Skip to content
Skip article header Engineering

ESMA Common Supervisory Action on Custody: How CASPs Prepare

ESMA's 8 July 2026 Common Supervisory Action on custody, the six focus areas ESMA itself named, the DORA read-across, attributed commentary from Latham & Watkins and the MiCA Crypto Alliance, and the engineering evidence a custody-authorized CASP should have ready, mapped to MiCA Article 75 and DORA obligations.

10 min read 36 views
Skip key takeaways

Key takeaways: the ESMA custody Common Supervisory Action 5

What ESMA actually launched on 8 July 2026, who is exposed by the numbers, how the review reads across DORA and the engineering evidence a custody-authorized CASP should have ready.

See our MiCA compliance software development services

The ESMA Common Supervisory Action on custody is the first coordinated review of Crypto-Asset Service Providers since the MiCA transitional period closed, and it lands directly on the part of the market that authorization alone never fully tested. On 8 July 2026 the European Securities and Markets Authority launched the exercise, asking every national competent authority to examine how a risk-based sample of authorized CASPs actually run custody in live operation, not how their applications described it on paper.

In short: ESMA launched a Common Supervisory Action on custody on 8 July 2026, naming six focus areas: governance arrangements, key and storage management, transaction controls, incident detection and response, smart contract risks and dependencies on third-party providers. NCAs run risk-based samples from the second half of 2026 through the first half of 2027, with findings consolidated into a report for ESMA's Board of Supervisors in the second half of 2027. Roughly 70% of the ESMA CASP register is custody-authorized, and the June 2026 deadline-wave cohort inside that population is the least tested in live operation. This guide separates what ESMA has actually said it will examine from attributed commentary and from our own engineering advice on what to have ready.

What ESMA launched on 8 July 2026

ESMA's press release describes the exercise as a review of "the digital operational resilience of Crypto-Asset Service Providers (CASPs), with a specific emphasis on custody services." Its own scope sentence names six risk areas tied to distributed ledger technology, from governance arrangements through dependencies on third-party providers, quoted in full below. That's six items in ESMA's own text.

Commentary from the MiCA Crypto Alliance frames the exercise as the first coordinated supervisory review of CASPs since the transitional period closed on 1 July 2026, distinct from the individual authorization reviews each NCA already ran. That framing is attributed to the Alliance, not part of ESMA's own release, and it's consistent with the CSA's underlying logic: authorization confirmed a firm's controls met the required standard at a single point in time, and this review tests how those same controls hold up in ongoing operation.

The six focus areas, in ESMA's own words

ESMA's press release states the CSA scope as a single sentence. We reproduce it here without paraphrasing, then break it into the six items it actually contains:

"It will focus on risks inherent to distributed ledger technology (DLT), including governance arrangements, key and storage management, transaction controls, incident detection and response, smart contract risks, and dependencies on third-party providers."

  1. Governance arrangements
  2. Key and storage management
  3. Transaction controls
  4. Incident detection and response
  5. Smart contract risks
  6. Dependencies on third-party providers

Six items, stated by ESMA itself. No NCA-by-NCA list of which authorities are running the exercise has been published, since every NCA participates in its own jurisdiction on a risk-based sample of authorized CASPs.

Mechanics and timeline

Each NCA selects its own risk-based sample of authorized CASPs and carries out the review within its jurisdiction, according to ESMA's release. The exercise runs from the second half of 2026 through the first half of 2027. NCAs then feed their findings back to ESMA, which consolidates them into a final report submitted to ESMA's Board of Supervisors in the second half of 2027, intended to support supervisory convergence on how MiCA's custody standards get applied in practice across member states. ESMA has not published a target for how many firms each NCA will sample, or a schedule of when a specific jurisdiction's review starts, so "risk-based sample" is the only sampling detail ESMA itself has released.

Who is exposed: the custody population by the numbers

Custody authorization is the majority case in the ESMA register, not a niche subset. As of 20 July 2026, 207 of the register's 295 active authorization records (70%) hold custody authorization, per our own raw-CSV parse in the ESMA CASP register data study. Inside that population, 57 custody authorization records date from June 2026 alone, the final month of the transitional period, and that data study identifies this cohort as the newest and least supervision-tested in live operation before ESMA's activity began. France (24), Malta (21), Cyprus (20) and the Netherlands (20) hold the largest custody-authorized populations, so NCA sampling pressure concentrates there.

A separate, smaller group of firms missed the 1 July 2026 deadline entirely and are working through wind-down obligations instead of a supervisory review, a population outside the CSA that our register data study covers in full. Non-custody CASPs, the remaining 30% of active records, are likewise outside this CSA's scope, though the governance and third-party-dependency focus areas preview ESMA's supervisory style for everyone.

Engineering evidence: what your CASP should be able to produce

The MiCA Crypto Alliance's commentary on the CSA makes one point worth carrying into a preparation checklist: control over private keys is what determines whether client assets can actually be recovered after an incident. This reading is the Alliance's own commentary, derived from ESMA's scope but not published by ESMA itself. No formal ESMA evidence checklist exists for the CSA. Everything else in this section is our own preparation advice, mapped to what MiCA and DORA actually require, not a restatement of ESMA's evidence expectations. ESMA has named six focus areas, and it has not published an evidence checklist, so treat the table below as engineering guidance, not a supervisory requirement.

ESMA focus area Evidence we recommend producing
Governance arrangements A documented custody policy with role separation between the people who can authorize a transaction and the people who can review or approve it, kept current, not just filed at authorization
Key and storage management Key ceremony records, a documented cold, warm and hot storage split with movement thresholds between tiers and a written rationale for the MPC, HSM or multi-sig architecture chosen (industry practice, not an ESMA-mandated wording)
Transaction controls Multi-approval or allowlisting evidence, authorization gates for outbound transfers and monitored transaction logs that show the controls actually fired, not just that they exist in a policy document
Incident detection and response A DORA-aligned incident runbook mapped to the 24-hour classification, 4-hour initial notification, 72-hour intermediate report and 1-month final report chain, with named owners and telemetry or on-call records behind it
Smart contract risks An inventory of the smart contracts the custody function actually touches, audit trails for each and documentation of who holds upgrade privileges over them, relevant wherever staking or DeFi integrations sit inside the custody flow
Dependencies on third-party providers A mapped inventory of sub-custodians, node operators, wallet infrastructure or WaaS vendors and cloud providers, mirroring the DORA Register of Information, with a concentration view of where a single provider's failure would hit multiple client accounts

Underneath all six of those, MiCA's own custody substance in Article 75 sets the legal floor a platform's engineering has to satisfy, whatever a CSA sample asks to see: three segregation safeguards, technical on-chain separation of client assets from the CASP's own assets, book-level individual registers per client with movements recorded without delay and legal insolvency-remoteness from the CASP's own estate. A CASP is liable for crypto-assets or means of access lost through an incident attributable to it, capped at the market value at the time of the loss. Statements of position are due to clients at least every three months and on request. Custody outsourcing or delegation to an entity that is not itself an authorized CASP is prohibited, a point ESMA's own wind-down statements repeat for context. Article 70 adds the safeguarding layer: adequate arrangements to protect clients' ownership rights in insolvency and a ban on using client crypto-assets on the CASP's own account (Art 70(1)), plus placement of client funds with a credit institution or central bank in separately identifiable accounts (Art 70(3)).

The DORA read-across

CASPs authorized under MiCA are, in Latham & Watkins' description, "expressly identified as 'financial entities' subject to DORA," and the firm's mid-July 2026 commentary reads the CSA as likely to be examined alongside DORA's own obligations, ICT risk management, incident reporting, resilience testing and third-party oversight, rather than as an isolated custody-only exercise. That's Latham & Watkins' reading; ESMA hasn't made this claim itself, but it matches the substance of what DORA already requires of every CASP regardless of the CSA:

  • A major ICT incident must be classified within 24 hours of detection, an initial notification submitted within 4 hours of that classification (and no later than 24 hours from initial awareness), an intermediate report within 72 hours of the initial notification and a final report within one month after that, under Commission Delegated Regulation (EU) 2025/301, with report templates under Implementing Regulation (EU) 2025/302.
  • Under RTS 2024/1772's incident classification matrix, the economic-impact criterion sets its materiality threshold at EUR 100,000 in gross direct and indirect costs and losses.
  • A complete Register of Information covering ICT third-party providers is submitted annually to the NCA on national deadlines clustered in Q1; NCAs consolidate submissions to the ESAs by 30 April.
  • Significant entities designated by their NCA face a first mandatory round of Threat-Led Penetration Testing by 17 January 2028, repeated at least every three years.

Here's our own read on the practical implication (ESMA and DORA don't make this claim themselves): if a custodian's DORA program is real rather than a filing exercise, most of the evidence a CSA sample would ask for already exists somewhere in the organization, an incident log with named owners, a register of third-party dependencies, tested reporting timelines. The work the CSA creates is less about building new controls from scratch and more about being able to produce what DORA already obligates in a form a supervisor can review quickly. Our DORA guidance for crypto firms and DORA compliance software architecture guide both go deeper on building that evidence trail as engineering, not paperwork.

Preparing on a realistic timeline

Latham & Watkins' mid-July 2026 commentary puts it directly: CASPs offering custody services in the EU "can expect potential NCA engagement in the short term, if caught by the review." The exercise itself runs into the first half of 2027 and the consolidated report only lands with ESMA's Board of Supervisors in the second half of 2027, which means remediation work started now still lands well before findings crystallize into supervisory practice across NCAs. Waiting for a specific sample notice from your own NCA before starting is the wrong sequencing, since the evidence a CSA review would ask for, incident runbooks, third-party inventories, key management documentation, takes months to build properly, not weeks.

The build-level work here overlaps directly with what a MiCA compliance software development engagement covers: identity and jurisdiction controls at the CASP-authorization layer, and the custody-specific segregation, key management and incident-evidence layer this CSA is designed to test.

How Pharos Production helps

We build the custody evidence trail as engineering, not as a document exercise after the fact, segregation ledgers that satisfy MiCA Article 75's three safeguards, key management architecture with the ceremony and movement records a reviewer can actually follow, DORA-aligned incident runbooks with the 24-hour to 1-month reporting chain built in and a third-party dependency register that doubles as your DORA Register of Information. If your platform sits inside the custody-authorized population this CSA is testing, we can walk through what a risk-based sample would likely ask to see for your specific architecture.

Sources: ESMA press release "ESMA launches Common Supervisory Action on CASPs' digital operational resilience" (8 July 2026); Latham & Watkins Global FinTech & Digital Assets Blog (mid-July 2026); MiCA Crypto Alliance commentary (14 July 2026); ESMA public statements ESMA75-113276571-1679 (17 April 2026) and ESMA75-113276571-1710 (23 June 2026); MiCA Level 1 Regulation Articles 70 and 75; DORA Commission Delegated Regulation (EU) 2025/301, with report templates under Implementing Regulation (EU) 2025/302, and RTS 2024/1772; our ESMA CASP register raw-CSV analysis dated 20 July 2026.

FAQ

Last updated:

Quick answers to common questions about custom software development, pricing, process and technology.

  • Copy link Copies a direct link to this answer to your clipboard.

    It is a coordinated review ESMA launched on 8 July 2026 into the digital operational resilience of CASPs, with a specific emphasis on custody services. National competent authorities run the exercise on risk-based samples of authorized CASPs within their own jurisdictions, from the second half of 2026 through the first half of 2027.

  • Copy link Copies a direct link to this answer to your clipboard.

    ESMA's own press release names six focus areas: governance arrangements, key and storage management, transaction controls, incident detection and response, smart contract risks and dependencies on third-party providers. That is six items in ESMA's own text.

  • Copy link Copies a direct link to this answer to your clipboard.

    Any authorized CASP offering custody services can be selected, since each NCA draws its own risk-based sample within its jurisdiction. 207 of the 295 active CASP records in the ESMA register (70%) hold custody authorization as of 20 July 2026, the majority of the register, not a niche subset; see our register data study for the full country breakdown.

  • Copy link Copies a direct link to this answer to your clipboard.

    NCAs feed their findings back to ESMA, which consolidates them into a final report submitted to ESMA's Board of Supervisors in the second half of 2027, after the exercise itself concludes. ESMA has not indicated it will publish per-firm results, the report is intended to support supervisory convergence across NCAs, not sanction individual firms.

  • Copy link Copies a direct link to this answer to your clipboard.

    CASPs authorized under MiCA are financial entities subject to DORA, and Latham & Watkins' commentary reads the CSA as likely to be examined alongside DORA's ICT risk management, incident reporting, resilience testing and third-party oversight obligations rather than as an isolated custody-only exercise. A CASP with a real DORA program already has most of the evidence a CSA sample would ask to see.

I work with startup founders who need a dedicated software development team but don’t want to gamble on hiring, random outsourcing, or opaque delivery.
Most founders face the same problem sooner or later.
Early technical and team decisions lock the product into tech debt, slow delivery, missed milestones and constant re-hiring. By the time this becomes visible, fixing it is already expensive.

As a CTO and software architect, I help founders design, build and run dedicated development teams that work as a true extension of the startup. Not as a black-box vendor.

My focus is on complex products where mistakes are costly:

  • Web3 and blockchain platforms
  • FinTech and regulated products
  • High-load startup systems
  • MVP → scale transitions

We don’t do body-shopping.
We don’t sell generic outsourcing.

Instead, we help founders:

  • build the right team structure from day one
  • keep technical ownership and transparency
  • scale delivery without losing control
  • avoid vendor lock-in and hidden risks

Teams are aligned with the product roadmap, business goals and long-term architecture. Not just short-term velocity.

Dmytro Nasyrov, Founder and CTO at Pharos Production
Dmytro Nasyrov Founder & CTO Let's work together!

Your business results matter

Achieve them with minimized risk through our bespoke innovation capabilities

Your contact details
Please enter your name
Please enter a valid email address
Please enter your message
* required

We typically reply within 4 hours. Prefer email? [email protected]

What happens next?

  1. Contact us

    Contact us today to discuss your project. We're ready to review your request promptly and guide you on the best next steps for collaboration

    Same day
  2. NDA

    We're committed to keeping your information confidential, so we'll sign a Non-Disclosure Agreement

    1 day
  3. Plan the Goals

    After we chat about your goals and needs, we'll craft a comprehensive proposal detailing the project scope, team, timeline and budget

    3-5 days
  4. Finalize the Details

    Let's connect on Google Meet to go through the proposal and confirm all the details together!

    1-2 days
  5. Sign the Contract

    As soon as the contract is signed, our dedicated team will jump into action on your project!

    Same day