Cyprus to audit crypto custody firms 2026-27

Cyprus Securities and Exchange Commission will inspect authorized crypto custodians with on-site and desk reviews from H2 2026 to H1 2027 under ESMA’s 2026 Common Supervisory Action.

The Cyprus Securities and Exchange Commission will carry out on-site inspections and desk-based reviews of authorized crypto asset service providers offering custody services from the second half of 2026 through the first half of 2027. The checks are part of the European Securities and Markets Authority’s 2026 Common Supervisory Action.

In a circular to regulated firms, CySEC chair George Theocharides wrote the regulator will audit a representative sample of local entities approved to provide digital asset custody. The inspections will concentrate on operational resilience and infrastructure risks linked to distributed ledger technology and custody operations.

Regulators will examine governance and control frameworks, key and storage management, security protocols for private keys, wallet storage and access controls. The reviews will also assess transaction controls, monitoring, incident response capabilities, smart contract security and third-party risk management.

CySEC wrote that the standards in its circular are mandatory and that firms’ preparedness will be used to select providers for on-site visits and desk audits. The regulator published a consultation paper in late 2025 proposing a new directive on prudential information reporting for crypto asset service providers.

ESMA and national competent authorities have identified custody and operational resilience as high-risk areas for financial stability and investor protection. The Common Supervisory Action aims to align supervisory approaches across EU member states and set consistent security expectations as crypto services integrate with traditional finance.

On-site reviews will allow inspectors to examine technical infrastructure and operational procedures at firm premises, while desk reviews will assess documentation, controls and remote monitoring systems. Firms selected for visits should expect scrutiny of incident response procedures, transaction monitoring systems and controls around outsourced services.

CySEC described the campaign as part of its remit to oversee authorized CASPs and to align national supervision with ESMA’s risk-based priorities. The regulator warned that failure to meet the prescribed standards could affect a firm’s standing and its authorization to offer custody services.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author