Passporting a crypto licence means that a regulatory authorisation granted in one jurisdiction can extend – automatically or by notification – to permit digital-asset activity across a broader territory, without requiring a full new application in every market. Under MiCA (Markets in Crypto-Assets Regulation), a CASP (crypto-asset service provider) authorised in one EU or EEA member state may notify the relevant national competent authority and begin offering services across the entire bloc. No equivalent mechanism exists in the UAE, Singapore, the UK or the United States, where each regime demands its own standalone authorisation. That asymmetry defines the strategic licensing decision for every cross-border digital-asset business in 2024 and beyond.
This guide covers the definition and scope of passporting under MiCA, the regimes where a passport does not run, how to structure an entity footprint for maximum reach, common structural errors, and when the cross-border complexity triggers a licensing or disputes question that requires specialist counsel.
What Is Passporting in the Context of a Crypto Licence?
Passporting gives a CASP authorised by one national competent authority (NCA) the legal right to provide authorised services in other member states, either on a freedom-of-services basis or through a branch, after a notification procedure. It is the single most consequential structural right in the MiCA regime and the primary reason operators choose an EU licensing anchor for their European build. The passport runs on the category of service authorised – custody, exchange, advisory, transfer – so a business holding a narrowly scoped authorisation cannot passport activity that exceeds that scope.
The principle derives from the single-market architecture that MiCA inherited from MiFID II and the e-money framework. ESMA, the European Securities and Markets Authority, coordinates between NCAs. The home-state NCA supervises the entity; the host-state NCA may impose conduct-of-business rules on top of the passported activity. Practically, this means that ESMA's supervisory convergence work matters: a passport obtained quickly in a lighter-touch member state is still subject to host-state consumer-protection rules once activity begins in that market.
In our licensing practice, the first question a founder asks is whether a single EU authorisation will "cover" their European user base. The answer is yes for passportable CASP activities – but the host state's conduct regime, language requirements for white papers, and local marketing rules all apply on top of the passport. Passporting unlocks market access; it does not eliminate local compliance obligations.
For a scoped assessment of your EU licensing anchor and the host-state obligations that will layer on top, contact OBOLUS at info@oboluslaw.com. The process above describes the standard notification path. Your entity structure, service scope and user geography change the analysis materially – and the choice of home-state NCA is difficult to reverse once made. Map your options before you commit.
Where Does Passporting Run – and Where Does It Stop?
The MiCA passport runs across the 27 EU member states plus the EEA countries that have adopted the regulation, giving a CASP authorised in any single member state the broadest territorial reach of any digital-asset licensing regime currently in force. Beyond that perimeter, no automatic passport exists. The UAE's VARA (Virtual Assets Regulatory Authority) and ADGM/FSRA (Abu Dhabi Global Market, Financial Services Regulatory Authority) operate entirely distinct activity-based licensing regimes; a MiCA CASP authorisation carries no weight with either authority. Similarly, the UK FCA's MLR registration (registration under the Money Laundering Regulations) is a standalone regime with its own eligibility criteria and review process.
Singapore's MAS (Monetary Authority of Singapore) licenses digital payment token service providers under the Payment Services Act. Hong Kong's SFC operates a separate VATP (virtual-asset trading platform) licensing track. Switzerland's FINMA applies its own token taxonomy and licence-route analysis. Japan's FSA works alongside the JVCEA self-regulatory body. Each of these regimes is self-contained. A business that wants regulated access to the EU, the UAE, Singapore and the UK needs four distinct regulatory relationships – minimum.
The BVI FSC and CIMA in the Cayman Islands have enacted VASP registration frameworks. These are often used for fund vehicles or holding structures rather than as operating licences for customer-facing activity. Neither the BVI VASP Act 2022 nor the Cayman VASP Act creates a passport into any other jurisdiction. Operators who treat an offshore VASP registration as a global permission to serve retail clients across multiple markets expose themselves to enforcement risk in every jurisdiction where their users are located.
In our cross-border practice, the most common structural error we encounter is precisely that assumption: that an offshore registration acts as a global licence. It does not. The relevant test in almost every leading jurisdiction is where the service is provided to the end user – not where the entity is incorporated or registered.
How Does the MiCA CASP Authorisation and Passporting Process Work?
The MiCA CASP authorisation process begins with an application to the home-state NCA, which then has a defined period – varying by the complexity of the application and the NCA's workload – to assess the applicant's fitness, governance, AML/CFT programme, safeguarding arrangements and operational resilience. Once granted, the passport is triggered by a notification from the home-state NCA to the relevant host-state NCA, after which the CASP may begin cross-border activity into that host state within the period specified under the applicable provisions of MiCA.
The choice of home-state NCA is strategic. Lithuania's Bank of Lithuania and the MFSA in Malta both built reputations during the earlier VASP-registration era for relatively structured and accessible application processes. Under MiCA, both NCAs are now operating within the full CASP authorisation framework, which imposes harmonised standards across the EU. The differentiation that existed under the prior regime has narrowed. An applicant should assess NCA processing capacity, language requirements, the substance requirements the NCA imposes on top of the MiCA minimum, and the political risk of a member state with a lighter supervisory history attracting regulatory scrutiny from ESMA.
ESMA has signalled, through its supervisory convergence work, that it will monitor divergent authorisation practices across NCAs. A CASP that is authorised in a member state primarily because that NCA has shorter queues – without genuine substance in that state – risks a challenge to the passport itself if ESMA determines that the authorisation was granted without adequate scrutiny. Substance requirements, including local management, compliance staffing and governance, are therefore not merely a practical obligation; they are the defence of the passport's validity.
The AML/CFT baseline for every CASP authorised under MiCA tracks the FATF Recommendations, including Recommendation 15 on virtual assets and the Travel Rule (the obligation to pass originator and beneficiary data with a transfer of value). ESMA and the EBA coordinate on the AML package that runs alongside MiCA. Host-state AML supervisors retain enforcement authority over a passported CASP's conduct in their territory.
How Should a Cross-Border Digital-Asset Business Structure Its Entity Architecture?
The right entity architecture for a cross-border digital-asset business depends on the services offered, the client profile, the user geographies, and the banking relationships available – not on the jurisdiction with the lowest filing fee. A business serving EU retail clients, institutional UAE counterparties and Singapore-based funds will need a separate regulated entity in each of those markets, each with its own capital base, governance structure and compliance programme. There is no shortcut.
The typical architecture for a well-structured operator involves a licensed EU CASP entity as the European anchor, a VARA-licensed entity for the UAE market, and either a MAS-licensed DPT service entity or a Singapore holding company with an operating subsidiary in the relevant licensed jurisdiction for Asia. A Cayman or BVI fund vehicle may sit above or alongside the operating entities for investment activity. Each entity must be genuinely independent in substance – separate controllers, separate capital, separate AML programmes – not a series of shells flowing to a single beneficial owner who believes the offshore holding company is the "real" business.
Banking is the variable that most often forces a restructure. Banks in the major hubs – Frankfurt, Singapore, Dubai, London – have their own internal risk policies on digital-asset businesses. A VARA licence alone does not guarantee access to UAE banking. A MiCA CASP authorisation does not guarantee euro-denominated settlement accounts at an EU correspondent bank. In our practice, we regularly advise clients to map the banking stack alongside the licensing stack before committing to a jurisdiction, because a licence without banking is operationally worthless.
Tax treatment sits on top of this. The location of management and control, the residence of the contracting entity, and the nature of the token being handled all interact with corporate tax, VAT and withholding-tax regimes in ways that a purely licensing-focused analysis will miss. The cross-border structuring question is not "which licence is cheapest?" – it is "which combination of licences, banking relationships and tax positions gives this business a durable operating platform?"
To map the licence, banking and tax stack for your build before you commit, write to OBOLUS at info@oboluslaw.com. If a prior application stalled or a banking relationship closed, a second read of the structure can surface the reason – and the route forward. Map your options.
What Are the Most Common Licensing Mistakes in Cross-Border Crypto Operations?
The most consequential licensing mistake in cross-border digital-asset operations is misidentifying the relevant jurisdiction for regulatory purposes – treating the entity's place of incorporation as the relevant regulatory perimeter, when almost every leading regime applies a market-access or services-location test instead. A business incorporated in the BVI but operating an exchange accessible to EU users is within the regulatory perimeter of MiCA, regardless of where its servers are located. Regulators in the leading hubs increasingly expect operators to have analysed this question formally before launch.
A second recurring error is scope creep: obtaining a narrow authorisation – advisory, for example – and then expanding into custody or exchange activity without notifying the home-state NCA and extending the authorisation. Under MiCA, each CASP activity requires separate authorisation. A business that drifts across categories risks operating outside its authorised perimeter, which can void the passport for the unauthorised activity and expose the entity to enforcement in every host state where that activity has been conducted.
Third: treating the Travel Rule as a future obligation. The Travel Rule – the obligation to collect and transmit originator and beneficiary information with a transfer of virtual assets – applies at the regulated VASP level in every jurisdiction that has implemented FATF Recommendation 15. A CASP that lacks a compliant Travel Rule solution at the point of authorisation will face remediation demands from its NCA. In our experience advising applicants through the authorisation process, AML infrastructure – including Travel Rule compliance – is frequently the item that extends timelines.
Fourth: underestimating the whitepaper obligation. Under MiCA, a business issuing certain token types must publish a whitepaper that meets prescribed content requirements and is notified to the relevant NCA. The whitepaper is not a marketing document; it is a regulated disclosure instrument. Treating it as such – and investing in its preparation accordingly – saves significant remediation time after submission.
When Does a Licensing or Passporting Issue Become a Disputes Question?
A regulatory licensing issue becomes a disputes question at the moment a third party – a regulator, a counterparty, a banking partner or an investor – takes an adverse action based on the business's regulatory status. That action might be a regulatory notice requiring remediation or suspension of operations; a bank's decision to close accounts on the ground of unresolved licensing; or an investor seeking to unwind a subscription on the basis that the fund's manager was not properly authorised at the time of the investment. Each of these scenarios has a legal resolution path, but the path is materially different depending on when counsel is engaged.
In a recent cross-border matter, a European exchange operator discovered mid-expansion that its passported CASP authorisation did not cover the transfer-service component of its product. A host-state NCA had issued an informal query. We mapped the scope of the existing authorisation against the product functionality, identified the specific gap, and coordinated the extension application with the home-state NCA while the operator continued other authorised activity. The informal query was resolved before it escalated to a formal notice.
The DIFC Courts in Dubai have established themselves as a credible forum for commercial disputes arising from digital-asset transactions and regulatory relationships, sitting alongside the well-developed jurisdiction of the English courts for on-chain asset recovery. The CFAAR network (Crypto Fraud and Asset Recovery network, launched in London in September 2021) provides a structured route for coordinating cross-border disclosure and freezing relief. Where a licensing dispute intersects with misappropriation of assets – for example, where an unlicensed operator has taken client funds – the recovery tools available in common-law courts become relevant quickly.
Operators facing a regulatory notice, a banking closure or a counterparty dispute arising from their licensing position should engage specialist counsel before responding. Early analysis of the regulatory basis for the adverse action, and the procedural options available, can determine whether the matter is resolved at the informal stage or escalates to formal enforcement.
Which Licensing Path Fits Your Business Profile?
Different operator profiles call for different first-licence choices. The analysis below maps common business profiles to indicative licensing strategies, with reference to the cross-border risks at each step.
A European-first retail exchange – serving EU users across multiple member states from the outset – should anchor in an EU member state and obtain full CASP authorisation under MiCA, with the passport as the primary route to multi-state access. The choice of home-state NCA should weigh processing timelines, substance requirements and ESMA convergence risk. The entity needs genuine local substance, an AML programme calibrated to the Travel Rule, and a banking relationship established before launch. Timeline is qualitative and varies by NCA; applicants should budget considerably more time than they expect.
A Gulf-focused institutional platform – serving professional counterparties in the UAE and the wider GCC – should engage with VARA for Dubai-mainland activity and with the ADGM/FSRA for Abu Dhabi. VARA's activity-based licensing requires a separate licence for each regulated activity. The ADGM/FSRA regime applies to entities within the ADGM financial free zone. Neither licence covers the other's territory; an operator active in both needs two regulated relationships. Banking in the UAE for digital-asset businesses requires early engagement with the relevant bank's correspondent-banking and compliance team – the licence application and the banking application should run in parallel.
An Asia-Pacific operator targeting Singapore, Hong Kong and Japan faces three entirely separate licensing processes: MAS under the Payment Services Act for DPT services, the SFC's VATP licensing track in Hong Kong, and the FSA/JVCEA route in Japan. Each has its own capital, governance and AML requirements. There is no regional passport equivalent to MiCA. An operator in this profile must budget for three standalone authorisation processes and three separate compliance programmes.
A global fund or custody platform structuring for institutional clients across multiple zones needs to analyse whether the fund vehicle itself requires authorisation in its jurisdiction of domicile – CIMA for a Cayman fund, for example – separately from whether the investment manager or custody provider needs its own licensing in each market where it operates. The two-entity analysis (fund domicile vs. manager licence) is frequently conflated, leading to structures that are correctly organised at the fund level but inadvertently operating an unlicensed investment management function in a regulated market.
Does a Single Offshore Registration Cover Global Operations?
A single offshore VASP registration does not authorise a business to serve clients globally; the jurisdictional reach of any registration is limited to the territory of the registering authority, and the market-access test in every major hub looks to where the service is delivered, not where the entity is registered. This is the most persistent misconception in cross-border digital-asset licensing, and it is the direct cause of enforcement actions, banking closures and investor disputes in each cycle of the industry.
The BVI VASP Act 2022 and the Cayman VASP Act are domestic registration regimes. They impose AML/CFT obligations on entities registered in those territories. They do not confer any right to offer services to users in the EU, the UAE, Singapore, the UK or the United States. An operator that is registered in the BVI and marketing its exchange to EU retail users without a MiCA CASP authorisation is operating in breach of MiCA's market-access provisions. ESMA and NCAs have the authority to take enforcement action against such operators, including requiring local intermediaries to block access to the platform.
The same principle applies to the AIFC/AFSA regime in Kazakhstan. The AIFC is a common-law jurisdiction within Kazakhstan with its own regulatory authority, the AFSA. AFSA authorisation permits activity within the AIFC perimeter and does not create a passport into other markets. For operators using the AIFC as a Central Asian hub, the AFSA licence covers that market; activity directed at users in the UAE, Singapore or the EU requires separate regulatory engagement in each of those jurisdictions.
In our practice, we regularly advise businesses that have launched on the assumption that a single registration suffices, and that are then confronted with NCA queries, banking refusals or investor concerns. The remediation path is longer and more expensive than the initial multi-jurisdiction analysis would have been. The cost of getting the structure right at the outset is materially lower than the cost of restructuring under regulatory pressure.
Related at OBOLUS
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – the full scope of OBOLUS licensing counsel across 70+ jurisdictions
- Digital-Asset Licensing in the Bahamas – what operators need to know about the SCB regime and DARE Act
- Founder Relocation and Tax in the Bahamas – the tax and residency position for digital-asset founders relocating to Nassau
FAQ
How long does a crypto licence take to obtain?
Timelines vary significantly by jurisdiction, licence category and the completeness of the application. Under MiCA, NCA processing periods differ between member states, and applicants with complex governance structures or multi-activity scope should budget for a process measured in months rather than weeks. In faster-processing hubs such as the AIFC or certain offshore regimes, timelines can be shorter, but substance and AML requirements still apply. The single most consistent cause of delay, in our experience, is incomplete AML/CFT documentation at the point of submission.
Which jurisdiction is best for licensing my crypto business?
There is no single best jurisdiction – the right answer depends on the services you are offering, the clients you are serving, where your users are located, your banking relationships and your capital position. A European retail exchange needs a MiCA CASP authorisation. A Gulf-focused institutional platform should engage VARA or ADGM/FSRA. An Asia-Pacific operator needs separate processes with MAS, the SFC or the FSA. We map the full licence, banking and tax stack against your specific operating profile before you commit to any jurisdiction.
Do I need a separate custody licence?
In most leading regimes, custody of virtual assets is a distinct regulated activity requiring its own authorisation. Under MiCA, custody and administration of crypto-assets is a CASP service category that must be specifically authorised – it is not included automatically within an exchange or advisory authorisation. VARA, MAS and the SFC each treat custody as a standalone regulated function with its own capital, governance and operational resilience requirements. A business offering custody alongside exchange or advisory services will generally need each activity expressly covered in its authorisation.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when assets are at risk. To discuss your situation, contact info@oboluslaw.com.
To pressure-test your structure before you commit, message us via t.me/oboluslaw. Map your options.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in multi-jurisdiction CASP authorisation strategy and cross-border entity architecture for digital-asset operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.