ESMA Launches Cross-EU Audit to Strengthen Crypto Custody and Resilience Under MiCA

MiCA-regulated platforms have grown beyond 270, with subsequent reporting indicating about 280 authorized providers across the EU.
Regulators have explicitly barred outsourcing core custody services to providers that do not hold a MiCA license, reinforcing that licensed entities must oversee custody.
The CSA is positioned as a joint test of digital operational resilience under both MiCA and the Digital Operational Resilience Act (DORA), with crypto firms treated as financial entities for DORA purposes.
Key implementation dates include the end of the transition on July 1, 2026, the CSA launching on July 8, 2026, and a final ESMA Board of Supervisors report due in the second half of 2027.
The CSA focuses on MiCA's custody framework, particularly Article 75, emphasizing safeguarding client crypto assets through segregation, governance, key management, and robust risk controls.
Europe's top securities watchdog has launched its first coordinated review of crypto custody firms across the EU. The European Securities and Markets Authority (ESMA) kicked off a Common Supervisory Action on July 8, 2026, targeting how crypto platforms safeguard client assets under the Markets in Crypto-Assets regulation, known as MiCA, according to Crypto Briefing.
The review covers more than 280 authorized Crypto-Asset Service Providers, or CASPs, across member states. Crypto Times reported that results will be consolidated into a final ESMA report due in the second half of 2027. The action marks a clear shift: MiCA is no longer just about getting a license — regulators are now actively checking how firms operate.
ESMA is zeroing in on Article 75 of MiCA, which sets rules for how firms must protect client crypto assets. Regulators will check whether firms properly segregate client funds, manage private keys securely, and run sound governance, according to Value The Markets. Inspectors will also look at transaction controls, reconciliation processes, and how firms respond to cyber incidents.
The review also tests firms against the Digital Operational Resilience Act, known as DORA. Under DORA, crypto firms are treated as financial entities and must meet strict IT and cyber risk standards. FX Daily Report noted that ESMA sees this as a joint stress test of both MiCA and DORA compliance at the same time.
One of the sharpest rules to emerge from this review: firms cannot hand off core custody work to providers that do not hold a MiCA license. ESMA has made clear that licensed entities must keep direct oversight of how client assets are stored and managed. This shuts down a common workaround where firms outsourced sensitive operations to third parties outside the regulatory perimeter.
Coindoo reported that ESMA is also addressing unauthorized providers still operating in the market. Those firms must follow an orderly wind-down process. Client assets should move to a licensed custodian or be returned to clients via self-custody. The goal is to close gaps before they become crises.
The timeline is tight. The MiCA transition period ended on July 1, 2026. One week later, on July 8, ESMA launched the custody review. National regulators will select firms for inspection using a risk-based approach, meaning higher-risk platforms face closer scrutiny first. The final Board of Supervisors report lands in the second half of 2027, according to Crypto Briefing.
This sequence is deliberate. Regulators spent the first phase of MiCA granting licenses to over 280 providers. Now the second phase begins: checking whether those firms actually do what they promised. FX Daily Report described it as ESMA moving from a gatekeeping role to an active enforcement posture across the bloc.
Before MiCA, crypto rules varied wildly from one EU country to the next. A firm licensed in one state could passport services across the bloc while operating under looser home-country rules. The Common Supervisory Action is designed to fix that. By coordinating national regulators under one framework, ESMA aims to make custody standards equally strict in every member state, according to Value The Markets.
Crypto Times noted that the review also signals a broader European push to treat crypto firms like other financial institutions — subject to the same operational resilience demands as banks and investment firms. For crypto platforms, that means less regulatory arbitrage and more accountability for how they handle the assets clients entrust to them.
Publishers
18
Articles
4
Reach
22