MiCA Crypto Regulation in Romania

What is the MiCA Regulation – crypto?
The European Union has introduced a transformative regulatory framework through Regulation (EU) 2023/1114, commonly referred to as the Markets in Crypto-Assets Regulation (MiCA). This groundbreaking legislation establishes the first harmonized regulatory approach to crypto-assets across the European Union’s member states, implementing comprehensive requirements for market participants while simultaneously fostering innovation and ensuring investor protection.
This Regulation applies to natural and legal persons, as well as organizations that either create and distribute digital assets to the public, list them for trading, or provide crypto-related services within the European Union. However, the regulation explicitly excludes certain categories from its scope, including unique and non-fungible tokens, financial instruments as defined under existing EU legislation, and specific financial products such as structured deposits, securitization positions, and insurance products.
Talk to a crypto lawyer in Romania today.
Find out how we can help you. Send us a few details about your case, and a representative from our team will contact you as soon as possible.
The regulation provides precise definitions that form the foundation of its regulatory framework. A crypto-asset is defined as a digital representation of value or rights that can be transferred and stored electronically using distributed ledger technology or similar technology. The regulation introduces a sophisticated classification system, distinguishing between various types of crypto-assets, including asset-referenced tokens, which maintain stable value by referencing other assets, and e-money tokens, which reference a single official currency.
Within the European Union, crypto-asset services can only be provided by:
- a legal person or other business entity that has received official authorization to act as a crypto-asset service provider under Article 63 of the Regulation;
- financial institutions including banks, securities depositories, investment companies, trading venue operators, e-money institutions, mutual fund managers, or alternative fund administrators who have permission to offer crypto-asset services as specified in Article 60 of the Regulation.
The regulation establishes a complex authorization regime for crypto-asset service providers. Under Article 59, service providers must obtain authorization from competent authorities before commencing operations in the European Union. The authorization process requires service providers to submit detailed documentation, including: a comprehensive program of operations setting out the types of services to be provided, detailed information about governance arrangements, technical documentation regarding ICT systems and security arrangements. The regulation mandates that service providers maintain adequate prudential safeguards, which must equal to an amount of at least the higher of the following:
- the amount of permanent minimum capital requirements indicated in Annex IV, depending on the type of the crypto-asset services provided;
- one quarter of the fixed overheads of the preceding year, reviewed annually.
Service providers must implement sophisticated governance arrangements that include clear organizational structures, effective risk management procedures, and adequate internal control mechanisms. These arrangements must be regularly reviewed and updated to ensure continued effectiveness and compliance with regulatory requirements. Moreover, crypto-asset service providers authorised in accordance with Article 63 shall have a registered office in a Member State where they carry out at least part of their crypto-asset services. They shall have their place of effective management in the Union and at least one of the directors shall be resident in the Union.
Furthermore, in the case of crypto-assets other than asset-referenced tokens or e-money tokens, the Regulation implements requirements for crypto-asset white papers, which must be published before any public offering or admission to trading. Article 6 of the Regulation specifies that white papers must contain information about the issuer or the person seeking admission to trading, the crypto-asset project, the offer to the public, rights and obligations attached to the crypto-assets, underlying technology, and associated risks. Additionally, white papers must include information about the environmental impact of the consensus mechanism used for issuing the crypto-assets. The white paper must be notified to competent authorities at least 20 working days before publication, allowing for regulatory review. The Regulation also requires that white papers be fair, clear, and not misleading, prohibiting any assertions regarding future value except for specific required risk statements.
MiCA introduces a sophisticated framework for “significant” asset-referenced tokens and e-money tokens as well, which are subject to enhanced supervision by the European Banking Authority. The classification criteria for significance includes multiple quantitative and qualitative factors: the number of holders exceeding 10 million, value exceeding €5 billion, daily transaction volume exceeding €500 million, interconnectedness with the financial system, and the fact that the same issuer issues at least one additional asset-referenced token or e-money token, and provides at least one crypto-asset service. Competent authorities of the issuer’s home Member State shall report to the European Banking Authority and the European Central Bank information relevant for assessing the fulfilment of the criteria set out in the Regulation.
The Regulation also establishes a market abuse prevention framework that mirrors elements of traditional financial markets regulation while adapting to the specific characteristics of crypto-assets. Article 89 prohibits insider dealing, defining it precisely and establishing clear parameters for what constitutes inside information in the context of crypto-assets. The framework also includes sophisticated mechanisms for preventing and detecting market manipulation, requiring market participants to establish and maintain effective systems and procedures. Article 92 mandates that persons professionally arranging crypto-asset transactions must implement effective arrangements to detect suspicious orders and transactions.
MiCA establishes a multi-layered supervisory system that combines national and European Union-level oversight. National competent authorities retain primary supervisory responsibility for most crypto-asset service providers and issuers, while the European Banking Authority assumes direct supervision of significant asset-referenced tokens and e-money tokens. The regulation creates supervisory colleges for significant tokens, facilitating cooperation between national authorities, the EBA, ESMA (European Securities and Markets Authority), and relevant central banks. These colleges serve as forums for information exchange and coordination of supervisory actions, ensuring consistent application of regulatory requirements across jurisdictions.
The regulation implements comprehensive consumer protection measures that address the specific risks associated with crypto-assets. Service providers must implement strict segregation of client assets, maintaining them separately from their own holdings. They must also establish clear procedures for handling client complaints and managing potential conflicts of interest. The regulation grants retail holders a 14-day right of withdrawal for certain crypto-asset purchases (other than asset-referenced tokens and e-money tokens), without incurring any fees or costs and without being required to give reasons, therefore providing an important safeguard against hasty investment decisions. Additionally, service providers must maintain professional liability insurance or comparable guarantees to protect against operational failures or misconduct.
MiCA establishes a detailed sanctioning regime that provides competent authorities with a range of enforcement tools. Administrative sanctions can be substantial, with maximum fines reaching up to 12.5% of annual turnover for significant asset-referenced tokens. The regulation also provides for periodic penalty payments to ensure ongoing compliance with regulatory requirements. Authorities are granted extensive investigative and supervisory powers, including the ability to conduct on-site inspections, access documents and data, and require immediate cessation of infringements. The regulation ensures procedural fairness by establishing clear rights of defense and appeal mechanisms for affected parties.
As the crypto-asset market continues to evolve, this regulatory framework provides the flexibility to address emerging risks while fostering responsible innovation. Regarding the perspectives for the future, the Regulation establishes the possibility of future evolutions. Therefore, the Commission must deliver two evaluation reports regarding the implementation of this Regulation to both the European Parliament and Council. An interim report is due by 30 June 2025, while the final report must be submitted by 30 June 2027. Both reports shall be prepared in consultation with EBA and ESMA. If considered necessary, these reports may be accompanied by legislative proposals.
Last but not least, the regulation’s influence is likely to extend beyond the European Union, potentially serving as a model for crypto-asset regulation in other jurisdictions and contributing to the development of global regulatory standards in this rapidly evolving sector.
What is the MiCA law în 2024 in Romania?
The successful implementation of MiCA will require significant adaptation by market participants and close cooperation between national and European supervisory authorities. Therefore, member states must adopt appropriate legislation în order to implement the provisions of the Regulation and facilitate its application.
The Regulation will apply from December 30, 2024, date by which Member States must adopt appropriate legislation. Although there are only two months left until the deadline set by the Regulation, Romania has not yet adopted any legislative measures to implement the Regulation, however, legislative drafts have been developed with the aim of implementing several requirements set forth by the Regulation.
A draft Government Emergency Ordinance has been published which, when adopted, will substantially changes the legislative framework on preventing and combating money laundering and financing terrorism, with a particular focus on the regulation of crypto active services. This Ordinance updates the definitions, removing the concept of virtual currencies and introducing the concepts of crypto-assets and crypto-asset service providers, aligned with the provisions of Regulation (EU) 2023/1114.
Furthermore, the draft Emergency Ordinance establishes the obligation for providers of crypto active services to apply, in addition to the standard know-your-customer measures, the following measures before establishing a business relationship:
- determining whether the respondent entity is licensed or registered;
- collecting sufficient information about the respondent entity to fully understand the nature of the respondent entity’s business and to determine from publicly available information the reputation of the entity and the quality of supervision;
- assessing the anti-money laundering and counter-terrorism financing measures implemented by the respondent entity;
- obtaining senior management approval prior to establishing each new correspondent relationship;
- documenting the responsibilities of each party to the correspondent relationship;
- in the case of directly accessible crypto-asset accounts, ensure that the respondent entity has verified the identity of the customers who have direct access to the correspondent entity’s accounts and has implemented know-your-customer measures for those customers on an ongoing basis and is able to provide relevant know-your-customer data to the correspondent entity upon request.
Moreover, the draft ordinance stipulates that cryptoasset service providers are obliged to identify and assess the money laundering and terrorist financing risk associated with cryptoasset transfers to or from an undisclosed address. Additionally, under the legislative draft, crypto-asset service providers will fall under the supervision of the Financial Supervisory Authority and the National Bank of Romania with regard to compliance with the regulations set forth in the law on preventing and combating money laundering and terrorist financing (L. no. 129/2029). Another innovative provision of the Ordinance is the requirement for crypto assurance service providers authorized in other Member States to establish a single point of contact on Romanian territory.
Another legislative draft aimed at implementig some of the provisions of the Regulation is a government decision concerning the approval of the procedure authorizing and/or registering providers of services facilitating exchanges between virtual and fiat currencies, as well as providers of digital wallets, and the procedure for granting and withdrawing technical approval.
According to the draft decision all service providers offering exchange between virtual and fiat currencies and those offering digital wallets must be authorized or registered by Romanian authorities. This process includes verifying providers’ compliance with security, transparency and consumer protection requirements. In addition, the Romanian authorities will establish a process to issue a technical approval verifying providers’ technical capabilities, which can be withdrawn if providers fail to meet regulatory standards. Through these authorization requirements, Romania aims to align with the international directives and EU legislation form anti-money laundering/counter-terrorism financing, requiring providers to implement strict policies for users’ identification and transaction monitoring.
The regulation introduces additional protections for consumers, ensuring they have access to clear information on the risks of using cryptocurrencies and digital wallets. The minimum-security standards aim to reduce fraud or cyberattack risks on digital wallets. The draft also includes administrative requirements for providers related to registration, periodic reporting, and capital requirements to ensure operational continuity and transparency.
How do you implement MiCA Regulation in Romania?
Unlike Directives which must be incorporated into national legislation by Member States, Regulations become automatically binding everywhere in the EU on their date of application. However, they may require amendments to national legislation or implementation by national regulatory agencies or authorities, as in the case of the MiCA Regulation.
Therefore, in order to implement the MiCA Regulation, it is necessary to draw up a legislative act establishing the competent authorities at national level and the allocation of tasks/responsibilities in terms of the different categories of crypto-assets, while also taking into account the involvement and competences of the European authorities supervising the banking and non-banking financial markets (EBA, ESMA, ECB).
In addition to establishing competences, the implementation of the MiCA Regulation should also cover the decision on the application of a simplified procedure. According to Art. 143 of the Regulation as an exception to Articles 62 and 63, national authorities may use a simplified authorization procedure for service providers who submit their applications between 30 December 2024 and 1 July 2026, provided these entities were already licensed under their respective national regulations to offer crypto-asset services as of 30 December 2024. Before granting authorization through these simplified procedures, the competent authorities must verify that the applicants comply with the requirements regarding the obligations for all crypto-asset service providers as well as the obligations in respect of specific crypto-asset services.
Service providers in the crypto-asset sector who were legally operating before 30 December 2024 may continue to provide their services until either 1 July 2026 or until they receive a decision on their authorization application under Article 63, whichever is sooner. However, Member States have the authority to either shorten this transition period or eliminate it entirely if they consider that their pre-existing national regulations from before 30 December 2024 is less strict than the requirements set forth in this Regulation.
The two legislative drafts mentioned in the previous section do not cover every aspect of the MiCA Regulation. Therefore, it remains to be seen whether Romania will decide to apply a simplified procedure, as well as whether it will decide to shorten or eliminate the transition period regarding the service providers in the crypto-asset sector who were legally operating before 30 December 2024.
In conclusion, Romania has started taking steps in order to implement the MiCA Regulation. However, in view of the fact that the legislative drafts do not cover every aspect of the Regulation, it is imperative to take further steps in the near future, considering that the deadline from which the Regulation will apply is 30 December 2024.
