The implementation of the MiCA regulation in the European Union is shifting from rulemaking to monitoring compliance and harmonizing practices among national regulators. This was stated by Verena Ross, head of the European Securities and Markets Authority (ESMA).
“Our focus under MiCA has shifted […] toward harmonizing supervisory practices,” Ross said.
On September 28, ESMA presented its 2027 work program. Among its priorities, the agency highlighted the coordination of national regulators in the supervision of crypto-asset service providers (CASP).
The regulator intends to focus on companies’ operational resilience, outsourcing, liquidity, the classification of crypto-assets, and the consistent application of rules across EU countries.
One area of focus will be oversight of the “pull” mechanism. This mechanism allows a company from a third country to serve a European client without a MiCA license if the client initiated the service entirely on their own.
Article 61 of MiCA stipulates that the exemption does not apply if a foreign company actively solicits clients in the EU through advertising, promotion, or other means. ESMA has previously emphasized that the mechanism must be interpreted narrowly and cannot be used to circumvent regulation.
The regulator will pay particular attention to the actual presence of crypto companies in the European Union. According to Article 59 of MiCA, a licensed CASP must have a registered office in one of the EU member states, conduct at least part of its business within the EU, maintain an effective center of management there, and have at least one resident director.
ESMA Will Intensify Monitoring of the Crypto Market
In 2027, the agency will continue to harmonize the practices of national regulators and develop a common supervisory infrastructure. ESMA’s roadmap states that by that time, the first phase of the integrated MiCA monitoring system should be fully operational.
The platform will allow 26 national competent authorities to use a single ESMA tool for day-to-day monitoring and supervision of the crypto market. The regulator also intends to develop centralized data and technological tools for risk analysis.
At the same time, ESMA will continue to oversee compliance with market integrity requirements. In April 2025, the agency published recommendations for national regulators on identifying and preventing market abuse in the crypto market. The document takes into account the market’s cross-border nature and the role of social media.
In July 2026, ESMA also launched a separate review of the operational resilience of crypto custodians. National regulators must assess key management and asset storage, transaction monitoring, incident handling, smart contract risks, and reliance on third-party providers.
MiCA Has Now Entered Full Implementation
On July 1, 2026, the MiCA transition period for crypto companies ended in the EU. After that date, service providers without the necessary authorization must cease serving European clients.
The end of the transition period has made the supervision of already licensed companies the next phase of MiCA’s implementation. Back in its 2026 agenda, ESMA indicated that it would focus not only on issuing authorizations but also on supervising CASPs and harmonizing the practices of national regulators.
At the same time, European regulators are discussing expanding the scope of MiCA itself. On September 24, the European Banking Authority proposed considering the inclusion of crypto lending and loans, including services through which centralized companies provide clients with access to DeFi protocols. Possible measures mentioned include leverage limits, additional disclosure requirements, and verification of the suitability of services for clients.
As a reminder, in July, the European Parliament adopted a political position on the further regulation of digital assets, including DeFi, NFTs, staking, and other segments that the current version of MiCA covers only partially or does not regulate directly.