
Updated on
September 2, 2026
Digital asset operators face a growing set of operational resilience expectations, and which ones apply depends on where a firm is licensed and where it operates. Most share the same core: a governed risk framework, a tested incident response capability, and a documented ability to recover critical functions after disruption. This page explains how that shows up in the frameworks institutional operators encounter most often. It is a starting reference, not a complete survey, and it is educational rather than legal advice.
The frameworks below are the ones institutional operators meet most often, not the only ones that matter, and not all apply to every firm. What binds a given firm depends on its licences and the markets it serves.
An EU crypto-asset service provider is governed by MiCA and DORA together. MiCA is the authorisation regime; its operational core, Article 68(7), requires CASPs to ensure continuity of services through resilient and secure ICT systems and to maintain a business continuity policy, with the ICT-specific continuity, response, and recovery plans delivered through DORA. DORA has applied since 17 January 2025 and treats every CASP authorised under MiCA as a financial entity (Article 2(1)(s)), mandating board-owned ICT risk management, staged incident reporting (initial notification within 4 hours of classifying an incident as major), resilience testing, and contractual control over critical ICT third parties. Read the combined obligations at MiCA and DORA requirements for CASPs.
New York's cybersecurity regulation, 23 NYCRR Part 500, applies to virtual currency firms licensed by the Department of Financial Services. Its second amendment (effective 1 November 2023) strengthened the incident response and business continuity requirements in Section 500.16 and the 72-hour incident notification in Section 500.17. Read how it applies to virtual currency firms at /learn/nydfs-part-500.
The NIST Cybersecurity Framework 2.0 (finalised February 2024) is a voluntary model, not a regulation. It organises cybersecurity risk into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. For digital asset operators, the Respond and Recover functions are the ones custody and prevention tooling tend to leave thin. Read the six functions applied to digital assets at /learn/nist-csf.
The GENIUS Act, enacted 18 July 2025, established a federal framework for US payment stablecoin issuers, requiring appropriate operational, compliance, and information technology risk management standards. The OCC's implementing rules are in the rulemaking phase, with the comment period closed on 1 May 2026. A dedicated page on the operational resilience angle for stablecoin issuers will follow once the OCC final rule is published.
Across them, the operational resilience expectation reduces to three capabilities. First, a governed framework that names accountable owners and is reviewed on a defined cadence. Second, a tested incident response capability that can classify, escalate, and report an event under a clock. Third, a documented and tested ability to recover critical functions and data after disruption. Prevention controls satisfy none of the recovery expectations on their own.
For the underlying concepts, see /learn/operational-resilience, /learn/incident-response, and /learn/digital-asset-recovery.
The binding regimes here treat recovery as a distinct obligation, separate from prevention, and NIST CSF names Respond and Recover as core functions. Custody and key-management controls address the Protect function; they do not, on their own, satisfy the need to recover assets and functions after a compromise. Keyless recovery, meaning recovery that does not depend on your private keys, speaks directly to the Respond and Recover expectations these frameworks set, because it moves assets to safety on a defined trigger without depending on key material that may already be lost or attacker-controlled.
Circuit Security provides operational resilience for institutional digital assets. Its Recovery and Response products, powered by Automatic Asset Extraction (AAE), give a recovery path that does not depend on the private keys, so they support the Respond and Recover functions that custody-only solutions leave open.
Frequently asked questions
What is the difference between DORA and MiCA for a CASP?
MiCA is the EU authorisation regime that lets a firm provide crypto-asset services and sets the high-level obligation to ensure continuity of those services. DORA is the detailed operational resilience regime that specifies how the ICT risk management, incident reporting, and recovery elements of that obligation must be implemented. A CASP is subject to both.
Do these frameworks expect the ability to recover assets, not just systems?
The binding regimes frame their obligations around recovering critical functions, data, and services, and NIST CSF treats Recover as a core function. For a digital asset operator, the assets under management are the critical function; an incident that leaves assets stranded or attacker-controlled is a resilience failure regardless of whether systems are restored. Recovery planning that ignores the assets themselves is incomplete.
Is NIST CSF a regulation, and is it mandatory?
No. NIST CSF 2.0 is a voluntary framework, not a regulation, and adopting it does not by itself satisfy any legal obligation. In practice it is widely adopted as a control baseline and often referenced in contracts, insurance, and diligence, so many institutional operators treat it as a practical requirement even though it is not law.
Which framework applies to a US stablecoin issuer?
US payment stablecoin issuers will be governed by the GENIUS Act and the implementing rules of their primary federal regulator, which for many issuers is the OCC. Those rules were in the rulemaking phase as of mid-2026.
Want to keep up to date with Circuit? Sign up below

We believe asset recoverability is table stakes for the next era of digital assets.