Skip to content
HOME / NEWS / SYNTHESIS
News
Live

ESMA Launches Year-Long Custody Compliance Review Across 283 EU-Registered CASPs


Key points

  • ESMA has instructed national regulators to audit digital asset custody practices at MiCA-registered CASPs over the next twelve months.
  • There are currently 283 registered CASPs in the EU, with more than a quarter of licences issued since June 2026, reflecting a last-minute surge before the transition deadline.
  • Binance withdrew its Greek MiCA application days before the deadline and is currently unlicensed in the EU.
  • The review will assess governance, key and storage management, transaction controls, incident response, smart contract risks, and third-party provider dependencies.
  • Although the review is MiCA-driven, ESMA's framing draws on DORA language, signalling that cross-regulatory compliance expectations are converging around operational resilience.

The European Securities and Markets Authority (ESMA) has directed national regulators to begin examining the digital asset custody practices of crypto asset service providers (CASPs) registered under the Markets in Crypto-Assets (MiCA) framework. The review programme will run for one year and arrives immediately after the close of the MiCA transition period for nationally licensed exchanges, a deadline that has already left some large operators unlicensed. Binance, for instance, withdrew its Greek application in the days before the cut-off.

The EU now counts 283 registered CASPs, a number that grew sharply in the final weeks of the transition window, with more than a quarter of all licences granted since the start of June. The commercial significance of MiCA registration is material: a licence confers passporting rights across the entire European market rather than restricting a provider to its home jurisdiction.

The custody review covers six broad areas: governance arrangements, key and storage management, transaction controls, incident detection and response, smart contract risks, and dependencies on third-party providers. ESMA’s framing borrows from the Digital Operational Resilience Act (DORA), a separate piece of EU legislation, even though the review is MiCA-driven. The scope reflects the pattern of material crypto losses attributable to custody failures, which suggests regulators view this as the most consequential near-term control gap to close.

Original source

Ledger Insights

ledgerinsights.com