Source: OJ L, 2025/305, 31.3.2025

Current language: EN

Article 17 Transfer services


Summary What does Article 17 of the RTS on CASP authorisation say?

This article sets out the information that applicants intending to provide crypto-asset transfer services on behalf of clients must submit to the competent authority as part of the authorisation process under MiCA.

It feeds directly into the broader authorisation requirements of Article 62(2) of Regulation (EU) 2023/1114, specifically point (r).

The article focuses on ensuring that applicants can demonstrate operational readiness, risk awareness, and transparency to both regulators and clients when offering this particular service.

Important points:

  • Applicants intending to provide crypto-asset transfer services must disclose the types of crypto-assets they will cover, their risk management arrangements including ICT and human resources, any available insurance policy, and how clients will be informed of those arrangements.
  • Describe in detail the arrangements put in place to address operational failures and cybersecurity risks during the provision of transfer services.
  • Ensure clients are adequately informed about the policies, procedures, and risk management arrangements in place.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

For the purposes of Article 62(2), point (r), of Regulation (EU) 2023/1114, applicants that intend to provide transfer services for crypto-assets on behalf of clients shall provide to the competent authority all of the following information:

  1. details on the types of crypto-assets for which the applicant intends to provide transfer services;

  2. a detailed description of the arrangements put in place by the applicant to comply with Article 82 of Regulation (EU) 2023/1114, including detailed information on the applicant’s arrangements and deployed ICT and human resources to address risks promptly, efficiently and thoroughly during the provision of transfer services for crypto-assets on behalf of clients, taking into account potential operational failures and cybersecurity risks;

  3. where available, a description of the applicant’s insurance policy, including on the insurance’s coverage of detriment to client’s crypto-assets that may result from cyber security risks;

  4. arrangements to ensure that clients are adequately informed about the policies, procedures and arrangements referred to in point (b).

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod