Commission Delegated Regulation (EU) 2025/885 of 29 April 2025 supplementing Regulation (EU) 2023/1114
as it stood on 2025-04-29, permalink: /eu-eurlex/32025r0885/2025-04-29
Article 1
For the purposes of this Regulation, the following definitions shall apply:
| (1) | ‘suspicious transaction and order report’ (STOR) means the report on suspicious orders or transactions, including any cancellation or modification thereof, and other aspects of functioning of the DLT where circumstances might exist indicating that market abuse has been committed, is being committed or is likely to be committed. |
|---|
| (2) | ‘electronic means’ are means of electronic equipment for the processing (including digital compression), storage and transmission of data, employing wires, radio, optical technologies, or any other electromagnetic means; |
|---|
| (3) | ‘group’ means a group as defined in Article 2, point (11), of Directive 2013/34/EU of the European Parliament and of the Council (5); |
|---|
| (4) | ‘order’ means each and every order, including each and every quote, irrespective of whether its purpose is initial submission, modification, update or cancellation of an order and irrespective of its type. |
|---|
Article 2
- Persons professionally arranging or executing transactions in crypto-assets shall establish and maintain arrangements, systems and procedures that ensure:
| (a) | effective and ongoing monitoring, for the purposes of preventing, detecting and identifying orders and transactions where circumstances might exist indicating that market abuse has been committed, is being committed or is likely to be committed, of all orders received and transmitted, and all transactions in crypto-assets executed; |
|---|
| (b) | effective and ongoing monitoring of aspects of the functioning of the DLT, for the purposes of detecting and identifying other aspects of the functioning of the distributed ledger technology, including the consensus mechanism, where circumstances might exist indicating that market abuse has been committed, is being committed or is likely to be committed; |
|---|
| (c) | the transmission of STORs to competent authorities in accordance with the requirements set out in this Regulation and using the template set out in the Annex. |
|---|
- The obligations referred to in paragraph 1 shall apply to orders, transactions and other aspects of the functioning of the DLT which might constitute market abuse and shall apply irrespective of:
| (a) | the capacity in which the order is placed or the transaction is executed; |
|---|
| (b) | the types of clients concerned; |
|---|
| (c) | whether the orders were placed or transactions executed on or outside a trading platform. |
|---|
- Persons professionally arranging or executing transactions in crypto-assets shall ensure that the arrangements, systems and procedures referred to in paragraph 1 are:
| (a) | appropriate and proportionate in relation to the scale, size and nature of their business activity; |
|---|
| (b) | regularly assessed, at least through an annually conducted audit and internal review, and updated when necessary; |
|---|
| (c) | clearly documented in writing, including any changes or updates to them, for the purposes of compliance with this Regulation, and that the documented information is maintained for a period of 5 years. |
|---|
- Persons professionally arranging or executing transactions in crypto-assets shall, upon request, provide the competent authority with the information on the assessment referred to in paragraph 3, including information on the level of automation put in place.
Article 3
- The arrangements, systems and procedures referred to in Article 92(1) of Regulation (EU) 2023/1114 shall:
| (a) | cover the full range of trading activities undertaken by the persons professionally arranging or executing transactions in crypto-assets; |
|---|
| (b) | produce alerts indicating activities requiring further analysis to detect potential market abuse; |
|---|
| (c) | enable crypto-asset service providers operating a trading platform to:(i)analyse, individually and comparatively, each transaction executed, and each order placed, modified, cancelled, or rejected in the systems of the trading platform;(ii)prevent the occurrence of repeated behaviours observed on the same trading platform; |
|---|---|
| (i) | analyse, individually and comparatively, each transaction executed, and each order placed, modified, cancelled, or rejected in the systems of the trading platform; |
| (ii) | prevent the occurrence of repeated behaviours observed on the same trading platform; |
| (d) | enable persons professionally arranging or executing transactions in crypto-assets to analyse, individually and comparatively each transaction executed and each order placed, modified, cancelled or rejected inside and outside a trading platform, irrespective of whether or not the orders and transactions are placed and executed by means of the distributed ledger, and aspects of the functioning of DLT that could constitute market abuse. |
|---|
Persons professionally arranging or executing transactions in crypto-assets shall put in place and maintain arrangements and procedures that ensure an appropriate level of human analysis in the prevention, monitoring, detection and identification of transactions, orders and aspects of the functioning of the distributed ledger technology that indicate the likelihood or existence of market abuse behaviours. Persons professionally arranging or executing transaction in crypto-assets shall collect additional personal data, only for the sole purpose of ensuring appropriate level of human analysis.
For the purposes of Article 92(1) of Regulation (EU) 2023/1114, persons professionally arranging or executing transactions in crypto-assets shall, to a degree which is appropriate for, and proportionate in relation to, the scale, size, and nature of their business activity, employ ICT systems.
The ICT systems referred to in the first subparagraph shall include ICT systems capable of deferred automated reading, replaying and analysis of order book data. Such systems shall have sufficient capacity to operate in an algorithmic trading environment.
For the purposes of the second subparagraph, algorithmic trading means trading in crypto-assets where a computer algorithm automatically determines individual parameters of orders, including as to whether to initiate the order, the timing, price or quantity of the order, or how to manage the order after its submission, with limited or no human intervention, and does not include any system that is only used for the purpose of routing orders to one or more trading platform or for the processing of orders involving no determination of any trading parameters or for the confirmation of orders or the post-trade processing of executed transactions.
- Persons professionally arranging or executing transactions in crypto-assets may by written agreement outsource to a third party or delegate to a legal person forming part of the same group, as defined in Article 2, point (11), of Directive 2013/34/EU of the European Parliament and of the Council (6) (‘providers’), the functions relating to the prevention, monitoring, detection and identification of orders, transactions or other aspects of the functioning DLT that could constitute market abuse, including analysis of data, including order and transaction data, and the generation of alerts. Persons delegating or outsourcing those functions shall remain fully responsible for complying with all of their obligations under this Regulation and Article 92 of Regulation (EU) 2023/1114. Where those functions are outsourced to a third party, persons outsourcing those functions shall comply with the following requirements at all times:
| (a) | retain the expertise and resources necessary to:(i)evaluate the quality of the services provided and the organisational adequacy of the providers;(ii)supervise the outsourced services;(iii)manage of the risks associated with the outsourcing of those functions on an ongoing basis; |
|---|---|
| (i) | evaluate the quality of the services provided and the organisational adequacy of the providers; |
| (ii) | supervise the outsourced services; |
| (iii) | manage of the risks associated with the outsourcing of those functions on an ongoing basis; |
| (b) | they shall have direct access to all the relevant information about the data analysis and the generation of alerts. |
|---|
The written agreement referred to in the first subparagraph shall describe the rights and obligations of the person delegating or outsourcing the functions and those of the provider. It shall also set out the grounds on the basis of which the person delegating or outsourcing the functions can terminate that agreement.
- As part of the arrangements, systems and procedures referred to in the first and second subparagraphs, persons professionally arranging or executing transactions in crypto-assets shall maintain the information documenting the analysis carried out with regard to orders, transactions and aspects of the functioning of DLT that could constitute market abuse for a period of 5 years. That information shall include the analysis made and the reasons for submitting or not submitting a STOR. Persons professionally arranging or executing transactions in crypto-assets shall provide that information to the competent authority upon request.
Article 4
Persons professionally arranging or executing transactions in crypto-assets shall organise and provide effective and comprehensive training to the staff involved in the prevention, monitoring, detection and identification of orders, transactions and other aspects of the functioning of the DLT that could indicate the existence of market abuse, including the staff involved in the processing of orders and transactions or in charge of the functioning of the DLT. Such training shall take place on a regular basis and shall be appropriate and proportionate to the scale, size and nature of the business.
Article 5
Persons professionally arranging or executing transactions in crypto-assets shall establish and maintain effective arrangements, systems and procedures that enable them to assess, for the purpose of submitting a STOR, whether with reference to an order, a transaction or other aspects of the DLT there might be circumstances indicating that market abuse has been committed, is being committed or is likely to be committed. Those arrangements, systems and procedures shall include an appropriate level of human analysis.
Persons professionally arranging or executing transactions in crypto-assets shall report a STOR:
| (a) | by using the STOR template set out in the Annex and completing the information fields relevant to the reported orders, transactions or other aspects of functioning of the DLT in a clear and accurate manner, including any supporting documents or attachments; |
|---|
| (b) | using the electronic means specified by that competent authority. |
|---|
For the purposes of point (b) of the first subparagraph, the competent authority shall specify on its website the electronic means to be used, and shall ensure that those electronic means ensure that the completeness, integrity, and confidentiality of the information are maintained during the transmission.
The STOR referred to in the first subparagraph shall be based on facts and analysis, considering all the information available to the persons professionally arranging or executing transactions in crypto-assets.
- Persons professionally arranging or executing transactions in crypto-assets shall ensure and maintain the confidentiality of the information laid down in the report on suspicious orders or transactions and ensure that the person in respect of which the STOR was submitted and anyone who is not required to know about the submission of a STOR by virtue of their function or position within the reporting person is not informed of:
| (a) | the generation of the alerts referred to in Article 3(1), point (b); |
|---|
| (b) | the assessment that may lead to the submission of a STOR; |
|---|
| (c) | the fact that the reporting person will complete the STOR without sending requests of information to the person in respect of which the STOR may be submitted to complete certain fields; |
|---|
| (d) | the submission of a STOR to the competent authority, or the intention to submit one. |
|---|
Article 6
Persons professionally arranging or executing transactions in crypto-assets shall ensure that they have in place effective arrangements, systems and procedures for the submission of a STOR without delay, once reasonable suspicion of market abuse is formed.
The arrangements, systems and procedures referred to in paragraph 1 shall entail the possibility to report STORs in relation to transactions, orders or other aspects of the functioning of the DLT which occurred in the past, where suspicion has arisen in the light of subsequent events or information. In such cases, persons professionally arranging or executing transactions in crypto-assets shall explain in the STOR the delay between the suspected breach and the submission of the STOR according to the specific circumstances of the case.
Persons professionally arranging or executing transactions in crypto-assets shall submit to the competent authority any relevant additional information which they become aware of after the STOR has been submitted, and shall provide any information or document requested by the competent authority.
Article 7
Competent authorities shall transmit STORs by using the form of unsolicited provision of information set out in Annex IV to Commission Implementing Regulation (EU) 2024/2545 (7).
The transmitting competent authority shall attach the STOR to the form referred to in paragraph 1, without being required to translate it into the language of the receiving competent authority. The transmitting competent authority shall include any additional documents provided in the STOR, specifying the legal basis for the provision of the information.
Article 8
- A competent authority that suspects that cross-border market abuse has taken place, may have taken place, or may be taking place, shall report the status of its preliminary assessment to the other competent authorities concerned without undue delay, including, where applicable, to the competent authorities of the trading platforms where the crypto-asset is admitted to trading.
When informed about cross-border market abuse situations, the receiving competent authorities shall, without undue delay, share information about the planning or existence of any supervisory activity or measure or, where applicable and where such information is available to the receiving competent authority, about an existing criminal investigation on the same case.
- Competent authorities concerned shall:
| (a) | periodically update each other about cross-border market abuse situations; |
|---|
| (b) | inform each other about significant interim developments related to cross-border market abuse situations; |
|---|
| (c) | coordinate their supervisory and enforcement actions. |
|---|
A competent authority that has formally initiated an investigation, enforcement activity or, where applicable, that is aware of a criminal investigation, shall inform the other competent authorities concerned thereof, including, where applicable, the competent authorities of the trading platforms where the crypto-asset is admitted to trading. The reporting competent authority may inform ESMA.
Competent authorities having initiated or involved in an investigation or enforcement activity in the context of cross-border situations may request the coordination of ESMA.
For the purposes of this Article, ‘cross-border market abuse situations’ shall mean any of the following situations:
| (a) | a situation in which more than one competent authority is competent to detect, investigate or sanction a potential market abuse case; |
|---|
| (b) | a situation in which cooperation between two or more competent authorities is necessary to detect, investigate or sanction a potential market abuse case. |
|---|
Article 9
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
Provenance and validity dates, identifier, hash
| as of | 2025-04-29 → this version applied |
| valid | 2025-04-29 → open publisher-asserted |
| type | REG_DEL Commission Delegated Regulation (EU) 2025/885 of 29 April 2025 supplementing Regulation (EU) 2023/1114 of the European Parliament and of the Council with regard to regulatory technical standards specifying the arrangements, systems and procedures to prevent, detect and report market abuse, the templates to be used for reporting suspected market abuse, and the coordination procedures between the competent authorities for the detection and sanctioning of market abuse in cross-border market abuse situations |
| language | en |
| published | 2025-04-29 |
| lex_id | eu-eurlex:32025r0885:2025-04-29 |
| record sha256 | 3a1e0e1be9b0ed036c864ff25a1de01925c6c7d103a8bf6a9e2cb943c7b21bb5 |
New here? What am I looking at?
This is a consolidated text: the original law with every later amendment merged in, as the official publisher produced it for a given date. Laws are amended constantly, so “the law” has no single text, only a text per date. That date is the banner above.
It has no legal force. Only the version published in the official gazette (Mémorial / Official Journal) is authentic, the publishers say so themselves, and so do we. Lex reproduces their text without altering a byte, and links the source on every page. This is legal information, never legal advice: it reports what the text said, never what it means for your situation.
“Valid from → to” = the window in which this text applied. “Open” = still current as far as the publisher has consolidated. Each article carries its own hash so you can prove it was not tampered with , here is how.
timeline next version (2025-04-29) →
| tier | A, publisher-supplied validity dates |
| history begins | publisher |
| index built | 2026-08-07T19:46:23Z · corpus 8d5e859 |
| stamp signature | valid (ECDSA-P256) |