
The regulation of the crypto market in the European Union enters a new phase: after completing the main work on implementing MiCA, the focus shifts to monitoring compliance with requirements and harmonizing the practices of national regulators. In ESMA's program for 2027, a separate focus is on the supervision of crypto asset service providers (CASP). The regulator intends to monitor their operational resilience, liquidity management, use of third-party contractors, and the correct classification of crypto assets. An additional direction will be the control over the presence of companies in the EU. A licensed CASP must have a registered office in one of the bloc's countries, conduct at least part of its activities there, have a factual management center, and have at least one resident director. There are plans to monitor the use of the reverse solicitation mechanism, which allows a company from a third country to serve an EU client without a MiCA license only if the client initiated the contact. Active solicitation of European users by a foreign company does not fall under this exception.
To unify supervision, ESMA is developing a common infrastructure for monitoring the crypto market. The first phase of the integrated system is expected to be fully operational in 2027, providing 26 national competent authorities with a single tool for everyday control. The platform will use centralized data and technological means for risk analysis. Work will continue in parallel to prevent market manipulation and other violations of MiCA requirements, including monitoring cross-border operations and social media activity. The operational resilience of crypto custodians is being separately checked: regulators are examining key management and asset storage procedures, transaction control, incident response, smart contract risks, and reliance on external suppliers. This approach implies a shift from predominantly formal license control to a continuous assessment of how companies actually organize their activities and manage risks.
The MiCA transition period for crypto companies in the EU ended on July 1, 2026. After this date, providers that have not obtained the necessary authorization must cease serving European clients, which fully transitions the industry to a mode of full compliance with requirements. Simultaneously, the expansion of the regulated perimeter is being discussed: potential new directions include crypto lending and certain services related to centralized platforms' access to DeFi protocols. Such operations may require additional disclosure rules, leverage limits, and product suitability assessments for clients. Thus, the further development of MiCA is associated not so much with creating a basic regulatory framework as with its uniform application, technological monitoring, and the possible expansion of the range of covered cryptocurrency services.





