Source: OJ L, 2025/885, 20.8.2025

Current language: EN

Article 2 General requirements


Summary What does Article 2 of the RTS on market abuse say?

This is a core foundational article that establishes the primary obligations for persons professionally arranging or executing transactions in crypto-assets.

It sets out the requirement to build and maintain monitoring systems capable of detecting potential market abuse across orders, transactions, and even the functioning of the underlying distributed ledger technology itself, including its consensus mechanism.

Notably, these obligations apply broadly regardless of the capacity in which a transaction is executed, the type of client involved, or whether activity takes place on or outside a trading platform.

The article also lays down governance requirements around how these systems must be maintained and documented over time.

Important points:

  • Establish and maintain ongoing monitoring systems covering orders, transactions, and DLT functioning to detect potential market abuse, and ensure suspicious transaction and order reports (STORs) are transmitted to competent authorities using the prescribed template.
  • The monitoring obligations apply universally — irrespective of the capacity of the order, the client type, or whether activity occurs on or outside a trading platform.
  • Document all arrangements, systems and procedures in writing, subject these to at least an annual audit and internal review, and retain that documentation for 5 years.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. Persons professionally arranging or executing transactions in crypto-assets shall establish and maintain arrangements, systems and procedures that ensure:

      1. effective and ongoing monitoring, for the purposes of preventing, detecting and identifying orders and transactions where circumstances might exist indicating that market abuse has been committed, is being committed or is likely to be committed, of all orders received and transmitted, and all transactions in crypto-assets executed;

      2. effective and ongoing monitoring of aspects of the functioning of the DLT, for the purposes of detecting and identifying other aspects of the functioning of the distributed ledger technology, including the consensus mechanism, where circumstances might exist indicating that market abuse has been committed, is being committed or is likely to be committed;

      3. the transmission of STORs to competent authorities in accordance with the requirements set out in this Regulation and using the template set out in the Annex.

    1. The obligations referred to in paragraph 1 shall apply to orders, transactions and other aspects of the functioning of the DLT which might constitute market abuse and shall apply irrespective of:

      1. the capacity in which the order is placed or the transaction is executed;

      2. the types of clients concerned;

      3. whether the orders were placed or transactions executed on or outside a trading platform.

    1. Persons professionally arranging or executing transactions in crypto-assets shall ensure that the arrangements, systems and procedures referred to in paragraph 1 are:

      1. appropriate and proportionate in relation to the scale, size and nature of their business activity;

      2. regularly assessed, at least through an annually conducted audit and internal review, and updated when necessary;

      3. clearly documented in writing, including any changes or updates to them, for the purposes of compliance with this Regulation, and that the documented information is maintained for a period of 5 years.

    1. Persons professionally arranging or executing transactions in crypto-assets shall, upon request, provide the competent authority with the information on the assessment referred to in paragraph 3, including information on the level of automation put in place.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod