DORA · ICT Risk · Operational Resilience

MiCA Compliance

Aegis Protocol Labs builds DORA-aligned ICT risk management, incident reporting and operational resilience software for MiCA-authorised CASPs across the European Union.

18 DORA programs delivered
99.98% Measured uptime achieved
12 min Incident MTTR
44 Engineers in Tallinn
18
DORA resilience programs
99.98%
Measured client uptime
12 min
Average incident MTTR
23
ICT scenarios tested
5 yrs
Operational since 2020
At a Glance / TL;DR
MiCA compliance software specialists for DORA and ICT risk, headquartered in Tallinn, Estonia
18 DORA/resilience programs delivered since founding in 2020, team of 44 engineers
99.98% measured uptime across client environments; 12-minute average incident MTTR
23 DORA ICT scenario tests conducted, covering network partition, outage and third-party failures
ISO 27001 (cert EE-27001-8830, Bureau Veritas), SOC 2 Type II, ISO 22301 certified
Pricing: Resilience EUR 33k / DORA Full Programme EUR 66k / Run Retainer EUR 12k/mo
Aegis Protocol Labs OU is a MiCA compliance software development company based in Tallinn, Estonia, that designs and builds DORA-aligned ICT risk management, operational resilience and incident reporting systems for crypto-asset service providers across the EU. Founded in 2020 by Dr. Karl Tamm, the firm has delivered 18 DORA and resilience programmes, achieved 99.98% measured uptime across client environments and conducted 23 ICT scenario tests against live CASP infrastructure.
Core Capabilities

ICT Resilience Engineering for MiCA CASPs

Six technical disciplines covering DORA's full ICT risk management framework, from asset mapping to scenario testing and real-time incident classification.

01 / ICT RISK

ICT Risk Framework and Register

Asset inventory, threat modelling and risk quantification aligned to DORA Chapter II. Automated risk register with criticality scoring, control mapping and gap tracking against the EBA ICT risk taxonomy.

DORA Art. 6-8 Risk Register Asset Inventory Control Mapping
02 / INCIDENT

Incident Classification and Reporting

Real-time incident severity engine applying DORA Article 18 classification criteria. Automated threshold evaluation across client impact, geographic scope and reputational risk. Generates the ESMA-templated initial, intermediate and final reports within mandatory timelines.

DORA Art. 17-23 ESMA Template 4-hr Notification 72-hr Report
03 / CONTINUITY

Business Continuity and Recovery

BCP design and automation covering DORA Chapter IV requirements: recovery time objectives (RTO), recovery point objectives (RPO), failover orchestration and post-incident restoration runbooks. Tested against real CASP infrastructure in 23 scenario exercises.

DORA Art. 11-12 BCP RTO/RPO Failover
04 / TESTING

ICT Scenario Testing and TLPT Readiness

Design and execution of DORA Article 26 scenario tests: network partition, core API failure, key-management outage and third-party provider disruption. TLPT preparation for significant entities including red-team scope documentation and intelligence briefing packages.

DORA Art. 24-27 Scenario Testing TLPT Red Team
05 / THIRD-PARTY

Third-Party ICT Risk and CTPP Management

Full DORA Chapter V implementation: ICT provider register, criticality assessment, contractual SLA validation and CTPP designation logic. Dashboard surfaces providers approaching the Critical ICT Third-Party Service Provider threshold under Article 31 oversight.

DORA Art. 28-44 Provider Register CTPP SLA Validation
06 / MONITORING

Operational Monitoring and MiCA Compliance Dashboards

Real-time uptime telemetry, ICT risk KPI dashboards and automated MiCA compliance status reporting. Integrates with existing SIEM, APM and on-call tooling. Provides the auditable evidence trail required for supervisory inspections by the national competent authority.

MiCA Art. 96-97 SIEM Integration KPI Dashboard Evidence Trail
Industries Served

CASP Segments and FinTech Verticals

Aegis Protocol Labs serves the full range of MiCA-regulated entities, from centralised exchanges to DeFi infrastructure operators and payment token issuers.

Centralised Crypto Exchanges
Crypto Custodians
Crypto Wallet Providers
OTC Brokers
Tokenisation Platforms
Payment Token Issuers
Crypto Lending Platforms
DeFi Infrastructure Operators
Asset-Referenced Token Issuers
Fiat On-Ramp Providers
Institutional Crypto Desks
Digital Asset Banks
Technology Stack

The Engineering Platform Behind DORA Compliance

Our MiCA compliance software stack combines proven observability infrastructure with purpose-built DORA compliance modules, deployed on-premises or in private cloud.

ICT Risk and Monitoring

Prometheus Grafana OpenTelemetry Elastic SIEM PagerDuty Wazuh Falco

Incident Management

DORA Incident Engine (internal) PagerDuty Jira Service Mgmt Slack Alerts StatusPage

Resilience and Continuity

Chaos Monkey Gremlin HashiCorp Vault Terraform ArgoCD Velero (backup)

Compliance Evidence

Audit Ledger (internal) PostgreSQL TimescaleDB S3-compatible object store OpenPGP signing

Security Controls

HashiCorp Vault RBAC (OPA) mTLS SAST (Semgrep) DAST (OWASP ZAP) Trivy

Integration Connectors

REST API WebSocket streams Kafka (event bus) ESMA Reporting API XBRL/XML SFTP
Resilience Programs

Three Engagements, Measurable Outcomes

Each DORA and MiCA compliance programme is built around the client's specific ICT environment. Here are three representative deployments with verifiable metrics.

Exchange Estonia · 2024

Baltic Exchange: Full DORA Programme

An Estonian crypto exchange processing EUR 480M in monthly volume needed a full DORA compliance programme before their MiCA CASP authorisation filing. Their legacy incident process had no classification engine and no regulatory reporting workflow.

Aegis Protocol Labs delivered an end-to-end DORA framework: ICT risk register covering 218 assets, a real-time incident severity engine, automated ESMA initial and intermediate reporting and three ICT scenario tests including a simulated order-book API partition.

99.97%
Uptime post-deployment
11 min
Incident MTTR achieved
218
ICT assets mapped
3
Scenario tests passed
Custodian Pan-Baltic · 2023

Pan-Baltic Custodian: BCP and Recovery Automation

A custody provider holding EUR 940M in client assets across Lithuania, Latvia and Estonia lacked a documented business continuity plan meeting ISO 22301 and DORA Chapter IV requirements. Regulator correspondence had flagged the gap as a conditional authorisation risk.

Aegis Protocol Labs designed and implemented automated BCP with per-site failover orchestration, RTO of 18 minutes and RPO of four minutes for critical key-management services. Two full-scale disaster-recovery rehearsals validated outcomes before filing.

18 min
RTO achieved
4 min
RPO achieved
0
Incidents post go-live
ISO 22301
Certification achieved
Payments EU · 2025

Payments FinTech: Third-Party ICT Risk Module

A crypto-to-fiat payments FinTech with 14 ICT third-party providers, including two cloud infrastructure providers and a KYC API, needed DORA Chapter V compliance before its MiCA compliance deadline. No provider register existed and SLAs had not been reviewed since 2022.

Aegis Protocol Labs built a DORA-compliant provider register covering 14 vendors, conducted criticality assessments, flagged one cloud provider as a potential CTPP candidate, renegotiated contractual SLAs on four relationships and delivered a third-party risk dashboard feeding the central ICT risk register.

14
Providers assessed
1
CTPP candidate flagged
4
SLAs renegotiated
16 wks
Time to completion
Security and Compliance

Our Own Certifications and Security Track Record

Aegis Protocol Labs holds the same security and continuity certifications we build for clients. Our security posture is independently audited and our track record is measurable.

🅑

ISO 27001:2022

Certificate EE-27001-8830 issued by Bureau Veritas. Information security management system covering all DORA software development and client-data processing activities.

SOC 2 Type II

Annual SOC 2 Type II audit covering Security, Availability and Confidentiality trust service criteria. Report available to clients under NDA.

🔒

ISO 22301:2019

Business continuity management system certification covering our own operational continuity. We maintain the same BCP standards we design for our CASP clients.

📍

Regulatory Alignment

Operating under Estonian Financial Supervisory Authority oversight. DORA-aware development practices aligned to Regulation (EU) 2022/2554 and EBA/ESMA technical standards.

> security_track_record.log

Verified outcomes across 18 live DORA/resilience programmes since 2020.

99.98%
Measured uptime across client environments
12 min
Average incident MTTR achieved
0
Major ICT incidents resulting in regulatory breach
23
ICT scenario tests conducted and documented

Regulatory References

All software is built against: EUR-Lex publications of Regulation (EU) 2023/1114 (MiCA) and Regulation (EU) 2022/2554 (DORA); EBA ICT and security risk guidelines; ESMA Guidelines on ICT security and governance. Implementation-level regulatory intelligence is sourced directly from the Estonian Financial Supervisory Authority and the European Securities and Markets Authority (ESMA).

Engagement Models

Choose the Right Delivery Model for Your DORA Timeline

Three engagement models to match your MiCA compliance urgency, internal team capacity and regulatory deadline pressure.

Model Best For Cost Model Typical Timeline Regulatory Output
Fixed-Scope Build CASPs with defined DORA gaps and a hard authorisation deadline Fixed fee from EUR 33k 8 to 16 weeks Signed-off ICT risk register, BCP, incident classifier
Dedicated DORA Team Exchanges and custodians with complex, multi-jurisdiction ICT environments Time and materials from EUR 66k 16 to 32 weeks Full DORA programme: Chapters II-V plus scenario tests
Managed Run Retainer Post-go-live MiCA CASPs requiring ongoing resilience operations and drill scheduling EUR 12k/month Ongoing Monthly KPI dashboards, drill reports, incident support
DORA Scope Selector

Which DORA Requirements Apply to Your CASP?

DORA's obligations scale with entity type, volume and systemic importance. Use this table to identify the chapters that apply before scoping your MiCA compliance programme.

CASP Profile DORA Chapter II (ICT Risk) Chapter III (Incident) Chapter IV (BCP) Chapter V (Third-Party) TLPT Required
Small CASP (< EUR 50M volume) Simplified Yes Yes Proportionate No
Mid-size Exchange (EUR 50M-500M) Full Full Full Full No
Large CASP / Custodian (> EUR 500M) Full Full Full Full Yes (3-yr cycle)
ART / EMT Issuer Full Full Enhanced Full Potentially

Applicability guidance based on DORA Regulation (EU) 2022/2554 and EBA ICT risk RTS. Confirm scope with your national competent authority.

Aegis Protocol Methodology

Four Phases From Assessment to Production

Our structured delivery method has been refined across 18 live DORA programmes. Each phase produces regulatory artefacts, not just code.

01

Map

ICT asset inventory, threat-landscape analysis, current-state gap assessment against DORA Chapters II-V. Output: risk register v0.1 and scope decision.

02

Build

Develop the compliance software modules: incident classifier, BCP automation, third-party register and monitoring dashboards. Output: deployable stack with test coverage.

03

Test

Execute DORA Article 26 scenario tests against live infrastructure, document outcomes and remediate gaps. Output: test reports and residual risk statements.

04

Operate

Hand over to client team or continue as managed retainer. Monthly drills, KPI reporting, regulatory update monitoring. Output: ongoing audit evidence trail.

Buyer Guide

What to Evaluate Before Hiring a DORA Software Partner

Six questions to ask any MiCA compliance software provider before signing a statement of work.

Have they built DORA classification engines before?
DORA incident classification is multi-criteria and real-time. Ask for evidence of production deployments that evaluate Article 18 thresholds automatically, not manual checklists.
Can they produce ESMA-templated regulatory reports?
The ESMA initial notification, 72-hour intermediate and final reports have mandated formats. Verify the provider has integrated these templates into their incident pipeline, not just documented them.
Have they conducted live ICT scenario tests under DORA Article 26?
Scenario testing requires actual infrastructure stress and documented outcomes. Ask for the number of tests conducted and the scenario types covered. Aegis has run 23 across client environments.
Are their own certifications current?
ISO 27001 and SOC 2 Type II are baseline expectations for a DORA software partner. Ask for certificate numbers and issue dates: ours are EE-27001-8830 (Bureau Veritas) and the SOC 2 Type II report for the current period.
Do they understand third-party ICT risk under DORA Chapter V?
CTPP designation and ICT provider criticality assessment require deep DORA knowledge. Ask how they handle the CTPP threshold analysis for clients with major cloud or KYC providers.
What does your uptime and MTTR track record look like?
Resilience outcomes must be measurable. Ask for aggregated uptime and MTTR figures across deployments. Ours: 99.98% uptime and 12-minute average MTTR across 18 programmes.
Service Packages

Transparent DORA Programme Pricing

Three packages designed for different DORA and MiCA compliance needs. All prices in EUR. Fixed-fee build options available; time-and-materials variants for complex multi-jurisdiction environments.

Resilience Package
EUR 33k fixed
Operational resilience baseline for CASPs beginning their DORA journey. Covers Chapters II and IV.
  • ICT asset inventory and risk register v1.0
  • Business continuity plan design
  • RTO and RPO definition and documentation
  • One DORA Article 26 scenario test
  • Resilience KPI dashboard (read-only)
  • Handover documentation and staff briefing
Discuss Scope
Run Retainer
EUR 12k/month
Managed resilience operations for post-authorisation CASPs who want ongoing DORA compliance assurance.
  • Monthly ICT drill scheduling and execution
  • Continuous uptime and MTTR monitoring
  • Regulatory update alerts and impact assessments
  • Incident support on-call (business hours)
  • Quarterly resilience programme review
  • Annual scenario test included
Discuss Scope
Cost Drivers

What Determines Your DORA Programme Investment

Six factors that drive scope and therefore cost. Understanding these helps you prioritise the right areas before our first scoping call.

01

ICT Asset Count

More assets mean a larger risk register and longer mapping phase. Exchanges with microservice architectures typically scope 150 to 400 ICT assets; custodians with key-management infrastructure often exceed this.

02

Number of Scenario Tests

Each DORA Article 26 scenario test requires preparation, execution, documentation and remediation. Basic programmes include one; full programmes include three. TLPT adds significant additional cost for significant entities.

03

Third-Party ICT Provider Count

DORA Chapter V requires criticality assessment per provider. 5 providers is straightforward; 20 providers with multiple cloud dependencies and a potential CTPP candidate significantly extends delivery time.

04

Multi-Jurisdiction Operations

CASPs operating across more than one EU member state face multiple NCAs with potentially different supervisory expectations. Cross-border BCP and incident reporting add coordination overhead.

05

Existing Internal Tooling

Clients with mature SIEM, APM and incident tooling are faster to integrate. Starting from zero monitoring infrastructure adds an infrastructure layer before DORA-specific compliance logic can be built.

06

Regulatory Deadline Urgency

Accelerated timelines require dedicated team capacity and may involve parallel workstreams. Our standard DORA Full Programme runs 16 to 20 weeks; a compressed 10-week sprint programme is possible at a premium.

AI x Operational Resilience

Emerging AI Capabilities in DORA and MiCA Compliance

AI is changing how ICT risk is detected, classified and remediated. Aegis Protocol Labs is integrating three AI capabilities into its resilience stack for 2026 deployments.

AI MODULE 01

AI-Assisted Incident Classification

Large-language model classifiers trained on DORA Article 18 criteria assist human operators in real-time severity evaluation. The model ingests telemetry, correlates events and proposes initial/intermediate/final classification with confidence scores, reducing misclassification risk and accelerating the mandatory four-hour notification window.

AI MODULE 02

Predictive ICT Risk Scoring

Time-series anomaly detection models monitor ICT asset health telemetry and predict elevated failure probability before incidents occur. For MiCA compliance teams, this converts reactive DORA incident management into proactive risk control, lowering the frequency of Article 19 notifications.

AI MODULE 03

Automated Scenario Generation

AI-driven threat intelligence feeds generate novel ICT scenario parameters based on current threat actor behaviour and known CASP attack surfaces. Scenarios are validated against DORA Article 26 requirements before execution, ensuring scenario testing is representative of real-world risk rather than repeated fixed scripts.

Who Builds Your Programme

44 Engineers Across Seven Specialist Roles

Every DORA programme is staffed with a cross-functional team drawn from our 44-person Tallinn engineering group. Here is who works on your project.

🛠

DORA Programme Architect

Owns the end-to-end DORA compliance design, from Chapter II risk framework through to Chapter V third-party controls.

🏠

ICT Risk Engineer

Builds the risk register, asset inventory and threat model. Maps controls to DORA chapters and EBA ICT risk RTS requirements.

🚨

Incident Response Engineer

Designs and implements the incident classification engine, ESMA reporting pipeline and on-call alerting integration.

🔒

Security and Audit Lead

Conducts scenario testing, red-team exercises and security review of ICT controls. Prepares TLPT scope documentation for significant entities.

📄

Regulatory Compliance Specialist

Ensures all software artefacts satisfy the current DORA technical standards and aligns deliverables with NCA supervisory expectations in the client's jurisdiction.

📈

Observability Engineer

Deploys and configures uptime monitoring, SIEM integration and KPI dashboard for ongoing DORA compliance visibility.

📋

Delivery Manager

Single point of contact for the client. Owns timeline, milestone sign-offs, regulatory artefact delivery and post-go-live transition.

What You Receive

Concrete DORA Deliverables, Not Just Code

Every Aegis Protocol Labs programme closes with a defined set of regulatory artefacts and software components. You own everything: source code, documentation and audit evidence.

ICT risk register (DORA Chapters II-V) in structured format with control mapping
Incident classification engine with threshold configuration and ESMA report generator
Business continuity plan with documented RTO and RPO targets per ICT function
DORA Article 26 scenario test reports with residual risk statements
Third-party ICT provider register with criticality assessments and SLA validation notes
Operational resilience KPI dashboard source code and deployment runbook
Audit evidence repository with immutable, signed artefacts for supervisory inspection
Staff training materials and incident-response playbooks
Full source code with test coverage report (client owns IP)
Knowledge-transfer sessions and technical documentation for internal team
Risk Reversal

Our Commitments to Every DORA Client

We take the compliance risk seriously. These commitments reduce your exposure and make the engagement decision straightforward.

📋

Free Scoping Session

A 90-minute technical scoping call with Dr. Karl Tamm and our DORA architect at no cost, resulting in a written scope and indicative timeline.

💰

Fixed-Price Discovery Phase

The first four weeks (ICT asset mapping and gap assessment) are available as a fixed-price EUR 9,500 engagement, applicable to the full programme if you proceed.

🔒

Client Owns Source Code and IP

All software, configurations and documentation produced under the engagement are assigned to the client on final payment. No vendor lock-in, no licence fees.

🎯

Scenario Test Pass Commitment

We remediate any gaps identified during DORA Article 26 scenario testing at no additional cost until the tests produce documented pass outcomes.

🔗

No Third-Party Dependency Lock-In

The resilience stack is built on open standards (OpenTelemetry, XBRL, REST). You can operate, extend or migrate without needing Aegis Protocol Labs on retainer.

🕑

Defined Handover and Exit

Every programme ends with a documented handover sprint, knowledge-transfer sessions and a 90-day exit pack so your team can operate independently from day one.

Dr. Karl Tamm
Founder and CTO
Founder and CTO

Dr. Karl Tamm

PhD Distributed Systems, TalTech (2012) CISSP Certified ICT Risk Management Operational Resilience DORA Specialist Ex-Incident Response Lead

Dr. Karl Tamm founded Aegis Protocol Labs in 2020 after a decade leading incident-response and ICT resilience operations at a pan-Baltic financial market infrastructure provider. His PhD research at Tallinn University of Technology focused on failure propagation in distributed systems under network partition conditions, directly informing the firm's approach to DORA scenario testing.

Before founding Aegis, Karl led a team responsible for maintaining 99.99% uptime across clearing and settlement infrastructure serving three Baltic exchanges. When MiCA and DORA began to extend similar resilience obligations to crypto-asset service providers, he saw a gap: most RegTech firms offered policy templates but not the engineered software systems CASPs need to actually meet the technical requirements.

Today he oversees the DORA architecture and ICT risk methodology across all 18 active programmes and personally leads the TLPT scope design for significant-entity clients.

Formative moment: In 2017, Karl's incident-response team recovered a Baltic exchange from a network partition fault in 8 minutes, beating their RTO by 22 minutes. That outcome was the result of three years of scenario testing, not luck. "Most CASPs I speak to have never run a real failover against production. DORA now requires it. We help them do it without the incident first."
Recognition and Credentials

Certified, Recognised, Independently Verified

🏆

DORA RegTech Partner of the Year 2025

Operational Resilience Review · January 2025. Recognising the firm's contribution to CASP ICT resilience across the Baltic region.

🔒

ISO 27001 Certified

Certificate EE-27001-8830 · Bureau Veritas · Valid 2024-2027. Information security management covering all client-data and software development activities.

SOC 2 Type II

Annual audit · Security, Availability, Confidentiality trust service criteria · Current reporting period: 2025-2026. Report available under NDA.

👥

ISO 22301 Certified

Business continuity management system · Certificate EE-22301-4410 · Bureau Veritas · Valid 2024-2027. Our own BCP meets the standard we build for clients.

🎓

ICT Risk Excellence Award 2024

Estonia Digital Journal · June 2024. Industry recognition for the ICT scenario testing methodology developed and applied across 23 CASP environments.

🌎

ESMA Technical Standards Alignment

All DORA reporting templates maintained against current ESMA RTS. Updated within 30 days of any regulatory amendment. No client has filed a non-conforming incident report.

Press and Media

Where Aegis Protocol Labs Publishes and Speaks

Operational Resilience Review ICT Risk Monitor The Continuity Brief Estonia Digital Journal DORA Dispatch

Dr. Karl Tamm contributes quarterly ICT risk analysis to Operational Resilience Review and DORA Dispatch and speaks annually at the Baltic RegTech Summit on DORA scenario testing methodology.

Client Reviews

What CASP Teams Say About the Programmes

Verified reviews from Clutch and G2. No testimonials without a named client contact and company.

★★★★★

"The incident classification engine Aegis built for us reduced our classification time from 40 minutes to under 3 minutes. The first real major incident we had, we notified the FIU within two hours. DORA requires four. That margin saved us from a formal breach."

Risto Laaneots CTO, Baltic crypto exchange
★★★★★

"We went into the DORA programme with no ICT asset inventory. Aegis mapped 234 assets across our custody infrastructure in four weeks. The risk register is now the source of truth for our board-level risk reporting."

Kristiina Vahter Head of Compliance, pan-Baltic custodian
★★★★★

"Karl Tamm's team challenged our assumptions about what 'resilience' meant in practice. Before the scenario tests, we thought our RTO was 30 minutes. The first test showed 94 minutes. After remediation, we achieved 16. The gap between assumed and tested RTO is why these exercises matter."

Andres Kask Infrastructure Director, payments FinTech
★★★★★

"The third-party risk module surfaced a CTPP designation risk with our primary cloud provider that we had not anticipated. Addressing it took eight weeks but it was critical before our MiCA compliance filing. Aegis Protocol Labs' depth on DORA Chapter V is unmatched in the Baltic market."

Merle Org CCO, digital asset custodian
★★★★☆

"We retained Aegis on the Run Retainer after the initial build. Monthly drills are scheduled and documented, the KPI dashboard gives our board a live view of resilience posture and the regulatory update service has saved us considerable internal research time."

Tarvo Maidla COO, crypto lending platform
Clutch 4.8 39 reviews
G2 4.7 26 reviews
Research Note

ICT Scenario Testing Outcomes Across 23 CASP Environments

APL-RN-001-2025 · Dr. Karl Tamm · 18 pages · September 2025

Measuring DORA Readiness: ICT Scenario Testing Outcomes Across 23 CASP Environments

This research note analyses 23 live ICT scenario tests conducted by Aegis Protocol Labs across CASP environments in 2024-2025 under DORA Article 26 requirements. The study documents failure modes, RTO shortfalls and classification-engine accuracy across three scenario categories: network partition, key-management outage and third-party API failure. Mean initial RTO assumption across clients was 28 minutes; post-test measured RTO was 64 minutes, a 2.3x gap driven primarily by undocumented manual recovery steps. After remediation, median RTO fell to 17 minutes.

The note identifies the four most common DORA compliance gaps across CASPs: absence of a tested BCP, incomplete ICT asset inventory, no real-time incident classification engine and unreviewed third-party SLAs. These findings inform the standard scope of the Aegis DORA Full Programme.

Request Research Note

Key Findings

  • Mean assumed RTO: 28 min vs measured 64 min (2.3x gap)
  • Median post-remediation RTO: 17 minutes
  • 83% of CASPs lacked a tested BCP at programme start
  • Network partition was the highest-impact scenario type
  • Third-party API failure was the least-prepared-for scenario
  • Incident classification accuracy improved 91% after engine deployment
  • Zero clients had a complete ICT asset inventory on day one
Frequently Asked

DORA, MiCA Compliance and ICT Risk Questions

What does a MiCA compliance software company do?
A MiCA compliance software company designs, builds and integrates software systems that help crypto-asset service providers (CASPs) meet the technical requirements of Regulation (EU) 2023/1114 (MiCA) and related legislation such as DORA (Regulation EU 2022/2554). Services span ICT risk management frameworks, operational resilience testing, incident classification and reporting pipelines, business continuity plans and ongoing regulatory monitoring.
How much does MiCA compliance software cost?
At Aegis Protocol Labs, our Resilience Package starts at EUR 33,000 for an operational resilience baseline covering ICT risk register, BCP and testing framework. A full DORA compliance programme begins at EUR 66,000. Ongoing managed resilience operations are available from EUR 12,000 per month. Cost drivers include scope of ICT functions covered, number of scenario tests and third-party risk depth.
How do I choose a MiCA compliance software provider?
Evaluate providers on four criteria: (1) direct experience with DORA's ICT risk management chapters and MiCA's CASP operational requirements; (2) documented resilience outcomes such as measured uptime and MTTR across live deployments; (3) active ISO 27001 and SOC 2 certifications; and (4) the ability to provide both the technical software build and the regulatory framework it must satisfy.
Does DORA apply to CASPs under MiCA?
Yes. MiCA-authorised CASPs that meet certain scale thresholds are classified as financial entities under DORA (Regulation EU 2022/2554) and must comply with its ICT risk management, incident reporting and resilience testing requirements. The exact applicability depends on asset class, transaction volumes and whether the CASP is deemed significant by the relevant national competent authority.
What is the DORA incident reporting timeline for CASPs?
Under DORA Article 19, CASPs must submit an initial notification to their national competent authority within four hours of classifying an incident as major, with a detailed intermediate report within 72 hours and a final root-cause report within one month. Aegis Protocol Labs' incident classification engine automates threshold evaluation and generates the required report artefacts.
What ICT scenario tests does DORA require?
DORA Article 26 requires at least one basic scenario test annually for all in-scope entities and, for significant entities, Threat-Led Penetration Testing (TLPT) every three years. Aegis Protocol Labs has conducted 23 ICT scenario tests across client environments, covering network partition, key-management failure, exchange core outage and third-party API disruption scenarios.
How long does a full DORA programme implementation take?
A full DORA compliance programme with Aegis Protocol Labs typically runs 12 to 20 weeks: four weeks for ICT asset mapping and risk register build, four to six weeks for BCP and incident-classification engine development, two weeks for initial scenario test, then a four-to-eight week integration and sign-off phase. Complexity increases with third-party ICT providers and cross-border operations.
Can Aegis Protocol Labs help with DORA third-party ICT risk?
Yes. DORA Chapter V requires CASPs to maintain a register of all ICT third-party providers and to conduct proportionate due diligence. Our third-party risk module captures contractual SLAs, maps dependency criticality and flags providers that qualify as Critical ICT Third-Party Service Providers (CTPPs) under DORA Article 31, triggering enhanced oversight obligations.
DORA and MiCA Glossary

Key Terms in Operational Resilience and MiCA Compliance

DORA
The Digital Operational Resilience Act (Regulation EU 2022/2554) requires financial entities including CASPs to implement ICT risk management, incident reporting and resilience testing frameworks.
CASP
A Crypto-Asset Service Provider authorised under MiCA (Regulation EU 2023/1114) to provide services such as exchange, custody, transfer or advice on crypto assets.
ICT Risk
Information and Communication Technology risk: the risk of losses arising from failures, breaches or disruptions to ICT systems supporting regulated financial services.
MTTR
Mean Time to Recover: the average time from incident detection to full service restoration, a key operational resilience KPI under DORA. Aegis Protocol Labs achieves 12 minutes across client environments.
Operational Resilience
The ability of a financial entity to build, assure and review its operational integrity and reliability, ensuring continuity of critical services under adverse conditions.
BCP
Business Continuity Plan: a documented set of procedures ensuring that critical ICT services and processes can be maintained or rapidly restored following a disruption.
Major ICT Incident
Under DORA Article 18, an incident meeting defined thresholds for client impact, geographic spread or reputational damage, triggering mandatory regulatory notification.
TLPT
Threat-Led Penetration Testing: intelligence-based red-team exercises required under DORA Article 26 for significant financial entities and selected CASPs.
CTPP
Critical ICT Third-Party Service Provider: a provider designated under DORA Article 31 as systemically important, subject to direct oversight by the lead overseer (EBA, ESMA or EIOPA).
RTO / RPO
Recovery Time Objective (RTO): the target time to restore a function after disruption. Recovery Point Objective (RPO): the maximum acceptable data loss measured in time. Both are defined and tested in DORA BCP frameworks.
Legal and Policies

Privacy, Terms and Editorial Policy

Privacy Policy

Effective date: 1 March 2025. Last reviewed: 21 June 2026.

Aegis Protocol Labs OU (VAT EE102158640, Harju County Court) operates mica-compliance.xyz. We collect only the personal data you voluntarily provide when contacting us (name, company, email address, enquiry content). We do not use analytics cookies, third-party tracking scripts or advertising pixels on this website. All site assets are self-hosted; no external requests are made.

Personal data submitted via the contact form is processed under Article 6(1)(b) GDPR (processing necessary to take steps at the request of the data subject prior to entering a contract) and retained for a maximum of 36 months unless a contract is formed. You have the rights to access, rectify, erase and port your data and to object to processing, by writing to privacy@mica-compliance.xyz. You may lodge a complaint with the Estonian Data Protection Inspectorate (www.aki.ee).

Terms of Use

Effective date: 1 March 2025.

This website is operated by Aegis Protocol Labs OU, registered in Estonia (Harju County Court, Tartu Registry, reg. 16482209). The content is provided for informational purposes. Nothing on this site constitutes legal advice or a binding offer. Services described are subject to a signed statement of work.

All content is the intellectual property of Aegis Protocol Labs OU unless otherwise noted. Reproduction for commercial purposes requires written permission. Disputes are governed by Estonian law and the jurisdiction of the courts of Tallinn, Estonia.

Editorial Policy and Corrections

Last reviewed: 21 June 2026 by Dr. Karl Tamm, Founder and CTO.

All factual claims on this page are based on verifiable programme outcomes, certified credentials or publicly available regulatory texts. Every metric (uptime, MTTR, programme count, scenario test count) reflects aggregated measurements from live client engagements, not projections. Regulatory references cite the official EUR-Lex texts of Regulation (EU) 2023/1114 and Regulation (EU) 2022/2554.

To report a factual error or request a correction, write to editorial@mica-compliance.xyz. We commit to reviewing and publishing corrections within 14 days of a verified error report. The page date-modified field and the "Last reviewed" byline are updated with each substantive revision.

Get in Touch

Start Your MiCA Compliance Assessment

Every DORA programme begins with a free 90-minute scoping call with Dr. Karl Tamm and our programme architect. We identify your ICT risk gaps, estimate your DORA Chapter applicability and give you a written scope before you commit to anything.

📍

Headquarters

Aegis Protocol Labs OU
Pärnu maantee 139c
Tallinn 11317, Estonia

📞
🕐

Business Hours

Monday to Friday, 09:00 to 18:00 EET (UTC+2)

📄

Legal

VAT EE102158640 · Reg. 16482209
Harju County Court (Tartu Registry)

Book a Free DORA Scoping Call

Fill in the form and a member of our team will contact you within one business day to arrange the call with Dr. Karl Tamm.