ESMA Shifts to Active MiCA Supervision and Custody Audits
ESMA starts active MiCA supervision focusing on crypto custody and operational resilience. Unlicensed firms face strict exit rules under the new regime.
European regulators are pivoting toward a new phase of oversight, placing a heavy emphasis on the security of custodial services, the operational resilience of licensed providers, and the management of companies that failed to secure authorization under the new European framework.
ESMA Transitions to Active Oversight Post-MiCA
With the final implementation of MiCA, European regulators are shifting their focus from processing license applications to the ongoing supervision of companies already active in the market.
On July 8, ESMA announced the launch of a Common Supervisory Action (CSA) specifically targeting the operational resilience of Crypto-Asset Service Providers (CASPs). These audits will be coordinated with national regulators to evaluate how effectively companies protect client assets against cyberattacks, technical failures, and other operational threats.
Custodial services will receive particular scrutiny, as ESMA identifies asset storage as a critical factor in investor protection. The regulator aims to verify that licensed entities maintain robust risk management systems, internal controls, and incident response procedures.
Stricter Rules for Custody and Unlicensed Firms
Alongside these new audits, ESMA is tightening its grip on companies that failed to obtain a license before the transition period ended on July 1.
The authority is collaborating with national competent authorities to ensure these firms wind down their operations in an organized manner without risking client funds. A key priority is the seamless transfer of assets to licensed providers or to personal self-custody wallets where applicable.
ESMA has also clarified rules regarding outsourcing. According to the regulator, companies are prohibited from outsourcing core services—including the custody of client crypto assets—to entities that do not hold a MiCA license themselves. This interpretation effectively prevents licensed European firms from using unregulated providers outside the EU for essential functions.
Supervision Now Targets Daily Operations
For licensed market participants, obtaining authorization is no longer the final hurdle for smooth operations.
Regulators will now monitor whether firms consistently meet MiCA requirements regarding corporate governance, the protection of client funds, risk management, and operational security.
ESMA is also urging investors to verify that their chosen providers appear on the official European register of licensed CASPs. Clients of unauthorized firms are encouraged to move their assets promptly, as they no longer benefit from the protections offered by the European regulatory framework.
Furthermore, the regulator expects all licensed companies to fully implement MiCA’s technical requirements. This includes the “Travel Rule,” which mandates that providers collect and exchange information about the originators and beneficiaries of crypto-asset transfers.
As the transition period concludes, the European crypto market enters a stage where the focus moves from licensing to constant supervision and practical enforcement. For sector participants, this translates to more frequent audits, higher security benchmarks, and significantly stricter control over how client assets are managed.

Fill in necessary fields and publish