The European Securities and Markets Authority launches joint regulatory action against crypto asset service providers
The European Securities and Markets Authority (ESMA) has launched a joint regulatory action against crypto asset service providers, focusing on digital operational resilience and custody controls across the EU. As the EU\'s financial market regulator, ESMA announced that the coordinated review was a regulatory exercise rather than an enforcement action or the formulation of new regulations. The move indicates that national authorities in each member state will review how authorized crypto asset service providers fulfill their custody obligations and meet operational resilience requirements.
This review is not a penalty or rule change, but a structured process designed to assess whether companies authorized to operate meet expected standards, especially in terms of customer asset protection.
Why Custody Controls Are the Focus
Custody is at the core of crypto operational risks. When service providers hold digital assets on their behalf, mistakes in key management, fund isolation, or disaster recovery can lead to permanent losses. Traditional finance has decades of custody infrastructure, while crypto custody is still maturing.
ESMA\'s decision to focus on custody and digital operations resilience reflects regulators \'belief that these functions carry excessive risks. The 244 crypto companies that were authorized in the European Economic Area before the MiCA deadline now face a practical-level review to confirm whether their internal controls are consistent with regulatory requirements.
The review covers how crypto asset service providers document custody processes, manage cybersecurity threats, and maintain business continuity. For companies that also provide organization-level crypto hosting services, the threshold for operational resilience is particularly high.
What should EU crypto companies focus on next
This joint regulatory action means that regulators from various countries will use a unified approach to conduct parallel evaluations. Organizations should be prepared to respond to documented requirements for hosting arrangements, IT risk frameworks, and incident response procedures.
This is a regulatory follow-up and does not necessarily result in fines or license revocation. However, companies that fail to meet expectations during the review may face rectification requirements or stricter ongoing supervision. The action will also incorporate ESMA\'s broader understanding of systemic risks in the crypto space.
Crypto asset service providers operating in the EU should pay attention to ESMA\'s subsequent findings and updated regulatory expectations. National regulators may also issue new guidance for jurisdictions based on the findings of coordinated reviews. For companies that are adapting to the EU\'s changing crypto regulatory environment, this review means a further increase in compliance attention.
This scope of action shows that post-implementation supervision of MiCA is shifting from licensing issuance to proactive supervision. Authorized companies should view it as the starting point, not the end point, of continued regulatory engagement.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following