ESMA Initiates Cyber Resilience Checks for Crypto-Asset Service Providers
The European Securities and Markets Authority (ESMA) has announced a new initiative to enhance the cyber resilience of authorized Crypto-Asset Service Providers (CASPs) in Europe. This Common Supervisory Action (CSA) will focus specifically on firms that offer custody services and is set to commence in the second half of 2026, following the recent expiration of the transitional period for the Markets in Crypto-Assets (MiCA) regulation on July 1, 2026.
With approximately 280 to 283 CASPs now holding the necessary licenses to operate within the European Union, the CSA aims to ensure that these licenses are backed by robust operational practices. The reviews will assess various aspects of digital operational resilience, including governance frameworks, cryptographic key management, transaction controls, and incident response protocols. National authorities across EU member states will conduct these reviews based on risk assessments.
This initiative aligns with both MiCA and the Digital Operational Resilience Act (DORA), which collectively aim to establish comprehensive standards for the management of ICT risk and cybersecurity within the financial sector. The consolidated report from this supervisory action is expected to be presented to ESMA's Board of Supervisors in the latter half of 2027, potentially leading to further regulatory measures if systemic issues are identified.
Source: KLEA News