MiCA Enforcement Triggers ESMA Custody Review
MiCA enforcement enters a new phase as ESMA begins coordinated reviews of crypto custody resilience across authorized CASPs through 2027.
- ESMA has launched its first coordinated crypto custody review since MiCA entered full enforcement across the European Union.
- National regulators will assess governance, key management, incident response, transaction controls, and smart contract risk frameworks.
- The coordinated supervisory exercise will continue into 2027, emphasizing operational resilience across regulated crypto custody providers.
MiCA enters a new supervisory phase as European regulators begin coordinated reviews of crypto custody resilience, strengthening oversight of authorized digital asset service providers across European Union member states.
ESMA Opens First Coordinated Custody Review Under MiCA
Wu Blockchain reported that ESMA launched its first Common Supervisory Action under MiCA. The initiative targets authorized Crypto-Asset Service Providers across the European Union.
Rather than introducing fresh legislation, the review evaluates existing compliance standards. National Competent Authorities will jointly conduct risk-based supervisory assessments through coordinated oversight.
The exercise focuses primarily on crypto custody operations and operational resilience. Custody providers remain responsible for protecting digital assets and managing sensitive cryptographic keys.
Because custody services safeguard customer funds, regulators consider operational security increasingly important. The coordinated review aims to establish consistent supervisory expectations across participating jurisdictions.
Governance And Operational Controls Become Central Focus
According to the announcement, governance frameworks represent one of the review’s primary priorities. Supervisors will evaluate management oversight of operational and technological risks.
Wu Blockchain noted that key management procedures will receive extensive regulatory examination. Authorities will review storage practices, backup processes, and cryptographic security controls.
Transaction controls also form a major component of the supervisory exercise. Regulators will assess authorization procedures, monitoring systems, and safeguards preventing unauthorized asset movements.
Incident detection and response capabilities complete another important review category. Supervisors expect firms to maintain effective recovery plans and business continuity procedures.
Review Extends Into 2027 As Oversight Evolves
The Common Supervisory Action also examines smart contract risks and third-party dependencies. Many custody providers rely on external infrastructure supporting daily operational activities.
Cloud providers, software vendors, and blockchain analytics platforms introduce additional operational considerations. Regulators therefore seek resilience extending beyond firms’ internal technological environments.
The coordinated review will continue from late 2026 through the first half of 2027. Risk-based sampling allows supervisors to prioritize firms presenting greater operational exposure.
For the broader crypto sector, MiCA now moves beyond licensing toward continuous supervision. Coordinated oversight seeks stronger custody standards while reinforcing confidence in Europe’s regulated digital asset ecosystem.




