What happened

The European Securities and Markets Authority (ESMA) has published its 2025 Annual Report, framing the year as one of progress across three themes: stronger supervision, regulatory simplification and innovation. For crypto businesses, the most relevant takeaway is ESMA’s confirmation that it worked closely with National Competent Authorities (NCAs) throughout the year on the implementation of the Markets in Crypto-Assets Regulation (MiCA), and that this work directly advanced the authorisation of crypto-asset service providers.

ESMA Chair Verena Ross described 2025 as the year momentum shifted “from policy ambition to concrete action.” The report situates MiCA alongside the implementation of the Digital Operational Resilience Act (DORA) and EMIR 3, presenting these frameworks as a coordinated effort to strengthen supervisory convergence and digital resilience across the EU financial system.

What it means in practice

For applicants and existing licensees, the report signals that the MiCA regime is now operating in a steady, supervised state rather than a transitional one. Three practical conclusions stand out.

1. Supervision is intensifying, not relaxing

ESMA explicitly references a “risk-based supervisory approach” that leverages supervisory data for “more efficient, intelligence-led oversight.” In plain terms, NCAs are increasingly data-driven in how they monitor authorised firms. Crypto-asset service providers should expect scrutiny to continue after authorisation — not just during the application phase. Robust reporting, governance and compliance functions are no longer optional formalities.

2. DORA and MiCA travel together

The report’s pairing of MiCA with DORA is a useful reminder that operational resilience obligations apply to crypto firms. Applicants building their authorisation files should treat ICT risk management, incident reporting and third-party oversight as core components of their readiness — not as a separate workstream to be addressed later.

3. Simplification is a stated priority

ESMA identifies regulatory simplification and burden reduction as a central focus, including streamlining transaction and fund reporting. While the named initiatives concern AIFMD and UCITS, the directional signal matters: ESMA is actively trying to reduce unnecessary reporting burden for market participants. Firms should monitor how this philosophy filters into crypto-asset supervisory practice over time.

Implications for licensees and applicants

The report also flags ESMA’s intensified work on digitalisation, artificial intelligence, distributed ledger technology and decentralised finance, with the stated aim of harnessing innovation while safeguarding market integrity and investor protection. For firms operating at the frontier — DeFi-adjacent models, tokenisation, or AI-driven services — this confirms that ESMA is watching these areas closely and that innovative business models will be assessed against existing investor-protection standards.

Executives weighing market entry should read this as confirmation that the EU’s framework is maturing and that a properly structured authorisation remains the route to passportable, EU-wide access. A well-prepared application for a crypto / VASP license in European Union is now competing within an established and increasingly data-driven supervisory environment.

Concrete next steps to consider

  • Build for ongoing supervision. Design your compliance, governance and reporting infrastructure to satisfy post-authorisation, data-led oversight — not just initial approval.
  • Integrate DORA from day one. Treat ICT risk management, incident reporting and third-party dependency oversight as integral to your MiCA readiness.
  • Document innovation carefully. If your model involves AI, DLT or DeFi elements, prepare to demonstrate how it aligns with investor-protection and market-integrity expectations.
  • Track simplification developments. Stay alert to ESMA’s burden-reduction work, which may streamline future reporting obligations relevant to crypto firms.
  • Choose your NCA deliberately. With supervisory convergence advancing, the substance of your application matters more than venue arbitrage.

The overall message is constructive: the EU crypto framework is settling into a credible, predictable supervisory rhythm. Firms that prepare thoroughly — and treat compliance as an operational discipline rather than a one-off hurdle — are best positioned to benefit.

Source: ESMA — ESMA 2025 Annual Report: focus on stronger supervision, regulatory simplification, and innovation