
OSL EU engaged Hacken for a tailored DORA training programme to build its teams' fluency in the EU's operational-resilience requirements — part of OSL's forward-looking "Open, Secure, Licensed" approach to regulatory readiness across jurisdictions.
Why OSL EU invested in DORA readiness early
OSL EU partnered with Hacken to build institutional-grade internal competency in the EU's Digital Operational Resilience Act (DORA), delivering a tailored training and assessment programme mapped to the operational realities of a licensed, publicly listed digital asset group rather than to a generic regulatory syllabus.
The EU's Digital Operational Resilience Act (DORA) is the operational-security backbone that any MiCA-authorised entity inherits. It includes five pillars: ICT governance, incident response, third-party risk, resilience testing, and information sharing. For a platform whose business is bridging fiat and digital assets at an institutional scale, being aligned with DORA is crucial. Therefore, OSL chose to build that competency ahead of the requirement.
What OSL EU needed
OSL EU needed its relevant teams to understand DORA's obligations deeply — not as abstract regulation, but mapped to how a global stablecoin trading and payments platform actually operates. Given OSL's scale and its existing ISO/IEC 27001:2022 foundation, the training had to go beyond introductory material and engage the operational realities of a licensed, publicly listed group.
How Hacken approached it
Hacken's DORA training is built as a working engagement that is tailored to particular entity undergoing training. The course is structured in five stages:
1. Scoping sessions. Hacken ran sessions to assess OSL's expectations and identify exactly where the team needed depth, so the programme targeted OSL's real requirements and processes.
2. Tailored materials. Hacken aligned the training materials to OSL's stated requirements, mapping each DORA obligation onto the platform's own operational context.
3. Live training days. Hacken delivered several days of live, in-house instruction led by the specialists who assess operational resilience in client/regulator engagements.
4. Continuous support between sessions. Hacken maintained an active communication between training days through a dedicated channel for feedback and questions, supported by shared documentation.
5. Practical assessment and certification. The programme closed with a practice examination, and Hacken issued certificates based onon the basis of the results.
The outcome
OSL's EU teams completed the DORA training course and the associated assessment, strengthening internal fluency in the operational-resilience obligations that EU market participation carries.
The programme builds directly on OSL's ISO/IEC 27001:2022 certification, extending a security-first foundation toward the specific requirements of the EU regulatory landscape. Where the ISMS establishes governed information security as a baseline, DORA competency adds the resilience-testing, incident-reporting, and third-party-governance dimensions that supervisory engagement in the EU requires.
Build Regulatory Competency Before It Is Required
For any exchange or platform with EU ambitions, DORA is the point at which "we take security seriously" must become documented, tested, and demonstrable operational resilience — and that capability takes time to build. Institutions that develop it early move faster when the supervisory moment arrives, because the competency is already resident in their teams.
Read OSL's ISO/IEC 27001:2022 case study: https://hacken.io/case-studies/osl-group-iso-certification/



