ESMA Launches Supervisory Review of CASP Custody Resilience Across EU
Key points
- ESMA has launched a Common Supervisory Action assessing digital operational resilience of crypto-asset service providers, concentrating on custody services, to run from the second half of 2026 to the first half of 2027.
- National competent authorities will examine a risk-based sample of authorised CASPs, focusing on governance, key and storage management, transaction controls, incident detection and response, smart contract risks, and third-party dependencies.
- The initiative addresses ESMA's risk-based supervisory priorities, which identify both digital operational resilience and CASPs as key areas of concern in a rapidly evolving market segment.
- A consolidated report summarising findings will be submitted to ESMA's Board of Supervisors in the second half of 2027, following the conclusion of the exercise.
- The exercise aims to enhance supervisory convergence across EU member states, signalling an impending harmonisation of operational expectations for CASP custody functions.
The European Securities and Markets Authority has initiated a Common Supervisory Action examining the digital operational resilience of crypto-asset service providers, with custody functions as the focal point. National competent authorities will assess a risk-based sample of authorised CASPs from the second half of 2026 through the first half of 2027, probing governance, key management, transaction controls, incident response, smart contract exposure, and third-party dependencies tied to distributed ledger technology.
The exercise reflects ESMA’s stated supervisory priorities, which flag both operational resilience and CASPs as heightened risk areas. By running a co-ordinated review across member states, the regulator aims to establish convergent expectations in a segment where practices remain uneven. Findings will be consolidated into a report for ESMA’s Board of Supervisors in the second half of 2027.
This is a supervisory stock-take rather than a rulemaking consultation. CASPs in scope should treat the timeline as a near-term deadline to document frameworks and surface gaps before national authorities arrive. For infrastructure providers and allocators relying on CASP custody, the review signals an impending tightening of operational standards that may alter counterparty risk profiles within the next eighteen months.