The inspections will focus on authorized CASPs approved to offer digital asset custody services. Regulators aim to assess the maturity of these firms’ operational security and technical infrastructure, with particular attention to risks tied to distributed ledger technology.
CySEC said the supervisory reviews will examine key operational resilience areas, including governance and control frameworks, as well as key and storage management. The regulator will also review security protocols governing private keys, wallet storage and access controls.
Other areas under review include transaction controls, monitoring and incident response, smart contract security and third-party risk management.
The initiative aligns CySEC with national competent authorities across the European Union and responds directly to ESMA’s risk-based supervisory priorities. EU regulators have repeatedly identified operational resilience and digital asset custodians as high-risk focal points for financial stability and investor protection.
By establishing a standardized framework for on-site visits and desk audits, ESMA and national regulators aim to promote supervisory convergence across member states and ensure uniform security expectations as the crypto ecosystem continues to integrate with traditional finance.
CySEC, which issued a consultation paper in late 2025 proposing a new directive on prudential information reporting for crypto asset service providers, warned local firms that the standards outlined in the circular are mandatory. The regulator said compliance readiness will serve as the baseline for selecting CASPs for upcoming inspections.