Skip to content

BLOCKCHAIN LAB BRIEFING · REGULATION

DORA Regulates the Firm’s ICT Risk. It Does Not Certify a Chain.

The EU’s Digital Operational Resilience Act sets ICT-risk, incident, testing and third-party duties on financial entities. A network’s uptime is not a DORA compliance mark.

2 October 2026

All briefings

01

What happened

Regulation (EU) 2022/2554, DORA, applies to a defined list of financial entities. It requires them to manage ICT risk, report major incidents, test resilience, and oversee ICT third parties, including concentration in critical providers. Application of the main obligations started on 17 January 2025.

A public network is not a financial entity because DORA exists. A bank, an insurer, a crypto-asset service provider or another in-scope firm that depends on that network is the entity with the duty.

02

Why it matters

Vendors selling chain compliance under DORA are selling a category error. The buyer’s board has to know its ICT assets, its third parties, its exit plan, and how an incident is classified. A status page is not that register.

For a studio project that wants a regulated firm as a client, the sales artefact is an ICT pack: subprocessors, key custody, incident contacts, recovery objectives, and what you cannot promise because a public network has no service level.

03

The operating layer

Write the dependency honestly. If settlement can halt because a sequencer, a bridge, or an RPC provider halts, that is an ICT dependency. Put it in the register. Name an exit: pause the product, fall back to a bank rail, or both.

Do not sign a contract that warrants uninterrupted ledger finality. You do not control it.

04

What is verified

DORA is published on EUR-Lex. The in-scope list and the January 2025 application date are in the regulation and the measures that followed. This briefing is not a determination that any reader’s firm is in scope.

05

What remains unclear

Which third-party designations national or European authorities have made, and whether a given infrastructure firm is treated as critical. How a firm classifies a chain halt: major incident or tolerated external event.

06

The catch

Borrowing DORA’s name in a white paper does not move the duty onto the protocol. The duty sits with the financial entity, including the duty to admit where resilience is limited by a dependency it does not govern.

Not legal advice, and not an ICT audit.

WATCH

What builders should watch

  1. 01Whether the operating company is a financial entity under DORA.
  2. 02The ICT register entry for each ledger, custodian and cloud provider.
  3. 03The fallback when the dependency fails.

BOTTOM LINE

Put the chain in the ICT register as a dependency. Do not put a compliance badge on the chain.

Sources

Blockchain Lab uses public social posts as reporting leads, not as proof. Every published briefing is assessed against primary sources, available documentation and relevant technical context. Social engagement is not used as evidence of the underlying claim.

Continue