What CySEC is checking
The regulator is zeroing in on how firms hold client assets and the tech that keeps their platforms running. Custody risks cover everything from private key management to whether a firm actually controls the coins it says it holds. Infrastructure risks are about the systems underneath—servers, databases, backup protocols, and how a company handles an outage or a breach.
This isn't a broad compliance sweep. It's a focused look at two areas that can sink a crypto business if they go wrong. CySEC hasn't spelled out the exact checklist, but firms should expect questions about cold wallet storage, segregation of client funds, and disaster recovery plans.
How the reviews will work
There are two tracks here. On-site inspections mean examiners will physically visit the firms' offices—checking equipment, interviewing staff, and watching how processes work in real time. Desk-based reviews are the paperwork side: CySEC will pull records, audit logs, and policies from a distance, then compare what's written down against what's actually happening.
For a small island regulator, that's a heavy lift. Cyprus has a fair number of crypto firms registered under the EU's Markets in Crypto-Assets regulation, and the MiCA framework is still being rolled out across member states. This inspection cycle looks like an attempt to make sure the firms that chose Cyprus as their home base are actually meeting the standards.
Timeline
The program kicks off in the latter half



