Source: OJ L, 2025/299, 13.2.2025

Current language: EN

Article 5 Periodic testing of the business continuity plans


Summary What does Article 5 of the RTS on continuity and regularity say?

This article directly builds on Article 4, which sets out the content of business continuity plans, by establishing the requirements for testing those plans.

The core obligation is that crypto-asset service providers must regularly test their business continuity plans using realistic scenarios to verify their actual ability to recover from disruptive incidents.

The article sets out how that testing should be conducted, what factors should inform it, how results must be reported, and importantly, that testing must not disrupt the normal running of services.

Important points:

  • Test your business continuity plans at least annually, informed by factors such as threat intelligence, lessons from past events, and any changes to recovery objectives or business functions.
  • Document all testing results in writing and submit them to both the management body and the relevant operating units.
  • Ensure that the testing process itself does not interfere with the normal conduct of services.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. Crypto-asset service providers shall test the operation of the business continuity plans referred to in Article 4 on the basis of realistic scenarios. Such testing shall verify the capability of the crypto-asset service provider to recover from disruptive incidents and to resume services in accordance with Article 4(2), point (b).

    1. Crypto-asset service providers shall test the business continuity plans annually taking into account:

      1. the results of the tests referred to in paragraph 1;

      2. the most recent threat intelligence;

      3. lessons derived from previous events;

      4. where relevant, any changes in the recovery objectives, including recovery time objectives and recovery point objectives as referred to in Article 4(2), point (b);

      5. changes in the business functions.

    1. Crypto-asset service providers shall document the results of the testing activity in writing, and submit them to their management body and to the operating units involved in the business continuity plans.

    1. Crypto-asset service providers shall ensure that the testing of the business continuity plans does not interfere with normal conduct of their services.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod