Springlex presents compliance legislation from the EU in an accessible format – for a solid experience while pursuing legal compliance.
Packages
Markets in crypto-assets (“MiCA”)
The EU framework for governing crypto-assets, aiming to protect investors, ensure market stability, and support innovation. It sets clear rules for different types of tokens, requires transparency from issuers, and introduces licensing and operational standards for service providers.
35
legal acts
View acts
Basic legislative acts
Common
- Commission Delegated Regulation (EU) 2025/422 RTS on sustainability indicators
- Commission Implementing Regulation (EU) 2024/2861 ITS on insider information disclosure
Crypto-asset service provider
- Commission Delegated Regulation (EU) 2025/885 RTS on market abuse
- Commission Delegated Regulation (EU) 2025/1142 RTS on CASP conflicts of interest
- Commission Delegated Regulation (EU) 2025/294 RTS on CASP complaints handling
- Commission Delegated Regulation (EU) 2025/414 RTS on acquisition of qualified holding in CASP
- Commission Delegated Regulation (EU) 2025/1140 RTS on record keeping
- Commission Delegated Regulation (EU) 2025/416 RTS on trading platform order book records
- Commission Delegated Regulation (EU) 2025/417 RTS on trading platform transparency data
- Commission Delegated Regulation (EU) 2025/299 RTS on continuity and regularity
- Commission Delegated Regulation (EU) 2025/305 RTS on CASP authorisation
- Commission Implementing Regulation (EU) 2025/306 ITS on CASP authorisation
- Commission Delegated Regulation (EU) 2025/303 RTS on notification of crypto-asset service provision
- Commission Implementing Regulation (EU) 2025/304 ITS on notification of crypto-asset service provision
ART/EMT issuer
- Commission Delegated Regulation (EU) 2025/1141 RTS on issuer conflicts of interest
- Commission Delegated Regulation (EU) 2025/293 RTS on issuer complaints handling
- Commission Delegated Regulation (EU) 2025/413 RTS on acquisition of qualified holding in ART issuer
- Commission Delegated Regulation (EU) 2025/415 RTS on stress test programmes
- Commission Implementing Regulation (EU) 2024/2984 ITS on crypto-asset white papers
- Commission Delegated Regulation (EU) 2025/296 RTS on crypto-asset white paper approval
- Commission Delegated Regulation (EU) 2025/419 RTS on own funds adjustment timeframe
- Commission Delegated Regulation (EU) 2025/298 RTS on non-EU currencies
- Commission Implementing Regulation (EU) 2024/2902 ITS on non-EU currency reporting
Significant ART/EMT issuer
- Commission Delegated Regulation (EU) 2024/1506 Criteria for significance classification
- Commission Delegated Regulation (EU) 2025/418 RTS on remuneration policy
- Commission Delegated Regulation (EU) 2024/1503 Fees charged by the EBA
- Commission Delegated Regulation (EU) 2024/1504 Fines and penalties of the EBA
Supervision
- Commission Delegated Regulation (EU) 2025/300 RTS on competent authority information exchange
- Commission Implementing Regulation (EU) 2024/2545 ITS on competent authority information exchange
- Commission Delegated Regulation (EU) 2025/292 RTS on third country supervisory cooperation
- Commission Delegated Regulation (EU) 2025/297 RTS on consultative supervisory colleges
- Commission Delegated Regulation (EU) 2024/1507 Intervention powers of authorities
- Commission Delegated Regulation (EU) 2025/421 RTS on crypto-asset white paper classification
- Commission Implementing Regulation (EU) 2024/2494 ITS on supervisory cooperation
Cyber resilience for products with digital elements (“CRA”)
Consumer protection legislation mandating certain essential cybersecurity requirements for products with digital elements and their manufacturers in order to get a CE marking in the EU.
1
legal acts
View acts
Basic legislative acts
High common level of cybersecurity for entities (“NIS 2”)
Horizontal legislation to achieve a high common level of cybersecurity for services, establishing national capabilities, cooperation at a EU level, and risk-management measures for entities.
2
legal acts
Artificial intelligence act (“AI act”)
Risk-based, harmonised rules for AI developers and deployers regarding specific uses of AI, and prohibiting some uses, in order to promote trustworthiness.
2
legal acts
View acts
Resilience of critical entities (“CER”)
Legislation aiming to increase the resilience of certain infrastructure providers (so-called critical entities) against natural hazards, terrorist attacks, sabotage, insider threats and public health emergencies.
2
legal acts
View acts
Digital operational resilience in the financial sector (“DORA”)
Comprehensive legislation on various cyber security topics including an oversight framework for service providers, applies to nearly all types of financial entities in the EU.
14
legal acts
View acts
Basic legislative acts
- Regulation (EU) 2022/2554 of the European Parliament and of the Council DORA regulation
- Directive (EU) 2022/2556 of the European Parliament and of the Council DORA directive
ICT risk management
ICT-related incidents
- Commission Delegated Regulation (EU) 2024/1772 RTS on incident classification
- Commission Delegated Regulation (EU) 2025/301 RTS on incident reporting
- Commission Implementing Regulation (EU) 2025/302 ITS on templates for incident reporting
Digital operational resilience testing
ICT third-party service providers
- Commission Delegated Regulation (EU) 2024/1773 RTS on ICT third-party service provider policy
- Commission Delegated Regulation (EU) 2025/532 RTS on subcontracting ICT services
- Commission Implementing Regulation (EU) 2024/2956 ITS on register of information
Oversight framework
- Commission Delegated Regulation (EU) 2024/1502 Criteria for designating critical service providers
- Commission Delegated Regulation (EU) 2025/295 RTS on harmonisation for oversight conduct
- Commission Delegated Regulation (EU) 2025/420 RTS on joint examination teams
- Commission Delegated Regulation (EU) 2024/1505 Oversight fees