DORA compliance for crypto exchange.
Digital Operational Resilience Act (Regulation (EU) 2022/2554). Enforced from 2025-01-17. Supervised by European Banking Authority + national competent authorities (BaFin, FCA-equivalent in EU member states). Coreal generates the evidence pack automatically on every Minctrl build — see /security-compliance for the full posture.
What this regulation covers.
ICT risk management, incident reporting and third-party oversight for financial entities operating in the EU.
For a crypto exchange, the salient angles are: Custody-light architecture (own funds vs customer funds segregation); Travel Rule (IVMS101) integration with originating wallets; MiCA capital requirements (€125k–€350k by Class). Primary licence: CASP authorisation under MiCA.
- Art. 5 — ICT risk management framework
- Art. 16 — Reporting major ICT-related incidents
- Art. 24 — Threat-led penetration testing (TLPT)
- Art. 28 — General principles for third-party ICT services
- Art. 30 — Concentration risk
What lands in the regulator file.
All items journaled, replayable, 7-year retention.
Which DORA articles apply to a casp?
Primarily: Art. 5 — ICT risk management framework; Art. 16 — Reporting major ICT-related incidents; Art. 24 — Threat-led penetration testing (TLPT). The full mapping is in the Coreal compliance posture document — see /security-compliance.
What evidence does Coreal generate per audit?
ICT risk register (versioned, per-process); Incident timeline with operator + AI-agent actions; Decision journal (7-year retention, replayable). The Minctrl pipeline produces this artefact set automatically on every build — see /company §05 'How we ship'.
What are the penalties for non-compliance?
Up to 2% of annual global turnover; member-state criminal liability for senior management on wilful non-compliance.
Bring the perimeter,
leave with a brief.
Read the Wave-1 runbook first.
The full 90-day launch sequence — phases, partner-bank gates, who signs off when. No form to read it.
Read the runbook →INDICATIVE DATA · Numbers and timelines reflect public regulator filings, vendor documentation and our own delivery experience. Per-engagement values vary with operator profile, BSS vintage and regulatory perimeter. Engage early for a fitted estimate under NDA.