Source: OJ L, 2025/299, 13.2.2025

Current language: EN

Article 4 Business continuity plans


Summary What does Article 4 of the RTS on continuity and regularity say?

This article translates the overarching business continuity policy established under Article 2 into concrete, operational plans.

It sets out what crypto-asset service providers must actually document and prepare for when things go wrong, covering everything from scenario planning and recovery objectives to client communications and outsourcing disruptions.

A notable feature of this article is its specific treatment of permissionless distributed ledgers, recognising that disruptions to these decentralised infrastructures present unique challenges where information may not be readily available to the provider.

Important points:

  • Establish business continuity plans that protect and, where necessary, re-establish the confidentiality, integrity, and availability of client data and business functions.
  • Include tailored communication procedures for disruptions involving permissionless distributed ledgers, covering expected resumption times, reasons and impact of the incident, risks to client funds and crypto-assets, and intended response measures — updating clients and competent authorities on a best effort basis where information is not readily available.
  • Ensure the plans explicitly address disruptions to outsourced critical or important functions, including scenarios where those functions become entirely unavailable.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. When implementing the business continuity policy referred to in Article 68(7) of Regulation (EU) 2023/1114, crypto-asset service providers shall establish business continuity plans. The business continuity plans shall set out the procedures necessary to protect and, where necessary, re-establish:

      1. the confidentiality, integrity, and availability of client data;

      2. the availability of the business functions, supporting processes and information assets of the crypto-asset service providers.

    1. The business continuity plans shall contain the following:

      1. a range of possible adverse scenarios relating to the operation of critical or important functions, including the unavailability of business functions, staff, workspace, external suppliers, data centres, or loss or alteration of critical data and documents;

      2. the procedures and policies to be followed in case of a disruptive incident, including:

        1. the measures that are necessary to recover critical or important functions;

        2. the deadlines by which those critical or important functions are to be recovered;

        3. recovery point objectives;

        4. the maximum time to resume services;

      3. the procedures and policies for relocating the business functions used to provide crypto-asset services to a back-up site;

      4. back-up of critical business data, including up-to-date information of the necessary contacts to ensure communication inside the crypto-asset service provider, between the crypto-asset service provider and its clients;

      5. procedures for timely communications with clients and other external stakeholders, including competent authorities.

    1. In the event of a disruption involving a permissionless distributed ledger used by the crypto asset service provider in the provision of its services, the communications referred to in paragraph 2, point (e) shall include the following information:

      1. when the services are expected to be resumed;

      2. the reasons and the impact of the disruptive incident;

      3. any risks concerning clientsfunds and crypto-assets held on their behalf;

      4. measures that the crypto-asset service intends to take in response to the disruption of a permissionless distributed ledger.

    2. Where that information is not readily available to the crypto-asset service provider, the crypto-asset service provider shall communicate updates as regards the information in the first subparagraph to clients and stakeholders, including competent authorities, on a best effort basis.

    1. The business continuity plans shall contain procedures to address any disruptions of outsourced critical or important functions, including where those critical or important functions become unavailable.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod