On 30 September 2026 the European Securities and Markets Authority (ESMA) published its response, referenced ESMA75-113276571-1721, to the European Commission's public consultation on the review of the Markets in Crypto-Assets Regulation (MiCA). The document asks the Commission to create a new regulated crypto-asset service for firms that give clients access to decentralised finance through an interface, to keep the DeFi exemption as narrow as possible while defining more clearly which activities are genuinely decentralised, to let ESMA issue binding opinions on how tokens are classified, and to write into MiCA an explicit ban on licensed providers offering services linked to stablecoins that do not comply with the rules. On staking, lending and borrowing, ESMA proposes targeted conduct, disclosure and safeguarding requirements rather than a new authorisation regime.
The most consequential proposal concerns CASPs acting as gateways to DeFi. ESMA describes a new regulated service covering firms that provide a technical interface enabling clients to interact with DeFi protocols, that facilitate transaction routing or interaction with smart contracts, or that otherwise act as intermediaries between clients and decentralised financial services. The obligations ESMA lists for such gateways include disclosure of the risks associated with DeFi protocols, transparency on protocol selection and routing practices, management of conflicts of interest, due diligence on the protocols made available, and operational and cybersecurity safeguards; ESMA states the obligations should remain proportionate to the control the CASP exercises over the underlying protocol, and that open-source development, self-custody, automated smart contracts and permissionless infrastructure should not automatically amount to regulated intermediation. The aim, ESMA writes, is to improve legal certainty for CeFi-DeFi hybrid models. Alongside the new service, ESMA reports divergent views across the EU on what full decentralisation means under Recital 22 of MiCA, warns about "decentralisation washing" whereby an identifiable operator relies on DeFi-style language to avoid obligations, and invites the Commission either to define DeFi in the legal text or to empower ESMA to issue technical guidelines.
On staking, ESMA recognises it as a core technical function of proof-of-stake networks that should not automatically be treated as lending or portfolio management, while highlighting investor-protection risks such as slashing, lock-up periods, unclear asset segregation in insolvency, and marketing that emphasises rewards while downplaying losses. It proposes that MiCA distinguish self-directed staking, technical staking services, pooled or custodial staking, and liquid or yield-bearing staking products, with enhanced disclosures on rewards, unbonding periods, validator selection, fees, operational dependencies and insolvency treatment. On lending, ESMA notes that CASPs borrowing client crypto-assets, sometimes without collateral, and re-lending them can produce cascading failures, because MiCA custody and segregation rules no longer apply once assets are lent out; it does not propose a new authorised service, but asks the Commission to require express written consent and disclosure whenever CASPs offer or facilitate lending. For borrowing, it requests targeted conduct, disclosure and risk-management requirements, particularly for retail clients and leveraged products, covering collateral, liquidation mechanisms, rehypothecation and affiliated counterparties.


