Highlights

  • The European Commission adopted a delegated regulation on September 8, 2026 extending its Central Contact Point framework to crypto-asset service providers.
  • CASPs become subject to the rule once their cumulative EU transaction volume passes €3 million in a financial year.
  • The regulation requires qualifying exchanges to designate a locally based compliance contact for supervisory and AML coordination.
  • The rule takes effect twenty days after publication in the EU's Official Journal, extending obligations previously limited to e-money and payment institutions.

Brussels Closes a Local-Presence Gap for Crypto

The European Commission adopted a delegated regulation on September 8, 2026 extending its “Central Contact Point” framework to crypto-asset service providers, giving national regulators in EU member states the power to require crypto exchanges and other licensed platforms operating locally to designate a dedicated compliance contact inside their jurisdiction. The rule amends existing technical standards that, until now, applied only to electronic money institutions and payment institutions, folding crypto-asset service providers, or CASPs, into the same anti-money-laundering oversight structure used across the rest of the EU's regulated financial sector. The regulation takes effect twenty days after its publication in the EU's Official Journal.

A €3 Million Threshold, and What It Requires

Under the delegated act, a CASP becomes subject to the Central Contact Point requirement once its cumulative transaction volume with EU customers passes €3 million in a financial year, a threshold designed to focus supervisory attention on platforms with a meaningful local footprint rather than every foreign exchange with incidental EU users.

Once that threshold is crossed, a national regulator can compel the exchange to appoint a named local contact person who can respond to supervisory requests, coordinate with anti-money-laundering authorities, and serve as the platform's point of accountability inside that member state, mirroring obligations already long-standing for e-money and payment firms operating cross-border in the bloc. The change closes a structural gap regulators had flagged: crypto exchanges could previously serve large EU customer bases from outside the bloc without any locally accountable representative, complicating enforcement and information-sharing during investigations. The Commission's own delegated regulation frames the change as ensuring a consistent approach to appointing contact points and determining their functions across all regulated sectors, rather than treating crypto as a special case.

Part of a Wider Pattern in Brussels

The move fits a broader pattern in Brussels this year of retrofitting crypto-specific obligations onto supervisory machinery originally built for banks and payment firms, rather than writing bespoke crypto rules from scratch — the same approach underpinning ongoing proposals to pull DeFi lending vaults under MiCA's scope.

Related: ECB's Schnabel Says Central Bank Money Must Move Onto Blockchain

For exchanges serving EU customers, the practical effect is added compliance overhead: platforms crossing the €3 million threshold will need to budget for a locally based compliance function, even if their core operations, staff, and infrastructure remain elsewhere. That cost falls hardest on mid-sized exchanges without an existing EU entity, while the largest, already-licensed platforms are likely to have satisfied comparable local-presence requirements under MiCA's broader licensing regime. Enforcement of these adjacent AML obligations has already produced real penalties this year — Austria's first published MiCA case fined Bitpanda €70,000 — underscoring that Brussels is following through on paper rules with actual fines rather than leaving them dormant. For the EU as a bloc, the change is part of a consistent regulatory posture: extend the same anti-money-laundering infrastructure used for traditional finance to crypto rather than build parallel, lighter-touch supervision.

What Comes Next

The delegated regulation enters into force twenty days after its publication in the Official Journal of the European Union, a date that will formally start the clock for national regulators to begin enforcing the Central Contact Point requirement against qualifying CASPs. Exchanges operating near or above the €3 million EU transaction-volume threshold will need to confirm with their home-member-state regulator whether a local contact point appointment is required, and if so, move to designate one before enforcement begins. The rule adds to a growing list of MiCA-adjacent compliance obligations landing on crypto platforms through 2026, alongside parallel proposals on DeFi lending vaults, meaning exchanges serving EU customers should expect the compliance perimeter to keep expanding rather than settle.

FAQ

What is the EU's Central Contact Point requirement?
It requires certain financial platforms operating in an EU member state to designate a locally based contact person who can respond to supervisory and anti-money-laundering requests, a rule the European Commission has now extended to crypto-asset service providers.

Which crypto exchanges does the new rule affect?
Any crypto-asset service provider whose cumulative transaction volume with EU customers exceeds €3 million in a financial year can be required by a national regulator to appoint a local contact point.

When does the rule take effect?
The delegated regulation enters into force twenty days after its publication in the Official Journal of the European Union.

Did this requirement exist for crypto firms before?
No. The Central Contact Point framework previously applied only to electronic money institutions and payment institutions; the September 8, 2026 delegated act is what extends it to crypto-asset service providers.