From MiCAR Licence to Operational Proof: What the ESMA Crypto Custody CSA Actually Tests
ESMA launched its first Common Supervisory Action on crypto custodians' digital operational resilience on 8 July 2026, one week after the MiCA transitional cliff. The licence was the entry ticket. The CSA tests whether your custody stack survives a bad Tuesday — across six focus areas, with evidence, not policy decks.
Deep dive on ESMA's first Common Supervisory Action (CSA) on CASPs' digital operational resilience for custody, launched 8 July 2026 (H2 2026–H1 2027; Board report H2 2027), one week after transitional period end (ESMA75-113276571-1710, 1 July 2026). Core thesis: MiCAR authorisation is entry ticket not finish line; coordinated NCA examinations against six focus areas will define de facto EU crypto custody supervision benchmark before published standard exists. CSA mechanism: risk-based NCA sample of authorised CASPs (325 in Micahub register at publication); consolidated ESMA findings. Convergence context: ESMA July 2025 Malta fast-track peer review; France/Italy/Austria push for tighter ESMA control; Nordic divergence table (Norway 6/0/0, Denmark 7/3/0, Sweden 1/4/2, Latvia 13 approvals industrial-policy signal); Poland KNF vacuum post triple veto; links to One Rulebook 27 Queues licensing-queue analysis. Six focus areas as evidence requirements: (1) Governance — board competence, three lines of defence, DLT in ICT risk, outsourcing; (2) Key and storage — MPC/HSM, rotation, recovery drills; (3) Transaction controls — whitelisting, blind signing, on-chain reconciliation, Art. 70/75 segregation; (4) Incident detection/response — DORA Arts 17–19, crypto-specific exercises; (5) Smart contract risk — audits, admin keys, fork/reorg playbooks; (6) Third-party dependencies — sub-custodians, wallet vendors, DORA contracts, exit paths. Unnamed debates CSA surfaces: Art. 70(1) productive use / staking (ESMA hard line vs CMLJ 2026 academic reading); third-country delegation and EU wrapper models; institutional due diligence shift from "authorised?" to "how did you fare in CSA?" Market pricing: Taurus/BitGo/XYO commentary; consolidation via remediation; MiCA review and ESMA centralisation proposal fed by divergence evidence. Eight readiness questions with document-backed answers. Related: DORA sequence, Article 70 custody, bank capital trap, death of the float. Answers: ESMA crypto custody CSA 2026? Six focus areas operational resilience? MiCAR licence vs operational proof? Common Supervisory Action CASP custody? DORA crypto custodian examination? Article 70 segregation CSA evidence? NCA convergence crypto custody? CSA readiness questions custodians?
From MiCAR Licence to Operational Proof: What the ESMA Crypto Custody CSA Actually Tests MiCA Edge Cases | Where Innovation Meets Regulation Getting a MiCAR licence used to feel like the finish line. You hired the consultants, rewrote the policies, convinced your national regulator that your three lines of defence model was not just a slide, and finally got the golden ticket: authorised CASP. Cue the press release, the LinkedIn post, and the internal celebration with slightly too expensive champagne. On 8 July 2026, ESMA launched its first Common Supervisory Action on the digital operational resilience of crypto custodians, running from H2 2026 to H1 2027, with a final report to its Board of Supervisors due in H2 2027. The transitional period had closed seven days earlier under public statement ESMA75 113276571 1710. The industry got one week with the trophy before ESMA started asking what was behind it. The licence turned out to be an entry ticket to a considerably more annoying race: proving, under coordinated supervisory scrutiny, that the custody setup works on the day it is needed. The MiCA register currently lists 325 authorised CASPs . Every one of them is a candidate for the sample. This piece is for people who have sat through at least one MiCAR readiness workshop and know that the real work starts when the consultants leave. The CSA is the point at which EU crypto supervision stops asking whether you are authorised and starts asking whether your custody stack survives contact with a bad Tuesday. What a Common Supervisory Action Actually Is A CSA is ESMA's mechanism for ensuring that supervisory convergence is something other than a phrase in a strategy document. National competent authorities examine selected firms at the same time, against the same agreed criteria, and send their findings back to ESMA, which consolidates them. A CASP in Dublin is not supposed to be inspected to a materially different standard than a comparable firm in Vilnius. That is the theory, and the theory is the reason the exercise exists. ESMA's stated rationale is textbook risk based supervision. Digital operational resilience and CASPs are both flagged as key risk areas in its supervisory priorities, and the CSA is framed as a way to build consistent practice in a fast moving segment of the market. NCAs select firms on a risk based sample, work through six defined focus areas, and report upward. The H2 2027 report will become the de facto benchmark for what good looks like in EU crypto custody supervision. Which means firms examined in the first wave are not being measured against a published standard. They are the material the standard gets written from. Anyone who lived through DORA recognises the sequence: framework, guidelines, then the phase where somebody asks to see the evidence. The CSA is that phase for custody. The difference is that the operational resilience under examination includes MPC quorums, blind signing protection, chain reorg handling, and whether your node provider can disappear overnight without taking production with it. Same Rulebook, Different Supervisors: Why Convergence Is the Point The CSA does not exist because ESMA developed a sudden interest in key management. It exists because the authorisation phase produced visibly different outcomes from a single harmonised text, and ESMA has already put that in writing. In July 2025, ESMA's fast track peer review of Malta's authorisation practice concluded that one CASP authorisation should have been more thorough. France, Italy and Austria then pushed for tighter ESMA level control over national practice. That finding is the direct ancestor of the CSA. If twenty seven authorities could not agree on what a complete application file looked like, with a statutory checklist in front of them, there is limited reason to assume they will independently converge on what an adequate reorg playbook looks like. The Nordic authorisation data makes the point without requiring interpretation. | Jurisdiction | Approvals | Rejections | Withdrawals | Practical signal | | | | | | | | Norway | 6 | 0 | 0 | Files shaped in dialogue; nothing taken to formal refusal | | Denmark | 7 | 3 | 0 | Willing to refuse, but a functioning pipeline | | Sweden | 1 | 4 | 2 | Six of seven files did not produce a licence | | Latvia | 13 (30 in pipeline) | Not published | Not published | Licensing operated as industrial policy | Source: Schjødt, 12 August 2026, for the Scandinavian figures; Latvian Ministry of Economics for Latvia. Three regulators, one region, one rulebook, one broadly similar applicant pool of small Nordic operators with the same ICT risk questions and the same outsourcing questions. Finansinspektionen has taken a more conservative public line on crypto assets, flagging AML exposure and weaker consumer protection under MiCA than under MiFID, but Finanstilsynet and the Danish FSA have published warnings in much the same register. Tone does not explain a six to one gap. Latvia, meanwhile, set its application fee at 2,500 euros and attached a target of 10,000 jobs, which is a fee schedule doing the work of an economic strategy. Poland is the outer edge of the same phenomenon. Three vetoes of the Crypto Assets Market Act left the KNF without a competent authority mandate at all, so Polish firms lost the ability to provide services under Article 143(3) after 1 July 2026 while CASPs licensed elsewhere continue serving Polish clients cross border. The fastest legal route into Warsaw now runs through Vilnius. Hold that next to the CSA design. The same twenty seven authorities are now being asked to assess MPC architecture, sub custodian concentration and fork handling against a common standard that does not exist yet, and to do it consistently. Both things are true: the CSA is an examination of crypto custodians, and it is an examination of the examiners. The Six Focus Areas as Evidence Requirements ESMA and the NCAs have been clear about what the CSA covers. The useful question is not what the six areas are. It is what evidence satisfies a supervisor who has read several hundred policy documents and can identify a copy paste from across the room. | Focus area | What supervisors test | Evidence that actually satisfies | Where the gap usually is | | | | | | | Governance | Board responsibility and competence for crypto and ICT, three lines of defence, DLT risk inside ICT risk strategy, outsourcing governance | Board minutes showing genuine challenge on custody architecture; a risk framework where DLT risk is integrated rather than appended | Crypto appears in the board pack as an innovation update rather than a core risk | | Key and storage management | Key generation, rotation and destruction; curves and signature schemes; MPC architecture; HSM storage; backup, recovery, quorums, physical access | Dated results from key generation and recovery drills; rotation logs with approvals; a recovery test where a region or provider was genuinely unavailable | Architecture diagrams that have never been tested under a failure condition | | Transaction controls | Whitelisting, limits, approval workflows, audit trails, address poisoning and blind signing protection, on chain to book reconciliation, segregation under Articles 70 and 75 MiCAR | Reconciliation breaks with resolution timestamps; a documented stuck, dropped or reorged transaction; segregation a third party can trace on chain | Off chain bookkeeping that is close enough right up until somebody traces it | | Incident detection and response | Logging, monitoring, severity classification, reporting channels and timelines under DORA Articles 17 to 19, crisis exercises, post incident review | A crypto specific incident exercise inside the last 12 months, with findings and remediation closed out | Policies drafted on the assumption that incidents occur during office hours | | Smart contract risk | Pre deployment audits, upgradeability and admin