Cyprus Securities and Exchange Commission Circular C790 regarding ML/TF risks following the end of the MiCA Transitional Period

MNK Risk Consulting > Regulatory Developments > Cyprus Securities and Exchange Commission Circular C790 regarding ML/TF risks following the end of the MiCA Transitional Period

Scope:

  • Crypto Asset Service Providers (CASPs)
  • Cyprus Investment Firms (CIFs)
  • UCITS Management Companies
  • Internally Managed UCITS
  • AIFMs
  • Internally Managed AIFs
  • Internally Managed AIFLNPs
  • Companies with sole purpose the management of AIFLNPs
  • Small AIFMs under Law 81(I)/2020

Summary:

CySEC issued Circular C790 highlighting the end of the Markets in Crypto-Assets Regulation (MiCAR) transitional period on 1 July 2026. From this date, firms must be authorised as Crypto-Asset Service Providers (CASPs) under MiCAR to continue providing crypto-asset services in the EU.

CySEC referred to an Advisory Note from the European Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA), which outlines the ML/TF risks arising from the end of the transitional period and the measures expected of both unauthorised Virtual Asset Service Providers (VASPs) winding down their activities and authorised CASPs onboarding migrating customers.

AMLA emphasises that customer migration from unauthorised VASPs to authorised CASPs should be managed through individual risk assessments and proportionate, risk-based Customer Due Diligence (CDD), rather than blanket de-risking.

Key risks include weakened AML/CFT controls during VASP wind-downs, illicit flows and sanctions evasion during abrupt market exits, changes in CASPs’ risk profiles due to higher-risk customer inflows, and increased pressure on transaction monitoring and compliance resources.

CySEC also refers to the FATF Report on Understanding and Mitigating the Risks of Offshore VASPs and urges Regulated Entities to consider these risks within their risk-based AML/CFT frameworks under Law 188(I)/2007.

Implications:

Affected firms should:

  • Identify and assess ML/TF risks associated with relationships, transactions or business activities involving unauthorised or offshore VASPs.
  • Where winding down unauthorised VASP activities, maintain a structured and documented wind-down plan with adequate AML/CFT governance, resources and enhanced monitoring until activities cease.
  • Keep CDD information up to date and continue to identify and report suspicious transactions throughout the wind-down process.
  • When onboarding customers migrating from unauthorised VASPs, conduct individual risk assessments and apply proportionate, risk-based CDD. Avoid blanket de-risking based solely on a customer’s origin.
  • Ensure transaction monitoring systems and compliance resources are capable of managing increased customer volumes and inflows.
  • Strengthen onboarding and risk integration processes, including the appropriate use of incoming customer risk information and enhanced due diligence where higher risks are identified.
  • Review and update the firm’s risk-based AML/CFT framework under the Prevention and Suppression of Money Laundering Activities Law (L.188(I)/2007), as amended, in light of these risks.

Firms should note that responsibility for AML/CFT compliance remains with them throughout and following any customer migration or wind-down process.

Should you need additional information regarding CASPs authorisation under MiCAR or to discuss further your crypto-assets business needs please free feel to contact us.