MICA LIBRARY · GUIDE

DORA — digital operational resilience.

The Digital Operational Resilience Act applies to CASPs as financial entities: one ICT-risk rulebook covering risk management, incident reporting, resilience testing, third-party risk, and information sharing.

PRIMARY SOURCE: REGULATION (EU) 2022/2554 ↗ · ESAs (EBA · ESMA · EIOPA) JOINT MATERIALS

At a glance

InstrumentRegulation (EU) 2022/2554 — digital operational resilience for the financial sector (DORA)
Adopted14 December 2022; in force 16 January 2023
Official JournalOJ L 333, 27.12.2022, p. 1–79
EUR-LexCELEX 32022R2554 ↗
Applies from17 January 2025
CompanionDirective (EU) 2022/2556 (sectoral amendments)
Who20+ categories of financial entities — explicitly including crypto-asset service providers and ART issuers
StatusIn force and applying

The five pillars

PillarObligation (articles)
1ICT risk management (Art. 5–16) — a documented framework owned by the management body: identification, protection, detection, response and recovery, backup, learning.
2Incident management & reporting (Art. 17–23) — classify ICT incidents; report major incidents to the competent authority in staged deadlines (initial / intermediate / final).
3Resilience testing (Art. 24–27) — a proportionate testing programme for all; advanced threat-led penetration testing (TLPT) for entities designated significant.
4ICT third-party risk (Art. 28–44) — contractual minimums with ICT providers, a register of information on all ICT contracts, concentration-risk assessment; critical ICT third-party providers (major clouds) come under direct ESA oversight.
5Information sharing (Art. 45) — voluntary cyber threat intelligence exchange between financial entities.

Proportionality: obligations scale with size and risk profile — a small CASP does not run a bank-grade programme, but no authorised CASP is out of scope. DORA acts as the financial sector’s lex specialis relative to the general NIS2 regime.

Why it matters for authorised CASPs

MiCA authorisation applications already ask for ICT and security arrangements — NCAs assess them against DORA. In practice the register of information and incident-reporting readiness are the first things supervisors request. Every provider on the MiCA Radar is in scope. See the TFR guide for the transfer-rule layer and the MiCA guide for the licence itself.

Educational summary of public sources. This guide condenses the official regulation text and ESMA/EBA materials for general information. It is not legal advice; obligations depend on your specific facts and Member State. Verify against the official sources linked above before relying on any point.