DeFi regulation & security
DORA evidence for crypto-asset service providers
Build a DORA evidence file that connects each business function to its systems, suppliers, tests and accountable owner. A policy document and an operational test answer different questions.
- Sources checked
- Published
- Prepared by
- DeFi Security Alliance
Scope: This guide covers the specified EU rule or assessment program and technical preparation. It does not determine a particular business's legal status or replace national filing instructions.
Identify the entity and applicable requirements
DORA Article 2(1)(f) includes crypto-asset service providers authorized under MiCA and issuers of asset-referenced tokens. An open-source repository does not become a financial entity merely because a CASP uses its code. Establish the legal entity, authorization and services before assigning obligations.
Proportionality under Article 4 concerns the entity's size, risk profile, nature, scale and complexity. Specific provisions also distinguish microenterprises and other categories. Document the basis for any exception rather than removing controls because a firm describes itself as a startup.
The management body has responsibilities under Article 5, and the ICT risk-management framework is addressed in Article 6. An outsourced security team can produce evidence. Responsibility for the entity's compliance remains with the entity. Use the EU regulation guide to establish the broader scope and the relevant country guide for the supervisory route.
Connect a requirement to an observable result
Build an evidence map around business functions such as custody, order handling or client withdrawals. The following is a DeFiSec preparation worksheet, not a regulator's submission form. Replace each suggested artifact with a record from the actual service and identify its owner and review date.
| Area | Legal reference | Suggested evidence | Verification question |
|---|---|---|---|
| Governance | Articles 5-6 | Approved risk framework, responsibilities and management decisions. | Who accepted the risk, and what information informed that decision? |
| Asset and dependency identification | Article 8 | Function-to-system map with information assets and external dependencies. | Can the team identify the systems affected when one provider fails? |
| Recovery | Articles 11-12 | Continuity plan, backup design and restoration exercise results. | Was recovery demonstrated with the dependencies the service actually uses? |
| Incidents | Articles 17-19 | Incident records, classification decisions and reporting responsibilities. | Can an operator explain the classification and reconstruct the response? |
| Testing | Articles 24-26 | Risk-based test plan, findings, fixes and independent validation where required. | Did the retest cover the production version and the original failure? |
| ICT third parties | Articles 28-30 | Contract register, due diligence, service dependencies and exit arrangements. | Can each critical function be traced to a contract and responsible owner? |
A screenshot of a successful backup job answers whether the job ran. A restoration exercise answers whether the selected data and service can be recovered. Preserve both when they support different assertions. Record failed checks and unresolved dependencies alongside successful results.
Build the ICT register from contractual relationships
Article 28(3) requires a maintained register for contractual arrangements involving ICT third-party services. It distinguishes arrangements supporting critical or important functions. The annual information sent to the authority and the full register available on request are related duties, not interchangeable documents.
Implementing Regulation 2024/2956 supplies the standard templates and relationships. Its instructions use a unique contractual-arrangement reference. Connect that reference to the provider, consuming entity, service and supported function. Apply the authority's current reporting instructions and corrected templates when preparing an actual submission.
For the implementation details, Pharos Production's guide to the DORA register of information for crypto businesses discusses the relationship between provider identifiers, contractual arrangements and functions. Use it when designing the evidence workflow. Use the official templates to determine required fields.
A useful internal quality check is to select one withdrawal path and trace every contracted dependency through the register. A cloud bill may identify the payer but omit the service's legal supplier or contract scope. Resolve that mismatch before exporting data.
Separate routine testing from designated TLPT
Article 24 establishes the testing program requirements for financial entities other than microenterprises, including at least annual appropriate tests of systems supporting critical or important functions. Article 25 describes testing methods and separately addresses microenterprises. Select tests that exercise the relevant risks rather than treating one penetration-test report as complete coverage.
Threat-led penetration testing under Article 26 applies to entities identified through the specified supervisory process, with exclusions and frequency adjustments in that article. The usual three-year interval is not a universal requirement for every CASP. Confirm designation, scope and supervisory arrangements before commissioning work as DORA TLPT.
Before an evidence review, select a sample across functions: a recovery exercise, a remediated finding, a supplier change and an incident-classification decision. For each, record scope, date, responsible person, result and remaining limitations. This sampling is an editorial preparation technique. It is not a statutory sample size or a compliance certification.
Continue your research
Sources and further reading
Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.
- DORA — Regulation (EU) 2022/2554European Union ·
- DORA Register of InformationPharos Production ·
- DORA register templates: Implementing Regulation (EU) 2024/2956European Union ·