Source: OJ L, 2025/299, 13.2.2025

Current language: FR

Article 6 Complexité et considérations de risque


Summary What does Article 6 of the RTS on continuity and regularity say?

This article acts as a calibration mechanism for the business continuity policy requirements set out in earlier articles.

It requires crypto-asset service providers to tailor their business continuity policy to their own risk profile, taking into account factors that could increase complexity or risk.

Crucially, it also mandates an annual self-assessment to ensure this calibration remains current and reflective of the provider's actual operations.

Important points:

  • Factor in elements of increased complexity or risk — including the types of services offered, reliance on permissionless distributed ledgers, and the potential impact of disruptions — when building your business continuity policy.
  • Conduct an annual self-assessment of the scale, nature, and range of your services, using the criteria in the Annex as a baseline alongside any other criteria you consider relevant.
  • The self-assessment feeds directly into how the business continuity policy is shaped, making it an ongoing obligation rather than a one-time exercise.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. Lorsqu’ils établissent la politique de continuité des activités, y compris les plans, procédures et mesures, les prestataires de services sur crypto-actifs tiennent compte de facteurs de complexité ou de risque accrus, notamment:

      1. le type et l’éventail des services sur crypto-actifs proposés;

      2. la mesure dans laquelle les services du prestataire de services sur crypto-actifs reposent sur un registre distribué sans permission;

      3. l’incidence potentielle de toute perturbation sur la continuité des activités du prestataire de services sur crypto-actifs et la disponibilité de ses services.

    1. Aux fins du paragraphe 1, les prestataires de services sur crypto-actifs procèdent chaque année à une autoévaluation de l’ampleur, de la nature et de l’éventail de leurs services. Les prestataires de services sur crypto-actifs fondent cette autoévaluation sur les critères énoncés à l’annexe et sur tout autre critère qu’ils jugent pertinent.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod