TLDR
The EU regulator ESMA has begun a MiCA-based review of how resilient licensed crypto custodians are, focusing on their custody and operational risk controls.
- ESMA has launched a Common Supervisory Action to test MiCA-authorized crypto firms custody resilience, including key management, transaction controls, and incident response.
- The review effectively raises the bar for exchanges and custodians, turning security claims into evidentiary requirements that matter for institutional adoption.
- Its findings could set EU-wide benchmarks, influence MiCAs next revision, and support shifting more crypto supervision from national regulators to ESMA.
Deep Dive
1. What ESMA Is Reviewing
ESMA has started a Common Supervisory Action to assess the operational resilience of crypto asset service providers licensed under MiCA, with a specific focus on custody services. The review will cover a sample of MiCA-authorized CASPs and examine the maturity of their digital operational resilience frameworks, including key and storage management, transaction controls, incident response, and reliance on third party technology providers, according to a recent custody resilience assessment.
The exercise runs under both MiCA and the EUs Digital Operational Resilience Act (DORA), which sets technology risk requirements for financial firms, so crypto custodians are effectively being tested against banking-style standards.
2. Why It Matters For Custodians And Users
Industry executives note that getting a MiCA license is now the start line, not the finish for custody providers, as regulators and institutional clients demand hard evidence of security and resilience rather than marketing claims. ESMAs review will push custodians to demonstrate clear asset segregation, robust access controls, documented incident response, and credible business continuity planning under stress.
Because custody technology is concentrated among a small number of vendors, regulators are also looking at supply chain risk: a weak or fragile provider could affect multiple CASPs at once. Firms that can show strong controls early are likely to gain an edge with institutional clients who want MiCA-style protections plus operational assurance.
For users and institutions, the quality of a custodians processes and audits will increasingly matter as much as its license, and weaker operators may be squeezed out.
3. What To Watch Next
ESMAs findings are expected to feed into the formal review of MiCA and ongoing debates about centralizing CASP supervision at ESMA rather than leaving it with national regulators. That could lead to more consistent enforcement across the EU and tighter expectations for custody resilience.
Crypto users and firms should watch for: 1) public guidance or reports summarizing ESMAs custody standards, 2) any follow up actions against CASPs that fail the resilience tests, and 3) changes in MiCA 2.0 proposals that reference custody, operational risk, or vendor concentration.
Conclusion
ESMAs MiCA custody resilience review turns Europes new crypto rulebook into a practical stress test of how safe and robust licensed custodians really are. For exchanges and wallet providers, the message is that licensing alone is not enough; demonstrable, audit-ready operational resilience will shape who wins institutional flows and how the next phase of EU crypto regulation is written.
