Try the live demo →

Compliance guides, for the person who owns the register

Practical, plain-English guides to the five regimes small EU financial and crypto firms actually have to file. Every guide links to a free checker you can run in your browser, nothing uploaded.

DORA

How to complete your DORA register of information
A practical, step-by-step guide to the DORA register of information — what it is, the tables and fields, how to fill it, the validation traps that bounce submissions, and how to keep it current.
Read the guide →
Does your SaaS vendor belong in your DORA register? The ICT third-party test
The plain-English test for which vendors count as an ICT service, the grey areas, what changes for critical functions, and the four questions that settle it.
Read the guide →
DORA for crypto firms (CASPs): the practical guide
What DORA actually requires of crypto-asset service providers — who's in scope, the five pillars, the register of information, and how it fits with MiCA.
Read the guide →
DORA for payment & e-money institutions
What DORA requires of payment institutions and e-money institutions — who's in scope, the five pillars, and proportionality for smaller firms.
Read the guide →

MiCA

MiCA Article 92 market-abuse surveillance — what CASPs must do
The behaviours you must monitor, the STOR obligation, and what a working surveillance system needs.
Read the guide →

AML / KYC

AML & KYC for crypto CASPs under MiCA — requirements & checklist
Customer due diligence, sanctions and PEP screening, the Travel Rule, transaction monitoring, SARs and an MLRO — with the 2026 deadlines.
Read the guide →

FCA

FCA operational resilience: the SYSC 15A guide
Important business services, impact tolerances, mapping, scenario testing, and the board-approved self-assessment for UK firms.
Read the guide →

Cyber Resilience Act

EU Cyber Resilience Act (CRA) — is your product in scope?
The SaaS-vs-product line that decides it, the risk classes, and the 2026/2027 deadlines.
Read the guide →
CRA Article 14 reporting — the 24-hour clock explained
From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA. Who reports, what triggers the clock, and how to be ready.
Read the guide →

Research

290 EU crypto firms authorised under MiCA, 98.6% in the final 18 months
A landscape analysis of ESMA's own public MiCA CASP register, sourced and reproducible: who's authorised, where, and when, ahead of the 1 July 2026 deadline.
Read the analysis →

See the tools these guides point to

Open CleanDesk →
DORA register · CRA scope · MiCA surveillance · AML — in your browser, nothing uploaded