TLDR
ESMA has begun a coordinated MiCA supervisory review of crypto custody providers, shifting focus from licensing to proving real-world operational resilience for EU-authorized platforms.
- ESMAs new Common Supervisory Action will sample MiCA-authorized custodians and scrutinize key management, storage, incident response, and third-party tech under MiCA and DORA.
- For custodians, a MiCA license is now the start line, with institutional clients and regulators demanding hard evidence that controls can withstand real-world stress.
- The findings are likely to shape MiCAs 2027 review, set benchmarks for custody standards, and feed debate over moving crypto supervision from national regulators to ESMA itself.
Deep Dive
1. What ESMA Is Reviewing
The European Securities and Markets Authority (ESMA) has launched a Common Supervisory Action (CSA) to examine the operational resilience of crypto asset service providers (CASPs) that already hold MiCA authorization, with custody services at the center of the exercise. This coordinated review is one of the first major supervisory actions under the EUs new crypto rulebook and follows the end of MiCAs transitional period.
Regulators will look at the maturity of firms digital operational resilience frameworks for custody, including private key and storage management, transaction controls, incident response plans, and reliance on third-party technology providers, as described in recent coverage of ESMAs initiative. ESMA is applying the CSA to a sample of authorized CASPs rather than the full market, but the standards it uses will likely become reference points for the wider industry.
2. Why Custody Resilience Matters
Industry voices stress that getting a MiCA license is only the beginning for custodians. Sebastien Dessimoz of Taurus argues that for custody firms a licence is the start line, not the finish, as they now need to prove security and resilience in practice rather than just claim it. Executives at providers like BitGo highlight that institutional clients are increasingly asking detailed questions about asset segregation, access controls, business continuity, and incident response.
The review sits at the intersection of MiCA, which sets crypto custody obligations, and the Digital Operational Resilience Act (DORA), which defines technology risk standards for EU financial firms. Because custody technology is concentrated in a handful of vendors, a weakness in one supplier could affect many platforms at once, making supply-chain resilience a key regulatory concern.
Crypto users should pay attention not only to whether a platform is MiCA-licensed, but also to how robust its custody and incident response frameworks appear when regulators start publishing expectations and outcomes.
3. What To Watch Next
Lawyers such as Yuriy Brisov note that ESMAs findings will feed into two important debates: the formal review of MiCA from 2027 and proposals to centralize CASP supervision at ESMA rather than leaving it with national regulators. If the CSA uncovers weaknesses, it could lead to tighter rules on custody, third-party dependencies, or minimum resilience standards.
Conversely, firms that can demonstrate strong operational resilience early may gain a competitive edge with institutions that need regulated, robust custody in the EU. Over time, ESMAs benchmarks may influence which exchanges and custodians become default venues for regulated European capital, while weaker operators face remediation or, in the worst case, loss of authorization.
Conclusion
ESMAs MiCA custody resilience review marks a shift in Europe from box-ticking licenses toward deeper scrutiny of how crypto assets are actually safeguarded. For users and institutions, the key signal will be which custodians can prove strong controls across keys, storage, incident handling, and vendor risk. As MiCA evolves and supervision potentially centralizes at ESMA, operational resilience, not just regulatory status, will increasingly determine which platforms earn long-term trust and capital flows.
