European supervision is intensifying its focus on CASPs. For the first time. a coordinated Common Supervisory Action (CSA), announced by ESMA, is focused specifically at the digital operational resilience of crypto custodians. This is a signal that banks and financial services firms with crypto activities should not ignore.
A Common Supervisory Action is a coordinated supervisory instrument used by the European Securities and Markets Authority (ESMA), whereby National Competent Authorities (NCAs) simultaneously examine specific market participants against agreed criteria. The aim is to promote consistent supervisory practices across the EU and to drive regulatory convergence.
This CSA is the first coordinated European supervisory initiative focused specifically on the digital operational resilience of crypto custodians. It provides concrete indications of the aspects that national supervisors will scrutinise with increasing rigour, and the expectations they hold regarding governance, security controls, and custody processes.
More than 280 authorised CASPs are now covered by MiCAR and are therefore directly in the focus of this convergence effort.
The selection of CASPs to be examined will be conducted on a risk-based basis by the NCA according to the following timeline:
For affected institutions, the message is clear: timely action is therefore recommended for CASPs.
The CSA covers six clearly defined focus areas for supervisory review, addressing the key elements of operational and technical security in crypto custody. The following topics are expected to be subject to regulatory scrutiny:
1. Governance Arrangements
The focus lies on board-level responsibilities and competencies for crypto custody and ICT, the three-lines-of-defence model, the integration of DLT risks into ICT risk strategy and ICT risk management frameworks, and outsourcing governance. Supervisors will assess whether crypto risks are embedded at board level and sufficiently integrated into existing frameworks.
2. Key and Storage Management
Under examination are the secure generation, rotation, and destruction of cryptographic keys; the cryptographic parameters and algorithms in use (e.g. curves, signature schemes); MPC architecture; HSM storage; backup and recovery procedures; access and administration concepts (in particular quorums); and physical security mechanisms. This is the Achilles' heel of crypto custody - an area where weaknesses can directly result in asset losses.
3. Transaction Controls
Supervisors will scrutinise whitelisting, limits, authorisation concepts and workflows, audit trails, protection against address poisoning and blind signing, reconciliation of on-chain and book positions, evidence of segregation of client and proprietary assets in accordance with Articles 70 and 75 MiCAR, and anti-money laundering and sanctions management. The explicit reference to MiCAR makes clear that the CSA operationalises the requirements of the new EU crypto framework.
4. Incident Detection and Response
The assessment will cover logging and monitoring, severity classification, reporting channels and timelines in accordance with Articles 17 - 19 DORA, crisis and contingency exercises, and post-incident reviews. Institutions that have already implemented DORA should be familiar with these requirements. But theCSA will specifically test whether implementation is functioning effectively in the crypto context.
5. Smart Contract Risks
Another area of supervisory focus could be audits prior to deployment, upgradeability and admin keys, bridge and staking/delegation risks, and the handling of chain reorganisations and forks. This area is of particular relevance for institutions integrating DeFi elements into their custody infrastructure.
6. Third-Party Dependencies
Supervisors will examine sub-service providers and third-party custodians, wallet technology vendors, cloud and node providers, DORA-compliant contractual clauses, the information register, and concentration and exit strategies. Dependency on external technology providers is one of the most critical vulnerabilities in modern crypto infrastructure.
The CSA is not an isolated event. A common supervisory practice is expected to be established across the EU, which will materially shape future national examinations. Institutions offering or developing crypto custody services should draw the following conclusions:
Compliance gaps will be exposed. The granular depth of the CSA's review (ranging from cryptographic key management to DORA-compliant third-party governance) will reveal where operational weaknesses exist. It is far better to identify these internally before the supervisor does.
MiCAR and DORA are interconnected. The thematic focus areas make clear that treating these two regulatory frameworks in isolation is insufficient. CASPs must implement both in an integrated and operationally robust manner.
Governance should be ensured by the management of the CASP. The explicit examination of board-level accountability for crypto and ICT risks signals that supervisors do not categorita crypto custody as a purely technical matter, but as a strategic leadership challenge.
Time is pressing. The CSA runs from H2 2026 to H1 2027. Institutions that have not yet begun preparing should do so without delay.
CASPs have an opportunity to identify potential weaknesses at an early stage and to demonstrate supervisory and market-facing readiness. A structured preparation approach typically includes:
The ESMA CSA on the digital operational resilience of CASPs marks a milestone in European crypto supervision. It makes abundantly clear that the regulation of crypto activities is no longer a theoretical construct. It is being tested rigorously in practice. Crypto custodians should act in a timely manner to be prepared for the CSA.
The flyer below provides an overview of the key points.
For questions on CSA preparation and regulatory requirements, please do not hesitate to get in touch.