ESMA expands cyber resilience checks to crypto-asset service providers in 2027

Summary

The European Securities and Markets Authority (ESMA) announced that its focus on cyber and operational resilience will expand in 2027 to include crypto-asset service providers, following the launch of its current priority in 2025 under the Digital Operational Resilience Act (DORA). This initiative aligns with ESMA's broader strategic supervisory program, aimed at ensuring financial firms' deployment of artificial intelligence and tokenization enhances client outcomes, as firms increasingly utilize these technologies for competitive advantage. The move comes as the European Commission considers revisions to the Markets in Crypto-Assets (MiCA) framework, which could broaden its regulations to encompass tokenization.

Analysis

MiCA: MiCA is the EU's Markets in Crypto-Assets regulation establishing licensing and oversight for crypto businesses across the bloc. Its transition period ended in July, after which crypto-asset service providers fall under expanded ESMA supervisory priorities including cyber resilience checks starting in 2027. The framework is under review for potential updates related to tokenization and stablecoin rules. Digital Operational Resilience Act: The Digital Operational Resilience Act (DORA) is an EU regulation aimed at strengthening the operational resilience of financial entities against ICT risks and cyber threats. Launched as an ESMA priority in 2025, it requires compliance checks by national authorities, with the scope expanding in 2027 to smaller firms and crypto-asset service providers. This aligns with ESMA's broader push for robust supervision amid technological changes. Innovation With Investor Safeguards: Innovation With Investor Safeguards is a Union strategic supervisory priority (USSP) established by ESMA to guide national regulators on emerging technologies in finance. Under this program, supervisors will catalog and initially check AI and tokenization uses in products and processes affecting client outcomes. The initiative addresses risks such as biased AI outputs and complex new products while noting potential efficiency gains. European Securities and Markets Authority: The European Securities and Markets Authority (ESMA) is the EU financial regulator tasked with supervising securities markets, fostering consistent supervision across member states, and protecting investors. It sets strategic supervisory priorities that national authorities implement, including the new Innovation With Investor Safeguards program focused on AI and tokenization starting in 2027. ESMA is also expanding its existing cyber and operational resilience work to encompass crypto-asset service providers licensed under MiCA. Innovation: National authorities will focus on AI and tokenization deployments that shape client outcomes rather than back-office functions alone. Regulation: The European Commission is considering revisions to MiCA that could extend its scope to cover tokenization. Supervision: ESMA's cyber and operational resilience priority, launched in 2025 under DORA, will widen in 2027 to include crypto-asset service providers.

Categories

cryptorwamacrotechaipolitics
View Original Tweet