Skip to content
Client Focus

Regulatory readiness

DORA: digital operational resilience for digital asset operations

The Digital Operational Resilience Act has applied to European Union financial entities, including authorized crypto-asset service providers, since January 17, 2025. It converts resilience from a policy statement into a set of records a supervisor can request at short notice.

What the regime is

DORA is a European Union regulation on the operational resilience of financial entities and the information and communication technology they depend on. It has four operating pillars: an ICT risk management framework owned by the management body, classification and reporting of ICT-related incidents, a digital operational resilience testing program, and management of ICT third-party risk supported by a register of information.

For firms operating on blockchain networks, the third-party population is wider than a traditional technology inventory suggests. Node and RPC providers, indexers, oracles, bridges, custody technology vendors and analytics suppliers all sit on the critical path of a service customers see, so each belongs in the register with a named owner and a tested exit plan.

Who it applies to

  • Crypto-asset service providers authorized under MiCA, as financial entities.
  • Credit institutions, payment institutions, electronic money institutions and investment firms.
  • Trading venues, central securities depositories and other supervised market infrastructure.
  • ICT third-party providers serving those entities, including providers designated as critical.

Last reviewed: August 22, 2026

Hands annotating a printed regulatory document with a pen on a desk

What the rules require in operation

Each obligation is stated with the operating consequence and the evidence a supervisor or auditor asks to see.

Obligations, operational meaning and evidence for DORA
ObligationWhat it means for a digital asset operationEvidence to produce
ICT risk management frameworkA documented framework covering the blockchain estate: nodes, validators, RPC paths, key management and the integrations behind settlement.Approved framework, risk register, management body minutes and annual review record.
Incident classification and major-incident reportingSeverity assignment at the moment of detection, with reporting windows that run through weekends because public networks do not close.Classified incident timelines with hop-by-hop timestamps, notification records and submitted reports.
Digital operational resilience testingScenario testing of node failover, RPC provider loss, signing path compromise and chain reorganization handling.Test scope, results, findings and remediation tracking to closure.
ICT third-party risk managementDue diligence and ongoing monitoring of chain infrastructure and analytics suppliers, with substitutability assessed rather than assumed.Supplier assessments, contract terms, monitoring records and exit plans that have been exercised.
Register of informationA maintained inventory of every contractual arrangement for ICT services supporting the on-chain service.Register extract in the reporting format, with criticality and owner per entry.
Business continuity and responseContinuity plans that assume continuous network operation and staffed escalation at every hour.Continuity test results, staffing records and post-incident reviews.

Key dates

  1. December 2022

    Regulation (EU) 2022/2554 enters into force.

  2. January 17, 2025

    DORA becomes applicable to in-scope financial entities.

  3. 2025 onward

    Registers of information reported and major-incident reporting in routine use.

  4. Ongoing

    Annual framework review, testing program and third-party monitoring cycles.

How Client Focus supports it

Run

ITIL-based incident, problem and change management with named service owners and hop-by-hop timestamps on every escalation.

Secure

Continuous monitoring, analyst validation and a published notification clock, with incident records retained for reporting.

Trust and compliance

Control frameworks, separation of duties and the due-diligence pack supervisors and procurement teams ask for.

Prepare for supervisory review.

Whether you are designing a new system, running one in production, or defending one, Client Focus brings engineering, network operations and security operations under one accountable model. Every request is reviewed by a principal of the firm.