Commission Delegated Regulation (EU) 2025/303 of 31 October 2024 supplementing Regulation (EU) 2023/1114
as it stood on 2024-10-31, permalink: /eu-eurlex/32025r0303/2024-10-31
Article 1
- For the purposes of Article 60(7), point (a), of Regulation (EU) 2023/1114, the notifying entity shall provide to the competent authority the programme of operations for the 3 years following the date of notification, including the following information:
| (a) | where the notifying entity belongs to a group as defined in Article 2, point (11), of Directive 2013/34/EU of the European Parliament and of the Council (6), an explanation of how the activities of the notifying entity fit within that group strategy and interact with the activities of the other entities of that group, including an overview of the current and planned organisation and structure of that group; |
|---|
| (b) | an explanation of how the activities of the entities affiliated with the notifying entity, including where there are regulated entities in the group, is expected to impact the activities of the notifying entity, including a list of and information on the entities affiliated with the notifying entity, and where there are regulated entities, the services provided by these entities and the domain names of each website operated by such entities; |
|---|
| (c) | a list of crypto-asset services that the notifying entity intends to provide and the types of crypto-assets to which the crypto-asset services will relate; |
|---|
| (d) | other planned activities, regulated in accordance with Union or national law or unregulated, including any other services than crypto-asset services, that the notifying entity intends to provide; |
|---|
| (e) | whether the notifying entity intends to offer crypto-assets to the public or seeks admission to trading of crypto-assets and if so, what type of crypto-assets; |
|---|
| (f) | a list of jurisdictions, both in the Union and in third countries, in which the notifying entity plans to provide crypto-asset services, including information on the targeted number of clients by geographical area; |
|---|
| (g) | types of prospective clients targeted by the notifying entitity’s crypto-asset services; |
|---|
| (h) | a description of the means of access to the notifying entity’s crypto-asset services by clients, including all of the following:(i)the domain names for each website or other ICT-based application through which the crypto-asset services will be provided by the notifying entity and information on the languages in which the website or other ICT-based application will be available, the types of crypto-asset services that will be accessed through that website or other ICT-based application and, where applicable, from which Member States the website or other ICT-based application will be accessible;(ii)the name of any ICT-based application available to clients to access the crypto-asset services, the languages in which that ICT-based application is available and the crypto-asset services which can be accessed through that ICT-based application; |
|---|---|
| (i) | the domain names for each website or other ICT-based application through which the crypto-asset services will be provided by the notifying entity and information on the languages in which the website or other ICT-based application will be available, the types of crypto-asset services that will be accessed through that website or other ICT-based application and, where applicable, from which Member States the website or other ICT-based application will be accessible; |
| (ii) | the name of any ICT-based application available to clients to access the crypto-asset services, the languages in which that ICT-based application is available and the crypto-asset services which can be accessed through that ICT-based application; |
| (i) | the planned marketing and promotional activities and arrangements for the crypto-asset services, including the following:(i)all means of marketing to be used for each of the services;(ii)the intended means of identification of the notifying entity;(iii)information on the relevant category of clients targeted;(iv)types of crypto-assets;(v)languages that will be used for the marketing and promotional activities; |
|---|---|
| (i) | all means of marketing to be used for each of the services; |
| (ii) | the intended means of identification of the notifying entity; |
| (iii) | information on the relevant category of clients targeted; |
| (iv) | types of crypto-assets; |
| (v) | languages that will be used for the marketing and promotional activities; |
| (j) | a detailed description of the human, financial and ICT resources allocated to the intended crypto-asset services, and their geographical location; |
|---|
| (k) | the notifying entity’s outsourcing policy and how it was adapted to crypto-asset services as well as a detailed description of the notifying entity’s planned outsourcing arrangements, including intra-group arrangements, and the way that the notifying entity will comply with Article 73 of Regulation (EU) 2023/1114, including information on the function or person responsible for outsourcing, the human and ICT resources allocated to the control of the outsourced functions, services or activities of the related arrangements and on the risk assessment related to the outsourcing; |
|---|
| (l) | the list of entities that will provide outsourced services for the provision of crypto-asset services, their geographical location and the relevant services outsourced; |
|---|
| (m) | a forecast accounting plan including stress scenarios at an individual and, where applicable, at a consolidated group and sub-consolidated level in accordance with Directive 2013/34/EU, taking into consideration any intra-group loans granted or to be granted by and to the notifying entity; |
|---|
| (n) | any exchange of crypto-assets for funds and other crypto-asset activities that the notifying entity intends to undertake, including through any decentralised finance applications with which the notifying entity intends to interact on its own account. |
|---|
Where the notifying entity intends to provide the service of reception and transmission of orders for crypto-assets on behalf of clients, it shall provide to the competent authority a copy of the procedures and a description of the arrangements ensuring compliance with Article 80 of Regulation (EU) 2023/1114.
Where the notifying entity intends to provide the service of placing of crypto-assets, it shall provide to the competent authority a copy of procedures to identify, prevent, manage and disclose conflicts of interests and a description of the arrangements in place to comply with Article 79 of Regulation (EU) 2023/1114 and Commission Delegated Regulation establishing technical standards adopted pursuant to Article 72(5) of Regulation (EU) 2023/1114.
Article 2
For the purposes of Article 60(7), point (b) (iii), of Regulation (EU) 2023/1114, the notifying entity shall submit to the competent authority a detailed description of its business continuity plan, including the steps to be taken to ensure continuity and regularity in the provision of its crypto-asset services.
The description referred to in paragraph 1 shall include the following:
| (a) | details showing that the established business continuity plan is appropriate and that arrangements are set up to maintain and periodically test that plan; |
|---|
| (b) | with regard to critical or important functions supported by third-party service providers, details on how business continuity is ensured in the event that the quality of the provision of such functions deteriorates to an unacceptable level or fails; |
|---|
| (c) | information on how business continuity is ensured in the event of the death of a key person and, where relevant, political risks in the service provider’s jurisdictions. |
|---|
Article 3
For the purposes of Article 60(7), point (b)(i) and (ii), of Regulation (EU) 2023/1114, the notifying entity shall provide the competent authority with information on its internal control mechanisms, policies and procedures to ensure compliance with the provisions of national law transposing Directive (EU) 2015/849 and on the risk assessment framework to manage risks relating to money laundering and terrorist financing, including the following:
| (a) | the notifying entity’s assessment of the inherent and residual risks of money laundering and terrorist financing associated with its provision of crypto-asset services, including the risks relating to:(i)the notifying entity’s customer base;(ii)the services provided;(iii)the distribution channels used;(iv)the geographical areas of operation; |
|---|---|
| (i) | the notifying entity’s customer base; |
| (ii) | the services provided; |
| (iii) | the distribution channels used; |
| (iv) | the geographical areas of operation; |
| (b) | the measures that the notifying entity has or will put in place to prevent the identified risks and comply with applicable anti-money laundering and counter-terrorist financing requirements, including the notifying entity’s risk assessment process, the policies and procedures to comply with customer due diligence requirements, and the policies and procedures to detect and report suspicious transactions or activities; |
|---|
| (c) | detailed information on how internal control mechanisms, policies and procedures are adequate and proportionate to the scale, nature, inherent risk of money laundering and terrorist financing, including the range of crypto-asset services provided, the complexity of the business model and how the notifying entity ensures its compliance with Directive (EU) 2015/849 and Regulation (EU) 2023/1113 of the European Parliament and of the Council (7); |
|---|
| (d) | the identity of the person in charge of ensuring the notifying entity’s compliance with anti-money laundering and counter-terrorist financing requirements, including evidence of that person’s skills and expertise; |
|---|
| (e) | arrangements, human and financial resources devoted to ensure, based on annual indications, that staff of the notifying entity is appropriately trained in anti-money laundering and counter-terrorist financing matters and on specific crypto-asset related risks; |
|---|
| (f) | a copy of the notifying entity’s anti-money laundering and counter-terrorism policies, procedures and systems; |
|---|
| (g) | a summary document outlining changes that have been made to the notifying entity’s anti-money laundering and counter-terrorism procedures and systems as a consequence of the planned crypto-asset services; |
|---|
| (h) | the frequency of the assessment of the adequacy and effectiveness of the internal control mechanisms, systems and procedures, including the identity of the person or function responsible for such assessment. |
|---|
Article 4
For the purposes of Article 60(7), point (c), of Regulation (EU) 2023/1114, the notifying entity shall provide the competent authority the following information:
| (a) | technical documentation of the ICT systems, DLT infrastructure relied upon, where relevant, and the security arrangements, including a description of the arrangements and deployed ICT and human resources established to comply with Regulation (EU) 2022/2554 of the European Parliament and of the Council (8) including the following:(i)a description of how the notifying entity ensures a sound, comprehensive and well-documented ICT risk management framework as part of its overall risk management system, including a detailed description of ICT systems, protocols and tools and of how the notifying entity’s procedures, policies and systems will safeguard the security, integrity, availability, authenticity and confidentiality of data in accordance with Regulations (EU) 2022/2554 and (EU) 2016/679;(ii)an identification of ICT services supporting critical or important functions, developed or maintained by the notifying entity, as well as those provided by third-party service providers, a description of such contractual arrangements and how those arrangements comply with Article 73 of Regulation (EU) 2023/1114 and Chapter V of Regulation (EU) 2022/2554;(iii)a description of the notifying entity’s procedures, policies, arrangements and systems for security and incident management; |
|---|---|
| (i) | a description of how the notifying entity ensures a sound, comprehensive and well-documented ICT risk management framework as part of its overall risk management system, including a detailed description of ICT systems, protocols and tools and of how the notifying entity’s procedures, policies and systems will safeguard the security, integrity, availability, authenticity and confidentiality of data in accordance with Regulations (EU) 2022/2554 and (EU) 2016/679; |
| (ii) | an identification of ICT services supporting critical or important functions, developed or maintained by the notifying entity, as well as those provided by third-party service providers, a description of such contractual arrangements and how those arrangements comply with Article 73 of Regulation (EU) 2023/1114 and Chapter V of Regulation (EU) 2022/2554; |
| (iii) | a description of the notifying entity’s procedures, policies, arrangements and systems for security and incident management; |
| (b) | if available, a description of a cybersecurity audit conducted by a third-party cybersecurity auditor having sufficient experience in accordance with Commission Delegated Regulation establishing technical standards pursuant to Article 26(11) fourth subparagraph of Regulation (EU) 2022/2554 covering ideally the following audits or tests by external independent parties:(i)organisational cybersecurity, physical security and secure software development lifecycle arrangements;(ii)vulnerability assessments and network security assessments;(iii)configuration reviews of ICT assets supporting critical and important functions as defined in Article 3, point (22) of Regulation (EU) 2022/2554;(iv)penetration tests on the ICT assets supporting critical and important functions as defined in Article 3, point (17) of Regulation (EU) 2022/2554, in accordance with all the following audit test approaches:(1)black box: the auditor has no information other than the IP addresses and URLs associated with the audited target. This phase is generally preceded by the discovery of information and the identification of the target by querying domain name system (DNS) services, scanning open ports, discovering the presence of filtering equipment;(2)grey box phase: auditors have the knowledge of a standard user of the information system (legitimate authentication, ‘standard’ workstation). The identifiers can belong to different user profiles in order to test different privilege levels;(3)white box phase: auditors have as much technical information as possible (architecture, source code, telephone contacts, identifiers, etc.) before starting the analysis and also access to technical contacts related to the target;(v)where the notifying entity uses and/or develops smart-contracts, a cybersecurity source code review of them; |
|---|---|
| (i) | organisational cybersecurity, physical security and secure software development lifecycle arrangements; |
| (ii) | vulnerability assessments and network security assessments; |
| (iii) | configuration reviews of ICT assets supporting critical and important functions as defined in Article 3, point (22) of Regulation (EU) 2022/2554; |
| (iv) | penetration tests on the ICT assets supporting critical and important functions as defined in Article 3, point (17) of Regulation (EU) 2022/2554, in accordance with all the following audit test approaches:(1)black box: the auditor has no information other than the IP addresses and URLs associated with the audited target. This phase is generally preceded by the discovery of information and the identification of the target by querying domain name system (DNS) services, scanning open ports, discovering the presence of filtering equipment;(2)grey box phase: auditors have the knowledge of a standard user of the information system (legitimate authentication, ‘standard’ workstation). The identifiers can belong to different user profiles in order to test different privilege levels;(3)white box phase: auditors have as much technical information as possible (architecture, source code, telephone contacts, identifiers, etc.) before starting the analysis and also access to technical contacts related to the target; |
| (1) | black box: the auditor has no information other than the IP addresses and URLs associated with the audited target. This phase is generally preceded by the discovery of information and the identification of the target by querying domain name system (DNS) services, scanning open ports, discovering the presence of filtering equipment; |
| (2) | grey box phase: auditors have the knowledge of a standard user of the information system (legitimate authentication, ‘standard’ workstation). The identifiers can belong to different user profiles in order to test different privilege levels; |
| (3) | white box phase: auditors have as much technical information as possible (architecture, source code, telephone contacts, identifiers, etc.) before starting the analysis and also access to technical contacts related to the target; |
| (v) | where the notifying entity uses and/or develops smart-contracts, a cybersecurity source code review of them; |
| (c) | a description of conducted audits of the ICT systems, if any, including used DLT infrastructure and security arrangements; |
|---|
| (d) | a description of the relevant information referred to in points (a) and (b) in non-technical language. |
|---|
Article 5
- For the purposes of Article 60(7), point (d), of Regulation (EU) 2023/1114, the notifying entity that intends to hold crypto-assets belonging to clients or the means of access to such crypto-assets, or clients’ funds other than e-money tokens, shall provide to the competent authority a detailed description of its procedures for the segregation of clients’ crypto-assets and funds, including the following:
| (a) | how the notifying entity ensures the following:(i)clients’ funds are not used for its own account;(ii)crypto-assets belonging to the clients are not used for its own account;(iii)the wallets holding clients’ crypto-assets are different from the notifying entity’s own wallets; |
|---|---|
| (i) | clients’ funds are not used for its own account; |
| (ii) | crypto-assets belonging to the clients are not used for its own account; |
| (iii) | the wallets holding clients’ crypto-assets are different from the notifying entity’s own wallets; |
| (b) | a detailed description of the approval system for cryptographic keys and safeguarding of cryptographic keys including multi-signature wallets; |
|---|
| (c) | how the notifying entity segregates clients’ crypto-assets, including from other clients’ crypto-assets where wallets containing crypto-assets of more than one client, are kept in omnibus accounts; |
|---|
| (d) | a description of the procedure ensuring that clients’ funds other than e-money tokens are deposited with a central bank or a credit institution by the end of the business day following the day on which they were received and are held in an account separately identifiable from any accounts used to hold funds belonging to the notifying entity; |
|---|
| (e) | where the notifying entity does not intend to deposit funds with the relevant central bank, which factors the notifying entity takes into account to select the credit institutions with which to deposit clients’ funds, including the notifying entity’s diversification policy, where available, and the frequency of review of the selection of credit institutions with which to deposit clients’ funds; |
|---|
| (f) | how the notifying entity ensures that clients are informed in clear, concise and non-technical language about the key aspects of the notifying entity’s systems, policies and procedures to comply with Article 70(1), (2) and (3) of Regulation (EU) 2023/1114. |
|---|
- In accordance with Article 70(5) of Regulation (EU) 2023/1114, crypto-asset service providers that are electronic money institutions or credit institutions shall only provide the information set out in paragraph 1 of this Article.
Article 6
For the purposes of Article 60(7), point (e), of Regulation (EU) 2023/1114, the notifying entity shall provide to the competent authority the following information:
| (a) | a description of the arrangements linked to the type of custody offered to clients, a copy of the notifying entity’s standard agreement for the custody and administration of crypto-assets on behalf of clients pursuant to Article 75(1) of Regulation (EU) 2023/1114 and a copy of the summary of the custody policy made available to clients in accordance with Article 75(3) third subparagraph of that Regulation; |
|---|
| (b) | the notifying entity’s custody and administration policy, including a description of identified sources of operational and ICT risks for the safekeeping and control of the crypto-assets or the means of access to the crypto-assets of clients, together with the following:(i)the policies and procedures, and a description of the arrangements to comply with Article 75(8) of Regulation (EU) 2023/1114;(ii)the policies and procedures, and a description of the systems and controls, to manage the operational and ICT risks, including where the custody and administration of crypto-assets on behalf of clients is outsourced to a third party;(iii)the policies and procedures relating to, and a description of, the systems to ensure the exercise of the rights attached to the crypto-assets by the clients;(iv)the policies and procedures relatig to, and a description of, the systems ensuring the return of crypto-assets or the means of access to the clients; |
|---|---|
| (i) | the policies and procedures, and a description of the arrangements to comply with Article 75(8) of Regulation (EU) 2023/1114; |
| (ii) | the policies and procedures, and a description of the systems and controls, to manage the operational and ICT risks, including where the custody and administration of crypto-assets on behalf of clients is outsourced to a third party; |
| (iii) | the policies and procedures relating to, and a description of, the systems to ensure the exercise of the rights attached to the crypto-assets by the clients; |
| (iv) | the policies and procedures relatig to, and a description of, the systems ensuring the return of crypto-assets or the means of access to the clients; |
| (c) | information on how the crypto-assets and the means of access to the crypto-assets of the clients are identified; |
|---|
| (d) | information on arrangements to minimise the risk of loss of crypto-assets or means of access to crypto-assets; |
|---|
| (e) | where the crypto-asset service provider has delegated the provision of custody and administration of crypto-assets on behalf of clients to a third-party:(i)information on the identity of any third-party providing the service of custody and administration of crypto-assets and its status in accordance with Article 59 or Article 60 of Regulation (EU) 2023/1114;(ii)a description of any functions relating to the custody and administration of crypto-assets delegated by the crypto-asset service provider, the list of any delegates and sub-delegates, as applicable, and any conflict of interest that could arise from such a delegation;(iii)a description of how the notifying entity intends to supervise the delegations or sub-delegations. |
|---|---|
| (i) | information on the identity of any third-party providing the service of custody and administration of crypto-assets and its status in accordance with Article 59 or Article 60 of Regulation (EU) 2023/1114; |
| (ii) | a description of any functions relating to the custody and administration of crypto-assets delegated by the crypto-asset service provider, the list of any delegates and sub-delegates, as applicable, and any conflict of interest that could arise from such a delegation; |
| (iii) | a description of how the notifying entity intends to supervise the delegations or sub-delegations. |
Article 7
- For the purposes of Article 60(7), point (f), of Regulation (EU) 2023/1114, the notifying entity that intends to operate a trading platform for crypto-assets shall provide to the competent authority the following information:
| (a) | the rules on the admission of crypto-assets to trading; |
|---|
| (b) | the approval process for admitting crypto-assets to trading, including the customer due diligence carried out in accordance with Directive (EU) 2015/849; |
|---|
| (c) | the list of any categories of crypto-assets that will not be admitted to trading and the reasons for such exclusion; |
|---|
| (d) | the policies, procedures and fees for the admission to trading, together with a description, where relevant, of membership, rebates and the related conditions; |
|---|
| (e) | the rules governing order execution, including any cancellation procedures for executed orders and for disclosing such information to market participants; |
|---|
| (f) | the methods put in place to assess the suitability of crypto-assets in accordance with Article 76(2) of Regulation (EU) 2023/1114; |
|---|
| (g) | the systems, procedures and arrangements put in place to comply with Article 76(7) of Regulation (EU) 2023/1114; |
|---|
| (h) | the manner of making public any bid and ask prices, the depth of trading interests at those prices that are advertised for crypto-assets through their trading platform and price, volume and time of transactions executed in respect of crypto-assets traded on their trading platform, in accordance with Article 76(9) and (10) of Regulation (EU) 2023/1114; |
|---|
| (i) | the fee structures and a justification on how those structures comply with Article 76(13) of Regulation (EU) 2023/1114; |
|---|
| (j) | the systems, procedures and arrangements put in place to keep data relating to all orders at the disposal of the competent authority or the mechanism to ensure that the competent authority has access to the order book and any other trading system; |
|---|
| (k) | with regards to the settlement of transactions:(i)whether the final settlement of transactions is initiated on the distributed ledger or outside the distributed ledger;(ii)the timeframe within which the final settlement of crypto-asset transactions is initiated;(iii)the way to verify the availability of funds and crypto-assets;(iv)the way to confirm the relevant details of transactions;(v)the measures foreseen to limit settlement fails;(vi)the moment at which settlement is final and the moment at which final settlement is initiated following the execution of the transaction; |
|---|---|
| (i) | whether the final settlement of transactions is initiated on the distributed ledger or outside the distributed ledger; |
| (ii) | the timeframe within which the final settlement of crypto-asset transactions is initiated; |
| (iii) | the way to verify the availability of funds and crypto-assets; |
| (iv) | the way to confirm the relevant details of transactions; |
| (v) | the measures foreseen to limit settlement fails; |
| (vi) | the moment at which settlement is final and the moment at which final settlement is initiated following the execution of the transaction; |
| (l) | the procedures and systems put in place to detect and prevent market abuse, including information on the communications to the competent authority of possible market abuse cases. |
|---|
- Notifying entities intending to operate a trading platform for crypto-assets shall provide to the competent authority a copy of the operating rules of the trading platform and of any procedures to detect and prevent market abuse.
Article 8
For the purposes of Article 60(7), point (g), of Regulation (EU) 2023/1114, the notifying entity that intends to exchange crypto-assets for funds or other crypto-assets shall provide to the competent authority the following information:
| (a) | a description of the commercial policy established in accordance with Article 77(1) of Regulation (EU) 2023/1114; |
|---|
| (b) | the method for determining the price of the crypto-assets that the notifying entity proposes to exchange for funds or other crypto-assets in accordance with Article 77(2) of Regulation (EU) 2023/1114, including how the volume and market volatility of crypto-assets impact the pricing mechanism. |
|---|
Article 9
For the purposes of Article 60(7), point (h), of Regulation (EU) 2023/1114, the notifying entity that intends to execute orders for crypto-assets on behalf of clients shall provide to the competent authority its execution policy, including the following information:
| (a) | the arrangements ensuring that the client has provided consent on the execution policy prior to the execution of the order; |
|---|
| (b) | a list of the trading platforms for crypto-assets on which the notifying entity will rely for the execution of orders and the criteria for the assessment of execution venues included in the execution policy in accordance with Article 78(6) of Regulation (EU) 2023/1114; |
|---|
| (c) | which trading platforms the notifying entity intends to use for each type of crypto-assets and confirmation that the notifying entity will not receive any form of remuneration, discount or non-monetary benefit in return for routing orders received to a particular trading platform for crypto-assets; |
|---|
| (d) | how the execution takes into accout price, costs, speed, likelihood of execution and settlement, size, nature, conditions of custody of the crypto-assets or any other relevant factors that are considered as part of all necessary steps to obtain the best possible result for the client; |
|---|
| (e) | where applicable, the arrangements for informing clients that the notifying entity will execute orders outside a trading platform and how the notifying entity will obtain the prior express consent of its client before executing such orders; |
|---|
| (f) | how the client is being warned that any specific instructions from a client may prevent the notifying entity from taking the necessary steps, in line with the arrangements that the notifying entity has established and implemented in its execution policy, to obtain the best possible result for the execution of those orders in respect of the elements covered by those instructions; |
|---|
| (g) | the selection process for trading venues, execution strategies employed, the arrangements used to analyse the quality of execution obtained and how the notifying entity monitors and verifies that the best possible results were obtained for clients; |
|---|
| (h) | the arrangements to prevent the misuse of any information relating to clients’ orders by the employees of the notifying entity; |
|---|
| (i) | the arrangements and procedures for how the notifying entity will disclose to clients information on its order execution policy and notify them of any material changes to their order execution policy; |
|---|
| (j) | the arrangements to demonstrate compliance with Article 78 of Regulation (EU) 2023/1114 to the competent authority, upon the request of that competent authority. |
|---|
Article 10
For the purposes of Article 60(7), point (i), of Regulation (EU) 2023/1114, the notifying entity that intends to provide advice on crypto-assets or portfolio management of crypto-assets shall provide to the competent authority the following information:
| (a) | a detailed description of the arrangements put in place by the notifying entity to ensure compliance with Article 81(7) of Regulation (EU) 2023/1114, including the following:(i)the mechanisms to control, assess and maintain effectively the knowledge and expertise of the natural persons providing advice on crypto-assets or managing portfolios of crypto-assets;(ii)the arrangements ensuring that natural persons involved in the provision of advice or portfolio management are aware of, understand and apply the notifying entity’s internal policies and procedures established to comply with Regulation (EU) 2023/1114, in particular with Article 81(1) of that Regulation and with Directive (EU) 2015/849;(iii)the amount of human and financial resources planned to be devoted on a yearly basis by the notifying entity to the professional development and training of the staff providing advice on crypto-assets or managing portfolios of crypto-assets; |
|---|---|
| (i) | the mechanisms to control, assess and maintain effectively the knowledge and expertise of the natural persons providing advice on crypto-assets or managing portfolios of crypto-assets; |
| (ii) | the arrangements ensuring that natural persons involved in the provision of advice or portfolio management are aware of, understand and apply the notifying entity’s internal policies and procedures established to comply with Regulation (EU) 2023/1114, in particular with Article 81(1) of that Regulation and with Directive (EU) 2015/849; |
| (iii) | the amount of human and financial resources planned to be devoted on a yearly basis by the notifying entity to the professional development and training of the staff providing advice on crypto-assets or managing portfolios of crypto-assets; |
| (b) | the mechanisms to control, assess and maintain that the natural persons giving advice on behalf of the notifying entity have the necessary knowledge and expertise, according to the critera for such assessment used in national legislation, to assess the suitability as referred to in Article 81(1) of Regulation (EU) 2023/1114. |
|---|
Article 11
For the purposes of Article 60(7), point (k), of Regulation (EU) 2023/1114, the notifying entity that intends to provide transfer services for crypto-assets on behalf of clients shall provide to the competent authority the following information:
| (a) | details on the types of crypto-assets for which the notifying entity intends to provide transfer services; |
|---|
| (b) | a detailed description of the arrangements put in place by the notifying entity to comply with Article 82 of Regulation (EU) 2023/1114, including detailed information on the notifying entity’s arrangements and deployed ICT and human resources to address risks promptly, efficiently and thoroughly during the provision of transfer services for crypto-assets on behalf of clients, taking into account potential operational failures and cybersecurity risks; |
|---|
| (c) | where available, a description of the notifying entity’s insurance policy, including on the insurance’s coverage of detriment to client’s crypto-assets that may result from cyber security risks; |
|---|
| (d) | arrangements to ensure that clients are adequately informed about the arrangements referred to in point (b). |
|---|
Article 12
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
Provenance and validity dates, identifier, hash
| as of | 2024-10-31 → this version applied |
| valid | 2024-10-31 → open publisher-asserted |
| type | REG_DEL Commission Delegated Regulation (EU) 2025/303 of 31 October 2024 supplementing Regulation (EU) 2023/1114 of the European Parliament and of the Council with regard to regulatory technical standards specifying the information to be included by certain financial entities in the notification of their intention to provide crypto-asset services |
| language | en |
| published | 2024-10-31 |
| lex_id | eu-eurlex:32025r0303:2024-10-31 |
| record sha256 | 9c890423f0d630492cbaa0b69e5e31974492f151518d1c6ae3111bf4e99a1d18 |
New here? What am I looking at?
This is a consolidated text: the original law with every later amendment merged in, as the official publisher produced it for a given date. Laws are amended constantly, so “the law” has no single text, only a text per date. That date is the banner above.
It has no legal force. Only the version published in the official gazette (Mémorial / Official Journal) is authentic, the publishers say so themselves, and so do we. Lex reproduces their text without altering a byte, and links the source on every page. This is legal information, never legal advice: it reports what the text said, never what it means for your situation.
“Valid from → to” = the window in which this text applied. “Open” = still current as far as the publisher has consolidated. Each article carries its own hash so you can prove it was not tampered with , here is how.
timeline next version (2024-10-31) →
| tier | A, publisher-supplied validity dates |
| history begins | publisher |
| index built | 2026-08-07T19:46:23Z · corpus 8d5e859 |
| stamp signature | valid (ECDSA-P256) |