ESMA expands cyber resilience checks to crypto-asset service providers in 2027

4 hours ago 2



One week after the final deadline for crypto firms to get licensed under Europe’s landmark regulatory framework, the continent’s top securities regulator is already moving to phase two: making sure those licenses actually mean something. The European Securities and Markets Authority (ESMA) announced on July 8 that it has launched a Common Supervisory Action (CSA) focused on the digital operational resilience of authorized Crypto-Asset Service Providers (CASPs) that offer custody services. The reviews will run from the second half of 2026 through the first half of 2027, with a consolidated report expected for ESMA’s Board of Supervisors in the latter half of 2027. From licensing to enforcement The timing is not accidental. MiCA’s transitional period ended on July 1, 2026, meaning every crypto firm operating in the EU now needs proper authorization. Roughly 280 to 283 CASPs currently hold that authorization, a meaningful jump from the 243 that had secured licenses before the deadline. The scope of the review covers governance frameworks, cryptographic key management, transaction controls, incident detection and response, smart contract risks, and reliance on third-party providers. Na...

Read Entire Article