ESMA puts crypto custody controls into a year-long resilience review
The EU watchdog will test key management, transaction controls, incident response and third-party dependencies across a risk-based sample of authorised crypto firms.
By The Third AnglePublished 4 min read
The Autorité des marchés financiers building in Paris, used as an illustration for ESMA's custody-resilience review; it is not the ESMA headquarters. Photo: Guilhem Vellut / Wikimedia Commons · CC BY 2.0
European crypto custody is heading into a supervisory test that will examine the systems behind a wallet balance, not just the licence attached to the firm holding it. The European Securities and Markets Authority said on July 8 that it was launching a Common Supervisory Action focused on the digital operational resilience of crypto-asset service providers, with custody as the central use case.
National competent authorities will carry out the exercise on a risk-based sample of authorised providers. ESMA says the work will run from the second half of 2026 through the first half of 2027, after which the collected findings will be consolidated into a report for its Board of Supervisors. No firm list or findings have been published yet.
Custody becomes an operating-systems question
The review's scope is wider than whether a provider keeps private keys in a secure location. ESMA lists governance arrangements, key and storage management, transaction controls, incident detection and response, smart-contract risks and dependencies on third-party providers. Together, those categories describe the path from a customer's instruction to an authorised transaction and the controls that are supposed to stop an error or compromise from becoming a loss.
That matters because custody failures rarely sit in one component. A signing system can be sound while an approval workflow is weak. A wallet can be segregated while a vendor with access to monitoring, recovery or infrastructure creates a separate point of failure. A smart contract can be audited while the surrounding permissions allow an operator to route funds somewhere the customer did not intend.
A supervisory exercise is not a new rule
ESMA describes the action as a way to improve supervisory convergence across the European Union. It is not a public ranking of custodians, a declaration that a named provider has failed, or a new custody exemption. The exercise will show how national supervisors are testing existing resilience expectations across a market whose products and technical dependencies are still changing.
The useful evidence will arrive in stages: which risk factors supervisors select, what records firms must produce, whether gaps are concentrated in key management or in external suppliers, and what the final report says about remediation. For customers and counterparties, the practical question is whether a provider can show a complete control chain from authorisation to signing, recovery and incident disclosure. ESMA's announcement starts that examination; it does not yet provide a verdict on the market.