TLDR
ESMA is launching a coordinated EU-wide review of crypto custody providers under MiCA to test how well firms safeguard client assets and manage operational risks.
- ESMA has started a common supervisory action where national regulators will audit custody-focused Crypto-Asset Service Providers through mid 2027.
- The reviews will drill into key management, storage controls, governance, incident response and reliance on third-party tech, raising the bar for EU crypto custodians.
- This is supervision rather than new rules, but weak firms could face remediation, tighter oversight and future rule changes as MiCA and MiCA 2.0 evolve.
Deep Dive
1. What ESMA Is Actually Doing
Under MiCA, ESMA has launched a Common Supervisory Action focused specifically on crypto custody and digital operational resilience across the EU. National competent authorities will select a risk based sample of authorized Crypto-Asset Service Providers and review how they run custody operations from now through the first half of 2027, before ESMA consolidates findings in a final report later in 2027. This follows the end of MiCAs transition phase on 1 July, when authorization became mandatory for CASPs operating across the bloc, and moves EU oversight from licensing into active testing of how rules work in practice, as described in ESMAs custody focused CSA summary on client asset protection and technology risk.
2. How It Affects Custody Providers And Users
Regulators will examine private key and storage management, segregation of client assets, governance structures, transaction controls, incident detection and response, and dependencies on external technology providers, according to the CSA outline on custody controls. Custody is a high risk function because failures in these areas can lead to irreversible loss of client crypto, so ESMA is trying to bring standards closer to traditional securities custody. For firms already licensed under MiCA, this means detailed requests for documentation and testing of real world resilience, not just paper compliance.
EU based users and institutions should gradually see safer custody arrangements, while CASPs that cut corners on security or continuity plans could face corrective measures or closer supervision.
3. What To Watch Next In MiCA And MiCA 2.0
The custody review feeds into a broader MiCA evolution, including discussions on expanding the framework to cover non EU stablecoin issuers, tokenized payments and deposits in a future MiCA 2.0 revision process, as outlined in the consultation on MiCAs next phase. ESMAs final report in 2027 will likely highlight common weaknesses and may inform new technical standards or guidance for custody and operational resilience. In parallel, the European Commissions ongoing consultations on DeFi, staking and stablecoins could add more activities under MiCA, increasing the compliance surface for EU facing crypto businesses.
Conclusion
ESMAs custody review marks the shift from MiCA as a legal text to MiCA as lived supervision, with regulators probing whether licensed CASPs can truly protect client assets under stress. For crypto users, the near term impact is more back end scrutiny rather than dramatic rule changes, but over the next few years the findings from this exercise and the MiCA 2.0 debate could reshape which providers are seen as safe and how EU crypto platforms must design their custody and risk systems.
