Key2Law: MiCA Ends Transitional Period, Reshaping iGaming Compliance
Jacob Mitchell
Key Takeaways:
- MiCA's transitional period ended, increasing scrutiny on iGaming crypto payments.
- Operators must verify payment partners hold valid CASP authorisation.
- Gambling and MiCA compliance should be an integrated framework.
- Regulators now assess practical application of AML/KYC controls.
- EU gambling licences lack passporting, unlike MiCA crypto authorisations.
- Regulatory predictability is crucial for long-term jurisdiction choice.
- Compliance is a long-term strategy, not just a regulatory obligation.
Mykyta Kim, chief executive officer of Key2Law, has outlined the significant implications for iGaming operators following the close of the Markets in Crypto-Assets Regulation (MiCA) transitional period on 1 July. Kim stated that crypto payments can no longer be treated as a secondary technical feature outside the main regulatory framework.
Operators that accept crypto-assets directly or rely on online casino payment methods, custody, exchange, or liquidity partners must now understand if those partners hold a valid Crypto-Asset Service Provider (CASP) authorisation under MiCA. This also requires understanding which specific services that authorisation covers.
MiCA's Impact on iGaming Compliance
MiCA does not replace existing gambling regulatory compliance but introduces an additional layer of scrutiny for iGaming businesses. The regulatory risk profile for operators accepting crypto payments changes significantly, even if they do not automatically become a CASP.
Kim noted that regulators, banks, payment providers, and auditors will now examine the entire payment chain. This includes scrutinising who receives funds, converts crypto-assets into fiat, holds assets, performs AML checks, and where customer risk sits.
Under the post-transition MiCA regime, relying on assurances from payment partners is no longer sufficient. Operators should immediately conduct both legal and operational risk assessments if a payment or liquidity partner lacks CASP authorisation.
Integrated Compliance and Regulatory Scrutiny
While gambling and MiCA are legally distinct regulatory regimes, their practical distinction is becoming less clear-cut. Key2Law advises operators to treat MiCA requirements and gambling licensing as one integrated compliance framework rather than two separate workstreams.
Regulators are increasingly assessing whether the payment infrastructure is lawfully structured, if AML and KYC controls are effective, and if an appropriate framework for managing regulatory risk is in place. Reliance on unauthorised service providers or weak oversight of crypto payment flows can attract additional scrutiny from licensing authorities and banking partners.
Kim highlighted that the overall quality of governance and risk management is becoming as important as compliance with individual regulatory requirements in regulated online casino markets. Regulators are now examining existing AML and KYC documentation in greater detail, testing whether it genuinely reflects the operator’s business model.
They expect a risk-based framework tailored to the operator’s activities, including documented risk assessment, customer due diligence procedures, transaction monitoring processes, and suspicious activity reporting mechanisms. The shift is from reviewing policies on paper to assessing how they work in practice, focusing on compliance responsibilities, monitoring systems, staff training, and risk response.
Strategic Licensing and Future Outlook
Unlike MiCA, which provides a framework for offering crypto-asset services across the EU, there is no equivalent passporting regime for gambling licences. Each Member State sets its own licensing requirements, tax rules, player protection standards, and compliance obligations.
Operators should not build European expansion strategies around the assumption that a single licence will provide access to the entire EU market. Key2Law advises starting with the operating model rather than the licence itself, addressing fundamental issues like corporate governance, AML, CDD frameworks, and internal controls from the outset.
Regulatory predictability, a clear framework, established supervisory practice, and accessible banking services are crucial factors for choosing a long-term jurisdiction. Jurisdictions that attract operators with minimal entry requirements but lack regulatory stability or frequently change rules are considered significant warning signs.
Kim anticipates that the biggest change over the next 12 months will be increased coordination between regulators and a more holistic approach to assessing regulated businesses. He concluded that a licence alone will no longer be enough to stand out, with the real competitive advantage being the ability to demonstrate a mature, well-governed, and sustainable compliance framework.


