Are you ready for ESMA's custody resilience review?
A self-assessment against ESMA's first Common Supervisory Action under MiCA. The test isn't whether you have a policy — it's whether you can prove the control works, on the day a supervisor asks.
On 8 July 2026, ESMA launched a Common Supervisory Action (CSA) on the digital operational resilience of authorised CASPs, with a specific focus on custody services. National competent authorities will review a risk-based sample of authorised CASPs — from H2 2026 to H1 2027, with a consolidated report to ESMA's Board of Supervisors in H2 2027.
It assesses the maturity of your resilience framework across six areas, and reads directly across DORA — under which authorised CASPs are financial entities. If you hold clients' crypto-assets or the means of access to them, an NCA information request is a realistic item on your workplan.
16 self-assessment items across the six areas ESMA named, on two pages.
-
1
Governance arrangementsWho is accountable when resilience fails
-
2
Key & storage managementHow client assets are actually secured
-
3
Transaction controlsWhether controls fire, and leave a trail
-
4
Incident detection & responseWhether you'd meet DORA's reporting windows
-
5
Smart contract riskRisks inherent to the DLT you rely on
-
6
Third-party dependenciesSub-custodians, cloud, infrastructure
Get the checklist
We use your email address to send you this checklist and occasional related updates on MiCA and DORA. Confirm the link we email you and the PDF arrives straight after. You can withdraw at any time using the unsubscribe link in any email. See our privacy policy.