FF News — The Fintech News Network

ESMA Launches Common Supervisory Action on CASP Digital Resilience and Custody

By Lauren Towner · 10 July 2026

Press Release: ESMA Launches Common Supervisory Action on CASP Digital Resilience and Custody | Featured Image by FF News

Quick Summary

The European Securities and Markets Authority (ESMA) has initiated a Common Supervisory Action (CSA) targeting the digital operational resilience of Crypto-Asset Service Providers (CASPs). This 2025 initiative ensures firms providing custody services comply with MiCA and DORA standards to protect investor assets and maintain service continuity.

How Will ESMA Assess CASP Digital Resilience?

The Common Supervisory Action will rigorously evaluate the technical arrangements CASPs utilize to safeguard client assets. Regulators are prioritizing operational risk management, specifically focusing on how firms prevent unauthorized access and manage private keys. National Competent Authorities will lead the data collection to ensure that custody service providers maintain high security standards under the new regulatory framework.

  • Asset Safeguarding: Review of internal policies for protecting client funds.
  • Service Continuity: Assessment of disaster recovery and business continuity plans.
  • ICT Risk: Evaluation of third-party dependencies and supply chain security.

What Does This Mean for MiCA and DORA Compliance?

As the Markets in Crypto-Assets (MiCA) regulation takes full effect, ESMA is moving from policy drafting to active supervisory enforcement. Firms must demonstrate digital operational resilience by proving they can withstand, respond to, and recover from ICT-related disruptions. The Digital Operational Resilience Act (DORA) provides the legal backbone for these requirements, mandating strict incident reporting mechanisms and regular stress testing of digital infrastructures.

How Will the CSA Impact the Crypto Market in 2025?

By conducting a coordinated supervisory activity across all EU member states, ESMA aims to eliminate regulatory arbitrage. This ensures that a CASP registered in one jurisdiction meets the same investor protection standards as one in another. The focus on ICT third-party risks means that CASPs will need to audit their cloud providers and software vendors more strictly to remain compliant throughout the 2025 review period.

FF NEWS TAKE:

This move by ESMA signals that the "wild west" era of crypto custody in Europe is officially over. By leveraging the Common Supervisory Action, ESMA is putting CASPs on notice that digital operational resilience is not optional. This is a significant needle-mover for institutional adoption; clear, enforced standards for custody are exactly what traditional finance needs to see before committing more capital to the crypto-asset ecosystem.

Companies in this story: ESMA, European Securities and Markets Authority

More from News