Why Has the EU Clarified Its Stablecoin Requirements?
On October 8, 2026, the European Securities and Markets Authority (ESMA) published an opinion clarifying supervisory expectations for crypto-asset services involving asset-referenced tokens and e-money tokens that do not comply with the Markets in Crypto-Assets Regulation, or MiCA. ESMA said crypto-asset service providers authorized under MiCA should cease providing services related to non-compliant stablecoins to clients in the European Union.
The scope extends beyond exchange listings. It includes trading, exchange services, order execution, transfers, custody, investment advice, portfolio management, and other services covered by MiCA. A platform does not need to issue a stablecoin itself to face compliance obligations. Providing access to, or facilitating transactions involving, a non-compliant token may also require operational changes.
The opinion is important because stablecoins can be embedded throughout a platform's services. A token may be used as a trading pair, a settlement asset, collateral, or a deposit and withdrawal instrument. Compliance teams therefore need to examine how each token is used, rather than reviewing only the token-listing decision.
How Should Crypto Platforms Implement MiCA Controls?
A practical compliance program starts with token classification and due diligence. Platforms should verify the issuer, regulatory status, applicable jurisdiction, and relevant authorization or documentation. A token's popularity, liquidity, or market capitalization does not establish that it meets the applicable legal requirements.
Controls should also extend across the asset lifecycle, including listing, trading, deposits, withdrawals, transfers, and custody. Where restrictions apply, a provider may need to prevent new exposure, suspend relevant services, or arrange a compliant exit process, depending on the circumstances and regulatory instructions.
ESMA stated that national competent authorities should require existing exposures to be addressed as soon as possible and no later than three months after publication of the opinion. Any continued services during the transition should be limited to activities necessary for liquidation, conversion, withdrawal, transfer, or safekeeping, and remain time-limited and closely supervised.
These requirements make documentation particularly important. Compliance teams should record why an asset was classified in a particular way, which services were affected, what restrictions were applied, and how customers were informed. A documented decision process helps demonstrate that controls are based on regulatory requirements rather than ad hoc operational judgments.
Why Do KYT and Transaction Monitoring Still Matter?
Token eligibility and transaction risk are related but distinct questions. Token-level review determines whether an asset can be supported under the applicable framework. Know Your Transaction (KYT) monitoring examines whether particular transactions may involve suspicious flows, sanctioned entities, or other high-risk activity.
Platforms need both layers. A compliant stablecoin can still be involved in a suspicious transaction, while an asset's regulatory status may require review even when a particular transfer does not appear suspicious. Address screening, transaction graph analysis, risk alerts, and case management can help teams investigate on-chain activity, but they do not replace issuer due diligence or legal analysis.
Cross-border providers should maintain an update process for token classifications and risk rules as regulations evolve. MiCA's implementation reinforces the need to connect legal review, product operations, transaction monitoring, and audit trails in one compliance workflow.
The broader lesson is that stablecoin compliance is no longer only a listing question. It is an ongoing control responsibility spanning the token, the services offered, the customer relationship, and the underlying transactions.