ESMA to Scrutinize Crypto Custody Risks Under MiCA Rules
Europe's top securities regulator is turning its focus to crypto custody providers, examining key management, incident response, and third-party tech risks.
The European Securities and Markets Authority (ESMA) is sharpening its supervisory lens on cryptocurrency custody providers following the transition to the Markets in Crypto-Assets (MiCA) regulatory framework. The EU's top securities watchdog has signaled it will assess how custodians manage private keys, respond to security incidents, and depend on external technology vendors — three pressure points that regulators have long viewed as systemic vulnerabilities in the digital asset ecosystem.
Custody is arguably the most operationally sensitive layer of any crypto business. Unlike traditional financial assets, where settlement and safekeeping rely on well-tested clearinghouse infrastructure, crypto custody hinges on cryptographic key management. A single lapse — whether a compromised key, a misconfigured wallet, or a breach at a third-party cloud provider — can result in irreversible asset loss. ESMA's decision to focus here reflects a broader recognition that MiCA's legal framework is only as strong as the operational resilience of the firms operating under it.
Read more Iran Holds Strait of Hormuz Talks With Saudi Arabia and Oman →
The emphasis on third-party technology reliance is particularly telling. Many custody providers outsource core infrastructure to a small number of cloud and security vendors, creating concentration risk that regulators across financial services have been flagging for years. ESMA's review suggests it intends to apply similar scrutiny to crypto custodians as EU banking supervisors have applied to traditional financial institutions under the Digital Operational Resilience Act (DORA), which also took effect this year.
Incident response protocols are the third pillar of ESMA's review. In practice, crypto firms have historically varied widely in their ability to detect, contain, and disclose security events in a timely manner. By making incident response a formal supervisory criterion, ESMA is effectively raising the floor for how custody providers must document and test their contingency procedures — a move that could prompt significant compliance investment across the sector.
For the broader crypto industry, ESMA's custody focus sends a clear signal: MiCA's passage was not the finish line but the starting gun for intensive regulatory oversight. Firms that treated licensing as the primary compliance hurdle may find that ongoing operational supervision is the more demanding challenge. Continue reading at Cointelegraph.