MiCA licenses are a start as EU probes crypto custodians

ESMA opened a Common Supervisory Action to assess operational resilience of MiCA‑authorized crypto asset service providers, focusing on custody controls, incident response and third‑party risks.

The European Securities and Markets Authority (ESMA) on Wednesday launched a Common Supervisory Action (CSA) to assess the operational resilience of crypto asset service providers (CASPs) that hold MiCA authorizations across the EU. The review targets custody controls, incident response and risks from third‑party suppliers and follows the end of MiCA’s transitional period.

ESMA will inspect a sample of MiCA‑authorized custodians and evaluate the maturity of their digital operational resilience frameworks for custody activities. The assessment will examine how firms manage private keys and storage, control transactions, prepare incident response plans and handle dependencies on external technology providers.

Regulators will pay particular attention to key and storage management, transaction controls, incident handling and concentration risk when several firms rely on the same vendors. The exercise aims to test whether operational controls can withstand realistic threats rather than only checking that firms hold a licence.

Sebastien Dessimoz, co‑founder and managing partner at Taurus, called a licence ‘the start line, not the finish’ and predicted a shift from asserting security to evidencing it as custodians face more detailed scrutiny.

Jody Mettler, chief operating officer of BitGo, noted institutional clients are increasingly querying how providers segregate assets, enforce access controls, handle incidents and maintain business continuity during market stress. ‘The signal is that regulators are looking more closely at the operational standards behind digital asset services, not just whether firms are licensed,’ she added.

Markus Levin, co‑founder of XYO, observed that obtaining MiCA authorization and demonstrating operational resilience are separate tests and said custodians that can prove robust controls before the review concludes could gain an advantage with institutional customers.

Yuriy Brisov, a lawyer at Digital & Analogue Partners, pointed to an overlap between MiCA custody obligations and the EU’s Digital Operational Resilience Act (DORA), which sets technology risk rules for financial firms. He warned that custody technology is concentrated in a small number of vendors, so a weak supplier could affect multiple firms.

Regulators intend to use the CSA findings to benchmark how custodians are assessed and to inform discussions about whether supervision of all CASPs should move from national authorities to ESMA. The review extends supervisory attention to custodial operations and third‑party dependencies as crypto services integrate with regulated financial infrastructure.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author