ESMA’s Common Supervisory Action on CASPs
Regulators are moving beyond licensing readiness. CASPs providing custody services should be prepared to demonstratethat governance, ICT controls, key management, incident response and third-party risk arrangements operate effectively in practice.
On 8 July 2026, the European Securities and Markets Authority (ESMA) announced a Common Supervisory Action (CSA) on the digital operational resilience of authorised Crypto-Asset Service Providers (CASPs) providing custody services.
The exercise will be carried out by national competent authorities (NCAs) across the EU during the second half of 2026 and the first half of 2027. It will assess the maturity and effectiveness of CASPs' digital operational resilience arrangements, based on a risk-based sample, with particular focus on operational and technology risks arising from crypto-asset custody activities.
Why this matters
The custody of crypto-assets presents operational and security risks that differ materially from those faced by traditional financial institutions. In particular, the loss, compromise or ineffective control of cryptographic keys may result in irreversible loss of client assets. For this reason, governance, access controls, incident response, recovery arrangements and third-party oversight are now central supervisory concerns.
The CSA coincides with the active enforcement phase of the EU’s Markets in Crypto-Assets (MiCA) regulation, which has expanded the CASP register to over 280 authorised providers.
CASPs under MiCA are also considered financial entities subject to the EU Digital Operational Resilience Act (DORA), which imposes obligations on ICT risk management, incident reporting, resilience testing, and third-party oversight.
The CSA is therefore closely aligned with DORA requirements, providing early supervisory guidance for CASPs on operational resilience expectations.
This is particularly relevant in Cyprus, which has become an active CASP jurisdiction in the EU. A number of CASPs have been authorised relatively recently, meaning that many firms may now be moving from the licensing phase into the more demanding phase of demonstrating operational implementation and supervisory readiness.
Focus areas
The CSA will evaluate thematurity of CASPs’ digital operational resilience frameworksin relation to custody activities.
Key areas of assessment include:
- Governancearrangementsfordigitaloperations.
- Key management and storage for crypto assets.
- Transactioncontrolsandmonitoring.
- Incidentdetectionandresponsemechanisms.
- Smartcontractrisks.
- Dependencies on third-party providers. The review specifically targets risks inherent todistributed ledger technology (DLT)used in custody services, ensuring that CASPs maintain robust controls to protect client assets.
The CSA represents ESMA’s first structured assessment of CASP custody resilience since the end of the MiCA transitional period, providing a benchmark for operational standards across the EU crypto market.
Implications for CASPs
CASPs providing custody services should not treat the CSA as a document review exercise. Supervisors are likely to expect evidence that controls operate in practice, not simply that policies exist.
Review and strengthen their digital operational resilience frameworks.
Ensure compliance with DORA and MiCA obligations.
Prepare for potential NCA engagementduring the CSA period.
Monitor findings as indicators of future supervisory expectations, including potential relevance for non-EU jurisdictions like the UK.
KPMG can support CASPs. Through our network, we have visibility of supervisory approaches and market practice across EU jurisdictions, allowing us to provide a practical review that goes beyond a generic compliance checklist.
Our people
Gerasimos Ntouskas
Board Member | Head of Technology Consulting | Chief Digital Officer
KPMG in Cyprus