TLDR
ESMA has launched an EU-wide review of MiCA-authorized crypto custodians to test how resilient their custody operations really are during stress.
- ESMAs Common Supervisory Action focuses on private key management, storage, transaction controls, incident response, and dependence on third-party tech providers.
- The review aims to move MiCA from license on paper to proven operational resilience, with potential remediation or restrictions for weaker custodians.
- From 2027, parts of MiCA will be revisited, especially around non-EU stablecoins, making this review an early signal of how supervision will evolve.
Deep Dive
1. ESMAs New Custody Review
The European Securities and Markets Authority (ESMA) has initiated a Common Supervisory Action across EU national regulators targeting crypto-asset service providers that offer custody under MiCA. The program explicitly examines digital operational resilience, including private key and storage management, transaction controls, incident response procedures, and risks tied to third-party technology providers, such as shared custody platforms or cloud services. This is one of the first coordinated supervisory exercises under the EUs crypto rulebook, following the end of MiCAs transitional period and moving the focus from authorizations to day-to-day risk management for client assets.
Industry commentary notes that authorization is only the starting point and that custodians must now show their controls can withstand real-world cyberattacks, outages, and market stress, not just pass a licensing application.
2. Why Custodian Resilience Matters
For users and institutions relying on MiCA-regulated platforms, the review is essentially a stress test of whether their coins remain safe and accessible during disruption. ESMA is combining MiCA obligations with the Digital Operational Resilience Act (DORA), reflecting concern that concentration among custody tech providers could create single points of failure.
At the same time, data from Binance shows that when EU services were shut ahead of MiCAs deadline, about 70 percent of withdrawn assets went to self-custody rather than other MiCA platforms, raising questions about where risk really sits for European users. Stronger standards for regulated custodians are meant to ensure that those who stay inside the perimeter benefit from robust safeguards instead of just regulatory labels.
crypto users should watch how their chosen platforms describe key storage, segregation, incident response, and business continuity, because future ESMA findings could force weaker custodians to tighten controls or scale back services.
3. What Comes Next Under MiCA
Regulators are expected to publish aggregated results from this Common Supervisory Action. Firms that fall short may be required to remediate, increase reporting, or, in more serious cases, face activity limits in custody functions. Looking ahead, European officials plan to review parts of MiCA from 2027, with particular focus on non-EU stablecoin issuers and the interaction between MiCA and newer frameworks like the U.S. GENIUS Act.
Market data already shows a growing MiCA-regulated exchange ecosystem, with venues such as Kraken and Coinbase highlighted for their liquidity, suggesting that custody resilience will increasingly become a competitive differentiator, not just a compliance checkbox.
Conclusion
ESMAs resilience review marks a shift in European crypto regulation from simply granting MiCA licenses to testing whether custodians can actually protect client assets under stress. For crypto users and institutions, the practical takeaway is that operational standards around key management, incident response, and third-party risk will matter more and may reshape which platforms are considered safe, scalable choices in the EU over the next few years.
