DORA creates indirect pressure because regulated financial institutions and CASPs must manage the risk of the third parties they depend on. If a provider supports a critical service such as custody, its controls can affect the customer’s ability to stay compliant. That means unregulated vendors may still need stronger governance, incident readiness, and operational discipline to remain viable in regulated markets.
Why DORA pulls custody and digital asset vendors into the compliance perimeter
DORA changes the question from “who is directly supervised?” to “whose service can affect a regulated firm’s operational resilience?” Custody and other digital asset technology providers often sit inside the execution path for a financial institution or CASP, so their availability, incident handling, and control quality can become part of the customer’s regulatory posture. That is why indirect scrutiny rises even when the vendor itself is not the primary regulated entity.
For custody, the practical issue is dependency. If the provider holds key operational responsibilities, a control failure can interrupt asset access, reporting, reconciliation, or recovery. Regulators do not need to directly license every vendor to care about the vendor’s discipline, because the regulated customer is still accountable for the outcome. This is the same reason third-party governance becomes a board-level concern, not just a procurement check.
The pressure also extends beyond formal obligations. In regulated markets, customers increasingly need suppliers that can evidence incident readiness, auditability, change control, and recovery capability. A provider that cannot support those expectations may still sell technology, but it will find it harder to remain a trusted dependency for institutions that must prove operational resilience under DORA.
Where the scrutiny lands in practice
DORA does not only affect contracts, it affects the operating model around custody, key management, and service continuity. The most scrutinised points are usually the ones that determine whether a regulated firm can continue operating through disruption: privileged access paths, recovery procedures, logging, incident notification, subcontractor dependencies, and the vendor’s ability to support evidence during audits or supervisory reviews.
This is why digital asset providers that are “unregulated” in the narrow licensing sense may still need to behave like regulated critical suppliers. They may be asked to document controls more formally, tighten escalation paths, shorten incident response times, and prove that operational changes will not destabilise customer environments. The customer’s DORA obligations effectively turn vendor maturity into a market-access requirement.
That pressure is especially visible when the provider exposes secrets, signing keys, or administrator pathways that could affect customer assets. Stronger governance around those dependencies is not just good hygiene, it is the difference between being a tolerable supplier and being a resilience liability. In that respect, DORA aligns closely with broader third-party and non-human identity control concerns described in the Ultimate Guide to NHIs, Regulatory and Audit Perspectives.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the technical controls, while DORA define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.3 — Cybersecurity Supply Chain Risk Management | DORA scrutiny is driven by third-party dependency risk and operational resilience. |
| RS.2 — Incident Response | Custody providers must support timely incident handling and customer escalation. | |
| Recommendation — Assess critical vendors under supply-chain risk governance and require resilience evidence. Test vendor incident response and require clear notification and escalation procedures. | ||
| CIS Controls v8 | 15 — Service Provider Management | The question centers on managing unregulated providers that materially affect regulated outcomes. |
| Recommendation — Classify custody vendors as service providers and enforce control, contract, and review requirements. | ||
| DORA | ICT Third-Party Risk — ICT Third-Party Risk Management | DORA directly increases scrutiny on providers supporting regulated financial services. |
| Incident Reporting — Incident Reporting | Provider incidents can affect a regulated entity's reporting obligations and evidence needs. | |
| Recommendation — Map critical custody dependencies and contract for resilience, auditability, and exit capability. Align vendor notification timelines with the customer's regulated incident reporting process. | ||
Practitioner Guidance
What to prioritise: Treat custody, infrastructure, and digital asset technology vendors as resilience-critical dependencies if they can affect service continuity, client asset movement, or regulatory evidence. The key question is not whether the vendor is supervised directly, but whether its failure would create a DORA problem for the institution that depends on it.
What to verify: Demand concrete proof of incident escalation, recovery testing, change control, and access governance. If the provider cannot show how it limits and monitors operational privilege, or cannot evidence how quickly it can restore service under stress, the customer is inheriting an exposure rather than outsourcing a capability.
Practitioner takeaway: In DORA-driven procurement, vendor selection is partly a resilience test, because the regulated buyer remains responsible for the outcome even when the critical control sits outside its own perimeter.
Related resources from NHI Mgmt Group
- How should security teams govern digital-asset custody when third parties are involved?
- Who is accountable when digital asset controls fail across multiple providers?
- Why does relying on software-stored private keys increase risk in regulated digital trust environments?
- Who is accountable when digital asset firms expand banking access and custody under evolving rules?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 23, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org