Market · In-house regulatory talent
MiCA digital-assets regulatory counsel.
The transitional window closed on 1 July 2026 and left a licensed population you can count. For a payments business, an exchange, a custodian or a bank-owned digital-asset arm, the question is no longer who files the application. It is who on the payroll owns the license, the conduct duties and the disclosure liability afterwards.
The register is countable. The seat behind it is not staffed.
MiCA regulation now has a licensed population you can count, and it is smaller than the announcements were. For a payments business, an exchange, a custodian or a bank-owned digital-asset arm the useful question is not whether crypto is back; it is who, on the company payroll, owns the license file, the conduct duties and the white-paper liability. Across 250 structured interviews with Paris legal and compliance leaders, 38 of the 61 respondents sitting inside regulated financial, payments and digital-asset institutions over a 24-month window told Sartori that file had no single named internal owner when it was submitted.
TRM Labs counted 281 authorized providers against 1,343 operating across the EEA when the transitional period closed on 1 July 2026. The rest exited, stalled mid-process or restructured behind somebody else’s license. The licensed population is small and named.
Every lens above is a duty that outlives the authorization decision. The four that a company cannot outsource are set out in section 03.
- 1 July 2026
- MiCA transitional period closed EU-wideUnauthorized providers directed to wind down, not to keep trading
- ESMA public statement, 23 June 2026
- 36 of 177
- CASP licenses held by banksAbout one in five, and the clearest signal of where this seat sits
- Ledger Insights, 10 April 2026
- 10.4%
- Compliance and legal share of tracked crypto job postings16.0% at centralized exchanges; 2,932 postings sampled
- Tiger Research, sampled 18 June 2026
- 12.5%
- Maximum fine on a significant asset-referenced token issuer10% for significant e-money tokens, under Article 131
- EBA/CP/2026/10, 26 June 2026
The application was the project. The perimeter is the job.
Almost every company that went through the authorization gate treated it as a transaction with an end date. The regulation is built the other way round: the decision is the moment the standing obligations switch on.
The commentary around the 1 July 2026 deadline read like the end of a story. Firms that were going to convert had converted; firms that were not had left. TRM Labs put the arithmetic at 281 authorized crypto-asset service providers out of 1,343 operating across the European Economic Area before the grandfathering ended — roughly one in five — with the unauthorized population skewed toward exchanges and payment services. Two months later, the register tracked by casptracker.eu from ESMA data showed 331 authorized providers across 30 EU and EEA markets and 26 national regulators, verified on 2 September 2026. Those are two dated snapshots of a moving list, not two points on a growth curve, and they should be read one at a time.
Read as a market story, the number says consolidation. Read as a corporate legal problem, it says something more useful: the population of companies that now hold a European digital-asset permission is small enough to name, and every one of them has acquired a set of obligations that do not switch off. ESMA’s public statement of 23 June 2026 made the point in the plainest possible terms for the firms on the wrong side of the line, directing unauthorized providers to stop onboarding, cease marketing and solicitation, and wind down custody in an orderly way while keeping anti-money-laundering controls running throughout. A wind-down under supervision is not a smaller compliance job than a license. It is the same job, with a worse ending.
The regulation itself is unusually direct about where responsibility lands. The EBA and ESMA Joint Guidelines of 27 June 2024 require named members of the management body and qualifying shareholders of providers and asset-referenced token issuers to be assessed for repute, knowledge, skill and experience. Article 68 of Regulation (EU) 2023/1114 requires the management body to be fit and proper, requires staff to hold adequate knowledge and expertise, and requires at least one director resident in the Union. Articles 15 and 26 put civil liability for a white paper that is not complete, fair and clear on the issuer and on the members of its administrative, management or supervisory body, with no contractual exclusion available. The supervisor is not assessing a policy document. It is assessing people, and then holding them there.
That is why the outside-counsel model that carried most companies through the gate stops working immediately after it. The panel firm that wrote the programme of operations does not attend the supervisory meeting eighteen months later. It does not hold the reverse-solicitation evidence file, it does not sit on the change-of-officer notification when the head of the digital-asset unit leaves, and it is not the person the AMF or BaFin writes to. In Sartori’s Paris mandate telemetry, 6 of the 19 in-house searches closed over the trailing three years were digital-asset or payments regulatory seats, and in 4 of those 6 the requisition was raised only after a supervisory query or an authorization-file follow-up had already arrived. The seat was created by a letter, not by a plan.
One-off engagementStanding accountability
- Application file Perimeter analysis, programme of operations, policies and governance map. Bounded work, an obvious external brief, and an end date everyone can see.
- Authorization decision Named individuals are assessed and attached to the permission. The company acquires a supervisory counterparty and a register entry in its own name.
- Standing conduct Disclosure liability, distribution evidence, resilience testing and change notifications, running until the permission is surrendered. No end date, and a name on it.
A wind-down under supervision is not a smaller compliance job than a license. It is the same job, with a worse ending.
Six duties that arrive with the permission and never leave it.
A general counsel scoping this hire should not describe it as crypto work. It is a licensing perimeter, a disclosure liability, a distribution evidence trail and an operational-resilience programme, all attached to the same permission and to the same named people.
The regulator assesses a person
Joint Guidelines of 27 June 2024 put named management-body members and qualifying shareholders through a repute, knowledge and experience test. A company cannot answer that with a panel firm.
Liability does not delegate
Articles 15 and 26 place white-paper civil liability on the issuer and its management body and bar contractual exclusion. Sign-off has to sit with someone who can refuse it.
Evidence beats opinions
The reverse-solicitation exemption is documentary. Whoever holds it has to reconstruct, client by client, who initiated contact, long after the person who wrote the memo has moved on.
Two rulebooks, one product
DORA has applied to licensed providers since 17 January 2025. Payments law meets MiCA at e-money tokens. The reading is continuous and it is not a crypto-only skill.
The supervisor can change
Crossing three of five significance criteria under Delegated Regulation (EU) 2024/1506 moves an issuer to EBA supervision and a supervisory college. The counterparty gets more senior overnight.
The text is already moving
The European Commission opened a targeted review on 20 May 2026 that runs to 30 September 2026, feeding the mandatory Article 140 and 142 report. Institutional memory has to live somewhere.
Why the reverse-solicitation line is the one that keeps people awake
Of the four duties, the exemption in Article 61 is the one most often mistaken for a commercial arrangement. It is not. ESMA’s final report of 17 December 2024, issued under Article 61(3), confirms that only authorized providers, or certain EU-authorized financial entities acting by notification, may provide crypto-asset services in the Union, that third-country firms are otherwise prohibited, and that the sole exception is a service initiated at the client’s own exclusive initiative — an exception ESMA says cannot be assumed and cannot be used to circumvent the regulation. The AMF restated the point in its own notice of 23 June 2026 and the CSSF in its notice of 2 July 2026, both naming email, advertising, banners and social media as solicitation.
Read as a legal question it is settled in a paragraph. Read as an operational question it is a permanent records problem, because the burden of proof runs the wrong way and the proof has to survive turnover. A chief compliance officer at an authorized custodian told Sartori that the difficult part of the license had not been obtaining it, but demonstrating eighteen months later that a client in another member state had made first contact — a fact that lived in a former colleague’s inbox. Across the same Paris interview cohort, 27 of the 61 respondents inside regulated financial, payments and digital-asset institutions, over a 24-month window, said the evidence duty sat with a function that had no dedicated headcount attached to it.
The second duty that resists delegation is disclosure. Paul Hastings, writing on the white-paper regime, makes the mechanical point that no supervisor reviews a white paper for accuracy before publication, which means the disclosure standard is self-executing from the moment of publication and the liability in Articles 15 and 26 attaches to the issuer and its management body without a contractual escape. Issuers whose tokens were already trading had until 23 December 2025 to bring existing white papers up to the new standard or face removal from licensed EU venues, with revision required on material change thereafter. A head of legal at a Paris-headquartered payment institution described being handed a white paper drafted by a product team for signature, and refusing until the sign-off route was written into the legal mandate rather than assumed.
The third is resilience. DORA has applied to licensed providers since 17 January 2025, which adds an ICT and third-party register obligation on top of the conduct rulebook, and the AMF put cyber-risk management and DORA implementation first among the three post-authorization supervisory priorities it published for 2026, ahead of promotional-communication compliance and prudential requirements. That is a specific, published statement of what a French supervisor intends to look at, and it maps directly onto what a company should be hiring for.
| Duty | Instrument and date | Who is exposed | Cadence |
|---|---|---|---|
| Fit and proper standing | EBA/ESMA Joint Guidelines, 27 June 2024 | Named management-body members and qualifying shareholders | At authorization, on every change of control or officer, and on request |
| White-paper civil liability | Articles 15 and 26, Regulation (EU) 2023/1114 | The issuer and the members of its management body; no contractual exclusion | On publication, on material change, and on the annual disclosure cycle |
| Reverse-solicitation evidence | ESMA final guidelines under Article 61(3), 17 December 2024 | The entity, in every EU market it touches | Per client relationship, continuously, and reconstructable years later |
| Operational resilience | DORA, applied to licensed providers from 17 January 2025 | The entity and its ICT third-party register | Continuous, with incident reporting and resilience testing |
| Prudential and promotional compliance | AMF supervisory priorities for 2026, published January 2026 | The licensed French entity | Ongoing supervision, sampled by the regulator without notice |
| Escalation to EBA supervision | Commission Delegated Regulation (EU) 2024/1506 | Issuers crossing three of five significance criteria | On threshold breach, then permanently under a supervisory college |
The buyer is a supervised institution, not a start-up.
The stereotype of this hire is a crypto-native exchange filling a compliance box. The register says otherwise: a large and growing share of the licensed population is banks, brokers, asset managers and payment institutions, and those employers put the seat inside an existing legal department with an existing reporting line.
Ledger Insights counted 36 of the 177 CASP licenses awarded across the EU in the hands of banks as of 10 April 2026, as a Spanish banking group became the sixth in its own market to hold one. Outrun Advisory’s register dashboard, updated 21 August 2026, splits the licensed population a second way: 209 crypto-native firms against 124 entrants from traditional finance, with banks and credit institutions at 41 of the total, investment firms, brokers and asset managers at 43, and payment and e-money institutions at 8. Those are two different cuts of the same register on two different dates, and both point the same way. The digital-asset permission is migrating into institutions that already have a general counsel, an internal audit function and a board that reads regulatory correspondence.
Germany is where that migration is easiest to see. Sixteen new licensed institutions were granted authorization by the German regulator in the fourth quarter of 2025 alone, and the cost of the file — set out in section 06 — has worked as a filter rather than a barrier. Deutsche Bank, Commerzbank and Landesbank Baden-Württemberg have moved into the regulated market on that basis; Germany’s second-largest lender secured a retail crypto-trading license reported in mid-January 2026 for rollout through its cooperative-bank network, and the savings-bank group was targeting a retail rollout by the summer of 2026. Each of those units needs an owner of its own license file who is not simply borrowed from the parent institution’s existing compliance function.
That distinction is the one companies get wrong most often. A general counsel at a bank-owned digital-asset unit told Sartori that the parent bank’s financial-crime function could read the AML file competently and had no view at all on the authorization file, and that the two documents had different owners sitting in the same building. The parent’s permissions and the unit’s permissions are separate objects. Conflating them is how a change-of-officer notification gets missed.
| Buyer | What the unit does | Where the seat reports | What the file looks like |
|---|---|---|---|
| Bank-owned digital-asset unit | Custody, brokerage and tokenized-asset services alongside a supervised balance sheet | Group general counsel, with a dotted line to the unit chief compliance officer | A license file that must not contaminate the parent bank's own permissions |
| Payment institution or e-money issuer | E-money tokens and payment rails where MiCA and payments law meet | Head of legal, often the only regulatory lawyer in the company | Two rulebooks read against one product, and one person reconciling them |
| Authorized exchange or broker | Trading venue, order handling, market-abuse surveillance and client assets | General counsel or chief compliance officer, second line of defense | Conduct, listings and surveillance under continuous supervision |
| Custodian or infrastructure provider | Safekeeping, staking and settlement for institutional clients | Head of legal, with the operational-resilience remit attached | Client-asset segregation plus a DORA third-party register |
| Stablecoin issuer | Reserve management, redemption at par, white-paper disclosure | General counsel, with sign-off authority written into the mandate | Personal liability on disclosure, and a supervisor that can change |
| Asset manager or corporate treasury | Tokenized funds, treasury exposure, or a distribution relationship with a licensed venue | Chief legal officer, usually adding this to an existing regulated-products remit | Perimeter analysis first: whether the company needs a license at all |
Demand for the people who staff these files is now visible in the hiring data rather than only in anecdote. Tiger Research, sampling 2,932 active crypto job postings on 18 June 2026, found compliance and legal roles at 10.4 percent of the total — 305 postings, the second-largest category after engineering — and at 16.0 percent of the 904 postings at centralized exchanges. The report notes that the category was not tracked as a separate line item in the same researchers’ 2023 edition, and attributes the growth to the licensing mandate, naming European exchanges and asset managers as having expanded compliance teams over the same period. A hiring category that did not exist as a line three years ago is now the second largest in its market.
Two European seats, built by two different regulators.
The same permission produces a different job depending on which authority granted it and what the parent company already is. Paris is a supervisory-relationship seat next to the coordinating regulator and a stablecoin issuer. Frankfurt is an institutional-integration seat inside banks and market infrastructure.
France ran the hardest version of the cutover. Finance Magnates reported that roughly 90 operators in the country had no license at the 1 July 2026 deadline, against an AMF regime in which providing services without authorization carries criminal exposure of up to two years and a €30,000 fine, and in which the regulator can publish blacklists and have unauthorized websites blocked. The AMF also told the market, before the deadline, that a complete authorization file still takes up to four months to review and that most initial filings require clarification or modification. For a general counsel that is a planning fact rather than a legal one: the license is not a thing you can acquire in the quarter you decide you need it.
Paris also carries the two institutions that make the seat unusually senior. ESMA is headquartered there, and France’s prudential authority, the ACPR, issued the electronic-money institution license on 1 July 2024 that made the first major global stablecoin issuer compliant across the Union on the day the stablecoin rules took effect — a French subsidiary carrying an EU-wide obligation for a US parent. The AMF’s own published priorities for 2026 name three things it will supervise after authorization: cyber-risk management and DORA implementation including the information register, compliance of promotional communications, and compliance with prudential requirements. A specification written against those three lines will find a different shortlist than one written against the word crypto.
Home authorityEuropean supervision
- National competent authority The authorization is granted and supervised at home. Correspondence, inspections and change notifications run in the national language and the national style.
- Significance review A token issuer is measured against the delegated criteria on reserves, holders, transactions, interconnection and cross-border activity. The classification is not something the issuer chooses.
- European supervision Direct or joint supervision by the European Banking Authority, with a supervisory college, higher capital buffers and more frequent reserve attestations. A more senior counterparty, permanently.
That ladder is the reason a stablecoin issuer’s general counsel is buying a different profile from a custodian’s. Under Commission Delegated Regulation (EU) 2024/1506, an asset-referenced or e-money token becomes significant on meeting at least three of five criteria, including a reserve or market value above €5 billion or more than 10 million holders. Crossing it moves direct supervision of asset-referenced tokens, and joint supervision of e-money tokens, to the European Banking Authority, which establishes and chairs a supervisory college. The company does not change; its regulatory counterparty does, and the person who has been managing a national relationship suddenly needs to manage a European one.
A supervisory-relationship seat: one authority, one language, and a company that is usually the EU entity of a larger group.
- The employer shape. A licensed French entity carrying an EU-wide obligation for a non-EU parent, or a payment institution adding token services to an existing permission.
- What the specification asks for. Working French and English, direct experience of the authorization file, and the ability to be the named liaison with regulators and auditors rather than the coordinator of external advisers.
- Where Sartori’s numbers come from. 19 in-house searches closed in Paris over the trailing three years, at a 93 percent completion rate, with counter-offer incidence at 29 percent and a median of 15 working days from offer to signature.
- The realistic timeline. 4 to 7 months on this line, and on the digital-asset subset the fit-and-proper notification for the named individual, not the shortlist, is what sets the start date.
An institutional-integration seat: a bank or a market-infrastructure group folding a licensed digital-asset unit into an existing governance structure.
- The employer shape. A bank-owned unit, a custodian, or consolidating market infrastructure. Boerse Stuttgart Digital and tradias announced a merger on 13 February 2026 with roughly 300 combined staff and dual headquarters in Frankfurt and Stuttgart.
- What the work is. Folding two license files and two compliance functions into one governance structure, without contaminating the parent institution’s existing permissions.
- What the specification asks for. German and English, MiCAR alongside MiFID II, market-abuse and trade-surveillance exposure, and comfort operating as second line of defense next to an established audit function.
- Why it is a different candidate. The Paris file rewards regulator-facing seniority; the Frankfurt file rewards someone who has survived an internal integration and can hold a position against a parent-company committee.
On the digital-asset seats we closed, the fit-and-proper notification for the named individual, not the shortlist, decided when the person could start.
What the permission costs to hold, and what the seat behind it pays.
Published compensation for this exact seat is thin, and inventing a band would not help anyone. What is published is the cost of the license itself and the shape of the specifications companies are writing, which together tell a general counsel more than a salary survey would.
Start with the license, because it is the number a board has already seen. Cointelegraph reported implementation costs of €350,000 to €600,000 for crypto companies going through the regime in 2026, alongside a general administrative-fine range starting at €5 million or 5 percent of annual turnover and rising for stablecoin-related breaches; the Czech regulator fined an unauthorized operator 118.5 million koruna for operating without a license. In Germany the licensing cost alone was put at €250,000 to €500,000. Against those figures, the marginal cost of a senior in-house owner is not the expensive line on the page. The expensive line is the fine methodology the EBA consulted on from 26 June 2026, which sets statutory maxima at 12.5 percent of annual turnover for infringements by issuers of significant asset-referenced tokens and 10 percent for significant e-money tokens, with responses due on 28 September 2026.
German licensing cost, low end
Manageable for a balance-sheet bank, punishing for a crypto-native start-up, which is why the German register filled with institutions.
Yahoo Finance / Finance markets, 2026 ↗What the published specifications actually ask for
One compensation band for this work is public in the sources this article uses. A large exchange advertised an Associate General Counsel, Institutional Legal role covering the EU and UK regimes at £159,120 to £176,800 a year plus bonus and equity, asking for seven or more years at a financial-services institution or a firm serving one, and naming MiCA alongside MiFID, EMIR and AIFMD as required regulatory ground. The listing has since closed. That is one data point at the senior end, and it should be read as one.
The shape of the seat is better read from the specifications themselves. A stablecoin issuer’s French entity advertised a Paris-based compliance director whose stated job was to be the primary liaison with regulators and auditors for the French company and to ensure compliance with MiCA, DORA and other EU frameworks, requiring fifteen or more years in cybersecurity, technology risk or IT governance within financial services and fluency in both French and English. A Vienna-headquartered exchange advertised a regulatory compliance team lead at seven or more years, with a degree in law, finance or business, MiCAR and MiFID II subject-matter expertise, market-abuse and trade-surveillance experience, full fluency in English and German, and the role described as a strategic partner to senior management and part of the second line of defense. Neither posting is a lawyer specification in the traditional sense. Both are descriptions of an accountable owner.
The payments rulebook is being rewritten on its own timetable, and the PSD3 package is a separate file with a separate perimeter that touches this one at e-money tokens — which is the single clearest reason payments regulatory lawyers convert into this seat more readily than any other adjacent group. Sartori’s Paris in-house telemetry puts counter-offer incidence at 29 percent across the trailing three years and the median offer to acceptance at 15 working days. On the digital-asset and payments subset of those closed searches, the counter-offer that mattered was rarely money: in three of the six, the employer came back with an expanded remit — sign-off authority, a direct line to the board, a headcount — because the candidate had told them the seat as scoped could not carry the liability it was being handed. Sartori’s quarterly survey has run since 2019; in three of the four most recent Paris waves, heads of legal at supervised institutions ranked a named internal owner of the license above headline compensation when scoping this hire.
Scope the seat against the duties, not against the word crypto.
A specification built on the technology attracts candidates who have read about the technology. A specification built on the six standing duties attracts the four or five people in the market who have carried them, and tells you which of your own committees still has to be moved before the hire can work.
| Stage | What ends at authorization | What starts at authorization |
|---|---|---|
| Perimeter and structure | The advice on which entity applies, in which member state, for which services | Living with the choice: passporting notifications, entity changes, group reorganizations |
| The application file | Programme of operations, policies, governance map, submission and follow-up questions | The supervisory relationship that opens the day the authorization is granted |
| People | Fit-and-proper documentation for the individuals named at the point of application | Every subsequent appointment, departure and change of control reopens the assessment |
| Disclosure | The white paper as published | Civil liability on the management body, annual updates, revision on material change |
| Distribution | The legal opinion on reverse solicitation | A per-client evidence trail that must survive a supervisor reading it years later |
| The rulebook itself | Compliance with the text as it stood at authorization | A review consultation that runs to 30 September 2026 and may reopen the text |
The four questions worth asking before the requisition opens
Who signs. Name the individual who will hold sign-off on a white paper or a material disclosure change, and write the escalation route into the mandate rather than into a policy. Articles 15 and 26 do not recognize an arrangement in which the product team drafts and the legal function initials.
Who answers the supervisor. Decide whether the named contact for the AMF, BaFin or the CSSF is an employee or an adviser. The regulator will form a view of that person, and the EBA and ESMA suitability guidelines mean the view is formal rather than social.
Who holds the evidence. Reverse-solicitation records, ICT third-party registers and change notifications all have to be reconstructable after the people who created them have left. That is an ownership question, and it is the one most often answered with a shrug.
What happens if the classification changes. If the business could cross the significance criteria, the seat has to be senior enough to manage a European supervisory college rather than a national inspection. Hiring for today’s counterparty and discovering tomorrow’s is an expensive way to learn the difference.
What our own data does not show
Two things, and both cut against the easy version of this story. First, our own speed. Of the 6 digital-asset and payments regulatory seats inside the 19 in-house searches Sartori closed in Paris over the trailing three years, 3 ran past six months — the slow end of our own 4-to-7-month band — and not because the shortlists were thin. The fit-and-proper notification for the named individual set the start date in every one of them, and no amount of search work compresses a supervisory clock. A company that budgets a quarter for this hire will be wrong by a quarter.
Second, coverage. Sartori maps roughly 9,000 lawyers in Paris, and that mapping is built on admitted lawyers. A material part of the second-line population that actually staffs these files — regulatory compliance leads, surveillance specialists, technology-risk officers — is not admitted at all, which means our view of this particular seat is partial by construction and we say so before a client discovers it. The 93 percent completion rate we quote for the Paris in-house line is a fact about the searches we accepted, not a claim that every version of this seat is fillable.
Common questions about MiCA digital-assets regulatory counsel
What does MiCA regulation require a company to keep in-house after the transition closed?
Four duties survive the authorization decision: fit-and-proper standing of named individuals, white-paper civil liability, reverse-solicitation evidence, and DORA operational resilience. None of them is a filing. The EBA and ESMA Joint Guidelines of 27 June 2024 assess named members of the management body and qualifying shareholders for repute, knowledge and experience, so the regulator is looking at a person, not only at an entity. Articles 15 and 26 of Regulation (EU) 2023/1114 put civil liability for a defective white paper on the issuer and the members of its management body, with no contractual exclusion. ESMA’s reverse-solicitation guidelines require a documentary trail proving each EU client relationship was client-initiated. DORA has applied to licensed providers since 17 January 2025. All four run continuously, which is why they land on a payroll rather than on a retainer.
How many firms actually hold a MiCA authorization?
TRM Labs counted 281 authorized providers out of 1,343 operating in the EEA when the transition closed on 1 July 2026 — roughly one in five. Two months later, the ESMA-sourced register tracked by casptracker.eu showed 331 authorized crypto-asset service providers across 30 EU and EEA markets and 26 national regulators, verified on 2 September 2026, with Germany at 76 and France at 35. Read one dated snapshot at a time: the register is a moving list of live authorizations, not a cohort you can difference between two dates. The direction is stable in every count — a small licensed population, and a much larger population that exited, stalled or restructured.
Who is personally exposed if a crypto-asset white paper turns out to be wrong?
The issuer and the members of its administrative, management or supervisory body, under Articles 15 and 26 of Regulation (EU) 2023/1114, with no contractual exclusion available. Paul Hastings notes that no supervisor vets a white paper for accuracy before publication, so the disclosure standard is self-executing: the burden sits with the issuer from the moment of publication. Existing tokens already trading had to bring their white papers up to the new standard by 23 December 2025 or face removal from licensed EU venues, and material changes require revision after that. That converts a launch document into a governance cadence, and it is the reason sign-off authority has to sit with someone empowered to refuse.
Does reverse solicitation let a non-EU firm keep serving EU clients?
Barely. ESMA’s final guidelines of 17 December 2024 read the Article 61 exemption narrowly: the client must initiate, and any EU-directed marketing by the firm ends it. The guidelines state that the exemption cannot be assumed and cannot be used to circumvent the regulation. Advertising, banners, affiliate outreach and social posts aimed at the Union all count as solicitation, and both the AMF on 23 June 2026 and the CSSF on 2 July 2026 restated that point in their own notices around the deadline. In practice the exemption is an evidence problem: whoever owns it has to be able to show, client by client, who made contact first — which is record-keeping with a supervisor at the end of it.
What does a digital-asset regulatory seat pay, and where does it sit on the org chart?
One published band exists in the sources this article uses: Coinbase advertised an Associate General Counsel role covering MiCA at £159,120 to £176,800 plus bonus and equity, and the listing has since closed. Below that, the shape is readable from live specifications rather than from salary surveys. Circle’s French entity advertised a Paris-based compliance director required to act as primary liaison with regulators and auditors across MiCA and DORA, with 15 or more years of experience and working French and English. A Vienna-headquartered exchange advertised a regulatory-compliance team lead at seven or more years, with MiCAR and MiFID II subject-matter depth and market-abuse surveillance, framed as second line of defense. The seat reports to a general counsel or a chief compliance officer, and on bank-owned units it usually reports twice.
Should a company hire this counsel or leave the work with outside counsel?
Split it by cadence. Outside counsel builds the application; a named in-house owner carries the four standing duties, which run for years. Sartori’s Paris mandate telemetry records 19 closed in-house searches over the trailing three years, and 6 of those were digital-asset or payments regulatory seats. In 4 of the 6, the requisition opened only after a supervisory query or an authorization-file follow-up had already landed — that is, after the company discovered that the file had no internal owner. Retaining the panel firm for first-of-kind questions is sensible and cheap. Retaining it as the permanent memory of a license the regulator expects a named person to stand behind is neither.
Regulator texts, register snapshots and the Paris research programme.
Statutory mechanics come from EUR-Lex and from the ESMA, EBA, AMF and CSSF publications named below. Authorization counts are dated register snapshots from the sources that published them. Cost, penalty and hiring figures are attributed to the outlet or report that measured them, in the sentence that carries them.
Sources & further reading
30 references- Sartori & Partners — Paris Legal Talent Research Programme (250 structured interviews; ~9,000 lawyers mapped; quarterly surveys since 2019; mandate telemetry) sartoriglobal.com ↗
- ESMA — ESMA calls on unauthorised crypto-asset service providers to wind down orderly (23 June 2026) esma.europa.eu ↗
- ESMA — ESMA Statement on MiCA Transitional Measures (4 December 2025) esma.europa.eu ↗
- ESMA — Final report on Guidelines on reverse solicitation under MiCA (ESMA35-1872330276-1899, 17 December 2024) esma.europa.eu ↗
- EBA and ESMA — Joint Guidelines on the assessment of suitability of members of the management body and of qualifying shareholders (27 June 2024) esma.europa.eu ↗
- EBA — Consultation Paper on methodology for setting fines under MiCA (EBA/CP/2026/10, 26 June 2026) eba.europa.eu ↗
- EBA — The EBA's supervisory role under MiCA eba.europa.eu ↗
- EUR-Lex — Regulation (EU) 2023/1114 (MiCA), consolidated text eur-lex.europa.eu ↗
- AMF — The AMF reminds Digital Asset Service Providers that the transitional period allowing them to continue providing services is ending (5 February 2026) amf-france.org ↗
- AMF — End of MiCA transitional period: ESMA sets out its expectations for professionals and warns retail investors (23 June 2026) amf-france.org ↗
- AMF — #IMPACT2027 : Priorités d'action et de supervision 2026 (January 2026) amf-france.org ↗
- CSSF — MiCA: Transition period for virtual asset service providers ended on 1 July 2026 cssf.lu ↗
- European Commission — Targeted consultation on the review of the MiCA Regulation (opened 20 May 2026) finance.ec.europa.eu ↗
- Skadden — Fit for Purpose? European Commission Launches Review of MiCA (10 June 2026) skadden.com ↗
- TRM Labs — EU VASPs After MiCA: Authorization Rates and Illicit Exposure trmlabs.com ↗
- casptracker.eu — MiCA license list 2026: ESMA CASP register of compliant crypto firms (verified 2 September 2026) casptracker.eu ↗
- Outrun Advisory — MiCAR dashboard (data updated 21 August 2026) outrun.at ↗
- Ledger Insights — Banks now 20% of MiCAR CASP licensees as CaixaBank joins the list (10 April 2026) ledgerinsights.com ↗
- Cointelegraph — MiCA Transition Ends After Wave of Last-Minute Crypto Licenses (1 July 2026) cointelegraph.com ↗
- Cointelegraph — EU Enters MiCA Enforcement Phase for Crypto Companies (July 2026) cointelegraph.com ↗
- Finance Magnates — Europe's Crypto Market After July 1: Who Stays, Who Leaves, and What Changes Under MiCA (25 June 2026) financemagnates.com ↗
- Paul Hastings — MiCA Crypto White Papers: Comply or Be De-Listed paulhastings.com ↗
- Circle — Circle is First Global Stablecoin Issuer to Comply with MiCA, EU's Landmark Crypto Law (1 July 2024) circle.com ↗
- crypto.news — Tether abandons Europe as MiCA ban wipes USDT crypto.news ↗
- Yahoo Finance — How MiCA Opens the Door for Banks and German Institutions finance.yahoo.com ↗
- MarketsMedia — Boerse Stuttgart Digital, tradias Form European Crypto Champion (13 February 2026) marketsmedia.com ↗
- Coinbase — Associate General Counsel, Institutional Legal (listing since closed) jobs.blockchaincapital.com ↗
- Circle — Director, Security Compliance, France (listing removed 10 June 2026) builtin.com ↗
- Bitpanda — Team Lead, Regulatory Compliance, Vienna jobs.jumpcrypto.com ↗
- Tiger Research — H1 2026 Global Crypto Hiring Market Analysis Report (23 June 2026) reports.tiger-research.com ↗
Authorization counts come from three different publishers reading the same ESMA register on three different dates. The 281-of-1,343 conversion rate is TRM Labs at the 1 July 2026 cutoff; the 331-provider total is the casptracker.eu snapshot verified 2 September 2026; the licensee-type split is Outrun Advisory at 21 August 2026. Cost bands and the Czech penalty are as reported by Cointelegraph and Yahoo Finance and are not regulator-published fees. The single compensation band is one closed job listing. Sartori figures are drawn from the Paris research programme: the interview cohort, mandate telemetry over the trailing three years, and the quarterly survey running since 2019.
For the adjacent EU regulatory hiring cycle a general counsel is usually running at the same time, see privacy and data-protection hiring in 2026. For how the second-line compliance seat next to this one is banded, see compliance officer salary in 2026. For how we build and check the internal figures quoted above, see the Sartori research programme and our search methodology.
Next steps on the in-house regulatory map.
Is Privacy and Data Protection Law Hiring in 2026?
The other EU regulatory hiring cycle a general counsel is running at the same time, and why the two seats are not interchangeable.
Read the privacy hiring readCompliance Officer Salary 2026
What the adjacent second-line seat pays, and how a regulated-products compliance function is usually banded.
See the compliance bandsParis Data Center Grid-Ready Land Counsel
The other Paris in-house seat created by a permitting perimeter rather than by deal flow.
Read the Paris land-counsel mapA quiet conversation
Putting a named owner behind a European digital-asset permission?
We map in-house regulatory counsel across Paris, Frankfurt and the wider EU licensed population, and we are as willing to tell a general counsel that a seat is scoped wrong as to open a search on it. Confidential, no obligation.