Client: WhiteBIT EU — entity of WhiteBIT, authorised to provide crypto assets services in the EEA. WhiteBIT is the largest European cryptocurrency exchange by traffic. It was founded in 2018 and is now a part of W Group, which serves more than 40 million customers globally.
Service: DORA Training (Cybersecurity Training)
Outcome: WhiteBIT EU's team completed a structured DORA training program and certification as part of its broader MiCA licensing preparation.
Why now?
MiCA moved from framework to enforcement in 2026, and with it came a harder bar than most crypto firms expected. A MiCA-authorized exchange is reclassified as a regulated financial entity — which means it inherits the Digital Operational Resilience Act (DORA) and its five pillars. Documented ICT governance, tested incident response, and demonstrable operational resilience stopped being nice-to-haves and became conditions of operating legally in the EU.
For WhiteBIT EU, that raised a specific question: not whether the organization understood security, but whether its teams could speak DORA's language fluently — the obligations, the evidence requirements, the operational controls a supervisor actually checks. Regulatory readiness is a team competency, not a document. That is the gap training closes.
WhiteBIT EU’s request
WhiteBIT EU was pursuing MiCA authorisation and wanted its relevant teams aligned on DORA's operational-resilience requirements, mapped to how those controls work inside their organisation. They needed training on their stack, their processes, and the questions their own people had.
How Hacken approached it
Hacken's DORA training is always personalised for each entity undergoing it.
It was structured as a working engagement in five stages:
- Scoping sessions. Before building any material, Hacken ran sessions to establish WhiteBIT EU's expectations and find where the team needed depth.
- Tailored materials. DORA's requirements mapped onto the exchange's own context and aligned with what we knew from scoping.
- Live training days. Several days of instruction led by Hacken practitioners, the same people who assess operational resilience on real regulatory engagements.
- Support between sessions. A dedicated channel for Q&A and feedback, plus shared documentation, so questions got answered while they were still fresh.
- Assessment and certification. WhiteBIT EU's team had a practice exam and Hacken issued certificates based on the results.
The outcome
WhiteBIT EU completed the DORA training and certification as part of its wider MiCA preparation. In 2026, its EU entity secured the MiCA licence, an outcome that reflects work across legal, compliance, and operational functions. Hacken's training contributed to the operational-resilience competency a MiCA-authorised entity has to demonstrate.
WhiteBIT EU's MiCA authorisation is an achievement for the exchange. Hacken's role was to help its teams build fluency in the operational-resilience obligations that authorisation now carries.
For those preparing
For any exchange or issuer heading into MiCA, DORA requires documented, tested, and demonstrable resilience controls evidence. Training scoped to your gaps and mapped to your stack, closed out with an assessment, makes you organisation capable of meeting these obligations.



