Logo
Compliance · Blockchain · Standards

DORA for Crypto and Web3 Companies: What You Need to Comply

26/09/2026
European Parliament hemicycle in Brussels — DORA regulation applies to crypto service providers

Image: "European Parliament Hemicycle, Brussels" by Profpcde, CC0

The Digital Operational Resilience Act — Regulation (EU) 2022/2554 — has applied since 17 January 2025. Unlike earlier EU financial rules, DORA explicitly names crypto-asset service providers (CASPs) authorized under MiCA as in-scope entities. If you operate a custodial wallet, exchange, or token service in the EU, DORA compliance is not optional — and its requirements reach deep into how you build and run infrastructure.

Who Is in Scope

DORA covers virtually every regulated financial entity: banks, payment institutions, investment firms, insurers — and CASPs. For Web3, the bright line is MiCA authorization: a CASP licensed under MiCA is automatically a DORA "financial entity". Pure DeFi protocols without a central operator sit outside the perimeter today, but any centralized front-end, custodian, or fiat on-ramp pulls the operation in. Their critical ICT vendors — cloud providers, node infrastructure, custody tech — fall under DORA's third-party regime too.

The Five Pillars

  1. ICT risk management and governance. A documented risk framework approved by the management body, with assigned accountability, asset inventory, and regular review — not a policy PDF that lives in a drawer.
  2. Incident management and reporting. Classification of ICT incidents by severity, with mandatory reporting of major incidents to the competent authority on tight deadlines — initial notification as early as 4 hours after classification under the RTS.
  3. Digital operational resilience testing. A risk-based testing program: vulnerability scans, scenario testing, and — for significant entities — threat-led penetration testing (TLPT) at least every three years. For crypto firms this means, at minimum, testing key-management and signing-path resilience.
  4. ICT third-party risk. A maintained register of information covering every ICT vendor contract, mandatory contractual clauses (audit rights, exit plans, subcontracting rules), and concentration-risk assessment. Cloud providers and smart-contract auditors both belong in the register.
  5. Information sharing. Optional participation in cyber-threat intelligence sharing arrangements between financial entities.

Where Smart Contracts Fit

DORA doesn't mention smart contracts by name, but they sit squarely inside the ICT risk framework for a CASP: a deployed contract is a critical function whose compromise is a reportable ICT incident. Practically, that means: audits belong in the resilience-testing program, audit vendors go in the register of information, key-management compromise scenarios belong in incident classification, and upgrade/multisig governance must be documented as part of the risk framework. See our DORA service overview for how we structure this work.

DORA, MiCA, NIS2, GDPR: How They Interlock

MiCA grants the license; DORA governs operational resilience. NIS2 applies to CASPs in parallel as "digital providers" in several member states, and GDPR still covers personal data on top. The overlap is real but manageable: DORA's register of information and incident reporting flow largely subsume NIS2's for financial entities (DORA is lex specialis where they conflict). The sensible approach is one integrated risk framework mapped to all four regimes, not four parallel programs.

A Practical First Pass

  1. Confirm scope. If you hold or are seeking MiCA authorization, you're in.
  2. Gap-assess the risk framework. Map existing security policies against DORA Chapter II requirements.
  3. Build the register of information. Inventory every ICT vendor and contract — most CASPs discover they have none.
  4. Set up incident classification. Define thresholds and reporting workflows before an incident forces the question.
  5. Schedule testing. Establish the resilience-testing calendar, including smart-contract audit cadence and TLPT if you're a significant entity.

A quick starting point: our free Blockchain Compliance Checker gives a structured readiness snapshot across DORA, MiCA, and AML requirements — useful as a first-pass baseline before a deeper DORA implementation engagement.

Frequently Asked Questions

Does DORA apply to crypto companies?

Yes — crypto-asset service providers authorized under MiCA are explicitly listed as financial entities under Article 2. Unlicensed pure-DeFi protocols are outside the perimeter, but any centralized custodian, exchange, or on-ramp operating in the EU is in scope.

When did DORA take effect?

DORA entered into force on 16 January 2023 and has applied since 17 January 2025. There is no transition period left — obligations are live now.

What is the register of information?

A mandatory, maintained register of all contractual arrangements with ICT third-party service providers — vendors, scope, criticality, data locations, subcontracting chains. Supervisors can request it at any time, and missing it is a common first finding in supervisory reviews.

How does DORA interact with smart contract audits?

Audits fit into the resilience-testing pillar: contract audits and security testing form part of the testing program, audit firms are ICT vendors in the register, and a contract exploit is a reportable ICT incident if it disrupts a critical function.

Related Insights

Privacy & Cookie Preferences

We use cookies to enhance your experience, analyze site performance, and support our marketing efforts. Your privacy matters, and you can withdraw consent at any time.