← Back to updates
ESMA

ESMA

European Securities and Markets Authority

Medium Impact

ESMA to run 2026-2027 CSA on CASPs’ digital operational resilience for crypto-asset custody

Published

Jul 8, 2026

Topics

Crypto-assets, CASPs, Digital operational resilience, Custody, DLT, Cyber and ICT risk, Third-party risk, MiCA, DORA

Executive Summary

ESMA has announced a Common Supervisory Action (CSA) on the digital operational resilience of authorised crypto-asset service providers (CASPs), focused on custody services. National Competent Authorities (NCAs) will examine a risk-based sample of CASPs from the second half of 2026 to the first half of 2027, with ESMA consolidating findings for its Board of Supervisors after the exercise in the second half of 2027. The CSA does not create a new reporting template or a new legal application date; it signals coordinated supervisory scrutiny of existing operational-resilience expectations under the EU crypto and ICT-risk frameworks. The review areas are operationally specific: DLT governance, private-key and storage management, transaction controls, incident detection and response, smart-contract risks and third-party dependencies. For authorised CASPs providing custody or safeguarding/control of crypto-assets, the business priority is to be able to evidence mature controls, ownership and testing results before NCA selection. Non-custody CASPs, wallet technology providers, ICT vendors and outsourced key-management providers may face due-diligence requests and heightened contractual oversight.

What Changed

newCSA launched for CASP custody resilience

Previous

No announced ESMA CSA dedicated specifically to CASP digital operational resilience for custody services.

New

NCAs will assess a risk-based sample of authorised CASPs, coordinated through ESMA’s CSA framework.

newDefined supervisory focus areas

Previous

General DORA and MiCA obligations applied, but ESMA had not announced this custody-specific CSA scope.

New

Firms should expect NCA questions and evidence requests around the specific focus areas named by ESMA.

newRisk-based NCA sampling

Previous

No CSA sample methodology for this topic had been announced.

New

Selection will be risk-based and limited to authorised CASPs chosen by NCAs.

newSupervisory timetable

Previous

No timetable for this custody resilience CSA existed.

New

CSA fieldwork is scheduled for H2 2026 to H1 2027, followed by consolidated reporting in H2 2027.

Business Impact

Who is affected

Directly affected

authorised EU CASPs providing custody services or safeguarding/control of crypto-assets on behalf of clients.

Indirectly affected

group compliance, risk, technology and internal audit teams supporting EU CASPs; wallet, key-management, cloud, DLT infrastructure, smart-contract and other ICT third-party providers; non-EU affiliates providing operational support to EU CASPs.

Jurisdictions

European Union, European Economic Area, where EU crypto-asset and financial-services rules are applied through local implementation or supervisory arrangements

Business processes

Custody technology governance and control ownership, Private-key generation, storage, backup, recovery and destruction controls, DLT transaction approval, monitoring, exception handling and reconciliation, ICT incident detection, classification, escalation and response, Smart-contract risk assessment and change control, ICT third-party due diligence, contracting, monitoring and exit planning, NCA supervisory request management and evidence production

Estimated effort

Medium

Compliance risk

Medium

Affected Reports

CSA preparedness evidence pack for custody digital operational resilienceDLT, private-key and storage management control registerCustody transaction-control and exception-review logICT/DLT incident detection, response and escalation playbookCritical ICT third-party and outsourced custody dependency inventory
FieldValidation rule
Custody DLT governance arrangementsESMA identified governance arrangements as a CSA assessment focus; this is a supervisory focus area, not a new regulatory template field.
Key and storage managementESMA identified key and storage management as a CSA assessment focus for CASP custody activities.
Transaction controlsESMA identified transaction controls as a CSA assessment focus for DLT-related custody risks.
Incident detection and responseESMA identified incident detection and response as a CSA assessment focus; DORA separately sets ICT incident and resilience requirements for in-scope financial entities, including CASPs.
Third-party provider dependenciesESMA identified dependencies on third-party providers as a CSA assessment focus; DORA also contains ICT third-party risk management requirements.

Recommended Actions

7 suggested next steps· derived from source analysis
  1. 1
    Confirmed actionStep 1 of 7

    treat the ESMA announcement as a supervisory exercise, not as a new filing obligation or new template; however, prepare for NCA evidence requests if the firm is an authorised CASP providing custody services.

  2. 2
    AI generatedStep 2 of 7

    map the CSA focus areas to existing DORA and MiCA control frameworks, identifying gaps in governance, key management, custody transaction controls, incident response, smart-contract risk and third-party oversight.

  3. 3
    AI generatedStep 3 of 7

    create a concise CSA evidence pack showing control owners, policies, testing results, incidents, remediation status and board or committee oversight for custody operations.

  4. 4
    AI generatedStep 4 of 7

    review private-key lifecycle controls, including generation, segregation, storage, backup, recovery, privileged access, dual control and destruction, against documented risk appetite.

  5. 5
    AI generatedStep 5 of 7

    test incident detection and response scenarios involving custody outages, compromised keys, failed DLT transactions, smart-contract vulnerabilities and third-party service disruption.

  6. 6
    AI generatedStep 6 of 7

    refresh third-party inventories and contracts for custody-critical ICT, wallet, DLT infrastructure, cloud and key-management providers, including audit rights, resilience expectations and exit arrangements.

  7. 7
    AI generatedStep 7 of 7

    brief senior management and local NCA-facing teams on the H2 2026 to H1 2027 CSA window and agree ownership for rapid response to supervisory questionnaires or onsite reviews.

Timeline

publication

Jul 8, 2026

ESMA published the CSA announcement on CASPs’ digital operational resilience for custody.

implementation

Date not specified

NCAs are scheduled to begin the CSA on a risk-based sample of authorised CASPs.

implementation

Date not specified

The CSA exercise is scheduled to run through the first half of 2027.

other

Date not specified

Findings collected from NCAs are expected to be consolidated into a final report for submission to ESMA’s Board of Supervisors following conclusion of the exercise.

Sources

AI-generated analysis is based on the following primary sources. Always verify against the official publication.

Related Evidence

Verified source support for this analysis

The evidence agent checks whether the drafted finding is supported by official publications and relevant public source material.

Receive updates like this by email

Get AI-generated analysis for the regulators and topics you care about.

Pulse is built by Datox. Datox automates AIFMD Annex IV and SEC Form PF reporting end to end.

See the Datox platform