The European Securities and Markets Authority, or ESMA, has opened a coordinated review of crypto-asset custody practices, putting client asset protection under direct regulatory examination. The move comes as the EU’s Markets in Crypto-Assets regulation, MiCA, shifts out of transition and into active supervision, with custody now one of the first areas facing structured scrutiny.
Custody controls and resilience frameworks are the main target
On 8 July, ESMA said it would launch a Common Supervisory Action with national regulators to assess the digital operational resilience of authorised crypto-asset service providers, or CASPs, with custody services as the specific focus. The review is designed to test how mature firms’ resilience frameworks are across both technical and governance layers that protect client holdings and support asset transfers.
The scope covers several risks tied to distributed ledger technology: governance arrangements, key and storage management, transaction controls, incident detection and response, smart contract risk, and dependencies on third-party providers. These are core custody functions. ESMA is trying to determine whether firms that have entered the regulated perimeter have built controls that match the risks they now carry.
Review timeline extends into the second half of 2027
According to ESMA’s schedule, the exercise will run from the second half of 2026 through the first half of 2027. A consolidated report will then be submitted to ESMA’s Board of Supervisors in the second half of 2027. The regulator linked the initiative to its risk-based supervisory priorities, where both digital operational resilience and crypto-asset service providers have been identified as key risk areas.
ESMA also said the action is meant to improve supervisory convergence across a market that is expanding quickly under MiCA. As more custodians, exchanges, and token issuers move into a single EU framework, the regulator wants a direct view of how these firms actually operate their custody controls, rather than relying only on authorisation status.
National regulators will review a risk-based sample
The review will not cover every authorised firm. National competent authorities are expected to examine a risk-based sample of providers, concentrating supervisory attention on cases where resilience gaps could cause the most damage. That keeps enforcement at the member-state level while sending a common set of findings back to the EU level.
This structure mirrors MiCA’s broader rollout model, where implementation is shared between national supervisors and EU institutions. In custody, that matters because asset protection depends on operational controls that can fail in very practical ways, from key handling and transaction approval to third-party service dependencies.
MiCA enforcement is accelerating as the register expands
The custody review arrives as MiCA enforcement picks up speed. ESMA’s interim register shows that the number of authorised providers has risen to 280 after the transitional period ended, up from 243. Newly listed firms include Standard Chartered, FalconX, and Sygnum Europe, while Cyprus led the latest approval wave with six approvals.
Luxembourg also featured in recent licensing developments. On 6 July, Ripple secured full CASP authorisation from Luxembourg’s CSSF, allowing it to serve the 30-country European Economic Area. In Spain, the CNMV said there would be no deadline extensions for unlicensed platforms, and chair Carlos San Basilio stated that no exceptions would be made. For ESMA, the custody exercise offers the first structured reading of resilience controls since firms began moving from national registrations to the shared EU register.

