✍️ Author: Karel Havlíček · 📅
Why a regulator was reviewing another regulator
On 10 July 2025, the European Securities and Markets Authority published a peer review of how the Malta Financial Services Authority had authorised crypto-asset service providers under MiCA.
The context matters. Malta moved faster than most Member States, issuing CASP authorisations ahead of other regulators. Under MiCA those licences passport across the entire EU — a firm licensed in Malta may serve customers in all 27 states. That makes one national regulator's standards everyone else's problem, which is precisely why ESMA looked.
Peer reviews of this kind are routine supervisory practice, not scandal. But the findings are worth knowing if you are choosing a platform, because the coverage of them has been unusually polarised — some outlets reported it as an indictment, others as a clean bill of health. Neither is accurate.
What the review actually said
The findings were mixed, and the detail matters more than the headline:
- The MFSA fully met expectations on supervisory resources and institutional settings.
- It largely met expectations in exercising supervisory powers after authorisation.
- It only partially met expectations in how it authorised at least one unnamed CASP — with unresolved governance, ICT and anti-money-laundering concerns that ESMA said should have been addressed before the licence was granted.
A central observation concerned timing: the MFSA issued a CASP authorisation ahead of other Member States, and ESMA considered that the assessment process should have been more thorough.
Read plainly, that is neither «Malta is fine» nor «Malta is rogue». It says the supervisor has real capacity and post-authorisation powers, and that in at least one case speed came at the cost of depth. The firm was not named, so no conclusion can be drawn about any specific platform.
What this means when you choose a platform
Three practical takeaways, none of them alarmist.
A licence is a floor, not a guarantee. MiCA authorisation means a firm met a defined standard at a point in time and is subject to ongoing supervision. It does not mean the firm cannot fail, be badly run, or lose your money. Treat it as the minimum filter rather than the end of your due diligence.
Passporting cuts both ways. The same mechanism that lets you use a well-run Irish or Dutch provider from Malta also means a licence granted anywhere applies everywhere. You cannot pick your supervisor by picking your country — which is exactly why ESMA reviews national authorities in the first place.
Verify, do not assume. Both the MFSA and ESMA maintain public registers of authorised firms. Checking takes a minute, and false licence claims remain one of the most common markers of fraud — a stated licence number that does not exist, belongs to a different company, or covers a different activity entirely.
The tax side is unaffected by any of this and is set out on the main Malta guide: what matters there is whether your activity is investment or trading, not where your platform is licensed.
❓ Frequently asked questions
What did the ESMA peer review of the MFSA find?
It found that the MFSA fully met expectations on supervisory resources and institutional settings, and largely met expectations in exercising supervisory powers after authorisation. However, it only partially met expectations in how it authorised at least one unnamed CASP, with unresolved governance, ICT and anti-money-laundering concerns that ESMA said should have been addressed before the licence was granted.
Does this mean Maltese crypto platforms are unsafe?
No. The review found genuine supervisory capacity and post-authorisation powers, and the firm in question was not named, so no conclusion can be drawn about any specific platform. The central criticism concerned timing — the MFSA issued an authorisation ahead of other Member States and ESMA considered the assessment should have been more thorough.
Why does one country's licensing standard matter across the EU?
Because MiCA licences passport. A firm authorised in any Member State may serve customers in all 27, so one national regulator's standards affect users everywhere. That is precisely why ESMA conducts peer reviews of national competent authorities.
How do I check whether a platform is genuinely authorised?
Both the MFSA and ESMA maintain public registers of authorised firms, so a claim can be verified directly in a minute. This matters because false licence claims are a common marker of fraud — a stated licence number may not exist, may belong to a different company, or may cover a different activity.
This article is informational and does not assess or recommend any specific firm. Authorisation registers change — verify a provider's current status in the MFSA register or ESMA's register before relying on it. Based on publicly available information as of July 2026.