Crypto custody services under the microscope: EU regulators turn their attention to compliance with digital operational resilience rules.

By Stuart Davis, Gabriel Lakeman, and Alain Traill

On 8 July 2026, the European Securities and Markets Authority (ESMA) announced the launch of a Common Supervisory Action (CSA) focusing on the digital operational resilience of cryptoasset service providers (CASPs), with a particular emphasis on custody services.

ESMA has framed the initiative as a response to its risk-based supervisory priorities, which identify both digital operational resilience and CASPs as key risk areas. According to ESMA’s announcement, the review will target risks inherent to distributed ledger technology (DLT) used in custody activities, including governance arrangements, key and storage management, transaction controls, incident detection and response, smart contract risks, and third-party dependencies.

The CSA lands at a time of increasing regulatory scrutiny for CASPs, following the recent expiry of the transitional period under the Markets in Crypto-Assets Regulation (MiCA) and growth of the EU’s CASP register (now with over 280 authorised providers). The CSA is likely to be read across relevant aspects of the EU’s Digital Operational Resilience Act (DORA), given that CASPs authorised under MiCA are expressly identified as “financial entities” subject to DORA. Under DORA, CASPs are already subject to substantial information and communication technology risk management, incident reporting, resilience testing, third-party oversight, and other digital operational resilience-related obligations.

In terms of implementation of the CSA, national competent authorities (NCAs) will each conduct a review within their own jurisdiction, selecting a risk-based sample of authorised CASPs. The exercise will start during the second half of 2026 and extend into the first half of 2027, with findings consolidated into a final report for ESMA’s Board of Supervisors in the second half of 2027.

Key Takeaways

CASPs offering custody services in the EU can expect potential NCA engagement in the short term, if caught by the review. Regardless, CASPs should ensure they are taking steps to comply with applicable digital operational resilience obligations, including under DORA.

As a reminder and by contrast to the position in the EU, the new cryptoasset regime introduced in the UK under the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 does not fully commence until autumn 2027. While DORA is not part of UK law, UK-facing crypto groups may consider treating ESMA’s CSA findings as an early indicator of the supervisory expectations which the FCA may adopt in relation to operational resilience.

This post was prepared with the assistance of Flore Bourdet in the London office of Latham & Watkins.