DORA for Crypto Firms: ICT Risk and Incident Reporting Explained
DORA for crypto firms explained: who it applies to, the five pillars, what CASPs must build, cost and penalties, and how DORA fits alongside MiCA.
Key takeaways 5
- DORA applies to all CASPs Crypto-asset service providers and issuers of asset-referenced tokens are explicitly in scope under DORA from 17 January 2025.
- Five pillars govern operational resilience DORA is built on ICT risk management, incident reporting, resilience testing, third-party risk and voluntary information sharing.
- Major incidents must be reported CASPs must classify ICT incidents and report major ones directly to the competent authority under DORA's incident management pillar.
- DORA readiness costs 2-5 million euro A Deloitte survey found 64% of financial entities expected to spend 2 to 5 million euro on DORA compliance readiness.
- Penalties reach 2% of turnover Breaches carry penalties of up to 2% of annual worldwide turnover, with personal liability for senior managers in serious cases.
MiCA is not the only EU regulation a crypto business must meet. The Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) applies to financial entities, including crypto-asset service providers, from 17 January 2025. It governs how you manage technology risk, report incidents and oversee your ICT vendors. This article explains what DORA requires of crypto firms and what you have to build.
For the obligation checklist see our MiCA compliance checklist, and for the build see our MiCA compliance software development.
What is DORA?
DORA is the EU rulebook for digital operational resilience in financial services. Where MiCA covers conduct and authorisation, DORA covers whether your systems can withstand, respond to and recover from ICT disruptions. The two run in parallel, and a CASP must satisfy both.
Who DORA applies to
DORA applies to a broad set of financial entities, and crypto-asset service providers and issuers of asset-referenced tokens are explicitly in scope. Critical ICT third-party providers to those entities also fall under a dedicated EU oversight framework.
The five pillars of DORA

| Pillar | What it requires |
|---|---|
| ICT risk management | A governance framework to identify, protect, detect, respond and recover |
| Incident management and reporting | Classify ICT incidents and report major ones to the competent authority |
| Digital operational resilience testing | Regular testing, with threat-led penetration testing for significant entities |
| ICT third-party risk | A register of information on ICT providers and contractual safeguards |
| Information sharing | Voluntary sharing of cyber-threat intelligence |
What CASPs must build
- An ICT-risk management framework with clear ownership and policies
- Incident classification and reporting workflows for major ICT incidents
- A maintained register of information for every ICT third-party provider
- Resilience testing schedules and evidence, including penetration testing
- Business continuity and recovery plans tied to your MiCA safeguarding obligations
DORA cost and penalties
DORA is a material budget line. In a Deloitte survey, 64% of financial entities expected to spend 2 to 5 million euro on DORA readiness. Breaches carry penalties of up to 2% of annual worldwide turnover, with personal liability for senior managers in serious cases.
How DORA fits with MiCA
Treat DORA and MiCA as one program, not two. The incident-reporting, third-party register and resilience-testing evidence DORA wants should write to the same immutable audit trail as your MiCA controls, so a regulator sees one coherent system. Build the gap assessment against MiCA, the Transfer of Funds Regulation and DORA together.
Pharos Production builds MiCA compliance software with DORA ICT-risk and incident-reporting workflows where they apply. See the cost breakdown or request a gap assessment.
FAQ
Quick answers to common questions about custom software development, pricing, process and technology.
Type to filter questions and answers. Use Topic to narrow the list.
Showing all 5
No matches
Try a different keyword, change the topic or clear filters
-
Yes. The Digital Operational Resilience Act applies to financial entities including crypto-asset service providers and issuers of asset-referenced tokens, from 17 January 2025.
Critical ICT third-party providers to those firms are also in scope.
-
ICT risk management, incident management and reporting, digital operational resilience testing, ICT third-party risk management and information sharing on cyber threats.
-
DORA breaches carry administrative penalties of up to 2% of annual worldwide turnover, with personal liability for senior managers in serious cases. The exact penalty is set by your national competent authority.
-
It varies by size. In a Deloitte survey, 64% of financial entities expected to spend 2 to 5 million euro on DORA readiness. Building DORA evidence into the same system as your MiCA controls keeps the cost down.
DORA and ICT resilience glossary 5
- DORA
- Regulation (EU) 2022/2554, the EU rulebook for digital operational resilience in financial services, applicable from 17 January 2025.
- CASP
- Crypto-asset service provider - a financial entity explicitly in scope of both DORA and MiCA under EU regulation.
- ICT risk management
- A DORA pillar requiring a governance framework to identify, protect, detect, respond to and recover from technology disruptions.
- Threat-led penetration testing
- Advanced resilience testing required under DORA for significant entities to simulate real-world cyberattack scenarios.
- ICT third-party risk
- A DORA pillar requiring a maintained register of all ICT providers and contractual safeguards governing those relationships.
I work with startup founders who need a dedicated software development team but don’t want to gamble on hiring, random outsourcing, or opaque delivery.
Most founders face the same problem sooner or later.
Early technical and team decisions lock the product into tech debt, slow delivery, missed milestones and constant re-hiring. By the time this becomes visible, fixing it is already expensive.As a CTO and software architect, I help founders design, build and run dedicated development teams that work as a true extension of the startup. Not as a black-box vendor.
My focus is on complex products where mistakes are costly:
- Web3 and blockchain platforms
- FinTech and regulated products
- High-load startup systems
- MVP → scale transitions
We don’t do body-shopping.
We don’t sell generic outsourcing.Instead, we help founders:
- build the right team structure from day one
- keep technical ownership and transparency
- scale delivery without losing control
- avoid vendor lock-in and hidden risks
Teams are aligned with the product roadmap, business goals and long-term architecture. Not just short-term velocity.