

MiCA requires crypto companies to have clear ICT governance, risk management processes, security controls, incident-handling procedures, and business continuity arrangements. Organisations must also be able to demonstrate these measures through clear, regulator-ready documentation as part of the licensing process.
The timeline depends on your starting point. Organisations with existing ICT security and documentation may only need a focused review and updates, while others need to build policies, controls, and evidence from scratch. Preparation typically takes from a few weeks to five-six months.
MiCA focuses on licensing and conduct requirements for crypto-asset activities, while DORA focuses on ICT risk and operational resilience. For crypto companies, MiCA sets what needs to be in place, and DORA strengthens how ICT risks are managed over time. In practice, many ICT controls, risk management processes, and incident handling measures support both regulations.