Skip to main content
DORA Auditor

DORA for Crypto-Asset Service Providers (CASPs)

Last updated: 2 authoritative sourcesDORA Auditor Editorial Team

Crypto-asset service providers (CASPs)authorised under MiCA, and issuers of asset-referenced tokens, are within DORA's scope under Article 2. As newly regulated entities they must build DORA compliance alongside MiCA authorisation, covering all five pillars. DORA has applied since 17 January 2025.

MiCA and DORA together

MiCA governs authorisation and conduct for crypto-asset services; DORA governs their digital operational resilience. CASPs typically face both at once, often from a lower compliance baseline than incumbent financial entities. See our DORA vs MiCA overlap.

Where CASPs are exposed

Getting started

Stand up the ICT risk-management framework, inventory third parties into the register of information, and benchmark with the best DORA auditors for crypto.

Supervisors are already looking at custody

Custody is the part of a CASP's operation supervisors are testing first. ESMA's Common Supervisory Action running from the second half of 2026 through the first half of 2027 has national competent authorities reviewing how CASPs apply DORA's ICT risk-management and third-party rules specifically to custody, key management, and exit strategy for custody technology. See our coverage of the review for what it tests and how to prepare. Firms that treat custody infrastructure, cold and hot wallets, signing devices, key shards, as any other ICT asset rather than as a critical function in its own right are the ones most likely to be flagged.

Information sharing: an optional pillar CASPs can use early

Unlike the other four pillars, information sharing under Article 45 is voluntary, and it is one of the fastest ways a newly regulated CASP can raise its detection capability without waiting for a mature in-house programme. Most crypto firms join an existing arrangement rather than building one: FS-ISAC is the most widely used cross-border option and publishes guidance mapping its membership to Article 45, though sector-specific crypto threat-sharing channels remain less established than banking ones. Joining is not paperwork-free. The arrangement itself needs documented rules of conduct covering confidentiality and GDPR, and the CASP must notify its competent authority when it joins, and again if it leaves. See our deep dive on Article 45 for the notification mechanics and how to weigh a global ISAC against a national scheme.

Frequently asked questions

Are CASPs really covered by DORA?
Do CASPs have to comply with both MiCA and DORA?
What is the hardest part of DORA for crypto firms?
What is ESMA's custody supervisory action checking for?
Do CASPs have to join a threat-information-sharing arrangement?

Sources

  1. Regulation (EU) 2022/2554 (DORA), EUR-Lex
  2. ESMA, Digital Operational Resilience Act (DORA)