
The first EU supervisory sweep of licensed crypto firms will test custody resilience through 2027 as regulators tighten oversight after MiCA took full effect.
ESMA has begun its first Common Supervisory Action covering crypto-asset service providers, opening an EU-wide review of custody risk at licensed firms just days after MiCA took full effect. National regulators will assess a risk-based sample of authorized CASPs from late 2026 into early 2027, examining governance, key and storage management, transaction controls, incident detection, smart contract risk and reliance on third-party providers. The exercise extends a supervisory tool long used for fund managers into crypto and builds on the Digital Operational Resilience Act, signaling a shift from rulemaking to enforcement-focused oversight of custody safeguards across the EU.