On 8 July 2026, ESMA announced the launch of a Common Supervisory Action (CSA) on the digital operational resilience of Crypto-Asset Service Providers authorised under MiCAR (Regulation (EU) 2023/1114). The action is in the assessment stage: National Competent Authorities (NCAs) will conduct it on a risk-based sample of authorised CASPs, starting in the second half of 2026 and running through the first half of 2027.
The CSA is grounded in MiCAR and the Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554), which became applicable to financial entities in January 2025. DORA Articles 5 to 16 set out ICT risk management requirements, Article 17 governs ICT-related incident management, and Article 28 covers ICT third-party risk rules. ESMA has identified digital operational resilience and CASP oversight as two of its risk-based Union Strategic Supervisory Priorities for the current cycle.
Authorised CASPs providing custody and administration services face direct scrutiny across six areas: governance arrangements for ICT risk, cryptographic key and storage management, transaction-level controls, incident detection and response procedures, smart contract risks, and third-party technology dependencies. CASPs that cannot demonstrate compliance with DORA requirements during NCA on-site or off-site assessments face remediation orders, supervisory measures, and potential referral for enforcement.
The CSA targets authorised CASPs only; entities operating under MiCAR transitional arrangements may not fall within the immediate scope of assessments, though NCAs retain discretion over sample selection. ESMA has indicated that CSA findings will inform any future convergence measures and potential revisions to supervisory expectations on CASP digital resilience.
Licentium advises CASPs on MiCAR authorisation, DORA compliance programmes, and ongoing supervisory engagement. For queries on this matter or to discuss how the CSA may affect your entity, contact us. Work we undertake includes MiCAR authorisation support, DORA gap assessments, ICT risk management policy drafting, NCA supervisory response preparation, and crypto regulatory advisory.
Source: ESMA, Common Supervisory Action on CASPs' Digital Operational Resilience, 8 July 2026