Rules
DORA: digital operational resilience for crypto
Alongside MiCA, many financial and crypto firms are also subject to the Digital Operational Resilience Act (DORA), a European regulation setting requirements for IT security, incident management and dealing with external technology suppliers. Where MiCA is mainly about licensing and conduct, DORA is about whether an organisation is technically resilient enough to withstand outages and cyberattacks. This guide explains what that means and what you notice as a user.
What DORA actually regulates
DORA requires financial institutions, including MiCA-licensed crypto service providers, to set up a framework for ICT risk management. This covers identifying vulnerabilities, testing digital resilience, reporting serious ICT incidents to supervisors, and managing risks arising from outsourcing to external technology providers such as cloud providers.
An important element is that institutions must periodically test whether their systems withstand attacks and outages, with mandatory, more advanced testing for the largest and most critical firms. Contracts with critical external ICT suppliers must also meet specific requirements, so that a supplier's outage doesn't spread uncontrolled to end users.
- Mandatory framework for ICT risk management
- Periodic resilience testing, stricter for the largest firms
- Requirements for contracts with critical technology suppliers
What you notice as a user
For most users DORA is invisible background regulation: you won't see a separate 'DORA notice' on a platform. You do notice its effects indirectly, for example through clearer communication from licensed providers during outages, with timely updates on the cause and expected recovery time instead of long silence.
DORA can also lead a platform to temporarily disable or slow certain services when a serious security incident is suspected, precisely because it's required to respond carefully and investigate and report the incident before fully resuming the service.
- Clearer, more timely communication during outages
- Possible temporary disabling of services after a serious incident
- Invisible background testing that improves platform stability
Relation to MiCA and customer protection
DORA and MiCA complement each other: MiCA governs, among other things, what happens if client money is lost through negligence, while DORA focuses on preventing the outages and cyber incidents that can cause such losses. A provider complying with both regulations is thus bound by stricter rules on both conduct and technical resilience.
For users the practical result is that platforms subject to DORA generally have stricter internal procedures for access management, backups and contingency plans. This reduces the risk of prolonged downtime or data loss, though no system is ever fully infallible.
Who falls under DORA
DORA is broad in scope and affects not only crypto service providers but also banks, investment firms, payment institutions and, under conditions, their critical external ICT suppliers. For the crypto sector this means both the provider itself and the parties it technically relies on must meet certain resilience requirements.
Frequently asked questions
Can I see anywhere that a platform is DORA-compliant?
Not as a separate label; DORA mainly works in the background through internal processes and supervision, not through a visible seal on the website.
Does DORA prevent a platform from ever going down?
No, DORA reduces the risk of outages and improves how they are handled, but it doesn't guarantee fully outage-free operation.
Does DORA also apply to a crypto platform's cloud supplier?
Critical external ICT suppliers fall under the DORA framework under certain conditions, with specific requirements for the contracts providers sign with them.
What happens if a provider fails to report a serious ICT incident?
That is a breach of the regulation which the supervisor can enforce against, separate from any damage customers suffered from the incident itself.
Read next
What is MiCA?
MiCA governs licensing, stablecoins and disclosure for crypto across the EU. What changes for users, providers and banks.
Consumer rights at an EU-licensed crypto provider
What rights do you have with an EU-licensed crypto provider? Complaint procedures, dispute resolution, and what isn't protected.
MiCA in the Netherlands: AFM and DNB explained
How the Netherlands implements MiCA: the split between AFM and DNB, the transitional regime for existing providers, and how to verify a licence.