Source: OJ L, 2025/303, 20.2.2025Current language: EN
- Markets in crypto-assets
Crypto-asset service provider
- RTS on notification of crypto-asset service provision
Article 4 ICT systems and related security arrangements
Summary What does Article 4 of the RTS on notification of crypto-asset service provision say?
This article specifies the ICT and cybersecurity information that a notifying entity must submit to the competent authority as part of the notification process under Regulation (EU) 2023/1114.
It is directly tied to Article 60(7)(c) of that Regulation and sits alongside other articles in this act that each address a distinct category of information required at notification.
The article is notably technical in its scope, requiring the notifying entity to demonstrate how its ICT infrastructure, risk management framework, and security arrangements comply with DORA (Regulation (EU) 2022/2554).
Beyond the core technical documentation, the article also calls for details of any third-party cybersecurity audits that have been conducted, covering a range of testing methodologies, and crucially requires that all of this information also be presented in non-technical language.
Important points:
- Provide full technical documentation of your ICT systems, DLT infrastructure, and security arrangements, demonstrating compliance with DORA and the data protection requirements of Regulation (EU) 2016/679.
- Submit details of any third-party cybersecurity audit conducted, including penetration tests carried out using black box, grey box, and white box approaches, as well as a smart contract source code review where applicable — though this is required only if such an audit is available.
- Accompany all technical documentation with a non-technical description, ensuring the competent authority can assess the information regardless of technical expertise.
Springlex's summary of the article, a reading aid, not a substitute for the legal text.
For the purposes of Article 60(7), point (c), of Regulation (EU) 2023/1114, the notifying entity shall provide the competent authority the following information:
technical documentation of the ICT systems, DLT infrastructure relied upon, where relevant, and the security arrangements, including a description of the arrangements and deployed ICT and human resources established to comply with Regulation (EU) 2022/2554 of the European Parliament and of the Council(8) including the following:
a description of how the notifying entity ensures a sound, comprehensive and well-documented ICT risk management framework as part of its overall risk management system, including a detailed description of ICT systems, protocols and tools and of how the notifying entity’s procedures, policies and systems will safeguard the security, integrity, availability, authenticity and confidentiality of data in accordance with Regulations (EU) 2022/2554 and (EU) 2016/679;
an identification of ICT services supporting critical or important functions, developed or maintained by the notifying entity, as well as those provided by third-party service providers, a description of such contractual arrangements and how those arrangements comply with Article 73 of Regulation (EU) 2023/1114 and Chapter V of Regulation (EU) 2022/2554;
a description of the notifying entity’s procedures, policies, arrangements and systems for security and incident management;
if available, a description of a cybersecurity audit conducted by a third-party cybersecurity auditor having sufficient experience in accordance with Commission Delegated Regulation establishing technical standards pursuant to Article 26(11) fourth subparagraph of Regulation (EU) 2022/2554 covering ideally the following audits or tests by external independent parties:
organisational cybersecurity, physical security and secure software development lifecycle arrangements;
vulnerability assessments and network security assessments;
configuration reviews of ICT assets supporting critical and important functions as defined in Article 3, point (22) of Regulation (EU) 2022/2554;
penetration tests on the ICT assets supporting critical and important functions as defined in Article 3, point (17) of Regulation (EU) 2022/2554, in accordance with all the following audit test approaches:
black box: the auditor has no information other than the IP addresses and URLs associated with the audited target. This phase is generally preceded by the discovery of information and the identification of the target by querying domain name system (DNS) services, scanning open ports, discovering the presence of filtering equipment;
grey box phase: auditors have the knowledge of a standard user of the information system (legitimate authentication, ‘standard’ workstation). The identifiers can belong to different user profiles in order to test different privilege levels;
white box phase: auditors have as much technical information as possible (architecture, source code, telephone contacts, identifiers, etc.) before starting the analysis and also access to technical contacts related to the target;
where the notifying entity uses and/or develops smart-contracts, a cybersecurity source code review of them;
a description of conducted audits of the ICT systems, if any, including used DLT infrastructure and security arrangements;
a description of the relevant information referred to in points (a) and (b) in non-technical language.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
placing of crypto-assets
Definition
official currency
Definition
distributed ledger
Definition
reception and transmission of orders for crypto-assets on behalf of clients
Definition
exchange of crypto-assets for funds
Definition
consensus mechanism
Definition
operation of a trading platform for crypto-assets
Definition
e-money token
Definition
crypto-asset service
- providing custody and administration of crypto-assets on behalf of clients;
- operation of a trading platform for crypto-assets;
- exchange of crypto-assets for funds;
- exchange of crypto-assets for other crypto-assets;
- execution of orders for crypto-assets on behalf of clients;
- placing of crypto-assets;
- reception and transmission of orders for crypto-assets on behalf of clients;
- providing advice on crypto-assets;
- providing portfolio management on crypto-assets;
- providing transfer services for crypto-assets on behalf of clients;
Definition
offer to the public
Definition
providing advice on crypto-assets
Definition
offeror
Definition
execution of orders for crypto-assets on behalf of clients
Definition
DLT
Definition
crypto-asset service provider
Definition
crypto-asset
Definition
DLT network node
Definition
funds
Definition
client
Definition
asset-referenced token
Definition
issuer
Definition
exchange of crypto-assets for other crypto-assets
Definition
electronic money token
Definition
providing custody and administration of crypto-assets on behalf of clients
Definition
providing transfer services for crypto-assets on behalf of clients
Definition
distributed ledger technology
Definition
competent authority
- designated by each Member State in accordance with Article 93 concerning offerors, persons seeking admission to trading of crypto-assets other than asset-referenced tokens and e-money tokens, issuers of asset-referenced tokens, or crypto-asset service providers;
- designated by each Member State for the application of Directive 2009/110/EC concerning issuers of e-money tokens;
Footnote 8