The Cyprus Securities and Exchange Commission (CySEC) will initiate a series of on-site and documentary inspections targeting authorized Crypto-Asset Service Providers (CASPs), as part of broader European efforts to strengthen operational resilience in the digital asset custody sector.
In a circular sent to regulated companies, CySEC Chairman George Theocharides stated that the regulator is preparing to audit a representative sample of local cryptocurrency organizations under the "Common Supervisory Action for 2026," coordinated by the European Securities and Markets Authority (ESMA).
This enforcement initiative, scheduled for the second half of 2026 through the first half of 2027, marks a significant intensification of direct regulatory oversight over crypto companies operating in Cyprus.
The inspections will focus on licensed CASPs authorized to provide digital asset custody services. Regulators aim to assess the maturity of these companies' operational security and technical infrastructure, with a particular focus on risks related to distributed ledger technology.
CySEC indicated that the supervisory checks will examine key areas of operational resilience, including governance and control systems, as well as key and wallet custody management. The regulator will also review security protocols governing the use of private keys, wallet storage, and access controls.
Other areas subject to review include transaction controls, incident monitoring and response, smart contract security, and third-party risk management.
This initiative aligns CySEC's actions with those of national competent authorities across the European Union and directly corresponds to ESMA's risk-based supervisory priorities. EU regulators have repeatedly identified operational resilience and digital asset custodians as high-risk areas crucial for financial stability and investor protection.
By establishing a standardized system for conducting on-site inspections and documentary audits, ESMA and national regulators aim to foster supervisory convergence among member states and ensure uniform security requirements as the crypto ecosystem further integrates with the traditional financial sector.
CySEC, which issued a consultation paper at the end of 2025 proposing a new prudential reporting directive for crypto-asset service providers, has warned local companies that the standards outlined in the circular are mandatory. The regulator stated that compliance readiness will serve as a starting point for selecting CASPs for the upcoming inspections.





