The European Securities and Markets Authority (ESMA) is moving from words to action, launching the first coordinated inspection of Crypto Asset Service Providers (CASPs) following the full entry into force of the MiCA regulation. The regulator's focus is on the digital operational resilience of digital asset custody services. This is a landmark event for the entire market, as it marks a transition from theoretical regulation to practical oversight.

Common Supervisory Action (CSA): What is being inspected?

The initiative is called the Common Supervisory Action (CSA). National regulators from EU countries will assess the maturity of operational resilience systems at selected companies. The inspection itself will run from the second half of 2026 to the first half of 2027. The inspection's focus is on risks inherent in distributed ledger technology (DLT). Specifically, regulators will examine governance, key management and storage, as well as transaction controls.

Separately, the ability of CASPs to identify and respond to incidents will be analyzed. The scope of attention also includes smart contract risks and dependence on third-party providers. The sample of companies for inspection will be risk-based, allowing efforts to be concentrated on the most vulnerable market participants. According to ESMA, this initiative fully aligns with supervisory governance priorities, where both operational resilience and the service providers themselves are considered key risk areas. The goal of the CSA is to enhance supervisory consistency in a rapidly changing market segment.

Why is this important and what will it lead to?

The significance of this step cannot be overstated. This is the first inspection of this scale since MiCA came into full effect. The EU is moving from setting rules to their practical application, and crypto asset custody is becoming one of the first targets of close scrutiny. The choice of focus is no coincidence: the industry's main risks are concentrated precisely in custody: key loss, hacks, and failures by third-party contractors. Recent incidents involving the suspension of withdrawals on certain platforms have clearly demonstrated how vulnerable this function can be for users.

For the market, this inspection means increased compliance costs and a higher bar for requirements. Large, well-prepared companies may gain a competitive advantage from this, while smaller participants with immature resilience systems will find it harder to meet the standards. In the long term, oversight could boost institutional investor confidence in regulated European platforms. However, overly strict application of the rules carries the risk of driving some business to jurisdictions with softer regulation.

My expertise: ESMA is taking a correct, albeit belated, step. The focus on custodial risks is a response to the real threats the market has faced more than once. However, it is important that the regulator does not overstep: excessive pressure could lead to an outflow of liquidity and innovation from the EU, ultimately weakening the market itself. The balance between security and flexibility is the key to MiCA's success.