Source: OJ L, 2025/299, 13.2.2025

Current language: EN

Article 3 Business continuity policy


Summary What does Article 3 of the RTS on continuity and regularity say?

Article 3 sets out the core requirements for what a business continuity policy must contain and achieve.

Building directly on Article 2, which establishes who is responsible for the policy, this article shifts focus to the substance of that policy itself.

It requires that the policy genuinely address disruptive incidents affecting critical systems, be recorded in a durable medium, and cover a defined set of mandatory elements — from scope and activation criteria to governance arrangements and alignment with ICT-specific continuity frameworks.

Important points:

  • Ensure your business continuity policy is recorded in a durable medium and addresses disruptive incidents or performance issues affecting systems critical to your business functions.
  • Include in the policy a clear scope, activation criteria with escalation procedures up to management body level, and governance provisions covering staff roles, responsibilities, and resources.
  • The policy must be consistent with ICT-business continuity plans and ICT response and recovery plans under Delegated Regulation (EU) 2024/1774, ensuring alignment across continuity frameworks.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. The business continuity policy referred to in Article 68(7) of Regulation (EU) 2023/1114 shall ensure that crypto-asset service providers properly address disruptive incidents or performance issues relating to the systems critical to the operation of their business functions and it shall be laid down in a durable medium.

    1. Crypto-asset service providers shall include in the business continuity policy all of the following:

      1. a specification of the scope of the business continuity policy, including its limitations and exclusions, to be covered by the business continuity plans, procedures, and measures;

      2. a description of the criteria to activate the business continuity plans, including escalation procedures up to the level of the management body;

      3. provisions on the governance and organisation of the crypto-asset service provider, including, the roles and responsibilities of the staff, ensuring that sufficient resources are available for the effective implementation of the policy;

      4. provisions that ensure consistency between the business continuity plans and the ICT-business continuity plans, and ICT response and recovery plans referred to in Articles 24 and 26 of Delegated Regulation (EU) 2024/1774.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod