DORA is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector, and it applies to crypto-asset service providers authorised under MiCA. It requires an ICT risk management framework, reporting of major incidents to the supervisor, regular resilience testing and strict control of ICT third-party providers. It has applied since 17 January 2025 and does not give these providers the simplified regime available to some other small entities. In Spain, the CNMV supervises it. The European Securities and Markets Authority launched a common supervisory action on 8 July 2026 on their operational resilience in custody, which national authorities are carrying out until the first half of 2027.
If you need a MiCA lawyer in Spain for your crypto-asset service provider licence, request a free initial assessment.
DORA covers crypto-asset service providers authorised under MiCA, under its article 2.1.f, and issuers of asset-referenced tokens. It has applied since 17 January 2025. The obligation starts with authorisation, so during the transitional period, which ended in Spain on 1 July 2026, providers operating without MiCA authorisation were not subject to DORA.
Since 1 July, anyone providing crypto-asset services in Spain is either authorised or a financial entity doing so by notification, and the latter were already subject to DORA in their own right. In practice, the whole sector is now covered.
Article 16 provides a simplified ICT risk management framework for some small entities, such as small and non-interconnected investment firms or certain exempted payment institutions. Crypto-asset service providers are not on that list. They apply the full framework of articles 5 to 15, although in proportion to their size, risk profile and the nature of their services, as article 4 requires.
DORA organises its obligations into five blocks. For a crypto-asset service provider, each one translates into specific documents and processes that the CNMV can request.
| Block | Articles | What it means for a crypto-asset provider |
|---|---|---|
| ICT risk management | 5 to 15 | The management body approves the framework and is accountable for it. Inventory of ICT assets, protection, detection, response, backups and business continuity |
| Incidents | 17 to 23 | Process to detect, classify and record incidents, and reporting of major ones to the CNMV |
| Resilience testing | 24 to 27 | Testing programme for systems. Threat-led penetration testing only for entities identified by the authority |
| ICT third-party risk | 28 to 30 | Third-party risk strategy, register of information on all ICT contracts and minimum clauses in each contract |
| Information sharing | 45 | Voluntary arrangements between entities to share cyber threat information |
A major ICT-related incident is reported to the CNMV in three stages. The initial notification is sent within four hours of classifying it as major and no later than twenty-four hours after becoming aware of it. The intermediate report follows within seventy-two hours of the initial notification. The final report, within one month of the last intermediate report. The deadlines are set in article 5 of Delegated Regulation (EU) 2025/301.
If a deadline falls on a weekend or public holiday, the provider may submit the notification before 12:00 on the next working day. That rule does not apply to some entities, including those considered essential or important under the NIS2 Directive.
The common supervisory action announced by the European Securities and Markets Authority on 8 July 2026 assesses the maturity of crypto-asset service providers’ digital operational resilience frameworks in relation to custody. National authorities apply it to a risk-based sample of authorised providers, from the second half of 2026 to the first half of 2027. Its findings will be gathered in a final report in the second half of 2027.
The European authority highlights the risks specific to distributed ledger technology that it will review:
For a provider holding clients’ crypto-assets, these are the points where documentation should be up to date before a request arrives.
Every contract with an ICT provider must include minimum content, set out in article 30.2 of DORA:
If the service supports a critical or important function, article 30.3 adds service levels with quantitative targets, contingency plans, participation in penetration testing, unrestricted rights of access, inspection and audit, and exit strategies with a transition period. Key custody by a third party, or the cloud behind a trading platform, usually falls into this category.
Article 28.3 also requires a register of information on all ICT contracts and an annual report to the authority on new contracts and their providers. Reviewing these contracts is part of the software and technology contracts work of any crypto-asset service provider.
The case is fictitious. Cumbre Digital, S.L. holds a MiCA licence from the CNMV for exchange and custody services, with 30,000 clients. One Tuesday at 9:10 its cloud provider suffers an outage that takes the platform offline. At 10:30 the risk team classifies the incident as major because of its duration and the number of clients affected.
Cumbre Digital sends the initial notification to the CNMV at 13:45, within four hours of the classification. Service is restored that afternoon. On Friday morning, before the seventy-two hours expire, it sends the intermediate report with the cause and the measures taken. A month later it submits the final report.
The follow-up review uncovers a contractual problem. The contract with the cloud provider did not include a contingency plan or an exit strategy, even though it supports a critical function. Cumbre Digital negotiates an addendum with those two clauses and updates its register of information.
The CNMV supervises compliance with DORA by crypto-asset service providers. DORA gives that role to the authority designated under MiCA, under its article 46.d, which in Spain is the CNMV by article 251 of the Spanish Securities Markets Act 6/2023. DORA does not set fine amounts and leaves penalties to the Member States. Act 6/2023 does so in its article 308, which classifies as very serious offences, for example, the absence of an ICT risk governance framework or the failure to report a major incident, and as serious offences the inadequacy of those same frameworks and processes.
No. DORA applies to providers authorised under MiCA. But since 1 July 2026 no one may provide crypto-asset services in Spain without authorisation or notification, and the application must describe the ICT systems and security measures. In practice, the DORA framework has to be designed before applying for the licence.
No. Article 16 of DORA reserves the simplified framework for entities such as small and non-interconnected investment firms, certain exempted payment and electronic money institutions and small occupational pension funds. Crypto-asset service providers apply the full framework of articles 5 to 15, although in proportion to their size and risk profile.
In three stages. The initial notification is sent within four hours of classifying the incident as major and no later than twenty-four hours after becoming aware of it. The intermediate report, within seventy-two hours of the initial notification. The final report, within one month of the last intermediate report. In Spain, reports go to the CNMV.
At a minimum, a description of the services and subcontracting, the location of the data, its protection and return, service levels, assistance with incidents, cooperation with the authorities and termination rights. If the cloud supports a critical or important function, such as the trading platform or custody, also contingency plans, audit rights and an exit strategy.
Only for entities identified by the competent authority. Article 26 of DORA requires these advanced tests, at least every three years, from financial entities that the authority identifies based on their importance and risk profile. The rest apply the general testing programme of articles 24 and 25.
DORA is not a stand-alone technology requirement. For a crypto-asset service provider it is part of the MiCA licence and of CNMV supervision, and the European action on custody shows where supervisors will look first. At Innovatech we prepare the application file for crypto-asset service providers, including the DORA component and ICT provider contracts, as part of our MiCA lawyer service in Spain. Write to us for a free initial assessment.
Marta Suárez-Mansilla is Managing Partner of Innovatech Legal and a Spanish lawyer (abogada), Madrid Bar (ICAM), working in technology law. She completed Harvard Law School's Copyright course and BerkeleyX's Blockchain programme, and has advised technology companies for more than eight years.
