The Financial Authority for Malta Financial Services (MFSA) has been revised from the European Securities and Markets Authority (ESMA) so as not to fully meet expectations in the authorization process of an cryptographic asset service provider (CASP) under the Crypto-Asets Regulatory Markets (Mica). ESMA’s peer review has identified key areas where Malta’s regulatory approach must be improved to guarantee coherent supervision standards across the EU.
The ESMA ad hoc peer review committee (PRC) has urged MFSA to reassess the unresolved problems of the authorization process to strengthen regulatory monitoring. This review was part of the broader ESMA strategy aimed at promoting the convergence of supervision among the competent national authorities (ANC). The report highlighted the importance of the coherent application of the authorization criteria to mitigate the risks inherent in the providers of cryptographic asset services, whose commercial models often involve complex and scalable challenges.
Malta has established itself as an important center for cryptographic companies within the EU, with four casps currently under license under Mica: Bitpanda, Crypto.com, OKX and ZBX. The ESMA journal did not specify which CASP was subject to partial authorization problems, leaving the uncertain market of the potential repercussions of these entities. Industry experts suggest that it is unlikely that the review results will trigger license revocations, but can encourage MFSA to tighten its supervision practices.
The ESMA report highlights three critical areas of interest in MFSA: parameters and supervision resources, the authorization process itself and the continuous supervision exam, including the exercise of adequate regulatory powers. While the Malta surveillance framework and the allocation of resources have been deemed satisfactory, the specific CASP authorization process revealed gaps in solving material problems before granting approval. This partial deficit indicates the need for increased diligence and risk assessment mechanisms during the authorization phase.
The ESMA RPC stressed that the NCA had to pay particular attention to the unique risks posed by providers of cryptographic asset services, including operational, financial and compliance risks. The report encourages the MFSA to implement timely adjustments to its supervision approach to monitor the pace of the growing complexity of the cryptography sector. The Mica frame, in force since June 29, 2024, represents the first complete attempt of the EU to harmonize the regulation of assets of cryptography between the Member States. The coordinated approach of ESMA for CASP authorizations aims to prevent regulatory arbitration and to guarantee the rules of the game for market players.
By approaching the identified gaps, the MFSA of Malta can strengthen its reputation as a reliable regulator within the EU crypto ecosystem. This is particularly important because the sector faces a meticulous examination of financial intelligence units and other surveillance organizations. The peer examination mechanism serves as a critical tool to monitor and improve the uniform application of mica provisions. The strengthening of these fields will be crucial to maintain the protection of investors, market integrity and promote confidence in the landscape of the regulation of evolving EU.



