ESMA puts reverse solicitation on its 2027 watch list: what investors need to know about exchanges without an EU licence
ESMA presented its work programme for 2027 on September 28, 2026 and made reverse solicitation a supervisory priority. What that means if your coins sit with a provider without EU authorisation, and which three steps make sense now.

Table of Contents
Table of Contents
The European Securities and Markets Authority, ESMA, presented its work programme for 2027 on September 28, 2026. It contains a technical term that can have tangible consequences for European investors: reverse solicitation. It refers to the exemption under which a crypto exchange without an EU licence may serve European customers at all. ESMA has expressly put that exemption on its list of supervisory priorities for 2027.
The most important qualification first, so that you read the news correctly: this is not a ban, and it does not take effect today. It is an announcement of what the supervisors intend to look at together over the coming year. That is precisely where its practical value lies for you. You have time to put your access, your withdrawal routes and your records in order calmly, while nothing has to happen under pressure.
Reverse solicitation: the exemption in Article 61 of the MiCA regulation
Reverse solicitation means this: a provider established outside the European Union may supply a crypto service in the EU only where the client has requested it at their own exclusive initiative. Article 61 of the regulation on markets in crypto-assets, MiCA for short, is therefore not a free pass in substance but a prohibition on approaching clients with a narrow back door: advertising, offering and promoting are forbidden, and only the client can open contact.
That sounds like a formality, but it is the legal reason why some internationally known trading venues have remained technically reachable for European users after the end of the MiCA transition period on July 1, 2026. The operators rely on the argument that their European customers came of their own accord. Whether that holds is decided neither by the provider nor by the small print in its terms of use, but by the competent supervisor on the facts.
What the ESMA guidelines of February 2025 laid down
Article 61(3) of the MiCA regulation instructs ESMA to determine the circumstances in which a third-country provider counts as soliciting. The authority did so in guidelines in February 2025, and its reading is deliberately broad: the requirements are drafted technology-neutrally, so that any act which promotes, offers or even indirectly touts crypto services to EU clients can count as solicitation. A clause in the terms of business stating that the client made contact themselves is expressly not sufficient under those guidelines. The facts have to show that no solicitation took place.
For you as a user, that is the decisive point. Consent you clicked away when opening the account does not protect the provider. It protects you even less.
The ESMA work programme for 2027 names five priorities for crypto supervision
In the statement on the programme, the authority describes 2027 as the year in which many of its strategic projects move from preparation into implementation. ESMA chair Verena Ross calls the year "an important milestone for the Savings and Investments Union", because numerous initiatives "move into the delivery phase". For crypto-assets, the statement announces that supervisory convergence in the EU will be strengthened together with the national authorities, "including on supervision of crypto-asset service providers (CASPs) under MiCA".
CASP stands for crypto-asset service provider, that is, the crypto service provider authorised under MiCA. That is the category exchanges, brokers, custodians and swap services fall into if they want to operate legally in the EU.
Which fields the authority has specifically in mind is not in the brief press release but in the programme itself. Cointelegraph reported five priorities for the supervision of crypto service providers from it on September 28:
- Operational resilience: how stable and sustainable a provider's systems are in the event of disruption.
- Outsourcing: which dependencies on third parties exist and which weaknesses follow from them.
- Liquidity: whether sufficient liquid funds and holdings are in place.
- Reverse solicitation: whether the geographic limits of the offering are being circumvented.
- Classification of assets: how individual tokens are to be classified under MiCA.
The order of this list is not a ranking, and none of the five points is a new rule. What is new is that the authority is declaring them examination fields to be worked through evenly across all member states in 2027. That outsourcing comes in second fits a pattern that has marked the year 2026: attacks and outages at trading venues repeatedly originated not in the core system but in bought-in software.

The ESMA guidelines do not accept disclaimers as proof
That makes an important distinction that often blurs in practice. Reachability is not permissibility. A trading platform that opens in a browser in Germany says nothing about whether it may provide services here. Conversely, a licence in another EU country very much does mean the provider may serve you in Germany: MiCA allows an authorised CASP to carry its permission into the remaining member states. Carrying the permission across is called passporting and is the normal case in the European single market.
Anyone who wants to know which of these situations their own provider is in cannot get around two public registers. ESMA maintains an EU-wide register of authorised crypto service providers, and BaFin maintains its company database for Germany. How to work with them in a few minutes is described step by step in our guide to checking a crypto provider. You will find the European register in ESMA's MiCA register.
Crypto exchanges with a MiCA licence comparedMIDAS: central market surveillance goes fully live in 2027
The second part of the programme concerns the ongoing observation of trading rather than authorisation. MIDAS is the central surveillance system with which ESMA scans the European crypto market for market abuse, that is, for insider dealing, for the exploitation of information not yet published and for faked turnover. On Cointelegraph's report of September 28, the first stage of the system is to go fully live in 2027, with the second stage following in the fourth quarter.
That is the quieter but more effective half of the announcement. A supervisor that brings order data together across trading venues sees patterns a single national authority would miss. For the individual investor that means two things: trading at authorised venues is better policed overall, and anyone operating in grey areas themselves, for instance with coordinated buying in groups, is moving in a field that becomes measurable.
Harmonised reporting, common risk indicators and supervisory dashboards
According to the same report, the programme includes three projects that sound like administrative plumbing and yet determine how quickly a supervisor can react. The regular reports crypto service providers make to their national authorities are to be standardised. Common risk metrics are to be added, so that the same situation is assessed the same way in Dublin and in Frankfurt. And the authorities are to receive overview displays in which the figures come together.
To see why that counts for a retail investor at all, picture the opposite. Until now it is largely the national authority that decides at what intervals and in what format a provider reports. If a firm fails, the search for reliable figures only begins in the emergency. Standardised reporting shortens exactly that search, and it raises the chance that a problem is noticed before the withdrawal freeze rather than after it.
Verena Ross explains the direction in the report with a sentence that sums it up well: "We want innovation to flourish within a framework that provides clarity for firms, safeguards for investors and confidence in the markets."
What changes for investors in Europe
Nothing changes immediately in your rights and obligations. A work programme is not legislation, and the fields named have long been regulated within the MiCA framework. Something else can shift, namely practical access.
If reverse solicitation is examined against the same standards in all member states in 2027, the room for providers without an EU licence gets smaller. What that means for you depends on where your coins are.
If your holdings sit with an authorised provider
Then what concerns you is mainly the supervisory side: more reporting, stricter requirements on outsourcing and resilience, and possibly queries about the classification of individual tokens. For you that is an improvement without any effort of your own. Which firms actually hold that licence is shown in our overview of regulated crypto exchanges with a MiCA licence, which we keep checking against the register.
If your holdings sit with a provider without an EU licence
Then the situation is different, regardless of how satisfied you are with the service. An account whose legal basis is a narrowly construed exemption can change without your having done anything wrong. In practice over recent months that has usually meant: trading is restricted for customers from the European Economic Area, deposits are blocked, withdrawals stay open for a period. Anyone who misses that period has no legal problem, but a timing problem.

BaFin stays responsible, the standardisation comes from Paris
A widespread misunderstanding belongs cleared up at this point. ESMA does not supervise your provider itself. Authorisation and ongoing supervision sit with the national authorities under MiCA, in Germany therefore with BaFin. ESMA maintains the European register, issues guidelines and works towards uniform application. That is why the programme uses the word convergence and not the word takeover.
For you that carries a tangible advantage: your point of contact stays German and German-speaking. Complaints about an authorised provider run through BaFin, and MiCA gives you a procedure of your own for that in Article 71, with deadlines. What to bear in mind and how long a provider has to answer is laid down in the regulation itself; the provider has to reply within the period named there.
The timeline: from the 2027 work programme to supervision on the ground
Time passes between a published work programme and an actual query to a provider. The programme applies to the 2027 calendar year, so it starts to bite in a good three months at the earliest. Until then nothing changes in the legal position, because the obligations themselves have been in force since the end of the transition period on July 1, 2026. What is added in 2027 is even enforcement.
That sequence is the reason a rushed reaction achieves nothing here. No investor has to close an account today because an authority has named an examination field. Anyone using a provider whose licence they have never looked up, however, now has a good window for it. The individual MiCA obligations and their deadlines are set out in our overview of MiCA licensing duties for crypto companies.
Limits of this assessment: what the work programme leaves open
A work programme is a statement of intent with a budget attached, not a legal rule. Three things are expressly not in it, and they belong to an honest reading.
First, the programme names no names. It does not say which providers will be examined, and no allegation against any particular company follows from the mention of reverse solicitation. Second, it says nothing about sanctions. Whether a condition, a fine or nothing at all stands at the end of an examination is decided by the competent national authority in each individual case. Third, the order of the priorities is not a ranking, even if the list suggests one.
Added to that is a limitation concerning our own research: the five priorities and the MIDAS stages are not in the authority's short press release but in the detailed programme document. For those we rely on ESMA's statement of September 28, 2026 and on Cointelegraph's report of the same day, which evaluated the document. Anyone wanting to read the wording themselves will find it in ESMA's statement on its priorities for 2027.
Reverse solicitation: what to take away
The news is no reason to hurry and a good reason to get organised. Three steps are enough, and none of them costs money.
- Establish whether your provider is authorised. Search the full company name in the European register and in BaFin's company database. If you find it in neither, the service is not operating in Europe on a permission of its own. Which firms hold a MiCA licence is shown in the overview of regulated crypto exchanges.
- Test the withdrawal route once before you need it. Push a small amount to an address of your own and note the time and the cost. Anyone who has walked the route once loses no days to verification when a deadline hits. Which devices come into question is set out in the hardware wallet comparison.
- Export your records now, not later. Download the trading and withdrawal history as a file while your access is working normally. Lose the access and you lose the convenient route to your tax data as well. Tools that read such exports can be found in the overview of crypto tax tools.
In short: on September 28, 2026 ESMA announced that for 2027 it will examine the exemption in Article 61 MiCA against uniform standards across Europe, along with outsourcing, resilience, liquidity and the classification of tokens. No rule has changed as a result. What has changed is the likelihood that a provider without European permission will go unbothered next year.
(As of September 29, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Frequently asked questions about reverse solicitation
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Binance Is Out of the EU: How to Move to a MiCA-Regulated Exchange
- MiCA Register 2026: Only 21 of 329 Licences Are Real Exchanges
- Crypto Exchange Shutting Down: What to Do Before the Deadline Passes
- Bitget Hack of $351 Million: What to Check at Your Crypto Exchange Now
- Binance Is Leaving the EU on July 1 — What It Means for Your Funds
More from CryptoTicker






























