Banks Now Fill Nearly 1 in 4 Slots on ESMA's MiCA Register
Europe's regulated crypto market is being reshaped from the inside. Traditional banks have roughly doubled their presence on the European Securities and Markets Authority (ESMA) MiCA register between late June and mid-September 2026, pushing their share of listed crypto-asset service providers (CASPs) from around 17% to nearly 23%. For accounting firms, auditors, and CFOs advising EU financial-sector clients, this is a structural shift that changes how MiCA compliance crypto engagements, audit scope, and counterparty classification need to be approached.
What the ESMA Data Actually Shows
ESMA maintains a public register of entities authorised or notified to provide crypto-asset services under the Markets in Crypto-Assets Regulation (MiCA). According to a Cointelegraph analysis of that register, the headline numbers between 26 June and 16 September 2026 tell a clear story.
The key figures at a glance
The total number of listed CASPs rose from 243 to 349 over the period. Within that growth, the bank cohort approximately doubled, rising from roughly 40 institutions to around 80. Non-bank providers still hold the majority of slots and grew in absolute terms, but their relative share fell from around 84% to 77% as banks expanded far faster. The direction of travel is unambiguous: banks are entering the MiCA-regulated space at a pace that outstrips the growth of native crypto companies.
Germany is driving the banking wave
Much of the banking expansion can be traced directly to Germany. The country's additions to the ESMA register include Deutsche Bank, Germany's largest lender, which confirmed it expects to receive MiCA regulatory approval for its institutional and corporate digital asset offering in October 2026. Beyond the headline name, numerous Volksbank, Raiffeisenbank, and VR Bank institutions also appeared on the register during the period. That last point matters: these are regional cooperative banks, not global investment houses. It signals that MiCA-compliant crypto services are now penetrating Germany's deep cooperative banking network, not just its tier-one institutions. For context on Germany's broader position in European crypto licensing, see our earlier coverage of Germany's growing role in European crypto adoption and MiCA licensing.
How Banks Enter the MiCA Register: The Notification Route
Understanding why banks can expand so quickly requires understanding a key structural feature of MiCA itself. Credit institutions do not go through the same authorisation process as native crypto firms.
Credit institution notification vs. CASP authorisation
Under MiCA, a credit institution that wishes to provide crypto-asset services can do so via a notification procedure rather than a full authorisation application. The institution must submit the required information to its home national competent authority at least 40 working days before it intends to provide those services for the first time. Provided the notification is complete, the institution may proceed without waiting for a formal authorisation decision in the same way a new-entrant CASP would.
This is a deliberate legislative design choice. Banks are already subject to extensive prudential supervision under the Capital Requirements Directive (CRD), so the MiCA framework does not require them to demonstrate the same baseline fitness that a new crypto firm must establish from scratch. The practical result is a faster, lighter on-ramp that explains the rapid doubling of bank entries on the ESMA register in under three months.
What services banks can offer under notification
The notification route covers the full range of crypto-asset services defined in MiCA, including custody and administration of crypto-assets on behalf of clients, operation of a trading platform, exchange of crypto-assets for funds or other crypto-assets, and execution and reception of transfer orders. This means banks are not entering the market in a limited or ring-fenced capacity; they can, in principle, offer the same suite of services as a fully authorised CASP.
Implications for MiCA Compliance Crypto Engagements
The bank influx has direct consequences for professionals handling MiCA compliance crypto work, whether that is ongoing advisory, audit, or financial reporting.
Expanded audit and assurance universe
For accounting firms and auditors, the register's growth from 243 to 349 CASPs in roughly 12 weeks represents a meaningful expansion of the addressable market for crypto-related assurance work. More importantly, the inclusion of regulated credit institutions changes the risk profile of individual engagements. Banks bring established internal control frameworks, existing AML/KYC infrastructure, and prudential reporting obligations, but they also introduce novel complexity at the intersection of traditional banking ledgers and digital asset accounting software requirements. Reconciling on-chain settlement with core banking systems is a live challenge that audit teams need to be equipped to address.
Counterparty classification and due diligence
CFOs and treasury teams at non-bank entities that interact with the CASP ecosystem now face a more heterogeneous counterparty landscape. A crypto custodian that was previously a native crypto firm may now be a regional cooperative bank operating under MiCA notification. The due diligence checklist, AML screening protocols, and contractual representations required differ materially depending on whether the counterparty holds a CASP authorisation or operates under the credit institution notification route. Finance teams should revisit their counterparty onboarding procedures to account for this distinction.
Competitive pressure on native CASPs
For accounting practices that advise or audit native crypto firms, the bank influx is relevant beyond regulatory mechanics. Banks entering via notification with existing client relationships, lower marginal cost of compliance, and established balance sheets will put competitive pressure on standalone CASPs, particularly in custody and brokerage. Some native CASPs may respond by seeking partnerships, consolidating, or pivoting to services where banks have less structural advantage. Each of those strategic responses has accounting, tax, and audit implications that advisers should be tracking now rather than after the fact. For further background on Deutsche Bank's specific digital asset move, our article on Deutsche Bank's digital asset custody launch in Europe provides useful context.
Accounting and Reporting Considerations
The practical accounting implications of this shift break down across two dimensions: what changes for banks themselves, and what changes for the firms and clients that engage with them.
For banks adding crypto-asset services
Banks that notify under MiCA and begin offering custody or trading services must integrate digital asset accounting software workflows with existing IFRS 9 and IFRS 7 reporting frameworks. Crypto-assets held in custody for clients are typically off-balance-sheet, but fee income, interest-equivalent structures, and any proprietary positions require careful classification. IFRS standards do not yet contain crypto-specific guidance at the level of granularity that practitioners need, meaning banks will be applying existing intangible asset or financial instrument frameworks by analogy, with all the judgement and disclosure risk that entails.
Operational risk capital treatment under CRD VI and any forthcoming EBA guidance on crypto exposures also feeds directly into Pillar 3 disclosures. Audit committees at newly MiCA-notified banks should be asking management now how these positions will be classified, measured, and disclosed in the next set of financial statements.
For firms using crypto bookkeeping software
Practices that use crypto bookkeeping software to support client reporting need to confirm that their tooling can handle the data formats, transaction types, and counterparty identifiers that bank-operated CASPs will generate. Bank-issued transaction reports may differ structurally from those produced by native crypto platforms, and any gaps in data ingestion can create reconciliation failures that are expensive to resolve at year-end. Proactive data-format mapping with new bank counterparties is a straightforward step that can prevent significant downstream work.
What Firms Should Do Right Now
The ESMA register is publicly accessible and updated regularly. The practical steps for advisory and audit practices are concrete and should not wait for further regulatory developments.
Immediate actions for accounting and advisory firms
First, pull the current ESMA MiCA register and cross-reference it against your existing client list. Any client that interacts with a CASP on that register should be reviewed to determine whether the provider is a bank-notified institution or a standard CASP authorisation holder, as the risk and compliance implications differ. Second, update engagement letters and audit planning memos to reflect the expanded CASP universe and the specific complexity of bank-operated crypto services. Third, ensure that staff working on digital asset engagements understand the distinction between the MiCA notification and authorisation routes, since this affects how you assess the regulatory standing of a counterparty or audit subject. Finally, monitor ESMA's register on a cadence that matches your clients' review cycles, because the pace of new entrants over the summer suggests the register will continue to grow materially through the end of 2026.
Frequently Asked Questions
What is the ESMA MiCA register and who appears on it?
ESMA maintains a public register of entities authorised or notified to provide crypto-asset services under the EU's Markets in Crypto-Assets Regulation. Both fully authorised CASPs and credit institutions that have filed a notification under MiCA appear on the register. It is the primary public record of who is legally permitted to offer regulated crypto services across the EU.
How does the bank notification route under MiCA differ from standard CASP authorisation?
A credit institution that wants to offer crypto-asset services under MiCA does not need to obtain a separate CASP authorisation. Instead, it submits required information to its home national competent authority at least 40 working days before commencing those services. This is a lighter and faster process than the full authorisation procedure that a new-entrant crypto firm must complete, reflecting the fact that banks are already subject to rigorous prudential supervision.
Why does the bank-versus-CASP distinction matter for audit and accounting work?
The regulatory entry route affects the internal control environment, the prudential capital framework, and the reporting obligations of the entity. A bank operating under MiCA notification is simultaneously subject to CRD requirements, EBA guidelines, and MiCA obligations, creating a more complex overlay than a standalone CASP. Auditors and advisers need to scope engagements accordingly and cannot apply a one-size-fits-all crypto-engagement approach.
What accounting standard applies to crypto-assets held by MiCA-notified banks?
There is currently no IFRS standard specifically addressing crypto-assets held by banks in a custody or proprietary capacity at the level of detail practitioners need. Banks are applying existing frameworks, principally IAS 38 for intangible assets or IFRS 9 for instruments that meet the financial asset definition, by analogy. The IASB has the topic on its agenda, but no finalised guidance had been issued as of the date of this article. This creates meaningful judgement and disclosure risk that audit committees should be actively discussing with management.
Is the pace of bank entries on the ESMA register likely to continue?
Based on the trajectory observed between June and September 2026, there is no obvious reason for the pace to slow in the near term. The 40-working-day notification window means banks that began preparing submissions in mid-summer would be appearing on the register through autumn. Germany's cooperative banking sector has shown that the appetite extends well beyond tier-one institutions. Firms should plan for a register that continues to expand materially through the remainder of 2026.
Source: Cointelegraph
