later falls outside the exemption. Categories such as utility tokens, asset-referenced tokens and e-money tokens are not the same type as one another.

The exemption is not limited to retail clients, but it is not relaxed for institutional ones either. In its statement of 17 April 2026, ESMA confirmed that the prohibition on providing MiCA services to EU clients and on soliciting them applies in a business-to-business context as well, and noted that certain functions, notably custody, cannot be delegated to entities that are not authorised as CASPs.

Only where the authorised entity genuinely provides the service to the client. Routing or redirecting EU clients from an EU entity to a third-country affiliate is treated as a breach, and group membership does not change that. ESMA has also warned that MiCA protections attach to the specific authorised EU entity, not to other companies operating under the same brand.

Mateusz Świtalski
About the author
Mateusz Świtalski

Mateusz Świtalski is a Polish attorney-at-law practising in Poznań, specialising in EU crypto and fintech regulation. He works directly with founders from incorporation through to full licensing authorisation.

Read full bio

have a question on this?

Send me a brief.

One named attorney, end to end — tell me what you are building and I will reply within one business day.

    Your data is used solely to respond to your message. Controller: Mateusz Świtalski Kancelaria Radcy Prawnego, Małachowskiego 8/P1, Poznań, info@switalski.law. Full details and your rights – Privacy Policy.

    1 business day
    Reply time
    Fixed fee
    Where possible
    NDA on request
    Standard wording

    Direct counsel – no account managers, no anonymous queue. · Confidential · EN / PL

    Continue reading

    Practitioner notes from the EU fintech frontline

    MiCA 8 September 2026 P2P crypto trading under MiCA: when trading your own capital becomes a service Read article MiCA 15 May 2026 Polish VASP Wind-Down After the MiCA Deadline: The Three Paths That Remain Read article