2024-10-16
ESMA issued this opinion responding to the European Commission's proposed amendments to draft regulatory technical standards governing authorisations and notifications for crypto-asset service providers under MiCA. While ESMA accepts the Commission's changes regarding data minimisation for management body assessments and the non-mandatory nature of third-party cybersecurity audits, it strongly advocates for legislative updates to ensure rigorous oversight. Specifically, ESMA recommends amending MiCA to mandate comprehensive good repute checks and require third-party cybersecurity audits to mitigate risks associated with ICT systems in the crypto-asset sector.