#MiCA #ESMA #加密监管 Have you passed just by obtaining a MiCA license? Today, in the ESMA’s 2027 work programme, there’s another perspective: regulators are shifting their focus to whether licensed institutions can continuously demonstrate that they have genuine operational capabilities.

This isn’t news about the EU issuing yet another new prohibition today. The document is the work programme for the year ahead—so you can’t write the proposed supervisory actions as if they’ve already been punishment for specific parties. It’s worth looking at because it breaks abstract compliance requirements into several items that can be checked: the digital operational resilience of crypto-asset service providers (CASPs), whether there are sufficient business entities and personnel within the EU, outsourcing risks, liquidity in the EU crypto market, and cross-border solicitation of clients and asset classification. ESMA also intends to push for greater consistency in the reporting format of CASP periodic reports received by regulators in different member states.

The timeline matters too. In June 2026, a joint supervisory action targeting operational resilience of crypto-custody services was already launched; ESMA plans to publish in 2027 a consolidated final report of findings across countries. What was published today is the 2027 execution list—its report conclusions have not been issued yet. The plan also states that the first phase of MIDAS, ESMA’s monitoring system for the MiCA crypto market, is expected to be fully operational by 2027; the rollout of the second phase still depends on approval by the ESMA Management Board. Calling it “comprehensive monitoring already live today” would be premature.

I believe the real variable here is “verifiability after licensing.” If member states gradually use more aligned reporting formats, custody outages, outsourcing of critical functions, and liquidity arrangements can be compared against a single yardstick more easily. Institutions that obtain authorization but cannot continuously explain operational risks may face greater pressure later. However, this is an inference based on the work programme—not a conclusion from an investigation into any specific trading platform, and it doesn’t mean any particular token will immediately benefit or be harmed.

Next, watch three things: which gaps the 2027 final report on custody resilience specifically points out; how member states implement consistent reporting formats; and whether the second phase of MIDAS can be approved. In your view, what evidence will licensed institutions find hardest to provide in the future—responses to custody failures, outsourcing controls, or local liquidity within the EU?

Source: ESMA “2027 Annual Work Programme”, 2026-09-28.