
The European Securities and Markets Authority (ESMA) has launched a Common Supervisory Action (CSA) with national regulators to assess how well crypto asset service providers (CASPs) protect digital assets held in custody, marking a coordinated supervisory effort across the European Union.
In a circular published on August 6, the Cyprus Securities and Exchange Commission (CySEC) said the review will focus on the digital operational resilience of authorized CASPs offering custody services. The exercise is scheduled to run from the second half of 2026 through the first half of 2027 and will include both on-site inspections and desk-based reviews.
The review will examine whether firms have adequate safeguards against operational and cyber risks associated with distributed ledger technology (DLT). Regulators will evaluate governance and internal controls, private key and storage management, transaction controls, threat monitoring and incident response, smart contract controls, and third-party risk management.
Only authorized CASPs that provide custody services will be included in the supervisory exercise. According to CySEC, the inspections are intended to ensure a consistent supervisory approach across EU member states while addressing risks in the rapidly growing crypto sector.
The initiative reflects ESMA's supervisory priorities, which identify both digital operational resilience and crypto asset service providers as areas requiring closer regulatory attention. As more firms offer crypto custody services under the EU's regulatory framework, supervisors are placing greater emphasis on firms' ability to protect client assets from cyber threats, operational failures, and technology-related risks.
CySEC said the expectations outlined in the circular will form part of its supervisory review during the CSA 2026 exercise, signaling that eligible crypto custody providers should ensure their operational resilience frameworks meet regulatory standards before inspections begin.