ESMA expands cyber resilience checks to crypto-asset service providers in 2027

Photo: Julio Lopez / Pexels

ESMA expands cyber resilience checks to crypto-asset service providers in 2027

Europe's securities watchdog launches coordinated supervisory action targeting custody-focused crypto firms just days after MiCA's transitional period expired

One week after the final deadline for crypto firms to get licensed under Europe’s landmark regulatory framework, the continent’s top securities regulator is already moving to phase two: making sure those licenses actually mean something.

The European Securities and Markets Authority (ESMA) announced on July 8 that it has launched a Common Supervisory Action (CSA) focused on the digital operational resilience of authorized Crypto-Asset Service Providers (CASPs) that offer custody services. The reviews will run from the second half of 2026 through the first half of 2027, with a consolidated report expected for ESMA’s Board of Supervisors in the latter half of 2027.

From licensing to enforcement

The timing is not accidental. MiCA’s transitional period ended on July 1, 2026, meaning every crypto firm operating in the EU now needs proper authorization. Roughly 280 to 283 CASPs currently hold that authorization, a meaningful jump from the 243 that had secured licenses before the deadline.

Advertisement

The scope of the review covers governance frameworks, cryptographic key management, transaction controls, incident detection and response, smart contract risks, and reliance on third-party providers. National competent authorities across EU member states will conduct the reviews on a risk-based basis.

DORA meets MiCA

The CSA draws on two major pieces of European regulation. The primary framework is MiCA itself, which establishes the licensing and conduct requirements for crypto firms. But the action also aligns with the Digital Operational Resilience Act (DORA), which sets broader standards for how financial entities manage ICT risk, cybersecurity, and operational continuity.

ESMA has also previously issued warnings to unauthorized entities operating in the EU without proper licensing. The CSA mechanism coordinates national regulators across EU member states to examine a specific topic simultaneously, creating a unified picture of how an industry segment is performing against regulatory expectations.

The consolidated report, expected in the second half of 2027, will be worth watching closely. If ESMA finds systemic issues with key management or third-party dependencies, it could trigger additional rulemaking that raises compliance costs further.

The gap between MiCA’s transitional deadline and the launch of this CSA was exactly one week.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
ESMA expands cyber resilience checks to crypto-asset service providers in 2027
ESMA expands cyber resilience checks to crypto-asset service providers in 2027

Europe's securities watchdog launches coordinated supervisory action targeting custody-focused crypto firms just days after MiCA's transitional period expired

Photo: Julio Lopez / Pexels

One week after the final deadline for crypto firms to get licensed under Europe’s landmark regulatory framework, the continent’s top securities regulator is already moving to phase two: making sure those licenses actually mean something.

The European Securities and Markets Authority (ESMA) announced on July 8 that it has launched a Common Supervisory Action (CSA) focused on the digital operational resilience of authorized Crypto-Asset Service Providers (CASPs) that offer custody services. The reviews will run from the second half of 2026 through the first half of 2027, with a consolidated report expected for ESMA’s Board of Supervisors in the latter half of 2027.

From licensing to enforcement

The timing is not accidental. MiCA’s transitional period ended on July 1, 2026, meaning every crypto firm operating in the EU now needs proper authorization. Roughly 280 to 283 CASPs currently hold that authorization, a meaningful jump from the 243 that had secured licenses before the deadline.

Advertisement

The scope of the review covers governance frameworks, cryptographic key management, transaction controls, incident detection and response, smart contract risks, and reliance on third-party providers. National competent authorities across EU member states will conduct the reviews on a risk-based basis.

DORA meets MiCA

The CSA draws on two major pieces of European regulation. The primary framework is MiCA itself, which establishes the licensing and conduct requirements for crypto firms. But the action also aligns with the Digital Operational Resilience Act (DORA), which sets broader standards for how financial entities manage ICT risk, cybersecurity, and operational continuity.

ESMA has also previously issued warnings to unauthorized entities operating in the EU without proper licensing. The CSA mechanism coordinates national regulators across EU member states to examine a specific topic simultaneously, creating a unified picture of how an industry segment is performing against regulatory expectations.

The consolidated report, expected in the second half of 2027, will be worth watching closely. If ESMA finds systemic issues with key management or third-party dependencies, it could trigger additional rulemaking that raises compliance costs further.

The gap between MiCA’s transitional deadline and the launch of this CSA was exactly one week.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.