TLDR
ESMA is running an EU-wide supervisory review of MiCA-authorized crypto custodians to test how robust their operational resilience really is.
- ESMAs Common Supervisory Action checks whether exchanges and wallet providers that hold customer crypto meet MiCA and DORA standards for secure, resilient custody.
- The review focuses on private key management, incident response, transaction controls, and third-party tech risk, with weak firms facing remediation or possible restrictions.
- Results will shape how MiCA is enforced from here, ahead of a broader MiCA rethink from 2027 that could tighten rules around stablecoins and custody.
Deep Dive
1. Scope Of The ESMA Review
The European Securities and Markets Authority has launched a Common Supervisory Action with national regulators to review operational resilience at MiCA-licensed crypto custodians, including exchanges with custody services and wallet providers across the EU. The coordinated exercise checks how these firms safeguard customer assets against cyberattacks, system failures, or surges in demand, and whether they meet MiCAs digital operational resilience requirements as well as obligations under the EUs Digital Operational Resilience Act. It is explicitly framed as a compliance check, not a new law or ban, and targets custody controls, private key and storage management, transaction controls, incident handling, and reliance on third-party technology providers, according to ESMA-focused coverage on EU-wide review of crypto custodians.
Confidence: high because multiple independent regulatory reports describe the same coordinated ESMA action and focus areas.
2. Impact On Exchanges, Wallets And Users
For firms, the key message is that having a MiCA license is not enough, they must show their controls work under real-world stress. Industry participants note that institutional clients now scrutinize segregation of assets, access controls, business continuity and incident response as closely as they do legal authorization, and ESMA is aligning supervision with that reality. For users, the review is designed to reduce the risk of outages and inaccessible funds at licensed platforms, but it may also expose weaker custodians whose controls do not pass muster.
if you rely on an EU-regulated platform for custody, this process should gradually improve safety, but could also trigger consolidation toward providers that demonstrate stronger operational resilience.
3. What To Watch Next
National regulators will run these checks simultaneously and ESMA is expected to publish aggregated findings, which may lead to remediation plans, tighter reporting requirements or activity limits for firms that fall short. The review is part of a broader evolution of MiCA supervision, with EU officials already signaling that parts of MiCA will be revisited from 2027, particularly around non-EU stablecoin issuers and how custody and operational resilience are enforced, as highlighted in early commentary on MiCAs next phase. Users and institutions should watch for platform updates mentioning ESMAs action, any changes to custody disclosures, and how exchanges and custodians talk about key management and incident handling.
Conclusion
ESMAs MiCA custodian review marks a pivot from simply licensing crypto firms to testing whether they can actually protect customer assets under stress. The outcome will influence which EU platforms are seen as truly safe, how concentrated custody technology supply chains are managed, and how MiCA is tightened or adjusted in its next regulatory iteration.
