Skip to content
Client Focus

Insights

DORA is in force: what crypto-asset service providers must now evidence

From January 17, 2025 the Digital Operational Resilience Act applies to crypto-asset service providers as financial entities.

Regulatory briefings

Published
August 22, 2026
Covers
January 2025
Reading time
6 minutes
By
Client Focus

The Digital Operational Resilience Act became applicable on January 17, 2025. Crypto-asset service providers authorized in the European Union are financial entities under the regulation, which places them inside the same operational resilience perimeter as banks, payment institutions and trading venues. The obligation is not a policy document. It is a set of records that a supervisor can ask for at short notice.

The four pillars in scope

DORA sets out an ICT risk management framework owned by the management body, classification and reporting of ICT-related incidents with major incidents escalated to the competent authority, a digital operational resilience testing program, and management of ICT third-party risk supported by a register of information covering every contractual arrangement for the use of ICT services. Each pillar produces artifacts. The framework produces approved policies and a risk register. Incident management produces classified timelines. Testing produces scope documents, findings and remediation records. Third-party management produces due diligence files, contract terms, monitoring records and exit plans.

What the digital asset specifics look like

For a firm operating on public networks, the third-party population is wider than a traditional ICT inventory suggests. Node and RPC providers, indexers, oracles, bridges, custody technology vendors and chain analytics suppliers all sit on the critical path of a service that customers see. Each belongs in the register of information with a named owner, a criticality assessment and a documented exit plan that has been tested rather than described. Substitutability is the question a supervisor returns to: if a single RPC provider degrades, what happens to order flow, settlement confirmation and monitoring coverage.

Incident reporting clocks are the second specific. The reporting windows for major incidents do not pause for weekends, public holidays or maintenance periods, and public networks produce their largest movements outside European business hours. A rota that depends on best-effort on-call arrangements will miss the initial notification window in the cases that matter most. Continuous coverage with named escalation owners is the practical response, not an aspiration.

What an operations partner produces

Client Focus prepares the operating evidence a DORA file requires: incident timelines with hop-by-hop timestamps showing detection, validation, notification, acknowledgement and closure; access and change records tied to authorized tickets; supplier assessments and monitoring output for the ICT providers on the critical path; and continuity and resilience test results with the remediation that followed. The record is assembled as the work happens, not reconstructed after a request arrives.

The distinction supervisors draw is between a firm that can describe its controls and a firm that can evidence them on a specific date, for a specific incident, with a specific person accountable. DORA turns that distinction into a legal obligation.

Hands annotating a printed regulatory document with a pen on a desk

Continue reading

Compliance analysts reviewing documentation in a meeting room

MiCA authorization for crypto-asset service providers: the operating obligations behind the license

As national transition periods under MiCA ran through 2025, firms discovered that authorization is an operating commitment, not a one-time filing.

Printed operational reports and a notebook on a desk in daylight

The GENIUS Act implementing rules: the control framework supervisors will examine

The OCC proposed rules in February 2026 and the FDIC in April 2026 setting capital, liquidity, reserve and risk-management requirements for permitted issuers.

Printed operational reports and a notebook on a desk in daylight

2025 in review: the year digital assets became an operations problem

Regulation arrived, losses concentrated, and banks moved to public networks. The common thread was accountability for operations.

Apply this to your own operations.

Client Focus reviews the estate, the coverage required and the gaps, then sets out what changes.