MICA LIBRARY · GUIDE
DORA — digital operational resilience.
The Digital Operational Resilience Act applies to CASPs as financial entities: one ICT-risk rulebook covering risk management, incident reporting, resilience testing, third-party risk, and information sharing.
PRIMARY SOURCE: REGULATION (EU) 2022/2554 ↗ · ESAs (EBA · ESMA · EIOPA) JOINT MATERIALS
At a glance
| Instrument | Regulation (EU) 2022/2554 — digital operational resilience for the financial sector (DORA) |
| Adopted | 14 December 2022; in force 16 January 2023 |
| Official Journal | OJ L 333, 27.12.2022, p. 1–79 |
| EUR-Lex | CELEX 32022R2554 ↗ |
| Applies from | 17 January 2025 |
| Companion | Directive (EU) 2022/2556 (sectoral amendments) |
| Who | 20+ categories of financial entities — explicitly including crypto-asset service providers and ART issuers |
| Status | In force and applying |
The five pillars
| Pillar | Obligation (articles) |
|---|---|
| 1 | ICT risk management (Art. 5–16) — a documented framework owned by the management body: identification, protection, detection, response and recovery, backup, learning. |
| 2 | Incident management & reporting (Art. 17–23) — classify ICT incidents; report major incidents to the competent authority in staged deadlines (initial / intermediate / final). |
| 3 | Resilience testing (Art. 24–27) — a proportionate testing programme for all; advanced threat-led penetration testing (TLPT) for entities designated significant. |
| 4 | ICT third-party risk (Art. 28–44) — contractual minimums with ICT providers, a register of information on all ICT contracts, concentration-risk assessment; critical ICT third-party providers (major clouds) come under direct ESA oversight. |
| 5 | Information sharing (Art. 45) — voluntary cyber threat intelligence exchange between financial entities. |
Proportionality: obligations scale with size and risk profile — a small CASP does not run a bank-grade programme, but no authorised CASP is out of scope. DORA acts as the financial sector’s lex specialis relative to the general NIS2 regime.
Why it matters for authorised CASPs
MiCA authorisation applications already ask for ICT and security arrangements — NCAs assess them against DORA. In practice the register of information and incident-reporting readiness are the first things supervisors request. Every provider on the MiCA Radar is in scope. See the TFR guide for the transfer-rule layer and the MiCA guide for the licence itself.
Educational summary of public sources. This guide condenses the official regulation text and ESMA/EBA materials for general information. It is not legal advice; obligations depend on your specific facts and Member State. Verify against the official sources linked above before relying on any point.