ESMA’s response to the MiCAR consultation
On 30 September 2026, ESMA published its response to the European Commission’s consultation on the review of the Markets in Crypto-Assets Regulation (MiCAR). Drawing on its experience since the end of the transitional period on 1 July 2026, ESMA proposes targeted amendments to reduce legal uncertainty and regulatory arbitrage, and to simplify the framework where possible. Below we discuss the proposals we consider most relevant.
- Classification of crypto-assets. ESMA notes that the classification of tokens remains one of the most important issues under MiCAR. We see this in practice as well, as classification questions come up regularly in our work, particularly for tokens with hybrid characteristics. The issue is made more difficult by the fact that MiFID II was not written with crypto-assets in mind. One of ESMA’s proposals is therefore to allow ESMA, in consultation or jointly with the EBA, to issue binding opinions on the classification of tokens, including on its own initiative.
- Decentralised finance. MiCAR does not apply to crypto-asset services provided in a fully decentralised manner without any intermediary. ESMA observes diverging views on when this is the case. It considers that greater legal certainty is needed on when a crypto-asset service, trading protocol or decentralised exchange (DEX) qualifies as fully decentralised. ESMA therefore iproposes to include a definition of DeFi in MiCAR itself. In ESMA’s view, the exemption should be as narrow as possible, so that it cannot be used to circumvent MiCAR. In addition, ESMA proposes a new regulated crypto-asset service: the provision of access to decentralised protocols or DeFi services by a CASP on behalf of clients. This “gatekeeper” service could cover situations where a CASP provides a technical interface enabling clients to interact with DeFi protocols, facilitates transaction routing or interaction with smart contracts, or otherwise acts as an intermediary between clients and DeFi services. We welcome clarity on this point. In practice, various parties that provide technical services in relation to DeFi are now uncertain whether they qualify as a CASP, which can currently be a grey area. Clarity would also benefit consumers, as they rely on these technical providers when accessing DeFi services, and do not always know what type of party they are interacting with and whether they benefit from any supervisory protection in that respect.
- Transfer services. Following Q&A 2071, the Commission’s position is that transfer services are a distinct and self-standing crypto-asset service that requires authorisation, also when provided as part of another crypto-asset service. As a result, investment firms that provide crypto-asset services through the notification procedure sometimes need a separate CASP authorisation for transfer services. This applies even where those services technically and materially are equivalent to investment services for which the firm is already authorised under MiFID II. ESMA proposes to clarify in MiCAR that such firms do not need a separate CASP licence for these transfer services. We support this proposal. We see in practice that the broad interpretation of what constitutes a transfer service undermines the possibility for MiFID firms to rely on the notification regime under MiCAR. We would furthermore also welcome more alignment on the definition of a transfer service and on when this service is provided. In our view, the interplay between regimes covering equivalent services does not work well. We see this in other regulatory areas too, such as between PSD3/PSR and MiCAR. For example, a transfer service is considered equivalent to the execution of payment transactions, but not every transfer service is considered the execution of a payment transaction. Because the definitions do not fully match, applying the regimes alongside each other remains difficult in practice.
- Prudential requirements. An entity authorised under both MiCAR and MiFID II (or another framework) must comply with the prudential requirements of each. However, where a MiFID II firm provides crypto-asset services on the basis of a MiCAR notification, its prudential requirements do not change. We are aware of discussions on this topic with national regulators. We understand that the regulator is bound by the current text and cannot interpret it otherwise. In our view, however, the outcome is not fair, as it creates an unlevel playing field. We are therefore happy that ESMA agrees with our view. ESMA proposes to align the capital requirements for CASPs with IFR/IFD by deleting the limitative list of variable costs that may be deducted when calculating fixed overheads. According to ESMA, this would contribute to a level playing field between entities providing services under multiple frameworks, including notifying entities and CASPs.
- Staking, lending and borrowing. ESMA proposes to bring staking, lending and borrowing services provided by CASPs within MiCAR through targeted conduct, disclosure and risk-management requirements, rather than a new heavy authorisation regime. ESMA wants clients to be better informed about risks such as slashing, lock-up periods, collateral, liquidation and the reuse of their assets.
The points raised by ESMA reflect issues we also see in practice and that our clients are dealing with. A revision of MiCAR that strengthens these points would therefore be helpful in time. One aspect that in our view remains underexposed is the position of CASPs whose services are not primarily investment-based, such as crypto-asset acquirers, which have a payment nature. MiCAR is based on MiFID II and therefore assumes that all crypto-asset services are investment-based. As this is not the case, such CASPs do not fully fit within the MiCAR framework. It would be helpful if ESMA, together with the EBA, would shed further light on this as well.