Source: OJ L, 2025/306, 31.3.2025

Current language: EN

Article 4 Notification of changes


Summary What does Article 4 of the ITS on CASP authorisation say?

This article establishes ongoing notification obligations that apply both during the application process and after authorisation has been granted.

It builds directly on Article 2, which sets out the initial application process, by addressing what happens when information changes.

The core principle is that neither applicants nor authorised crypto-asset service providers can simply submit their information once and leave it static — any changes must be reported to the competent authority.

A notable procedural consequence is also established: when an applicant submits updated information during the application phase, this resets the clock on the authority's decision-making timeline.

Important points:

  • Notify the competent authority of any changes to your application information without undue delay, using the same form from the Annex.
  • Be aware that submitting updated information during the application process resets the decision deadline under Article 63(9) of Regulation (EU) 2023/1114, starting it from the date the authority receives the update.
  • Authorised crypto-asset service providers are also required to notify the competent authority of any changes to the information on which their authorisation was based.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. The applicant shall notify the competent authority of any changes to the information provided in the application for authorisation without undue delay. The applicant shall provide the updated information by using the form set out in the Annex.

    1. Where the applicant provides updated information in accordance with paragraph 1, the time limit laid down in Article 63(9) of Regulation (EU) 2023/1114 shall start from the date of receipt of that updated information by the competent authority.

    1. Crypto-asset service providers shall notify the competent authority of any changes to the information based on which the authorisation was granted.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod