Article 73 of MiCA permits crypto-asset service providers to outsource operational functions, but it requires them to take reasonable steps to avoid additional operational risk and remain fully responsible for their obligations. The rule prevents a provider from treating a vendor contract as a transfer of regulatory accountability. Regulation (EU) 2023/1114 on markets in crypto-assets
Follow the evidence
Trace how the event could reach markets, then inspect a competing explanation.
Compare explanations
Switch lenses to see what each account explains—and what remains uncertain.
Article 73 requires an outsourcing policy that includes contingency plans and exit strategies proportionate to the provider’s scale and services. Written agreements must define rights and obligations and give the CASP a right to terminate. An exit clause is useful only if data, access and operational capability can actually be transferred or recovered. A practical control inventory maps each outsourced activity to its owner, location, data, service levels, subcontractors, recovery objective and replacement route. Concentration deserves special attention. Multiple functions may appear diversified while relying on the same cloud region, identity provider or infrastructure subcontractor. Testing should include vendor outage, cyber incident, loss of a key licence, insolvency and an uncooperative termination. The provider should know how it will communicate with clients, preserve records and continue critical services. These are operational implications of the rule, not claims that MiCA guarantees uninterrupted service.
Article 73 requires an outsourcing policy that includes contingency plans and exit strategies proportionate to the provider’s scale and services. Written agreements must define rights and obligations and give the CASP a right to terminate. An exit clause is useful only if data, access and operational capability can actually be transferred or recovered. A practical control inventory maps each outsourced activity to its owner, location, data, service levels, subcontractors, recovery objective and replacement route. Concentration deserves special attention. Multiple functions may appear diversified while relying on the same cloud region, identity provider or infrastructure subcontractor. Testing should include vendor outage, cyber incident, loss of a key licence, insolvency and an uncooperative termination. The provider should know how it will communicate with clients, preserve records and continue critical services. These are operational implications of the rule, not claims that MiCA guarantees uninterrupted service.
Clients and counterparties can review the provider’s legal disclosures, service terms and incident communications for named dependencies. Public information may not reveal every vendor, but it should not obscure which authorised entity remains responsible. A support agent blaming a third party does not change that legal relationship. For a business customer, due diligence should examine audit rights, data portability, key management, subcontracting and termination assistance. Recovery claims should be supported by test dates and outcomes. A theoretical backup that has never restored current data is weaker evidence than a documented exercise with measured recovery times. The central Article 73 distinction is simple: work can move, responsibility cannot. Outsourcing may improve scale and specialist capability, but it also creates dependencies. MiCA turns those dependencies into governance, access and exit obligations that a provider should be able to demonstrate before a failure forces the question.
Outsourcing cannot change the provider’s duties to clients or supervisors
MiCA says outsourcing must not delegate the provider’s responsibility, alter the relationship or obligations owed to clients, or change the conditions of authorisation. Third parties must cooperate with the competent authority, and outsourcing cannot block supervisory functions or on-site access to information needed for oversight. Regulation (EU) 2023/1114 on markets in crypto-assets
The provider must retain expertise and resources to assess service quality, supervise the outsourced function and manage its risks continuously. It must have direct access to relevant information. A contract dashboard or vendor certification can support that work, but neither replaces the provider’s own ability to understand failures and challenge performance.
MiCA also requires third parties to meet EU data-protection standards, with those standards reflected in written agreements. Providers and vendors must make necessary information available to authorities on request. These obligations matter when customer data, private keys, transaction records or incident logs sit outside the provider’s direct infrastructure.
Contingency plans and termination rights make vendor dependence testable
Article 73 requires an outsourcing policy that includes contingency plans and exit strategies proportionate to the provider’s scale and services. Written agreements must define rights and obligations and give the CASP a right to terminate. An exit clause is useful only if data, access and operational capability can actually be transferred or recovered.
A practical control inventory maps each outsourced activity to its owner, location, data, service levels, subcontractors, recovery objective and replacement route. Concentration deserves special attention. Multiple functions may appear diversified while relying on the same cloud region, identity provider or infrastructure subcontractor.
Testing should include vendor outage, cyber incident, loss of a key licence, insolvency and an uncooperative termination. The provider should know how it will communicate with clients, preserve records and continue critical services. These are operational implications of the rule, not claims that MiCA guarantees uninterrupted service.
Ask who performs the critical function and who can restore it
Clients and counterparties can review the provider’s legal disclosures, service terms and incident communications for named dependencies. Public information may not reveal every vendor, but it should not obscure which authorised entity remains responsible. A support agent blaming a third party does not change that legal relationship.
For a business customer, due diligence should examine audit rights, data portability, key management, subcontracting and termination assistance. Recovery claims should be supported by test dates and outcomes. A theoretical backup that has never restored current data is weaker evidence than a documented exercise with measured recovery times.
The central Article 73 distinction is simple: work can move, responsibility cannot. Outsourcing may improve scale and specialist capability, but it also creates dependencies. MiCA turns those dependencies into governance, access and exit obligations that a provider should be able to demonstrate before a failure forces the question.
