Source: OJ L, 2025/305, 31.3.2025

Current language: EN

Article 5 Business continuity plan


Summary What does Article 5 of the RTS on CASP authorisation say?

This article requires applicants for crypto-asset service provider authorisation to submit a detailed description of their business continuity plan to the competent authority.

It builds on the broader authorisation requirements of Article 62(2) of Regulation (EU) 2023/1114, specifically addressing point (i) of that provision.

The article goes beyond simply requiring a plan to exist — it demands evidence that the plan is operational, tested, and capable of addressing specific disruption scenarios, including third-party failures and personnel risks.

Important points:

  • Submit a detailed business continuity plan as part of the authorisation application, covering how continuity and regularity of crypto-asset services will be maintained.
  • Address third-party dependencies explicitly — the plan must explain how continuity is preserved if a critical or important function provided by a third party deteriorates to an unacceptable level or fails.
  • Account for key person risk and, where relevant, political risks in a service provider's jurisdiction as part of the continuity arrangements.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. For the purposes of Article 62(2), point (i), of Regulation (EU) 2023/1114 applicants shall submit to the competent authority a detailed description of the business continuity plan, including the steps to be taken to ensure continuity and regularity in the provision of the applicant’s crypto-asset services.

    1. The description referred to in paragraph 1 shall include the following:

      1. details proving that the business continuity plan is appropriate and that arrangements are set up to maintain and periodically test that plan;

      2. with regard to critical or important functions supported by third-party service providers, information on how business continuity is ensured where the quality of the provision of such functions deteriorates to an unacceptable level or fails;

      3. information on how business continuity is ensured in the event of the death of a key person and, where relevant, political risks in the service provider’s jurisdiction.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod