ESMA's 2027 MiCA Program Puts Operational Resilience First for Bitcoin (BTC) Firms
ESMA's 2027 MiCA work program targets operational resilience, outsourcing and liquidity as only 281 of 1,343 EU crypto firms held licenses after July 1.
AI SummaryAI
- Only 281 of 1,343 crypto service providers held MiCA authorization after the July 1 deadline.
- Unauthorized firms sent $5 billion to sanctioned counterparties versus $1.7 billion from authorized firms.
- ESMA's register reached 300 providers in early July, adding Standard Chartered and FalconX.
- MIDAS crypto market surveillance system's first phase becomes fully operational in 2027.
Operational Resilience Leads ESMA's 2027 MiCA Agenda
Operational resilience, outsourcing arrangements and liquidity risk will set the tone of crypto supervision in the European Union next year, under the 2027 work program the European Securities and Markets Authority (ESMA) published on Monday. The program — the annual document that directs how the hard fork-resistant rulebook known as the Markets in Crypto-Assets Regulation (MiCA) is enforced — tasks ESMA and the national competent authorities (NCAs) that license crypto asset service providers (CASPs) with building a more consistent supervisory record across member states, after two years spent writing and implementing the rulebook itself. Chair Verena Ross framed the shift at Monday's ECON committee hearing of the European Parliament's Committee on Economic and Monetary Affairs, saying ESMA's MiCA work had moved “from rulemaking towards supervision and convergence,” adding that innovation should flourish “within a framework that provides clarity for firms, safeguards for investors and confidence in the markets.” Five priorities stand out: operational resilience, outsourcing, liquidity, reverse solicitation — the carve-out that lets an EU client approach a third-country firm on the client's own exclusive initiative — and whether firms maintain sufficient operations inside the EU rather than depending on functions or infrastructure based elsewhere. On resilience, supervisors will carry forward an EU-wide priority in place since 2025, while a new digital innovation priority will initially examine how supervised entities deploy artificial intelligence and tokenization, technologies that projects such as Fetch.ai (FET) are built around. ESMA also plans common risk indicators and supervisory dashboards so NCAs can monitor licensed firms on comparable terms, and its MIDAS surveillance system — the centralized tool for detecting potential market abuse across crypto venues, from Bitcoin (BTC) order books to niche platforms — is expected to reach full operation in its first phase during 2027, extending oversight to venue types well beyond traditional exchanges, including prediction markets such as Polymarket.
A Smaller Licensed Pool After the July 1 Deadline
The supervisory pivot lands after MiCA's final transition period expired on July 1, ending national registrations and leaving firms without EU-wide authorization formally outside the perimeter. Only 281 of 1,343 crypto service providers operating across the European Economic Area had secured MiCA authorization at the deadline, and the risk gap was stark: 12% of unauthorized firms carried High or Severe risk ratings against 2% of authorized providers, while unauthorized firms had sent $5 billion directly to sanctioned counterparties compared with roughly $1.7 billion from licensed ones. The authorized pool has since grown — ESMA's register reached 300 providers in early July after 57 firms gained authorization, among them Standard Chartered and FalconX — and licensed venues can use MiCA passporting to offer covered services across all member states, an edge several of the Best Crypto Exchanges have moved to secure. Supervision has already moved past the licensing question: a Common Supervisory Action launched in July is testing how authorized custodians manage private keys, transaction controls, incident response and reliance on third-party technology providers, examining the controls that operate after a license is granted rather than the license itself. Enforcement questions persist around firms serving Europeans without authorization. Binance, which missed the July 1 deadline and withdrew its Greek application in June, continued serving some EU customers through reverse solicitation while pursuing licenses elsewhere, and ESMA has sought confirmation that the exchange is winding down relevant EU operations. Classification of crypto assets — a task complicated by protocol events such as a hard fork, which can split a ledger and blur which token carries which rights — also features in the 2027 plan. A BaFin official warned in September that centralizing authorization at EU level could burden firms and erode local market knowledge. ESMA's findings will feed the European Commission's MiCA review, due by June 2027, following a public consultation that ran from May through Aug. 31. Readers tracking the market in real time can follow live spot and futures prices on Bitget.
The Reverse-Solicitation Clause Carries the Weight
COINOTAG's reading of the program document: it creates no new law. It binds national competent authorities to coordinated priorities under powers MiCA already grants, with supervisory findings flowing into the Commission's review expected by June 2027. The provision doing the most work is the paired scrutiny of reverse solicitation and firms' “sufficient” EU operations — the same carve-out Binance leans on. If supervisors narrow the exclusive-initiative test in 2027, offshore venues without a license lose their last lawful route to EU clients, and client-facing services such as copy trading, where firms mirror third-party traders' positions, become harder to offer outside the authorized perimeter.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


