From the journal

ESMA Launches Common Supervisory Action on CASP Digital Operational Resilience, EU, July 2026

On 8 July 2026, the European Securities and Markets Authority launched a Common Supervisory Action targeting digital operational resilience at authorised crypto-asset service providers, with the initial phase focused on custody activities. National Competent Authorities will run risk-based assessments across a sample of authorised CASPs from the second half of 2026 through the first half of 2027.

2 min read

On 8 July 2026, ESMA announced the launch of a Common Supervisory Action (CSA) on the digital operational resilience of Crypto-Asset Service Providers authorised under MiCAR (Regulation (EU) 2023/1114). The action is in the assessment stage: National Competent Authorities (NCAs) will conduct it on a risk-based sample of authorised CASPs, starting in the second half of 2026 and running through the first half of 2027.

The CSA is grounded in MiCAR and the Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554), which became applicable to financial entities in January 2025. DORA Articles 5 to 16 set out ICT risk management requirements, Article 17 governs ICT-related incident management, and Article 28 covers ICT third-party risk rules. ESMA has identified digital operational resilience and CASP oversight as two of its risk-based Union Strategic Supervisory Priorities for the current cycle.

Authorised CASPs providing custody and administration services face direct scrutiny across six areas: governance arrangements for ICT risk, cryptographic key and storage management, transaction-level controls, incident detection and response procedures, smart contract risks, and third-party technology dependencies. CASPs that cannot demonstrate compliance with DORA requirements during NCA on-site or off-site assessments face remediation orders, supervisory measures, and potential referral for enforcement.

The CSA targets authorised CASPs only; entities operating under MiCAR transitional arrangements may not fall within the immediate scope of assessments, though NCAs retain discretion over sample selection. ESMA has indicated that CSA findings will inform any future convergence measures and potential revisions to supervisory expectations on CASP digital resilience.

Licentium advises CASPs on MiCAR authorisation, DORA compliance programmes, and ongoing supervisory engagement. For queries on this matter or to discuss how the CSA may affect your entity, contact us. Work we undertake includes MiCAR authorisation support, DORA gap assessments, ICT risk management policy drafting, NCA supervisory response preparation, and crypto regulatory advisory.

Source: ESMA, Common Supervisory Action on CASPs' Digital Operational Resilience, 8 July 2026

Crypto Regulatory

More from the journal

See all

New Zealand Opens Online Casino Gambling Licence Applications Under New Regulatory Regime, July 2026

On 16 July 2026, New Zealand's Department of Internal Affairs published its public notice opening the Expressions of Interest stage for online casino gambling licences under the Online Casino Gambling Act. Up to 15 licences will be available, each valid for up to three years with renewal for a further five, with a competitive selection process to follow the EOI stage.

Illinois Enacts Artificial Intelligence Safety Measures Act for Frontier AI Developers, USA, July 2026

On 6 July 2026, Illinois Governor JB Pritzker signed Senate Bill 315, the Artificial Intelligence Safety Measures Act (AISMA), into law, making Illinois the third US state to pass frontier AI legislation and the first to require mandatory independent third-party safety audits. The Act imposes safety auditing, governance, and transparency obligations on developers of frontier AI models meeting defined capability thresholds.

UKJT Issues Legal Statement on AI Liability Under English Private Law, July 2026

On 7 July 2026, the UK Jurisdiction Taskforce published its Legal Statement on Liability for AI Harms, concluding that existing English private law is capable of resolving most AI liability disputes without AI-specific legislation. The statement covers negligence, vicarious liability, professional liability, product liability, and false statement claims arising from AI-caused harm.