
Four things DORA examiners ask crypto CASPs for, and why the compliance document does not answer any of them.
CASP authorisation is not the finish line. It is the point at which your controls become continuously examinable.
Once authorised under MiCA, a CASP falls within DORA’s scope as a financial entity.
So a policy saying that access to signing infrastructure is restricted is no longer enough. A supervisor can ask you to demonstrate who accessed the HSM, MPC platform, wallet-management system or approval workflow, what they did, who authorized it and whether the evidence has been preserved against alteration.
The compliance binder tells the examiner what should happen. The logs show whether it did.
Some of the crypto leadership teams I speak with learned this after the authorization, not before. The gap analysis arrived. The legal advisor mapped obligations to controls at a policy level. Nobody walked into the CTO’s office and said: you are now being examined by the same people who examine banks, using the same evidence standards.
What examiners actually test
Compliance counsel delivers documents. Examiners test evidence. The gap between the two is where companies lose.
I have sat on the regulated-infrastructure side of these reviews. The questions are not abstract. They are operational, and they assume the answer takes minutes to produce, not days. Four of them come in the first session.
1. Pull twelve months of access logs for your hot wallet and signing infrastructure. We need them within 24 hours.
Some of the crypto firms fail to do this. Logs exist somewhere. They are not centralized, not retained to a documented schedule, not queryable by anyone other than the engineer who configured the system. The examiner does not care that the logs technically exist on a host. The DORA ICT risk management RTS (Commission Delegated Regulation (EU) 2024/1774), sets the logging and monitoring obligations. If production takes a week, that is a finding.
2. Walk us through the key ceremony for your last cold storage key generation. Show us the dual-control evidence.
“We use HSM” is not the answer. The answer is a ceremony script, signed attestation from two custodians, a documented retention policy, evidence that the procedure was executed, an HSM audit log export of the operation, and a written procedure that maps to MiCAR Article 70 safeguarding obligations. If your team improvised the last ceremony because the documented procedure obligations does not match what you actually do, the examiner will find that in three simple investigative questions.
3. Show us your incident classification procedure. Walk us through how you determined the incident last quarter was not a major ICT-related incident under DORA Article 18.
Aspirational language fails here. Based on DORA Article 18 and the underlying classification RTS (Commission Delegated Regulation (EU) 2024/1772), define classification using concrete thresholds: number of customers affected, geographic scope of the disruption, duration, economic impact, data integrity loss, reputational consequences etc. Your procedure must operationalize those thresholds for your specific environment, with timing triggers wired into your on-call rotation. “The incident response team will assess severity” is not a procedure. It is a sentence.
4. Describe the threat intelligence input that scoped your last threat-led penetration test.
The DORA TLPT RTS (Commission Delegated Regulation (EU) 2025/1190), adopted under DORA Article 26, establishes the methodology for threat-led penetration testing. The TIBER-EU framework on which DORA TLPT is modeled requires a threat intelligence phase that directly informs the testing (RED TEAM) team scenario. If your last penetration test was scoped by the endpoints you wanted checked rather than by the threat actors known to target your infrastructure type, you did not run a TLPT. You ran a penetration test with TLPT on the invoice. The examiner knows the difference.
This is security operation problem
Compliance counsel does what compliance counsel is paid to do: map regulation to control objectives and produce a gap analysis. That document is a starting point, not a finished operating capability.
The work between “we have a documented control” and “we can produce evidence in a 24-hour examiner window” is security engineering. Log pipelines built to retention requirements. Key management procedures rehearsed quarterly with records kept. Incident classification triggers wired into the actual system, not described in a policy appendix. TLPT scenarios scoped from a threat intelligence feed that someone reads regularly.
The consequence of discovering the gap during examination rather than before it: the examiner writes the findings(s). The finding(s) goes on the register. The remediation timeline is the regulator’s to set, not yours. The CASP passport that took your team approximately months to obtain becomes conditional on closing findings inside window you did not choose. And the engineering work required to close regulatory findings under deadline pressure is the most expensive engineering work your team will ever have to do.
What I would do
Three quick moves before the examiner correspondents arrive:
Run a quick table top exercise against the four questions above. Not a gap analysis exercise. If a response to any of the above questions takes more than a day (24 hrs) to produce an evidence, then I would register it as a gap.
Map the evidence pipes. For every DORA Chapter II or Chapter III obligation , name the system that produce the evidence, retention schedule, the person who can extract it, and the current time-to-produce. Most team discover during this exercise that several pipelines do not exist and the rest depend on one engineer.
Close the staffing gap. The DORA-shaped security operations function is not a compliance hire. It is a security engineering hire with regulated-entity experience: someone who has built log retention to an examiner standard, run a key ceremony, and written an incident classification procedure that a regulator has actually tested.
The CASP license got you the right to operate. DORA determines whether you keep operating without findings on the public register.
You find out which of the four you have on the day the examiner asks, and that is the most expensive day to find out.
References
- https://www.eba.europa.eu/regulation-and-policy/single-rulebook/interactive-single-rulebook/17716
- https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023R1114
- https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554
- https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1772
- https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202501190
- https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1774
- https://www.esma.europa.eu/regulation/micar
- https://www.ecb.europa.eu/paym/cyber-resilience/tiber-eu/html/index.en.html
