On this page
- What CEX.IO is
- Which entity is which
- What the PCI DSS certificate does and does not mean
- Fees on the global fee page
- Security and custody: what is evidenced
- Notable incidents and regulatory actions
- Tax reporting
- What would change the picture
- What an Irish reader can do now
- Who this suits, and who it does not
- How to verify all of this yourself
As of 5 October 2026, CEX.IO says it is not onboarding new EU or EEA customers, so an Irish resident cannot currently open an account. Existing EEA accounts are withdrawal-only. The company's EEA entity, CEX.IO Europe S.L. in Madrid, has applied to Spain's securities regulator, the CNMV, for authorisation under MiCA, and CEX.IO says the application remains under review. That entity does not appear on ESMA's interim register of authorised crypto-asset service providers, which we searched on the same date.
That is the headline, and we would rather give it to you before anything else. The rest of this page is for people who want the full picture: what CEX.IO is, which of its companies is which, what the fee page says, what is evidenced about its security, and what would change our view. We have no commercial relationship with CEX.IO and this review is not a recommendation to sign up. The link to its site is there so you can read its own documents.
What CEX.IO is
CEX.IO was founded in 2013 and describes itself as an exchange offering buying and selling of crypto, spot trading, a wallet, an institutional service called Prime and a mobile app. It makes sizeable claims about itself: more than 15 million users, $7.5 billion of deposits across 185-plus countries, 300-plus assets and over a million app downloads. Treat these as marketing figures. They are the company's own and unaudited, and we have not been able to check any of them.
One piece of its history is worth knowing because it is the sort of thing the company discloses itself. Its about page describes a 2013 episode in which the GHash.IO mining pool, which CEX.IO hosted, approached 51% of Bitcoin's hash rate, and says the company voluntarily restricted it. That is the company's account, not an independent finding.
Which entity is which
The word "CEX.IO" covers several companies, and this is where most of the confusion comes from. The company's legal pages list them separately, and what each registration actually is differs a lot. The table sets them side by side. Only the first row is the one that would matter to an Irish customer.
| Entity | Where | What the registration is | Relevant to an Irish reader? |
|---|---|---|---|
| CEX.IO Europe S.L. | Madrid, Spain | MiCA application with the CNMV, under review. CEX.IO also says it was registered with the Bank of Spain for AML purposes; we could not confirm the number or whether that register is still open. | Yes, this is the EEA entity. Not onboarding new EEA users. |
| CEX.IO Markets UK Ltd | London | FCA registration as a cryptoasset business under the money laundering regulations, FRN 1007192. Anti-money-laundering only; no Ombudsman or FSCS cover. | No. It does not serve EEA residents. |
| CEX.IO Corp | United States | FinCEN money services business; NMLS 1804170; state money-transmitter licences. | No. |
| CEX OVRS LLC | Nevis | An offshore company serving customers "all over the world except" listed countries. | We do not point Irish readers to it. It sits outside EU authorisation. |
Two historic entities show up in third-party sources and we have left them out of the table because we could not verify them: a Lithuanian VASP company (its page on cex.io now returns a 404) and an Irish-registered company, CEX IO EU Limited, which third-party company databases show as dissolved in February 2024. We did not query the Companies Registration Office. We found no Central Bank of Ireland registration or authorisation for any CEX.IO company.
A word on the headline claim of "30+ licences and registrations" on the about page. Most of those appear to be US state money-transmitter licences. Useful in the US, but they say nothing about MiCA or about Irish customer protection.
What the PCI DSS certificate does and does not mean
CEX.IO publishes a PCI DSS Level 1 service provider certificate. We read the PDF: it was issued to "CEX.io LTD." by the assessor Kyte Global, is numbered 18815, is dated 23 March 2026 and is valid for one year. That is a real, checkable document.
What it covers is the handling of payment card data. PCI DSS is the card industry's security standard, so the certificate is evidence of how the company deals with card payments. It is not a financial licence, it is not a MiCA authorisation, and it says nothing about how customer crypto is held or whether the company can meet withdrawals. The certificate itself states that it offers no guarantee of security. Read it as one positive data point and no more.
Fees on the global fee page
CEX.IO's fee schedule is a single global page, with euro methods updated on 30 July 2026. These are the figures as listed on 5 October 2026. They are not EEA-specific, and since EEA deposits and trading are currently switched off, you cannot use them today. We include them so you can compare with other exchanges, and so you can see what changes if the position changes.
| Item | Listed at |
|---|---|
| SEPA deposit | Free, minimum €5 |
| SEPA withdrawal | €2.99, minimum €10 |
| Open banking deposit | €1.99, minimum €20 |
| Visa/Mastercard deposit | 0.49% to 4.99% plus a service charge, depending on provider and country |
| Spot trading | 0.25% at the default tier, falling to 0.10% above $20m of 30-day volume |
| New customer limits | $1,000 a day and $3,000 a month in the first three months after verification |
A few extras from the same page. PayPal is listed at 3.99% plus $5. Google Pay and Apple Pay deposits sit in the same 0.49% to 4.99% band, with no withdrawal. Margin trading is not available in Europe, per CEX.IO's help centre. Staking and savings products are advertised on the homepage with the note "not available in the US and EEA". One help-centre country list dated 31 August 2026 still includes Ireland for those products; we treat that as stale, because the homepage and the terms say otherwise. Identity verification is required, and address verification applies for some methods.
For a like-for-like look at what the euro routes cost elsewhere, see our euro fee comparison.
Security and custody: what is evidenced
The homepage mentions two-factor authentication, DDoS mitigation, multi-signature wallets and "cold storage safeguards". These are company statements. We looked for the details that would let an outsider test them and did not find any: no published share of assets held in cold storage, no proof of reserves, and no named independent security audit. The "real-time audit" badge from a review site on the homepage is not an audit of the exchange's systems.
None of this means the platform is unsound. It means we cannot confirm the claims, and you should weigh them accordingly. The same standard applies to every exchange we review.
The homepage notice about the MiCA status also contains a strongly worded statement about the funds. We have deliberately not repeated it, since it is the company's assertion and not something we can evidence.
Notable incidents and regulatory actions
On 15 February 2023 the US Federal Deposit Insurance Corporation sent a cease-and-desist letter to CEX.IO Corp, among others, about statements that were false or misleading regarding deposit insurance. We read the PDF. To be fair about its scope: it concerns the US entity and US deposit-insurance claims, it is a letter and not a fine, and it does not concern Irish customers. It matters to a reader mainly as a reason to read any "protected funds" language on a crypto site closely, whichever site it is. We found no fines from the Central Bank of Ireland, ESMA or the CNMV. Complaints about frozen accounts exist on complaint boards, but those are not verifiable and we have not relied on them.
Tax reporting
We did not find or test a tax-report export for CEX.IO, so we will not describe one. What matters in Ireland does not depend on the exchange: disposals, including swaps and spending, are CGT events, and you need your own records. If you hold an account, download your transaction history while the account is accessible. Our crypto tax guide covers what Revenue expects, and the CARF and DAC8 page explains why authorised providers will start reporting on you from 2026. An unauthorised provider is outside that framework, so do not assume anyone reports on your behalf.
What would change the picture
CNMV application under review. No new EEA sign-ups. Not on the ESMA register.
CEX.IO Europe S.L. would appear in ESMA's interim register CSV with Ireland in its list of passported states. Look for the legal name, the CNMV as home regulator and IE in the services countries.
CEX.IO would need to reopen onboarding and publish EEA-specific fees. We would update this page, and re-check the fees from an Irish connection.
Until that happens, please treat any article that presents CEX.IO as an open option for Irish sign-ups, ours included if it ever slips out of date, with suspicion. The ESMA position from 23 June 2026 is that unauthorised providers must stop onboarding new EU clients and stop marketing.
What an Irish reader can do now
- Check the live notice
Open cex.io and read the service notice and the EEA section of the terms. If you hold an account, your own login shows what is available to you.
- Verify the register yourself
Download ESMA's interim register CSV, search for "CEX" and for the Madrid entity's name. No result means no authorisation on that date.
- Read the Central Bank's notice
The Central Bank of Ireland's consumer notice explains what holders at unauthorised providers should consider. Our MiCA and Central Bank explainer puts it in context.
- Compare authorised options
Our comparison of exchanges for Ireland and the list of firms authorised in Ireland show who can serve you today. For an Irish-authorised example, see our Kraken review.
Who this suits, and who it does not
CEX.IO suits, at this moment, one group: people who already hold an EEA account and need to withdraw. For everyone else in Ireland, it is not an available option, and we would not look for workarounds. The offshore Nevis entity is the obvious temptation and we advise against it: it sits outside the EU framework, and the reasons for MiCA's protections, such as segregation of client assets and a complaints procedure, would not apply in the same way.
It does not suit anyone looking for a deposit-protected product (no crypto is covered by the deposit guarantee, as the Central Bank notes), or anyone who needs a provider they can verify on the ESMA register today.
How to verify all of this yourself
Everything above can be checked in about ten minutes. The EEA entity, address and application wording are on cex.io/legal/es. The withdrawal-only wording is in the EEA section of the terms of use. The PCI certificate is a PDF on cex.io. The UK and US registrations have their own pages under cex.io/legal-security, and you can cross-check FRN 1007192 on the FCA's register. The register of authorised providers is ESMA's interim CSV. Dates matter: all of the above was checked on 5 October 2026.
This is general information, not personal financial, tax or legal advice. Crypto can lose value quickly, and it is not covered by a deposit guarantee or investor compensation scheme.
Sources and further reading
- CEX.IO – EEA entity and legal notice (CEX.IO Europe S.L.)
- CEX.IO – Terms of use (EEA section)
- CEX.IO – Legal and security index
- CEX.IO – Fee schedule
- CEX.IO – PCI DSS certificate (PDF)
- ESMA – interim MiCA register of CASPs (CSV)
- Central Bank of Ireland – warning for consumers with crypto-assets at unauthorised CASPs
- FDIC – letter to CEX.IO Corp., 15 February 2023 (PDF)
Facts last checked 5 October 2026Published 5 October 2026How we research
Risk warning. Crypto-assets are volatile and you can lose all the money you put in. They are not covered by the Irish Deposit Guarantee Scheme. This page is general information, not financial or tax advice.



