The supervisory action will assess how mature CASPs’ digital operational resilience frameworks are, with emphasis on risks inherent to distributed ledger technology (DLT). Regulators will examine governance arrangements, key and storage management, transaction controls, incident detection and response protocols, smart contract risks, and dependencies on third-party providers.
National Competent Authorities (NCAs) across EU member states will carry out the exercise on a risk-based sample of authorized CASPs. The approach focuses on the most systemically important providers and those with elevated risk profiles. ESMA will use findings to assess whether current safeguards adequately protect crypto assets held in custody.
The supervisory action responds to ESMA’s broader risk-based supervisory priorities, which identify both digital operational resilience and the CASP sector as key areas of concern. The timing—spanning from the second half of 2026 through the first half of 2027—allows regulators to conduct thorough on-site and document reviews across the EU’s CASP landscape.
Custody is foundational to the crypto-asset ecosystem. Operational failures—whether from key mismanagement, smart contract vulnerabilities, inadequate incident response, or third-party dependencies—can result in irreversible asset loss. ESMA’s focus on custody-specific resilience reflects the systemic importance of these services and the speed at which DLT-related incidents cascade.
Following fieldwork, ESMA will consolidate findings into a final report to its Board of Supervisors in the second half of 2027. The outcome is likely to inform future rulemaking on custody standards, potentially tightening requirements for key management, governance, and incident response across the EU.
What this means for crypto-card users
Crypto-card providers rely on third-party custodians to hold underlying assets. This supervisory action may accelerate adoption of higher security standards at those custodians, reducing operational disruption or asset-loss risks that could affect card functionality. Tighter compliance costs may increase custody fees downstream, though regulators typically expect providers to absorb these expenses. Users should verify which custodian their card provider uses and confirm participation in this audit; transparency here signals regulatory alignment. For EU users, this action demonstrates regulatory commitment to asset safety, though new rules may take years to finalize.