EU Crypto Shift: ESMA Launches Massive Custody Stress Test

ESMA launched a coordinated EU-wide review of crypto custody operations on July 8, 2026, moving MiCA supervision from the licensing question to the harder question of whether crypto firms can actually protect client assets under stress.
Key Takeaways
- ESMA has launched a coordinated EU review of operational resilience at authorised crypto custodians.
- National regulators will inspect a risk-based sample of crypto-asset service providers.
- The review covers private keys, asset storage, transaction controls, incidents, smart contracts and external providers.
- Serious or unresolved breaches can lead to corrective orders, service restrictions, penalties or loss of authorisation.
- ESMA has not announced a common interim deadline before the final report expected in late 2027.
European regulators are moving directly from MiCA licensing into a coordinated examination of the systems that authorised crypto firms use to protect client assets.
On July 8, the European Securities and Markets Authority launched a Common Supervisory Action focused on crypto custody. National regulators across the EU will review a risk-based sample of authorised Crypto-Asset Service Providers, or CASPs, using an assessment coordinated by ESMA.
This is not an enforcement case against one exchange or custodian, and it does not mean every authorised firm will be inspected. It is an EU-wide supervisory exercise intended to establish whether national authorities are testing custody resilience consistently across member states.
Licensing Was the First Gate
July 1 was the latest possible end of MiCA’s transitional period for firms that had been operating under earlier national regimes. Member states were allowed to shorten that period, but no provider could continue relying on the EU’s grandfathering provision beyond that date.
Coindoo’s review of which exchanges secured MiCA authorisation before the deadline covered the first stage of that transition. The new ESMA exercise addresses the next question: whether authorised firms can demonstrate that their custody systems work under operational stress.
Two EU frameworks apply here. MiCA establishes the obligations attached to providing crypto services, including custody. The Digital Operational Resilience Act, or DORA, requires covered financial firms to manage technology risk, test their resilience, report major incidents and control their dependence on outside technology providers.
Authorised CASPs fall within DORA’s scope. A firm can therefore hold a MiCA licence and still face supervisory action if its technology controls, recovery procedures or third-party arrangements do not meet the required standard.
Why Custody Is Receiving Special Attention
A custody failure can affect client assets before a firm has time to contain the incident. If a private key is compromised or a withdrawal control fails, a blockchain transfer may be difficult or impossible to reverse.
Article 75 of MiCA places specific responsibilities on firms that hold crypto-assets for clients. Custodians must maintain a custody policy, keep records of each client’s positions, separate client assets from their own holdings and have procedures for returning those assets.
MiCA also makes a custodian liable for the loss of crypto-assets or the means of access when the incident is attributable to the provider. Liability is capped at the market value of the lost assets when the loss occurred.
The CSA therefore goes beyond checking whether a security policy exists. It examines whether the operational system supporting those legal duties is mature enough to protect assets in practice.
What Regulators Will Examine
ESMA identified seven areas covering the main points at which a custody system can fail.
Governance Arrangements
Regulators will examine how responsibility for custody risk is assigned, escalated and reported to senior management. A control framework needs clear ownership rather than responsibilities divided ambiguously between security, operations and compliance teams.
Key Management
The review covers how cryptographic keys are created, accessed, backed up, recovered and retired. It also reaches the approval controls used when keys sign transactions.
Storage Management
Supervisors will assess how assets are distributed between online and offline storage and how access to each environment is restricted. The relevant question is not only how much sits in cold storage, but how assets can be moved out of it.
Transaction Controls
This includes the processes governing withdrawals and other asset movements, such as approval requirements, transaction limits and controls intended to identify unauthorised or unusual transfers before execution.
Incident Detection and Response
Firms must be able to identify an incident, contain the affected systems, preserve evidence, restore services and complete required notifications. Recovery plans also need to work when the primary infrastructure is unavailable.
Smart Contract Risks
Where custody services interact with smart contracts, supervisors will assess how code-related risks are identified and controlled. A vulnerability in an external contract can expose assets even when the custodian’s own wallet infrastructure remains secure.
Third-Party Dependencies
The exercise covers reliance on cloud services, custody technology, security vendors and other external providers. Firms remain responsible for resilience even when a critical function has been outsourced.
The Review Is About Evidence, Not Policy Language
A written custody policy is only one part of the assessment. Supervisors need evidence that the controls described in it are operating as intended.
For key management, that can include access records, approval logs, recovery tests and evidence showing how responsibilities are separated. For asset storage, firms need records that reconcile client positions with the assets held onchain and demonstrate that client holdings remain segregated from corporate funds.
Incident plans also need operational support. A document stating that a firm can recover from an outage carries limited value if recovery procedures have not been tested, the responsible staff cannot be reached or the backup environment depends on the same failed provider.
This is where older custody stacks may face difficulty. A system can function during normal market conditions while still lacking the documentation, testing history or vendor oversight expected from an authorised financial entity.
What Happens If a Custodian Fails the Review
The CSA does not create a single automatic penalty for failing one of the seven areas. Any corrective or enforcement action will be taken by the relevant national regulator using its existing powers under MiCA, DORA and national law.
An NCA can first require information, supporting documents and remedial action within a specified period. The response will depend on the seriousness of the deficiency, the risk to client assets and whether the firm acts to correct it.
Under MiCA, national regulators have powers that include:
- Ordering the firm to stop the conduct that caused an infringement.
- Requiring material information to be disclosed to clients.
- Publicly identifying a provider that has failed to meet its obligations.
- Suspending a crypto service for up to 30 consecutive working days where there are reasonable grounds to suspect an infringement.
- Prohibiting a service where an infringement has been established.
- Imposing administrative measures or financial penalties under the applicable national framework.
Authorisation is not normally lost because of a minor control gap discovered during one review. The risk becomes more serious when a provider no longer meets the conditions under which it was authorised and fails to complete the remedial action requested by its regulator within the specified period.
MiCA also allows an authorisation to be withdrawn for a serious infringement. A regulator may limit that withdrawal to a particular crypto service, meaning a firm could lose permission to provide custody without necessarily losing every other authorised activity.
No Common Interim Deadline Has Been Published
The exercise will run from the second half of 2026 through the first half of 2027. ESMA will consolidate the national findings and submit a final report to its Board of Supervisors in the second half of 2027.
ESMA has not published an EU-wide deadline for selected firms to submit documents, a date for interim findings or a public schedule showing when each national review will begin.
The first practical milestone will be contact from national regulators to the CASPs included in their samples. Those communications may set domestic deadlines for questionnaires, supporting evidence, interviews or further supervisory work, but the timing does not need to be identical in every member state.
Firm-specific corrective action also does not have to wait for ESMA’s final report. If an NCA identifies an urgent weakness during the exercise, it can address that firm under its existing supervisory powers while the wider CSA continues.
Public signals to watch before late 2027 include enforcement notices from national regulators, changes to authorisation status and measures added to ESMA’s MiCA register. Routine information requests or private remediation plans may not become public.
One Review, National Enforcement
The value of a Common Supervisory Action is that regulators assess the same broad risks at the same time and share their findings through ESMA. That makes it easier to identify weaknesses that appear across several firms or member states.
Third-party concentration is one example. A custody provider may appear resilient when examined alone, but the picture changes if many CASPs depend on the same cloud environment, key-management vendor or wallet technology. A disruption at one supplier could then affect several regulated firms simultaneously.
National authorities still make the firm-level decisions. Their supervisory approach and the powers available under domestic law can influence how quickly a weakness moves from a remediation request to a public measure. ESMA’s role is to reduce unjustified differences in how the shared EU rules are interpreted and applied.
MiCA Supervision Is Moving Into the Systems Layer
The July review changes the focus from whether a provider obtained authorisation to whether it can continue protecting client assets when technology, staff or external suppliers fail.
For custodians, that means demonstrating more than possession of a licence or a well-written security policy. They need records showing that keys remain controlled, client holdings are segregated, withdrawals are properly authorised, incidents can be contained and outsourced services can fail without taking the entire custody operation with them.
The final ESMA report will show whether the weaknesses identified are isolated or common across the European market. Individual firms, however, may be required to correct serious deficiencies long before that report appears.









