CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

ESMA Launches Supervisory Action on CASP Custody Resilience

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING ESMA Launches Supervisory Action onCASP Custody Resilience

The European Securities and Markets Authority has confirmed it is launching a Common Supervisory Action targeting the digital operational resilience of crypto-asset service providers, with a specific focus on custody activities. For accounting firms advising licensed CASPs, internal audit teams, and CFOs responsible for digital asset operations, this is not a consultation to watch from a distance. National Competent Authorities will begin examining a risk-based sample of authorised CASPs in the second half of 2026, and findings will feed into a final report to ESMA's Board of Supervisors in the second half of 2027. If your clients or your own firm hold or service digital assets in custody, the clock has already started. Firms that rely on robust crypto accounting software and integrated compliance frameworks will be better positioned when examiners arrive.

ESMA Launches Supervisory Action on CASP Custody Resilience

What the Common Supervisory Action Covers

A Common Supervisory Action is a coordinated examination exercise in which ESMA works alongside National Competent Authorities across EU member states to apply consistent supervisory standards to a defined population of regulated entities. The approach ensures that a firm authorised in, say, France faces the same scrutiny as one authorised in Germany or the Netherlands, reducing regulatory arbitrage and lifting the floor for the entire sector.

This particular CSA is directed at CASPs' digital operational resilience frameworks as they relate to custody. ESMA has identified both digital operational resilience and the CASP sector itself as priority risk areas in its supervisory agenda, and this action operationalises that concern.

Six Risk Dimensions Under Examination

ESMA's announcement sets out the specific areas NCAs will probe. Each represents a distinct risk category that firms need to assess internally before an examiner does it for them.

  • Governance arrangements: How are decisions made around custody infrastructure? Who is accountable, and is that accountability documented at board level?
  • Key and storage management: How are private keys generated, stored, backed up, and rotated? Are hardware security modules or equivalent controls in place?
  • Transaction controls: What pre- and post-trade controls exist to detect and prevent unauthorised or erroneous transactions involving custodied assets?
  • Incident detection and response: Does the firm have real-time monitoring, defined escalation paths, and tested recovery procedures for custody-related incidents?
  • Smart contract risks: Where custody infrastructure involves smart contracts, are those contracts audited, version-controlled, and subject to ongoing vulnerability assessment?
  • Third-party provider dependencies: Are material dependencies on cloud providers, node operators, or technology vendors mapped, contracted, and tested for concentration risk?

Each of these dimensions maps directly onto the Digital Operational Resilience Act (DORA), which imposes binding requirements on financial entities, including CASPs, across the EU. The CSA effectively cross-references MiCA's custody obligations with DORA's operational resilience standards, creating a layered compliance picture.

Timeline and Process

How the Exercise Will Run

The exercise spans roughly twelve months of active supervisory work. NCAs will select their samples on a risk basis, meaning larger custodians, those with more complex DLT architectures, or those with prior supervisory findings are more likely to be selected. The selection is not random, and firms should not assume that a clean licensing record exempts them.

Once selected, a firm should expect document requests, interviews with technical and governance staff, and possibly on-site or virtual inspections. NCAs will then report their findings back to ESMA, which will consolidate them into a final report for the Board of Supervisors. That report, expected in the second half of 2027, will almost certainly inform follow-on supervisory guidance, potential Q&A updates, or targeted rule-making under MiCA's delegated acts.

What Happens After the Report

CSA final reports have historically triggered sector-wide supervisory letters, thematic guidance, or direct follow-up actions against firms that fell short. The 2027 report will land at a point when MiCA's full supervisory architecture is still bedding in, which means its findings could shape how NCAs apply custody requirements for years to come. Accounting firms advising CASPs should track the report's publication and be prepared to update client advice accordingly.

Why Custody Is the Focus

Custody is the highest-risk activity a CASP can perform. A firm that trades crypto on behalf of clients can cause financial harm if it executes poorly. A firm that custodies client assets can cause catastrophic, potentially irreversible harm if its key management fails, its smart contracts are exploited, or a critical third-party provider goes offline without adequate fallback. ESMA's decision to anchor this CSA in custody reflects the asymmetric risk profile of the activity.

Distributed ledger technology introduces risks that have no direct analogue in traditional securities custody. There is no central registrar to reverse an erroneous transaction. Private key compromise is permanent. Smart contract bugs can be exploited within seconds of deployment. These characteristics mean that the governance and technical controls that suffice for a traditional custodian are often structurally inadequate for a DLT-based one, and ESMA is testing whether the authorised CASP population has genuinely adapted to that reality.

Accounting and Audit Implications

For Accounting Firms and External Auditors

External auditors of CASPs need to understand that the CSA findings will directly affect their risk assessments. If an NCA identifies material weaknesses in a client's key management or incident response capability, those weaknesses are relevant to the auditor's going-concern assessment, to the evaluation of internal controls over financial reporting, and to the completeness of asset disclosures. Audit teams that have not yet built DLT-specific procedures into their custody testing programs are exposed.

There is also a practical documentation angle. Auditors routinely request evidence of asset existence and completeness for custody holdings. A CASP that cannot demonstrate clean key management controls or that relies on undocumented third-party infrastructure will struggle to provide audit-ready evidence. Firms offering digital asset accounting software or advisory services to CASPs should be stress-testing their clients' documentation now, before NCAs do it instead.

The Belgium FSMA flags six unauthorized CASPs after MiCA deadline case illustrates how quickly supervisory pressure can escalate once an authority identifies compliance gaps. Firms that treat MiCA licensing as a one-time event rather than a continuous compliance obligation are misjudging the regulatory trajectory.

For CFOs and Finance Teams at CASPs

CFOs at authorised CASPs carry direct accountability for the financial integrity of custody operations. The six risk dimensions ESMA has flagged are not purely technical; they have direct financial reporting consequences. Third-party concentration risk, for instance, is a disclosure item under IFRS 7 and under MiCA's own reporting obligations. Incident detection and response failures that result in asset loss trigger immediate questions about asset write-downs, insurance recoverability, and client liability.

Finance teams should be working with their technology and compliance counterparts now to produce an internal gap assessment across the six dimensions. That assessment should be documented, signed off by the board, and retained as evidence of proactive compliance. When an NCA arrives, demonstrating that the firm self-identified and addressed gaps is materially better than having the examiner find them first.

Firms that have implemented integrated crypto bookkeeping software with real-time custody reconciliation will have a natural advantage: they can pull transaction-level evidence quickly and demonstrate that their controls are operational rather than theoretical. This is also the moment to review whether any disclosures in the most recent financial statements adequately reflect the custody risk environment described in ESMA's announcement.

Supervisory Convergence and the Broader MiCA Context

This CSA does not sit in isolation. It is part of ESMA's broader effort to build supervisory convergence across the EU's 27 national regulators as MiCA's full framework takes effect. Earlier enforcement actions, such as the situations covered in what the AMF's new supervisory role means for accounting firms and CFOs, show that NCAs are moving from a transitional, registration-focused mode into active, thematic supervision.

The CSA model is specifically designed to prevent a race to the bottom, where CASPs seek authorisation from the most lenient NCA and then passport across the EU. By requiring all NCAs to apply the same examination framework simultaneously, ESMA creates a consistent standard of evidence. The consolidated report then feeds back into that standard, tightening it further over time.

For accounting professionals, the practical takeaway is that supervisory expectations for CASPs are converging upward, not settling at a minimum. Firms whose compliance programs were designed to meet the bare minimum at authorisation will face increasing pressure as CSA findings set new de facto benchmarks.

Practical Steps for Firms Right Now

Immediate Actions Before H2 2026

The second half of 2026 is not far away. Firms with custody operations or clients with custody operations should be taking the following steps without delay.

  • Map all third-party providers involved in custody infrastructure, including cloud, node, and key management vendors, and document the contractual and operational resilience provisions for each.
  • Review board-level governance documentation to confirm that custody risk ownership is explicitly assigned and that escalation procedures are formally approved.
  • Test incident response procedures specifically for custody scenarios, including key compromise, smart contract exploit, and third-party outage.
  • Commission or review existing audits of any smart contracts used in custody operations, and ensure version control and change management records are complete.
  • Assess whether current crypto accounting software or bookkeeping systems can produce on-demand reconciliation reports for custodied assets that would satisfy an NCA document request.
  • Review financial statement disclosures for adequacy in light of the risk dimensions ESMA has identified, particularly around third-party concentration and operational incident history.
ESMA Launches Supervisory Action on CASP Custody Resilience

Frequently Asked Questions

Which CASPs will be examined in this CSA?

NCAs will select a risk-based sample of CASPs that are authorised in their jurisdiction and carry out custody activities. ESMA has not published a specific selection methodology, but risk-based sampling typically prioritises larger firms, those with more complex operations, or those with prior supervisory findings. There is no published list of selected firms.

Does this apply to CASPs that only trade and do not custody?

The CSA's stated focus is on custody services. CASPs that do not hold client assets in custody are less likely to be in scope for this specific action, but they remain subject to DORA's broader operational resilience requirements and to other supervisory priorities ESMA has identified.

How does this CSA relate to DORA?

DORA applies to financial entities in the EU, including CASPs, and sets binding requirements for ICT risk management, incident reporting, operational resilience testing, and third-party risk management. The CSA assesses how well CASPs have implemented those standards specifically in their custody operations, so the two frameworks are directly complementary.

When will the final report be published?

ESMA has indicated that findings will be consolidated and submitted to its Board of Supervisors in the second half of 2027, following the conclusion of the examination phase in the first half of 2027. Public release timelines for CSA final reports vary, but they are typically published after the Board of Supervisors has reviewed them.

What should an accounting firm do if a CASP client is selected for examination?

Firms should help the client organise documentation across the six risk dimensions ESMA has identified, coordinate between the client's legal, compliance, and technology teams, and ensure that financial statement disclosures are consistent with the information provided to the NCA. Discrepancies between regulatory submissions and audited accounts create significant credibility risk.

Source: European Securities and Markets Authority (ESMA)

EUGeneralAdoptedAML/KYC & Licensing

Related articles

AML/KYC & Licensing
Digital Sovereignty Is Now a Board-Level Risk: What DORA and the ECB Mean for Crypto Accounting Software
AML/KYC & Licensing
Four Financial Centres Racing to Lead on Crypto Regulation
AML/KYC & Licensing
EU Tightens Cross-Border VAT Fraud Data-Sharing: What ECOFIN's Agreement Means for Firms
AML/KYC & Licensing
Continuous Monitoring: Why a Cleared Crypto Screening Can Become a Liability