31 August 2026, 09:47 PM
Over the years, I have worked with various financial institutions, fintech companies, and crypto businesses across Europe, and one similarity that I have observed is that organisations often know they must meet regulatory requirements but are unsure which framework governs licensing, which covers cybersecurity, and how they both align.
In this guide, I explain the meaning and applicability of both acts, the requirements of both acts, how MiCA and DORA intersect, the penetration testing requirements introduced under DORA, and the practical steps fintechs and CASPs should take to achieve compliance in 2026.
Key Takeaways
Source: https://qualysec.com/mica-and-dora-regulation/
- MiCA (Regulation EU 2023/1114) is a European law that governs crypto-asset markets and Crypto-Asset Service Providers (CASPs) operating their business in Europe
- DORA (Regulation EU 2022/2554) governs the cybersecurity requirements of financial organisations operating within Europe.
In this guide, I explain the meaning and applicability of both acts, the requirements of both acts, how MiCA and DORA intersect, the penetration testing requirements introduced under DORA, and the practical steps fintechs and CASPs should take to achieve compliance in 2026.
Key Takeaways
- Dual Compliance Imperative: Crypto businesses and financial institutions operating in the EU must comply with both MiCA (market conduct, licensing, and consumer protection) and DORA (digital operational resilience and cybersecurity).
- Regulatory vs. Technical Obligations: MiCA establishes the operational framework for Crypto-Asset Service Providers (CASPs), but explicitly cross-references DORA for technical cybersecurity execution and threat testing.
- Two-Tiered Testing Requirements: DORA establishes two distinct penetration testing mandates: Standard Resilience Testing (annual, baseline) and Threat-Led Penetration Testing (TLPT) (triennial, adversary simulation for designated entities).
- Action Plan: Achieving compliance requires identifying Critical or Important Functions (CIFs), establishing structured vulnerability management, executing threat simulations, and maintaining audit-ready remediation records.
Source: https://qualysec.com/mica-and-dora-regulation/