Skip to content
buybitcoinsmart

Glossary / Regulation & tax

ESMA register

Also known as ESMA crypto-asset register.

What is the ESMA register?
The ESMA register is the European Union's public list of authorised crypto-asset service providers, token issuers and published white papers, kept by the European Securities and Markets Authority under MiCA.

Article 109 of Regulation (EU) 2023/1114 orders ESMA to build it and to keep it publicly available on its website. Withdrawn authorisations and enforcement measures stay published there for five years, so the register records failures as well as licences. Checking a platform's entry tells you which national regulator, if any, actually stands behind it.

How it works

The ESMA register is four lists bound together, not one. Article 109(1) names them: crypto-asset white papers for assets that are neither asset-referenced nor e-money tokens, issuers of asset-referenced tokens, issuers of e-money tokens, and crypto-asset service providers. National regulators do the authorising and then feed ESMA the data, because the same article obliges them to communicate any change notified to them. That flow of notifications is what keeps the list current.

A service provider's entry is more detailed than a yes or a no. Article 109(5) requires the firm's legal name, legal form and legal entity identifier, its commercial name, address, telephone number, email and website, the name and contact details of the competent authority that granted the authorisation, the list of crypto-asset services it may provide, the host Member States it intends to serve, and the dates of authorisation and of any withdrawal. Superseded documents are not quietly deleted either: Article 109(2) sends out-of-date white papers to a separate archive that has to be clearly marked as out of date.

Three provisions make the register useful after something has gone wrong. Article 109(7) keeps a withdrawn authorisation, along with the enforcement measures notified under Article 109(6), on display for five years. Article 110 sets up a second and deliberately non-exhaustive register of entities providing crypto-asset services in breach of Article 59 or 61, carrying at least the commercial name or website of the entity and the authority that reported it, published in machine-readable format. Article 108(2) adds a quieter use: ESMA publishes hyperlinks from the register into each national authority's complaints-handling pages.

Where you see it

Finland's Financial Supervisory Authority sends retail buyers to the register before they choose a platform. Its crypto-asset activities page tells you to test any claimed supervision against the register maintained by the authority actually named, to avoid a provider that offers no information about a supervisor at all, and it points at both the FIN-FSA's own public list of supervised entities and what it calls ESMA's interim register of crypto-asset operators across the European Union and the European Economic Area. The same page notes that supervisors also keep warning lists of suspicious or unauthorised service providers, so absence from a register and presence on a warning list are two separate checks, and a careful buyer runs both.

ESMA register vs National competent authority

The ESMA register publishes authorisations; a national competent authority grants them. ESMA compiles, a regulator such as the FIN-FSA decides, and MiCA wires the two together by making the granting authority's name and contact details part of the entry itself under Article 109(5)(c). That is why a firm can be listed at European level while its file, its complaints procedure and its supervisor all sit in one Member State. The national register stays authoritative for detail, and the European list exists so that you do not have to guess which national register to search first.

Not to be confused with

Frequently asked questions

Does appearing in the ESMA register mean an exchange is safe?

No, it only means the firm holds a MiCA authorisation and that a named supervisor stands behind it. The entry records the authorising authority, the services covered and any withdrawal, but it says nothing about fees, solvency or service quality.

How long does a withdrawn MiCA authorisation stay visible?

Five years. Article 109(7) of Regulation (EU) 2023/1114 keeps a withdrawn authorisation, and the enforcement measures notified to ESMA under Article 109(6), published in the register for five years.

What should I check if a platform is not in the ESMA register?

Check the national regulator's own register of supervised entities and its warning list. Finland's FIN-FSA advises testing any claimed supervision against the register kept by the authority named, and avoiding any provider that gives no information about a supervisor at all.

Read next

Related terms

More in Regulation & tax