DORA + MiCAR Regulatory Timeline: Every Key Deadline for Crypto VASPs

A visual side-by-side timeline of DORA and MiCAR compliance milestones for crypto asset service providers — entry-into-force dates, authorization deadlines, TLPT, RTS application, and the obligations that govern your 2026–2027 planning.

If you operate a crypto asset service provider (CASP) in the European Union, you're juggling two overlapping regulatory regimes — DORA for ICT operational resilience and MiCAR for authorization and market conduct — and the deadlines don't line up the way most compliance roadmaps assume they do.

This post consolidates the key DORA and MiCAR compliance milestones into a single side-by-side timeline so you can plan your 2026 and 2027 obligations in one view.

Why a Single Timeline Matters

DORA and MiCAR were drafted in parallel and entered into force within months of each other, but they impose fundamentally different obligations. DORA (Regulation (EU) 2022/2554) is about ICT risk management, third-party concentration, incident reporting, and operational resilience testing. MiCAR (Regulation (EU) 2023/1114) is about authorization, capital, white-paper disclosure, market abuse, and asset safeguarding.

The catch for VASPs is that you're in scope for both. You can't sequence them — the DORA obligations are already in force, and the MiCAR authorization cliff isn't far behind. National competent authorities (BaFin, AMF, AFM, and the rest of the ESAs) are coordinating their supervisory programmes, so evidence you produce for one regime is increasingly being read against the other.

A single timeline helps you see where the deadlines cluster — and where the work actually has to land.

The Timeline

| Date | DORA | MiCAR |
|---|---|---|
| 29 Jun 2023 | — | MiCAR entered into force (Regulation (EU) 2023/1114 published in OJ) |
| 17 Jan 2025 | DORA applies — all in-scope financial entities, including CASPs, must comply | — |
| 30 Dec 2024 | — | MiCAR Titles II, III, IV applicable — most CASP obligations, ART/EMT regime live |
| 7 Jan 2025 | — | AMLD6 (Directive (EU) 2024/1260) enters into force; member-state transposition deadline 7 Jul 2027 (subsequently aligned to 7 Jan 2027 in implementing acts) |
| 30 Jun 2025 | RTS on ICT third-party risk register (DORA Art. 28) applicable | — |
| 30 Dec 2025 | — | MiCAR white-paper, ART/EMT issuer obligations fully applicable; pre-existing CASPs must hold authorization |
| 17 Jan 2026 | TLPT (Threat-Led Penetration Testing) mandatory for significant entities under DORA Art. 26–27; existing pre-DORA CASPs must have contract clauses meeting Art. 30 | — |
| 1 Jul 2026 | — | ART/EMT significant-supervision threshold (ECB direct supervision under Art. 43/55) |
| 30 Jun 2026 | DORA critical-ICT-provider designation regime operational (Art. 31–44) | — |
| 30 Dec 2026 | — | Grandfathering cliffs for pre-existing CASPs (Art. 142 transitional provisions close) |
| 7 Jan 2027 | — | AMLD6 transposition deadline; AMLA operational; cross-border cooperation protocols activated |

What This Means for Your 2026–2027 Plan

The deadlines above cluster in two waves: a January–July 2026 wave (TLPT, ART/EMT supervision) and a December 2026–January 2027 wave (CASP grandfathering, AMLD6 transposition). If you're a VASP, here's the priority order:

**1. ICT risk register (now).** DORA's third-party risk RTS has been applicable since 30 June 2025. If you don't have a current register of every critical ICT provider — wallet, custody, RPC, monitoring, KYC — your NCA can ask for it in any supervisory engagement.

**2. MiCAR Art. 68 white-paper refresh.** White papers must be reviewed annually and republished whenever there's a material change. By 30 December 2025 your pre-existing CASP arrangements either have authorization or they don't. White-paper drift is one of the easiest enforcement triggers for NCAs.

**3. DORA TLPT scoping.** Threat-led penetration testing under TIBER-EU isn't a generic pentest. If your AUM, transaction volume, or client count crosses the significant-entity thresholds, you need a TLPT programme in place — scoped, resourced, and tested before January 2026.

**4. Cross-evidence consolidation.** The work you do for DORA's third-party risk register draws on the same counterparty records you keep for MiCAR's safeguarding and AML obligations. Consolidate your vendor screen outputs, your AML typology monitoring, and your incident reporting drafts into a single evidence package — your NCA will read across regimes.

Where Arkē Slots In

Arkē's three pillars map cleanly onto the timeline artefacts you need to produce:

Closing

The DORA + MiCAR deadlines aren't abstractions — they're already being enforced. The firms that handle 2026 cleanly are the ones that treated DORA and MiCAR as a single operational resilience problem rather than two separate compliance workstreams.

[Plan your 2026–2027 DORA + MiCAR roadmap →](/regulations)

Explore related regulation

Deep-dive the regulatory framework behind this analysis on the Arkē Regulations page.

View Regulations →
← Back to All Posts Try Arkē Screen Counterparty