CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

MiCA Licensing Is Just the Start: ESMA Puts Crypto Custodians Under the Microscope

CryptaCount Editorial · · 8 min read
AML / KYC / LICENSING MiCA Licensing Is Just the Start: ESMAPuts Crypto Custodians Under theMicroscope

For crypto custodians operating in the EU, a MiCA licence is no longer the destination. The European Securities and Markets Authority (ESMA) has launched a Common Supervisory Action (CSA) targeting the operational resilience of crypto asset service providers (CASPs), with custody at the centre of the review. The message to the market is unmistakable: MiCA compliance for crypto firms now means proving that security controls hold up in practice, not just on paper.

MiCA Licensing Is Just the Start: ESMA Puts Crypto Custodians Under the Microscope

What the ESMA Common Supervisory Action Actually Covers

The CSA applies to a sample of CASPs that have already received MiCA authorisation. ESMA has confirmed the review will assess the maturity of each firm's digital operational resilience framework specifically as it relates to custody activities.

The Four Risk Areas Under Examination

ESMA's review concentrates on four distinct operational risk areas:

  • Key and storage management: How private keys are generated, stored, and rotated, and whether cold and hot storage segregation is genuinely enforced rather than assumed.
  • Transaction controls: The approval workflows, authorisation thresholds, and anomaly-detection mechanisms that govern outgoing transfers.
  • Incident response: Whether firms have tested, documented plans for security breaches, unplanned outages, and market-stress scenarios, not simply written policies that have never been exercised.
  • Third-party dependencies: The concentration risk that arises when multiple CASPs rely on a small number of custody technology vendors, meaning a single supplier failure could affect many firms simultaneously.

Industry executives who spoke to Cointelegraph after the announcement were direct about the significance of the shift. Sebastien Dessimoz, co-founder and managing partner at digital asset infrastructure firm Taurus, described the exercise as a move "from asserting security to evidencing it." That phrase captures exactly what the CSA demands: verifiable proof, not attestation.

The Dual Regulatory Framework: MiCA and DORA Together

One of the most consequential aspects of this CSA is that it sits under two EU regulatory frameworks simultaneously. MiCA sets out the custody obligations that authorised CASPs must meet. The Digital Operational Resilience Act (DORA) independently imposes technology risk management requirements on financial firms, including those holding or administering crypto assets.

Why the Overlap Creates a Higher Compliance Burden

Yuriy Brisov, a lawyer at Digital & Analogue Partners, pointed out to Cointelegraph that custody technology is concentrated among a small number of vendors. That concentration means a single weak link in the supply chain can affect many authorised CASPs at once. Demonstrating resilience across that supply chain, under both MiCA and DORA simultaneously, is, in his words, "the real challenge for CASPs."

For accounting firms and CFOs advising or auditing CASPs, this dual obligation has direct consequences for how compliance evidence is gathered and reported. A firm that satisfies MiCA's custody rules may still fail DORA's ICT risk management standards if it cannot show that its third-party vendors have been assessed and contractually bound to the required resilience levels. The two frameworks demand different types of documentation, and firms need to be producing both.

Our earlier coverage of ESMA's supervisory action on CASP custody resilience set out the initial scope of this exercise. The reporting now emerging from industry participants confirms that the scope is being taken seriously at the executive level.

Institutional Clients Are Already Demanding More

The regulatory pressure has not arrived in isolation. Jody Mettler, chief operating officer of BitGo and president of BitGo Trust, noted that institutional clients had already been asking more detailed questions about asset segregation, access control management, incident response protocols, and business continuity planning during periods of market stress, before the CSA was formally announced. Regulators are, in effect, catching up with the due diligence standards that large institutional counterparties have already started applying.

That convergence matters for accounting and audit professionals. When institutional investors require custody providers to produce operational resilience evidence as a condition of onboarding, that evidence needs to be presented in a format that can be independently verified. Audit trails, key management logs, penetration testing reports, and third-party vendor assessments all become relevant to the engagement scope in ways they were not when MiCA was simply an authorisation exercise.

What This Means for Accounting Firms and CFOs

The CSA is a supervisory exercise, not an enforcement action at this stage. But the findings will feed directly into two ongoing policy debates that carry significant consequences for how crypto accounting and compliance functions are structured across the EU.

The MiCA Review and Centralised ESMA Supervision

Brisov told Cointelegraph that the CSA findings are expected to influence both the ongoing MiCA review and the separate proposal to shift supervision of all CASPs from national competent authorities to ESMA directly. If ESMA supervision is centralised, the consistency of compliance standards across member states will increase sharply. Firms that have structured their MiCA compliance around the softer expectations of particular national regulators may find those positions are no longer sustainable.

For accounting firms, this is a planning signal. Clients who secured MiCA authorisation through national regulators in jurisdictions with lighter-touch supervisory styles should be advised now that a centralised ESMA regime could apply more uniform and demanding standards. The time to close gaps is before the findings are published, not after.

Competitive Differentiation for Better-Prepared Custodians

Markus Levin, co-founder of blockchain infrastructure company XYO, noted that obtaining MiCA authorisation and demonstrating operational resilience are "two different tests." Custodians that can evidence robust controls before the CSA review concludes are likely to gain a competitive advantage as institutional adoption deepens. That framing is directly relevant to CFOs at crypto-native firms: investment in compliance infrastructure now is not simply a cost, it is a positioning decision.

For audit teams working with CASPs, the practical consequence is that the scope of an operational review engagement is widening. Key management procedures, access control frameworks, incident response test logs, and vendor due diligence files are all becoming standard audit deliverables, not optional extras. Firms using crypto accounting software and digital asset accounting tools need to ensure that those systems can produce the granular transaction-level records and access logs that an ESMA-standard resilience review would require.

The EU MiCA review consultation and what it means for accounting firms provides important context on how the regulatory framework itself is likely to evolve, which shapes the longer-term compliance architecture that CASPs and their advisers should be building toward.

Immediate Action Points for Compliance and Finance Teams

The ESMA CSA is live. Whether or not a specific CASP falls within the initial sample, the review will set benchmarks that are likely to become the standard expectation for the sector as a whole. Compliance and finance teams should treat the following as immediate priorities.

Documentation and Gap Analysis

  • Map DORA obligations against existing MiCA compliance documentation. Identify where evidence gaps exist, particularly around ICT risk management and third-party vendor assessments. The two frameworks share some requirements but the evidentiary standards differ.
  • Review custody technology vendor contracts. DORA requires contractual resilience obligations to flow down to critical third-party providers. Existing contracts signed before DORA came into full effect may not contain the required clauses.
  • Test incident response plans. A written plan that has never been exercised will not satisfy an ESMA review. Tabletop exercises and documented results are the minimum expected standard.
  • Audit key management procedures. Who has access, under what conditions, and with what authorisation controls? If the answer cannot be produced quickly and in a format an external reviewer would accept, that is a gap.
  • Assess concentration risk in custody technology. If your CASP clients share infrastructure vendors with a significant number of other authorised firms, the systemic risk profile is elevated and regulators will expect to see that it has been recognised and managed.

Accounting professionals advising CASPs on their use of crypto bookkeeping software and digital asset accounting software should also confirm that those systems generate immutable audit trails and are able to support the record-keeping obligations that both MiCA and DORA impose. A system that produces summary reports is not sufficient if granular transaction records are required for a supervisory review.

MiCA Licensing Is Just the Start: ESMA Puts Crypto Custodians Under the Microscope

Frequently Asked Questions

What is ESMA's Common Supervisory Action on CASPs?

It is a coordinated review, led by ESMA and conducted through national competent authorities, that assesses the operational resilience of a sample of MiCA-authorised crypto asset service providers. The focus is specifically on custody activities and the four risk areas of key management, transaction controls, incident response, and third-party dependencies.

Does a MiCA licence automatically satisfy DORA requirements?

No. MiCA and DORA are separate regulatory frameworks with different evidentiary requirements. A CASP that has received MiCA authorisation still needs to demonstrate compliance with DORA's ICT risk management standards, including the contractual obligations that must be placed on critical third-party technology vendors.

Which firms are included in the ESMA CSA?

ESMA has confirmed that the CSA applies to a sample of CASPs that have already been authorised under MiCA. The precise selection methodology has not been published, but the findings are expected to set benchmarks that will apply sector-wide over time.

How should accounting firms prepare clients for this level of scrutiny?

Start with a gap analysis that maps existing MiCA compliance documentation against DORA's ICT risk management requirements. Then work through vendor contracts, key management procedures, incident response test records, and transaction control frameworks. Clients should be able to produce this evidence quickly and in a format that an external reviewer can assess independently.

What are the implications if ESMA gains direct supervisory authority over all CASPs?

Centralised ESMA supervision would replace the current model where national competent authorities apply MiCA standards with varying degrees of rigour. The practical effect would be a more uniform and likely more demanding compliance baseline across all EU member states. Firms that structured their authorisation around lighter-touch national supervisors should begin closing gaps now, before any centralisation takes effect.

Source: Cointelegraph

EUGeneralEnforcementAML/KYC & Licensing

Related articles

AML/KYC & Licensing
CSSF Flags consulting-mla.com as Unlicensed: What Accounting Firms and CFOs Must Act On
AML/KYC & Licensing
EU Sanctions 'Stern': Trickbot Boss and the $300M Ransom Trail
AML/KYC & Licensing
MFSA Fines Everest Network €40,560 for VFA Breaches
AML/KYC & Licensing
Binance's MiCA Setback and the Race for New Licenses