Markets in Crypto-Assets Regulation (MiCA) authorization has dominated the compliance conversation for crypto-asset service providers (CASPs) operating in the EU. But authorization is only one part of the picture. Once a firm is licensed as a CASP, it is automatically pulled into a second, separate regulatory regime: the Digital Operational Resilience Act (DORA).

DORA has applied to CASPs since January 17, 2025, the same date it applied to banks, insurers, and asset managers across the EU, with no phase-in period left to plan around. MiCA decides whether a firm can offer crypto-asset services. DORA decides whether that firm's technology stack is resilient enough to be trusted with them. Both obligations are live at the same time, and satisfying one does not discharge the other.

Why MiCA Authorization Doesn't Cover DORA

DORA, formally Regulation (EU) 2022/2554, names CASPs authorized under MiCA as financial entities under Article 2(1)(s). That single clause is what pulls the entire DORA rulebook into scope for crypto firms: custody and administration of crypto-assets, operation of a trading platform, exchange services, execution of orders, placement, and portfolio management are all covered activities. Issuers of asset-referenced tokens and e-money tokens fall under DORA separately as financial entities in their own right, on top of the MiCA-specific reserve and operational rules that already apply to them.

MiCA itself does impose some operational expectations. Article 68 addresses systems and security access protocols, Article 75 covers custody safekeeping, and there are baseline business continuity obligations throughout. DORA complements these obligations: it's the cross-sectoral standard that deepens and harmonizes the ICT risk side of the business, applying proportionately under Article 4 so a small portfolio-management CASP faces lighter expectations than a large multi-asset exchange. No CASP is exempt from the core requirements around ICT risk management, incident reporting, and third-party oversight, regardless of size.

What DORA Requires

For a CASP, DORA compliance touches several distinct areas of the business:

  • ICT risk management framework. Firms need documented governance over their technology risk, with board-level accountability rather than a policy sitting in a compliance folder.
  • Incident reporting. Major ICT-related incidents must be classified and reported to regulators within defined timelines, which requires infrastructure capable of detecting and escalating issues quickly.
  • Digital operational resilience testing. Larger or more critical firms fall under threat-led penetration testing (TLPT) requirements, which go beyond a standard security audit and simulate real adversarial conditions against production systems.
  • Third-party risk management. DORA requires oversight of critical ICT third-party providers, including cloud infrastructure, custody technology, and, for many CASPs, the smart contracts and libraries their products are built on.

That last point is where the overlap with a firm's technical foundation becomes most concrete. A CASP's risk register under DORA needs to account for the security posture of the protocols, smart contracts, and frameworks it relies on, not just its internal systems.

Where Security Standards Come In

The most common misconception firms run into is assuming that a completed MiCA authorization file, with its policies, controls, and disclosures, already satisfies DORA. It does not. The two regimes overlap in intent but are evaluated separately, with different evidence expectations and different regulators asking different questions.

The practical answer is to build one evidence base that speaks to both regimes at once: a control set for authorization and conduct, and a resilience and risk-management layer that maps directly onto DORA's ICT requirements. Smart contract audits and security audits belong in that evidence base as ongoing proof of the ICT risk management and third-party oversight DORA expects on a continuing basis.

This is the environment OpenZeppelin's security audits are built for: 900+ security audits completed since 2016, backing $250 billion in value secured. As financial infrastructure moves onchain, institutional-grade security standards for smart contracts and protocols are becoming a documented, auditable part of a firm's regulatory file. OpenZeppelin is the security standard onchain finance is built on, and that standard increasingly needs to satisfy both crypto-specific rules like MiCA and cross-sectoral frameworks like DORA at the same time.

The Takeaway

Any firm authorized as a CASP under MiCA is, by definition, a DORA-regulated financial entity. There is no separate compliance runway once that authorization is granted. A firm authorized in 2026 is expected to be operationally resilient from its first day of operating, with the same ICT risk management, incident reporting, and testing obligations scaled to its size and risk profile under applicable regulations and DORA’s proportionality principle. Treating security audits, smart contract audits, and third-party risk assessments as a continuous compliance function, rather than a pre-launch task, is what closes the gap between the two regimes.

FAQs

Does MiCA authorization automatically mean a CASP is DORA-compliant?

No. MiCA and DORA are separate regimes evaluated independently. MiCA authorization covers market access and conduct; DORA governs ICT risk management, incident reporting, and operational resilience testing.

Since when has DORA applied to crypto-asset service providers?

DORA has applied to CASPs since January 17, 2025, on the same terms as banks and other financial entities.

Which CASP activities fall under DORA?

Custody and administration of crypto-assets, trading platform operation, exchange services, order execution and transmission, placement, advice, and portfolio management are all covered, per DORA Article 2(1)(s).

Are asset-referenced token and e-money token issuers subject to DORA too?

Yes. ART and EMT issuers are named as financial entities under DORA separately, in addition to MiCA-specific reserve and operational requirements.

What role do security audits play in DORA compliance?

Security audits and smart contract audits provide ongoing evidence for the ICT risk management and third-party oversight obligations DORA requires, supporting a firm's risk register and incident-readiness documentation.

The opinions, statements, and assessments in this article do not constitute legal, tax, regulatory or any other professional advice. Given the inherent nature of the information in this article, its contents are based on information gathered and understood at the time of its creation. It is subject to change. The information is provided on an “as-is” basis without representation or warranty and accepts no liability for any action or failure to act taken in response to the information contained or referenced in this article.