MiCA Compliance
Aegis Protocol Labs builds DORA-aligned ICT risk management, incident reporting and operational resilience software for MiCA-authorised CASPs across the European Union.
ICT Resilience Engineering for MiCA CASPs
Six technical disciplines covering DORA's full ICT risk management framework, from asset mapping to scenario testing and real-time incident classification.
ICT Risk Framework and Register
Asset inventory, threat modelling and risk quantification aligned to DORA Chapter II. Automated risk register with criticality scoring, control mapping and gap tracking against the EBA ICT risk taxonomy.
Incident Classification and Reporting
Real-time incident severity engine applying DORA Article 18 classification criteria. Automated threshold evaluation across client impact, geographic scope and reputational risk. Generates the ESMA-templated initial, intermediate and final reports within mandatory timelines.
Business Continuity and Recovery
BCP design and automation covering DORA Chapter IV requirements: recovery time objectives (RTO), recovery point objectives (RPO), failover orchestration and post-incident restoration runbooks. Tested against real CASP infrastructure in 23 scenario exercises.
ICT Scenario Testing and TLPT Readiness
Design and execution of DORA Article 26 scenario tests: network partition, core API failure, key-management outage and third-party provider disruption. TLPT preparation for significant entities including red-team scope documentation and intelligence briefing packages.
Third-Party ICT Risk and CTPP Management
Full DORA Chapter V implementation: ICT provider register, criticality assessment, contractual SLA validation and CTPP designation logic. Dashboard surfaces providers approaching the Critical ICT Third-Party Service Provider threshold under Article 31 oversight.
Operational Monitoring and MiCA Compliance Dashboards
Real-time uptime telemetry, ICT risk KPI dashboards and automated MiCA compliance status reporting. Integrates with existing SIEM, APM and on-call tooling. Provides the auditable evidence trail required for supervisory inspections by the national competent authority.
CASP Segments and FinTech Verticals
Aegis Protocol Labs serves the full range of MiCA-regulated entities, from centralised exchanges to DeFi infrastructure operators and payment token issuers.
The Engineering Platform Behind DORA Compliance
Our MiCA compliance software stack combines proven observability infrastructure with purpose-built DORA compliance modules, deployed on-premises or in private cloud.
ICT Risk and Monitoring
Incident Management
Resilience and Continuity
Compliance Evidence
Security Controls
Integration Connectors
Three Engagements, Measurable Outcomes
Each DORA and MiCA compliance programme is built around the client's specific ICT environment. Here are three representative deployments with verifiable metrics.
Baltic Exchange: Full DORA Programme
An Estonian crypto exchange processing EUR 480M in monthly volume needed a full DORA compliance programme before their MiCA CASP authorisation filing. Their legacy incident process had no classification engine and no regulatory reporting workflow.
Aegis Protocol Labs delivered an end-to-end DORA framework: ICT risk register covering 218 assets, a real-time incident severity engine, automated ESMA initial and intermediate reporting and three ICT scenario tests including a simulated order-book API partition.
Pan-Baltic Custodian: BCP and Recovery Automation
A custody provider holding EUR 940M in client assets across Lithuania, Latvia and Estonia lacked a documented business continuity plan meeting ISO 22301 and DORA Chapter IV requirements. Regulator correspondence had flagged the gap as a conditional authorisation risk.
Aegis Protocol Labs designed and implemented automated BCP with per-site failover orchestration, RTO of 18 minutes and RPO of four minutes for critical key-management services. Two full-scale disaster-recovery rehearsals validated outcomes before filing.
Payments FinTech: Third-Party ICT Risk Module
A crypto-to-fiat payments FinTech with 14 ICT third-party providers, including two cloud infrastructure providers and a KYC API, needed DORA Chapter V compliance before its MiCA compliance deadline. No provider register existed and SLAs had not been reviewed since 2022.
Aegis Protocol Labs built a DORA-compliant provider register covering 14 vendors, conducted criticality assessments, flagged one cloud provider as a potential CTPP candidate, renegotiated contractual SLAs on four relationships and delivered a third-party risk dashboard feeding the central ICT risk register.
Our Own Certifications and Security Track Record
Aegis Protocol Labs holds the same security and continuity certifications we build for clients. Our security posture is independently audited and our track record is measurable.
ISO 27001:2022
Certificate EE-27001-8830 issued by Bureau Veritas. Information security management system covering all DORA software development and client-data processing activities.
SOC 2 Type II
Annual SOC 2 Type II audit covering Security, Availability and Confidentiality trust service criteria. Report available to clients under NDA.
ISO 22301:2019
Business continuity management system certification covering our own operational continuity. We maintain the same BCP standards we design for our CASP clients.
Regulatory Alignment
Operating under Estonian Financial Supervisory Authority oversight. DORA-aware development practices aligned to Regulation (EU) 2022/2554 and EBA/ESMA technical standards.
> security_track_record.log
Verified outcomes across 18 live DORA/resilience programmes since 2020.
Regulatory References
All software is built against: EUR-Lex publications of Regulation (EU) 2023/1114 (MiCA) and Regulation (EU) 2022/2554 (DORA); EBA ICT and security risk guidelines; ESMA Guidelines on ICT security and governance. Implementation-level regulatory intelligence is sourced directly from the Estonian Financial Supervisory Authority and the European Securities and Markets Authority (ESMA).
Choose the Right Delivery Model for Your DORA Timeline
Three engagement models to match your MiCA compliance urgency, internal team capacity and regulatory deadline pressure.
| Model | Best For | Cost Model | Typical Timeline | Regulatory Output |
|---|---|---|---|---|
| Fixed-Scope Build | CASPs with defined DORA gaps and a hard authorisation deadline | Fixed fee from EUR 33k | 8 to 16 weeks | Signed-off ICT risk register, BCP, incident classifier |
| Dedicated DORA Team | Exchanges and custodians with complex, multi-jurisdiction ICT environments | Time and materials from EUR 66k | 16 to 32 weeks | Full DORA programme: Chapters II-V plus scenario tests |
| Managed Run Retainer | Post-go-live MiCA CASPs requiring ongoing resilience operations and drill scheduling | EUR 12k/month | Ongoing | Monthly KPI dashboards, drill reports, incident support |
Which DORA Requirements Apply to Your CASP?
DORA's obligations scale with entity type, volume and systemic importance. Use this table to identify the chapters that apply before scoping your MiCA compliance programme.
| CASP Profile | DORA Chapter II (ICT Risk) | Chapter III (Incident) | Chapter IV (BCP) | Chapter V (Third-Party) | TLPT Required |
|---|---|---|---|---|---|
| Small CASP (< EUR 50M volume) | Simplified | Yes | Yes | Proportionate | No |
| Mid-size Exchange (EUR 50M-500M) | Full | Full | Full | Full | No |
| Large CASP / Custodian (> EUR 500M) | Full | Full | Full | Full | Yes (3-yr cycle) |
| ART / EMT Issuer | Full | Full | Enhanced | Full | Potentially |
Applicability guidance based on DORA Regulation (EU) 2022/2554 and EBA ICT risk RTS. Confirm scope with your national competent authority.
Four Phases From Assessment to Production
Our structured delivery method has been refined across 18 live DORA programmes. Each phase produces regulatory artefacts, not just code.
Map
ICT asset inventory, threat-landscape analysis, current-state gap assessment against DORA Chapters II-V. Output: risk register v0.1 and scope decision.
Build
Develop the compliance software modules: incident classifier, BCP automation, third-party register and monitoring dashboards. Output: deployable stack with test coverage.
Test
Execute DORA Article 26 scenario tests against live infrastructure, document outcomes and remediate gaps. Output: test reports and residual risk statements.
Operate
Hand over to client team or continue as managed retainer. Monthly drills, KPI reporting, regulatory update monitoring. Output: ongoing audit evidence trail.
What to Evaluate Before Hiring a DORA Software Partner
Six questions to ask any MiCA compliance software provider before signing a statement of work.
Transparent DORA Programme Pricing
Three packages designed for different DORA and MiCA compliance needs. All prices in EUR. Fixed-fee build options available; time-and-materials variants for complex multi-jurisdiction environments.
- ICT asset inventory and risk register v1.0
- Business continuity plan design
- RTO and RPO definition and documentation
- One DORA Article 26 scenario test
- Resilience KPI dashboard (read-only)
- Handover documentation and staff briefing
- Everything in Resilience Package
- Incident classification engine (real-time)
- ESMA-templated regulatory reporting pipeline
- Third-party ICT risk register and SLA review
- CTPP threshold analysis and flag
- Three ICT scenario tests with full documentation
- Full MiCA compliance dashboard with evidence trail
- 90 days post-go-live support
- Monthly ICT drill scheduling and execution
- Continuous uptime and MTTR monitoring
- Regulatory update alerts and impact assessments
- Incident support on-call (business hours)
- Quarterly resilience programme review
- Annual scenario test included
What Determines Your DORA Programme Investment
Six factors that drive scope and therefore cost. Understanding these helps you prioritise the right areas before our first scoping call.
ICT Asset Count
More assets mean a larger risk register and longer mapping phase. Exchanges with microservice architectures typically scope 150 to 400 ICT assets; custodians with key-management infrastructure often exceed this.
Number of Scenario Tests
Each DORA Article 26 scenario test requires preparation, execution, documentation and remediation. Basic programmes include one; full programmes include three. TLPT adds significant additional cost for significant entities.
Third-Party ICT Provider Count
DORA Chapter V requires criticality assessment per provider. 5 providers is straightforward; 20 providers with multiple cloud dependencies and a potential CTPP candidate significantly extends delivery time.
Multi-Jurisdiction Operations
CASPs operating across more than one EU member state face multiple NCAs with potentially different supervisory expectations. Cross-border BCP and incident reporting add coordination overhead.
Existing Internal Tooling
Clients with mature SIEM, APM and incident tooling are faster to integrate. Starting from zero monitoring infrastructure adds an infrastructure layer before DORA-specific compliance logic can be built.
Regulatory Deadline Urgency
Accelerated timelines require dedicated team capacity and may involve parallel workstreams. Our standard DORA Full Programme runs 16 to 20 weeks; a compressed 10-week sprint programme is possible at a premium.
Emerging AI Capabilities in DORA and MiCA Compliance
AI is changing how ICT risk is detected, classified and remediated. Aegis Protocol Labs is integrating three AI capabilities into its resilience stack for 2026 deployments.
AI-Assisted Incident Classification
Large-language model classifiers trained on DORA Article 18 criteria assist human operators in real-time severity evaluation. The model ingests telemetry, correlates events and proposes initial/intermediate/final classification with confidence scores, reducing misclassification risk and accelerating the mandatory four-hour notification window.
Predictive ICT Risk Scoring
Time-series anomaly detection models monitor ICT asset health telemetry and predict elevated failure probability before incidents occur. For MiCA compliance teams, this converts reactive DORA incident management into proactive risk control, lowering the frequency of Article 19 notifications.
Automated Scenario Generation
AI-driven threat intelligence feeds generate novel ICT scenario parameters based on current threat actor behaviour and known CASP attack surfaces. Scenarios are validated against DORA Article 26 requirements before execution, ensuring scenario testing is representative of real-world risk rather than repeated fixed scripts.
44 Engineers Across Seven Specialist Roles
Every DORA programme is staffed with a cross-functional team drawn from our 44-person Tallinn engineering group. Here is who works on your project.
DORA Programme Architect
Owns the end-to-end DORA compliance design, from Chapter II risk framework through to Chapter V third-party controls.
ICT Risk Engineer
Builds the risk register, asset inventory and threat model. Maps controls to DORA chapters and EBA ICT risk RTS requirements.
Incident Response Engineer
Designs and implements the incident classification engine, ESMA reporting pipeline and on-call alerting integration.
Security and Audit Lead
Conducts scenario testing, red-team exercises and security review of ICT controls. Prepares TLPT scope documentation for significant entities.
Regulatory Compliance Specialist
Ensures all software artefacts satisfy the current DORA technical standards and aligns deliverables with NCA supervisory expectations in the client's jurisdiction.
Observability Engineer
Deploys and configures uptime monitoring, SIEM integration and KPI dashboard for ongoing DORA compliance visibility.
Delivery Manager
Single point of contact for the client. Owns timeline, milestone sign-offs, regulatory artefact delivery and post-go-live transition.
Concrete DORA Deliverables, Not Just Code
Every Aegis Protocol Labs programme closes with a defined set of regulatory artefacts and software components. You own everything: source code, documentation and audit evidence.
Our Commitments to Every DORA Client
We take the compliance risk seriously. These commitments reduce your exposure and make the engagement decision straightforward.
Free Scoping Session
A 90-minute technical scoping call with Dr. Karl Tamm and our DORA architect at no cost, resulting in a written scope and indicative timeline.
Fixed-Price Discovery Phase
The first four weeks (ICT asset mapping and gap assessment) are available as a fixed-price EUR 9,500 engagement, applicable to the full programme if you proceed.
Client Owns Source Code and IP
All software, configurations and documentation produced under the engagement are assigned to the client on final payment. No vendor lock-in, no licence fees.
Scenario Test Pass Commitment
We remediate any gaps identified during DORA Article 26 scenario testing at no additional cost until the tests produce documented pass outcomes.
No Third-Party Dependency Lock-In
The resilience stack is built on open standards (OpenTelemetry, XBRL, REST). You can operate, extend or migrate without needing Aegis Protocol Labs on retainer.
Defined Handover and Exit
Every programme ends with a documented handover sprint, knowledge-transfer sessions and a 90-day exit pack so your team can operate independently from day one.
Dr. Karl Tamm
Dr. Karl Tamm founded Aegis Protocol Labs in 2020 after a decade leading incident-response and ICT resilience operations at a pan-Baltic financial market infrastructure provider. His PhD research at Tallinn University of Technology focused on failure propagation in distributed systems under network partition conditions, directly informing the firm's approach to DORA scenario testing.
Before founding Aegis, Karl led a team responsible for maintaining 99.99% uptime across clearing and settlement infrastructure serving three Baltic exchanges. When MiCA and DORA began to extend similar resilience obligations to crypto-asset service providers, he saw a gap: most RegTech firms offered policy templates but not the engineered software systems CASPs need to actually meet the technical requirements.
Today he oversees the DORA architecture and ICT risk methodology across all 18 active programmes and personally leads the TLPT scope design for significant-entity clients.
Certified, Recognised, Independently Verified
DORA RegTech Partner of the Year 2025
Operational Resilience Review · January 2025. Recognising the firm's contribution to CASP ICT resilience across the Baltic region.
ISO 27001 Certified
Certificate EE-27001-8830 · Bureau Veritas · Valid 2024-2027. Information security management covering all client-data and software development activities.
SOC 2 Type II
Annual audit · Security, Availability, Confidentiality trust service criteria · Current reporting period: 2025-2026. Report available under NDA.
ISO 22301 Certified
Business continuity management system · Certificate EE-22301-4410 · Bureau Veritas · Valid 2024-2027. Our own BCP meets the standard we build for clients.
ICT Risk Excellence Award 2024
Estonia Digital Journal · June 2024. Industry recognition for the ICT scenario testing methodology developed and applied across 23 CASP environments.
ESMA Technical Standards Alignment
All DORA reporting templates maintained against current ESMA RTS. Updated within 30 days of any regulatory amendment. No client has filed a non-conforming incident report.
Where Aegis Protocol Labs Publishes and Speaks
Dr. Karl Tamm contributes quarterly ICT risk analysis to Operational Resilience Review and DORA Dispatch and speaks annually at the Baltic RegTech Summit on DORA scenario testing methodology.
What CASP Teams Say About the Programmes
Verified reviews from Clutch and G2. No testimonials without a named client contact and company.
"The incident classification engine Aegis built for us reduced our classification time from 40 minutes to under 3 minutes. The first real major incident we had, we notified the FIU within two hours. DORA requires four. That margin saved us from a formal breach."
"We went into the DORA programme with no ICT asset inventory. Aegis mapped 234 assets across our custody infrastructure in four weeks. The risk register is now the source of truth for our board-level risk reporting."
"Karl Tamm's team challenged our assumptions about what 'resilience' meant in practice. Before the scenario tests, we thought our RTO was 30 minutes. The first test showed 94 minutes. After remediation, we achieved 16. The gap between assumed and tested RTO is why these exercises matter."
"The third-party risk module surfaced a CTPP designation risk with our primary cloud provider that we had not anticipated. Addressing it took eight weeks but it was critical before our MiCA compliance filing. Aegis Protocol Labs' depth on DORA Chapter V is unmatched in the Baltic market."
"We retained Aegis on the Run Retainer after the initial build. Monthly drills are scheduled and documented, the KPI dashboard gives our board a live view of resilience posture and the regulatory update service has saved us considerable internal research time."
ICT Scenario Testing Outcomes Across 23 CASP Environments
Measuring DORA Readiness: ICT Scenario Testing Outcomes Across 23 CASP Environments
This research note analyses 23 live ICT scenario tests conducted by Aegis Protocol Labs across CASP environments in 2024-2025 under DORA Article 26 requirements. The study documents failure modes, RTO shortfalls and classification-engine accuracy across three scenario categories: network partition, key-management outage and third-party API failure. Mean initial RTO assumption across clients was 28 minutes; post-test measured RTO was 64 minutes, a 2.3x gap driven primarily by undocumented manual recovery steps. After remediation, median RTO fell to 17 minutes.
The note identifies the four most common DORA compliance gaps across CASPs: absence of a tested BCP, incomplete ICT asset inventory, no real-time incident classification engine and unreviewed third-party SLAs. These findings inform the standard scope of the Aegis DORA Full Programme.
Request Research NoteKey Findings
- Mean assumed RTO: 28 min vs measured 64 min (2.3x gap)
- Median post-remediation RTO: 17 minutes
- 83% of CASPs lacked a tested BCP at programme start
- Network partition was the highest-impact scenario type
- Third-party API failure was the least-prepared-for scenario
- Incident classification accuracy improved 91% after engine deployment
- Zero clients had a complete ICT asset inventory on day one
DORA, MiCA Compliance and ICT Risk Questions
What does a MiCA compliance software company do?
How much does MiCA compliance software cost?
How do I choose a MiCA compliance software provider?
Does DORA apply to CASPs under MiCA?
What is the DORA incident reporting timeline for CASPs?
What ICT scenario tests does DORA require?
How long does a full DORA programme implementation take?
Can Aegis Protocol Labs help with DORA third-party ICT risk?
Key Terms in Operational Resilience and MiCA Compliance
Privacy, Terms and Editorial Policy
Privacy Policy
Effective date: 1 March 2025. Last reviewed: 21 June 2026.
Aegis Protocol Labs OU (VAT EE102158640, Harju County Court) operates mica-compliance.xyz. We collect only the personal data you voluntarily provide when contacting us (name, company, email address, enquiry content). We do not use analytics cookies, third-party tracking scripts or advertising pixels on this website. All site assets are self-hosted; no external requests are made.
Personal data submitted via the contact form is processed under Article 6(1)(b) GDPR (processing necessary to take steps at the request of the data subject prior to entering a contract) and retained for a maximum of 36 months unless a contract is formed. You have the rights to access, rectify, erase and port your data and to object to processing, by writing to privacy@mica-compliance.xyz. You may lodge a complaint with the Estonian Data Protection Inspectorate (www.aki.ee).
Terms of Use
Effective date: 1 March 2025.
This website is operated by Aegis Protocol Labs OU, registered in Estonia (Harju County Court, Tartu Registry, reg. 16482209). The content is provided for informational purposes. Nothing on this site constitutes legal advice or a binding offer. Services described are subject to a signed statement of work.
All content is the intellectual property of Aegis Protocol Labs OU unless otherwise noted. Reproduction for commercial purposes requires written permission. Disputes are governed by Estonian law and the jurisdiction of the courts of Tallinn, Estonia.
Editorial Policy and Corrections
Last reviewed: 21 June 2026 by Dr. Karl Tamm, Founder and CTO.
All factual claims on this page are based on verifiable programme outcomes, certified credentials or publicly available regulatory texts. Every metric (uptime, MTTR, programme count, scenario test count) reflects aggregated measurements from live client engagements, not projections. Regulatory references cite the official EUR-Lex texts of Regulation (EU) 2023/1114 and Regulation (EU) 2022/2554.
To report a factual error or request a correction, write to editorial@mica-compliance.xyz. We commit to reviewing and publishing corrections within 14 days of a verified error report. The page date-modified field and the "Last reviewed" byline are updated with each substantive revision.
Start Your MiCA Compliance Assessment
Every DORA programme begins with a free 90-minute scoping call with Dr. Karl Tamm and our programme architect. We identify your ICT risk gaps, estimate your DORA Chapter applicability and give you a written scope before you commit to anything.
Headquarters
Aegis Protocol Labs OU
Pärnu maantee 139c
Tallinn 11317, Estonia
Phone
+372 614 8800Business Hours
Monday to Friday, 09:00 to 18:00 EET (UTC+2)
Legal
VAT EE102158640 · Reg. 16482209
Harju County Court (Tartu Registry)
Book a Free DORA Scoping Call
Fill in the form and a member of our team will contact you within one business day to arrange the call with Dr. Karl Tamm.