Skip to main content
0

Introduction

The Cyprus Securities and Exchange Commission issued Circular C794 on 6 August 2026. It informs Crypto Asset Service Providers (CASPs) that ESMA has initiated a Common Supervisory Action (CSA) for 2026. This CSA, a clarification, focuses on assessing CASPs’ digital operational resilience concerning custody activities. The review will span from the second half of 2026 to the first half of 2027.

CySEC Circular C794 – At a Glance

  • Issued date: 6 August 2026
  • Applies to: Crypto Asset Service Providers (CASPs)
  • Deadline: [CONFIRM]
  • Key requirement: Participate in digital resilience assessment for custody
  • Submission method: [CONFIRM]

What Does This Circular Require?

What firms must do. CASPs must prepare for participation in the assessment of their digital operational resilience frameworks, especially focusing on custody activities.

Legal basis. CySEC Circular C794

Regulatory objective. To enhance supervisory convergence and assess the maturity of digital resilience frameworks in the custody space.

Who Is in Scope?

The circular applies to all authorised CASPs providing custody services and aims to evaluate their digital operational resilience.

  • Crypto Asset Service Providers (CASPs)

Edge cases and exceptions:

  • Entities not authorised or not providing custody will not be part of the sample.

Key Requirements Breakdown

Reporting / Submission Requirements

Participate in on-site visits or desk-based reviews conducted by CySEC.

Technical / System Requirements

Focus on digital operational resilience aspects such as governance, transaction controls, and threat management.

Practical Implementation: What Firms Should Do

In practice, CASPs should review their digital operational resilience frameworks, considering governance, key management, transaction controls, and threat monitoring. CySEC may conduct reviews to ensure compliance within the CSA’s scope, focusing on these key areas.

Key Dates and Deadlines

DateWhat happens
Second half of 2026Start of the CSA assessment period
First half of 2027End of the CSA assessment period

How to Apply This Correctly

  1. Ensure digital resilience frameworks are robust, focusing on custody activities.
  2. Prepare for potential on-site visits or desk-based reviews by CySEC.
  3. Review governance arrangements, storage and key management practices.

Compliance Officer Checklist

  • Review digital operational policies
  • Assess transaction control procedures
  • Evaluate smart contract risk management
  • Ensure third-party risk management frameworks align with guidelines

Evidence to Retain

  • Governance framework documentation
  • Key and storage management policies
  • Incident detection and response records

Why This Matters

Non-compliance with this CSA can impact CASPs’ regulatory standing and operational effectiveness. By participating, CASPs will help ensure their frameworks meet ESMA’s and CySEC’s standards for digital resilience, reducing potential risk exposure.

Frequently Asked Questions

What is the CSA 2026 about?

The CSA 2026 focuses on assessing the digital operational resilience of CASPs, particularly in custody activities, to enhance supervisory convergence across the EU.

Who needs to participate in the CSA?

The CSA targets authorised Crypto Asset Service Providers (CASPs) that provide custody services.

What areas will the CSA examine?

The CSA will examine governance frameworks, management of keys, transaction controls, incident response, smart contracts, and third-party management.

When will the CSA be conducted?

The CSA will take place from the second half of 2026 to the first half of 2027.

What actions should CASPs take now?

CASPs should review and ensure their digital operational resilience frameworks meet the outlined requirements, in preparation for on-site or desk-based reviews.

How CX Financia Can Support You

CX Financia provides vital support through Regulatory Compliance and Risk Management services. We assist firms in aligning with CySEC’s requirements, ensuring your digital operational resilience frameworks meet the necessary standards. Contact us to ensure your firm is prepared.

Read the CySEC C794

Disclaimer

General information, not regulatory advice. Always consult with a professional advisor.

Close Menu