2026-08-06 | C794Added
CySEC informs Crypto Asset Service Providers (CASPs) that the European Securities and Markets Authority (ESMA) has launched a Common Supervisory Action for 2026 with national competent authorities to assess digital operational resilience frameworks for custody activities. The exercise, running from the second half of 2026 to the first half of 2027, targets authorized CASPs providing custody services and focuses on risks related to distributed ledger technology, including governance, key management, transaction controls, incident response, smart contracts, and third-party dependencies. CySEC plans to conduct on-site visits or desk-based reviews on a risk-based sample of these providers to ensure consistency with the supervisory action.
TO : Crypto Asset Service Providers (CASPs) FROM : Cyprus Securities and Exchange Commission DATE : 6 August 2026 CIRCULAR NO. : C794 SUBJECT : ESMA launches a Common Supervisory Action with NCAs on CASPs’ digital operational resilience for custody
The Cyprus Securities and Exchange Commission (“the CySEC”) wishes, with this circular, to inform the Crypto Asset Service Providers (CASPs) that the European Securities and Markets Authority (“ESMA”) has launched a Common Supervisory Action for 2026 (“CSA 2026”) with national competent authorities (“NCAs”) on CASPs’ digital operational resilience for custody.
The CSA will assess the maturity of CASPs’ digital operational resilience frameworks in relation to custody activities. It will focus on risks inherent to distributed ledger technology (DLT), including governance arrangements, key and storage management, transaction controls, incident detection and response, smart contract risks, and dependencies on third-party providers. National Competent Authorities (NCAs) will carry out the exercise on a risk-based sample of authorised CASPs. The exercise will run from the second half of 2026 to the first half of 2027. This initiative responds to ESMA’s risk-based supervisory priorities, which identify both digital operational resilience and CASPs as key areas of risk. ESMA has developed this CSA to enhance supervisory convergence in a rapidly evolving segment of the market.
In the context of the CSA 2026, CySEC is planning to conduct on-site visits and/or desk-based reviews on a sample of CASPs. To ensure a minimum level of consistency in the sample across NCAs, NCAs should select only CASPs that: • have already been authorised and • are authorised to provide custody services (to be consistent with the scope of the CSA described above).
The CSA will focus on the following digital operational resilience risks: