Three regulations, three acronyms, three compliance teams. But what if they were all really asking for the same thing?
A compliance lead at a fintech opens their dashboard this morning. Three deadlines stare back. MiCA, closing its transitional window on 1 July. eIDAS 2.0, requires a digital identity wallet to be integrated by December. DORA, which no longer expects well-written policies but concrete proof of resilience. Three projects, three timelines, three budgets, and the nagging sense of running them all at once without ever seeing how they connect.
That connection does exist, though. Behind all three texts lies the same shift: verified identity stops being just one feature among others and becomes a mandatory layer of infrastructure. And 2026 is the year the three timelines converge.
who
What the three timelines are really saying
Taken in isolation, each text looks like just one more regulatory project. Put end to end, they trace a convergence that few teams connect.
MiCA first. The transitional period ends on 1 July 2026 across the Union: after that date, any crypto-asset service provider (CASP/PSAN) operating without authorisation is in breach and must cease its activity. The reward is a European passport for those in compliance, and penalties of up to 5 million euros or 5% of turnover for the rest.
eIDAS 2.0 next. Regulation (EU) 2024/1183 requires every Member State to make available at least one digital identity wallet (EUDI Wallet) by the end of December 2026. A year later, regulated players that use strong authentication will have to accept it. So 2026 is the year to be ready, not the year to start thinking about it.
DORA last. The text has applied since 17 January 2025, but 2026 marks the end of leniency: authorities are no longer satisfied with theoretical governance; they demand proof of operational resilience in real time, under supervision described as "interventionist."
Three dates, the same year. And a common thread the timelines don't say out loud: none of these texts will settle for approximate identity.
Why treating MiCA, eIDAS, and DORA in silos makes the problem worse
The instinct is to open three separate projects, with three owners, three vendors, and three audits. Except all three rest on the same foundation, and walling it off means paying three times for a single base.
MiCA: a European passport, backed by a KYC that doesn't forgive. MiCA finally harmonises the crypto market and offers an authorisation valid across all 27 States. But that authorisation assumes a flawless onboarding and anti-money-laundering setup: without robust identity verification that can be reused at every client relationship, the passport stays out of reach.
eIDAS 2.0: a sovereign wallet, but one that doesn't remove the need to verify. The European wallet promises a reusable identity controlled by the user. Even so, the regulated player still has to know how to receive, verify, and trust these attestations, and to keep proving identity when the wallet isn't yet presented. eIDAS doesn't remove the need for verification: it turns it into an interoperable building block.
DORA: ICT resilience that starts with access control. DORA talks about continuity, incident management, and third-party risk. But the resilience of a financial system starts at its front door: who accesses what, and with what proof of identity. Weak authentication is an attack surface that everything else in the DORA framework then tries to patch up.
The common denominator jumps out the moment you overlay the three: verified identity is the load-bearing layer across all three frameworks. Treating it in silos means tripling the effort on a single base.

The real cost: not three projects, but a cascade
Approaching MiCA, eIDAS, and DORA separately doesn't produce three neatly filed budget lines. It sets off a chain reaction.
- Tripled workstreams. Three integrations, three vendors, three audits to answer what is, at bottom, the same need for proof of identity. The cost multiplies where pooling would have divided it.
- Inconsistent evidence. Each framework verifies identity in its own way, with its own tools. The result: blind spots between the silos, exactly where an auditor will come looking.
- Integration debt. Stacking one-off solutions stretches time-to-market and locks the architecture in place. Every new text is grafted onto an already cluttered system.
- The risk of simultaneous enforcement. All three deadlines fall in the same year. A delay on one weakens your posture on the others and exposes you to penalties that add up instead of staying contained.
The impossible equation: compliance or speed?
This is the dilemma every product and compliance function knows. On one side, three regulators demanding, almost simultaneously, authorisation, interoperability and proven resilience. On the other hand, a market that forgives neither months lost to integration nor journeys weighed down by compliance work.
The temptation is to treat it as a slider: a bit more compliance here, a bit less speed there, and a compromise in the middle. That's a trap. Arbitrating this way means accepting either a regulatory delay or technical debt, two equally risky bets when all three deadlines converge.
The real question isn't "how many projects can we run in parallel?" It's: "How do we satisfy all three frameworks from a single identity foundation, without tripling either the cost or the timeline?"
What would change if identity were treated as infrastructure
Imagine a single proof of identity, verified once against an official document, then reusable at every checkpoint the three texts require. Not three siloed verifications, but a common foundation that MiCA, eIDAS and DORA all lean on.
The effects show up directly in the metrics that matter.
- Compliance: one and the same proof covers MiCA's KYC/AML, the interoperable identification eIDAS is aiming for, and the access control DORA expects. One base, three requirements met.
- Time-to-market: one integration instead of three. The compliance timeline compresses instead of stacking up.
- Audit cost: a single, traceable source of truth, easier to present to three different authorities.
- Resilience: strong authentication with no secret to manage reduces the attack surface, precisely what DORA seeks to secure at the root.
But can three such different frameworks really be pooled?
A fair objection. MiCA belongs to financial markets, eIDAS to digital identity, and DORA to cybersecurity. Three worlds, three authorities, three logics. How could a single base serve them all?
Three things answer that question.
Interoperability is the very goal of eIDAS 2.0. The regulation was designed so that an identity attestation, verified once, can be reused across services and borders. Pooling isn't a workaround for the framework: it's its whole point.
An identity tied to an official document serves all three uses. The same proof, a face matched in real time against a verified ID document, feeds MiCA's AML onboarding just as well as the identification eIDAS requires and the strong authentication DORA expects. The purpose changes; the foundation stays the same.
Zero Knowledge Proof and the absence of biometric storage align compliance and resilience. Proving identity without keeping any biometric data satisfies data minimisation (GDPR, eIDAS) while shrinking the exposed surface that DORA requires you to protect. What secures one strengthens the other.
The cost of inaction
Continuing to treat these three texts as three separate projects means footing a bill that climbs on four fronts at once.
A tripled compliance cost, from redundant tools and audits piled onto a single need. A cumulative penalty risk, when MiCA, eIDAS, and DORA sanctions all trigger in the same year rather than staying contained. A loss of market access for the CASP that misses the European passport on 1 July. And a competitive lag on the wallet, when players are ready to receive digital identity pull ahead of those discovering the integration in 2027.
It isn't a problem for tomorrow. It's a problem for this year, one whose bill grows heavier with every deadline that draws closer.
Identity should never be one more project on the pile
The proliferation of frameworks isn't an organisational fate. It's the symptom of reading a single underlying shift in silos: in 2026, verified identity becomes regulatory infrastructure, on the same footing as the network or storage. A layer you don't rebuild three times, but one that everything else rests on.
The question is no longer whether these regulations will converge: they already are, on the calendar as much as on the substance. It's how long a company can afford to fund the same foundation three times before treating it as what it has become: a single base.
This is exactly the problem ShareID solves. An official identity verified once, then reusable at every critical moment of the journey (onboarding, sensitive operation, access) through an MFA 3.0 that satisfies eIDAS strong authentication, MiCA's KYC and DORA's access control. A single glance is enough. No secret to manage, no biometric data stored, a reusable cryptographic proof. Not three projects running in parallel: a single identity infrastructure, built for the year it becomes mandatory.
.png)

.png)