Skip to content
Client Focus

Regulatory readiness

Regulatory readiness reference

Four regimes shape how institutions operate on blockchain networks. Each reference sets out who is in scope, the operational obligations behind the rules, the evidence a supervisor asks for and the dates that matter.

Hands annotating a printed regulatory document with a pen on a desk

Regimes covered

These pages describe operating practice. Primary sources are linked on every page so the underlying text can be read directly.

DORA: digital operational resilience for digital asset operations

The Digital Operational Resilience Act has applied to European Union financial entities, including authorized crypto-asset service providers, since January 17, 2025. It converts resilience from a policy statement into a set of records a supervisor can request at short notice.

MiCA: authorization and the operating obligations behind the license

The Markets in Crypto-Assets Regulation created a single European Union authorization regime for crypto-asset service providers and issuers. Authorization is an operating commitment rather than a one-time filing, and DORA supplies the resilience rules MiCA presumes.

The GENIUS Act: the control framework permitted stablecoin issuers must operate

Federal stablecoin legislation created a licensing regime for payment stablecoin issuers, with reserve, redemption, control and third-party oversight requirements. Implementing rules proposed in 2026 set out the control framework supervisors will examine.

US bank supervision: OCC, FDIC, Federal Reserve, FFIEC and NYDFS

United States banking agencies permit a range of digital asset activity, including node operation and custody, provided it is conducted in a safe and sound manner. The examination question is operational: where does the activity run, who administers it, and what is the record.

Last reviewed: August 22, 2026

How Client Focus supports regulatory readiness

Evidence is produced by the operating system of record rather than assembled after the fact. Run supplies the incident, problem and change record, Secure supplies detection and notification history, and Trust and compliance holds the control framework.

Run

ITIL-based operations with named service owners and hop-by-hop timestamps on every escalation.

Secure

Continuous monitoring with analyst validation and a published notification clock.

Trust and compliance

Control frameworks, separation of duties and the due-diligence pack requested by supervisors and procurement teams.

Prepare for supervisory review.

Client Focus maps operating controls to the regimes that apply to your services and provides the evidence supervisors ask for.