The Cyprus Securities and Exchange Commission (CySEC) has announced that it will take part in a European-wide supervisory exercise examining the digital resilience of crypto asset service providers that offer custody services, with inspections set to begin in the second half of 2026.

The initiative follows the launch of the 2026 Common Supervisory Action (CSA 2026) by the European Securities and Markets Authority (ESMA) in cooperation with national competent authorities across the European Union.

According to a CySEC circular, the exercise will assess how well authorised crypto asset service providers (CASPs) have developed their digital operational resilience frameworks in relation to custody activities.

The review will examine the risks associated with distributed ledger technology (DLT), the technology underpinning many crypto assets, while focusing on how firms protect digital assets and maintain secure operations.

CySEC explained that the exercise will examine governance arrangements, the management of digital keys and storage systems, transaction controls, incident detection and response procedures, risks linked to smart contracts, and firms’ dependence on third-party service providers.

The regulator said that national competent authorities will conduct the review using a risk-based sample of authorised CASPs, with the supervisory exercise running from the second half of 2026 until the first half of 2027.

According to CySEC, the initiative reflects ESMA’s risk-based supervisory priorities, which identify both digital operational resilience and crypto asset service providers as key areas requiring closer oversight.

The regulator added that ESMA developed the Common Supervisory Action to improve supervisory consistency across the European Union in what it described as a rapidly evolving segment of the financial market.

As part of the exercise in Cyprus, CySEC plans to carry out on-site inspections and desk-based reviews involving a selected group of crypto firms.

The regulator explained that, to ensure consistency across participating authorities, only firms that have already been authorised and are licensed to provide custody services will be included in the sample.

CySEC said the supervisory review will concentrate on firms’ governance and internal control frameworks, the management of storage systems and digital keys, transaction controls, threat monitoring, incident detection and response procedures, controls surrounding smart contracts, and the management of risks arising from third-party providers.

The commission also made clear that it expects crypto asset service providers to comply with the contents of the circular, as these expectations will form part of CySEC’s supervisory review during the Common Supervisory Action.