The European Securities and Markets Authority (ESMA) recently launched a Common Supervisory Action (CSA) targeting the digital operational resilience of Crypto-Asset Service Providers (CASPs) across the European Union, with a specific emphasis on custody services. This significant move comes shortly after the Markets in Crypto-Assets Regulation (MiCA) entered into full enforcement on July 1, 2026, marking a pivotal shift from regulatory authorization to active, coordinated supervision.
The CSA, which will be carried out by National Competent Authorities (NCAs) in EU member states, aims to assess the maturity of CASPs' digital operational resilience frameworks as they pertain to custody activities. This initiative is not a one-off check but a structured, coordinated effort designed to ensure consistent application of MiCA's stringent requirements across the bloc. The reviews are scheduled to run from the second half of 2026 through the first half of 2027, with ESMA consolidating the findings into a final report to be submitted to its Board of Supervisors in the latter half of 2027.
ESMA's scrutiny will focus on several critical areas inherent to distributed ledger technology (DLT) and crypto custody. These include governance arrangements, robust key and storage management practices, effective transaction controls, and comprehensive incident detection and response mechanisms. Regulators will also examine risks associated with smart contracts and the dependencies CASPs have on third-party providers, acknowledging the complex ecosystem in which these firms operate. This comprehensive scope mirrors the operational resilience frameworks applied to traditional financial market infrastructures under other EU regulations like DORA.
The decision to prioritize custody services reflects regulators' view of where the greatest risks lie within the crypto asset landscape. Custody is the layer where user assets are most vulnerable, making a provider's operational resilience—including cybersecurity posture, IT governance, and incident response capabilities—paramount for investor protection and market integrity. Industry experts note that a MiCA license should be seen as a starting point, not an endpoint, with the expectation now shifting from merely asserting security to actively evidencing it.
This coordinated supervisory action raises the bar for firms that have already secured authorization under MiCA. It signals that the grace period for EU crypto custodians is over, and regulators are moving into an enforcement mode to ensure compliance with the new framework. The review is expected to increase compliance costs for some firms and may even drive consolidation within the EU custody sector, while simultaneously boosting demand for regulated custody solutions and institutional staking as regulatory clarity in Europe continues to evolve.
Ultimately, this initiative underscores the European Union's commitment to establishing a robust and secure regulatory environment for crypto assets, aligning supervisory expectations for crypto custody providers with those of traditional financial services. The findings from this CSA will be crucial in shaping future supervisory guidelines and potentially influencing further technical standards for the custody sector under MiCA.
Original announcement: ESMA