ESMA launched a Common Supervisory Action focused on the digital operational resilience of crypto-asset service providers in relation to custody. National competent authorities will review a risk-based sample of authorised CASPs from the second half of 2026 to the first half of 2027. ESMA says the work will look at DLT governance, key and storage management, transaction controls, incident detection, smart contract risks and third-party dependencies.
The important part is that MiCA oversight is moving from licensing into operational testing. A CASP can be authorised and still have weak custody procedures, poor incident response or concentrated vendor risk.
The second-order effect is market pressure: smaller platforms may find that compliance costs now move from paperwork to technical resilience.
Next, watch whether the review leads to guidance, enforcement or stricter custody expectations.
