Operating a crypto exchange without the right licence is not a regulatory technicality — it is an existential risk. Enforcement actions freeze banking rails within days, and regulators across every major hub are moving from guidance to hard authorisation requirements. Boards that treated licensing as a compliance task for the legal team to handle quietly are now discovering it is a strategic decision that shapes entity structure, banking relationships, product scope and cross-border reach for years.
Crypto exchange licensing today means managing a layered set of obligations: a VASP authorisation (virtual asset service provider licence) at the operating entity level, separate regulated-activity permissions where custody is offered, and jurisdiction-by-jurisdiction analysis wherever users actually sit. The days of a single offshore registration covering a global user base are over. This analysis examines what boards need to understand before committing to a structure — the regime logic, the cross-border exposure, the common errors and the decision calculus that separates sustainable licensing from expensive rework.
The sections below move from the regulatory perimeter through practical process, cross-border interaction, common board-level mistakes, a decision matrix by operator profile and a self-assessment checklist — ending with the questions we are asked most often.
Why Exchange Licensing Is a Board-Level Decision, Not a Compliance Checkbox
Licensing determines the boundaries of what the business can lawfully do, where it can bank and which institutional partners will engage with it — making it a structural choice, not an administrative one. A founding team that selects a licence jurisdiction for speed alone typically rebuilds the structure within two years, at a cost that dwarfs the original saving.
In our practice, the most consequential misalignment we see is between the jurisdiction where the entity is registered and the jurisdictions where users actually transact. Regulators do not apply rules based on the entity's corporate seat alone. They look at where the service is marketed, where the users are located and where the exchange's order book or custodial assets sit. A Cayman-registered entity running a platform that accepts EU residents is within MiCA's (the Markets in Crypto-Assets Regulation's) scope — regardless of where the company is incorporated.
That reality forces boards to ask three questions before any application begins. First: which activities are regulated in each jurisdiction where users will be served? Second: can a single licence passport into the required markets, or is a multi-entity structure necessary? Third: does the selected jurisdiction's regime match the business model — exchange-only, custody, lending, staking — or will the licence leave core revenue lines unlicensed?
Getting these questions wrong is expensive. In a recent engagement, a payments company had operated under a broadly worded VASP registration for several months before a banking partner's compliance team identified that the exchange function was a separately regulated activity under the applicable regime. The bank suspended the account within a business week. Rebuilding the licence stack — and recovering the banking relationship — took considerably longer than it would have taken to map the activities correctly at the outset.
The process above describes the standard path. Your facts — the entity, the user base, the banking — change the analysis. For a scoped assessment of where your licensing exposure sits, contact OBOLUS at Map your options.
What Activities Trigger a Crypto Exchange Licence?
The regulated perimeter for a crypto exchange is defined by the activities it performs, not by how the business describes itself in marketing materials. Across the flagship regimes — MiCA in the EU, VARA in Dubai, MAS in Singapore, the SFC in Hong Kong, and the FCA in the UK — the consistent trigger is the operation of a facility where third parties can buy, sell or exchange virtual assets.
But the perimeter is broader than the order book. Most regimes separately regulate:
- Custody of client assets — holding private keys on behalf of users is a distinct regulated activity in most flagship regimes, including under MiCA's CASP (Crypto-Asset Service Provider) authorisation framework and VARA's activity-based licence categories.
- Transfer and settlement — moving client assets between wallets or to external addresses is regulated in Singapore under the Payment Services Act's Digital Payment Token (DPT) service provisions, and analogously in other hubs.
- Lending and staking — yield-generating products attached to an exchange create separate regulatory questions, particularly where they engage securities or deposit-taking rules.
- Token issuance — an exchange that lists its own token faces whitepaper and disclosure obligations under MiCA's regime for asset-referenced tokens (ARTs) and other crypto-assets.
The intersection of these activities is where boards consistently underestimate the licence count. An exchange offering spot trading, a custodial wallet and an earn product is not operating under one business model — it is operating under three or four regulated activity layers. Each layer requires its own authorisation, its own capital allocation and its own compliance programme, either within a single licence (where the regime permits) or across multiple entities.
How Do the Major Licensing Regimes Compare for an Exchange Operator?
No single regime is categorically superior. The right choice depends on the operator's user base, product mix, capital position and banking access — and a structure that works for a derivatives exchange serving professional traders is unlikely to work for a retail spot platform seeking EU passporting.
Under MiCA, a CASP authorisation granted by a national competent authority in one EU member state can passport across the full EU and EEA. That passporting right is the regime's most powerful feature for operators with European user bases. Lithuania, long used as an EU VASP entry point, continues its transition to CASP authorisation under MiCA; Malta's MFSA is processing VFA framework transitions to the new CASP standard. The trade-off is a rigorous authorisation process with capital requirements that vary by licence category, a detailed whitepaper regime for any token issuance, and ongoing supervisory obligations that are more demanding than most prior VASP registrations.
VARA in Dubai operates an activity-based structure: separate permissions cover advisory services, broker-dealer activities, custody, exchange operations, lending, management and transfer/settlement. Operators frequently apply for multiple VARA permissions under a single entity. VARA applies across mainland Dubai; entities operating in the DIFC financial free zone sit under a different regime. The AIFC's AFSA in Kazakhstan offers a common-law environment suited to operators targeting Central Asian and CIS user bases, with a framework that borrows structurally from FCA and ADGM precedents.
In Singapore, MAS licenses DPT services under the Payment Services Act. The tiered licence structure — standard payment institution versus major payment institution — sets different thresholds for transaction volume and capital. The MAS regime is demanding on AML/CFT and Travel Rule compliance; operators regularly report a licensing timeline measured in many months. Hong Kong's SFC VATP (virtual-asset trading platform) licensing regime imposes comparably stringent requirements, with a mandatory fit-and-proper vetting process for senior management.
Switzerland's FINMA applies a token taxonomy — payment, utility and asset tokens — that shapes the regulatory path. Fintech licence, banking licence and SRO affiliation each suit a different operator profile. The FCA in the UK applies the Money Laundering Regulations registration regime for cryptoasset businesses, alongside financial promotion rules that carry real enforcement teeth.
What Does the Cross-Border Reality Mean for a Licensing Plan?
For most exchange operators, the entity that holds the licence is not the entity that faces the legal risk — and that gap is where enforcement actions originate. The cross-border reality of digital-asset trading means that a platform's user base, banking infrastructure, liquidity providers and custodied assets typically span multiple jurisdictions simultaneously.
Regulators have become sophisticated about this. The FCA's financial-promotion regime applies to any communication that lands with a UK user, regardless of where the exchange is registered. MiCA's reach captures any exchange that markets to EU residents. Singapore's MAS has pursued operators marketing DPT services locally without a licence even where the operating entity was offshore. This convergence of extraterritorial reach means the question is not "where is the company registered?" but "where are the users, and what does each of those jurisdictions require?"
In our cross-border practice, we routinely advise clients who have licensed in one hub and then discovered that a second jurisdiction — often the home market of a significant user segment — requires either a separate licence or at minimum a regulatory notification. The cost of retroactive compliance is almost always higher than the cost of mapping the exposure in advance.
The banking dimension compounds this. An exchange licensed in a jurisdiction with limited banking infrastructure may hold client funds in a bank account in a different country — triggering that country's payment services or custody rules independently of the licence jurisdiction. Operators we advise regularly encounter banking partners who require not just the primary licence but evidence of the entire regulatory stack: the operating licence, the AML programme certification, the Travel Rule implementation and, increasingly, proof of cyber-security audits.
The Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer) applies at different thresholds in different jurisdictions, but the FATF Recommendation 15 baseline means that any exchange with cross-border transfer functionality needs a technical implementation of the rule — and a counterparty network of other obliged entities to send data to. Licensing without addressing Travel Rule architecture leaves the compliance programme structurally incomplete.
If a prior application stalled or a banking account was closed, a second read can surface the structural reason and the route back. For a scoped review of your cross-border exposure, write to OBOLUS at Map your options.
What Are the Most Common Board-Level Mistakes in the Licensing Process?
The most expensive board-level mistake in exchange licensing is optimising for speed at the expense of fit — selecting a jurisdiction because it offers a fast registration, only to discover that the resulting licence does not cover the target user base or product mix.
A second persistent error is treating licensing as a one-time event. Regulatory regimes evolve. Malta's VFA framework is transitioning to MiCA CASP authorisation. The BVI's VASP Act introduced registration obligations that post-date many structures set up under prior assumptions. Operators who licensed two or three years ago and have not reviewed their structure since are frequently operating under a licence that no longer maps to either their current business model or the current regulatory requirement.
A third category of error involves the separation of the operating entity from the licensing entity. In tax-efficient structures, the entity that contracts with users is often different from the entity that holds the licence. Where those entities diverge — particularly where the licensed entity is in one jurisdiction and the user-facing entity is in another — regulators in the user jurisdiction may treat the user-facing entity as conducting regulated activity without authorisation, irrespective of the group's overall licence position.
Boards also consistently underestimate the internal resource requirement of a licence application. A credible application for authorisation under MiCA, VARA or MAS requires a detailed regulatory business plan, AML/CFT policy documentation, a travel rule implementation specification, fit-and-proper submissions for senior management and, frequently, a compliance monitoring programme. Engaging counsel late — after the business plan has been drafted and the corporate structure fixed — limits the ability to optimise on those inputs. The most effective licensing projects we work on begin with a structural review before any external communication with a regulator.
A common assumption is that a single offshore registration is sufficient to serve clients globally. That assumption was commercially convenient when major regulators were still publishing guidance and had not yet operationalised enforcement. It is not supportable now. MiCA, VARA, the MAS Payment Services Act and the FCA MLR registration regime each impose their own obligations on operators serving users in their respective territories — and those obligations run regardless of where the exchange is incorporated.
Which Licensing Path Fits Which Operator Profile?
The right licensing path turns on the operator's current stage, target market and product scope. No two structures are identical, but the following profiles represent the decision logic we apply most frequently.
Profile A: EU retail exchange, spot trading and custody, seeking passporting. The applicable regime is MiCA, and the most efficient path is CASP authorisation through a member-state NCA, followed by passport notifications for other EU/EEA markets. Lithuania and Malta are the jurisdictions most commonly evaluated for their combination of CASP processing capability and established VASP transition infrastructure. The key risk is timeline: CASP authorisation is a substantive process, not a registration, and the preparation and review period is typically measured in many months. Boards should plan for parallel work on the compliance programme and the banking relationship while the application proceeds.
Profile B: Global institutional exchange, multi-product, offshore-domiciled. A BVI or Cayman holding structure with operating subsidiaries licensed in VARA's Dubai regime (for the exchange and custody permissions), MAS Singapore (for DPT services), and FCA registration (for UK user access) is a common architecture. The cross-border complexity is high, but the commercial benefit — deep institutional banking, a credible regulatory profile and geographic market access — justifies the overhead for exchanges above a meaningful scale threshold. The key risk is coordination: each regulatory application runs on its own timeline and under its own requirements, and a delay in one hub can affect banking in another.
Profile C: Early-stage Web3 exchange, narrow product, cost-conscious. The AIFC/AFSA in Kazakhstan or the BVI FSC VASP registration under the VASP Act 2022 offer registration processes that are less demanding than MiCA CASP or MAS licensing. These are genuine regulatory regimes with AML obligations and supervision, not blank-slate environments. The key risk is marketability: banks and institutional partners in major markets increasingly require a licence from a recognised hub. A BVI or AIFC registration may support early operations but is unlikely to be sufficient as the business scales toward EU, UK or Singapore user bases.
Profile D: Exchange with custody and lending product, targeting US and EU users. This is the highest-complexity scenario. The combination of custody (a separately regulated activity under MiCA and under most US state regimes), lending (which engages deposit-taking rules in several jurisdictions) and exchange services — across a transatlantic user base — requires a multi-entity, multi-licence structure with independent legal opinions on the activity characterisation in each jurisdiction. Boards in this profile should not expect a single adviser to map the full stack; they should expect allied counsel in each relevant jurisdiction working under a coordinated legal brief.
What Does the Licensing Process Actually Look Like?
The licensing process for a crypto exchange typically follows a sequence that is broadly consistent across regimes, even where the specific requirements differ. Understanding that sequence in advance reduces the most common source of delay: incomplete submissions that require a regulator to return a file for supplementary information.
The first phase is structure optimisation. Before any application is filed, the legal and compliance team should have confirmed the corporate structure, identified all regulated activities, mapped the jurisdictions in which those activities are conducted and verified that the chosen licence covers each of them. This phase also involves AML/CFT programme development — most regimes require a completed AML policy, a risk-assessment methodology and evidence of a compliance officer appointment before the application is accepted as complete.
The second phase is preparation of the regulatory business plan. This document is the core of most applications. It describes the business model, the products offered, the risk management approach, the IT infrastructure, the governance structure and the financial projections. Regulators read this document carefully. A business plan that describes aspirations rather than a concrete operating model is a reliable predictor of a request for supplementary information — or a rejection.
The third phase is the fit-and-proper assessment of senior management. Most regimes require detailed submissions on the background, qualifications and regulatory history of directors and key control function holders. The timeline for this phase is partly outside the applicant's control: a regulator that needs to conduct its own checks on a senior manager in a third country will take the time it needs.
The fourth phase is submission, review and correspondence. Even a well-prepared application will typically generate questions. Experienced counsel anticipates the most likely questions and prepares supporting materials in advance. The goal is to reduce the number of back-and-forth cycles with the regulator, because each cycle adds weeks to the timeline.
Timelines vary significantly by jurisdiction and by the current processing load at the relevant regulator. They are measured in months, not weeks, across every substantive regime — and boards that have communicated a go-live date to investors based on a timeline that does not reflect regulatory processing reality face a category of pressure that degrades the quality of the application itself.
A Pre-Application Checklist for Exchange Boards
Before engaging a regulator or filing an application, an exchange board should be able to answer the following questions clearly. Where any answer is unclear, that gap represents a risk to the application and to the business.
- Have all regulated activities — trading, custody, transfer, lending — been identified and mapped to the licence categories available in each target jurisdiction?
- Has the corporate structure been reviewed to confirm that the licensed entity is the entity that will actually conduct the regulated activity in each jurisdiction?
- Is the AML/CFT programme complete, documented and assigned to a qualified compliance officer?
- Has the Travel Rule implementation been designed and tested against the technical standard used by counterparties in the target jurisdictions?
- Have the fit-and-proper requirements for all proposed directors and senior managers been assessed, including any prior regulatory history in any jurisdiction?
- Has the banking strategy been confirmed — meaning a banking partner has been engaged (not merely approached) that will accept the licensed entity as a client?
- Is the regulatory business plan written to describe the actual operating model, not a theoretical one?
- Has the board received independent legal advice on the activity characterisation in each jurisdiction where users will be served, not just the primary application jurisdiction?
Operators we advise who can answer all of these questions affirmatively before filing submit materially stronger applications. Those who cannot typically encounter the supplementary-information cycle that adds months to their timelines.
Related at OBOLUS
- Licensing and registration for digital-asset businesses – a full overview of OBOLUS's licensing practice across 70+ jurisdictions
- Setting up a crypto exchange in Turkey – jurisdiction-specific guidance on Turkish VASP registration and exchange setup
- Tax treatment of tokens in Jersey – how Jersey approaches the taxation of digital assets for exchange operators
FAQ
How long does a crypto licence take to obtain?
Timeline varies significantly by jurisdiction and regime. A substantive authorisation — such as a MiCA CASP, a MAS DPT licence or a VARA multi-activity permission — typically takes many months from a complete filing, and the preparation phase before filing adds further time. Simpler registration regimes, such as the BVI VASP Act registration, can move faster. Incomplete applications, senior manager vetting delays and regulatory back-and-forth all extend the timeline. Boards should not commit to a commercial launch date without a realistic assessment of the application path in their chosen jurisdiction.
Which jurisdiction is best for licensing my crypto business?
There is no universally best jurisdiction. The right choice depends on your target user base, product mix, capital position and banking requirements. An EU retail exchange needs MiCA CASP authorisation for passporting. An institutional multi-product exchange may require VARA and MAS licences alongside an FCA registration. An early-stage operator may start with a BVI or AIFC registration. Any adviser who recommends a jurisdiction without first understanding the business model and user geography is optimising for speed over fit — and that trade-off consistently proves costly.
Do I need a separate custody licence?
In most flagship regimes, custody is a separately regulated activity. Under MiCA, custody and administration of crypto-assets on behalf of clients is a distinct CASP service requiring its own authorisation — it cannot be assumed under an exchange licence alone. VARA similarly separates custody permissions from exchange activity permissions. MAS treats custody of DPT assets as a regulated function. If your exchange holds client assets — private keys, staked positions, earn balances — you should assume custody regulation applies and obtain a legal assessment of the specific requirement in each relevant jurisdiction before operating.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit — so the structure is built once, correctly. We work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications when disputes arise. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
To pressure-test your licensing structure before you commit, message us via Map your options.
By Victor Olsen, Regulatory & Compliance Analyst — specialises in VASP authorisation strategy and cross-border regulatory perimeter analysis for exchange operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.