Most bad digital asset partnerships are visible in the first meeting, in the answers nobody asked for. These are the questions we would put to any firm pitching to build crypto infrastructure for a regulated institution, including us.
The stakes changed in Europe this year. MiCA's transitional period ended on 1 July 2026, and DORA has applied since January 2025. Under DORA Article 28(1), a firm using technology providers remains "fully responsible" for its obligations. A weak partner leaves you with the risk and none of the tools to manage it.
1. What will you never do for us?
Boundaries show whether a partner understands your regulatory perimeter. A technology firm that also holds client crypto-assets, manages private keys, routes orders or takes referral fees from vendors it recommends has interests that can pull against yours. A good answer is short. Ours is public: we build the infrastructure, and you operate it under your own licence.
2. How does your contract map to DORA Article 30?
This separates firms that have read DORA from firms that have heard of it. Article 30 lists what an ICT contract must contain, from data locations and service levels to incident assistance, audit rights and exit terms. For critical or important functions the list gets longer. A prepared partner walks you through each clause in their standard terms. An unprepared one offers to "work with your legal team," which usually means your lawyers draft the terms and the vendor negotiates them down.
3. Where will our data be, and who else touches it?
Ask for named locations and named subcontractors, and how you'll hear when either changes. The EU's technical standards on subcontracting (Delegated Regulation 2025/532) expect you to understand the chain behind services that support critical functions. "Our cloud provider handles that" is an answer you'll end up explaining to your supervisor.
4. How do we leave?
DORA Article 28(8) requires exit strategies for services supporting critical or important functions. Ask to see a sample exit plan. Check that it covers data return format, knowledge transfer, code handover and a realistic timetable. We write ours at the start of an engagement. If a partner says exit planning comes later, it probably won't come at all.
5. Who owns the code?
Ask whether you get the source code, documented interfaces and runbooks, and whether an engineer outside the partner's team could run the system. Black boxes create the concentration risk DORA asks you to assess before signing, and they make every future change more expensive.
6. How do you separate data from opinion?
For on-chain analytics, attribution of addresses to entities is inference. Ask whether it comes with confidence levels and documented methods. Also ask whether the provider publishes price targets. A regulated firm needs evidence it can defend to an auditor, and price views don't help with that.
7. Who is accountable after go-live?
Many programmes stall between the consultancy that wrote the strategy and the vendor that built the product. Ask who on the partner's side will still own the outcome twelve months after launch.
Frequently asked questions
Does DORA apply directly to technology providers?
Mostly no. DORA's obligations fall on financial entities, and providers feel them through Article 30 contract terms. The exception is providers designated as critical by the European Supervisory Authorities, who named the first 19 in November 2025.
Can a crypto firm outsource custody to a technology provider under MiCA?
Article 73 allows outsourcing but keeps the crypto-asset service provider fully responsible. A technology partner can build and support custody systems while the regulated firm keeps control of the assets and keys.
Ask us these questions first. We'd rather be challenged before the build than after it. Start a conversation or see how we work with regulated institutions.
Sources: Regulation (EU) 2022/2554 (DORA), Arts 28 and 30; Regulation (EU) 2023/1114 (MiCA), Art 73; Delegated Regulation (EU) 2025/532; EBA, CTPP designation, 18 Nov 2025. General information only, not legal or investment advice.
Disclaimer
Everything here is published openly and written for an undifferentiated audience. It describes markets, protocols, technology and risk, and presents facts separately from opinion. It contains no recommendations about crypto-assets, no price targets, no buy/sell/hold signals and no directional calls, and it is not tailored to the circumstances of any reader; nothing here is investment advice or a personal recommendation. We do not accept payment to publish coverage of any asset, protocol or venue, and neither the author nor any related party holds an undisclosed position in the assets discussed. Sources are cited where used; where none is cited, the analysis is the author's own. This note reflects the position as of the publication date and may become outdated. For more information: Terms of Service.
Transparency note
This article reflects our own views and conclusions. AI tools may have assisted with research, fact-checking, and language editing, but the content, opinions, and final judgment remain ours. Despite reasonable efforts to verify sources, errors or omissions may exist.