Skip to main content

Loading

Please wait a moment

Page is Loading...


      ESMA’s Common Supervisory Action on CASPs

      Regulators are moving beyond licensing readiness. CASPs providing custody services should be prepared to demonstratethat governance, ICT controls, key management, incident response and third-party risk arrangements operate effectively in practice.

      On 8 July 2026, the European Securities and Markets Authority (ESMA) announced a Common Supervisory Action (CSA) on the digital operational resilience of authorised Crypto-Asset Service Providers (CASPs) providing custody services.

      The exercise will be carried out by national competent authorities (NCAs) across the EU during the second half of 2026 and the first half of 2027. It will assess the maturity and effectiveness of CASPs' digital operational resilience arrangements, based on a risk-based sample, with particular focus on operational and technology risks arising from crypto-asset custody activities.

       

      Why this matters

      The custody of crypto-assets presents operational and security risks that differ materially from those faced by traditional financial institutions. In particular, the loss, compromise or ineffective control of cryptographic keys may result in irreversible loss of client assets. For this reason, governance, access controls, incident response, recovery arrangements and third-party oversight are now central supervisory concerns.

      The CSA coincides with the active enforcement phase of the EU’s Markets in Crypto-Assets (MiCA) regulation, which has expanded the CASP register to over 280 authorised providers.

      CASPs under MiCA are also considered financial entities subject to the EU Digital Operational Resilience Act (DORA), which imposes obligations on ICT risk management, incident reporting, resilience testing, and third-party oversight.

      The CSA is therefore closely aligned with DORA requirements, providing early supervisory guidance for CASPs on operational resilience expectations.

      This is particularly relevant in Cyprus, which has become an active CASP jurisdiction in the EU. A number of CASPs have been authorised relatively recently, meaning that many firms may now be moving from the licensing phase into the more demanding phase of demonstrating operational implementation and supervisory readiness.

       

      Focus areas

      The CSA will evaluate thematurity of CASPs’ digital operational resilience frameworksin relation to custody activities.

       

      Key areas of assessment include:

      •  Governancearrangementsfordigitaloperations.
      • Key management and storage for crypto assets.
      • Transactioncontrolsandmonitoring.
      • Incidentdetectionandresponsemechanisms.
      • Smartcontractrisks.
      • Dependencies on third-party providers. The review specifically targets risks inherent todistributed ledger technology (DLT)used in custody services, ensuring that CASPs maintain robust controls to protect client assets.

       

      The CSA represents ESMA’s first structured assessment of CASP custody resilience since the end of the MiCA transitional period, providing a benchmark for operational standards across the EU crypto market.

      Implications for CASPs

      CASPs providing custody services should not treat the CSA as a document review exercise. Supervisors are likely to expect evidence that controls operate in practice, not simply that policies exist.

      Review and strengthen their digital operational resilience frameworks.

      Ensure compliance with DORA and MiCA obligations.

      Prepare for potential NCA engagementduring the CSA period.

      Monitor findings as indicators of future supervisory expectations, including potential relevance for non-EU jurisdictions like the UK.

      KPMG can support CASPs. Through our network, we have visibility of supervisory approaches and market practice across EU jurisdictions, allowing us to provide a practical review that goes beyond a generic compliance checklist.

      best execution

      ESMA’s Common Supervisory Action on CASPs

      Read our alert


      Our people

      Marios Lazarou

      Board Member, Head of Advisory

      KPMG in Cyprus

      Marie-Helene Angelides

      Senior Associate

      KPMG in Cyprus

      Christoforos Evlavis

      Board Member

      KPMG in Cyprus


      Gerasimos Ntouskas

      Board Member | Head of Technology Consulting | Chief Digital Officer

      KPMG in Cyprus

      Chloe Karacosta

      Senior Manager, Risk Consulting

      KPMG in Cyprus