Commission Delegated Regulation (EU) 2025/299 of 31 October 2024 supplementing Regulation (EU) 2023/1114
as it stood on 2024-10-31, permalink: /eu-eurlex/32025r0299/2024-10-31
Article 1
For the purposes of this Regulation, the following definitions shall apply:
| (a) | ‘critical or important function’ means a critical or important function as defined in Article 3, point (22), of Regulation (EU) 2022/2554; |
|---|
| (b) | ‘permissionless distributed ledger’ means a specific type of distributed ledger in which no entity controls the distributed ledger and DLT network nodes can be set up by any person complying with the technical requirements and the protocols of that distributed ledger. |
|---|
Article 2
The business continuity policy referred to in Article 68(7) of Regulation (EU) 2023/1114 shall be comprised of plans, procedures and measures.
The management body of crypto-asset service providers, in the exercise of its functions referred to in Article 68(6) of Regulation (EU) 2023/1114, shall establish and endorse the plans, procedures, and measures that comprise the business continuity policy. The crypto-asset service provider’s management body shall be responsible for the implementation of the business continuity policy, and for reviewing its effectiveness at least on an annual basis.
Crypto-asset service providers shall ensure that any modifications to the business continuity policy are transmitted to all relevant internal staff through effective communication channels.
Article 3
The business continuity policy referred to in Article 68(7) of Regulation (EU) 2023/1114 shall ensure that crypto-asset service providers properly address disruptive incidents or performance issues relating to the systems critical to the operation of their business functions and it shall be laid down in a durable medium.
Crypto-asset service providers shall include in the business continuity policy all of the following:
| (a) | a specification of the scope of the business continuity policy, including its limitations and exclusions, to be covered by the business continuity plans, procedures, and measures; |
|---|
| (b) | a description of the criteria to activate the business continuity plans, including escalation procedures up to the level of the management body; |
|---|
| (c) | provisions on the governance and organisation of the crypto-asset service provider, including, the roles and responsibilities of the staff, ensuring that sufficient resources are available for the effective implementation of the policy; |
|---|
| (d) | provisions that ensure consistency between the business continuity plans and the ICT-business continuity plans, and ICT response and recovery plans referred to in Articles 24 and 26 of Delegated Regulation (EU) 2024/1774. |
|---|
Article 4
- When implementing the business continuity policy referred to in Article 68(7) of Regulation (EU) 2023/1114, crypto-asset service providers shall establish business continuity plans. The business continuity plans shall set out the procedures necessary to protect and, where necessary, re-establish:
| (a) | the confidentiality, integrity, and availability of client data; |
|---|
| (b) | the availability of the business functions, supporting processes and information assets of the crypto-asset service providers. |
|---|
- The business continuity plans shall contain the following:
| (a) | a range of possible adverse scenarios relating to the operation of critical or important functions, including the unavailability of business functions, staff, workspace, external suppliers, data centres, or loss or alteration of critical data and documents; |
|---|
| (b) | the procedures and policies to be followed in case of a disruptive incident, including:(i)the measures that are necessary to recover critical or important functions;(ii)the deadlines by which those critical or important functions are to be recovered;(iii)recovery point objectives;(iv)the maximum time to resume services; |
|---|---|
| (i) | the measures that are necessary to recover critical or important functions; |
| (ii) | the deadlines by which those critical or important functions are to be recovered; |
| (iii) | recovery point objectives; |
| (iv) | the maximum time to resume services; |
| (c) | the procedures and policies for relocating the business functions used to provide crypto-asset services to a back-up site; |
|---|
| (d) | back-up of critical business data, including up-to-date information of the necessary contacts to ensure communication inside the crypto-asset service provider, between the crypto-asset service provider and its clients; |
|---|
| (e) | procedures for timely communications with clients and other external stakeholders, including competent authorities. |
|---|
- In the event of a disruption involving a permissionless distributed ledger used by the crypto asset service provider in the provision of its services, the communications referred to in paragraph 2, point (e) shall include the following information:
| (a) | when the services are expected to be resumed; |
|---|
| (b) | the reasons and the impact of the disruptive incident; |
|---|
| (c) | any risks concerning clients’ funds and crypto-assets held on their behalf; |
|---|
| (d) | measures that the crypto-asset service intends to take in response to the disruption of a permissionless distributed ledger. |
|---|
Where that information is not readily available to the crypto-asset service provider, the crypto-asset service provider shall communicate updates as regards the information in the first subparagraph to clients and stakeholders, including competent authorities, on a best effort basis.
- The business continuity plans shall contain procedures to address any disruptions of outsourced critical or important functions, including where those critical or important functions become unavailable.
Article 5
Crypto-asset service providers shall test the operation of the business continuity plans referred to in Article 4 on the basis of realistic scenarios. Such testing shall verify the capability of the crypto-asset service provider to recover from disruptive incidents and to resume services in accordance with Article 4(2), point (b).
Crypto-asset service providers shall test the business continuity plans annually taking into account:
| (a) | the results of the tests referred to in paragraph 1; |
|---|
| (b) | the most recent threat intelligence; |
|---|
| (c) | lessons derived from previous events; |
|---|
| (d) | where relevant, any changes in the recovery objectives, including recovery time objectives and recovery point objectives as referred to in Article 4(2), point (b); |
|---|
| (e) | changes in the business functions. |
|---|
Crypto-asset service providers shall document the results of the testing activity in writing, and submit them to their management body and to the operating units involved in the business continuity plans.
Crypto-asset service providers shall ensure that the testing of the business continuity plans does not interfere with normal conduct of their services.
Article 6
- When establishing the business continuity policy, including the plans, procedures and measures, crypto-asset service providers shall take into account elements of increased complexity or risk, including:
| (a) | the type and range of crypto-asset services offered; |
|---|
| (b) | the extent to which the services of the crypto-asset service provider rely on permissionless distributed ledger; |
|---|
| (c) | the potential impact of any disruptions on the continuity of the crypto-asset service provider’s activities and availability of its services. |
|---|
- For the purposes of paragraph 1, crypto-asset service providers shall conduct a self-assessment of the scale, the nature, and range of their services annually. Crypto-asset service providers shall base that self-assessment on the criteria set out in the Annex and any other criteria that the crypto-asset service provider considers relevant.
Article 7
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
Provenance and validity dates, identifier, hash
| as of | 2024-10-31 → this version applied |
| valid | 2024-10-31 → open publisher-asserted |
| type | REG_DEL Commission Delegated Regulation (EU) 2025/299 of 31 October 2024 supplementing Regulation (EU) 2023/1114 of the European Parliament and of the Council on markets in crypto-assets with regard to regulatory technical standards on continuity and regularity in the performance of crypto-asset services |
| language | en |
| published | 2024-10-31 |
| lex_id | eu-eurlex:32025r0299:2024-10-31 |
| record sha256 | ea723c30a6b45d001bb6c3b2017744e04cd9f60a8a66edeed6cf4e5c8b12b8ab |
New here? What am I looking at?
This is a consolidated text: the original law with every later amendment merged in, as the official publisher produced it for a given date. Laws are amended constantly, so “the law” has no single text, only a text per date. That date is the banner above.
It has no legal force. Only the version published in the official gazette (Mémorial / Official Journal) is authentic, the publishers say so themselves, and so do we. Lex reproduces their text without altering a byte, and links the source on every page. This is legal information, never legal advice: it reports what the text said, never what it means for your situation.
“Valid from → to” = the window in which this text applied. “Open” = still current as far as the publisher has consolidated. Each article carries its own hash so you can prove it was not tampered with , here is how.
timeline next version (2024-10-31) →
| tier | A, publisher-supplied validity dates |
| history begins | publisher |
| index built | 2026-08-07T19:46:23Z · corpus 8d5e859 |
| stamp signature | valid (ECDSA-P256) |