ICT documentation: what is that?
Under MiCA and DORA regulations, the lack of proper ICT infrastructure documentation is increasingly scrutinized during the licensing process for crypto companies. According to an ENISA report, 488 cybersecurity incidents were recorded in the European financial sector during just the first half of 2024. This highlights the urgent need for robust ICT infrastructure documentation to ensure operational resilience and regulatory compliance. What exactly does ICT documentation include? How does it affect licensing, and what are the risks of failing to provide it? In this article, we explain how to meet MiCA requirements, what regulators look for, and how to avoid critical mistakes during the licensing process.
What is ICT documentation?
ICT documentation is a structured set of documents that outlines strategies, policies, and procedures related to information and communication technologies. Its purpose is to ensure security, resilience, and compliance with regulatory requirements.
This documentation covers a wide range of areas, including ICT risk management, incident response, business continuity, outsourcing governance, and data protection. In the context of cryptoasset regulation in the EU, the main regulatory frameworks defining ICT documentation requirements are:
- Regulation (EU) 2023/1114 (MiCA) – establishes mandatory requirements for crypto-asset service providers (CASPs), including the implementation of effective ICT policies and procedures.
- Regulation (EU) 2022/2554 (DORA) – introduces uniform standards for digital operational resilience in the financial sector and mandates comprehensive ICT documentation.
- Guidelines and recommendations by ESMA, EBA, and EIOPA – provide further guidance on developing and implementing robust ICT governance and security frameworks.
Why is ICT documentation critical for crypto companies?
Maintaining up-to-date and complete ICT documentation is crucial for crypto companies for several reasons:
- Regulatory compliance – lack of required documentation can lead to license denial or financial penalties imposed by regulators.
- Operational resilience – well-defined procedures enable an effective response to incidents and help minimize potential losses.
- Market trust and credibility – transparent and reliable ICT processes enhance client and partner confidence and strengthen the company's reputation in the market.
What does the ICT documentation include?
To comply with MiCA and DORA regulations, a crypto company must go beyond a basic set of IT policies and establish a complete and well-structured ICT documentation architecture. This documentation is not only required during the licensing stage but is also critical for ongoing regulatory supervision, including annual audits and assessments of operational resilience. Companies that provide custody services or operate trading platforms are especially expected to demonstrate their ability to manage ICT threats and minimize potential harm to clients and the broader financial system.
Core components of the documentation
Every crypto company applying for CASP status in the EU must maintain:
- Description of ICT systems and infrastructure – a detailed overview of all relevant technologies used by the company, including hardware, software, network architecture, backup and recovery systems, and security protocols.
- ICT strategy & governance policy – a document defining strategic objectives, principles, and responsibilities in ICT management;
- ICT risk management policy – methods for assessing, mitigating, and responding to ICT-related risks;
- Incident response plan – formal procedures for detecting, classifying, responding to, and reporting ICT incidents;
- Business continuity & disaster recovery plan – recovery scenarios for business operations, including regular testing of backups and failover systems;
- Outsourcing and third-party risk documentation – policies and contractual templates for engaging external IT vendors;
- Cybersecurity framework – minimum standards for data protection, access control, logging, and continuous monitoring.
Additional components (for custodial and trading platforms)
If a company offers custodial services or operates a token trading infrastructure, its ICT documentation must also include:
- Technical architecture diagrams – descriptions of IT infrastructure, including nodes, storage, gateways, load balancers, and backup channels;
- Access control policy – access rights model, multi-factor authentication procedures, and least privilege principles;
- Encryption & key management protocols – procedures for data encryption, as well as key generation, storage, and rotation;
- Monitoring & audit logs – policies for log retention, internal audits, and tracking of user and administrator activity;
- Backup procedures – schedules for data backups, restoration protocols, and periodic recovery testing.
The completeness, relevance, and legal accuracy of these documents serve as key indicators of a platform’s reliability, transparency, and commitment to protecting client data and assets. Regulatory authorities such as ESMA, national FIUs, or central banks may use these materials to assess the overall operational integrity of the business, not only in the context of licensing, but also in ongoing supervision.
ICT documentation requirements under MiCA and DORA
The European regulatory framework for digital infrastructure in the financial sector is built upon two key legal acts - the MiCA Regulation and the DORA Regulation. Both introduce strict and specific requirements for ICT documentation that all crypto-asset service providers (CASPs) wishing to operate in the EU must comply with.
MiCA focuses on regulating crypto service providers, while DORA ensures the digital operational resilience of the entire financial infrastructure. Together, these regulations establish a comprehensive control system over ICT processes, covering everything from risk management and incident response to outsourcing of critical functions.
MiCA requirements for CASPs (Articles 61–63)
Under Articles 61–63 of Regulation (EU) 2023/1114 (MiCA), every company applying for a CASP license must:
- Develop and implement a documented ICT risk management policy that includes threat assessments, response strategies, and control mechanisms;
- Appoint a responsible person or unit in charge of ICT security and internal controls;
- Establish incident response procedures, including mandatory reporting to competent authorities in case of major ICT disruptions;
- Regularly review and update ICT documentation, especially when changes occur in the IT infrastructure or business model.
MiCA also requires proof that these procedures are implemented in practice, not just written on paper. This is verified both during the license application process and through ongoing supervisory inspections.
DORA requirements for critical services
As of 17 January 2025, Regulation (EU) 2022/2554 (DORA) is fully in effect, introducing universal digital operational resilience standards across the EU. Under DORA, every crypto or fintech company must:
- Establish a structured ICT risk management framework based on the five components of the resilience cycle: identification, protection, detection, response, and recovery;
- Conduct regular testing of IT infrastructure, including cyberattack scenarios, stress simulations, and BCP/DRP procedures;
- Formalize outsourcing policies, including control over subcontractors, SLA auditing, and mandatory DORA-compliant contractual clauses;
- Develop crisis communication plans, including customer notifications and incident reporting to supervisory authorities.
Important: DORA applies to all entities covered by MiCA, PSD2, the e-Money Directive, and other EU financial regulations — regardless of company size. Non-compliance can result in administrative fines, temporary bans on operations, or removal from official registers.
Penalties and risks for lack of ICT documentation
Failure to comply with ICT documentation requirements under MiCA and DORA is regarded by European regulators as a serious violation, directly linked to potential threats to financial system stability and user security. Even if a company has a clean financial record and a transparent corporate structure, the absence of proper ICT documentation may result in severe restrictions or the suspension of operations.
Potential consequences:
- Rejection of CASP license. During the license application process, regulators may refuse to issue a license if ICT procedures are incomplete, duplicated, contradictory, or do not reflect the company’s actual IT infrastructure.
- Suspension of operations. Under Article 97 of MiCA and DORA, national competent authorities have the right to temporarily prohibit a CASP from operating until ICT deficiencies are resolved, particularly when needed to protect consumers or financial stability.
- Administrative fines. Each EU member state sets its penalty thresholds, but in general, fines for non-compliance with DORA or MiCA can reach up to €5 million or 10% of the company’s annual turnover.
- Reputational damage. Crypto companies lacking up-to-date ICT documentation risk losing access to banking services, payment gateways, and may face refusals from institutional clients and investors.
- Enhanced supervision. Even if a license is formally granted, regulators may impose additional annual audits, infrastructure reviews, and restrictions on specific services.
How Key2Law can help prepare ICT documentation for MiCA
Transitioning to MiCA and DORA compliance requires not only technical maturity but also in-depth legal alignment of all internal processes. One of the key tasks on this path is preparing a comprehensive and fully compliant set of ICT documentation. The Key2Law team supports clients at every stage: from initial audits to regulatory defense.
We can help you:
- Understand which documents are mandatory for your specific business model, whether you're a custodial service, trading platform, token issuer, or payment solution provider;
- Conduct a full review of your current IT environment and risk landscape, identifying gaps and inconsistencies with MiCA/DORA requirements;
- Draft and adapt the full set of ICT policies: from risk management frameworks to disaster recovery plans with legally sound language and regulatory justification;
- Prepare supporting materials for your license application, including compliance matrices, self-assessment reports, and explanatory notes to accompany the documentation;
- Represent your interests before regulators - during application submission, clarification requests, or inspections (including direct involvement of Key2Law experts in regulator communications).
Partnering with Key2Law means gaining a strategic advisor with deep expertise in European crypto regulation. We help you not only meet regulatory requirements but navigate the licensing journey with confidence, avoiding penalties, delays, and compliance exposure. Contact Key2Law today to receive tailored advice on preparing your ICT documentation and other critical components of your MiCA application.