
The Cyprus Securities and Exchange Commission (CySEC) plans to conduct on-site inspections and desk-based reviews of authorized crypto asset service providers (CASPs) from the second half of 2026 through mid-2027, with a stated emphasis on custody and infrastructure risks. The initiative aims to strengthen oversight of firms operating in Cyprus’ digital asset sector and bolster investor protection.
Inspection Timeline and Scope
CySEC’s program will combine on-site supervisory visits with desk-based examinations of authorized CASPs. The reviews are scheduled to roll out in H2 2026 and continue into mid-2027. The regulator is expected to assess how firms structure, manage, and report their crypto-asset activities, and whether their controls meet applicable regulatory standards.
Focus on Custody and Infrastructure Risks
The inspections will prioritize the safeguarding of client assets and the resilience of core operational systems. CySEC’s focus on custody and infrastructure risks underscores regulatory attention to how firms hold and protect digital assets, the robustness of their technology stacks, and the integrity of processes supporting trading, settlement, and recordkeeping.
Implications for Cyprus-Registered CASPs
Firms authorized by CySEC should anticipate closer scrutiny of governance, risk management, and operational resilience. Depending on findings, the supervisory cycle could result in remediation requirements and, where necessary, enforcement actions. CASPs are likely to benefit from reviewing their custody arrangements, security controls, incident response, and outsourcing oversight ahead of the inspections.
Broader Regulatory Context
As an EU member state, Cyprus aligns its financial supervision with evolving European standards for crypto-asset oversight, including the Markets in Crypto-Assets (MiCA) framework. CySEC’s inspection program reflects the region’s ongoing efforts to establish consistent safeguards for investors and ensure orderly market conduct in the digital asset industry.