Source: OJ L, 2025/305, 31.3.2025

Current language: EN

Article 9 ICT systems and related security arrangements


Summary What does Article 9 of the RTS on CASP authorisation say?

This article sets out the ICT and cybersecurity disclosure requirements that applicants for crypto-asset service provider authorisation must satisfy, feeding directly into Article 62(2)(j) of MiCA (Regulation (EU) 2023/1114).

It requires applicants to submit technical documentation covering their ICT risk management framework, DLT infrastructure, security arrangements, third-party ICT service providers, and incident management procedures, all framed against their obligations under DORA (Regulation (EU) 2022/2554).

Notably, it also calls for a description of any cybersecurity audits carried out by an independent third-party auditor, covering a broad range of testing methodologies, and crucially requires that all of this technical information be presented in non-technical language as well.

Important points:

  • Provide full technical documentation of your ICT systems, DLT infrastructure, security arrangements, and third-party ICT service provider contractual arrangements, demonstrating compliance with DORA and the GDPR.
  • Submit a description of any third-party cybersecurity audits conducted, including penetration tests across black box, grey box, and white box approaches, and, where relevant, a source code review of any smart contracts used or developed.
  • Accompany all technical disclosures with a non-technical language description of the same information.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

For the purposes of Article 62(2), point (j), of Regulation (EU) 2023/1114, applicants shall provide to the competent authority the following information:

  1. technical documentation of the ICT systems, DLT infrastructure relied upon, where relevant, and the security arrangements, including a description of the arrangements and deployed ICT and human resources established to comply with Regulation (EU) 2022/2554 of the European Parliament and of the Council(9)as follows:

    1. a description of how the applicant ensures a sound, comprehensive and well-documented ICT risk management framework as part of its overall risk management system, including a detailed description of ICT systems, protocols and tools and of how the applicant’s procedures, policies and systems to safeguard the security, integrity, availability, authenticity and confidentiality of data comply with Regulations (EU) 2022/2554 and (EU) 2016/679;

    2. an identification of ICT services supporting critical or important functions, developed or maintained by the applicant, and ICT services supporting critical or important functions provided by third-party service providers, a description of such contractual arrangements (identity and geographical location of the providers, description of the outsourced activities or ICT services with their main characteristics, copy of contractual agreements) and how those arrangements comply with Article 73 of Regulation (EU) 2023/1114 and Chapter V of Regulation (EU) 2022/2554;

    3. a description of the applicant’s procedures, policies, arrangements and systems for security and incident management;

  2. if available, a description of a cybersecurity audit conducted by a third-party cybersecurity auditor having sufficient experience in accordance with Commission Delegated Regulation establishing technical standards adopted pursuant to Article 26(11) fourth subparagraph of Regulation (EU) 2022/2554 covering ideally the following audits or tests:

    1. organisational cybersecurity, physical security and secure software development lifecycle arrangements;

    2. vulnerability assessments and scans and, network security assessments;

    3. configuration reviews of ICT assets supporting critical and important functions as defined in Article 3, point (22) of Regulation (EU) 2022/2554;

    4. penetration tests on the ICT assets supporting critical and important functions as defined in Article 3, point (17) of Regulation (EU) 2022/2554, in accordance with all the following audit test approaches:

      1. black box: the auditor has no information other than the IP addresses and URLs associated with the audited target. This phase is generally preceded by the discovery of information and the identification of the target by querying domain name system (DNS) services, scanning open ports, discovering the presence of filtering equipment, etc.;

      2. grey box phase: auditors have the knowledge of a standard user of the information system (legitimate authentication, ‘standard’ workstation, etc.). The identifiers can belong to different user profiles in order to test different privilege levels;

      3. white box phase: auditors have as much technical information as possible (architecture, source code, telephone contacts, identifiers, etc.) before starting the analysis and also access to technical contacts related to the target;

    5. where the applicant uses and/or develops smart-contracts, a cybersecurity source code review of them;

  3. a description of conducted audits of the ICT systems, if any, including used DLT infrastructure and security arrangements;

  4. a description of the relevant information referred to in points (a) and (b) in non-technical language.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod