TLDR
ESMA has launched an EU-wide supervisory review to test how MiCA-licensed crypto custodians handle operational resilience for custody services.
- The review is a Common Supervisory Action that samples authorized CASPs and drills into custody controls like key management, incident response, and third-party dependencies.
- For custodians, a MiCA license is now the starting point, with regulators and institutional clients demanding hard evidence of security, segregation, and business continuity.
- Findings will feed into MiCAs review and debates on centralizing crypto supervision under ESMA, potentially reshaping the competitive landscape for EU custody providers.
Deep Dive
1. What ESMA Is Testing
ESMA has launched a Common Supervisory Action (CSA) on crypto asset service providers (CASPs) to assess the operational resilience of custody services after MiCAs transitional period ended, making the rules fully effective across the EU. The CSA targets a sample of MiCA-authorized CASPs and evaluates the maturity of their digital operational resilience frameworks, focusing on key and storage management, transaction controls, incident response, and reliance on third-party technology and service providers. This is described as one of the first major supervisory exercises under MiCA, moving from licensing to deep operational testing, according to reporting on ESMAs initiative in Europes crypto market.
EU custodians will be judged not just on compliance paperwork but on how well their systems cope with real-world failures, which can directly affect how safely user assets are held.
2. Why It Matters For Custodians And Users
Industry voices like Taurus and BitGo stress that a licence is the start line, not the finish, as ESMA now expects custodians to prove robust controls rather than just claim them, including asset segregation, access management, and continuity planning during stress events, as highlighted in coverage of the CSA on MiCA custodians. Institutional clients are already asking detailed questions about custody architecture, and this review aligns regulatory expectations with those demands. For retail users, the main effect is indirect: stronger standards and audits should reduce the risk that a single operational failure (for example, compromised keys or a flawed incident response) leads to large-scale asset loss.
3. What Comes Next
The CSA operates under both MiCA and the EUs Digital Operational Resilience Act (DORA), which specifies technology risk requirements for financial firms, including crypto businesses. Legal experts note that custody technology is concentrated among a small number of vendors, so ESMAs findings on supply chain resilience could set benchmarks for how regulators assess custodians in future and influence proposals to move CASP supervision from national regulators to ESMA itself, as outlined in an analysis of ESMAs MiCA-related review. The results are expected to inform MiCAs formal review and any MiCA 2.0 adjustments, shaping which custody models and providers gain regulatory favor and institutional flows.
Confidence: high because multiple independent regulatory and industry reports describe the same ESMA CSA structure and objectives.
Conclusion
ESMAs operational resilience tests mark a new phase of MiCA: licensing alone is no longer enough, and custody providers must demonstrate that their technology, processes, and vendors can withstand stress. For crypto users and institutions in Europe, the outcome will likely mean tighter standards, possible consolidation among custodians, and clearer regulatory benchmarks for what safe crypto custody should look like. Watching which firms pass these tests cleanly will be key to understanding where the most robust infrastructure is emerging in the EU market.
