Skip to main content

Crypto Custody Under the European Microscope

What the ESMA CSA Means for Banks and Financial Services Firms

European supervision is intensifying its focus on CASPs. With a coordinated Common Supervisory Action (CSA), ESMA is — for the first time — directing its attention specifically at the digital operational resilience of crypto custodians. This is a signal that banks and financial services firms with crypto activities cannot afford to ignore.

Background: What Is a Common Supervisory Action?

A Common Supervisory Action (CSA) is a coordinated supervisory instrument used by the European Securities and Markets Authority (ESMA), whereby national competent authorities (NCAs) simultaneously examine specific market participants against agreed criteria. The aim is to promote consistent supervisory practices across the EU and to drive regulatory convergence.

This CSA is the first coordinated European supervisory initiative focused specifically on the digital operational resilience of CASPs in the area of crypto custody. It provides concrete indications of the aspects that national supervisors will scrutinise with increasing rigour, and the expectations they hold regarding governance, security controls, and custody processes.

For affected institutions, this is far more than an abstract regulatory exercise: over 280 authorised CASPs now fall within the European supervisory framework and are therefore directly in the crosshairs of this convergence effort.

Timeline: When and How Will the CSA Unfold?

The selection of CASPs to be examined will be conducted on a risk-based basis by the national competent authorities. The timeline is clearly defined:

  • The CSA will be carried out across member states from H2 2026 to H1 2027.
  • ESMA will subsequently consolidate the findings to promote consistent supervisory practice across the EU.
  • A final report to the ESMA Board of Supervisors is expected in H2 2027.
  • The resulting common supervisory practice is expected to shape future national examinations significantly.

For affected institutions, the message is clear: the window for preparation is narrow. Those who fail to act now risk being caught unprepared when a review arrives.

The Six Areas of Focus in Detail

The CSA covers six clearly defined focus areas for supervisory review, addressing the key elements of operational and technical security in crypto custody. The following topics are highly likely to be subject to regulatory scrutiny:

1. Governance Arrangements

The focus lies on board-level responsibilities and competencies for crypto custody and ICT, the three-lines-of-defence model, the integration of DLT risks into ICT risk strategy and ICT risk management frameworks, and outsourcing governance. Supervisors will assess whether crypto risks are embedded at board level and sufficiently integrated into existing frameworks.

2. Key and Storage Management

Under examination are the secure generation, rotation, and destruction of cryptographic keys; the cryptographic parameters and algorithms in use (e.g. curves, signature schemes); MPC architecture; HSM storage; backup and recovery procedures; access and administration concepts (in particular quorums); and physical security mechanisms. This is the technical core of custody operations — an area where weaknesses can directly result in asset losses.

3. Transaction Controls

Supervisors will scrutinise whitelisting, limits, authorisation concepts and workflows, audit trails, protection against address poisoning and blind signing, reconciliation of on-chain and book positions, evidence of segregation of client and proprietary assets in accordance with Articles 70 and 75 MiCAR, and anti-money laundering and sanctions management. The explicit reference to MiCAR makes clear that the CSA operationalises the requirements of the new EU crypto framework.

4. Incident Detection and Response

The assessment will cover logging and monitoring, severity classification, reporting channels and timelines in accordance with DORA Articles 17–19, crisis and contingency exercises, and post-incident reviews. Institutions that have already implemented DORA should be familiar with these requirements — but the CSA will specifically test whether implementation is functioning effectively in the crypto context.

5. Smart Contract Risks

The focus here is on audits prior to deployment, upgradeability and admin keys, bridge and staking/delegation risks, and the handling of chain reorganisations and forks. This area is of particular relevance for institutions integrating DeFi elements into their custody infrastructure.

6. Third-Party Dependencies

Supervisors will examine sub-service providers and third-party custodians, wallet technology vendors, cloud and node providers, DORA-compliant contractual clauses, the information register, and concentration and exit strategies. Dependency on external technology providers is one of the most critical vulnerabilities in modern crypto infrastructure.

What Does This Mean in Practice for Banks and Financial Services Firms?

The CSA is not an isolated event. A common supervisory practice is expected to be established across the EU, which will materially shape future national examinations. Institutions offering or developing crypto custody services should draw the following conclusions:

Compliance gaps will be exposed. The granular depth of the CSA's review — ranging from cryptographic key management to DORA-compliant third-party governance — will reveal where operational weaknesses exist. It is far better to identify these internally before the supervisor does.

MiCAR and DORA are interconnected. The thematic focus areas make clear that treating these two regulatory frameworks in isolation is insufficient. CASPs must implement both in an integrated and operationally robust manner.

Governance is a leadership responsibility. The explicit examination of board-level accountability for crypto and ICT risks signals that supervisors do not view crypto custody as a purely technical matter, but as a strategic leadership challenge.

Time is pressing. The CSA runs from H2 2026 to H1 2027. Institutions that have not yet begun preparing should do so without delay.

How Well Prepared Are You?

CASPs have an opportunity to identify potential weaknesses at an early stage and to demonstrate supervisory and market-facing readiness. A structured preparation approach typically includes:

  • A CSA Readiness Assessment to identify regulatory and operational gaps against ESMA's expectations
  • A Mock Regulatory Inspection that simulates the supervisory perspective and surfaces weaknesses before they are identified externally
  • Independent assurance services covering selected resilience and control areas — particularly where third parties or complex technical infrastructure are involved
  • A structured remediation process for findings, whether arising from a completed examination or from gaps identified during the readiness assessment

Conclusion

The ESMA CSA on the digital operational resilience of CASPs marks a turning point in European crypto supervision. It makes abundantly clear that the regulation of crypto activities is no longer a theoretical construct — it is being tested rigorously in practice, with concrete thematic priorities, a consistent supervisory standard, and direct consequences for affected institutions. Banks and financial services firms offering crypto custody would be well advised to use the remaining time before H2 2026 to conduct a thorough and honest stocktake of their preparedness.

 

The flyer below provides an overview of the key points.

For questions on CSA preparation and regulatory requirements, please do not hesitate to get in touch.

Flyer: the EU, and national regulators launch a Common Supervisory Action targeting CASPs

Did you find this useful?

Thanks for your feedback

Insights and Further Information