ESMA's 2027 MiCA Supervision Priorities: What CASPs Must Prepare For
The European Securities and Markets Authority (ESMA) has formally moved past MiCA's legislative construction phase. Speaking to the European Parliament's Committee on Economic and Monetary Affairs, ESMA Chair Verena Ross confirmed that the regulator's focus has shifted "from rulemaking towards supervision and convergence." The 2027 work programme, published on the same day, sets out exactly where that supervisory attention will land, and the list reads like a compliance gap-analysis checklist for every crypto asset service provider (CASP) active in the EU.
The Strategic Shift: From Rules to Supervision
MiCA's core framework is now in force across all EU member states. What follows is the harder work: making sure national competent authorities (NCAs) apply it consistently, and that CASPs do not exploit divergence between jurisdictions to soften compliance obligations in practice.
Ross framed the ambition clearly, stating that ESMA wants "innovation to flourish within a framework that provides clarity for firms, safeguards for investors and confidence in the markets." That framing matters. ESMA is not signalling a crackdown for its own sake; it is trying to prevent regulatory arbitrage from hollowing out a regime that took years to build.
Why convergence is the headline priority
Because NCAs supervise CASPs at the national level, inconsistent application of MiCA's requirements creates real compliance risk. A firm supervised in one member state may face substantially different expectations on outsourcing governance or liquidity management than an equivalent firm supervised in another. ESMA's coordination role is to close those gaps, and the 2027 programme makes that explicit. Accounting and compliance teams at multi-jurisdictional CASPs should treat this as a warning that low-bar interpretations adopted during the licensing rush are unlikely to survive coordinated supervisory review.
Key Supervisory Focus Areas for 2027
ESMA's work programme identifies several specific thematic priorities. Each carries direct operational and financial reporting implications.
Operational resilience
CASPs are expected to demonstrate genuine resilience to operational disruptions, covering technology infrastructure, staffing, and the continuity of services to clients. This aligns with broader EU financial services regulation, including DORA, which applies to CASPs from the same date MiCA became fully effective. Firms that have treated resilience as a checkbox exercise face real exposure here. Auditors reviewing CASP clients should expect NCAs to request detailed evidence of business continuity testing, incident response protocols, and recovery time objectives.
Outsourcing risk
Outsourcing is one of the most practically complex areas in MiCA compliance. Many CASPs rely on third-party technology providers, custody partners, or affiliated group entities for critical functions. ESMA's focus on outsourcing risk signals that supervisors will scrutinise whether those arrangements genuinely transfer operational capability or merely shift liability on paper. Key questions will centre on whether the CASP retains meaningful oversight of outsourced functions, whether contracts include adequate audit rights, and whether exit strategies are credible.
From an accounting perspective, outsourcing arrangements may also trigger questions about the recognition of right-of-use assets or service concession arrangements depending on contract structure. Finance teams should review whether existing disclosures adequately describe material outsourcing dependencies.
Substance requirements and reverse solicitation
ESMA has flagged concerns that some firms are licensing in the EU without maintaining meaningful operations inside the bloc, effectively using an EU licence as a passporting vehicle while keeping substantive activity elsewhere. The 2027 programme targets this directly. Supervisors will assess whether CASPs have sufficient staff, decision-making authority, and risk management capability located within the EU.
Reverse solicitation, the provision of services to EU clients at the exclusive initiative of the client, is also under close scrutiny. MiCA permits third-country firms to serve EU clients on this basis without authorisation, but ESMA has consistently emphasised that the exemption is narrow and cannot be used systematically. Any firm relying on reverse solicitation arguments as a material part of its EU business model should expect that argument to be tested.
Liquidity and asset classification
Liquidity risk management and the correct classification of crypto assets round out the thematic priorities. On liquidity, supervisors will assess whether CASPs hold adequate liquid resources relative to the nature and scale of their activities, particularly for stablecoin issuers already subject to MiCA's explicit reserve requirements. On asset classification, the concern is whether firms are correctly identifying which tokens fall within MiCA's scope and which may be regulated under other frameworks such as MiFID II. Misclassification has both compliance and accounting consequences, since the applicable recognition and measurement treatment under IFRS or national GAAP may differ depending on whether a token is treated as an e-money token, an asset-referenced token, or another category of crypto asset.
Harmonised Reporting and Supervisory Dashboards
Alongside the thematic priorities, ESMA plans to standardise the periodic reporting that CASPs submit to NCAs. The goal is a common data structure that allows ESMA to aggregate supervisory intelligence across member states and build shared risk indicators.
What harmonised reporting means for finance teams
For accounting and finance teams, this is a practical signal. If your firm's current periodic reporting to your NCA uses bespoke formats, internal categorisations, or non-standard metrics, you should expect pressure to align with whatever common template ESMA agrees. This is not simply a compliance administration point. Harmonised reporting will require firms to map their internal data architecture to regulatory definitions, which may surface inconsistencies between how transactions are booked internally and how they must be reported to supervisors.
Digital asset accounting software that can produce regulatory-ready outputs alongside general ledger entries will become increasingly important as the reporting burden standardises. Firms relying on manual reconciliation between their books and regulatory submissions are accumulating a structural inefficiency that convergence will make harder to sustain. This is precisely the kind of operational challenge where ESMA's 2027 Work Programme and its implications for MiCA and CASPs deserves careful reading alongside your current systems review.
MIDAS: The Market Surveillance System Goes Live
ESMA's Market Infrastructure Data Analytical System, known as MIDAS, is central to its market abuse monitoring mandate under MiCA. The first phase of MIDAS is expected to be fully operational in 2027, with the fourth quarter rollout of expanded features subject to board approval.
What MIDAS will do
MIDAS is designed to ingest trading and transaction data from CASPs and use it to detect potential market manipulation, insider trading, and other abusive practices across EU crypto markets. The 2027 work programme confirms that the next phase will add analytical capabilities and expand the data types the system can process, building on earlier phases disclosed in February.
For compliance teams, MIDAS changes the risk calculus materially. Market abuse surveillance in crypto markets has historically been fragmented, with individual exchanges operating their own systems to varying standards. A centralised EU-level system drawing on cross-platform data will be capable of pattern recognition that no single firm's internal surveillance can match. Firms that have invested in robust transaction monitoring as part of their MiCA compliance programme are better positioned; those that have not face both regulatory and reputational exposure.
The accounting implications are indirect but real. If MIDAS triggers supervisory inquiries or enforcement actions, the costs associated with regulatory investigations, remediation programmes, and potential fines will need to be assessed for provisioning under IAS 37. Finance teams should ensure that their risk assessment processes include MIDAS-related regulatory risk as an explicit line item.
For broader context on how ESMA has been tracking risk in crypto and DeFi markets through 2026, the ESMA H1 2026 Risk Report and crypto accounting exposure provides useful background on the indicators the authority has been monitoring.
The MiCA Review: Feeding Supervisory Experience into Policy
ESMA also confirmed that it intends to contribute its supervisory experience from 2025 and 2026 into the European Commission's formal MiCA review, which is expected to conclude by June 2027. That review could lead to legislative proposals amending MiCA, and ESMA's supervisory findings will directly inform what those amendments address.
Implications for firms planning ahead
This timeline has strategic significance. Firms that engage constructively with their NCAs, maintain well-documented compliance programmes, and can demonstrate genuine adherence to MiCA's requirements are better placed to influence how the review interprets early implementation experience. Firms that have cut corners will find those gaps surfacing in exactly the evidence base that informs the next round of legislation.
For CFOs and heads of compliance, the MiCA review timeline also creates a planning obligation. Any compliance investment decisions being deferred pending regulatory clarity should be reassessed in light of the June 2027 deadline. Waiting for the review outcome before addressing known gaps is a higher-risk strategy than it may appear.
Accounting and Reporting Implications: A Practical Summary
The shift from rulemaking to supervision under MiCA creates a set of concrete accounting and reporting obligations that finance teams need to map against current practice.
Key areas to review now
Outsourcing contracts should be reviewed for adequacy of disclosure in financial statement notes, particularly where outsourced functions are material to the business. Liquidity risk disclosures under IFRS 7 should reflect the specific liquidity profile of crypto assets held, including any concentration risks in asset-referenced or e-money tokens. Provisions under IAS 37 should be stress-tested to include regulatory investigation costs and potential MiCA-related penalties as a recognised risk category. Internal data governance should be assessed for its ability to produce harmonised regulatory reports without manual reprocessing, since ESMA's standardisation agenda will eventually flow down to NCA-level reporting requirements.
Crypto bookkeeping software and digital asset accounting software choices made during the MiCA licensing phase may not be adequate for the supervisory phase that follows. The reporting demands of a live supervisory relationship with a NCA benchmarked against ESMA's common indicators are materially different from the demands of an authorisation application.
Frequently Asked Questions
What is ESMA's primary focus under MiCA in 2027?
ESMA has shifted from producing technical standards and guidelines to coordinating how national regulators supervise CASPs in practice. Its 2027 work programme targets operational resilience, outsourcing risk, substance requirements, reverse solicitation practices, liquidity management, and asset classification as thematic priorities.
What is MIDAS and when will it affect CASPs?
MIDAS is ESMA's centralised crypto market-abuse surveillance system. The first phase is expected to be fully operational in 2027, with expanded analytical features rolling out in Q4 2027 subject to board approval. It is designed to detect market manipulation and insider trading across EU crypto markets by aggregating data from multiple CASPs.
How does the reverse solicitation focus affect third-country firms?
MiCA allows third-country firms to serve EU clients without authorisation only where the client initiates the service request exclusively on their own initiative. ESMA has consistently narrowed the practical scope of this exemption, and the 2027 programme signals that NCAs will actively test whether firms are genuinely relying on it or using it as a systematic workaround. Firms with material EU revenue attributed to reverse solicitation should take legal advice on their position.
What should accounting teams prioritise in light of this programme?
Three areas warrant immediate attention: reviewing outsourcing disclosures in financial statement notes, stress-testing IAS 37 provisions to include MiCA regulatory risk, and assessing whether current digital asset accounting software can produce NCA-ready periodic reports without manual reconciliation. Firms that cannot produce clean regulatory data from their accounting systems face a structural disadvantage as ESMA's harmonisation agenda takes effect.
When is the MiCA review expected and why does it matter?
The European Commission's formal MiCA review is expected to conclude by June 2027. ESMA will feed its supervisory observations from 2025 and 2026 into that review, which may lead to legislative amendments. Firms should treat the review timeline as a reason to address compliance gaps now rather than waiting, since supervisory findings will directly shape whatever legislative changes follow.
Source: Cointelegraph
