Source: OJ L, 2025/303, 20.2.2025

Current language: EN

Article 11 Transfer services


Summary What does Article 11 of the RTS on notification of crypto-asset service provision say?

This article sets out the specific information that a notifying entity must submit to the competent authority when it intends to provide crypto-asset transfer services on behalf of clients.

It sits within a broader notification framework tied to Article 60(7) of Regulation (EU) 2023/1114, and is one of several service-specific articles that build on the general notification requirements established earlier in the act.

The article focuses on demonstrating operational readiness, covering the scope of crypto-assets to be transferred, the risk management arrangements in place, any applicable insurance coverage, and how clients will be kept informed.

Important points:

  • Disclose to the competent authority the types of crypto-assets for which transfer services will be provided, along with detailed ICT and human resource arrangements to address operational failures and cybersecurity risks.
  • Where an insurance policy exists, provide a description of it, including its coverage of potential detriment to clients' crypto-assets arising from cybersecurity risks.
  • Put in place arrangements to ensure clients are adequately informed about the risk management measures deployed during the provision of transfer services.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

For the purposes of Article 60(7), point (k), of Regulation (EU) 2023/1114, the notifying entity that intends to provide transfer services for crypto-assets on behalf of clients shall provide to the competent authority the following information:

  1. details on the types of crypto-assets for which the notifying entity intends to provide transfer services;

  2. a detailed description of the arrangements put in place by the notifying entity to comply with Article 82 of Regulation (EU) 2023/1114, including detailed information on the notifying entity’s arrangements and deployed ICT and human resources to address risks promptly, efficiently and thoroughly during the provision of transfer services for crypto-assets on behalf of clients, taking into account potential operational failures and cybersecurity risks;

  3. where available, a description of the notifying entity’s insurance policy, including on the insurance’s coverage of detriment to client’s crypto-assets that may result from cyber security risks;

  4. arrangements to ensure that clients are adequately informed about the arrangements referred to in point (b).

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod