Key Findings of the ESMA Custody Review
Published 7/9/2026, 6:34:41 AM
ESMA's first MiCA custody review, conducted via a Common Supervisory Action (CSA), marks the transition from regulatory development to active enforcement. As of July 1, 2026, the transitional "grandfathering" period has ended, making full MiCA authorization mandatory for all Crypto-Asset Service Providers (CASPs) in the EU. The review signals a shift toward institutional-grade security, specifically targeting key management, asset segregation, and operational resilience.
Key Findings of the ESMA Custody Review
The review focuses on digital operational resilience and the safeguarding of client assets. While specific technical mandates for Multi-Party Computation (MPC) and FIPS-validated Hardware Security Modules (HSMs) are noted as focus areas, they remain subject to ongoing supervisory scrutiny rather than universal prescription.
- Key & Storage Management: There is a strict emphasis on the majority of client assets being held in cold storage.
- Asset Segregation: CASPs must maintain strict legal and operational segregation of client assets from the firm’s own estate, with a total prohibition on commingling assets with other group entities (ESMA_QA_2578).
- Liability Framework: Custodians now bear explicit liability for the loss of crypto-assets or private keys resulting from operational failures.
- Operational Resilience: Under the Digital Operational Resilience Act (DORA), effective since January 17, 2025, custodians must demonstrate robust incident detection and management of third-party dependencies.
Operational and Compliance Implications
The conclusion of the transitional period on July 1, 2026, has created immediate hurdles for firms that failed to secure authorization.
| Requirement | Detail | Operational Impact |
|---|---|---|
| Authorization | Mandatory CASP license from a National Competent Authority (NCA). | Unauthorized firms must cease services immediately and execute wind-down plans. |
| Capital Reserves | Minimum €125,000 for custody services. | Firms must also maintain liquid funds equal to 25% of fixed overheads. |
| Staff Competence | Mandatory documentation by July 28, 2026. | Two-tier training (Information vs. Advice) required for all client-facing staff. |
| Stablecoins (EMTs) | 100% reserve backing; 30% in EU credit institutions. | Issuers (e.g., USDC, EURC) must comply with PSD2 for transfer services. |
Market Impact and Enforcement
ESMA's review has already led to significant market consolidation and exits by major players unable or unwilling to meet the new standards.
- Market Exits: Major platforms have faced regulatory friction; for instance, Bitget suspended services for French users effective March 31, 2026, while seeking authorization. Reports also indicate Binance faced rejection for its license application in Greece.
- Licensing Hubs: As of March 2026, over 40 CASP licenses have been issued across the EU, with Germany and France emerging as the primary regulatory hubs for crypto operations.
- Orderly Wind-Down: An April 2026 ESMA statement mandates that unauthorized CASPs stop onboarding new EU clients and limit existing services to position closures or asset transfers.
Critical Deadlines for 2026
- July 1, 2026: Full MiCA enforcement begins; end of all transitional "grandfathering" periods.
- July 28, 2026: Deadline for firms to document staff knowledge and competence under Article 81(7).
- H1 2027: Expected conclusion of the first coordinated EU-wide custody assessments by National Competent Authorities.
In summary, ESMA's review forces European crypto operations to adopt traditional financial-grade custody standards. Firms that cannot meet the €125,000 capital floor, strict cold storage requirements, and DORA-compliant resilience frameworks are being systematically pushed out of the EEA market.