On August 25, 2026, the European Union's latest sanctions package against Russia took effect, directly targeting all licensed crypto-asset service providers across Europe. The change doesn't come from MiCA, the sector's primary regulatory framework. It comes from geopolitics. And it shifts the compliance burden for every authorized CASP in ways that many operators haven't fully reckoned with yet.
The development matters because it exposes a gap that even well-run firms can overlook: being MiCA-authorized does not mean being sanctions-compliant. These are two separate regulatory regimes, and confusing them carries serious legal risk.
TL;DR: From August 25, 2026, EU sanctions bar Russian and Belarusian nationals from controlling or directing any MiCA-authorized CASP, not just custody providers. A new tool also lets the EU block crypto operators from dealing with third-country platforms that help circumvent Russia sanctions.
What Changes on August 25
The 21st EU sanctions package, adopted by the Council on July 23, 2026, and reported by the EU Council press office, introduces two specific measures for the crypto sector. The first is an extension of an existing ban. Russian and Belarusian nationals have long been prohibited from owning, controlling, or holding executive positions in certain European crypto firms, but that restriction previously applied only to providers of wallet, account, and custody services. From August 25, the ban covers all MiCA-authorized crypto-asset service providers, including exchanges, trading platforms, portfolio managers, and other licensed categories.
The timing creates an acute compliance challenge. MiCA's transition period ended on July 1, 2026, meaning many firms, including several Italian and other EU operators, obtained their authorization only recently. They now face an immediate obligation to verify that none of their shareholders or senior executives fall under the newly expanded restriction. It's a non-trivial check, and getting it wrong exposes a firm to sanctions violations from day one of its MiCA license.

The Third-Country Tool: The Most Consequential Change
The second measure is strategically more significant. The package introduces a new instrument that allows the EU to prohibit dealings with crypto service providers and platforms located in third countries, meaning outside the bloc, when those countries systematically fail to prevent their infrastructure from being used to evade Russia sanctions.
The reach of this tool is broad. The EU is explicitly reserving the right to cut off entire jurisdictions from crypto-related business relationships if they function as routing channels for sanctions evasion. As of August 25, no country has yet been designated under this mechanism, according to the EU Council. The tool is armed and ready, but hasn't been fired. Its existence alone, though, changes the risk calculus for every CASP: counterparty due diligence now requires assessing not just who you're dealing with, but which country their platform is based in.
The New Crypto Sanctions: What Changes
Effective August 25, 2026. Source: EU Council, legal analysis, 2026
- Extended ban: Russian and Belarusian nationals can no longer control or direct any MiCA-authorized CASP, not just custody service providers.
- Third-country risk: The EU can now prohibit dealings with crypto providers in countries that help Russia circumvent sanctions.
- The core point: MiCA authorization is not sanctions compliance. The two regimes are separate and run in parallel.
MiCA and Sanctions: Two Distinct Regimes
This is where the story carries its sharpest lesson for the industry. There's a widespread assumption that MiCA authorization makes a firm “compliant” in any meaningful regulatory sense. August 25 shows why that assumption is wrong.
MiCA governs how a firm is organized: its governance structure, capital requirements, custody arrangements, and client protections. Sanctions law operates on an entirely different plane. A transaction can be impeccably structured under MiCA and still be prohibited because one party or one jurisdication is sanctioned. Being “MiCA-authorized” and “EU-sanctions-compliant” are not the same thing, and conflating them is a compliance failure waiting to happen. An operator can hold a full MiCA license and still find itself in breach of EU sanctions rules, with no overlap between the two violations.
As SpazioCrypto has previously analyzed in examining the layered obligations of the European crypto market, regulatory compliance is built in strata. Each layer is independent. Passing one doesn't satisfy the others.
What CASPs Need to Do Now
The practical implication for licensed operators across the EU is clear: internal compliance programs must be upgraded. Respecting MiCA's operational rules is no longer enough. Firms now need robust counterparty screening systems capable of identifying sanctioned individuals and entities, and, with the third-country mechanism now in place, assessing the jurisdictional risk of every platform they interact with.
In compliance terminology, this means investing in genuine screening infrastructure, not checkbox tools. The obligation sits alongside existing anti-money-laundering requirements, to which it is closely linked. For smaller operators, this represents a material organizational and financial burden. There's no way around it: operating legally in the EU crypto market in 2026 requires the capacity to manage multi-layered regulatory complexity. That capacity is increasingly what separates serious, institutionally structured firms from those that won't survive the next supervisory cycle.
The Bigger Picture: Crypto Inside Geopolitics
Stepping back, the August 25 measures reflect something larger than a technical sanctions update. They signal a fundamental shift in how crypto is perceived and governed within Europe's broader financial and political architecture. Crypto is no longer treated as a parallel universe with its own isolated rulebook. It is now embedded in the full weight of international financial law, foreign policy, and state-to-state relations.
The lesson for anyone in this sector runs in two directions. The first is that maturity in a financial market means absorbing the complexity that comes with it. Operators in 2026 must be fluent not just in blockchain mechanics and market structure, but in international sanctions law, a field that specialist lawyers spend careers mastering. The second is that the very inclusion of crypto in these geopolitical instruments confirms its systemic significance. Regulators and governments don't target industries they consider marginal. The 21st sanctions package, according to the EU Council, includes the largest batch of individual designations in the past four years, and crypto sits in that package by design. That's the clearest possible signal of where the industry now stands.
For licensed operators, the immediate priority is a sanctions-specific review of ownership and governance structures before any supervisory inquiry arrives. The deadline for that review is not some future compliance cycle. It was August 25, 2026.




