European CommissionTechnical standards C(2026) 6179

Commission act C(2026) 6179: central contact points for crypto-asset service providers

European CommissionTechnical standards C(2026) 6179Issued

By the ExamPass CY editorial teamPublished

Short answer

On 8 September 2026 the European Commission adopted C(2026) 6179, which extends the EU standards on AML/CFT central contact points to crypto-asset service providers (CASPs). A host Member State may require a CASP from another Member State that runs establishments other than a branch on its territory to appoint one, for example where those establishments carry out more than EUR 3 million of activity a year. The act is not yet in force: it enters into force 20 days after publication in the Official Journal.

At a glance

What changes
Host Member States will be able to require CASPs from other Member States that operate establishments other than branches on their territory to appoint a central contact point for AML/CFT.
Who is affected
CASPs with a head office in one Member State and establishments other than a branch in another, including Cyprus-authorised CASPs active elsewhere in the EU.
  • Crypto-asset service providers (CASPs) operating in other Member States
  • Cyprus-authorised CASPs with establishments elsewhere in the EU
  • AML compliance officers of CASPs
  • E-money issuers and payment service providers (rules unchanged)
What to do
Map non-branch establishments in other Member States, estimate their yearly activity against the EUR 3 million test and check each host State's rules.
By when
Not yet in force — 20 days after publication in the Official Journal

What has the Commission adopted?

On 8 September 2026 the European Commission adopted Delegated Regulation C(2026) 6179. It extends the regulatory technical standards on central contact points in Delegated Regulation (EU) 2018/1108, which currently covers only e-money issuers and payment service providers, to crypto-asset service providers. The existing rules for e-money and payment firms stay as they are.

The legal basis is Article 45(11) of the fourth Anti-Money Laundering Directive, Directive (EU) 2015/849. Regulation (EU) 2023/1113 on information accompanying transfers of funds and crypto-assets rewrote Article 45(9) of that Directive so that Member States may also ask CASPs established on their territory in forms other than a branch, with a head office in another Member State, to appoint a central contact point. The act is based on EBA draft standards, consulted on from 4 December 2024 to 4 February 2025. A CASP has its MiCA meaning, but firms that only give advice on crypto-assets are excluded.

When can a host Member State require a central contact point?

A host Member State may require a CASP that has establishments on its territory other than a branch, and a head office elsewhere in the EU, to appoint a central contact point where any of three tests is met: it has 10 or more such establishments; the value of the services and activities carried out by those establishments is expected to exceed EUR 3 million in a financial year, or exceeded it in the previous one; or the firm does not give the host supervisor, on request and in time, the information needed to apply the first two tests.

Host States may also require a central contact point from categories of CASPs where this is commensurate with the money laundering and terrorist financing risk of their establishments. In exceptional cases they may empower their supervisor to require one from an individual firm where there are reasonable grounds to believe that its establishments present a high risk.

What does a central contact point do?

The central contact point acts for the CASP in the host State. It informs the firm of local AML/CFT requirements for its policies and procedures, oversees whether the establishments comply with them and with the firm's own controls, reports breaches to head office, makes sure corrective action is taken and makes sure staff attend AML/CFT training. It also represents the firm before the host supervisor and financial intelligence unit, answers their requests and provides information, reporting regularly where appropriate. Host States may add further functions where the overall risk justifies it.

When does it apply, and what should CASPs do?

The act has been adopted but is not yet in force. It enters into force 20 days after its publication in the Official Journal, which follows the scrutiny period of the European Parliament and the Council; as at 3 October 2026 we found no publication. Even then, a central contact point is needed only where a host Member State has chosen to require one.

The regime may be short-lived. Directive (EU) 2015/849 is repealed with effect from 10 July 2027, when Article 41 of Directive (EU) 2024/1640 becomes the basis for central contact points. That article also covers activity through agents, distributors and other infrastructure, and gave AMLA the task of drafting new standards. In the meantime, Cyprus-authorised CASPs should map any establishments in other Member States that are not branches, estimate their yearly activity against the EUR 3 million test and check what each host State requires. For the wider picture, see our study note on the AML obligations of CASPs.

In the official wording

“the cumulative value of the services and activities carried out by the CASP’s establishments is expected to exceed EUR 3 million per financial year”

European Commission, Commission Delegated Regulation amending the RTS in Delegated Regulation (EU) 2018/1108 as regards the criteria for the appointment of central contact points for crypto-asset service providers and rules on their functions, C(2026) 6179 final, Art. 1(2)(a)(ii)

When does it apply?

Applies now

  • Nothing new yet: C(2026) 6179 is adopted but not published in the Official Journal, so it is not in force.
  • Delegated Regulation (EU) 2018/1108 continues to apply to e-money issuers and payment service providers.

Applies later

  • Directive (EU) 2015/849, the legal basis of this act, is repealed; central contact points then rest on Article 41 of Directive (EU) 2024/1640 and AMLA's standards.

What to do

  1. List any establishments in other Member States that are not branches, and the services each provides.No fixed deadline
  2. Estimate each host-State establishment network's yearly activity against the EUR 3 million test and count establishments against the 10-establishment test.No fixed deadline
  3. Check whether each host Member State has chosen to require central contact points from CASPs, and what extra functions it asks for.No fixed deadline
  4. Watch the Official Journal for publication of C(2026) 6179 and note the entry-into-force date.No fixed deadline

In the exam

The CySEC AML exam covers the AML obligations of crypto-asset service providers and the EU AML framework; central contact points are one way host supervisors oversee cross-border obliged entities.

Related study notes

Preparing for an exam?

Practise the topics behind this update

Exam-style questions with a hint before you answer and a full explanation after, chapter by chapter.

Sources

  1. Commission Delegated Regulation amending the RTS in Delegated Regulation (EU) 2018/1108 as regards the criteria for the appointment of central contact points for crypto-asset service providers and rules on their functions, C(2026) 6179 final (opens in a new tab)

    European CommissionOfficial text

  2. Commission Delegated Regulation (EU) 2018/1108 on central contact points for electronic money issuers and payment service providers (opens in a new tab)

    EUR-LexOfficial text

  3. Directive (EU) 2015/849 (fourth Anti-Money Laundering Directive) (opens in a new tab)

    EUR-LexOfficial text

  4. Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets (opens in a new tab)

    EUR-LexOfficial text

  5. Directive (EU) 2024/1640 (AMLD6), Articles 41 and 77 (opens in a new tab)

    EUR-LexOfficial text

Summary prepared by the ExamPass CY editorial team; it is not the official text. Quotations are reproduced from the source for the purpose of reporting and review.

© European Union, https://eur-lex.europa.eu. EU material is reused with credit and has been summarised; only the Official Journal of the European Union is authentic.

Get the weekly Regulatory Brief

New CySEC, ESMA, AMLA and EU publications in plain English: what changes, who is affected and what to do by when.

How often?

More updates

All updates →