TLDR
ESMA is launching a coordinated EU-wide review of crypto custody under MiCA, significantly stepping up checks on how licensed providers safeguard client assets.
- ESMA has started a common supervisory action, with national regulators auditing custody-related controls at MiCA-licensed Crypto Asset Service Providers through the first half of 2027.
- The focus is on digital operational resilience, including key management, storage, governance, incident response, and reliance on third-party tech, raising the practical compliance bar for custodial firms.
- Crypto platforms and users should watch for ESMA findings, national guidance, and any enforcement moves, which could tighten standards and affect which services remain available in the EU.
Deep Dive
1. What ESMA Is Doing Under MiCA
The European Securities and Markets Authority (ESMA) has launched a Common Supervisory Action that targets crypto custody services across the EU. National competent authorities will examine a risk-based sample of MiCA-authorized CASPs, focusing on custody functions rather than every firm in the registry.
The review runs from now until the first half of 2027, after which ESMA will consolidate the results into a final report for its Board of Supervisors. The action follows the end of MiCAs transitional period on 1 July, when authorization under MiCA became the only gateway to providing regulated crypto services in the EU, as outlined in ESMAs custody-focused review of CASPs.
2. Why Custody And Resilience Are The Focus
Under MiCA, custodial providers must meet strict requirements on segregation of client assets, governance, prudential safeguards, and incident reporting. ESMAs initiative zeroes in on digital operational resilience frameworks for custody, with supervisors reviewing key and storage management, transaction controls, incident detection and response, and dependencies on external technology providers, as highlighted in ESMAs custody risk scrutiny.
Custody is where user assets are most exposed to operational failures. Weak private key management, poor disaster recovery, or opaque use of third-party infrastructure can result in permanent loss of funds. ESMAs move shifts attention from simply holding a MiCA license to proving that day-to-day controls actually protect assets.
Firms can no longer treat custody compliance as box-ticking. Robust security, documentation, and incident-handling will increasingly determine which providers regulators trust and institutions choose.
3. What Crypto Firms And Users Should Watch
For CASPs, the immediate impact is supervisory intensity. Regulators are expected to request detailed documentation of custody procedures, IT risk frameworks, and business continuity plans, and may impose remedial actions or closer ongoing supervision on firms that fall short.
For users, the outcome will be clearer over time. ESMAs final report and any follow-on guidance could standardize custody expectations across member states, reduce regulatory gaps, and potentially push weaker or non-compliant providers out of the market. Parallel MiCA 2.0 discussions on stablecoins and tokenization suggest the broader framework may tighten further around high-risk areas.
Conclusion
ESMAs intensified MiCA custody checks mark a shift from writing rules to actively testing how crypto platforms apply them in practice. If the coordinated review drives stronger, more consistent custody standards, EU users could see safer but more selectively available services, as firms that invest in resilience and transparency gain regulatory and institutional trust.
