Skip to content

GLOSSARY · BLOCKCHAIN & WEB3

DORA (Digital Operational Resilience Act)

What DORA, Regulation (EU) 2022/2554, is: who it covers since 17 January 2025, its five pillars and what it means for crypto and crowdfunding providers.

WHAT IS IT? · FOR DUMMIES

DORA is an EU law requiring banks, authorised crypto exchanges, crowdfunding platforms and other financial firms to be ready for IT failures and cyberattacks. They must monitor and test their systems, report serious incidents to the supervisor and keep their technology suppliers under control.

WHAT IS IT? · PRO

DORA is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector: it requires banks, investment firms, crypto-asset service providers, crowdfunding platforms and other financial entities to manage technology risk under common rules across the EU. It has applied since 17 January 2025 and, like any EU regulation, is directly applicable in every Member State (art. 64).

Who it applies to. Art. 2(1) lists twenty types of financial entity (points a to t) and adds third-party information and communication technology (ICT) service providers (point u). For the crypto and tokenization sector, the most relevant are:

  • crypto-asset service providers authorised under MiCA and issuers of asset-referenced tokens (art. 2(1)(f));
  • crowdfunding service providers (art. 2(1)(s));
  • investment firms and trading venues (art. 2(1)(e) and (i)).

In its DORA FAQ, updated on 10 February 2026, the CNMV, Spain's securities regulator, confirms that among the entities it supervises the regulation covers crypto-asset service providers authorised under MiCA and crowdfunding service providers authorised under Regulation (EU) 2020/1503.

The five pillars.

  • ICT risk management: a sound, documented framework (art. 6), with the management body ultimately responsible for defining, approving and overseeing it (art. 5(2)).
  • Incidents: a process to detect, manage and report ICT-related incidents (art. 17) and reporting of major incidents to the competent authority (art. 19).
  • Testing: a digital operational resilience testing programme (art. 24) that may include vulnerability scans, source code reviews where feasible and penetration tests (art. 25(1)); some entities must carry out threat-led penetration testing at least every three years (art. 26).
  • Third-party risk: principles for contracting ICT services (art. 28), a register of information on all contracts with ICT providers (art. 28(3)) and minimum contractual clauses (art. 30).
  • Information sharing on cyber threats between entities, on a voluntary basis (art. 45).

Proportionality. The ICT risk management rules apply according to each entity's size, risk profile and complexity (art. 4). Some, such as small and non-interconnected investment firms, use a simplified framework (art. 16), and microenterprises have exemptions spread across the regulation, according to the CNMV.

DORA, the CASP licence and tokenization. Anyone applying for the CASP licence in Spain under MiCA becomes subject to DORA once authorised; the CASP test helps check whether a project needs that licence. DORA does not mention smart contracts, but its testing programme covers the entity's ICT systems, and on a tokenization platform that can include the contracts it uses: that is where a smart contract audit fits. The link with the crypto-asset framework is in the MiCA entry.

Official sources: Regulation (EU) 2022/2554, DORA (BOE); CNMV, DORA FAQ (10 February 2026). Framework verified as of 2 October 2026.

01 / Key points

  • Regulation (EU) 2022/2554, applicable since 17 January 2025 (art. 64)
  • Covers crypto-asset service providers authorised under MiCA and crowdfunding platforms (art. 2(1)(f) and (s))
  • Five pillars: ICT risk management, incidents, testing, third-party risk and information sharing
  • The management body is ultimately responsible for ICT risk (art. 5(2))
  • Applied proportionately: a simplified framework and exemptions for smaller entities (arts. 4 and 16)

02 / Advantages

  • Common rules across the EU, with no separate law in each country
  • More trust from customers and investors in service continuity
  • Supplier control: contracts with minimum clauses and a register of all ICT services

03 / Disadvantages

  • Compliance cost: framework, testing, register and reporting
  • Paperwork for small entities, even with proportionality
  • Third-party dependence: contracts with ICT providers have to be reviewed and renegotiated