What DORA requires from crypto-asset service providers

DORA is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector, and it applies to crypto-asset service providers authorised under MiCA. It requires an ICT risk management framework, reporting of major incidents to the supervisor, regular resilience testing and strict control of ICT third-party providers. It has applied since 17 January 2025 and does not give these providers the simplified regime available to some other small entities. In Spain, the CNMV supervises it. The European Securities and Markets Authority launched a common supervisory action on 8 July 2026 on their operational resilience in custody, which national authorities are carrying out until the first half of 2027.

Table of contents

Who DORA applies to in the crypto sector and since when

DORA covers crypto-asset service providers authorised under MiCA, under its article 2.1.f, and issuers of asset-referenced tokens. It has applied since 17 January 2025. The obligation starts with authorisation, so during the transitional period, which ended in Spain on 1 July 2026, providers operating without MiCA authorisation were not subject to DORA.

Since 1 July, anyone providing crypto-asset services in Spain is either authorised or a financial entity doing so by notification, and the latter were already subject to DORA in their own right. In practice, the whole sector is now covered.

Article 16 provides a simplified ICT risk management framework for some small entities, such as small and non-interconnected investment firms or certain exempted payment institutions. Crypto-asset service providers are not on that list. They apply the full framework of articles 5 to 15, although in proportion to their size, risk profile and the nature of their services, as article 4 requires.

DORA’s five blocks of obligations applied to a CASP

DORA organises its obligations into five blocks. For a crypto-asset service provider, each one translates into specific documents and processes that the CNMV can request.

BlockArticlesWhat it means for a crypto-asset provider
ICT risk management5 to 15The management body approves the framework and is accountable for it. Inventory of ICT assets, protection, detection, response, backups and business continuity
Incidents17 to 23Process to detect, classify and record incidents, and reporting of major ones to the CNMV
Resilience testing24 to 27Testing programme for systems. Threat-led penetration testing only for entities identified by the authority
ICT third-party risk28 to 30Third-party risk strategy, register of information on all ICT contracts and minimum clauses in each contract
Information sharing45Voluntary arrangements between entities to share cyber threat information

Reporting major incidents within 4 hours, 72 hours and one month

A major ICT-related incident is reported to the CNMV in three stages. The initial notification is sent within four hours of classifying it as major and no later than twenty-four hours after becoming aware of it. The intermediate report follows within seventy-two hours of the initial notification. The final report, within one month of the last intermediate report. The deadlines are set in article 5 of Delegated Regulation (EU) 2025/301.

If a deadline falls on a weekend or public holiday, the provider may submit the notification before 12:00 on the next working day. That rule does not apply to some entities, including those considered essential or important under the NIS2 Directive.

Custody and private keys, the supervisory focus in 2026

The common supervisory action announced by the European Securities and Markets Authority on 8 July 2026 assesses the maturity of crypto-asset service providers’ digital operational resilience frameworks in relation to custody. National authorities apply it to a risk-based sample of authorised providers, from the second half of 2026 to the first half of 2027. Its findings will be gathered in a final report in the second half of 2027.

The European authority highlights the risks specific to distributed ledger technology that it will review:

  • Custody governance
  • Management and storage of cryptographic keys
  • Transaction controls
  • Incident detection and response
  • Smart contract risks
  • Dependence on third-party providers

For a provider holding clients’ crypto-assets, these are the points where documentation should be up to date before a request arrives.

Contracts with ICT providers

Every contract with an ICT provider must include minimum content, set out in article 30.2 of DORA:

  • A description of the services and the conditions for subcontracting
  • The locations of the data and the services
  • Data protection, availability, integrity and confidentiality, and the return of data
  • Service levels
  • Assistance with incidents and cooperation with the authorities
  • Termination rights and notice periods
  • The provider’s participation in ICT security training

If the service supports a critical or important function, article 30.3 adds service levels with quantitative targets, contingency plans, participation in penetration testing, unrestricted rights of access, inspection and audit, and exit strategies with a transition period. Key custody by a third party, or the cloud behind a trading platform, usually falls into this category.

Article 28.3 also requires a register of information on all ICT contracts and an annual report to the authority on new contracts and their providers. Reviewing these contracts is part of the software and technology contracts work of any crypto-asset service provider.

Example: an exchange facing an outage at its cloud provider

The case is fictitious. Cumbre Digital, S.L. holds a MiCA licence from the CNMV for exchange and custody services, with 30,000 clients. One Tuesday at 9:10 its cloud provider suffers an outage that takes the platform offline. At 10:30 the risk team classifies the incident as major because of its duration and the number of clients affected.

Cumbre Digital sends the initial notification to the CNMV at 13:45, within four hours of the classification. Service is restored that afternoon. On Friday morning, before the seventy-two hours expire, it sends the intermediate report with the cause and the measures taken. A month later it submits the final report.

The follow-up review uncovers a contractual problem. The contract with the cloud provider did not include a contingency plan or an exit strategy, even though it supports a critical function. Cumbre Digital negotiates an addendum with those two clauses and updates its register of information.

Who supervises and enforces DORA in Spain

The CNMV supervises compliance with DORA by crypto-asset service providers. DORA gives that role to the authority designated under MiCA, under its article 46.d, which in Spain is the CNMV by article 251 of the Spanish Securities Markets Act 6/2023. DORA does not set fine amounts and leaves penalties to the Member States. Act 6/2023 does so in its article 308, which classifies as very serious offences, for example, the absence of an ICT risk governance framework or the failure to report a major incident, and as serious offences the inadequacy of those same frameworks and processes.

Does DORA apply to a crypto-asset provider that is not yet authorised?

No. DORA applies to providers authorised under MiCA. But since 1 July 2026 no one may provide crypto-asset services in Spain without authorisation or notification, and the application must describe the ICT systems and security measures. In practice, the DORA framework has to be designed before applying for the licence.

No. Article 16 of DORA reserves the simplified framework for entities such as small and non-interconnected investment firms, certain exempted payment and electronic money institutions and small occupational pension funds. Crypto-asset service providers apply the full framework of articles 5 to 15, although in proportion to their size and risk profile.

In three stages. The initial notification is sent within four hours of classifying the incident as major and no later than twenty-four hours after becoming aware of it. The intermediate report, within seventy-two hours of the initial notification. The final report, within one month of the last intermediate report. In Spain, reports go to the CNMV.

At a minimum, a description of the services and subcontracting, the location of the data, its protection and return, service levels, assistance with incidents, cooperation with the authorities and termination rights. If the cloud supports a critical or important function, such as the trading platform or custody, also contingency plans, audit rights and an exit strategy.

Only for entities identified by the competent authority. Article 26 of DORA requires these advanced tests, at least every three years, from financial entities that the authority identifies based on their importance and risk profile. The rest apply the general testing programme of articles 24 and 25.

DORA is not a stand-alone technology requirement. For a crypto-asset service provider it is part of the MiCA licence and of CNMV supervision, and the European action on custody shows where supervisors will look first. At Innovatech we prepare the application file for crypto-asset service providers, including the DORA component and ICT provider contracts, as part of our MiCA lawyer service in Spain. Write to us for a free initial assessment.

Managing Partner at Innovatech Legal | Website | + posts

Marta Suárez-Mansilla is Managing Partner of Innovatech Legal and a Spanish lawyer (abogada), Madrid Bar (ICAM), working in technology law. She completed Harvard Law School's Copyright course and BerkeleyX's Blockchain programme, and has advised technology companies for more than eight years.