Source: OJ L, 2025/305, 31.3.2025

Current language: EN

RTS on CASP authorisation

COMMISSION DELEGATED REGULATION (EU) 2025/305

of 31 October 2024

supplementing Regulation (EU) 2023/1114 of the European Parliament and of the Council with regard to regulatory technical standards specifying the information to be included in an application for authorisation as a crypto-asset service provider

(Text with EEA relevance)

THE EUROPEAN COMMISSION,

Having regard to the Treaty on the Functioning of the European Union,

Having regard to Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets, and amending Regulations (EU) No 1093/2010 and (EU) No 1095/2010 and Directives 2013/36/EU and (EU) 2019/1937(1)OJ L 150, 9.6.2023, p. 40, ELI: http://data.europa.eu/eli/reg/2023/1114/oj., and in particular Article 62(5), third subparagraph, thereof,

Whereas:

Open full page
Recital 1Detailed yet proportionate information for CASP authorisation

To enable competent authorities to assess whether legal persons or other undertakings seeking authorisation as a crypto-asset service provider in accordance with Article 62 of Regulation (EU) 2023/1114 (‘applicants’) meet the applicable requirements laid down in Title V and, where relevant, Title VI of that Regulation, the information to be provided in an application for authorisation as crypto-asset service provider submitted in accordance with Article 62(1) of that Regulation (‘application for authorisation’) should be sufficiently detailed and comprehensive without imposing undue burden.

Recital 2Minimum information enabling comprehensive authorisation assessment

The application for authorisation should contain data about the identity of the applicant, the governance arrangements and internal control mechanisms, the suitability of the members of the management body and the sufficiently good repute of the shareholders or members with qualifying holdings. In compliance with the principle of data minimisation as expressed in Article 5(1), point (c) of Regulation (EU) 2016/679 of the European Parliament and of the Council(2)Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1, ELI: http://data.europa.eu/eli/reg/2016/679/oj)., such information should be sufficient to enable competent authorities to carry out a comprehensive assessment of applicants, and of their ability to comply with the relevant requirements of Regulation (EU) 2023/1114. Furthermore, that information should be sufficient to enable competent authorities to verify that there are no objective and demonstrable grounds for refusal of the authorisation as referred to in Article 63(10), points (a) to (d), of that Regulation.

Recital 3Corporate documentation and identification information requirements

To ensure that the competent authorities’ assessment is based on accurate information, applicants should provide copies of their corporate documents, including their legal entity identifier, the articles of association, a copy of their registration in the national register of companies and, where applicants intend to operate a trading platform, the commercial name used.

HAS ADOPTED THIS REGULATION:

  1. Article 1General information
  2. Article 2Programme of operations
  3. Article 3Prudential requirements
  4. Article 4Information about governance arrangements and internal control mechanisms and conflict of interests
  5. Article 5Business continuity plan
  6. Article 6Detection and prevention of money laundering and terrorist financing
  7. Article 7Identity and proof of good repute, knowledge, skills and experience, and of sufficient time commitment of the members of the management body
  8. Article 8Information relating to shareholders or members with qualifying holdings
  9. Article 9ICT systems and related security arrangements
  10. Article 10Segregation and safekeeping of clients’ crypto-assets and funds
  11. Article 11Complaints-handling procedures
  12. Article 12Custody and administration policy
  13. Article 13Operating rules of the trading platform and market abuse detection
  14. Article 14Exchange of crypto-assets for funds or other crypto-assets
  15. Article 15Execution policy
  16. Article 16Provision of advice on crypto-assets or portfolio management of crypto-assets
  17. Article 17Transfer services
  18. Article 18Entry into force

This Regulation shall be binding in its entirety and directly applicable in all Member States.

Done at Brussels, 31 October 2024.

For the Commission

The President

Ursula VON DER LEYEN

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod