The short answer

A licence can be lost to paperwork alone. Under MiCA a regulator must withdraw a crypto authorisation that goes unused for 12 months or dormant for nine consecutive months. Hong Kong suspends a licence once the annual fee is over three months late and can revoke it past four. Keeping a licence means an audit on a set cycle, filings on fixed dates, change notifications in days, and training hours per person.

Figure 01

Three published thresholds at which a licence goes

12months unusedMiCA Article 64(1): an authorisation not used within 12 months of the date of the authorisation must be withdrawn
ninemonths dormantNo crypto-asset services provided for nine consecutive months — the same mandatory ground
4months lateHong Kong: an annual fee over 4 months overdue means revocation of the licence or registration
Source: MiCA Article 64(1); the Hong Kong SFC's published ongoing obligations. An AML audit is not automatically annual — a Swiss SRO member is audited every 12, 24 or 36 months by risk profile.

This page is about year two, not the application: what you owe each year, and the published point at which a regulator starts withdrawing. Our ongoing work is described under compliance maintenance, the wider picture in after the licence. Rules quoted as published in October 2026.

Key takeaways

  • Article 64(1) of MiCA says competent authorities shall withdraw an authorisation on seven listed grounds. Three of them are triggered without any breach: an authorisation left unused for 12 months, express renunciation, or nine consecutive months without providing services.
  • Hong Kong publishes the exact ladder: surcharge, then suspension, then revocation, measured in months late.
  • An AML audit is not automatically annual. A Swiss SRO member is audited every 12, 24 or 36 months by risk profile.
  • In Hong Kong the clock on a change notification is days: 7 business days for a director change, and 7 business days before you stop a regulated activity.
  • Your exit plan is a standing obligation — MiCA requires the client-transfer procedure to exist before anything goes wrong.

What actually gets a crypto licence withdrawn?

The EU wrote the answer into the text. Article 64 of MiCA opens in the mandatory voice, and the seven grounds it lists run from an unused authorisation to a serious infringement of the Regulation itself.

Competent authorities shall withdraw the authorisation of a crypto-asset service provider if the crypto-asset service provider does any of the following:Regulation (EU) 2023/1114 (MiCA), Article 64(1)
  1. has not used its authorisation within 12 months of the date of the authorisation;
  2. has expressly renounced it;
  3. has not provided crypto-asset services for nine consecutive months;
  4. obtained the authorisation by irregular means, such as false statements in the application;
  5. no longer meets the conditions under which it was granted and has not taken the remedial action the regulator asked for within the time given;
  6. fails to have effective systems, procedures and arrangements to detect and prevent money laundering and terrorist financing under Directive (EU) 2015/849;
  7. has seriously infringed the Regulation, including holder and client protection or market integrity.

Ground five cuts both ways: falling out of compliance is not itself fatal, failing to fix it inside the window is. Recovery routes at the application stage are in what happens if your licence application is rejected.

Can a regulator take away only part of the licence?

Yes. Article 64(4) lets a competent authority limit a withdrawal to one of the crypto-asset services an authorisation covers, closing that business line without the firm losing its status. Article 64(2) is the discretionary list, and 64(2)(b) runs the other way: a regulator may withdraw the crypto authorisation if you lose your payment-institution or e-money authorisation and do not remedy it within 40 calendar days.

Under Article 64(7), EBA, ESMA or a host-state authority may ask the home regulator to re-examine the conditions whenever there are grounds to suspect they are no longer met.

In Hong Kong, does a late filing really cost the licence?

It does, and the Securities and Futures Commission publishes the schedule, so the consequence of each month late is already written down. An annual fee less than a month late attracts a 10% surcharge; past three months the licence or registration is suspended, and past four it is revoked. An annual return more than four months late can end in revocation too, under sections 195(4)(b) and (6) of the Securities and Futures Ordinance.

Figure 02

Hong Kong: what a late annual fee costs, by how late it is

Hong Kong: what a late annual fee costs, by how late it is
Overdue periodPenalty
Less than 1 month10% surcharge
Over 1 month but less than 2 months30% surcharge
Over 2 months but less than 3 months50% surcharge
Over 3 months but less than 4 monthsSuspension of licence or registration
Over 4 monthsRevocation of licence or registration
Source: Securities and Futures Commission, Ongoing obligations of licensed corporations and registered institutions, retrieved 2 October 2026.

Change notifications are tighter: a director notifies within 7 business days of becoming or ceasing to be one, and an intended cessation of a regulated activity at least 7 business days before it happens. Stop everything and you still owe audited accounts within four months of the cessation date.

What is the annual filing calendar, jurisdiction by jurisdiction?

Hong Kong files an annual return and the annual fee within one month of each licence anniversary, and audited accounts within four months of its financial year end. Singapore's payment service licensees file an auditor's report on Form 4 within six months of the financial year end. Switzerland's AML audit runs on a 12, 24 or 36-month cycle instead.

Figure 03

The recurring filings, and what each deadline is counted from

The recurring filings, and what each deadline is counted from
JurisdictionWhat is dueWhen
Hong KongAnnual returnWithin one month after each anniversary date of the licence (SFO s.138(4))
Hong KongAudited accounts and required documentsWithin four months after each financial year end (SFO s.156(1))
Hong KongAnnual feeWithin one month after each anniversary date (SFO s.138(2))
Singapore (payment service licensees)Auditor's report, on Form 4Within 6 months after the financial year end
SwitzerlandAML audit by an SRO-approved firmEvery 12, 24 or 36 months by risk profile
Source: Securities and Futures Ordinance ss.138(2), 138(4) and 156(1); MAS Guidelines on Audit of Payment Service Providers (PS-G04); VQF, SRO membership — rights and duties.

Two of Hong Kong's three deadlines run off the licence anniversary and one off the financial year, so a single annual reminder is not enough. Singapore is the most prescriptive of the three: the Monetary Authority of Singapore names five mandatory audit areas for every payment service provider, one of which is the remediation of findings from prior external audits and MAS inspections. That one compounds: a finding is not closed when you answer it, it joins next year's mandatory scope.

How often is a Swiss SRO member audited?

Switzerland does not run a flat annual cycle. VQF, an SRO recognised by FINMA, sets the interval from the member's own profile: every 12 months for an increased risk profile or complex business model, every 24 months for a medium profile, every 36 months for a low profile with straightforward activities. The inputs are the business model, transaction volume, customer structure and previous audit results, and extraordinary audits can be ordered at any time.

Audit frequency is therefore an output of last year's audit: a clean file buys a longer interval, a finding pulls you back. An intermediary affiliated to an SRO is supervised by that SRO, not by FINMA directly. What must be in place before any of this starts is in local substance requirements explained, and the Swiss fee picture in what a Swiss SRO licence actually costs.

Who has to be trained, and for how many hours?

The Hong Kong Securities and Futures Commission counts it in hours. Every licensed individual completes 10 CPT hours per calendar year regardless of how many regulated activities they engage in, five of which must be directly relevant to what they are licensed for. Responsible officers and executive officers take two additional hours a year on regulatory compliance, and in a person's first 12 months two CPT hours must be on ethics.

Switzerland counts it in roles. The AML officer must have the necessary specialist knowledge and receive regular training, and VQF applies higher experience and training requirements to virtual asset service providers specifically. Where fewer than six people do AML work no deputy is required, but an authorised person with system access must be designated so contact with the SRO is never interrupted.

What happens to clients if the authorisation goes?

MiCA puts the exit plan in the present tense. Article 64(8) requires procedures for the timely and orderly transfer of client crypto-assets and funds to another provider when an authorisation is withdrawn, a procedure that has to exist while everything still works. The withdrawal is then public: the competent authority notifies ESMA without undue delay and ESMA publishes it in the Article 109 register.

Switzerland leaves a trail too. An SRO reports to FINMA the termination of memberships, exclusion decisions and their reasons, and the mere opening of sanctions proceedings that could end in exclusion; it also reports at least once a year with a list of the sanction decisions it issued. Leaving voluntarily can require a final audit, which VQF may waive in justified cases.

CryptoLicense is the licensing advisory brand of CL GLOBAL SDN BHD (1421939-T), trading since 2020, with 100+ companies served across 10+ jurisdictions and Swiss SRO membership as its largest line of work; the registered entities and their public company numbers are on our entity proof page, and the vocabulary above is defined in the glossary. No approval can be guaranteed and no regulator timeline can be promised — both sit entirely within the regulator's discretion. This page states what the published rules said in October 2026; it is not legal advice.

Frequently asked questions

Can a crypto licence be withdrawn even if we have broken no rules?

Under MiCA, the EU's crypto-asset regulation, yes. Article 64(1) requires withdrawal where an authorisation has not been used within 12 months of being granted, or where no crypto-asset services have been provided for nine consecutive months. Neither ground involves a breach.

Is a Swiss SRO member audited every year?

Not necessarily. VQF sets the cycle by risk profile: every 12 months for an increased risk profile or complex business model, every 24 months for a medium profile, every 36 months for a low profile with straightforward activities. The decision uses the business model, transaction volume, customer structure and previous audit results.

How late can a Hong Kong annual fee be before the licence is at risk?

The SFC, Hong Kong's licensing regulator, publishes the full ladder: under one month late attracts a 10% surcharge, over one month 30%, over two months 50%, over three months suspension of the licence or registration, and over four months revocation.