Source: OJ L, 2025/299, 13.2.2025

Current language: EN

Article 6 Complexity and risk considerations


Summary What does Article 6 of the RTS on continuity and regularity say?

This article acts as a calibration mechanism for the business continuity policy requirements set out in earlier articles.

It requires crypto-asset service providers to tailor their business continuity policy to their own risk profile, taking into account factors that could increase complexity or risk.

Crucially, it also mandates an annual self-assessment to ensure this calibration remains current and reflective of the provider's actual operations.

Important points:

  • Factor in elements of increased complexity or risk — including the types of services offered, reliance on permissionless distributed ledgers, and the potential impact of disruptions — when building your business continuity policy.
  • Conduct an annual self-assessment of the scale, nature, and range of your services, using the criteria in the Annex as a baseline alongside any other criteria you consider relevant.
  • The self-assessment feeds directly into how the business continuity policy is shaped, making it an ongoing obligation rather than a one-time exercise.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. When establishing the business continuity policy, including the plans, procedures and measures, crypto-asset service providers shall take into account elements of increased complexity or risk, including:

      1. the type and range of crypto-asset services offered;

      2. the extent to which the services of the crypto-asset service provider rely on permissionless distributed ledger;

      3. the potential impact of any disruptions on the continuity of the crypto-asset service provider’s activities and availability of its services.

    1. For the purposes of paragraph 1, crypto-asset service providers shall conduct a self-assessment of the scale, the nature, and range of their services annually. Crypto-asset service providers shall base that self-assessment on the criteria set out in the Annex and any other criteria that the crypto-asset service provider considers relevant.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod