Digital-Asset Licensing in United States (federal + state MTL)
Operating a digital-asset business in or toward the United States without the correct authorisations is one of the fastest ways to attract enforcement action from multiple agencies simultaneously. The U.S. regime is not a single licence — it is a layered matrix of federal obligations under the Bank Secrecy Act administered by FinCEN, potential securities or commodities registration requirements under the SEC and CFTC, and individual money-transmitter licences (MTLs) required by each state where customers reside. An exchange, custodian or token issuer that underestimates that stack risks frozen banking rails, civil penalties and criminal referral. This page maps the regime for inbound and domestic operators and sets out what a rigorous licensing programme looks like in practice.
The United States imposes the most disaggregated digital-asset licensing requirements of any major economy. Federal registration with FinCEN as a money services business (MSB) is the baseline. State MTLs, a NYDFS BitLicense for New York activity, and potential SEC or CFTC registration layer on top depending on the products offered and the states served. There is no single federal VASP licence equivalent, and no passporting mechanism between states. Every operator targeting U.S. persons must build its authorisation stack from the ground up.
The sections below address each layer in turn — the federal baseline, state MTL requirements, the New York BitLicense, securities and commodities considerations, the cross-border reality for non-U.S. platforms, the AML and Travel Rule posture, and how the U.S. stack compares with other flagship hubs for an inbound operator deciding where to anchor its licensing programme.
Who Needs a Licence to Operate in the U.S.?
Any business that transmits value in digital-asset form — including exchanges, custodians, payment processors, OTC desks and stablecoin issuers — will generally require federal MSB registration and, in most cases, state MTLs for each state in which customers are located. The jurisdictional trigger is not where the company is incorporated. It is where the users are. A Cayman-incorporated exchange with U.S. retail users is, in the view of U.S. regulators, conducting money transmission in the United States and must hold the corresponding authorisations — or actively block U.S. persons and maintain documented controls to that effect.
FinCEN's MSB registration under the applicable Bank Secrecy Act provisions is the entry-level federal requirement. It is a registration, not a substantive licence — it triggers AML programme, recordkeeping and reporting obligations, including Suspicious Activity Reports (SARs). Registration does not, however, substitute for state MTLs, and it does not resolve securities or commodities questions.
Whether a digital asset is a security is determined by the substance of the rights it confers, not by the label it carries. The SEC has applied the Howey test — the principle that an investment of money in a common enterprise with an expectation of profit from others' efforts constitutes an investment contract — to a wide range of tokens. CFTC jurisdiction attaches where a token is treated as a commodity. In our practice, the securities/commodity question is often the first structural issue to resolve before a licensing programme is designed, because the answer determines which federal regulator holds primary authority and whether exchange-level or broker-dealer registration is required.
The NYDFS BitLicense remains the most demanding single-state digital-asset authorisation in the country. Launched in 2015, it applies to any virtual currency business activity involving New York or New York residents. Its requirements — capital, cybersecurity, AML, custody standards and change-of-control approvals — go significantly beyond most state MTL regimes. For many operators, the commercial necessity of serving New York customers means the BitLicense is unavoidable; others explicitly geo-block New York until their compliance infrastructure can support it.
For a scoped assessment of your U.S. licensing exposure across federal and state layers, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts — the entity structure, the product set, the user geography — change the analysis materially.
How Do State Money-Transmitter Licences Work for Crypto?
State MTLs are the most operationally demanding component of U.S. digital-asset compliance: there are over 50 separate licensing regimes, each with its own application form, capital requirement, surety bond, examination schedule and renewal cycle. Most states have extended their money-transmission statutes to cover virtual currency transmission, though the precise statutory definition of covered activity varies considerably. A handful of states have enacted bespoke digital-asset frameworks; most rely on adapted money-transmission law.
The Nationwide Multistate Licensing System (NMLS) centralises application filing for many states, but centralised filing does not mean uniform requirements. Capital minimums, permissible-investment rules, net-worth thresholds and examination frequency differ state by state. Some states — notably Wyoming, which passed a series of digital-asset statutes creating a distinct regulatory space — have positioned themselves as relatively accommodating. Others impose requirements that rival the NYDFS BitLicense in scope. The practical consequence is that a business serving customers in 30 states must manage 30 separate licence relationships, renewal calendars and regulatory examination programmes.
Operators we advise routinely underestimate the ongoing compliance burden of a full U.S. MTL stack. It is not a one-time application exercise. It is a permanent regulatory relationship with each state's licensing authority, requiring dedicated compliance staff, annual audited financials in several jurisdictions and rapid response to examination requests. Building that infrastructure before launch — rather than retrofitting it after a cease-and-desist letter — is the correct sequencing.
A practical decision point arises for international operators: whether to pursue a full 50-state stack from the outset, to phase licensing by commercial priority, or to hold back from U.S. customers entirely until the infrastructure is in place. Each carries different risk profiles. Phased licensing is common in our experience, but it requires watertight geoblocking and documented evidence of its effectiveness for unlicensed states — a point regulators scrutinise closely.
What Does the NYDFS BitLicense Require?
The NYDFS BitLicense is the most substantive digital-asset-specific authorisation in the United States, imposing detailed requirements on capital adequacy, cybersecurity, AML controls, custody safeguarding and governance that go beyond the baseline MTL. It applies to any entity engaging in virtual currency business activity involving New York or New York residents — defined broadly to include exchange, transfer, custody, issuance and administration of virtual currency.
The NYDFS has developed a track record of rigorous examination and significant enforcement actions against virtual currency licensees. Cybersecurity requirements under the applicable NYDFS cyber regulation are among the most detailed in the U.S. financial sector. Custody standards require segregation of customer assets and independent audits. The AML programme requirements align with federal Bank Secrecy Act standards but are examined directly by NYDFS examiners who have developed significant crypto-specific expertise.
Change-of-control approvals — required when ownership or control of a licensee changes above defined thresholds — have proved to be a material transaction risk in M&A and investment rounds involving BitLicense holders. We have seen deals where the BitLicense transfer timeline was the critical path item for closing. Any acquisition or significant investment in a NYDFS-licensed entity should factor the approval process into the transaction timeline from the outset.
NYDFS has also moved to address stablecoins specifically. Dollar-backed stablecoins issued or held in New York must comply with guidance on reserve composition, attestation and redemption standards. Issuers operating under the BitLicense regime must satisfy these conditions. For a non-U.S. stablecoin issuer considering U.S. distribution, this is a threshold structural question.
How Do SEC and CFTC Jurisdiction Affect Digital-Asset Businesses?
The SEC and CFTC exercise overlapping and sometimes contested jurisdiction over digital assets, depending on whether a given token is classified as a security or a commodity. That classification question is the central legal risk for any platform, issuer or fund operating in the U.S. digital-asset space, and it has been the subject of active regulatory and judicial development over recent years.
For exchange operators, the securities question is existential: trading platforms that list tokens the SEC characterises as unregistered securities face registration requirements as national securities exchanges or broker-dealers, both of which carry compliance obligations far more demanding than MSB registration. The CFTC, for its part, asserts jurisdiction over crypto derivatives, futures and leveraged products. A platform offering both spot and derivatives products may face dual federal agency oversight.
Token issuers must conduct a genuine securities-law analysis before any offering or sale. The application of the Howey test is fact-specific and turns on the economic reality of the offering, not on its technical design. In our practice, operators who skip this step and rely on informal "utility token" characterisations face the greatest exposure — the label has no legal effect if the substance satisfies the investment-contract definition.
Investment advisers and fund managers with digital-asset exposure must also assess their obligations under the applicable federal investment-adviser and investment-company provisions. Family offices, VC funds and DeFi-adjacent structures have each faced regulatory scrutiny in this space. The cross-border dimension compounds the analysis: a fund managed from a non-U.S. jurisdiction that raises from U.S. investors must assess whether the applicable exemptions from registration are properly structured and maintained.
If you are structuring a token offering, an exchange or a fund with any U.S. nexus, write to OBOLUS at info@oboluslaw.com before committing to the design. A second read at the structural stage is materially cheaper than a reconfiguration after a Wells notice.
What Are the AML and Travel Rule Obligations in the U.S.?
U.S. AML obligations for digital-asset businesses are anchored in the Bank Secrecy Act, administered by FinCEN, and require MSBs — including crypto exchanges, custodians and money transmitters — to implement a written AML programme, conduct customer due diligence, file SARs and submit Currency Transaction Reports where applicable. FinCEN's guidance confirms that convertible virtual currency exchanges and administrators are MSBs subject to the full BSA compliance stack.
The Travel Rule — the obligation, derived from FATF Recommendation 15, to pass originator and beneficiary identifying information alongside value transfers — applies to U.S. money transmitters under the BSA's recordkeeping and transmittal rules. The applicable threshold for Travel Rule data collection and transmission in the U.S. context has historically been set at a level lower than the international FATF threshold for virtual asset transfers, though operators should confirm current FinCEN guidance on applicable thresholds as these continue to evolve.
Sanctions compliance is a parallel but distinct obligation. The Office of Foreign Assets Control (OFAC) has designated digital-asset addresses and entities, and has brought enforcement actions against platforms for facilitating transactions involving sanctioned parties. An effective sanctions compliance programme for a U.S.-nexus digital-asset business must include real-time screening of counterparty addresses and robust escalation procedures — not merely a static list check at account opening.
State-level AML requirements under MSB frameworks generally require BSA-equivalent programmes and may impose additional obligations. NYDFS, for example, conducts independent AML examinations of its virtual currency licensees and has issued consent orders addressing AML programme deficiencies. The practical effect is that a BitLicense holder faces AML oversight from both FinCEN and NYDFS — not an either/or proposition.
How Does the U.S. Licensing Stack Affect Non-U.S. Operators?
Non-U.S. platforms targeting U.S. customers face the full weight of the U.S. licensing matrix without the benefit of an existing U.S. regulatory relationship. The jurisdictional reach of U.S. financial-services law is broad: the question is not whether the platform is incorporated in the U.S., but whether it actively solicits or serves U.S. persons. Enforcement history demonstrates that regulators and prosecutors have been willing to pursue non-U.S. entities aggressively where a U.S. nexus exists.
For a non-U.S. operator, the strategic options are broadly three. First, obtain the required U.S. authorisations — MSB registration, relevant state MTLs, applicable federal registrations — before opening to U.S. customers. Second, implement documented and audited geoblocking that excludes U.S. persons from all services, and maintain that exclusion rigorously. Third, establish a separate U.S.-regulated subsidiary that operates under the full U.S. compliance stack while the offshore parent serves non-U.S. markets. Each option has a different cost, timeline and risk profile.
In our cross-border practice, the most common error we see is operators adopting the geoblocking option without implementing it with the rigour that would satisfy a regulator. IP-based blocks are the floor, not the ceiling. Effective geoblocking requires controls at account opening, transaction monitoring, marketing restrictions and documented periodic testing. A regulator presented with a pattern of U.S.-resident transactions on a "geoblocked" platform will not accept the existence of a technical block as a complete answer.
The interaction between U.S. requirements and other flagship licensing regimes — MiCA in the EU, VARA in Dubai, MAS in Singapore — is a routine part of cross-border structuring. A business holding a MiCA CASP authorisation gains EU passporting but no U.S. safe harbour. A business licensed under the VARA regime in Dubai that also serves U.S. persons must still hold U.S. authorisations for those users. Licensing in one jurisdiction does not displace the obligations triggered by activity in another. This is the core reason the "single offshore licence" myth — the assumption that one authorisation suffices for global operations — fails in practice.
In a recent cross-border structuring matter, an Asia-Pacific exchange sought to expand into European and U.S. markets. We mapped the full authorisation matrix across the relevant jurisdictions, identified that the proposed U.S. entry structure would trigger federal and state registration requirements in six states from day one, and advised on a phased entry sequencing that aligned the geoblocking and licensing timelines. The operator entered the market with a defensible compliance posture rather than a retroactive remediation exercise.
How Does the U.S. Compare With Other Major Licensing Hubs?
For an operator weighing where to anchor its primary licensing structure, the U.S. regime presents a distinctive risk/reward profile relative to other flagship hubs — demanding in cost and complexity, but critical for access to the world's deepest capital markets and largest retail investor base.
The EU's MiCA regime, administered by ESMA and national competent authorities, offers a single CASP authorisation that passports across 27 member states — a significant structural advantage over the U.S. state-by-state MTL stack. MiCA imposes substantive capital and organisational requirements, but the regulatory relationship is with one primary NCA rather than 50 separate state agencies. For operators primarily serving European clients, MiCA-first is a rational sequencing choice; U.S. access can be layered on where commercial necessity justifies the incremental compliance investment.
VARA in Dubai offers an activity-based licensing model with a single regulator, competitive timelines by comparison to the U.S. stack, and a growing institutional market. It does not provide U.S. market access, but for operators whose core customer base is in the Middle East, Asia or emerging markets, it offers a faster path to regulated status than a full U.S. programme. Similar logic applies to the MAS regime in Singapore under the Payment Services Act, which has established itself as Asia's most credible digital-asset regulatory environment and offers a structured path to regulated status with a single regulator.
Profile A — a globally ambitious exchange that must serve U.S. customers: the U.S. licensing stack is unavoidable; the design question is sequencing and entity structure, with a U.S. subsidiary holding the federal and state authorisations while the parent is licensed in a more streamlined hub for non-U.S. activity. Timeline to meaningful U.S. market access is measured in months to years, not weeks.
Profile B — an institutional-focused custodian or OTC desk primarily serving professional clients outside the U.S.: a MiCA CASP or VARA licence may provide the primary regulated framework, with U.S. activity either excluded or structured through a separately capitalised U.S. registered entity once AUM justifies the investment. This profile can reach regulated status faster and at lower initial compliance cost.
Profile C — a token issuer planning a public offering or exchange listing: the U.S. securities analysis is the first question regardless of where the issuer is incorporated. The Howey analysis runs on the substance of the offering. If the token is a security, the issuer faces a binary choice — register with the SEC, or structure an offering that does not involve U.S. persons. Neither path is simple; both require early legal engagement before the token design is finalised.
To map the licence, banking and entity stack for your U.S. entry or cross-border structure, message OBOLUS at info@oboluslaw.com or via t.me/oboluslaw.
Related at OBOLUS
- Licensing & Registration for Digital-Asset Businesses – our full-service licensing practice across 70+ jurisdictions and authority types
- Licence Renewal and Variation in the United Kingdom – FCA MLR registration, variation and ongoing compliance for UK-authorised operators
- VASP Business Risk Assessment for Established Operators – structured AML, Travel Rule and sanctions risk reviews for operating businesses
FAQ
How long does a crypto licence take to obtain?
Timelines vary significantly by jurisdiction and licence type. A FinCEN MSB registration can be completed relatively quickly once the AML programme is in place. State MTL applications typically take several months per state, with more demanding states — including New York under the BitLicense regime — taking considerably longer. A full multi-state MTL stack built in sequence can take a year or more from first application to final approval. We advise clients to build the licensing timeline into their commercial launch plan from the outset.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. The right jurisdiction depends on where your customers are, what products you offer, your capital base and your operational capacity. For U.S.-facing businesses, U.S. authorisations are unavoidable regardless of where the entity is incorporated. For primarily non-U.S. businesses, MiCA, VARA, MAS and other flagship regimes each offer distinct advantages. A common mistake is selecting a jurisdiction for its perceived ease rather than for its alignment with the actual customer base and product set. We map the decision across commercial, regulatory and banking dimensions before recommending a structure.
Do I need a separate custody licence?
Custody of digital assets is a regulated activity in most significant jurisdictions. In the U.S., state trust company charters or specific custodial authorisations may be required depending on the assets held and the states involved. NYDFS has specific custody requirements within the BitLicense framework. Under MiCA in the EU, custody is a regulated CASP activity requiring separate authorisation. Whether a standalone custody licence is required — or whether custody can be conducted within a broader authorisation — turns on the jurisdiction, the asset types and the client categories. Early legal analysis is essential before custody services are offered.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit — identifying exposure before it becomes enforcement. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst — specialising in multi-jurisdictional digital-asset authorisation strategies and U.S. federal and state licensing programme design for inbound and domestic operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.