Source: OJ L, 2025/303, 20.2.2025

Current language: EN

Article 2 Business continuity plan


Summary What does Article 2 of the RTS on notification of crypto-asset service provision say?

This article sets out what a notifying entity must submit to the competent authority regarding its business continuity plan, as required under Article 60(7)(b)(iii) of Regulation (EU) 2023/1114.

It is a focused, disclosure-oriented article that builds directly on the overarching authorisation notification framework.

Rather than defining what a business continuity plan must look like in operational terms, it specifies the information that must be provided to the competent authority to demonstrate that such a plan exists, is tested, and accounts for specific risk scenarios.

Important points:

  • Submit a detailed description of your business continuity plan to the competent authority, covering how continuity and regularity of crypto-asset services will be maintained.
  • The plan must address the failure or deterioration of critical or important functions provided by third-party service providers.
  • The plan must also account for the death of a key person and, where relevant, political risks in the jurisdictions of service providers.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. For the purposes of Article 60(7), point (b) (iii), of Regulation (EU) 2023/1114, the notifying entity shall submit to the competent authority a detailed description of its business continuity plan, including the steps to be taken to ensure continuity and regularity in the provision of its crypto-asset services.

    1. The description referred to in paragraph 1 shall include the following:

      1. details showing that the established business continuity plan is appropriate and that arrangements are set up to maintain and periodically test that plan;

      2. with regard to critical or important functions supported by third-party service providers, details on how business continuity is ensured in the event that the quality of the provision of such functions deteriorates to an unacceptable level or fails;

      3. information on how business continuity is ensured in the event of the death of a key person and, where relevant, political risks in the service provider’s jurisdictions.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod