Two EU frameworks are reshaping how gaming-adjacent businesses handle technology and crypto risk:
- DORA (Digital Operational Resilience Act) - applies from 17 January 2025 to financial entities, including many payment and e-money institutions that serve iGaming. If you are in scope - directly or through your group - you need documented ICT risk management.
- MiCA (Markets in Crypto-Assets Regulation) - fully applicable since 30 December 2024. If your platform touches crypto-assets - deposits, withdrawals, tokens or related services - MiCA determines what you may offer and how.
DORA Compliance Support
- Applicability and scope analysis for your entity and group structure
- ICT risk-management framework and governance documentation
- Incident classification, response and reporting procedures
- Digital operational resilience testing strategy
- Third-party ICT provider register and contract clause alignment
MiCA Compliance Support
- Token and service classification analysis (what MiCA means for your model)
- CASP authorisation readiness and gap analysis
- White-paper and disclosure review where applicable
- Custody, conflicts-of-interest and market-abuse policy frameworks
- Interaction between MiCA, AML rules and your gaming licence
Approach
We start with a scoped gap analysis, deliver a prioritised remediation roadmap, and then draft the policies and procedures your teams will actually operate. Engage per framework as a fixed-fee project, or continuously via subscription.