Europe is reviewing its crypto rulebook less than two years after it took full effect. Most of the debate concerns stablecoins, tokenization and the shape of DeFi.
One question, buried deep in a long technical consultation, matters more to Bitcoiners than most: could MiCA reach the wallet software in your pocket? The answer is not settled. But the early responses point in a clear direction.
The Question in the Consultation
The European Commission opened its targeted consultation on the review of MiCA on May 20, 2026. The deadline was later extended to September 30.
The relevant text sits in Question 64, part of a section on possible certification schemes for DeFi protocols. Respondents were asked to rate their agreement with a series of statements.
Two concern wallets directly.
The first: developers offering non-custodial wallets should be required to obtain a certificate before making those wallets available to the public.
The second: those developers should instead be incentivized to obtain one. The difference is not cosmetic. A mandatory certificate is a gate. Software that has not passed through it cannot lawfully reach users. An incentive leaves the gate open and rewards those who choose to walk through a different door.
The next question raises the stakes further. Question 65 asks, among other things, whether CASPs should be prevented from connecting clients to protocols that lack certification. Read together, the two questions show how a scheme described as voluntary could still shape market access in practice.
Why Custody Is the Hinge
MiCA regulates custody as a service provided to clients. In broad terms, that means safekeeping or controlling crypto assets, or the means of access to them such as private keys, on behalf of someone else.
A developer who publishes non-custodial wallet software does none of that. The user generates and holds the keys. The developer never sees them, cannot move funds and cannot freeze them.
That is why mandatory certification for wallet developers would be a conceptual shift, not technical adjustment. It would attach a regulatory requirement to the act of writing and distributing software, rather than to the act of holding or controlling someone else’s assets.
Industry Pushes Back
Two industry bodies took that point directly.
The French digital asset association Adan opposes mandatory certification for non-custodial wallet software. Its argument is that such a wallet gives its developer neither custody nor discretionary control over users’ assets, so publishing the software should not, on its own, amount to providing a crypto-asset service.
Adan supports voluntary certification instead, on the condition that it stays genuinely voluntary and does not turn into a market access requirement through the back door. The association frames its whole response around one principle: regulation should follow effective control and real risk.
The Global Blockchain Business Council takes a similar line. It strongly disagrees with mandatory certification and favors a voluntary, outcome-based approach.
It also argues that software providers should not face CASP authorization simply because their technology supports crypto transactions, where they do not independently control client assets.
The common thread is simple. Regulation should attach to whoever controls assets or provides a financial service, not to the code people use.
ESMA Draws Its Own Line
The more significant signal came from the regulator.
In its response to the Commission, published September 30, the European Securities and Markets Authority (ESMA) said that open-source development, self-custody, automated smart contracts and permissionless infrastructure should not automatically be treated as regulated intermediation.
That is close to the industry position on self-custody. It is not, however, a light-touch position on DeFi.
ESMA proposes a new regulated service under MiCA for CASPs that give clients access to decentralized protocols. It would cover firms that offer a technical interface to DeFi, route transactions or smart contract interactions, or otherwise act as intermediaries between clients and decentralized services.
The expected obligations include risk disclosures, transparency on protocol selection and routing, conflict of interest management, due diligence on the protocols offered and operational safeguards. ESMA says those duties should scale with the degree of control a CASP has over the underlying protocol.
The authority also warned about what it calls decentralization washing, where an identifiable operator uses DeFi language to avoid MiCA. It asked the Commission to define DeFi in the legal text and to keep the exemption for fully decentralized activity as narrow as possible.
The picture that emerges is coherent. Holding your own bitcoin is one thing. Running a business that stands between clients and DeFi is another.
Where the Line Could Blur
The difficult cases sit in between.
Many wallets today are not just key managers. Some integrate swaps, staking or access to third-party protocols directly in the app. ESMA’s proposal is addressed to CASPs, and it ties obligations to control.
But the more a wallet behaves like a gateway, the stronger the argument that its operator is doing more than publishing software.
That is the question the Commission will have to answer with precision. A rule drafted around function and control would leave pure self-custody tools untouched. A rule drafted around features could catch far more than intended.
What Happens Next
Nothing changes yet. A consultation response is an input, not a rule. The Commission will now weigh the submissions as it prepares its review. Under Article 140 of MiCA, that report is due by June 30, 2027.
The Commission has said it may be accompanied by a legislative proposal if warranted.
For bitcoiners, two things are worth watching. First, whether the Commission keeps the distinction between self-custody software and regulated financial services. Second, where it finally draws the line around businesses that provide access to DeFi.
If that line follows control, self-custody stays where it is today. If it follows code, the debate is just beginning.
Disclaimer: This article is analysis and commentary for informational purposes only. It is not legal advice, and nothing here is written in a professional capacity.
For clear, sourced analysis of bitcoin law and regulation around the world, subscribe to The Bitcoin Act at thebitcoinact.xyz.





