DeFi Security AllianceRequest an audit
Menu

DeFi regulation & security

DORA evidence for crypto-asset service providers

Build a DORA evidence file that connects each business function to its systems, suppliers, tests and accountable owner. A policy document and an operational test answer different questions.

Sources checked
Published
Prepared by
DeFi Security Alliance

Scope: This guide covers the specified EU rule or assessment program and technical preparation. It does not determine a particular business's legal status or replace national filing instructions.

Identify the entity and applicable requirements

DORA Article 2(1)(f) includes crypto-asset service providers authorized under MiCA and issuers of asset-referenced tokens. An open-source repository does not become a financial entity merely because a CASP uses its code. Establish the legal entity, authorization and services before assigning obligations.

Proportionality under Article 4 concerns the entity's size, risk profile, nature, scale and complexity. Specific provisions also distinguish microenterprises and other categories. Document the basis for any exception rather than removing controls because a firm describes itself as a startup.

The management body has responsibilities under Article 5, and the ICT risk-management framework is addressed in Article 6. An outsourced security team can produce evidence. Responsibility for the entity's compliance remains with the entity. Use the EU regulation guide to establish the broader scope and the relevant country guide for the supervisory route.

Connect a requirement to an observable result

Build an evidence map around business functions such as custody, order handling or client withdrawals. The following is a DeFiSec preparation worksheet, not a regulator's submission form. Replace each suggested artifact with a record from the actual service and identify its owner and review date.

DORA evidence preparation worksheet
AreaLegal referenceSuggested evidenceVerification question
GovernanceArticles 5-6Approved risk framework, responsibilities and management decisions.Who accepted the risk, and what information informed that decision?
Asset and dependency identificationArticle 8Function-to-system map with information assets and external dependencies.Can the team identify the systems affected when one provider fails?
RecoveryArticles 11-12Continuity plan, backup design and restoration exercise results.Was recovery demonstrated with the dependencies the service actually uses?
IncidentsArticles 17-19Incident records, classification decisions and reporting responsibilities.Can an operator explain the classification and reconstruct the response?
TestingArticles 24-26Risk-based test plan, findings, fixes and independent validation where required.Did the retest cover the production version and the original failure?
ICT third partiesArticles 28-30Contract register, due diligence, service dependencies and exit arrangements.Can each critical function be traced to a contract and responsible owner?

A screenshot of a successful backup job answers whether the job ran. A restoration exercise answers whether the selected data and service can be recovered. Preserve both when they support different assertions. Record failed checks and unresolved dependencies alongside successful results.

Build the ICT register from contractual relationships

Article 28(3) requires a maintained register for contractual arrangements involving ICT third-party services. It distinguishes arrangements supporting critical or important functions. The annual information sent to the authority and the full register available on request are related duties, not interchangeable documents.

Implementing Regulation 2024/2956 supplies the standard templates and relationships. Its instructions use a unique contractual-arrangement reference. Connect that reference to the provider, consuming entity, service and supported function. Apply the authority's current reporting instructions and corrected templates when preparing an actual submission.

For the implementation details, Pharos Production's guide to the DORA register of information for crypto businesses discusses the relationship between provider identifiers, contractual arrangements and functions. Use it when designing the evidence workflow. Use the official templates to determine required fields.

A useful internal quality check is to select one withdrawal path and trace every contracted dependency through the register. A cloud bill may identify the payer but omit the service's legal supplier or contract scope. Resolve that mismatch before exporting data.

Separate routine testing from designated TLPT

Article 24 establishes the testing program requirements for financial entities other than microenterprises, including at least annual appropriate tests of systems supporting critical or important functions. Article 25 describes testing methods and separately addresses microenterprises. Select tests that exercise the relevant risks rather than treating one penetration-test report as complete coverage.

Threat-led penetration testing under Article 26 applies to entities identified through the specified supervisory process, with exclusions and frequency adjustments in that article. The usual three-year interval is not a universal requirement for every CASP. Confirm designation, scope and supervisory arrangements before commissioning work as DORA TLPT.

Before an evidence review, select a sample across functions: a recovery exercise, a remediated finding, a supplier change and an incident-classification decision. For each, record scope, date, responsible person, result and remaining limitations. This sampling is an editorial preparation technique. It is not a statutory sample size or a compliance certification.

Continue your research

Sources and further reading

Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.

  1. DORA — Regulation (EU) 2022/2554European Union ·
  2. DORA Register of InformationPharos Production ·
  3. DORA register templates: Implementing Regulation (EU) 2024/2956European Union ·

Publication record

First publication of this guide and its source-backed evidence map.

Report an outdated source