808bits

What a DORA reviewer wants in a custody exit plan

2026-06-05 · updated 2026-09-03 · 4 min

Article 28(8) of DORA is one paragraph. It requires every financial entity to put in place exit strategies for ICT services supporting critical or important functions, and it says what those strategies must be: “comprehensive, documented and, in accordance with the criteria set out in Article 4(2), sufficiently tested and reviewed periodically.” It goes on to require “transition plans enabling them to remove the contracted ICT services and the relevant data from the ICT third-party service provider and to securely and integrally transfer them to alternative providers or reincorporate them in-house.” It has applied since 17 January 2025.

For most ICT services that is familiar work, a data export and a migration plan to a second vendor. For a digital-asset custody platform it is not. What you have to remove is signing capability over assets on-chain, and whether you can is a cryptographic fact about your setup rather than a clause in the contract.

I read Article 28 and the technical standard that details it, Commission Delegated Regulation (EU) 2024/1773, and mapped each requirement onto what a custody exit actually has to contain. The mapping came out nine items long. Some of what it taught me is below.

Tested and feasible

Article 10 of the technical standard requires “a documented exit plan for each contractual arrangement and for the periodic review and testing of the documented exit plan,” and says the plan must be “realistic, feasible, based on plausible scenarios and reasonable assumptions” with “a planned implementation schedule.” Two of those words carry most of the weight. A paragraph saying keys will be recovered from backup is documented, and nobody has tested it or shown it is feasible.

Signing capability, not data

When wallet infrastructure runs on an MPC custody platform, the platform holds some key shares and the customer holds a recovery backup. The exit question is therefore harder than “can we migrate our records”, and it splits into three. Can we reconstruct signing capability from the customer-held backup without the vendor’s systems? Does that backup cover all current key material, or only what existed when it was created? Once we can sign, can we move everything, including what is staked, locked, or sitting inside a smart contract?

A plan that does not answer those three has not shown there is an exit.

Uneven exits

Fireblocks publishes an open-source offline recovery tool. So does Cobo. BitGo’s recovery wizard covers its multisig wallets without BitGo’s service. Copper puts the third key shard with an independent party so that client plus third party reach the threshold without Copper. Other vendors route recovery through a named backup provider rather than a tool you can run yourself.

Each of those is a different exit, with different evidence, and I have read plans that do not say which one applies. Where a vendor offers none of them, that absence is itself an Article 29 concentration-risk finding, and it belongs in the register.

What a reviewer discounts

Most custody exit documentation reads like this: “In the event of provider failure, keys will be recovered from the encrypted backup using the provider’s published recovery tooling.” One sentence, true as far as it goes, and untested. A reviewer who probes it wants dates, because “do you have a backup” is a different question from “when did you last prove it works”. Then a coverage number, since backups are point-in-time and workspaces grow. The verification has to have been done without the vendor in the room, because the scenario being planned for is the one where the vendor is gone. There should be a timeline for the assets a sweep cannot move, in days and weeks of unbonding. And a rehearsal, because the regulation says tested.

All of that is evidence rather than prose, and a vendor attesting to its own escapability counts for the least of it.

DORA binds EU financial entities, but the perimeter is wider than it looks from Zug or Zurich. EU group entities are in scope directly, EU clients push the requirements down by contract, and FINMA’s Circular 2023/1 asks the same questions of Swiss banks under different numbering.

A custody exit strategy with no dates in it describes an exit someone hopes exists.