On September 30th, the European Commission closed its so-called “consultation on the review of Regulation on the Markets in Crypto-Assets (MiCA)”. This blog is about what this review is, and isn’t, and our view of the responsibility of our industry around it.
What the Review Is
It may seem odd to have a review of a regulation that came into force just 3 months ago. But let’s remember MiCA was drafted in 2019!
The speed of development of digital assets markets already convinced the EU to contemplate whether an adjustment of the rules is needed:
- The speed at which RWAs and crypto assets are intertwining highlighted a residual grey area from MiCA 1.0: the border between a financial instrument and a crypto asset.
- Staking and lending were never fully regulated in MiCA 1.0 – although custodial staking is clearly subject to custodial requirements.
- Figuring out whom in the DeFi universe to regulate for what narrowly escaped the scope of MiCA 1.0. It’s back on the table.
- Issuing the same stablecoin under different jurisdictions is proving complicated, especially when more and more markets have their own, slightly different, rules.
The review asks many more questions besides these four, and it will likely uncover areas where quick fixes are needed simply because we have the benefit of 6-7 years of industry and supervisory experience. It is very possible that some of the quick-fix issues make a material difference to business models, even if they are not hogging the spotlights.
What the Review Is Not
This review is not a commitment to MiCA 2.0, far less a clear plan of what it will address. All these focus areas are educated guesses based on knowing the most discussed issues in Brussels. We are still due a proposal by the Commission, which will then be negotiated with the European Parliament and the Member States. Even though the European Central Bank and the European Supervisory Authorities have voiced their views – they are not formally part of the policymaking process.
In parallel, the EU is debating whether to centralize the supervision of very large exchanges – but this is not part of MiCA 2.0 (which also may seem convoluted outside the EU bubble).
Our Responsibility
As the MiCA 2.0 check is still half-blank, we thought our responsibility was to give the Commission real market data on which regulatory grey areas have delayed or fully discouraged client investment in new products, and which regulatory clarifications will unlock client product lines for which the market sees the most demand.
We think this thinking supports European competitiveness, and focuses regulatory resources where the most consumer exposure would be.
We think this is a very different question from focusing on the thorniest regulatory issues – because they may matter for a disproportionately small portion of the market right now!
To this end, we conducted an anonymous survey of customers who have secured a MiCA license, and we would like to share the results.
Survey Findings of Customers Who Have Secured a MiCA License
P2 — What is your primary business line?
Single choice. Base: all respondents (n=17).
| Business Line | % | n |
| Exchange, trading, brokerage, and/or market making | 47% | 8 |
| Custody | 41% | 7 |
| Payments | 6% | 1 |
| Banking | 6% | 1 |
Q1 — How should tokenised financial instruments be regulated?
Single choice. Base: all respondents (n=17).
| View | % | n |
| They should be regulated in the same way as other financial instruments | 53% | 9 |
| They should be regulated in the same way as crypto-assets | 29% | 5 |
| A new dedicated regime covering both should be created | 12% | 2 |
| No view | 6% | 1 |
Q2 — Is the boundary between MiCA crypto-assets and MiFID financial instruments clear enough for you to structure products with confidence?
Single choice. Base: all respondents (n=17).
| Response | % | n |
| No, and it delays our product launches | 35% | 6 |
| No, but we work around it | 35% | 6 |
| Yes, it is clear | 24% | 4 |
| No view | 6% | 1 |
Q3 — In the last 12 months, has classification uncertainty caused you to change course on an EU product?
Multiple choice. Base: all respondents (n=17); totals may exceed 100%.
| Action taken | % | n |
| Delayed a launch | 35% | 6 |
| Redesigned the product | 29% | 5 |
| Abandoned the product | 29% | 5 |
| Launched outside the EU instead | 18% | 3 |
| No option selected | 41% | 7 |
Q4 — If a firm dealing in crypto-assets under MiCA could begin dealing in tokenised financial instruments under MiFID through a simplified top-up authorisation:
Single choice. Base: all respondents (n=17).
| Response | % | n |
| The outcome would incentivise my firm to invest more in relevant use cases in the EU | 53% | 9 |
| The outcome would be unfair to firms who already have full MiFID licences | 24% | 4 |
| The outcome would make no difference to our business | 12% | 2 |
| No view | 12% | 2 |
Q5 — Regulation on which of these is unclear for your business in the EU today?
Multiple choice. Base: all respondents (n=17); totals may exceed 100%.
| Activity | % | n |
| Offering DeFi lending and borrowing | 71% | 12 |
| Offering staking | 65% | 11 |
| Using tokenised assets as collateral | 59% | 10 |
| Custody of tokenised financial instruments | 59% | 10 |
| Offering tokenised funds | 53% | 9 |
| Offering other DeFi strategies and services | 47% | 8 |
| Offering tokenised deposits | 47% | 8 |
| Offering perpetual futures | 41% | 7 |
| Offering wrapped and bridged tokens | 41% | 7 |
| Prediction markets | 41% | 7 |
| Re-staking | 24% | 4 |
| Offering NFTs issued in series | 18% | 3 |
| No option selected | 6% | 1 |
Q6 — Rank the five with the highest expected client demand over the next 24 months.
Ranking (1 = highest demand). Weighted score: rank 1 = 5 points, rank 5 = 1 point. Activities not ranked by any respondent are omitted.
| Activity | Ranked in top five | Ranked first | Average rank | Weighted score |
| Offering tokenised funds | 9 | 3 | 2.2 | 34 |
| Custody of tokenised financial instruments | 11 | 2 | 3.2 | 31 |
| Offering staking | 9 | 3 | 3.2 | 25 |
| Offering perpetual futures | 7 | 1 | 2.7 | 23 |
| Offering DeFi lending and borrowing | 7 | 0 | 2.9 | 22 |
| Using tokenised assets as collateral | 6 | 0 | 3.0 | 18 |
| Prediction markets | 5 | 2 | 2.8 | 16 |
| Offering tokenised deposits | 5 | 1 | 3.6 | 12 |
| Offering other DeFi strategies and services | 1 | 1 | 1.0 | 5 |
| Offering wrapped and bridged tokens | 1 | 0 | 2.0 | 4 |
Q7 — Which single unclear area most constrains your EU revenue today?
Single choice. Base: all respondents (n=17).
| Area | % | n |
| Offering staking | 24% | 4 |
| Offering tokenised funds | 18% | 3 |
| Custody of tokenised financial instruments | 18% | 3 |
| Prediction markets | 12% | 2 |
| Offering DeFi lending and borrowing | 6% | 1 |
| Offering tokenised deposits | 6% | 1 |
| Using tokenised assets as collateral | 6% | 1 |
| No response | 12% | 2 |
Q8 — Do the EMT rules need further clarity, and if so where?
Multiple choice. Base: all respondents (n=17); totals may exceed 100%.
| Area | % | n |
| Boundary with payment services under PSD3 | 71% | 12 |
| CASP obligations when handling non-EU stablecoins | 65% | 11 |
| Interest and remuneration prohibition | 47% | 8 |
| Multi-issuer and third-country structures | 41% | 7 |
| Reserve location and the 30 to 60 per cent deposit requirement | 24% | 4 |
| Use of EMTs as collateral or as a settlement asset | 24% | 4 |
| Redemption mechanics and who owes the redemption | 6% | 1 |
| Distribution and marketing responsibilities | 6% | 1 |
| EMT rules are clear enough for you as they stand | 24% | 4 |
Q9 — Would resolving that uncertainty change your investment or product decisions in the EU within 12 months?
Single choice. Base: all respondents (n=17).
| Response | % | n |
| Yes, marginally | 35% | 6 |
| Yes, materially | 35% | 6 |
| No | 6% | 1 |
| No view | 24% | 4 |
Q10 — Which MiCA requirements have been a burden for your business?
Multiple choice. Base: all respondents (n=17); totals may exceed 100%.
| Requirement | % | n |
| Authorisation timelines and divergence between national authorities | 71% | 12 |
| Ongoing reporting | 41% | 7 |
| Own funds and prudential calculation | 35% | 6 |
| Governance and outsourcing | 35% | 6 |
| White paper obligations | 35% | 6 |
| Sustainability disclosures | 29% | 5 |
| Order and record-keeping | 29% | 5 |
| Complaint handling | 18% | 3 |
| Other (write-in) | 18% | 3 |
| No option selected | 6% | 1 |
Write-in responses:
- DORA
- Overlap between MiCAR Art. 73 outsourcing requirements and DORA ICT third-party requirements, leading to double classification of the same suppliers
- Level II
Q11 — Do MiCA rules restrict EU client access to non-EU liquidity?
Single choice. Base: all respondents (n=17).
| Response | % | n |
| Yes, materially | 35% | 6 |
| Yes, marginally | 35% | 6 |
| No | 12% | 2 |
| No view | 12% | 2 |
| No response | 6% | 1 |
Q12 — MiCA imposes no general reporting obligation on CASPs today. Which of the following, if any, should CASPs be required to report regularly?
Multiple choice. Base: all respondents (n=17); totals may exceed 100%.
| Reporting area | % | n |
| Counterparty risk exposures | 35% | 6 |
| Volumes of leveraged contracts and the extent to which leverage is actually used on trading platforms | 18% | 3 |
| Direct holdings of crypto-assets by the CASP itself | 12% | 2 |
| Large exposures to derivatives with crypto-assets as the underlying | 6% | 1 |
| No option selected | 47% | 8 |
Q13 — Which parts of DORA most need improvement or clarification for crypto-asset firms?
Multiple choice. Base: all respondents (n=17); totals may exceed 100%.
| Area | % | n |
| Proportionality for smaller firms | 53% | 9 |
| Identification and designation of critical ICT third-party providers | 35% | 6 |
| Subcontracting rules and visibility down the supply chain | 35% | 6 |
| Divergence in how national authorities apply DORA | 35% | 6 |
| Third-party risk management and mandatory contractual terms | 29% | 5 |
| Exit strategies and concentration risk | 24% | 4 |
| ICT risk management framework requirements | 18% | 3 |
| Register of information | 18% | 3 |
| Incident reporting timelines and templates | 18% | 3 |
| Resilience testing, including threat-led penetration testing | 18% | 3 |
| Major incident classification thresholds | 12% | 2 |
| Nothing needs changing | 6% | 1 |
| Other (write-in) | 6% | 1 |
| No option selected | 6% | 1 |
Write-in responses:
- DORA appliance on ICT third party service providers that are themselves licensed entities (financial institutions)
Q14 — Has DORA compliance changed how you select or retain technology providers?
Multiple choice. Base: all respondents (n=17); totals may exceed 100%.
| Change | % | n |
| Delayed onboarding a new provider | 59% | 10 |
| Consolidated onto fewer providers | 41% | 7 |
| Dropped or declined a provider that would not accept the contractual terms | 29% | 5 |
| Brought a function in-house | 6% | 1 |
| DORA has not changed how you select or retain providers | 6% | 1 |
| No option selected | 12% | 2 |
Q15 — Is there anything else on the MiCA review that Fireblocks should reflect in its response?
Open text. 3 substantive responses, reproduced as submitted.
- The MiCA review should prioritise legal certainty over new perimeter. First, staking needs an explicit framework: its qualification, the allocation of responsibilities between the CASP and validators, and client disclosures, with a clear boundary from the EMT remuneration prohibition. Second, white paper obligations for crypto-assets without an identifiable issuer should be clarified as to responsibility and liability, allowing reliance on a single white paper filed in the ESMA register. Third, MiCAR outsourcing requirements (Art. 73) and DORA ICT third-party requirements should be aligned to avoid double classification of the same providers. Fourth, supervisory convergence on authorisation timelines and practices is needed to preserve the level playing field of the passport. Finally, a proportionate top-up authorisation for CASPs to provide custody of tokenised financial instruments would support EU tokenisation without lowering substantive requirements.
- Interpretation on transferability of crypto assets according to ESMA Q&A 2550: the requirement set out in this interpretation for CASPs to offer the customers possibility to withdraw the customers cryptos outside the platform is unclear and very burdensome for CASPs, especially due to Travel rule requirements. Some NSAs have also required more strict compliance with this interpretation than other NSAs. And from AML perspective the interpretation exposes CASPs and EUs crypto markets to very high AML risks as the AML mitigating measures the CASPs have are not unified across all different (hundreds or thousands of) crypto currencies CASPS provide for trading.
- Importance of Tech-neutrality principle and changing the risk-aversion mindset.