From the journal

ESMA Launches Common Supervisory Action on CASP Digital Operational Resilience, EU, July 2026

On 8 July 2026, the European Securities and Markets Authority launched a Common Supervisory Action targeting digital operational resilience at authorised crypto-asset service providers, with the initial phase focused on custody activities. National Competent Authorities will run risk-based assessments across a sample of authorised CASPs from the second half of 2026 through the first half of 2027.

2 min read

On 8 July 2026, ESMA announced the launch of a Common Supervisory Action (CSA) on the digital operational resilience of Crypto-Asset Service Providers authorised under MiCAR (Regulation (EU) 2023/1114). The action is in the assessment stage: National Competent Authorities (NCAs) will conduct it on a risk-based sample of authorised CASPs, starting in the second half of 2026 and running through the first half of 2027.

The CSA is grounded in MiCAR and the Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554), which became applicable to financial entities in January 2025. DORA Articles 5 to 16 set out ICT risk management requirements, Article 17 governs ICT-related incident management, and Article 28 covers ICT third-party risk rules. ESMA has identified digital operational resilience and CASP oversight as two of its risk-based Union Strategic Supervisory Priorities for the current cycle.

Authorised CASPs providing custody and administration services face direct scrutiny across six areas: governance arrangements for ICT risk, cryptographic key and storage management, transaction-level controls, incident detection and response procedures, smart contract risks, and third-party technology dependencies. CASPs that cannot demonstrate compliance with DORA requirements during NCA on-site or off-site assessments face remediation orders, supervisory measures, and potential referral for enforcement.

The CSA targets authorised CASPs only; entities operating under MiCAR transitional arrangements may not fall within the immediate scope of assessments, though NCAs retain discretion over sample selection. ESMA has indicated that CSA findings will inform any future convergence measures and potential revisions to supervisory expectations on CASP digital resilience.

Licentium advises CASPs on MiCAR authorisation, DORA compliance programmes, and ongoing supervisory engagement. For queries on this matter or to discuss how the CSA may affect your entity, contact us. Work we undertake includes MiCAR authorisation support, DORA gap assessments, ICT risk management policy drafting, NCA supervisory response preparation, and crypto regulatory advisory.

Source: ESMA, Common Supervisory Action on CASPs' Digital Operational Resilience, 8 July 2026

Crypto Regulatory

More from the journal

See all

Hong Kong SFC and FSTB Conclude Consultation on Virtual Asset Advisory and Management Regimes, 26 May 2026

On 26 May 2026, Hong Kong's Securities and Futures Commission and Financial Services and the Treasury Bureau published consultation conclusions on proposed licensing regimes for virtual asset advisory and management service providers. The regimes apply the same business, same risks, same rules principle and align SFC licensing requirements with those for securities advisory and management businesses. A bill implementing the regimes is planned for introduction into the Legislative Council in 2026.

OCC Grants Circle Final Charter for First National Digital Currency Bank N.A., 9 July 2026

The Office of the Comptroller of the Currency granted final approval on 9 July 2026 for Circle Internet Group to establish First National Digital Currency Bank, N.A., operating as Circle National Trust. The bank opened 24 July 2026 under direct OCC oversight and will manage USDC reserves on a directed basis, act as collateral trustee for USDC holders, and provide digital asset custody services to Circle affiliates.

Manitoba Enacts Public Sector AI and Cybersecurity Governance Act June 2026

On 1 June 2026, Bill 51, The Public Sector Artificial Intelligence and Cybersecurity Governance Act (S.M. 2026, c. 43), received Royal Assent in Manitoba, Canada. The Act mandates transparency, accountability structures, and cybersecurity incident reporting for public sector entities using AI systems. Substantive obligations take effect only through regulations yet to be made.