DORA for Crypto-Asset Service Providers (CASPs)
Crypto-asset service providers (CASPs)authorised under MiCA, and issuers of asset-referenced tokens, are within DORA's scope under Article 2. As newly regulated entities they must build DORA compliance alongside MiCA authorisation, covering all five pillars. DORA has applied since 17 January 2025.
MiCA and DORA together
MiCA governs authorisation and conduct for crypto-asset services; DORA governs their digital operational resilience. CASPs typically face both at once, often from a lower compliance baseline than incumbent financial entities. See our DORA vs MiCA overlap.
Where CASPs are exposed
- Custody and key-management systems as critical, high-integrity ICT assets.
- Heavy reliance on ICT third parties (cloud, node infrastructure, custody tech).
- Security and resilience testing of production systems.
Getting started
Stand up the ICT risk-management framework, inventory third parties into the register of information, and benchmark with the best DORA auditors for crypto.
Supervisors are already looking at custody
Custody is the part of a CASP's operation supervisors are testing first. ESMA's Common Supervisory Action running from the second half of 2026 through the first half of 2027 has national competent authorities reviewing how CASPs apply DORA's ICT risk-management and third-party rules specifically to custody, key management, and exit strategy for custody technology. See our coverage of the review for what it tests and how to prepare. Firms that treat custody infrastructure, cold and hot wallets, signing devices, key shards, as any other ICT asset rather than as a critical function in its own right are the ones most likely to be flagged.
Information sharing: an optional pillar CASPs can use early
Unlike the other four pillars, information sharing under Article 45 is voluntary, and it is one of the fastest ways a newly regulated CASP can raise its detection capability without waiting for a mature in-house programme. Most crypto firms join an existing arrangement rather than building one: FS-ISAC is the most widely used cross-border option and publishes guidance mapping its membership to Article 45, though sector-specific crypto threat-sharing channels remain less established than banking ones. Joining is not paperwork-free. The arrangement itself needs documented rules of conduct covering confidentiality and GDPR, and the CASP must notify its competent authority when it joins, and again if it leaves. See our deep dive on Article 45 for the notification mechanics and how to weigh a global ISAC against a national scheme.
Frequently asked questions
Are CASPs really covered by DORA?
Yes. Crypto-asset service providers and asset-referenced-token issuers authorised under MiCA are listed financial entities under DORA Article 2.
Do CASPs have to comply with both MiCA and DORA?
Yes. MiCA covers authorisation and conduct; DORA covers ICT operational resilience. The obligations are complementary.
What is the hardest part of DORA for crypto firms?
Often the third-party register and formalised governance, since many crypto firms rely on numerous ICT providers and start from a lighter compliance base.
What is ESMA's custody supervisory action checking for?
A Common Supervisory Action running from H2 2026 through H1 2027 that reviews how CASPs apply DORA's ICT risk-management and third-party rules to custody operations, key management, and exit strategy.
Do CASPs have to join a threat-information-sharing arrangement?
No. Article 45 information sharing is voluntary, but many CASPs join anyway, most often through FS-ISAC, since it can raise detection capability quickly. Joining requires a documented arrangement and a notification to the competent authority.