What is the difference between MiCA and DORA?
MiCA regulates crypto-asset markets and service providers; DORA regulates digital operational resilience in financial services.
MiCA vs DORA: MiCA is the EU crypto-assets regime; DORA is the financial-sector ICT resilience regime. A crypto firm can need MiCA authorisation and DORA operational-resilience controls. Sources: EUR-Lex: Markets in Crypto-Assets Regulation; EUR-Lex: Digital Operational Resilience Act.
The short version
MiCA asks whether the activity is crypto-asset issuance, trading or service provision. DORA asks whether a financial entity has robust ICT risk, incident and third-party controls.
Side by side
Regulation
MiCA
Markets in Crypto-Assets Regulation
- What it is
- MiCA is the EU framework for crypto-asset offers, admission to trading and crypto-asset service providers.
- Scope
- Crypto-assets not otherwise covered by existing financial-services law, including asset-referenced tokens, e-money tokens and crypto-asset services.
- Who it applies to
- Issuers, offerors, persons seeking admission to trading and crypto-asset service providers.
- Key dates
- Adopted in 2023.
- Application is phased, with stablecoin-related rules and CASP rules applying on different dates.
- Core obligations
- Publish and notify required crypto-asset white papers where applicable.
- Meet authorisation, governance and conduct requirements for crypto-asset services.
- Follow market-abuse and disclosure rules in scope.
- Penalties
- MiCA requires Member States to provide administrative sanctions and other measures, including fines and supervisory powers.
Regulation
DORA
Digital Operational Resilience Act
- What it is
- DORA is the EU financial-sector framework for ICT risk management, incident reporting, resilience testing and ICT third-party risk.
- Scope
- Digital operational resilience for financial entities and oversight of critical ICT third-party service providers.
- Who it applies to
- Financial entities listed in DORA and, through oversight, critical ICT third-party service providers.
- Key dates
- Entered into force in 2023.
- Applies from 17 January 2025.
- Core obligations
- Maintain ICT risk-management frameworks.
- Report major ICT-related incidents and significant cyber threats where required.
- Run digital operational resilience testing and manage ICT third-party risk.
- Penalties
- DORA relies on competent authorities' supervisory and enforcement powers, including administrative measures and penalty payments for critical ICT third-party providers.
Which applies to you?
If you issue crypto-assets or provide crypto-asset services, check MiCA. If you are a financial entity or critical ICT provider in the financial ecosystem, check DORA.
Frequently asked
Do crypto-asset service providers need DORA?
Crypto-asset service providers are among the financial entities DORA can cover, so MiCA and DORA can both matter.
Is DORA a crypto law?
No. DORA is broader financial-sector digital operational resilience law, not a crypto-market rulebook.
Is MiCA an operational resilience law?
MiCA includes governance and conduct rules for crypto markets, but DORA is the specialised ICT resilience framework.
Official sources
Comparisons are grounded explainers, not legal advice. Use the linked EUR-Lex texts and official sources for binding legal wording.
Related terms
Does this comparison affect your company?
Enter your company and Lex builds a cited Exposure Map in about 30 seconds. Free, no login.