If you operate a crypto asset service provider (CASP) in the European Union, you're juggling two overlapping regulatory regimes — DORA for ICT operational resilience and MiCAR for authorization and market conduct — and the deadlines don't line up the way most compliance roadmaps assume they do.
This post consolidates the key DORA and MiCAR compliance milestones into a single side-by-side timeline so you can plan your 2026 and 2027 obligations in one view.
Why a Single Timeline Matters
DORA and MiCAR were drafted in parallel and entered into force within months of each other, but they impose fundamentally different obligations. DORA (Regulation (EU) 2022/2554) is about ICT risk management, third-party concentration, incident reporting, and operational resilience testing. MiCAR (Regulation (EU) 2023/1114) is about authorization, capital, white-paper disclosure, market abuse, and asset safeguarding.
The catch for VASPs is that you're in scope for both. You can't sequence them — the DORA obligations are already in force, and the MiCAR authorization cliff isn't far behind. National competent authorities (BaFin, AMF, AFM, and the rest of the ESAs) are coordinating their supervisory programmes, so evidence you produce for one regime is increasingly being read against the other.
A single timeline helps you see where the deadlines cluster — and where the work actually has to land.
The Timeline
| Date | DORA | MiCAR |
|---|---|---|
| 29 Jun 2023 | — | MiCAR entered into force (Regulation (EU) 2023/1114 published in OJ) |
| 17 Jan 2025 | DORA applies — all in-scope financial entities, including CASPs, must comply | — |
| 30 Dec 2024 | — | MiCAR Titles II, III, IV applicable — most CASP obligations, ART/EMT regime live |
| 7 Jan 2025 | — | AMLD6 (Directive (EU) 2024/1260) enters into force; member-state transposition deadline 7 Jul 2027 (subsequently aligned to 7 Jan 2027 in implementing acts) |
| 30 Jun 2025 | RTS on ICT third-party risk register (DORA Art. 28) applicable | — |
| 30 Dec 2025 | — | MiCAR white-paper, ART/EMT issuer obligations fully applicable; pre-existing CASPs must hold authorization |
| 17 Jan 2026 | TLPT (Threat-Led Penetration Testing) mandatory for significant entities under DORA Art. 26–27; existing pre-DORA CASPs must have contract clauses meeting Art. 30 | — |
| 1 Jul 2026 | — | ART/EMT significant-supervision threshold (ECB direct supervision under Art. 43/55) |
| 30 Jun 2026 | DORA critical-ICT-provider designation regime operational (Art. 31–44) | — |
| 30 Dec 2026 | — | Grandfathering cliffs for pre-existing CASPs (Art. 142 transitional provisions close) |
| 7 Jan 2027 | — | AMLD6 transposition deadline; AMLA operational; cross-border cooperation protocols activated |
What This Means for Your 2026–2027 Plan
The deadlines above cluster in two waves: a January–July 2026 wave (TLPT, ART/EMT supervision) and a December 2026–January 2027 wave (CASP grandfathering, AMLD6 transposition). If you're a VASP, here's the priority order:
**1. ICT risk register (now).** DORA's third-party risk RTS has been applicable since 30 June 2025. If you don't have a current register of every critical ICT provider — wallet, custody, RPC, monitoring, KYC — your NCA can ask for it in any supervisory engagement.
**2. MiCAR Art. 68 white-paper refresh.** White papers must be reviewed annually and republished whenever there's a material change. By 30 December 2025 your pre-existing CASP arrangements either have authorization or they don't. White-paper drift is one of the easiest enforcement triggers for NCAs.
**3. DORA TLPT scoping.** Threat-led penetration testing under TIBER-EU isn't a generic pentest. If your AUM, transaction volume, or client count crosses the significant-entity thresholds, you need a TLPT programme in place — scoped, resourced, and tested before January 2026.
**4. Cross-evidence consolidation.** The work you do for DORA's third-party risk register draws on the same counterparty records you keep for MiCAR's safeguarding and AML obligations. Consolidate your vendor screen outputs, your AML typology monitoring, and your incident reporting drafts into a single evidence package — your NCA will read across regimes.
Where Arkē Slots In
Arkē's three pillars map cleanly onto the timeline artefacts you need to produce:
- **Counterparty screening → DORA third-party risk register evidence.** When you onboard a wallet provider, custodian, exchange integration, or RPC node, Arkē screens the entity against 19,049 OFAC SDN entries plus EU consolidated lists and GPT-enriched PEP and adverse media checks. The screen output (timestamp, risk score, flags) is the documented evidence trail your DORA Art. 28 register needs.
- **Transaction monitoring → MiCAR market-abuse and Travel Rule evidence.** Arkē's monitor endpoint applies AML typology detection to batched transaction data. For VASP transfers above the €1,000 Travel Rule threshold, the same monitoring output supports your MiCAR market-abuse surveillance obligation under Art. 86–88.
- **SAR reporting → DORA Art. 19 major-incident drafts.** When you classify an ICT-related incident as "major" under DORA thresholds, Arkē's reporting endpoint produces structured FIU-compatible drafts — adaptable to your NCA's preferred submission template.
- **Batch screening → vendor concentration analysis.** Ahead of your annual DORA assessment, run your full ICT provider register through Arkē batch screening. Concentration risk surfaces clearly when the same beneficial owner or jurisdiction appears across multiple critical providers.
Closing
The DORA + MiCAR deadlines aren't abstractions — they're already being enforced. The firms that handle 2026 cleanly are the ones that treated DORA and MiCAR as a single operational resilience problem rather than two separate compliance workstreams.
[Plan your 2026–2027 DORA + MiCAR roadmap →](/regulations)