
Regulatory briefings / Covers: January 2025
DORA is in force: what crypto-asset service providers must now evidence
From January 17, 2025 the Digital Operational Resilience Act applies to crypto-asset service providers as financial entities.
As national transition periods under MiCA ran through 2025, firms discovered that authorization is an operating commitment, not a one-time filing.
The Markets in Crypto-Assets Regulation set a single authorization regime for crypto-asset service providers across the European Union, with national transition arrangements running through 2025. Firms that concentrated on the application file learned during that period that the license is the start of a continuing obligation. Supervisors examine how the service is operated, not how it was described.
Providers holding client crypto-assets must segregate them from their own, maintain records that allow client positions to be identified at any moment, and manage the keys that control those assets under documented procedures. The practical test is reconstruction: can the firm show, for an arbitrary past date, which client held which asset, where the keys were held, and who had authority to move them.
Acting honestly, fairly and professionally in clients' interests translates into disclosure of terms, fees and risks, order handling and best execution practices where relevant, and a complaints handling procedure with recorded outcomes and timelines. Complaints data is one of the first datasets a supervisor asks for, because it reveals operating problems before incident reports do.
Management bodies must have appropriate knowledge and dedicate sufficient time to the activity. Outsourcing does not transfer responsibility: the provider remains accountable for outsourced functions and must be able to supervise them. Incidents must be handled through a defined process with records that support notification to clients and authorities.
MiCA presumes operational resilience without specifying most of it. DORA supplies that layer: the ICT risk management framework, incident classification and reporting, resilience testing and the register of ICT third-party arrangements. A firm treating the two regimes as separate projects duplicates work and creates inconsistent records. A firm treating them as one operating model produces a single evidence set that answers both.
Custody records that reconstruct client positions and key control by date. Written operational procedures for issuance, transfer, withdrawal and exception handling, versioned and approved. Incident logs with classification, timestamps, notification decisions and named owners. An outsourcing and ICT third-party register with criticality, monitoring output and tested exit plans. Complaints records with resolution times. Continuity and testing results with remediation tracked to closure.
None of these are novel to financial services. What is novel is applying them to infrastructure the firm does not own, on networks that operate continuously. That is an operations problem, and it is solved with staffing, clocks and records rather than with additional policy text.

Related insights

Regulatory briefings / Covers: January 2025
From January 17, 2025 the Digital Operational Resilience Act applies to crypto-asset service providers as financial entities.

Regulatory briefings / Covers: July 2025 to August 2026
The House passed the CLARITY Act in July 2025; Senate consideration continued through 2026.

Perspectives / Covers: 2025
Regulation arrived, losses concentrated, and banks moved to public networks. The common thread was accountability for operations.
Client Focus reviews the estate, the coverage required and the gaps, then sets out what changes.