If you are mapping who regulates crypto in the EU, EIOPA is the one ESA you can almost set aside — it does insurance and pensions, not crypto, and has no role under MiCA. It is in scope here for exactly one reason: it is the third of the three European Supervisory Authorities that jointly run DORA. This is a profile of what EIOPA is, what it deliberately does not do, and how it fits beside ESMA and the EBA. Every fact is sourced.
Quick facts
- Full name: European Insurance and Occupational Pensions Authority (EIOPA) (EIOPA)
- Established: by Regulation (EU) No 1094/2010; operating since 2011 (EU institutions directory)
- Legal status: an independent EU authority / decentralised EU agency; one of the three European Supervisory Authorities (ESAs) — with the EBA (banking) and ESMA (securities) — in the European System of Financial Supervision (ESFS) (EIOPA)
- Headquarters: Frankfurt am Main, Germany (EU institutions directory)
- Mission: “to protect the public interest by contributing to the short, medium and long-term stability and effectiveness of the financial system for the Union economy, its citizens and businesses” (EIOPA)
- Chairperson: Petra Hielkema — first term 1 September 2021 to 31 August 2026; the Council of the EU has extended her mandate for a second five-year term starting 1 September 2026 (EIOPA)
- Executive Director: Damian Jaworski (EIOPA — internal organisation)
- Website: eiopa.europa.eu
What EIOPA is — and what it is not
EIOPA is the EU-level authority for insurance and occupational pensions (EIOPA). It is one of the three ESAs in the ESFS, alongside the EBA and ESMA, and it is an independent EU agency seated in Frankfurt.
What it is not — and this is the point: EIOPA has no MiCA or crypto mandate. It does not write the crypto rulebook (that is ESMA), it does not supervise stablecoin issuers (significant ART/EMT is the EBA), and it does not licence crypto firms (national regulators do). On the MiCA vertical, EIOPA simply does not appear. Its only intersection with this site’s verticals is DORA, because DORA applies across the whole financial sector — insurance and pensions included.
What EIOPA actually does
EIOPA’s core work is insurance and occupational-pensions supervision and rule-making — solvency, consumer protection, market stability in those sectors. For the verticals here, only one strand is relevant:
- It is one of the three ESAs under DORA, responsible for the insurance and occupational-pensions side of the EU’s ICT operational-resilience regime.
Everything else EIOPA does (Solvency II, pension transparency, insurance stress tests) sits outside AI Act / GDPR / MiCA / DORA scope and is not covered here.
EIOPA’s role under DORA
EIOPA is one of the three European Supervisory Authorities (ESAs) — with the EBA and ESMA — that jointly run DORA (Regulation (EU) 2022/2554, the EU’s ICT operational-resilience law for finance).
DORA’s headline novelty is direct EU oversight of critical ICT third-party providers (CTPPs — the cloud and tech suppliers the financial system depends on, e.g. the hyperscale clouds). The three ESAs jointly designate which providers are “critical” under Article 31 DORA and run the oversight through a Joint Committee, with a Lead Overseer per provider — EBA, ESMA or EIOPA, depending on which financial sector relies on it most. The first list — 19 designated CTPPs — was published by the ESAs’ Joint Committee on 18 November 2025. EIOPA’s specific weight in that machinery is the insurance and pensions sector. For the full DORA picture see the DORA pillar.
ESMA vs EBA vs EIOPA — the three ESAs, who does what
The three ESAs are routinely conflated. The clean split, across the verticals here:
- ESMA — securities markets; under MiCA, the crypto rulebook + register; one of three DORA ESAs.
- EBA — banking; under MiCA, prudential supervision of significant stablecoins; one of three DORA ESAs.
- EIOPA — insurance and occupational pensions; no MiCA role at all; one of three DORA ESAs.
So on crypto, two of the three ESAs matter (ESMA, EBA) and one does not (EIOPA). On DORA, all three matter equally — that is why EIOPA is profiled here.
Leadership
EIOPA is run by a Chairperson (the public-facing head, who chairs the Board of Supervisors of national insurance/pensions regulators) and an Executive Director (who runs the organisation day to day).
- Chairperson: Petra Hielkema. Her first term ran 1 September 2021 to 31 August 2026; the Council of the EU has extended her mandate for a second five-year term beginning 1 September 2026, following the Board of Supervisors evaluation conducted in accordance with Regulation (EU) No 1094/2010 (EIOPA).
- Executive Director: Damian Jaworski, listed under EIOPA’s Senior Management (EIOPA — internal organisation).
(Note: national figures such as the BaFin “Chief Executive Director for Insurance” sit on EIOPA’s Board/Management Board as Member-State representatives — they are not EIOPA’s own Executive Director. Don’t conflate the two.)
What this means for you
- If you are a crypto firm or stablecoin issuer: EIOPA is not your regulator and has no MiCA role — your authorities are national NCAs, with ESMA (rulebook/register) and the EBA (significant stablecoins) at EU level.
- If you are an insurer, pension provider, or a financial entity in those sectors under DORA: EIOPA is one of your three ESAs, and the Lead Overseer for a CTPP you depend on may be EIOPA if your sector is the main user.
- If you are mapping the EU financial-supervision architecture: EIOPA completes the trio (banking = EBA, markets/crypto = ESMA, insurance/pensions = EIOPA); on DORA the three act jointly.
- If you are a journalist or researcher: “the EU insurance regulator” = EIOPA, Regulation (EU) No 1094/2010, operating since 2011, Frankfurt; Chairperson Petra Hielkema (second term from 1 September 2026); it has no crypto/MiCA role — only DORA links it to this site.
TL;DR
EIOPA is the EU’s insurance and occupational-pensions authority, established by Regulation (EU) No 1094/2010, operating since 2011, based in Frankfurt, and one of the three ESAs (with the EBA and ESMA) in the European System of Financial Supervision. It has no MiCA or crypto mandate: it appears here solely as the third ESA under DORA, sharing the joint oversight of critical ICT third-party providers (19 designated on 18 November 2025) and acting as Lead Overseer where the insurance/pensions sector is the main user. Chairperson Petra Hielkema (first term 1 September 2021–31 August 2026; extended for a second five-year term from 1 September 2026); Executive Director Damian Jaworski.
Sources
- EIOPA — About — full name, mission, one of three ESAs with EBA and ESMA, Frankfurt
- EU institutions directory — EIOPA — established 2011, Frankfurt am Main, decentralised agency / ESFS
- EIOPA — Council extends the term of Chairperson Petra Hielkema — first term 1 September 2021–31 August 2026, second five-year term from 1 September 2026, Regulation (EU) No 1094/2010
- EIOPA — Internal organisation — Executive Director Damian Jaworski
- DORA — Regulation (EU) 2022/2554 (EUR-Lex) — Article 31, CTPP regime
- List of designated CTPPs, ESAs Joint Committee, 18 November 2025
- DORA pillar · ESMA profile · EBA profile · eiopa.europa.eu