Data and methodology
Every fact on this site comes from one source: the interim MiCA register published by the European Securities and Markets Authority. This page explains what we do with it, so you can judge how far to trust a page here versus the original.
Source
ESMA publishes five CSV files under Articles 109–110 of MiCA: CASPS.csv (authorised crypto-asset service providers),
NCASP.csv (non-compliant entities), EMTWP.csv and ARTZZ.csv (issuers of e-money and asset-referenced
tokens with their white papers) and OTHER.csv (white papers for other crypto-assets). The files are fed by the national
competent authorities; ESMA does not verify their content. We download them from
ESMA's MiCA page.
Refresh
A scheduled job fetches the files once a day. Each row is compared with what we already hold; differences are written to the change log, dated the day we saw them. ESMA's own "last update" date for each record is shown on the entity's page. Last run: 26 August 2026, 19:24 (ok).
Cleaning
- One page per entity. The CASP file has one row per (provider, batch of services). We merge rows by LEI into one provider, taking the union of services and countries and the earliest authorisation date.
- Services. Most rows label services "a." to "j."; some carry only the text, in varying capitalisation. We map every variant to the ten codes of Article 3(1)(16). Rows we cannot map are kept without a service and flagged in our admin view.
- Countries. Passporting lists are split on the pipe character and reduced to valid EEA codes.
- LEIs are normalised to 20 alphanumeric characters (the file contains trailing dots and 21-character values).
- Websites are split into domains for the check tool. We match the exact host, its parent domain and its subdomains — nothing fuzzier, because "resembles" is exactly the fraud pattern the register exists to defeat.
- Non-compliant entities that appear several times (successive warnings, new domains) are merged into one page, listing every domain named.
- Removed rows are not deleted. An entity that vanishes from the file keeps its page with the status "no longer listed" and the date we last saw it, so that a link keeps meaning something.
What we do not do
- We do not add information from other sources — no company descriptions, reviews, fee comparisons or news.
- We do not rate providers. "Authorised" is the register's word, not ours.
- We do not link to the websites of non-compliant entities; they are shown as text.
- We do not record who searched for what. Search queries are stored without any personal data, to see which names people look for and do not find.
Known limits
- Regulators report with a delay of days to weeks; a freshly authorised provider may not be in the file yet.
- The file has inconsistencies that no cleaning removes with certainty: one country's regulator may list the trading name where another lists the legal entity.
- Withdrawal dates are only present when a regulator entered them. A provider that quietly stops operating stays "authorised" until the entry is changed.
- The register is "interim": ESMA has announced a fuller database. When it arrives, the format will change and so may this site.
Spotted a mistake? Tell us, ideally with the ESMA row in question.