Run
ITIL-based incident, problem and change management with named service owners and hop-by-hop timestamps on every escalation.
The Digital Operational Resilience Act has applied to European Union financial entities, including authorized crypto-asset service providers, since January 17, 2025. It converts resilience from a policy statement into a set of records a supervisor can request at short notice.
Overview
DORA is a European Union regulation on the operational resilience of financial entities and the information and communication technology they depend on. It has four operating pillars: an ICT risk management framework owned by the management body, classification and reporting of ICT-related incidents, a digital operational resilience testing program, and management of ICT third-party risk supported by a register of information.
For firms operating on blockchain networks, the third-party population is wider than a traditional technology inventory suggests. Node and RPC providers, indexers, oracles, bridges, custody technology vendors and analytics suppliers all sit on the critical path of a service customers see, so each belongs in the register with a named owner and a tested exit plan.

Obligations
Each obligation is stated with the operating consequence and the evidence a supervisor or auditor asks to see.
| Obligation | What it means for a digital asset operation | Evidence to produce |
|---|---|---|
| ICT risk management framework | A documented framework covering the blockchain estate: nodes, validators, RPC paths, key management and the integrations behind settlement. | Approved framework, risk register, management body minutes and annual review record. |
| Incident classification and major-incident reporting | Severity assignment at the moment of detection, with reporting windows that run through weekends because public networks do not close. | Classified incident timelines with hop-by-hop timestamps, notification records and submitted reports. |
| Digital operational resilience testing | Scenario testing of node failover, RPC provider loss, signing path compromise and chain reorganization handling. | Test scope, results, findings and remediation tracking to closure. |
| ICT third-party risk management | Due diligence and ongoing monitoring of chain infrastructure and analytics suppliers, with substitutability assessed rather than assumed. | Supplier assessments, contract terms, monitoring records and exit plans that have been exercised. |
| Register of information | A maintained inventory of every contractual arrangement for ICT services supporting the on-chain service. | Register extract in the reporting format, with criticality and owner per entry. |
| Business continuity and response | Continuity plans that assume continuous network operation and staffed escalation at every hour. | Continuity test results, staffing records and post-incident reviews. |
Timeline
Regulation (EU) 2022/2554 enters into force.
DORA becomes applicable to in-scope financial entities.
Registers of information reported and major-incident reporting in routine use.
Annual framework review, testing program and third-party monitoring cycles.
Support
ITIL-based incident, problem and change management with named service owners and hop-by-hop timestamps on every escalation.
Continuous monitoring, analyst validation and a published notification clock, with incident records retained for reporting.
Control frameworks, separation of duties and the due-diligence pack supervisors and procurement teams ask for.
Related
Terms used on this page are defined in the digital asset operations glossary.
Whether you are designing a new system, running one in production, or defending one, Client Focus brings engineering, network operations and security operations under one accountable model. Every request is reviewed by a principal of the firm.