EST · MMXXVI
Home/Jurisdictions/Germany/Economic substance for licensed vasps in Germany (BaFin)
Licensing & Registration

Economic substance for licensed vasps in Germany (BaFin)

Economic substance for licensed vasps in Germany (BaFin). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to O

Operating a virtual asset service provider (VASP) under BaFin supervision in Germany is not simply a matter of filing paperwork from abroad. Germany's regulatory regime – anchored in the Kreditwesengesetz (Banking Act) as extended to crypto custody, and now transitioning under MiCA (the Markets in Crypto-Assets Regulation) toward a unified EU CASP authorisation – demands demonstrable economic substance on German soil. Operators who assume a letterbox entity will satisfy BaFin face enforcement, revoked authorisation, and severed banking relationships. This page sets out what substance means in practice, how the authorisation process works, where cross-border structures create friction, and how to build an entity that survives supervisory scrutiny.

What Does Economic Substance Mean Under BaFin?

Economic substance, under the BaFin supervisory regime, means that a licensed VASP or CASP (crypto-asset service provider, the MiCA-era term) maintains genuine decision-making authority, qualified personnel, and operational infrastructure in Germany – not a forwarding address and a nominal director. BaFin applies this requirement as a precondition to authorisation and as an ongoing supervisory expectation throughout the life of a licence.

In practical terms, BaFin expects to see a managing director who is resident and reachable, with genuine responsibility for day-to-day compliance. The regulator scrutinises whether risk management, internal audit, and compliance functions are staffed locally or whether they are merely outsourced back to a parent entity elsewhere. Outsourcing arrangements are permissible under the applicable regime, but they must not hollow out the German entity's accountability.

Germany's position within the EU adds a second layer. Under MiCA, a CASP authorised in Germany passports across all EU/EEA member states. That passporting value makes the German licence commercially attractive – but it also means ESMA and the European college of supervisors will scrutinise the substance of the home-state entity. A structure that cannot withstand ESMA-level review is unlikely to survive BaFin's pre-authorisation assessment either.

In our licensing practice, we regularly advise inbound operators – particularly those building from a non-EU parent – that the first question is not "which EU jurisdiction is cheapest?" but "where can we genuinely operate?" Germany rewards operators who commit to it. It is not designed for regulatory arbitrage.

Who Needs a BaFin VASP or CASP Authorisation?

Any entity offering crypto custody, trading, brokerage, exchange, or related services to clients connected to the German market requires authorisation under the applicable BaFin regime – regardless of where the entity is incorporated. BaFin applies a functional test: the relevant question is whether the service reaches German clients, not merely whether the entity is registered in Germany.

The pre-MiCA route involved registration or authorisation under the Banking Act and the companion provisions covering crypto custody business (Kryptoverwahrgeschäft). Under MiCA, that transitions to CASP authorisation under the regulation itself, with BaFin acting as the national competent authority. Entities already registered under the prior regime will need to assess their transition timeline under the applicable MiCA grandfathering provisions.

The practical perimeter is wider than most operators initially assume. A token issuer making a public offer into Germany may need a MiCA whitepaper notification. An exchange serving German retail clients needs the full CASP authorisation. A custodian holding assets for German institutional investors falls squarely within the custody category. A platform offering staking-as-a-service or lending to German users is in a grey zone that BaFin has indicated it will treat with the same seriousness as a licensed activity.

Operators based outside the EU – in the UAE, Singapore, or the United States – who want to serve German or EU clients cannot rely on an offshore licence alone. A common assumption is that a single VASP registration in a permissive offshore jurisdiction is sufficient to serve clients globally. It is not. Accessing German clients requires German (or at minimum EU) authorisation, or a strict reverse-solicitation posture that in practice is very difficult to maintain. We have seen enforcement actions proceed against entities that believed their offshore licence provided a shield; it did not.

For a scoped assessment of your entity's exposure to BaFin's perimeter, contact OBOLUS at info@oboluslaw.com. The process above describes the standard perimeter analysis. Your facts – the entity structure, the user base, the asset types offered – change the analysis materially. Map your options before you commit to a structure.

What Is the BaFin Authorisation Process for a VASP?

The BaFin authorisation process for a CASP or VASP is a multi-stage administrative procedure that rewards preparation and penalises incomplete applications. The first step is internal: building the substance before the application, not after.

BaFin's pre-application engagement model allows prospective applicants to submit preliminary inquiries. This is valuable and we recommend using it. The regulator's published guidance and its supervisory communications make clear that it expects a fully assembled management team, an AML/KYC compliance framework aligned with FATF Recommendation 15 and the Travel Rule (the obligation to pass originator and beneficiary data with a transfer), internal governance documentation, and a detailed business plan before the formal file is submitted.

The authorisation timeline varies by complexity and completeness of the application. Where applications are well-prepared and substance is genuinely in place, the process is typically measured in months rather than quarters. Incomplete applications – missing the qualified management director, lacking a documented risk framework, or showing obvious outsourcing of all real functions – will be returned or queried at length. In our practice, we have observed that the most common cause of delay is not BaFin's processing time but the applicant's failure to have substance in place before filing.

Key components of a complete BaFin CASP application include: a legal entity registered in Germany (GmbH or AG in most cases); at least one managing director with regulatory fitness-and-propriety clearance; a documented compliance and AML programme meeting the applicable German AML provisions; an IT and security framework; an internal audit function; and capital at the level required under the applicable category of CASP licence. Capital requirements vary by licence category and are set by the applicable regime – operators should not rely on any figure in the public domain without verifying it against the current BaFin guidance and MiCA implementing measures.

What Substance Requirements Does BaFin Enforce in Practice?

BaFin's substance expectations go beyond the minimum legal form and require that the German entity be the genuine locus of risk and decision-making for its regulated activities. This is enforced through ongoing supervision, not just at authorisation.

Personnel substance is the most scrutinised element. The managing directors of the German entity must not be "figureheads." BaFin expects them to understand the business model, to be available to the regulator, and to be accountable for compliance outcomes. Where a VASP is a subsidiary of a larger group – a common structure for inbound operators – BaFin will look through group reporting lines to assess whether the German directors have genuine authority or are simply executing instructions from a parent board seated outside the EU.

Operational substance covers the systems and controls that actually run the business. If the exchange engine, the custody infrastructure, the customer onboarding system, and the AML screening tool are all operated by affiliates abroad, BaFin will assess whether meaningful oversight and control rests in Germany. Outsourcing contracts must satisfy the applicable requirements, including the ability to terminate, audit, and substitute service providers. The German entity must be able to demonstrate it could continue regulated operations if an intragroup service provider were withdrawn.

Physical presence is relevant but not absolute. BaFin does not require a large German office. What it requires is a genuine operational footprint – registered office, key personnel resident or regularly present, and meaningful decision-making occurring in-country. A nominal address at a registered-agent premises will not satisfy this standard.

In a recent licensing matter, a payments group seeking to expand its crypto custody offering into Germany had structured its entity with a sole director based in a different EU member state and all operational functions contracted to a parent company in Asia. We advised a restructuring of the management layer and the creation of a Germany-based compliance officer role before application. The substantive rework took several months. The alternative – filing the original structure – would almost certainly have drawn an objection from BaFin and reset the clock entirely.

How Do Tax and Banking Interact With a German Crypto Licence?

A BaFin-authorised VASP does not operate in a vacuum; the German entity sits at the intersection of EU financial regulation, German tax law, and a banking environment that has historically been cautious toward crypto businesses. Managing all three simultaneously is the practical challenge that determines whether a German licence delivers its commercial value.

On the tax side, Germany taxes crypto assets under a detailed framework that distinguishes between trading income, custody income, and capital gains depending on the entity structure and holding period. For corporate entities – the standard structure for a licensed VASP – the applicable corporate income tax and trade tax regimes apply to operating income, and the treatment of token inventories, staking rewards, and treasury positions requires specific analysis. We work alongside tax counsel on this layer; the substance decisions that satisfy BaFin also affect the tax characterisation of the German entity's profits, so the two analyses must be run together.

Banking access for German crypto VASPs has improved materially as the sector has matured, but it remains a genuine operational risk. German domestic banks have been cautious. EU-licensed challenger banks and specialist payment institutions in other member states have provided the primary banking rails for many German-authorised VASPs in practice. The MiCA authorisation and its passporting architecture should, over time, improve access to banking services across the EU – but operators should not assume that a BaFin licence resolves their banking challenges automatically.

For operators whose holding structure sits outside the EU – a common configuration where the ultimate parent is in the UAE, the Cayman Islands, or Singapore – the German VASP is typically a regulated subsidiary within a larger group. Transfer pricing between the German entity and its affiliates, the substance requirements for cross-border service agreements, and the German controlled foreign corporation rules all need to be addressed. Allied counsel in the relevant jurisdiction handles the non-EU layer; our role is to ensure the German entity's structure is coherent on both the regulatory and the tax dimensions.

If a prior application has stalled or a banking relationship has been refused, a structural review can surface the reason and identify the route back. Write to OBOLUS at info@oboluslaw.com or message us via t.me/oboluslaw. Map your options.

What AML and Travel Rule Obligations Apply to German VASPs?

German VASPs operate under one of the most demanding AML/CFT compliance environments in the EU, combining FATF Recommendation 15 obligations, the applicable German AML Act provisions, and the Travel Rule requirements that apply to crypto-asset transfers above the applicable threshold.

The Travel Rule requires that a VASP collect and transmit originator and beneficiary information alongside a virtual-asset transfer. In the EU context, this obligation is operationalised through the Transfer of Funds Regulation as extended to crypto-assets under MiCA. The practical challenge is interoperability: the German VASP must be able to exchange Travel Rule data with counterpart VASPs globally, including in jurisdictions where the Travel Rule is implemented differently or not at all. This creates a sunrise problem – and a compliance gap – for operators building cross-border transfer corridors.

BaFin has signalled that it expects VASPs to have implemented operational Travel Rule compliance, including a documented approach to the "unhosted wallet" question (transactions involving wallets not held at a regulated institution). The regulator's supervisory communications make clear that inadequate AML/CFT frameworks are among the most common grounds for refusing or conditioning an authorisation.

Operators with a cross-border client base – serving users in multiple EU member states under the German passport – face the additional complexity of aligning their KYC and customer due diligence standards across jurisdictions. The MiCA CASP authorisation does not eliminate national-level AML obligations; it layers EU requirements on top of existing domestic regimes. For a German-authorised CASP passporting into, say, France or the Netherlands, the operator must understand both the baseline German obligations and any host-state supervisory expectations.

Which Operator Profile Is Best Suited to a German BaFin Authorisation?

Germany is not the right primary licence jurisdiction for every operator. The decision to anchor in Germany turns on a set of specific commercial and structural factors.

Profile A – EU-market-first exchange or custodian. An operator whose primary commercial target is the EU retail or institutional market, whose management team is Europe-based, and who wants the reputational weight of a BaFin authorisation alongside EU-wide passporting rights is a natural fit for Germany. The authorisation is substantive and takes time to obtain, but the resulting CASP passport covers the full EU/EEA without additional licensing in each member state. The key risk is the substance burden: the German entity must be genuine, and the management personnel must be prepared for ongoing supervisory engagement with BaFin.

Profile B – Offshore operator seeking an EU regulatory bridge. An operator based in Dubai, Singapore, or the Cayman Islands who wants to access EU clients faces a harder analysis. Germany can serve as the EU regulatory bridge, but only if the operator is prepared to build genuine substance there. A structural arrangement where the German entity is a thin subsidiary and all real operations remain offshore will not satisfy BaFin. For this profile, the question is whether the commitment to EU substance is genuine; if it is, Germany is a credible choice. If not, the operator should consider whether EU market access is actually a current priority.

Profile C – Operator already registered in another EU member state under MiCA. An operator already authorised as a CASP in, say, Malta or Lithuania has the option to passport into Germany without obtaining a separate BaFin authorisation. For this profile, the Germany-substance question does not arise at the primary licence level – but the operator must notify BaFin of its intention to passport and comply with any German host-state requirements under MiCA. The German legal and compliance environment still applies to German-facing operations; it is simply administered through the home-state supervisor.

We map the licence, banking, and tax stack across operating, custody, and payment layers before an operator commits to a jurisdiction. The right structure in Germany looks different from the right structure in Abu Dhabi or Singapore, and those differences have material cost and timeline implications.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

The authorisation timeline under BaFin varies by the complexity of the business model and the completeness of the application. Well-prepared applications – with substance genuinely in place, a qualified management team, and a documented compliance programme – are typically processed within a matter of months. Incomplete applications, or those where substance has not been established before filing, can take significantly longer as BaFin raises queries and requests supplementary information. Pre-application engagement with the regulator is strongly recommended to calibrate expectations and identify gaps before formal submission.

Which jurisdiction is best for licensing my crypto business?

There is no universal answer. The right jurisdiction turns on where your clients are, where your management team is located, how much substance you can genuinely commit to a given hub, and what the banking environment looks like for your business model. Germany with a BaFin-issued CASP authorisation is the strongest choice for EU-market-focused operators who want passporting rights and regulatory credibility. For operators primarily targeting non-EU markets, hubs such as Abu Dhabi (ADGM/FSRA), Singapore (MAS), or the Cayman Islands (CIMA) may be more appropriate. A cross-jurisdiction stack analysis is the correct starting point.

Do I need a separate custody licence?

Under the MiCA CASP framework, custody is one of the regulated crypto-asset services that requires specific authorisation. An operator already authorised as a CASP for exchange or brokerage services and who wishes to add custody must ensure that the custody activity is covered by its authorisation scope. Under the prior German regime, crypto custody (Kryptoverwahrgeschäft) was a distinct regulated category under the Banking Act. Operators transitioning from the pre-MiCA regime should confirm that their MiCA CASP authorisation covers every regulated activity their business model involves. Offering custody without the correct scope is an authorisation breach.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking, and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody, and payment layers before you commit to a structure. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing and Jurisdictions Analyst – specialises in VASP and CASP authorisation strategy across the EU and Gulf jurisdictions, with a focus on substance structuring and BaFin engagement.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours