Missing context values: The H1 contains a colon in a way that may affect display, and the META_TITLE appears truncated ("Where the Legal" – stopping mid-phrase). Both are used verbatim per the rules, as instructed. The JURISDICTION field is blank, which is by design for a cross-jurisdictional analysis page. Proceeding with full output now.
Renewal and variation: why the legal stakes are higher than most operators expect
A crypto licence renewal is not a formality. Across every major regime – from MiCA and ESMA in the EU to VARA in Dubai and the MAS Payment Services Act in Singapore – a renewal window is a full regulatory re-evaluation in compressed form. Miss the deadline, submit materially incomplete documentation, or trigger an undisclosed change of control in the months before filing, and the regulator treats the licence as lapsed. The enforcement consequences – suspended operations, frozen banking rails, mandatory client notifications – can land within days. This analysis maps where the legal lines fall, what triggers a variation application (a formal request to amend the scope or conditions of an existing authorisation), and how operators across multiple jurisdictions manage both processes without halting their businesses.
The failure mode we see most often is not outright non-compliance. It is the operator that believes its original authorisation still covers a materially expanded product set. A VASP registration obtained for a spot exchange does not automatically extend to custody, lending or staking reward products. Adding those services without a formal variation is operating outside the licence perimeter – a category of breach that regulators in the leading hubs treat as equivalent to operating unlicensed.
The sections below examine the renewal and variation regimes jurisdiction by jurisdiction, the decision logic that determines which path applies, and the structural errors that create enforcement exposure. A decision matrix by operator profile appears in the final analysis section.
What triggers a variation rather than a routine renewal?
A variation is required whenever a proposed change would expand, restrict or materially alter the regulated activities covered by the existing authorisation – and the line between administrative update and formal variation is drawn differently in each regime. Under MiCA, a CASP (crypto-asset service provider) authorised for exchange services must apply for a variation before offering custody services, portfolio management or advisory services; the passporting mechanism does not extend to activities not originally authorised. Under the VARA regime in Dubai, the activity-based licence structure means that adding a transfer-and-settlement function to an existing exchange licence requires a fresh activity approval, not merely a notification.
The practical triggers fall into several categories. First, a change in the regulated activities themselves – adding a new product type that maps to a separately licensed activity. Second, a change in the ownership or control structure above the licensed entity, including acquisition of a controlling stake or a restructuring that moves the parent to a new jurisdiction. Third, a material change in the technology architecture – for example, shifting from a fully custodial model to a non-custodial or hybrid model, which can alter the custody and safeguarding obligations that attach to the licence. Fourth, a change in the client base that brings in a new category of users the original licence did not contemplate, such as institutional prime brokerage added to a retail-facing exchange authorisation.
Regulators including the FCA in the United Kingdom and the SFC in Hong Kong publish guidance on notification obligations, but the guidance invariably preserves significant discretion on whether a proposed change is material enough to require a formal variation. In our cross-border practice, we find that operators almost always underestimate what counts as material. The safer default is to treat any structural or product change as potentially variation-triggering and to obtain a pre-submission confirmation from the regulator or qualified counsel before proceeding.
CTA #1 — Early reader
The renewal or variation path above describes the standard process. Your facts – the entity structure, the product set, the client base, the banking relationships – change the analysis substantially. If you are approaching a renewal window or planning a product expansion, a scoped pre-submission review can surface the issues before the regulator does. Map your options with OBOLUS before you file.
How do renewal timelines work across the major regimes?
Renewal timelines vary significantly by regime, and the practical lead time the operator needs is almost always longer than the regulator's published clock. Under the MiCA framework, the initial CASP authorisation is not subject to a fixed periodic renewal in the traditional sense; instead, the authorisation is ongoing but subject to continuous supervisory review, with the regulator retaining the right to withdraw or impose conditions on an ongoing basis. The practical renewal pressure arises when a business undergoes a change that requires notification or when a transitional grandfathering period expires for operators that held a pre-MiCA national registration.
Contrast this with the VARA model in Dubai, where licences are issued for a defined term and renewal applications must be submitted within the window specified in the licence conditions. Missing that window does not automatically lapse the licence, but it does expose the operator to a gap period during which the regulator may impose interim conditions or require the business to pause regulated activities pending the renewal decision. In our practice, we recommend submitting renewal documentation well ahead of the stated deadline – not because the regulator's clock is unreliable, but because the internal document-gathering process for a renewal (updated AML/CFT programme, refreshed fitness-and-propriety assessments, updated technology audits) reliably takes longer than clients anticipate.
Under the MAS Payment Services Act in Singapore, the major payment institution licence for digital payment token services does not carry a fixed expiry date, but the licensee must maintain continuous compliance with the conditions of its licence and notify MAS of prescribed changes within defined periods. Failure to notify on time is itself a breach, independent of whether the underlying change would have been approved. The AIFC/AFSA regime in Kazakhstan similarly imposes ongoing notification obligations, with variation applications required for any change in the regulated activities or the controller structure.
In practice, the regimes that impose the most acute renewal pressure are those operating under grandfathering transitions – operators that hold legacy registrations from a pre-MiCA national regime, a pre-VARA free zone authorisation, or a pre-Payment Services Act money-service registration. These operators face a defined transition window within which they must obtain a full authorisation under the new regime or cease the relevant activities. The transition window is not a grace period for continued operation in an unlicensed state; it is a deadline after which enforcement is available.
Why does the cross-border structure make renewal and variation harder?
The most complex renewal and variation situations arise not from a single-jurisdiction operator managing one licence, but from a group structure where a parent entity, an operating subsidiary, a custody entity and a technology provider sit in different jurisdictions – each with its own regulatory relationship and each potentially subject to separate renewal or variation obligations simultaneously. A group that built its structure for speed at launch and has never mapped the regulatory perimeter of each entity often discovers, during a renewal exercise, that one subsidiary is providing services to clients in a jurisdiction where neither it nor the parent holds a licence.
Under MiCA, the passporting mechanism is available to a CASP authorised in one member state to offer services across the EU and EEA. But passporting is activity-specific: it covers only the activities listed in the original authorisation. A CASP authorised in Lithuania for exchange services cannot passport a custody service it has not been authorised to provide. Regulators in the host member state – supervised in part by their own ESMA-aligned national competent authority – retain the right to take measures against a passporting CASP that is operating outside its authorised perimeter in their jurisdiction.
The interplay between the Dubai VARA mainland regime and the ADGM/FSRA framework in Abu Dhabi creates similar complications for groups with a UAE presence. An entity licensed by FSRA to conduct regulated virtual asset activities in ADGM cannot rely on that authorisation to conduct mainland Dubai-facing activities. The two regimes are legally distinct. A group that receives clients from both markets must either hold a separate VARA authorisation or structure its client-facing activities so that mainland Dubai clients are served exclusively by the VARA-licensed entity.
In the BVI and Cayman Islands, the VASP registration frameworks are primarily designed to address the AML/CFT perimeter; they do not in themselves authorise the VASP to solicit clients in other jurisdictions. A BVI-registered VASP offering services to EU retail clients is subject to MiCA regardless of where the entity sits. This is the principle that client-facing activities are regulated at the point of impact, not the point of incorporation – and it is the single most common source of the multi-licence exposure that surfaces during renewal and variation reviews.
Operators we advise routinely discover, during a renewal preparation exercise, that their actual client base has drifted materially from the jurisdiction profile that was documented at the time of the original application. A platform that launched with a predominantly retail EU client base and has since acquired institutional clients in Singapore, Hong Kong and the US is now touching at least four distinct regulatory regimes. The renewal of the EU CASP authorisation does not resolve the MAS, SFC, or SEC/CFTC exposure.
What are the most common structural errors that surface at renewal?
The five structural errors that most frequently derail renewal applications – or trigger variation requirements that were not anticipated – are well-documented across the regimes we work across. The first is undisclosed changes of control. A private equity injection, a token-for-equity swap, or a restructuring that moves the ultimate beneficial owner above the licensed entity can all constitute a change of control requiring prior regulatory notification. Operators that treat pre-licensing ownership requirements as a one-time disclosure and not as an ongoing obligation routinely find that their renewal applications are queried or paused pending a full ownership re-assessment.
The second is product-scope drift. As described above, adding custody, lending, staking reward distribution or structured products to an exchange platform without a formal variation is operating outside the licence perimeter. The third error is AML programme staleness. Most regimes require the AML/CFT programme to be reviewed and updated on a defined cycle; a renewal application that submits a programme last updated several years earlier will be treated as materially deficient.
The fourth error is the technology-change blind spot. Migrating from a centralised to a partially non-custodial architecture, integrating a third-party smart-contract settlement layer, or adopting a new blockchain network as a primary settlement rail can all constitute material changes to the technology risk profile that the regulator assessed at the time of original authorisation. Most regime guidance makes clear that a material technology change should be notified, even if it does not in itself require a formal variation. Operators that treat their technology stack as internal and not regulatory fail to identify the notification point.
The fifth error, and the most consequential, is the gap-period problem. When a renewal application is filed late, or when a variation application is filed after the relevant change has already been implemented, the operator has been operating in a non-compliant state for the intervening period. Regulators distinguish between prospective compliance (the application was filed before the change or before the deadline) and retrospective disclosure (the change happened and is now being reported). The latter is treated as a breach. The former may not be.
What does the variation process look like in practice?
A formal variation application under any of the major regimes is structurally similar to a new authorisation application, but targeted at the specific change being proposed. The operator must demonstrate that the proposed expanded activity falls within the applicable regulatory perimeter, that the entity has the systems, controls, capital and personnel to conduct the new activity, and that the AML/CFT framework covers the new activity and its associated risks. The regulator reviews the application against the same fitness-and-propriety and systems-and-controls standards that applied to the original authorisation, but focused on the incremental activity.
Under VARA, the activity-based licence model means that a variation to add a new regulated activity – say, adding virtual asset lending to an existing exchange licence – requires a separate activity licence application for the lending component. The process involves submitting updated rulebook compliance documentation, revised AML/KYC procedures, and demonstrating the capital and operational infrastructure for the lending activity specifically. The timeline is not published as a binding commitment but is generally comparable to the original authorisation process for the relevant activity category.
Under MiCA, a CASP applying to extend its authorisation to cover additional CASP services must submit an application to the national competent authority in its home member state. The NCA has a defined assessment period; if it does not respond within that period, the extension is deemed granted – but the deemed-grant mechanism should not be relied upon without qualified legal confirmation that the application was complete and properly submitted.
Under the MAS Payment Services Act, a major payment institution that wishes to add a new type of payment service must apply for a variation of its licence. MAS will assess whether the entity's systems, controls and capital remain adequate for the expanded scope. The notification timelines for prescribed changes are fixed; missing them is a standalone breach.
In our cross-border practice, we have seen variation applications delayed – and in some cases refused – because the operator submitted an application for the change it wanted to make, without resolving the prior compliance gap (the period during which the activity was already being conducted without authorisation). We strongly advise addressing the compliance history in the application, rather than presenting the variation as a purely forward-looking request. Regulators have access to transaction data, complaint records and, increasingly, on-chain analytics. A variation application that does not acknowledge a prior period of out-of-scope operation is less credible than one that discloses it and explains the remediation steps already taken.
CTA #2 — Mid-page, for the operator who has already encountered a problem
If a variation application has stalled, been queried on compliance-history grounds, or if your business has been operating outside its authorised perimeter for a period, a second read on the structure and the history can surface both the problem and the route back. Regulators in every major hub distinguish between operators that self-identify and remediate versus those that wait to be found. The window for the former is narrow. Map your options now.
A recent cross-border variation matter
In a recent cross-border licensing matter, a digital-asset exchange operator holding a CASP authorisation in an EU member state sought to add custody and staking services to its product set. The operator had already begun offering custody to a small group of institutional clients on a trial basis, treating it as an extension of its existing exchange infrastructure. When it approached us ahead of a scheduled renewal, the compliance review identified that custody and staking both required a formal variation – and that the trial period had created a retroactive compliance gap. We structured the variation application to include a disclosure of the trial period, a remediation note documenting the steps taken to bring those clients within the authorised perimeter on an interim basis, and a forward-looking compliance programme for the expanded activities. The NCA accepted the application and issued the variation without imposing a formal sanction. The outcome reflected the regulator's general willingness to treat proactive disclosure favourably relative to continued concealment – but the engagement needed to begin before the renewal filing, not after.
Decision matrix: which operators face which renewal and variation risks?
The operator profile determines the renewal and variation risk profile in predictable ways. The matrix below describes four common profiles in qualitative terms.
Profile A: single-jurisdiction EU CASP, product set stable. This operator faces the lowest variation risk. The primary renewal concern is continuous compliance documentation – AML programme currency, fitness-and-propriety refresh, technology audit – and the passporting notification obligations if services are marketed into other EU member states. The key risk is underinvesting in renewal preparation and submitting incomplete documentation, which triggers a regulator query and delays the renewal confirmation.
Profile B: multi-activity operator in Dubai (VARA), growing into custody and lending. This operator faces the highest variation risk in the short term. Each new regulated activity requires a separate activity licence. The operator must apply for each expansion before implementing it. The timeline for each activity variation is comparable to the original authorisation. The capital and operational requirements for lending and custody are materially more demanding than for an exchange licence alone. The key risk is product launch before the variation is granted.
Profile C: operator with a BVI or Cayman VASP registration serving EU, Singapore and US clients. This operator faces multi-jurisdictional exposure that the offshore registration does not resolve. A BVI registration satisfies BVI AML/CFT requirements; it does not authorise the operator to serve EU clients under MiCA, Singapore clients under the Payment Services Act, or US clients under the SEC, CFTC or state money-transmitter frameworks. The operator needs a licence stack that reflects its actual client geography. The key risk is that a renewal of the offshore registration creates a false sense of compliance across the full business.
Profile D: group with legacy national VASP registrations transitioning to MiCA. This operator faces the most time-sensitive risk. Transitional grandfathering periods under MiCA are finite. The operator must submit a full CASP authorisation application within the applicable transition window or cease the relevant activities in the affected member state. The key risk is treating the grandfathering period as an operational extension rather than a compliance deadline.
Is a single offshore licence enough for a global digital-asset business?
The most consequential myth in digital-asset licensing is that a single well-chosen offshore registration insulates a business from regulatory exposure in the jurisdictions where its clients are located. It does not. The principle that applies across every major regime – MiCA in the EU, the Payment Services Act in Singapore, the SFC VASP regime in Hong Kong, the FCA registration in the UK – is that the regulation follows the client relationship, not the entity's place of incorporation. A business that solicits EU retail clients from a non-EU entity is subject to MiCA regardless of where that entity is registered.
The offshore registration has legitimate uses. A BVI or Cayman holding structure can serve valid tax, corporate governance and operational purposes. A VASP registration in those jurisdictions satisfies the local AML/CFT requirements and provides a credible compliance foundation for banking relationships. But neither replaces the client-facing authorisation required in the jurisdictions where those clients are located.
Operators we advise that have built their structure on a single offshore foundation typically face one of two outcomes: a gradual accumulation of client-jurisdiction exposure that surfaces during a compliance review or a banking due-diligence process, or a direct regulatory inquiry from a client-jurisdiction regulator that has identified the solicitation activity. Neither outcome is resolved by pointing to the offshore registration. The route to resolution is a properly scoped licence stack – one entity, one licence, one client population per regulated activity per jurisdiction – managed as an ongoing compliance programme rather than a one-time filing.
We regularly advise operators on mapping the licence, banking and tax stack before they commit to a structure. The mapping exercise is significantly cheaper before the structure is built than after the enforcement inquiry lands.
Related at OBOLUS
- Licensing and registration for digital-asset businesses – Full-scope guidance on VASP and CASP authorisation across the major regimes.
- VASP licence application in Gibraltar – Jurisdiction-specific analysis of the Gibraltar DLT regulatory regime and application process.
- PSP and acquiring agreement in Kazakhstan (AIFC) – Structuring payment service provider arrangements within the AIFC common-law framework.
FAQ
How long does a crypto licence take to obtain?
Timelines vary substantially by regime and by how complete the application is at submission. Under the MiCA CASP framework, the national competent authority has a defined assessment period after a complete application is submitted; applicants in faster EU member states have historically received decisions in a matter of months. Under VARA in Dubai and MAS in Singapore, timelines are influenced by the complexity of the activity scope, the quality of AML documentation, and the regulator's current workload. An incomplete application resets the clock. Build in adequate preparation time – typically several weeks of internal document-gathering before you file.
Which jurisdiction is best for licensing my crypto business?
There is no single best jurisdiction. The right choice turns on the client geography, the regulated activities, the banking requirements and the operator's capital position. An EU-facing business needs a CASP authorisation under MiCA for passporting access; a primarily institutional business in the Gulf may benefit from a VARA or ADGM/FSRA authorisation; a business serving Asian markets needs to consider MAS or SFC licensing. Most operators of scale require a licence stack across more than one jurisdiction. The starting point is always mapping the actual client base and regulated activities against each regime that applies to them.
Do I need a separate custody licence?
In most major regimes, yes. Custody is a separately defined regulated activity under MiCA, the VARA rulebooks, the MAS Payment Services Act, and the SFC VASP framework. An operator authorised to run an exchange is not automatically authorised to hold client assets in custody. Adding custody without a formal variation is operating outside the authorised perimeter. The capital and operational requirements for custody are typically more demanding than for exchange activities alone. If custody is part of your product roadmap, it needs to be in the authorisation scope from the outset, or addressed through a formal variation before the activity begins.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence, banking and tax stack across operating, custody and payment layers before you commit – a scoped engagement that consistently surfaces exposure before it becomes enforcement. Digital assets are the whole of our practice. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums. To discuss your situation, contact info@oboluslaw.com.
By Roman Levitt, Technology & DeFi Counsel – specialising in the intersection of digital-asset technology architecture and regulatory authorisation requirements across multi-jurisdiction licence stacks.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.