The Digital Operational Resilience Act became applicable on January 17, 2025. Crypto-asset service providers authorized in the European Union are financial entities under the regulation, which places them inside the same operational resilience perimeter as banks, payment institutions and trading venues. The obligation is not a policy document. It is a set of records that a supervisor can ask for at short notice.
The four pillars in scope
DORA sets out an ICT risk management framework owned by the management body, classification and reporting of ICT-related incidents with major incidents escalated to the competent authority, a digital operational resilience testing program, and management of ICT third-party risk supported by a register of information covering every contractual arrangement for the use of ICT services. Each pillar produces artifacts. The framework produces approved policies and a risk register. Incident management produces classified timelines. Testing produces scope documents, findings and remediation records. Third-party management produces due diligence files, contract terms, monitoring records and exit plans.
What the digital asset specifics look like
For a firm operating on public networks, the third-party population is wider than a traditional ICT inventory suggests. Node and RPC providers, indexers, oracles, bridges, custody technology vendors and chain analytics suppliers all sit on the critical path of a service that customers see. Each belongs in the register of information with a named owner, a criticality assessment and a documented exit plan that has been tested rather than described. Substitutability is the question a supervisor returns to: if a single RPC provider degrades, what happens to order flow, settlement confirmation and monitoring coverage.
Incident reporting clocks are the second specific. The reporting windows for major incidents do not pause for weekends, public holidays or maintenance periods, and public networks produce their largest movements outside European business hours. A rota that depends on best-effort on-call arrangements will miss the initial notification window in the cases that matter most. Continuous coverage with named escalation owners is the practical response, not an aspiration.
What an operations partner produces
Client Focus prepares the operating evidence a DORA file requires: incident timelines with hop-by-hop timestamps showing detection, validation, notification, acknowledgement and closure; access and change records tied to authorized tickets; supplier assessments and monitoring output for the ICT providers on the critical path; and continuity and resilience test results with the remediation that followed. The record is assembled as the work happens, not reconstructed after a request arrives.
The distinction supervisors draw is between a firm that can describe its controls and a firm that can evidence them on a specific date, for a specific incident, with a specific person accountable. DORA turns that distinction into a legal obligation.