01
Perimeter & classification
Confirms which entities, tokens, and activities actually fall inside MiCA/DORA scope before the rest of the assessment is scoped.
Diagnostic
A 15-point, evidence-based MiCA/DORA control assessment for platforms issuing, servicing or safekeeping tokenized assets.
The shift
Supervision has moved from “do you hold the licence” to “can you evidence, on demand, that the architecture does what your policy file says it does.”
Most compliance documentation is written against templates drawn from securities or payments practice, while the operative risk sits in the token layer.
What's tested
01
Confirms which entities, tokens, and activities actually fall inside MiCA/DORA scope before the rest of the assessment is scoped.
02
Reserve composition, redemption rights, disclosure obligations, and conduct requirements tested against the deployed system, not the policy file.
03
ICT risk management, third-party dependency mapping, incident reporting, and resilience testing obligations.
04
Upgrade-key governance, settlement and reconciliation integrity — the surface where template-based compliance work systematically under-delivers.
Method
On-chain verification: custody, segregation, upgrade-path and reconciliation claims tested against the contracts actually deployed, not against their descriptions.
Each control scored under depeg, oracle failure, key compromise, finality stall and vendor exit.
Structure
01 / Week 1
Gap list delivered within five days.
02 / Week 2
Interim flash report on any red finding the day it is confirmed.
03 / Week 3
Final report with scored heatmap, findings register and prioritised remediation roadmap.
Delivered under your engagement terms where relevant. White-label or co-branded.
Request the methodology