ESMA
European Securities and Markets Authority
ESMA to run 2026-2027 CSA on CASPs’ digital operational resilience for crypto-asset custody
Published
Jul 8, 2026
Topics
Crypto-assets, CASPs, Digital operational resilience, Custody, DLT, Cyber and ICT risk, Third-party risk, MiCA, DORA
Executive Summary
ESMA has announced a Common Supervisory Action (CSA) on the digital operational resilience of authorised crypto-asset service providers (CASPs), focused on custody services. National Competent Authorities (NCAs) will examine a risk-based sample of CASPs from the second half of 2026 to the first half of 2027, with ESMA consolidating findings for its Board of Supervisors after the exercise in the second half of 2027. The CSA does not create a new reporting template or a new legal application date; it signals coordinated supervisory scrutiny of existing operational-resilience expectations under the EU crypto and ICT-risk frameworks. The review areas are operationally specific: DLT governance, private-key and storage management, transaction controls, incident detection and response, smart-contract risks and third-party dependencies. For authorised CASPs providing custody or safeguarding/control of crypto-assets, the business priority is to be able to evidence mature controls, ownership and testing results before NCA selection. Non-custody CASPs, wallet technology providers, ICT vendors and outsourced key-management providers may face due-diligence requests and heightened contractual oversight.
What Changed
Previous
No announced ESMA CSA dedicated specifically to CASP digital operational resilience for custody services.
New
NCAs will assess a risk-based sample of authorised CASPs, coordinated through ESMA’s CSA framework.
Previous
General DORA and MiCA obligations applied, but ESMA had not announced this custody-specific CSA scope.
New
Firms should expect NCA questions and evidence requests around the specific focus areas named by ESMA.
Previous
No CSA sample methodology for this topic had been announced.
New
Selection will be risk-based and limited to authorised CASPs chosen by NCAs.
Previous
No timetable for this custody resilience CSA existed.
New
CSA fieldwork is scheduled for H2 2026 to H1 2027, followed by consolidated reporting in H2 2027.
Business Impact
Who is affected
Directly affected
authorised EU CASPs providing custody services or safeguarding/control of crypto-assets on behalf of clients.
Indirectly affected
group compliance, risk, technology and internal audit teams supporting EU CASPs; wallet, key-management, cloud, DLT infrastructure, smart-contract and other ICT third-party providers; non-EU affiliates providing operational support to EU CASPs.
Jurisdictions
European Union, European Economic Area, where EU crypto-asset and financial-services rules are applied through local implementation or supervisory arrangements
Business processes
Custody technology governance and control ownership, Private-key generation, storage, backup, recovery and destruction controls, DLT transaction approval, monitoring, exception handling and reconciliation, ICT incident detection, classification, escalation and response, Smart-contract risk assessment and change control, ICT third-party due diligence, contracting, monitoring and exit planning, NCA supervisory request management and evidence production
Estimated effort
Medium
Compliance risk
Medium
Affected Reports
| Field | Validation rule |
|---|---|
| Custody DLT governance arrangements | ESMA identified governance arrangements as a CSA assessment focus; this is a supervisory focus area, not a new regulatory template field. |
| Key and storage management | ESMA identified key and storage management as a CSA assessment focus for CASP custody activities. |
| Transaction controls | ESMA identified transaction controls as a CSA assessment focus for DLT-related custody risks. |
| Incident detection and response | ESMA identified incident detection and response as a CSA assessment focus; DORA separately sets ICT incident and resilience requirements for in-scope financial entities, including CASPs. |
| Third-party provider dependencies | ESMA identified dependencies on third-party providers as a CSA assessment focus; DORA also contains ICT third-party risk management requirements. |
Recommended Actions
- 1Confirmed actionStep 1 of 7
treat the ESMA announcement as a supervisory exercise, not as a new filing obligation or new template; however, prepare for NCA evidence requests if the firm is an authorised CASP providing custody services.
- 2AI generatedStep 2 of 7
map the CSA focus areas to existing DORA and MiCA control frameworks, identifying gaps in governance, key management, custody transaction controls, incident response, smart-contract risk and third-party oversight.
- 3AI generatedStep 3 of 7
create a concise CSA evidence pack showing control owners, policies, testing results, incidents, remediation status and board or committee oversight for custody operations.
- 4AI generatedStep 4 of 7
review private-key lifecycle controls, including generation, segregation, storage, backup, recovery, privileged access, dual control and destruction, against documented risk appetite.
- 5AI generatedStep 5 of 7
test incident detection and response scenarios involving custody outages, compromised keys, failed DLT transactions, smart-contract vulnerabilities and third-party service disruption.
- 6AI generatedStep 6 of 7
refresh third-party inventories and contracts for custody-critical ICT, wallet, DLT infrastructure, cloud and key-management providers, including audit rights, resilience expectations and exit arrangements.
- 7AI generatedStep 7 of 7
brief senior management and local NCA-facing teams on the H2 2026 to H1 2027 CSA window and agree ownership for rapid response to supervisory questionnaires or onsite reviews.
Timeline
publication
Jul 8, 2026
ESMA published the CSA announcement on CASPs’ digital operational resilience for custody.
implementation
Date not specified
NCAs are scheduled to begin the CSA on a risk-based sample of authorised CASPs.
implementation
Date not specified
The CSA exercise is scheduled to run through the first half of 2027.
other
Date not specified
Findings collected from NCAs are expected to be consolidated into a final report for submission to ESMA’s Board of Supervisors following conclusion of the exercise.
Sources
AI-generated analysis is based on the following primary sources. Always verify against the official publication.
- News / CSA announcementEuropean Securities and Markets AuthorityJul 8, 2026ESMA launches Common Supervisory Action on CASPs’ digital operational resilience for custody ↗
https://www.esma.europa.eu/press-news/esma-news/esma-launches-common-supervisory-action-casps-digital-operational-resilience
- RegulationEUR-Lex / Official Journal of the European UnionDec 27, 2022Regulation (EU) 2022/2554 on digital operational resilience for the financial sector ↗
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R2554
- RegulationEUR-Lex / Official Journal of the European UnionJun 9, 2023Regulation (EU) 2023/1114 on markets in crypto-assets ↗
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32023R1114
Related Evidence
Verified source support for this analysis
The evidence agent checks whether the drafted finding is supported by official publications and relevant public source material.
Receive updates like this by email
Get AI-generated analysis for the regulators and topics you care about.