Source: OJ L, 2025/299, 13.2.2025

Current language: EN

Article 2 Business continuity organisational arrangements


Summary What does Article 2 of the RTS on continuity and regularity say?

This article establishes the governance and ownership requirements for the business continuity policy that crypto-asset service providers must maintain under Regulation (EU) 2023/1114.

It places clear and direct accountability on the management body of the crypto-asset service provider, making it responsible not only for establishing and endorsing the policy but also for its ongoing implementation and effectiveness.

The article also addresses the internal dissemination of any changes to the policy.

Important points:

  • Ensure your business continuity policy is comprised of plans, procedures, and measures, as established and endorsed by the management body.
  • The management body is responsible for implementing the policy and reviewing its effectiveness at least on an annual basis.
  • Transmit any modifications to the business continuity policy to all relevant internal staff through effective communication channels.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. The business continuity policy referred to in Article 68(7) of Regulation (EU) 2023/1114 shall be comprised of plans, procedures and measures.

    1. The management body of crypto-asset service providers, in the exercise of its functions referred to in Article 68(6) of Regulation (EU) 2023/1114, shall establish and endorse the plans, procedures, and measures that comprise the business continuity policy. The crypto-asset service provider’s management body shall be responsible for the implementation of the business continuity policy, and for reviewing its effectiveness at least on an annual basis.

    1. Crypto-asset service providers shall ensure that any modifications to the business continuity policy are transmitted to all relevant internal staff through effective communication channels.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod