MiCA Travel Rule: What CASPs Must Have by July 2026

The MiCA Travel Rule demands verified identity data on every crypto transfer. Most CASPs are still unprepared for the July 2026 deadline.

Emily Carter
By Emily CarterAI Strategy Consultant at Joinble
·10 min read
Share
MiCA Travel Rule: What CASPs Must Have by July 2026
imageUse this imagedownloadDownload

Six weeks from today, on July 1, 2026, the MiCA transitional window shuts for good. In the EU, any crypto-asset service provider (CASP) still without MiCA authorization must stop operating. Extensions do not exist. Nested inside that licensing cutoff is a second duty that plenty of compliance teams continue to underrate: the Travel Rule.

December 2024 is when the Travel Rule became technically binding. A large share of CASPs still have not put it into operation. Wiring the obligation into production is more demanding than it first appears. No single messaging standard exists for the industry. Supervisors — France, Germany, and the Netherlands in particular — have already made plain that they will wait no longer.

What the Travel Rule actually demands, the points at which most CASPs fall short, and the work required to close that gap ahead of July 1 are laid out below.

What the MiCA Travel Rule Actually Requires

Regulation (EU) 2023/1113, the recast Transfer of Funds Regulation (TFR), is how the Travel Rule is given effect in the EU. CASPs must collect, verify, and send originator and beneficiary information with every crypto-asset transfer under that instrument.

The data that must travel with every transaction

The sending CASP has to pass the following to the receiving CASP on any crypto-asset transfer:

Field Required
Originator full name Yes
Originator account number (wallet address) Yes
Originator address, date of birth, or national ID Yes
Beneficiary full name Yes
Beneficiary account number (wallet address) Yes

The EU sets no minimum threshold. Only transfers above USD 1,000 fall under the FATF standard. From the first euro, the EU TFR applies. That difference is materially stricter than the global baseline, and it is the clause compliance teams most often misread after they designed systems around FATF thresholds.

The self-hosted wallet problem

Whenever a transfer involves a self-hosted wallet — private wallets such as Ledger or Trezor that a regulated entity does not manage — friction spikes. Should a customer want to withdraw more than €1,000 to a self-hosted wallet, the CASP has to confirm that the customer owns or controls it.

Asking for a signed message from the private key (cryptographic proof of ownership), or taking an on-chain micro-transaction from the wallet concerned, is what that confirmation usually means in practice. Each method needs technical infrastructure that many CASPs still lack. Each also produces friction that users push back against.

Collecting data for hosted-wallet transfers while skipping self-hosted wallet verification is not compliance; it is partial compliance. Supervisors treat both categories the same way.

How MiCA has rewritten KYC duties across crypto is surveyed in our State of KYC in Crypto 2026 report, which covers the full landscape of what changed since December 2024.

Why Technical Integration Has Been So Difficult

Infrastructure, not regulatory intent, is the real bottleneck. Structured data must move between institutions under the Travel Rule, yet the EU has not mandated an interoperability standard.

TRISA, OpenVASP, Sygna, and others already exist as messaging protocols. Adoption varies by jurisdiction. When the sender runs TRISA and the receiver runs Sygna — or runs nothing — the transfer either cannot proceed in a compliant manner, or it proceeds non-compliantly by default.

The sunrise problem

People sometimes label this the "sunrise problem": even if the receiving institution is not ready to take the data, the Travel Rule duty still applies. One CASP is trying to comply; the other has no Travel Rule infrastructure. Under the regulation the sending CASP may refuse the transfer — though that refusal carries its own compliance and commercial risk.

Sending CASPs, AMLA has indicated, should record their attempts to transmit data and keep logs of receiving-side failures. "We tried and they could not receive" can be defended. "We didn't try" cannot.

The KYC data quality problem

Messaging is only one layer. A deeper quality issue sits underneath. Originator KYC data on file has to be complete, verified, and transmissible for Travel Rule compliance. Lightweight enrolment — a scan here, a selfie there — leaves a hole the Travel Rule exposes at once.

So this is not merely a transmission problem. It is a KYC quality problem. CASPs that onboarded customers with lightweight verification in earlier years now carry a retroactive compliance liability: verified data they never collected cannot be sent.

What Regulators Are Already Doing

July 2025 is when the Anti-Money Laundering Authority (AMLA) became operational; since then it has set clear expectations for CASPs across member states. AMLA's full regulatory mandate is analysed in our article on AMLA and EU crypto KYC compliance.

National supervisors did not wait for AMLA to move first:

  • France (AMF): Travel Rule enforcement has been running since Q1 2026. During licensing reviews, CASPs unable to show compliant data transmission are being denied authorization.
  • Germany (BaFin): Specific guidance issued in March 2026 requires CASPs to document their Travel Rule solution — not merely assert compliance, but present the technical architecture, tested against real transfer flows.
  • Netherlands (DNB): Administrative fines have been issued to exchanges for systematic Travel Rule non-compliance on cross-border transfers to non-EU counterparties.

Enforcement is underway. The fines are real. CASPs that expected regulatory tolerance to last past July 1 now face a fundamentally different risk calculus.

The Compliance Gap in Numbers

Industry data available through Q1 2026 shows:

  • Approximately 35% of EU-registered CASPs have not fully operationalized Travel Rule data transmission for outbound transfers
  • Self-hosted wallet verification is missing from roughly 60% of CASP withdrawal flows that include crypto withdrawal capabilities
  • Automated name matching — checking that beneficiary names correspond to KYC records at the receiving institution — is in place at only 40% of CASPs

None of these are edge-case shortfalls. They describe a large slice of the industry still sitting in a pre-compliance posture more than 18 months after the regulation took full effect.

How Automated KYC Closes the Gap

CASPs that hit Travel Rule compliance on schedule tend to share one trait: they built or adopted identity infrastructure that treats KYC data as structured, transmissible records rather than static documents.

Three practical implications follow:

Complete verified identity at onboarding. Fully verified originator data at onboarding is ready to travel with every later transaction. Loosely collected data is not. No shortcut exists around this step.

Ongoing identity monitoring. Travel Rule compliance is not a one-off. Customer data expires. Documents lapse. Risk profiles shift. Monitoring systems have to flag stale transmitted data before a transaction fires the obligation.

Self-hosted wallet verification built into withdrawal flows. Manual exceptions will not suffice. A withdrawal to a self-hosted wallet above €1,000 should automatically trigger the verification step inside the transaction workflow.

Agentic identity infrastructure — systems that autonomously monitor, verify, and maintain customer identity records across their full lifecycle — is where this stops being a competitive edge and becomes a compliance requirement. How those systems work in practice is covered in our article on agentic KYC and AI agents for compliance.

That model is what Joinble's AI Agents are built around: continuous identity verification that holds compliance posture across the entire customer lifecycle, not only at onboarding. By the time a transfer starts, the identity data is already verified, current, and structured for transmission.

What Happens After July 1

Travel Rule non-compliance on July 1, 2026 is not an abstract risk:

Scenario Consequence
Unlicensed CASP, transitional period expired Must cease EU operations immediately
Licensed CASP, Travel Rule non-compliant Subject to administrative enforcement
Licensed CASP, incomplete self-hosted wallet verification Targeted enforcement for those transactions
CASP transmitting unverified originator data Sanctions, potential license review

Fines under the AMLR can reach €5,000,000 or 12.5% of annual turnover, whichever is higher. A CASP generating €40 million in annual revenue therefore faces a maximum fine of €5 million per enforcement action.

Doing the work correctly costs a fraction of that. Firms that invest now pay once. Firms that wait pay twice — emergency remediation plus the penalties that pile up while they scramble.

For CASPs in real-world asset tokenization, the stakes stack further. Travel Rule duties sit on top of existing securities regulation, and identity verification is already load-bearing infrastructure for RWA compliance. Those layered obligations are covered in our analysis of KYC in asset tokenization.

July 1 is not the sole date on the calendar. EU Member States must implement AMLD6's beneficial ownership registry rules on July 10, 2026 — extending UBO verification requirements to non-EU entities and mandating five years of historical ownership data. CASPs serving complex corporate clients will have to satisfy both sets of duties at once.

A parallel domestic deadline applies to CASPs in the UK: the Money Laundering and Terrorist Financing (Amendment) Regulations 2026 take effect June 30, with new EDD rules for correspondent relationships arriving in February 2027. UK and EU obligations run in parallel, not identically — threshold structures now diverge, and compliance documentation has to be kept separately for each jurisdiction. The full breakdown is in our article on UK AML 2026 and the new crypto rules.

FAQ

Does the Travel Rule apply to transfers between two wallets at the same CASP? No. Different regulated CASPs exchanging value is the scope of the Travel Rule. Originator and beneficiary data transmission is not required for internal transfers inside the same institution.

What is the minimum threshold for Travel Rule compliance in the EU? None exists. All crypto-asset transfers, from the first euro, fall under Regulation (EU) 2023/1113 regardless of amount. That is stricter than the FATF threshold of €1,000, which does not apply in the EU context.

What happens if the receiving CASP has no Travel Rule infrastructure? A regulatory dilemma lands on the sending CASP. Refusing the transfer is compliant but commercially damaging; proceeding without the required data is non-compliant. AMLA guidance points sending CASPs toward documenting transmission attempts and retaining records of receiving-side failures as evidence of a good-faith compliance effort.

Does the Travel Rule apply to transfers to self-hosted wallets? Yes. Transfers exceeding €1,000 to or from a self-hosted wallet require the CASP to verify that the customer owns or controls the wallet. Transfers below €1,000 to self-hosted wallets fall under standard record-keeping requirements.

What messaging protocol should CASPs use for Travel Rule data transmission? No specific protocol is mandated by the EU regulation. TRISA, OpenVASP, Sygna, or any interoperable solution may be used. What matters is that verified originator and beneficiary data reaches the counterparty institution securely before or simultaneously with the transfer.

Can CASPs get an extension on Travel Rule compliance past July 1? No. Closure of the MiCA transitional period is marked by the July 1, 2026 date. France, Germany, and the Netherlands are among several member states that shut their transitional windows early. The current regulatory framework contains no extension mechanism.

Update — August 2026: Approximately 80% of EU crypto firms failed to obtain CASP authorization once the transitional period closed. Post-MiCA: What 80% Exit Means for Crypto KYC analyses what happened and what licensed CASPs must address now.

Emily CarterEmily Carter
Share

Related Articles

iGaming KYC Under AMLR: The 2027 Compliance Wake-Up
Compliance07 Sep, 2026

iGaming KYC Under AMLR: The 2027 Compliance Wake-Up

The EU AMLR's €2,000 gambling threshold takes effect July 2027. Deepfake attacks in iGaming surged 700% in 2026. Here's what operators must do now.

DORA and KYC: Identity Vendors Are Now ICT Third Parties
Compliance31 Aug, 2026

DORA and KYC: Identity Vendors Are Now ICT Third Parties

DORA's ICT third-party rules apply to KYC vendors from 2025. Here's what financial firms must audit, contract, and monitor to stay compliant in 2026.

SR 26-2: The Governance Gap in AI-Powered KYC
Compliance17 Aug, 2026

SR 26-2: The Governance Gap in AI-Powered KYC

The Fed's new model risk guidance explicitly excludes generative and agentic AI. For banks using AI in KYC, that gap is now a compliance liability.