← Back to Home News · EU

ESMA puts CASP custody resilience under EU review

Make RegTech.com preferred on Google
ESMA puts CASP custody resilience under EU review
ESMA launched a Common Supervisory Action on the digital operational resilience of crypto-asset service providers, with a specific emphasis on custody, on 8 July 2026.
AI Summary
  • ESMA has launched a Common Supervisory Action on the digital operational resilience of crypto-asset service providers, with a specific focus on how they hold client assets. Announced on 8 July 2026, it is one of the first coordinated European checks aimed at whether crypto custodians can withstand a serious technology failure or attack.
  • National regulators will apply a common ESMA methodology to a risk-based sample of authorised providers, testing six areas: governance, key and storage management, transaction controls, incident detection and response, smart-contract risk, and dependence on third-party suppliers. Supervisory work runs through the second half of 2026 and into 2027, with a final report to ESMA’s Board of Supervisors in the second half of 2027.
  • The exercise does not create new rules. It tests firms against DORA’s technology-resilience duties and MiCA’s custody obligations, both already in force, and signals that operational resilience in crypto custody is now a supervised discipline rather than a best-effort promise.

Europe’s markets regulator is turning its attention to how crypto firms hold customer assets. On 8 July 2026, the European Securities and Markets Authority (ESMA) launched a Common Supervisory Action focused on the digital operational resilience of crypto-asset service providers, with an emphasis on custody. It is one of the first coordinated European checks to assess whether firms holding client crypto can withstand a serious technology failure or attack.

What ESMA is actually doing

A Common Supervisory Action, or CSA, is not an enforcement case. It is the mechanism ESMA uses to run the same supervisory exercise across national regulators at the same time. ESMA sets a common methodology and set of questions; each national competent authority applies it to a risk-based sample of the crypto firms it supervises; those regulators gather data and inspect, and consolidate the results into an EU-wide picture. 

ESMA has said national authorities will carry out the exercise on a risk-based sample of authorised providers rather than every firm, and the findings will feed into a final report to its Board of Supervisors in the second half of 2027, after supervisory work running through the second half of 2026 and into the first half of 2027.

The point of a CSA is convergence. ESMA wants national regulators to assess the same things in the same way, so a crypto firm passported across the bloc is not held to a materially softer standard in one member state than in another. ESMA framed the exercise as a response to its risk-based supervisory priorities, which single out both digital operational resilience and crypto-asset service providers as key risk areas, and as a way to build supervisory convergence in a fast-moving part of the market.

Six areas under the microscope

ESMA said the review will assess the maturity of firms’ digital operational resilience frameworks in relation to custody across six areas:

  • Governance, meaning clear ownership and accountability for how custody and the technology behind it are run.
  • Key and storage management, the handling of the cryptographic keys that ultimately control client assets, including how they are generated, backed up, recovered and segregated between hot and cold storage.
  • Transaction controls, the safeguards around moving assets, such as withdrawal approvals and checks.
  • Incident detection and response, how quickly a firm can spot and contain a breach or outage.
  • Smart contract risks, where custody or asset movement depends on on-chain code.
  • Dependencies on third-party providers, the wallet vendors, cloud services and other suppliers a custodian relies on.

Read together, that list maps where crypto custody actually breaks. 

Where DORA and MiCA turn this into obligations

The CSA tests firms against two existing obligations. The first is the Digital Operational Resilience Act (DORA), the EU regulation on financial-sector technology risk that has applied since January 2025. DORA requires firms to run a proper ICT risk-management framework, classify and report major incidents, test resilience regularly, and manage risk concentrated in third-party technology suppliers, with contracts and oversight to match. For the largest and most significant entities, that testing extends to threat-led penetration testing on a multi-year cycle, exercises designed to mimic a real attacker.

The second is the Markets in Crypto-Assets Regulation (MiCA), which sets the custody duties themselves. A licensed provider must keep client crypto-assets segregated from its own, hold them so clients are protected if the firm fails, maintain a custody policy and registers of what it holds for whom, and is liable to clients for losses attributable to the firm. Because a MiCA licence passports across the EU, a weakness at one custodian is not a local problem. That exposure travels across borders with the licence, which is why ESMA wants a common standard rather than twenty-seven different ones.

What custodians will need to show

For a compliance or operations team at a crypto custodian, the CSA is a readiness test. The firms in scope should expect to demonstrate, on request and within the review window, that they can produce:

  • documented governance and clear accountability for custody and its supporting technology;
  • disciplined key and wallet management, covering key generation, backup and recovery, hot and cold segregation and access controls;
  • transaction controls such as withdrawal thresholds, address whitelisting and multi-signature approvals;
  • incident detection and response aligned to DORA’s classification and reporting duties;
  • a handle on smart-contract risk, including audits, upgrade governance and on-chain monitoring;
  • real oversight of third parties, from due diligence and contracts through to monitoring of wallet vendors, cloud providers and sub-custodians;
  • client-asset segregation backed by auditable registers, and a custody policy and asset-return procedure that would survive a stress event.

Why it matters

The custody failures that make headlines are rarely a dramatic hack of the core vault. They are the boring edges: a supplier that gets breached, a plugin that leaks data, a firmware bug, a recovery process that was never really tested. Our own reporting has tracked exactly those failure modes, from a wallet data breach traced to an order-tracking plugin and a customer-data exposure through a shipping partner to a hardware-wallet firmware flaw that put seeds at risk, and a broader argument for statutory security standards after repeated wallet failures. ESMA’s six areas read the checklist drawn from those incidents.

For firms, the practical message is that operational resilience is now a supervised discipline. A regulator can ask to see the evidence, and MiCA already makes the firm liable when custody goes wrong. For the market, a common EU baseline is overdue: as we reported when the MiCA transitional deadline left many providers still unlicensed, and when an independent security review faulted a licensed stablecoin, a licence on paper is not the same as resilience in practice. This CSA is ESMA’s attempt to close that gap before a failure does it for them.

Link copied to clipboard
AI Bot
AI Bot
Hi! I'm the RegTech.com assistant. How can I help you today?
Ask me anything — top trending news, latest regulatory changes in the EU, or simply search for topics.