Photo: Julio Lopez / Pexels
ESMA expands cyber resilience checks to crypto-asset service providers in 2027
Europe's securities watchdog launches coordinated supervisory action targeting custody-focused crypto firms just days after MiCA's transitional period expired
One week after the final deadline for crypto firms to get licensed under Europe’s landmark regulatory framework, the continent’s top securities regulator is already moving to phase two: making sure those licenses actually mean something.
The European Securities and Markets Authority (ESMA) announced on July 8 that it has launched a Common Supervisory Action (CSA) focused on the digital operational resilience of authorized Crypto-Asset Service Providers (CASPs) that offer custody services. The reviews will run from the second half of 2026 through the first half of 2027, with a consolidated report expected for ESMA’s Board of Supervisors in the latter half of 2027.
From licensing to enforcement
The timing is not accidental. MiCA’s transitional period ended on July 1, 2026, meaning every crypto firm operating in the EU now needs proper authorization. Roughly 280 to 283 CASPs currently hold that authorization, a meaningful jump from the 243 that had secured licenses before the deadline.
The scope of the review covers governance frameworks, cryptographic key management, transaction controls, incident detection and response, smart contract risks, and reliance on third-party providers. National competent authorities across EU member states will conduct the reviews on a risk-based basis.
DORA meets MiCA
The CSA draws on two major pieces of European regulation. The primary framework is MiCA itself, which establishes the licensing and conduct requirements for crypto firms. But the action also aligns with the Digital Operational Resilience Act (DORA), which sets broader standards for how financial entities manage ICT risk, cybersecurity, and operational continuity.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
ESMA has also previously issued warnings to unauthorized entities operating in the EU without proper licensing. The CSA mechanism coordinates national regulators across EU member states to examine a specific topic simultaneously, creating a unified picture of how an industry segment is performing against regulatory expectations.
The consolidated report, expected in the second half of 2027, will be worth watching closely. If ESMA finds systemic issues with key management or third-party dependencies, it could trigger additional rulemaking that raises compliance costs further.
The gap between MiCA’s transitional deadline and the launch of this CSA was exactly one week.