Anyone who wants to check whether a crypto platform is authorised at all in the European Union sooner or later comes across an official register built for exactly that purpose. The European s
Anyone who wants to check whether a crypto platform is authorised at all in the European Union sooner or later comes across an official register built for exactly that purpose. The European securities regulator ESMA has maintained a register of non-compliant firms since February 2025. It is meant to collect, across Europe, those providers that supply crypto-asset services without the required permission.
We downloaded the register file on August 16, 2026, counted it line by line and called up every web address stored in it individually. The result sits awkwardly beside the European ambition of this register. Of 167 entries, 165 come from a single member state. Germany's BaFin has contributed not one, even though it has been issuing warnings about crypto platforms throughout the current year. And of 242 stored web addresses, 153 no longer answered at all on the day of the survey.
This analysis was carried out by cryptoticker.io itself on August 16, 2026.
The ESMA register of non-compliant providers: what Article 110 of MiCA requires
The legal basis is set out in Regulation (EU) 2023/1114, better known as MiCA. Article 110 is headed "Register of non-compliant entities providing crypto-asset services" and opens with a sentence worth memorising: "ESMA shall establish a non-exhaustive register of entities providing crypto-asset services in breach of Article 59 or 61."
Article 59 is the central authorisation rule. Anyone offering crypto-asset services commercially in the EU needs authorisation as a crypto-asset service provider, or has to belong to one of the few groups that already hold a banking or investment licence. Article 61 governs the special case of a provider from a third country approaching customers in the EU on its own initiative.
Paragraph 2 sets out how thin an entry may be: it must contain at least the trading name or the website of the firm, plus the name of the authority that supplied the information. The regulation demands no more. Paragraph 3 requires that the register be publicly accessible in machine-readable format and updated regularly.
That is precisely where the division of labour shaping this register comes from. ESMA operates the directory, but it does not fill it. The supply comes from the competent authorities of the member states. Whether a country contributes anything is for that country to decide.
167 entries and 162 trading names: the result of the count from August 16, 2026
The file this analysis rests on is called NCASP.csv and sits on ESMA's server. The server timestamp gives August 12, 2026, 8:47 UTC as the last change. The register is republished weekly, so the version we analysed was four days old when we retrieved it.
The file contains 167 entries. Merging spelling variants, 162 distinct trading names sit behind them; some names appear more than once because an authority has taken several decisions on the same offering. Not a single entry carries an identifier that would pin down the legal person behind it: the field for the Legal Entity Identifier is empty in all 167 rows.
The file records 247 mentions of web addresses, spread over 242 distinct addresses. 131 entries make do with a single address; the most extensive lists 15. Among the endings, the Italian country code dominates with 106 addresses, followed by 64 addresses under .com. After that come 17 addresses under .top, twelve under .co, and nine each under .net and .pro.
The decisions the entries rest on run from February 10, 2025 to July 22, 2026. 102 decisions fall in 2025, another 65 in the first seven months of 2026. Two months stand out in this series because not a single decision is dated in them: August 2025 and February 2026. The most recently processed entry carries July 31, 2026 as its update date.
CONSOB, AFM and Národná banka Slovenska: three supervisors supply, the rest do not
The field naming the competent authority is the most revealing part of the file. 165 of the 167 entries come from the Italian securities regulator CONSOB. One entry was contributed by the Dutch supervisor AFM, one more by the National Bank of Slovakia. That makes exactly three supervisory authorities that have ever filled the shared European register.
For comparison: MiCA applies in all 27 EU member states and, through the EEA agreement, additionally in Iceland, Liechtenstein and Norway. Each of those countries has at least one competent authority. So 27 of 30 jurisdictions are represented in the register with zero entries.
A technical detail on the side that gets in the way of any analysis of this file: the name of the Italian authority is recorded in two spellings that differ only by an extra space. Anyone grouping by authority name therefore arrives at four authorities instead of three. We merged the two spellings.
The imbalance allows two readings, and both remain conjecture as long as no authority explains its practice. It is possible that fewer unauthorised offerings are simply identified elsewhere. It is equally possible that the findings are made but not reported to ESMA, because Article 110 sets no deadline and no procedure for transmission. Which of the two explanations applies cannot be read out of the file.
For you as an investor in Germany, the second number is the more important one: zero. Not one entry in the European register comes from the Federal Financial Supervisory Authority.
That expressly does not mean BaFin is inactive. It publishes consumer notices on providers supplying financial and crypto-asset services without permission, and it is doing so at a high frequency in 2026. Our analysis of the BaFin warnings on crypto platform series showed how extensive this national body of material is. It is simply that none of it reaches the European register.
In practice that means: if you look up a doubtful provider in the ESMA register and fail to find it there, you have learned nothing about the German market. A search in the European register does not replace a look at BaFin's own records. At best it adds cases from Italy.

A non-exhaustive register captures only the strip somebody has raked. The rest of the surface stays unchecked and therefore looks unremarkable.
"Non-exhaustive register": why a missing entry is no seal of approval
Those two words from Article 110, paragraph 1 are the legal core of the whole matter. The legislator deliberately set the register up as "non-exhaustive". It therefore makes no claim to capture every unauthorised provider.
That wording is neither an oversight nor a weakness of implementation, but a conscious decision in the text of the regulation. For practice it has an uncomfortable consequence: an entry in the register is a solid warning signal, while its absence is no signal whatsoever. From "it is not in there" it follows neither that a provider is authorised nor that any authority has examined it.
Anyone seeking a statement about a provider's authorisation therefore has to go the other way and look in a positive list. Which providers actually hold a permission in the EU is recorded in a different register, and the question of what else you should look at in a regulated platform we cover in our overview of the best regulated crypto exchanges.
Empty reason field: 166 of 167 entries give no ground
At first glance the register file looks forthcoming and carries twelve columns, among them one for the type of breach and one for its justification. Counting shows that these two columns stay almost entirely without content.
In the column on the type of breach, all 167 rows hold the same value, namely "No". What that value is supposed to mean in context does not emerge from the file; no legend is supplied with it. In the justification column, 166 rows carry the placeholder "None". Exactly one entry contains a written-out sentence, namely the entry from the Dutch AFM, which names a breach of Article 59 of MiCA there.
We deliberately name no company at this point. What stands in an official register is a finding by the supervisory authority concerned; the view of the firm affected is not recorded there, and we cannot obtain it. Anyone who wants to see the name will find it in the register itself, reachable via ESMA's MiCA page.
For usability this has consequences. As a rule, an entry does not reveal what the breach consisted of, whether it is continuing or whether the provider has since responded. A history is missing too: whether and when entries are removed again cannot be discerned from the file.
242 web addresses called up: 153 no longer answer at all
Because the web address is, alongside the trading name, the only solid identifying feature, we called up all 242 distinct addresses individually on August 16, 2026. We measured only whether a server answers and with which status code, with a time limit of ten seconds per address.
47 addresses delivered a regular reply with status code 200, which is 19.4 percent. 153 addresses did not answer at all within the time limit. The remaining cases split into 27 server errors, 19 of them with code 502, plus 13 refusals, twelve of them with code 403. Two addresses got stuck in a redirect.
This measurement says something about the state of the register and little about individual providers. Around two thirds of the officially recorded addresses lead nowhere. For a directory whose practical purpose is to let consumers find a suspicious address again, that is a high share of dead files.
We cross-checked the measurement, because a missing reply can also be down to one's own connection. Four known, reliably reachable addresses answered in the same run and with the same command with code 200. Five addresses drawn at random from the group without a reply stayed silent on a second attempt as well, this time with a browser identifier and a cookie store.

Of 242 addresses recorded in the register, 47 still opened a regular page on the day of the survey.
The positive list is the better test: 329 authorised providers in the CASP register
Alongside the warning list, ESMA publishes a second register, and that one answers the question you probably care about: who holds a permission? We counted this file on August 16, 2026 as well and found 329 authorised crypto-asset service providers from 26 home states in it.
Germany forms the largest group in it: 73 entries name the Federal Republic as home state, followed by France with 35 and the Netherlands with 29. For the question of who may serve you as a customer in Germany, a different figure matters, because an authorisation can be used across Europe: 168 of the 329 entries list Germany as a country in which the service is provided.
How this register breaks down by type of service, and why the number of pure trading platforms turns out considerably smaller, we wrote up in our analysis of the MiCA register from August 6. The figures there refer to one particular type of service and are not directly comparable with the 329 total entries.
BaFin database, ESMA register, warning notices: how to check your provider
From these findings a sequence emerges that can be worked through in a few minutes and that starts with the most informative source.
The positive list first, the warning lists afterwards
Begin with BaFin's company database. It is reachable through the authority's MVP portal and answers, for the German market, the question of whether a firm holds a permission. Check the full company name there, not the brand a platform trades under. The two frequently diverge.
Then take ESMA's CASP register. It additionally shows providers that obtained their authorisation in another member state and may operate in Germany too under the European passport. Only as a third step is it worth looking at the warning lists: BaFin's consumer notices for Germany, and the register of non-compliant entities for the rest of the EU.
A provider you find in neither of the two positive lists is the real warning case. That finding weighs more heavily than any absence from a warning list, because authorisation has to be registered and its absence is therefore meaningful.
Limits of this analysis: what the register does not answer
Four things we could not check, and they should be read along with the rest.
First, a web address failing to answer does not mean the offering behind it has ended. We measured from a single location at a single point in time. A block on certain countries of origin, a move to a new address or a brief outage all look the same in this measurement.
Second, the register does not allow you to determine which legal person stands behind a trading name, because the identifier field is empty throughout. Whether two similar-sounding entries concern the same firm is therefore open.
Third, we asked none of the three supplying authorities, and not BaFin either, for a statement on their reporting practice. Why the register is filled so one-sidedly therefore remains unanswered. This text makes no claim about it.
Fourth, the version analysed is a snapshot from August 12, 2026. The directory grows weekly; anyone calling it up later will see different figures. The method stays the same, and it can be recalculated with the register file at any time.
Reading the EU warning list properly: what to take away
- Treat the ESMA register as a supplement, not as an authority of record. Under Article 110 of MiCA it is expressly non-exhaustive, and for Germany it contains zero entries. Anyone looking for a platform whose authorisation is documented does better with a positive list, and will find an orderly starting point in our overview of the best regulated crypto exchanges.
- Check the company name, not the brand. The register carries trading names and web addresses, but no company identifier. Enter the full name of the operator, which you will find in the legal notice, into BaFin's database, and then match it against the terms in the comparison of the best crypto exchanges.
- Keep your holdings independent of the platform question. Whether a provider is authorised does not decide whether your coins have to sit with it. Anyone wanting to store larger holdings themselves will find the suitable devices in the hardware wallet comparison.
(As of August 16, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)