ESMA's MiCA Shift: From Writing Rules to Supervising Crypto Firms
MiCA's rulebook is largely built. ESMA now says the hard part is supervision — CASP resilience, outsourcing, reverse solicitation and harmonised reporting.
The EU's markets regulator has signalled a change of gear on MiCA. According to ESMA's chair, the authority's crypto work will now centre less on drafting the rulebook and more on supervising the firms that fall under it — specifically CASP resilience, outsourcing arrangements, reverse solicitation and harmonised reporting. In practice, that means the interesting questions for crypto firms in the EU are shifting from 'what does the text say?' to 'how will my national regulator check it, and against what benchmark?'
- Resilience — whether a crypto-asset service provider can keep operating and protect client assets through outages, cyber incidents, key-person dependencies or sudden market stress.
- Outsourcing — how far a CASP leans on third parties such as cloud providers, trading or custody vendors, and whether those dependencies, including ones outside the EU, are properly identified, contracted and monitored.
- Reverse solicitation — the MiCA carve-out where an EU client approaches a third-country firm purely on its own initiative. Regulators treat it as a narrow exception, not a distribution channel.
- Harmonised reporting — consistent data collection across national competent authorities so supervisors across member states work from comparable information rather than divergent templates.
The case for supervision-first
Supporters argue the sequencing is simply what a maturing regime looks like. MiCA's licensing wave is underway, so the marginal value now sits in how consistently the rules are applied. Without supervisory convergence, a firm could face materially different scrutiny depending on which national competent authority authorised it — which undermines the single-market logic of a regulation that was designed to be directly applicable across the EU. A supervision-first ESMA also lines up with the broader EU push on operational resilience for financial entities, which crypto-asset service providers are already expected to sit inside. From this view, resilience, outsourcing and clean data are not new obligations so much as the areas where existing obligations are most likely to be tested in a real incident.
The pushback and the open questions
Critics and even some supervisors raise fair concerns. National competent authorities differ widely in crypto expertise and headcount, so 'harmonised supervision' can mean the strictest regulator's expectations become everyone's de facto standard — without a formal rule change. Reverse solicitation is notoriously hard to police: a website, a social media post or an unsolicited marketing push blurs the line between a client's own initiative and active targeting, and proving intent after the fact is difficult. Industry groups warn that resilience and outsourcing reviews could duplicate work already done under existing operational resilience regimes, adding cost that falls hardest on smaller CASPs. And there is a structural tension: ESMA coordinates and can promote convergence, but day-to-day authorisation and enforcement remains with national authorities, so outcomes may stay uneven in practice.
What to watch next
- Whether ESMA publishes further convergence or peer-review outputs that reveal how differently national authorities are treating the same MiCA obligations.
- How supervisory reviews actually define 'resilience' — the specific evidence, testing or documentation CASPs are asked to produce.
- Any enforcement or sanction action tied to reverse solicitation, which would give the clearest signal on where regulators draw the line.
- Whether harmonised reporting templates are standardised across member states, and how quickly firms are expected to comply.
- Whether the Commission or ESMA signals any legislative or technical adjustment in response to supervisory friction, rather than treating the rulebook as finished.
What does it mean that ESMA is shifting MiCA from rulemaking to supervision?
It means the EU's core crypto rulebook is largely in place, and ESMA's attention is moving to how consistently those rules are applied. The named priorities are CASP resilience, outsourcing, reverse solicitation and harmonised reporting across national regulators.
What is reverse solicitation under MiCA?
It is the limited situation where an EU client contacts a third-country firm entirely on the client's own initiative, rather than the firm marketing into the EU. Regulators treat it as a narrow exception, and how to prove that genuine initiative is one of the harder supervision questions.
Which firms does MiCA supervision apply to?
MiCA's licensing and conduct requirements apply to crypto-asset service providers authorised in the EU, including exchanges, custody providers and other regulated crypto services. Supervision is carried out day to day by national competent authorities, with ESMA coordinating and promoting convergence.
Does this change any MiCA rules?
The shift as described is about supervisory focus rather than new requirements. But in practice, tighter and more harmonised supervision can raise the effective bar — especially where national regulators apply existing obligations more rigorously or consistently.
Why is outsourcing such a focus for crypto firms?
Many CASPs rely heavily on third-party infrastructure, including cloud and specialist vendors, some outside the EU. Supervisors want those dependencies identified, contracted and monitored, since an outage or failure at a provider can directly affect client assets and service continuity.