Are you ready for ESMA's custody resilience review?

A self-assessment against ESMA's first Common Supervisory Action under MiCA. The test isn't whether you have a policy — it's whether you can prove the control works, on the day a supervisor asks.

On 8 July 2026, ESMA launched a Common Supervisory Action (CSA) on the digital operational resilience of authorised CASPs, with a specific focus on custody services. National competent authorities will review a risk-based sample of authorised CASPs — from H2 2026 to H1 2027, with a consolidated report to ESMA's Board of Supervisors in H2 2027.

It assesses the maturity of your resilience framework across six areas, and reads directly across DORA — under which authorised CASPs are financial entities. If you hold clients' crypto-assets or the means of access to them, an NCA information request is a realistic item on your workplan.

16 self-assessment items across the six areas ESMA named, on two pages.

  1. 1
    Governance arrangements
    Who is accountable when resilience fails
  2. 2
    Key & storage management
    How client assets are actually secured
  3. 3
    Transaction controls
    Whether controls fire, and leave a trail
  4. 4
    Incident detection & response
    Whether you'd meet DORA's reporting windows
  5. 5
    Smart contract risk
    Risks inherent to the DLT you rely on
  6. 6
    Third-party dependencies
    Sub-custodians, cloud, infrastructure

Get the checklist

We use your email address to send you this checklist and occasional related updates on MiCA and DORA. Confirm the link we email you and the PDF arrives straight after. You can withdraw at any time using the unsubscribe link in any email. See our privacy policy.

Written by Viktor Andriichuk, who builds the production systems that make these obligations operational.