EU supervisors put crypto custody resilience under closer review

The European Securities and Markets Authority (ESMA) has begun a coordinated supervisory exercise examining how authorised crypto-asset service providers protect custody operations from technology and operational failures.

Announced on 8 July 2026, the Common Supervisory Action will be carried out by national competent authorities on a risk-based sample of authorised providers. The exercise is scheduled to run from the second half of 2026 through the first half of 2027, with a consolidated report expected to reach ESMA's Board of Supervisors in the second half of 2027.

What supervisors will examine

ESMA identified six broad areas of attention:

  • governance arrangements;
  • cryptographic key and storage management;
  • transaction controls;
  • incident detection and response;
  • smart-contract risks; and
  • dependence on third-party providers.

These controls matter because a custody service can fail even when the underlying blockchain continues to operate. An exchange or custodian may depend on hot and cold wallets, access-control systems, transaction-signing procedures, cloud infrastructure, software suppliers and internal recovery processes. Weakness in any part of that chain can interrupt withdrawals or expose assets and data.

The exercise sits within a broader EU framework. The Digital Operational Resilience Act, generally known as DORA, applies to crypto-asset service providers authorised under the Markets in Crypto-Assets Regulation (MiCA). DORA establishes requirements covering ICT risk management, incident handling, resilience testing and third-party technology risk.

What the announcement does — and does not — establish

The confirmed fact is that ESMA has launched a coordinated review and specified its scope and timetable. The announcement does not say that every authorised provider will be examined, nor does it identify a provider as unsafe or accuse one of misconduct.

It is reasonable to expect the exercise to make supervisory practices more consistent and to increase attention on custody controls. That is an inference from the stated purpose of the review, not a guarantee of a particular enforcement outcome.

Regulatory authorisation also should not be confused with a guarantee. A licence or register entry does not eliminate cyber risk, counterparty risk, insolvency risk, liquidity constraints, software defects or the possibility of human error.

What users can check now

EU users can consult ESMA's current MiCA register and the relevant national regulator to verify the legal entity providing a service. The name on an app or website may not, by itself, identify the entity holding customer assets.

Before depositing funds, users should also review the provider's custody and withdrawal terms, asset-segregation disclosures, incident procedures and available account-security controls. Keeping assets in self-custody can reduce reliance on a provider, but it transfers responsibility for seed phrases, private keys, backups and transaction verification to the user.

The practical lesson is not that one custody model is risk-free. It is that users should understand which risks they are accepting, verify a provider's current status and avoid treating regulatory supervision as insurance against loss.

Primary sources

This article is for general information and education only. It is not financial, investment, legal or cybersecurity advice. Crypto-assets and custody arrangements can involve loss of capital, fraud, operational failure, cyberattack and regulatory risk.

Comments

Popular posts from this blog

Ethereum's 2026 roadmap: shipped upgrades versus future plans

UK crypto regulation: what changes in October 2027

What the SEC's 2026 crypto interpretation actually says