808bits

What a DORA reviewer wants in a custody exit plan

2026-06-05 · updated 2026-09-03 · 4 min

Article 28(8) of DORA is one paragraph. It requires every financial entity to put in place exit strategies for ICT services supporting critical or important functions, and it says what those strategies must be: “comprehensive, documented and, in accordance with the criteria set out in Article 4(2), sufficiently tested and reviewed periodically.” It goes on to require “transition plans enabling them to remove the contracted ICT services and the relevant data from the ICT third-party service provider and to securely and integrally transfer them to alternative providers or reincorporate them in-house.” It has applied since 17 January 2025.

For most ICT services that maps onto familiar work: data export, parallel running, a migration plan to a second vendor. For a digital-asset custody platform it does not. What you have to remove is signing capability over assets on-chain, and whether you can is a cryptographic fact about your setup rather than a clause in the contract.

I read Article 28 and the technical standard that details it, Commission Delegated Regulation (EU) 2024/1773, and mapped each requirement onto what a custody exit actually has to contain. The mapping came out nine items long. Some of what it taught me is below.

Tested and feasible

Article 10 of the technical standard requires “a documented exit plan for each contractual arrangement and for the periodic review and testing of the documented exit plan,” and says the plan must be “realistic, feasible, based on plausible scenarios and reasonable assumptions” with “a planned implementation schedule.” Two words carry most of the weight, tested and feasible. A paragraph saying keys will be recovered from backup is documented. Nobody has tested it and nobody has shown it is feasible.

Signing capability, not data

When wallet infrastructure runs on an MPC custody platform, the platform holds some key shares and the customer holds a recovery backup. The exit question is therefore not “can we migrate our records” but three harder ones. Can we reconstruct signing capability from the customer-held backup without the vendor’s systems? Does that backup cover all current key material, or only what existed when it was created? Once we can sign, can we move everything, including what is staked, locked, or sitting inside a smart contract?

A plan that does not answer those three describes an exit that may not exist.

Uneven exits

Fireblocks publishes an open-source offline recovery tool. So does Cobo. BitGo’s recovery wizard covers its multisig wallets without BitGo’s service. Copper puts the third key shard with an independent party so that client plus third party reach the threshold without Copper. Other vendors route recovery through a named backup provider rather than a tool you can run yourself.

Each of those is a different exit, with different evidence, and I have read plans that do not say which one applies. Where a vendor offers none of them, that absence is itself an Article 29 concentration-risk finding, and it belongs in the register.

What a reviewer discounts

Most custody exit documentation reads like this: “In the event of provider failure, keys will be recovered from the encrypted backup using the provider’s published recovery tooling.” One sentence, technically true, untested. A reviewer who probes it wants dates, because “do you have a backup” is a different question from “when did you last prove it works”. They want a coverage number, because backups are point-in-time and workspaces grow. They want the verification done without the vendor in the room, because the scenario being planned for is the one where the vendor is gone. They want an honest timeline for the assets a sweep cannot move, in days and weeks of unbonding. And they want a rehearsal, because the regulation says tested and an untested plan is a hypothesis.

All of that is evidence, not prose. A vendor attesting to its own escapability counts for the least of it.

DORA binds EU financial entities, but the perimeter is wider than it looks from Zug or Zurich. EU group entities are in scope directly, EU clients push the requirements down by contract, and FINMA’s Circular 2023/1 asks the same questions of Swiss banks under different numbering. Only the letterhead of the reviewer changes.

Read your custody exit strategy and count the dates in it. Intentions describe an exit someone hopes exists. Evidence describes one that does.