# Aegis Protocol Labs: MiCA Compliance > Aegis Protocol Labs OU is a MiCA compliance software development company based in Tallinn, Estonia, that designs and builds DORA-aligned ICT risk management, operational resilience and incident reporting systems for crypto-asset service providers across the EU. Founded in 2020 by Dr. Karl Tamm, the firm has delivered 18 DORA and resilience programmes, achieved 99.98% measured uptime across client environments, and conducted 23 ICT scenario tests against live CASP infrastructure. Canonical: https://mica-compliance.xyz/ Last updated: 2026-06-21 --- ## Quick facts - Company: Aegis Protocol Labs OU - Legal: Estonia, Harju County Court (Tartu Registry), reg. 16482209, VAT EE102158640 - HQ: Pärnu maantee 139c, Tallinn 11317, Estonia - Phone: +372 614 8800 - Email: hello@mica-compliance.xyz - Founder: Dr. Karl Tamm, PhD (Distributed Systems, TalTech 2012), Founder and CTO - Founded: 2020 (5 years operating) - Team: 44 engineers, Tallinn - Sub-niche: DORA, ICT risk management, operational resilience for MiCA CASPs - DORA resilience programmes delivered: 18 - Measured uptime achieved: 99.98% - Average incident MTTR: 12 minutes - ICT scenario tests conducted: 23 - Clutch rating: 4.8 / 5 (39 reviews) - G2 rating: 4.7 / 5 (26 reviews) - Certifications: ISO 27001 (cert EE-27001-8830, Bureau Veritas), SOC 2 Type II, ISO 22301 - Pricing: Resilience EUR 33k / DORA Full Programme EUR 66k / Run Retainer EUR 12k/mo - 301 context: part of pharosproduction.com MiCA compliance software portfolio --- ## Services Source: https://mica-compliance.xyz/#resilience Six technical disciplines covering DORA's full ICT risk management framework: 1. ICT Risk Framework and Register (DORA Chapters II-VIII; automated risk register with criticality scoring and EBA ICT risk taxonomy alignment) 2. Incident Classification and Reporting (DORA Articles 17-23; real-time severity engine; ESMA-templated initial, intermediate and final reports) 3. Business Continuity and Recovery (DORA Chapter IV; BCP automation, RTO/RPO definition, failover orchestration) 4. ICT Scenario Testing and TLPT Readiness (DORA Article 26; 23 tests conducted including network partition, key-management outage, third-party API failure; TLPT prep for significant entities) 5. Third-Party ICT Risk and CTPP Management (DORA Chapter V; ICT provider register, criticality assessment, CTPP designation threshold logic, SLA validation) 6. Operational Monitoring and MiCA Compliance Dashboards (MiCA Articles 96-97; SIEM integration, KPI dashboards, auditable evidence trail) --- ## Technology Stack Source: https://mica-compliance.xyz/#stack ICT Risk and Monitoring: Prometheus, Grafana, OpenTelemetry, Elastic SIEM, PagerDuty, Wazuh, Falco Incident Management: DORA Incident Engine (internal), PagerDuty, Jira Service Management, Slack Alerts, StatusPage Resilience and Continuity: Chaos Monkey, Gremlin, HashiCorp Vault, Terraform, ArgoCD, Velero Compliance Evidence: Audit Ledger (internal), PostgreSQL, TimescaleDB, S3-compatible object store, OpenPGP signing Security Controls: HashiCorp Vault, RBAC (OPA), mTLS, SAST (Semgrep), DAST (OWASP ZAP), Trivy Integration: REST API, WebSocket streams, Kafka, ESMA Reporting API, XBRL/XML, SFTP --- ## Case Studies Source: https://mica-compliance.xyz/#programs **Baltic Exchange: Full DORA Programme (2024)** Delivered end-to-end DORA framework for an Estonian exchange processing EUR 480M monthly volume. 218 ICT assets mapped, real-time incident severity engine deployed, three scenario tests passed. Outcomes: 99.97% uptime, 11-minute incident MTTR. **Pan-Baltic Custodian: BCP and Recovery Automation (2023)** Designed and implemented automated BCP with per-site failover for a custody provider holding EUR 940M in client assets across Lithuania, Latvia and Estonia. RTO: 18 minutes; RPO: 4 minutes. ISO 22301 certification achieved. Zero incidents post go-live. **Payments FinTech: Third-Party ICT Risk Module (2025)** DORA Chapter V compliance for a crypto-to-fiat payments FinTech with 14 ICT providers. CTPP candidate flagged, 4 SLAs renegotiated. Time to completion: 16 weeks. --- ## Engagement Models Source: https://mica-compliance.xyz/#engagement | Model | Cost | Timeline | Output | |---|---|---|---| | Fixed-Scope Build | From EUR 33k | 8-16 weeks | ICT risk register, BCP, incident classifier | | Dedicated DORA Team | From EUR 66k (T&M) | 16-32 weeks | Full DORA programme Chapters II-V + scenario tests | | Managed Run Retainer | EUR 12k/month | Ongoing | Monthly drills, KPI reporting, incident support | --- ## Pricing Source: https://mica-compliance.xyz/#pricing - Resilience Package: EUR 33,000 fixed (ICT risk register, BCP design, RTO/RPO definition, one scenario test, KPI dashboard) - DORA Full Programme: EUR 66,000 fixed (all Chapters II-V, incident classifier, ESMA reporting pipeline, third-party register, 3 scenario tests, 90-day post-go-live support) - Run Retainer: EUR 12,000/month (monthly drills, uptime monitoring, regulatory updates, incident on-call, quarterly review, annual scenario test) - All prices in EUR; valid until 2026-12-31 --- ## Security and Certifications Source: https://mica-compliance.xyz/#security - ISO 27001:2022: Certificate EE-27001-8830, Bureau Veritas, valid 2024-2027 - SOC 2 Type II: Annual audit (Security, Availability, Confidentiality); current reporting period 2025-2026 - ISO 22301:2019: Certificate EE-22301-4410, Bureau Veritas, valid 2024-2027 Track record across 18 live programmes: - 99.98% measured client uptime - 12-minute average incident MTTR - Zero major ICT incidents resulting in regulatory breach - 23 ICT scenario tests conducted and documented --- ## Founder Source: https://mica-compliance.xyz/#founder Dr. Karl Tamm, Founder and CTO - PhD in Distributed Systems, Tallinn University of Technology (2012) - CISSP certified - Previous role: incident-response lead at pan-Baltic financial market infrastructure provider (10 years) - Specialism: ICT risk management, operational resilience and incident reporting under DORA - Contributes quarterly ICT risk analysis to Operational Resilience Review and DORA Dispatch - LinkedIn: https://www.linkedin.com/in/karl-tamm-aegis --- ## Research Note Source: https://mica-compliance.xyz/#research APL-RN-001-2025: "Measuring DORA Readiness: ICT Scenario Testing Outcomes Across 23 CASP Environments" - Author: Dr. Karl Tamm; Published: September 2025; 18 pages - Key finding: Mean assumed RTO across clients was 28 minutes; measured RTO was 64 minutes (2.3x gap). Median post-remediation RTO: 17 minutes. - 83% of CASPs lacked a tested BCP at programme start - Zero clients had a complete ICT asset inventory on day one - Incident classification accuracy improved 91% after engine deployment --- ## Regulatory References MiCA: Regulation (EU) 2023/1114 (Markets in Crypto-Assets Regulation): https://eur-lex.europa.eu/ DORA: Regulation (EU) 2022/2554 (Digital Operational Resilience Act): https://eur-lex.europa.eu/ ESMA ICT guidelines: https://www.esma.europa.eu/ Estonian Financial Supervisory Authority (Finantsinspektsioon): https://www.fi.ee/ --- ## Awards - DORA RegTech Partner of the Year 2025 (Operational Resilience Review, January 2025) - ICT Risk Excellence Award 2024 (Estonia Digital Journal, June 2024) --- ## Contact Aegis Protocol Labs OU Pärnu maantee 139c, Tallinn 11317, Estonia Phone: +372 614 8800 Email: hello@mica-compliance.xyz Business hours: Monday-Friday 09:00-18:00 EET VAT: EE102158640 | Reg: 16482209 | Harju County Court (Tartu Registry)