ESMA's 2027 Work Programme: What It Means for MiCA, CASPs, and Crypto Accounting
ESMA has published its 2027 work programme, and the message for regulated crypto firms is unambiguous: the preparation phase is over. The authority is pivoting from drafting technical standards to actively supervising, converging, and enforcing, and crypto-asset service providers sit squarely in the crosshairs. For accounting firms, auditors, and CFOs operating in the EU digital asset space, understanding what ESMA intends to prioritise next year is not optional reading. It is operational intelligence that should feed directly into compliance roadmaps and the choice of crypto accounting software capable of meeting emerging data demands.
From Rule-Writing to Delivery: The Strategic Context
ESMA's 2027 programme sits within the authority's broader multi-annual strategy covering 2023 to 2028. The earlier years of that strategy were dominated by legislative groundwork: transposing MiCA into supervisory expectations, building technical standards under DORA, and designing the architecture for the Savings and Investments Union (SIU). In 2027, that groundwork becomes the baseline, not the objective.
The authority's chair framed this plainly in the published statement accompanying the programme, describing 2027 as "an important milestone" as "many of ESMA's strategic initiatives move into the delivery phase." The word delivery carries real regulatory weight. It signals that national competent authorities across the EU will face intensified pressure to apply ESMA's standards consistently, and that firms previously afforded transitional flexibility will be held to a higher bar.
The Savings and Investments Union as the Organising Frame
Much of ESMA's 2027 agenda is organised around the SIU, the EU's flagship project to deepen and integrate capital markets across member states. The Market Integration and Supervision Package (MISP), which co-legislators are expected to finalise in 2027, will expand ESMA's direct mandates. The authority has already begun preparing for those expanded responsibilities, meaning firms should anticipate a more assertive pan-European supervisor rather than the more federated model they may be used to dealing with through local NCAs.
For crypto-focused firms, the SIU framing matters because it underscores that digital assets are no longer treated as a peripheral concern. Tokenisation and crypto-asset market integrity are explicitly named as ongoing ESMA priorities for 2027, sitting alongside traditionally mainstream concerns like clearing resilience and T+1 settlement.
MiCA Supervision: What ESMA Is Actually Planning
The most operationally significant section of the work programme for crypto firms is ESMA's stated intention to enhance supervisory convergence on MiCA, working alongside NCAs to oversee crypto-asset service providers. This is a step change from the earlier phase, when the focus was on producing guidelines and Q&As to help firms and national regulators interpret the regulation.
Convergence Means Consistency, Which Means Less Arbitrage
Supervisory convergence is ESMA's mechanism for ensuring that a CASP licensed in, say, Lithuania is held to materially the same standard as one licensed in the Netherlands. In practice, ESMA uses peer reviews, thematic examinations, and convergence tools to close the gaps that historically allowed firms to forum-shop for more permissive national regulators. The explicit inclusion of CASP oversight in the 2027 programme signals that those gaps are about to get considerably narrower.
For accounting firms advising CASPs across multiple EU jurisdictions, this has a direct implication: a compliance posture calibrated to the most lenient NCA interpretation of MiCA is no longer a defensible strategy. Advice must be anchored to the most robust reading of the regulation, because ESMA's convergence work will progressively eliminate the softer interpretations. That recalibration almost certainly touches transaction reporting formats, AML documentation standards, and the quality of data that crypto bookkeeping software must be able to produce on demand.
Operational Licensing Pressure on CASPs
ESMA's programme also references continued progress on processing applications and beginning supervision in areas where it has direct authority, specifically consolidated tape providers and ESG rating providers. While CASPs are supervised at national level under MiCA, the convergence mandate means ESMA will be scrutinising how NCAs handle those authorisations. Firms still in the authorisation pipeline, or planning applications in 2025 or 2026 for a 2027 operational launch, should factor in the likelihood that the review standard will be higher and more uniform than it was in 2024.
Our earlier analysis of EBA's call for crypto lending and DeFi rules under MiCA highlighted how the regulatory perimeter is still expanding. ESMA's 2027 push on convergence compounds that dynamic: firms face both a widening perimeter and a tightening enforcement posture simultaneously.
Four Simplification Initiatives and What They Mean for Reporting
One of the more practically significant elements of the 2027 programme is ESMA's package of simplification initiatives. Four flagship workstreams, covering transaction reporting, funds reporting, the retail investor journey, and risk-based supervision, are moving into a new delivery phase. The stated aims are to reduce administrative burden, improve data usability, and make supervision more effective.
Transaction Reporting Reform
Transaction reporting is the area most likely to affect firms running digital asset portfolios or advising clients who do. ESMA's simplification work here is intended to reduce unnecessary complexity in reporting fields and improve the quality of data that flows to regulators. For firms currently using digital asset accounting software to generate MiFID-style transaction reports or preparing for equivalent MiCA reporting obligations, a change in the underlying reporting schema is a significant operational event. Systems will need to be updated, data mappings reviewed, and reconciliation processes tested against new field structures.
The timing is important. If the simplification reforms are finalised in 2027 and come into force shortly after, firms that delay their system reviews until the rules are published will have very little runway to implement changes without operational disruption. The prudent approach is to engage with the consultation process as it develops and maintain flexible reporting infrastructure that can accommodate schema changes without a full rebuild.
Risk-Based Supervision and Data Quality
ESMA's fourth simplification initiative, risk-based supervision, is perhaps the most consequential for how regulators will interact with firms day to day. Moving to a more explicitly risk-based model means supervisors will allocate scrutiny in proportion to the risk profile of the entity and its activities. For crypto firms, which by their nature operate in a higher-risk segment, this almost certainly means more intensive engagement rather than less.
The corollary for accounting and reporting infrastructure is that data quality becomes the first line of defence. A firm whose crypto bookkeeping software produces clean, complete, and timely data will be far better positioned in a risk-based supervisory dialogue than one whose records require manual reconciliation before they can be shared with an NCA. The quality of underlying transaction data is not just an accounting concern; it is a supervisory risk management concern.
Tokenisation, AI, and Emerging Technology Priorities
ESMA's 2027 programme explicitly names tokenisation as a continuing priority, building on work already underway to assess the opportunities and risks it presents for EU capital markets. The authority will also advance AI-based supervisory tools internally and publish analysis on the impact of artificial intelligence on financial markets more broadly.
Tokenisation: From Experimentation to Market Infrastructure
The inclusion of tokenisation as a named 2027 priority, rather than a research topic, reflects a maturation in how ESMA is thinking about distributed ledger technology. The authority is moving past the question of whether tokenised assets are real and towards questions of how they are supervised, how they interact with existing market structure rules, and how risks, including settlement, custody, and liquidity risks, are managed at scale.
For accounting firms and CFOs, this trajectory means tokenised asset positions on client or corporate balance sheets are increasingly likely to be subject to the same regulatory scrutiny as conventionally settled securities. Accounting policies for tokenised instruments, including classification, measurement, and disclosure, need to be robust before regulators arrive asking questions. We have covered the expanding supervisory perimeter in detail in our piece on ESMA naming AI and tokenisation a Union supervisory priority from 2027.
DORA Compliance and ICT Third-Party Risk
ESMA's 2027 programme also confirms continuing oversight of Critical ICT Third-Party Service Providers under DORA, jointly with the other European Supervisory Authorities. For crypto firms, DORA's requirements around operational resilience, incident reporting, and third-party risk management are not a future concern: they are current obligations. Firms that have not yet completed a full DORA gap analysis against their technology stack, including the cloud providers and data vendors that underpin their crypto accounting software, should treat that work as urgent.
EMIR 3 and Clearing: Indirect but Real Implications
ESMA's planned review of EMIR 3 reforms is primarily aimed at traditional derivatives clearing, but it carries indirect relevance for crypto firms with institutional counterparties. The push to reduce EU dependence on systemically important clearing services located outside the EU is part of a broader strategic autonomy agenda. As crypto derivatives markets mature and more instruments are brought within clearing mandates, the infrastructure choices made now, about which venues and clearing houses to use, will be shaped by this regulatory direction of travel.
CFOs at firms with crypto derivatives exposure should flag this to treasury and risk teams now, even if the direct regulatory impact on crypto markets is still some distance away. The direction is clear and consistent with the overall thrust of EU financial policy.
Practical Priorities for Accounting Firms and CFOs
Translating ESMA's 2027 agenda into a practical action list for accounting firms and CFOs operating in the EU digital asset space produces a reasonably clear set of near-term priorities.
Review Reporting Infrastructure Now, Not After the Rules Change
The transaction reporting simplification initiative will change data field requirements. Firms should audit their current reporting pipelines, identify which fields are generated automatically by their crypto accounting software and which require manual intervention, and open conversations with technology providers about update timelines. Waiting for the final rules before beginning this review is a false economy.
Stress-Test MiCA Compliance Against the Toughest NCA Standard
As supervisory convergence tightens, the compliance floor will rise to meet the most rigorous national interpretation of MiCA rather than the average. Legal and compliance teams should map current policies against the most demanding published NCA guidance and identify gaps. This applies especially to AML procedures, client asset safeguarding documentation, and the disclosure obligations that sit at the heart of MiCA's investor protection framework.
Build Data Quality Into the Operating Model
Risk-based supervision rewards firms that can demonstrate clean, well-governed data. For crypto-focused businesses, that means investing in digital asset accounting software and reconciliation processes that produce audit-ready transaction records as a matter of routine, not just ahead of regulatory visits. The accounting and supervisory rationales for this investment are increasingly aligned.
Source: European Securities and Markets Authority (ESMA)
Frequently Asked Questions
What is ESMA's 2027 work programme?
It is ESMA's annual plan setting out its regulatory, supervisory, and operational priorities for the year. The 2027 edition marks a shift from legislative preparation to active delivery of major initiatives, including MiCA supervision, reporting simplification, and expanded tokenisation work.
How does ESMA's supervisory convergence work affect CASPs in practice?
ESMA coordinates with national competent authorities across EU member states to ensure that MiCA is applied consistently. This means firms cannot rely on more permissive national interpretations of the regulation. Compliance standards will progressively align upward toward the most rigorous NCA approach, raising the bar for licensing and ongoing supervision.
What are ESMA's four simplification initiatives and why do they matter?
The four workstreams cover transaction reporting, funds reporting, the retail investor journey, and risk-based supervision. The transaction reporting initiative is most directly relevant to crypto firms, as it will likely change data field structures and reporting schemas. Firms using automated reporting tools need to plan for system updates before the new requirements take effect.
Does DORA apply to crypto firms, and what does ESMA's 2027 agenda mean for that obligation?
Yes. CASPs and other regulated crypto entities are subject to DORA's operational resilience requirements, including incident reporting and ICT third-party risk management. ESMA's 2027 programme confirms continued joint oversight of Critical ICT Third-Party Service Providers. Firms should ensure their DORA gap analyses are complete and that third-party arrangements, including technology and data vendors, are documented and reviewed.
When should firms start preparing for ESMA's 2027 reporting changes?
Now. Consultation processes for the simplification initiatives are already underway or imminent. Firms that engage early can influence final rule design and will have more time to adapt reporting infrastructure. Those that wait for published final rules will have considerably less implementation runway.
