VASP licence application: A Cross-jurisdiction Comparison
Operating a digital-asset business without the correct authorisation is not a grey area. Regulators across the leading hubs are enforcing hard: banking relationships close overnight, payment rails freeze, and the cost of remediation almost always exceeds what a well-structured licensing strategy would have cost at the outset. The question facing any operator expanding internationally is not whether to licence, but where – and in what sequence. A VASP (virtual asset service provider) application is never a single-jurisdiction exercise; the entity's home, its user base and its banking counterparties each pull the analysis in a different direction. This page maps the core variables, contrasts the leading regimes and provides the decision logic operators need before committing capital to any jurisdiction.
The bottom line: no single licence covers global activity. MiCA CASP authorisation covers the EU/EEA, VARA covers mainland Dubai, MAS licensing covers Singapore, and SFC authorisation covers Hong Kong – each regime is geographically bounded, and the interaction between them determines your actual compliance posture. The sections below trace the practical differences, common failure points and the cross-border analysis that most operators miss.
Why jurisdiction selection determines more than regulatory cost
Jurisdiction selection is a structural decision, not an administrative one. The choice of where to seat a VASP licence determines the applicable capital regime, the AML/CFT obligations that flow from FATF Recommendation 15 (the FATF standard requiring virtual asset service providers to implement risk-based AML controls), the tax treatment of fees and treasury, and – critically – which banking and payment counterparties will onboard the entity at all.
In our cross-border practice, the operators who encounter the most friction are those who selected a jurisdiction on perceived speed or low cost alone, without modelling the banking and client-acceptance consequences downstream. A licence that takes a short time to obtain but leaves the business without a viable IBAN or correspondent banking relationship is not a solved problem. It is a deferred one.
The cross-border reality compounds this. A business authorised in one EU member state under the legacy VASP regime must now transition to MiCA CASP authorisation and rethink its passporting logic. An operator licenced in a Gulf free zone finds its mainland distribution constrained by VARA's separate regime. Operators we advise routinely discover that the licence they hold covers a narrower set of activities than the business they are actually running.
There is also a timing dimension that operators consistently underestimate. Enforcement risk runs from the date the unlicensed activity begins – not from the date a licence application is filed. The window between business launch and regulatory authorisation is a period of legal exposure in almost every major jurisdiction, and the length of that window is set by factors largely outside the operator's control once the application is submitted.
How do the leading licensing regimes compare for a new applicant?
Each major VASP regime has a distinct structure, set of licence categories and application logic; understanding these differences is the starting point for any jurisdictional choice.
EU – MiCA CASP: The MiCA regime administered by ESMA and national competent authorities is the most architecturally significant shift in crypto regulation in recent years. A CASP authorisation in any one EU member state carries passporting rights across the EU/EEA – which makes the choice of home member state a strategic question rather than a pure compliance one. The framework distinguishes between services (exchange, custody, transfer, advice, portfolio management) and requires authorisation for each service class. The token-level regime – covering asset-referenced tokens (ARTs) and e-money tokens (EMTs) – runs in parallel and imposes whitepaper publication obligations. Timeline and capital requirements vary by licence class and are set at the national competent authority level; operators should model this with current NCA guidance rather than rely on generalised estimates.
UAE – VARA: The VARA regime covers mainland Dubai and operates on an activity-based licensing model. Each activity type – advisory, broker-dealer, custody, exchange, lending, management, transfer and settlement – is licenced separately under the relevant VARA rulebook. This means a business running an exchange and a custody service holds two licence components, not one. VARA's rulebooks are detailed and prescriptive; applicants who treat the process as a box-ticking exercise rather than a substantive governance build typically encounter extended review cycles.
Singapore – MAS Payment Services Act: The MAS regime under the Payment Services Act distinguishes between Digital Payment Token (DPT) service providers by scale and scope, with different licence tiers carrying different capital and safeguarding obligations. Singapore's application process is known for its depth of scrutiny; the MAS expects operators to demonstrate a genuine nexus to Singapore – management presence, meaningful local operations – rather than a letterbox structure. Banking access in Singapore for licensed VASPs has tightened materially in recent years, and operators should validate their banking pathway before filing.
Hong Kong – SFC VASP: The SFC licensing regime for virtual asset trading platforms (VATPs) is aimed at exchange-type operators. The SFC applies a high standard on governance, custody arrangements and investor protection. Hong Kong's approach is particularly relevant for operators with significant Asian retail or institutional flow, but the capital and compliance expectations are substantial. The regime is evolving; operators entering the Hong Kong market should engage with current SFC guidance rather than legacy materials.
BVI and Cayman: Both the BVI FSC under the VASP Act 2022 and CIMA under the Cayman Virtual Asset (Service Providers) Act offer registration or licensing tracks that are widely used for fund structures, custody vehicles and token-issuer entities. Neither regime carries passporting rights into the EU or major retail markets; they are typically used in combination with a front-end licence in a client-facing jurisdiction, not as a standalone solution.
What does a MiCA CASP application require in practice?
A MiCA CASP application is a governance-and-substance exercise, not a paperwork drill. The regime requires a demonstrable operational footprint in the member state of authorisation, a compliant AML/KYC framework aligned to the applicable FATF standards, and a management team whose collective competence the national competent authority is prepared to accept on scrutiny.
The choice of home NCA matters. Different national competent authorities within the EU have different review styles, different capacity constraints and different interpretations of how MiCA's requirements apply at the margin. In our practice, operators who approach NCA selection as a function of regulatory philosophy – not just speed – build more durable businesses. A faster NCA is only faster if it does not revert the application for substantive remediation.
The passporting mechanism is a genuine advantage of MiCA, but it functions on notification, not automatic permission. The process requires engagement with both the home NCA and the host NCA in each target member state. Operators who assume that passporting is instantaneous and unconditional routinely discover friction they did not price into their market-entry timeline.
Token-level compliance adds a second track. An operator issuing an ART or an EMT alongside a CASP business must satisfy both the service authorisation and the token-issuer obligations under MiCA – including whitepaper publication requirements. Operators we advise on dual-track MiCA applications find that the token-level whitepaper obligations generate more intensive NCA interaction than the service authorisation itself.
CTA #1: The analysis above describes the standard CASP path. Your specific entity structure, user base and token mechanics change the analysis materially. For a scoped jurisdictional mapping, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options.
How does VARA licensing interact with Gulf structuring?
VARA licensing is an activity-by-activity commitment, and operators entering the Dubai market need to map each line of business to the correct rulebook component before filing. The regime's activity-based architecture means that a business which expands its product set after receiving its initial authorisation will typically need to apply for additional activity permissions rather than simply notifying VARA.
The geographic scope question is critical for Gulf-market operators. VARA's remit covers mainland Dubai. The DIFC – Dubai's common-law financial free zone – has its own regulatory framework administered separately. Abu Dhabi operates under the FSRA within the ADGM free zone. A business that wants to operate across mainland Dubai and the DIFC, or across Dubai and Abu Dhabi, is navigating at least two distinct regulatory regimes. We have seen operators hold three separate authorisations across the UAE to cover their intended footprint.
Banking access is the live variable for UAE-licenced VASPs. The local banking market has historically been cautious about digital-asset clients, and the VARA licence itself does not guarantee banking. Operators should run the banking qualification process in parallel with the licence application, not sequentially after it. A stall at the banking stage after licence grant is a common and expensive failure pattern.
For businesses with a Gulf-facing operation that also services European clients, the VARA licence and a MiCA CASP authorisation in an EU member state are often held in parallel. The governance and compliance infrastructure for both regimes has meaningful overlap in its AML/KYC requirements – both draw on FATF standards – but the reporting, capital and rulebook obligations are entirely separate. Operators who attempt to run this dual structure without dedicated compliance capacity in each jurisdiction typically develop material gaps.
What are the most common mistakes operators make in VASP applications?
The most common mistake in a VASP application is submitting before the business model is sufficiently defined. Regulators in every leading hub probe the alignment between the stated business plan, the proposed governance structure and the actual product the business intends to run. Inconsistencies between the application narrative and the technical or commercial reality are among the most frequent reasons for application rejection or prolonged review.
A second major failure point is AML framework inadequacy. The Travel Rule – the obligation under FATF standards to pass originator and beneficiary data with a virtual asset transfer – is now a live requirement in every significant licensing jurisdiction. Applicants who submit an AML policy that is visibly borrowed from a financial services template, without demonstrating how the Travel Rule is operationalised across the firm's transaction flows, routinely encounter NCA or regulator pushback. In Singapore, the MAS has been particularly explicit about its expectations on Travel Rule implementation.
A third failure pattern is the multi-activity omission. Operators describe one business but run another. A platform that offers spot exchange, a staking product and an OTC desk is running multiple regulated activities under most regimes, and an application filed for only one of them creates both a licensing gap and a credibility problem with the regulator. We regularly advise operators who discover, during a licence review, that their existing product set exceeds the scope of the authorisation they hold.
The governance documentation failure is related: insufficient evidence of the fitness and propriety of the management team. Every leading regulator conducts individual-level scrutiny of key personnel. Gaps in the employment history, undisclosed regulatory events in other jurisdictions or inconsistent professional background documentation can stall or end an application that is otherwise technically sound.
How should operators structure a multi-jurisdiction licence stack?
A multi-jurisdiction licence stack should be designed around the operator's actual user geography, banking relationships and regulated activity scope – not around a list of the easiest or cheapest jurisdictions to access. The stack has at least three layers: the operating licence in the client-facing jurisdiction, the custody authorisation (where custody is a separately regulated activity, as it is under MiCA and several other regimes), and the payment or money-transmission authorisation where the business moves fiat.
In our practice, the most durable structures are those where the jurisdictional choices reinforce each other. An EU CASP licence for European clients, a VARA-licenced entity for Gulf operations and a MAS-licenced entity for Southeast Asian flow creates a coherent structure with genuine regulatory substance in each market. It is more expensive to build and maintain than a single offshore registration – but it withstands scrutiny at the banking, institutional-client and enforcement level in a way that a single registration does not.
The myth that a single offshore licence is sufficient to serve clients globally is the most persistent and costly misconception in digital-asset business structuring. A registration in the BVI or Cayman Islands does not authorise activity directed at EU residents, UK consumers, Singapore users or US persons. The jurisdictional reach of each licence is defined by the home regulator's rules – not by the operator's preference. Operators who ignore this are not unlicensed in name; they are unlicensed in substance in every market they actually serve.
Tax and banking interact with the licence stack in ways that are not always visible at the application stage. The jurisdiction in which a trading desk books revenue may create a permanent establishment exposure in another jurisdiction. The choice of custody jurisdiction affects the tax characterisation of client assets in some markets. These interactions need to be modelled as part of the initial structure design, not resolved after the licence is granted.
CTA #2: If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. To map the licence, banking and tax stack for your build, write to OBOLUS at info@oboluslaw.com. Map your options.
Which licence track fits your operator profile?
Different operator profiles require different jurisdictional entry strategies. The following decision logic reflects the analysis we apply in practice.
Profile A – EU-facing exchange or custody operator: The primary instrument is MiCA CASP authorisation in a home EU member state, selected for NCA compatibility and banking access. Timeline is measured in months from a complete application submission; operators should model a realistic preparation period before filing. The key risk is under-scoping the regulated activity set at the application stage and needing to amend later.
Profile B – Gulf-region operator building an exchange or OTC desk: VARA authorisation is the primary instrument for mainland Dubai activity. The application requires significant governance and compliance infrastructure investment upfront. Timeline for a complete VARA application is typically a matter of several months; the banking parallel-track is equally time-sensitive. Key risk: activity scope creep requiring additional VARA activity permissions after initial grant.
Profile C – Asian market operator with Singapore or Hong Kong focus: MAS Payment Services Act licensing for Singapore-directed DPT activity, or SFC VASP authorisation for Hong Kong. Both require demonstrable local substance. Timeline for MAS licensing has extended as scrutiny has deepened. Key risk: banking access, which is not guaranteed by licence grant and requires independent validation.
Profile D – Fund or token issuer using offshore structures: BVI FSC registration or Cayman CIMA authorisation for the vehicle itself, combined with a client-facing licence in the relevant operating jurisdiction. Offshore registration alone is not sufficient for regulated activity directed at EU, UK, Singapore or US persons. Key risk: assuming the offshore registration provides a compliance shield in client-facing markets where it does not.
Profile E – Global operator building a multi-market stack: Typically requires at least an EU CASP, a Gulf licence (VARA or FSRA/ADGM) and an Asian licence (MAS or SFC), with separate consideration of UK FCA registration for UK-directed activity and US state-by-state money-transmitter licensing for any US exposure. The build timeline for a full stack is measured in years, not months. Key risk: underestimating the compliance resourcing required to sustain multiple concurrent regulatory relationships.
A recent multi-jurisdiction licensing matter
In a recent cross-border licensing engagement, a payments company operating across two Gulf jurisdictions and the EU discovered, during an internal review, that its existing authorisations did not cover all of the activities it was running. Specifically, a token-transfer function introduced in a product update had created a regulated activity under both the VARA rulebook and the applicable MiCA CASP service category – neither of which was reflected in the company's current authorisation scope. We mapped the full activity set against the applicable regimes, identified the specific gaps and designed a remediation and supplementary application sequence that addressed the regulatory exposure without requiring a full restart of the existing licence applications. The company submitted its supplementary applications within a matter of weeks, and the banking relationships that had been flagged for review were stabilised pending the regulatory response.
Is one offshore licence really not enough to serve a global client base?
A common assumption is that a registration in a well-regarded offshore centre – the BVI, Cayman, or a smaller EU jurisdiction – provides a compliant foundation for serving clients globally. It does not. Every major retail and institutional market – the EU, the UK, Singapore, Hong Kong, Japan and the United States – applies its own licensing requirements to activity directed at persons in that market. The relevant test is typically where the client is located and where the marketing, distribution or service is directed – not where the operator's legal entity sits.
FATF's mutual evaluation process has made this harder to ignore. Jurisdictions that tolerate regulatory arbitrage face grey-listing consequences that directly impair their banking correspondent relationships. An operator relying on an offshore registration to service a European or Asian client base is exposed not only to the regulatory enforcement risk in those markets but also to the downstream banking risk that flows from operating in a manner that counterparty banks increasingly identify as non-compliant.
The correct frame is not "which single licence covers the most ground" but "what licence stack accurately reflects the markets I am genuinely serving." That is a more expensive structure to build. It is materially less expensive than an enforcement action, a debanking event or an operational shutdown in a core market.
Related at OBOLUS
- Licensing & Registration for Digital-Asset Businesses – our full practice overview across 70+ jurisdictions for exchanges, custodians and issuers.
- Crypto Exchange Licensing for Established Operators – a service-level analysis for operators scaling across multiple markets.
- Crypto Fund Formation: A Cross-jurisdiction Comparison – a parallel analysis of fund structuring and the licensing questions that sit around it.
FAQ
How long does a crypto licence take to obtain?
Timeline varies significantly by jurisdiction, regime and the completeness of the application at submission. Some registrations can be completed in a matter of weeks; full CASP authorisations under MiCA, VARA activity licences or MAS Payment Services Act licences typically take several months from a complete filing to a decision. Application preparation – governance documentation, AML framework, business plan – often takes as long as the regulatory review itself. Operators who arrive at the filing stage with incomplete materials extend their own timelines materially.
Which jurisdiction is best for licensing my crypto business?
There is no universally correct answer. The right jurisdiction is the one that matches the operator's actual user geography, activity scope and banking requirements. An EU CASP authorisation is the logical anchor for a European client base; VARA is the primary instrument for mainland Dubai; MAS licensing governs Singapore-directed activity. Operators serving multiple geographies typically need a licence stack rather than a single jurisdiction. The choice should be validated against banking access and tax treatment before commitment, not after.
Do I need a separate custody licence?
In most leading regimes, yes. Under MiCA, custody and administration of crypto-assets on behalf of clients is a separately authorised CASP service. VARA treats custody as a distinct activity under its rulebook. MAS licensing similarly addresses custody as a separate function. An exchange operator that also holds client assets without a separate custody authorisation is typically running an unauthorised regulated activity in the same jurisdiction where it holds its exchange licence. The practical consequence is both a licensing gap and a material risk in the event of client-asset disputes or regulatory examination.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and where a matter escalates to a dispute, our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums. To discuss your situation, contact info@oboluslaw.com.
By Glen Sorensen, Disputes & Recovery Analyst – specialising in cross-border VASP licensing exposure, enforcement risk and regulatory remediation across the EU, Gulf and Asian regimes.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.