The European Securities and Markets Authority (ESMA) has launched a joint regulatory action against crypto asset service providers, focusing on the resilience of digital operations, marking a significant increase in supervision of custodians operating under the Cryptographic Asset Markets Regulatory Framework (MiCA).
ESMA\'s review focus on crypto custody providers
ESMA has announced joint regulatory actions targeting crypto asset service providers and the resilience of digital operations, coordinating EU national authorities to jointly review how crypto service providers manage operational risks associated with their digital infrastructure. The action focuses on companies authorized or operating under MiCA, the European Union\'s comprehensive regulatory framework for crypto assets. Custody providers who hold client assets on behalf of investors are a core concern because of their systemic role in asset security.
This action comes at the official end of the MiCA transition period. ESMA issued a public statement in June 2026 confirming that transition arrangements for crypto companies have come to an end, which means that all providers must now fully comply with MiCA\'s requirements. This regulatory action comes directly on the heels of this milestone, after ESMA ordered unauthorized crypto asset service providers to stop accepting new EU customers.
Importance of ESMA initiatives to crypto companies and users
Custody is the most vulnerable link of user assets. A provider\'s operational resilience, including its cybersecurity posture, IT governance and incident response capabilities, directly determines whether customer funds remain secure during an outage or attack.
This joint regulatory action further raises the bar for hosting providers already working to comply with MiCA. Companies that were authorized during the MiCA transition period now face active regulation of their operating practices, rather than just licensing status.
The differences between managed and unmanaged services under MiCA also add complexity. The regulatory treatment of different custody models remains an open issue, and ESMA\'s review may bring clarity to regulatory expectations for various custody structures.
The action also reflects the broader enforcement posture across the EU. Regulators across the country have begun drawing red lines, Spain has refused to extend the deadline for unlicensed crypto companies, and the European Banking Authority has outlined its crypto fines framework under MiCA.
Next steps after ESMA review announcement
Custody providers should expect national regulators to request documents on IT risk management frameworks, business continuity plans, and third-party service provider oversight as part of this joint action.
Companies that have recently joined the MiCA registration list may face special scrutiny as ESMA evaluates whether newly authorized providers are actually implementing operational resilience standards, rather than just treating authorization as a formality task.
Key points to focus on include: operational resilience standard guidance that ESMA may issue in the future for the crypto custody space, enforcement actions taken against non-compliant companies, and whether the review results will lead MiCA to develop additional technical standards or guidelines for the custody industry.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following