Skip to main content
Authority

European Securities and Markets Authority (ESMA)

ESMA writes the securities rulebook that national authorities such as the AFM apply, and directly supervises a small set of market infrastructure: credit rating agencies, trade repositories, securitisation repositories, benchmark administrators, data reporting service providers and third-country central counterparties. For an investment firm or fund manager, ESMA is where your obligations are drafted, not where they are enforced.

Checked by Remmert
5 min read

What is ESMA responsible for?

ESMA was established by Regulation (EU) No 1095/2010 and began work on 1 January 2011, replacing the Committee of European Securities Regulators. It coordinates national competent authorities across the EU, drafts technical standards, issues guidelines and Q&As, runs peer reviews, and maintains reference data systems including FIRDS and FITRS. Verena Ross has chaired ESMA since 1 November 2021, and Natasha Cazenave has been Executive Director since 1 June 2021. A succession process is under way: ESMA published a shortlist of Chair candidates on 20 May 2026.

For an investment firm or fund manager, ESMA is where your obligations are drafted, not where they are enforced: it writes the securities rulebook that national authorities such as the AFM apply.

Last updated: 17 August 2026. First version of this page. Corrected during verification: the Moody's Deutschland sanction date, and the per-member-state MiCA transitional periods, which differ from the EU backstop.

Key facts

Which entities does ESMA supervise directly?

Not investment firms or fund managers. Those are supervised nationally. ESMA's direct population is market infrastructure: credit rating agencies, trade repositories under EMIR and SFTR, securitisation repositories, critical and third-country benchmark administrators, data reporting service providers, and third-country central counterparties through the recognition regime.

Three additions in 2026 show how that population grows:

  • EuroCTP B.V. was authorised as the consolidated tape provider for shares and ETFs on 27 July 2026, with a transition period running to 30 September 2026.
  • The Clearing Corporation of India was recognised as a Tier 1 third-country CCP on 1 July 2026.
  • ESMA published the register of external reviewers under the EU Green Bond Regulation on 22 June 2026, a new registration category.

Which regulations does ESMA develop or oversee?

RegulationWhat ESMA doesNotable status as at 17 Aug 2026

What does ESMA publish, and how often?

Consultation papers, final reports, guidelines, Q&As, public statements, supervisory briefings, peer reviews, an annual work programme and an annual report, plus the Trends, Risks and Vulnerabilities report. Q&As are issued in batches on a rolling basis: a batch on 10 July 2026 covered the ESG Ratings Regulation, MiCA and MiFIR secondary markets. A newsletter, Spotlight on Markets, appears periodically; the June to July edition was published 31 July 2026. ESMA also runs the reference data systems FIRDS and FITRS and, from 2026, the first-phase data collection for the European Single Access Point.

What has ESMA published recently?

The ten most recent items we captured, as at 17 August 2026, from ESMA's news feed. This section is fed by our monitoring pipeline and is regenerated, not hand-maintained.

DatePublication

Which deadlines does ESMA own?

2026

  1. 30 September 2026Upcoming

    End of EuroCTP's transition period as consolidated tape provider

  2. 7 December 2026Upcoming

    First T+1 regulatory deadline: allocation and confirmation processes

  3. 1 July 2026Passed

    End of the general MiCA transitional period under Article 143(3)

2027

  1. 11 October 2027Upcoming

    Full EU transition to T+1 settlement

No fixed date

  1. Jul 2027Expected

    Public launch of the European Single Access Point

What does ESMA's enforcement look like?

ESMA can fine the entities it supervises directly, and does so rarely. It fined Moody's Deutschland GmbH €2,145,000 (the public notice on ESMA's sanctions page is dated 30 June 2026, and the decision was announced on 2 July 2026) for four breaches of the Credit Rating Agencies Regulation, concerning incomplete and inaccurate data reported to ESMA's central platform and inadequate internal controls. ESMA characterised the breaches as negligent, and no published credit rating was affected.

For a firm supervised nationally, ESMA's enforcement record is not the relevant signal. The relevant one is its convergence work: peer reviews and follow-up reports, such as the 20 July 2026 review of cross-border investment services supervision across six member states, are what change how the AFM or BaFin actually supervises you.

What changes for a mid-sized institution?

Two mechanisms. Fund managers below the AIFMD thresholds operate under a lighter registration regime rather than full authorisation. And ESMA's current reporting workstream is explicitly aimed at reducing transaction-reporting burden: its July 2026 newsletter frames the simplification package in terms of annual industry savings. Neither changes what applies to you; both change how much of it you have to file.

What can GenCompl.ai do for you?

ESMA's output is the upstream source for a large share of what the AFM later asks. We track its consultations, final reports, Q&A batches, registers and statements, and date each change, so an obligation can be followed from ESMA draft through national application. The version that matters to you is narrower: which of these attaches to your permission set, on what date, under which article.

Regulations

  • Markets in Crypto-Assets (MiCA)

    MiCA is Regulation (EU) 2023/1114. Full application began on 30 December 2024 and the EU-wide transitional period expired on 1 July 2026, so there is now no grandfathering anywhere in the EEA. Around 325 crypto-asset service providers are authorised. Not one asset-referenced token issuer appears on ESMA's register.

    NextMiCA review consultation closes

    Checked

  • Digital Operational Resilience Act (DORA)

    DORA is Regulation (EU) 2022/2554. It has applied since 17 January 2025 to 20 categories of licensed financial entity, from banks to crypto-asset service providers. It requires an ICT risk management framework, major incident reporting within 4 hours of classification, an annual register of ICT contracts, and threat-led penetration testing every three years.

    NextNext register of information cycle, reference date expected 31 December 2026

    Checked