The European Securities and Markets Authority (ESMA) will make operational resilience, outsourcing, liquidity, reverse solicitation and firms’ EU-based operations central to its supervision of crypto companies in 2027.
The regulator’s work programme, published on Monday, marks a shift from developing and implementing the Markets in Crypto Assets Regulation (MiCA) towards checking how authorised crypto-asset service providers (CASPs) comply with the rules in practice.
ESMA chair Verena Ross described the change to the European Parliament’s Committee on Economic and Monetary Affairs as a move “from rulemaking towards supervision and convergence”.
ESMA will work with national competent authorities to coordinate oversight and improve consistency across the European Union. It plans to introduce common risk indicators, reporting standards and supervisory dashboards to help authorities assess licensed firms using comparable information.
Operational resilience will be a major focus. Supervisors will also examine outsourcing arrangements, liquidity management, the classification of crypto assets and whether companies maintain sufficient operations within the EU rather than relying extensively on functions or infrastructure based elsewhere.
Under MiCA, CASPs remain responsible for meeting their regulatory obligations when work is outsourced. Such arrangements must not prevent national regulators from carrying out their supervisory responsibilities.
The priorities follow work already under way. In July, crypto.news reported that ESMA had begun reviewing MiCA custodians, including their management of private keys and storage, transaction controls, incident response and dependence on third-party technology providers.
The Common Supervisory Action is designed to assess the controls firms operate after receiving authorisation, rather than focusing only on whether a licence has been granted.
Cyber and operational resilience will remain an EU-wide supervisory priority in 2027, alongside a new focus on digital innovation. ESMA said on 23 September that this would initially cover the use of artificial intelligence and tokenisation by supervised entities. The resilience priority has been in place since 2025.
Market surveillance and reporting
ESMA expects the first phase of its MIDAS crypto-market surveillance system to become fully operational in 2027. The centralised platform is intended to help identify potential market abuse.
A second phase, first disclosed in February, is planned for the fourth quarter of 2027, subject to board approval. It will add further analytical capabilities and new types of data. ESMA has already issued guidance to national authorities on preventing and detecting market abuse under MiCA.
The regulator also plans to expand its wider use of data and technology through the ESMA Data Platform, artificial intelligence tools, cybersecurity work and tokenisation initiatives.
Supervision after the transition deadline
ESMA’s increased focus follows the expiry of the final MiCA transition period on 1 July. Firms previously operating under national registrations then faced EU-wide authorisation requirements.
At the time, 281 of 1,343 crypto service providers operating across the European Economic Area had secured MiCA authorisation, leaving 1,062 without approval. Of the unauthorised firms, 12% had High or Severe risk ratings, compared with 2% of authorised providers. Unauthorised firms had sent $5 billion directly to sanctioned counterparties, while authorised firms recorded about $1.7 billion.
ESMA’s register reached 300 providers in early July after 57 firms, including Standard Chartered and FalconX, gained authorisation. Those providers can use MiCA passporting rights to offer covered services across EU member states.
Questions remain over firms serving European customers without a MiCA licence. Binance continued serving some EU customers through provisions including reverse solicitation after missing the 1 July deadline and withdrawing its Greek application in June. ESMA sought confirmation that the exchange was properly winding down relevant EU operations while pursuing authorisation elsewhere.
Reverse solicitation, where an EU client independently initiates contact with a third-country firm, will remain a supervisory priority.
ESMA’s findings will contribute to the European Commission’s MiCA review, expected by June 2027. The Commission’s consultation on the framework ran from May to 31 August and included individuals, providers, issuers, financial institutions, academics, industry groups and public authorities.
The work programme leaves national regulators responsible for CASP oversight, while placing greater emphasis on coordination, shared tools and consistent application of MiCA.
