---
title: "DORA (Digital Operational Resilience Act)"
url: "https://www.unknowngravity.com/en/glosario/dora-resiliencia-operativa-digital"
site: Unknown Gravity
published: "2026-10-03T00:52:40+00:00"
modified: "2026-10-03T00:52:40+00:00"
language: en-US
description: "DORA is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector: it requires banks, investment firms, crypto-asset service providers, crowdfunding platforms and other…"
section: "Home > DORA (Digital Operational Resilience Act)"
---

# DORA (Digital Operational Resilience Act)

**DORA is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector: it requires banks, investment firms, crypto-asset service providers, crowdfunding platforms and other financial entities to manage technology risk under common rules across the EU.** It has applied since 17 January 2025 and, like any EU regulation, is directly applicable in every Member State (art. 64).

**Who it applies to.** Art. 2(1) lists twenty types of financial entity (points a to t) and adds third-party information and communication technology (ICT) service providers (point u). For the crypto and tokenization sector, the most relevant are:

- crypto-asset service providers authorised under MiCA and issuers of asset-referenced tokens (art. 2(1)(f));
- crowdfunding service providers (art. 2(1)(s));
- investment firms and trading venues (art. 2(1)(e) and (i)).

In its DORA FAQ, updated on 10 February 2026, the CNMV, Spain's securities regulator, confirms that among the entities it supervises the regulation covers crypto-asset service providers authorised under MiCA and crowdfunding service providers authorised under Regulation (EU) 2020/1503.

**The five pillars.**

- **ICT risk management:** a sound, documented framework (art. 6), with the management body ultimately responsible for defining, approving and overseeing it (art. 5(2)).
- **Incidents:** a process to detect, manage and report ICT-related incidents (art. 17) and reporting of major incidents to the competent authority (art. 19).
- **Testing:** a digital operational resilience testing programme (art. 24) that may include vulnerability scans, source code reviews where feasible and penetration tests (art. 25(1)); some entities must carry out threat-led penetration testing at least every three years (art. 26).
- **Third-party risk:** principles for contracting ICT services (art. 28), a register of information on all contracts with ICT providers (art. 28(3)) and minimum contractual clauses (art. 30).
- **Information sharing** on cyber threats between entities, on a voluntary basis (art. 45).

**Proportionality.** The ICT risk management rules apply according to each entity's size, risk profile and complexity (art. 4). Some, such as small and non-interconnected investment firms, use a simplified framework (art. 16), and microenterprises have exemptions spread across the regulation, according to the CNMV.

**DORA, the CASP licence and tokenization.** Anyone applying for the [CASP licence in Spain under MiCA](/en/articulos/casp-license-spain-mica) becomes subject to DORA once authorised; the [CASP test](/en/test-casp) helps check whether a project needs that licence. DORA does not mention smart contracts, but its testing programme covers the entity's ICT systems, and on a tokenization platform that can include the contracts it uses: that is where a [smart contract audit](/en/servicios/blockchain-security-audits) fits. The link with the crypto-asset framework is in the [MiCA](/en/glosario/mica-reglamento-criptoactivos) entry.

**Official sources:** [Regulation (EU) 2022/2554, DORA (BOE)](https://www.boe.es/buscar/doc.php?id=DOUE-L-2022-81962); [CNMV, DORA FAQ (10 February 2026)](https://www.cnmv.es/DocPortal/Ciberseguridad/FAQ_DORA.pdf). *Framework verified as of 2 October 2026.*
