Audit · DORA

How to Prepare Your Company for DORA and MiCA in Practice

Remote Admin Audit Team·December 16, 2025·4 min read

To prepare a company for the DORA and MiCA regulations, you need to simultaneously get cybersecurity, IT business continuity, vendor management, and operational compliance in the crypto-asset space in order. This isn’t a “paperwork” project — it’s a real change in how you manage technology, risk, and board-level accountability.

What are the DORA and MiCA regulations in practice, and who do they apply to?

DORA (Digital Operational Resilience Act) is an EU regulation that has been in force since January 17, 2025, covering the digital resilience of financial entities and technology providers serving the financial sector. It covers, among others:

  • banks, investment fund companies, brokerages, payment institutions,

  • fintechs and neobanks,

  • ICT providers for the financial sector (cloud, hosting, SOC, MSP, SaaS).

MiCA (Markets in Crypto-Assets) regulates the crypto-asset market in the EU. It applies to companies such as:

  • cryptocurrency exchanges,

  • token issuers (ARTs, EMTs),

  • crypto-asset service providers (CASPs),

  • fintechs bridging traditional finance and blockchain.

In practice:
👉 DORA = IT operational resilience,
👉 MiCA = legality and transparency of crypto activity.

What real risks do DORA and MiCA eliminate?

From an IT engineer’s and auditor’s perspective, these regulations were created in response to very specific problems:

  • no infrastructure resilience testing,

  • no incident response procedures,

  • dependence on a single cloud provider,

  • competency chaos between IT, compliance, and the board,

  • no control over technology risk in crypto.

In my experience, the most common problem is illusory security: policies exist, but nobody knows whether the system would survive a real incident.

Where should a company start preparing for DORA and MiCA?

I always start with an inventory, not documents.

1. Technical and operational audit (the zero point)

You need clear answers to these questions:

  • which systems are business-critical?

  • where is sensitive data located?

  • who actually administers the infrastructure?

  • what happens if a key system goes down for 24 hours?

Without this, everything that follows is fiction.

How does DORA change the approach to cybersecurity?

DORA doesn’t ask whether you have a firewall — it asks:

“Would your organization survive a real cyber incident?”

What has to actually work:

  • continuous monitoring (24/7 SOC),

  • incident classification (ICT-related incidents),

  • incident reporting to the regulator,

  • resilience testing (including scenario-based testing).

In the projects I’ve led, the biggest shift was moving the emphasis from “protection” to resilience and recovery.

How do you set up incident management in line with DORA?

DORA requires a company to:

  • have a formal incident management process,

  • be able to classify and escalate incidents,

  • be able to prove it responds according to procedure.

In practice, this means:

  • IR (Incident Response) playbooks,

  • “table-top” exercises for the board,

  • a clear division of roles between IT, compliance, and management.

For many companies, this is the first time the board genuinely engages with cybersecurity — and that’s a very good thing.

How does DORA regulate IT vendors and the cloud?

This is one of the most underrated areas.

DORA requires:

  • full control over ICT outsourcing,

  • vendor risk assessment,

  • contracts that include SLAs, audit rights, and an exit plan,

  • readiness to switch vendors.

If a company runs on a single hyperscaler with no plan B — that’s a regulatory gap.

What technical obligations does MiCA impose on crypto companies?

MiCA introduces order where there used to be a free-for-all.

In practice, it requires, among other things:

  • segregation of client assets,

  • strong IT security mechanisms,

  • auditable transaction systems,

  • technology risk management.

For crypto companies, this often means rebuilding the backend, not just updating the terms of service.

How do you combine DORA and MiCA requirements within one organization?

At fintechs and crypto platforms, the two regulations overlap.

The approach that works best in practice:

  • a single IT risk management model,

  • a shared security architecture,

  • centralized monitoring and reporting,

  • one common “language” between IT, compliance, and the board.

Keeping these areas separate ends up duplicating costs and creating decision-making chaos.

What mistakes do I see most often in DORA and MiCA implementations?

From experience:

  1. Documents without real testing

  2. Compliance disconnected from infrastructure

  3. Lack of board involvement

  4. No control over IT vendors

  5. Treating the regulation as a “one-off project”

DORA and MiCA are a continuous process, not a checkbox.

How long does preparing for DORA and MiCA actually take?

Depending on the scale of the organization:

  • a small fintech / crypto startup: 3–6 months,

  • a mid-sized financial institution: 6–12 months,

  • a large organization: 12+ months.

The earlier you start with the technical side rather than the paperwork, the cheaper and faster it goes.

Are DORA and MiCA a cost, or a competitive advantage?

From a market perspective, they’re a quality filter.

Companies that:

  • have a stable IT architecture,

  • genuinely manage risk,

  • are operationally transparent,

will win out over companies that just “somehow work.”

I’ve already seen cases where DORA compliance became a sales argument, not a cost.

How do you prepare a company smartly, not just “to the letter of the law”?

The best implementations I’ve led all had one thing in common:

regulatory compliance was a byproduct of well-designed IT

If you want a practical approach to DORA and MiCA, start with the technology, not the legal clauses. The regulations just put that in order.

This is exactly the moment when cybersecurity stops being a cost and starts being the foundation of the business.