EST · MMXXVI
Home/Jurisdictions/Germany/Vara licence application in Germany (BaFin)
Licensing & Registration

Vara licence application in Germany (BaFin)

Vara licence application in Germany (BaFin). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Vara licence application in Germany (BaFin)

Applying for a virtual asset service provider (VASP) authorisation in Germany means engaging with the Bundesanstalt für Finanzdienstleistungsaufsicht – BaFin – under a regime that is simultaneously one of the most demanding in Europe and, since MiCA (the EU's Markets in Crypto-Assets Regulation) came into force, one of the most strategically important. A German authorisation carries full EU passporting rights. Miss a step in the application or misread the scope of regulated activities, and the consequences are immediate: enforcement notices, suspended operations and, in the worst cases, frozen banking rails. This page maps the regulated perimeter, the process, the cross-border interaction with tax and banking, and the decision logic an inbound operator needs before committing to a German licence.

What does BaFin regulate, and who needs a licence?

Any business that provides a crypto-asset service as defined under the applicable MiCA provisions – whether operating an exchange, running a custody service, placing or advising on crypto-assets, or transferring or settling digital assets – requires a CASP authorisation (Crypto-Asset Service Provider) from a competent authority. In Germany, that authority is BaFin. The regime applies to businesses established in Germany and to those seeking to passport services into Germany from a German licence base. BaFin supervises a spectrum of activities, from execution-only platforms to full discretionary asset management in crypto-assets, and the scope of your licence must correspond precisely to every activity you carry on commercially.

Germany's relationship with digital-asset regulation predates MiCA. BaFin had developed a mature supervisory practice under the prior domestic framework – classifying crypto-assets as financial instruments in a broad category – before the EU-wide MiCA regime displaced and harmonised that approach. That institutional experience matters. BaFin's assessment standards are detailed and its examiner teams technically literate. An application that would pass without comment in a lighter-touch regime will receive substantive queries here on governance, IT security, safeguarding mechanics and outsourcing arrangements.

Entities already authorised under the prior German VASP regime face a transition to full CASP authorisation. The timeline and scope of that transition are set by the MiCA transition provisions and BaFin's published supervisory expectations; operators should not assume a legacy registration automatically grandfathers to a full MiCA CASP licence.

For a business sitting between a German operating entity and a non-EU parent or service provider, the perimeter question becomes a cross-border question immediately. Which activities occur in Germany? Where is the order book held? Where is custody exercised? Each answer can shift a borderline activity from unregulated to fully authorised territory.

What licence categories apply under the BaFin CASP regime?

MiCA defines ten categories of crypto-asset service, and a German CASP authorisation is scoped to the specific services the applicant will provide. The categories cover custody and administration of crypto-assets on behalf of clients; operation of a trading platform; exchange of crypto-assets for fiat or for other crypto-assets; execution of orders; placement; reception and transmission of orders; portfolio management; advice; transfer services; and underwriting or firm commitment services. BaFin does not issue a generic "crypto licence": the authorisation document lists the services permitted, and any material expansion requires a variation application.

In practice, most inbound operators target one of three core combinations. A retail-facing exchange typically needs custody, trading-platform operation and exchange services at a minimum. An institutional broker-dealer model typically adds placement and order reception. A custody-only provider – common for fund-services businesses – applies for the custody and administration category alone, but must then demonstrate that its operating model does not, in substance, bleed into management or execution activities that require additional authorisation.

Token issuers are treated differently. Issuance of crypto-assets that are not asset-referenced tokens or e-money tokens triggers whitepaper publication obligations under MiCA rather than a CASP authorisation requirement. Asset-referenced tokens (ARTs) and e-money tokens (EMTs) require their own issuer authorisation, separate from any CASP licence. A business that both issues a stablecoin and operates an exchange platform needs both tracks, and their timelines rarely align without deliberate planning.

How does the BaFin CASP authorisation process work?

The BaFin authorisation process runs in sequential stages, each generating a substantive workload before the formal clock starts. Operators that underestimate the pre-application phase consistently extend the overall timeline by months. The process works as follows.

The first stage is a pre-application engagement with BaFin. BaFin expects applicants to approach the supervisory team before submission. In our practice, this initial dialogue is the single most valuable stage of any German application: it surfaces the supervisory lens BaFin will apply to your specific activity set and allows the application to be scoped and framed accordingly. A pre-application meeting is not a rubber stamp; it is an audit of your business model's regulatory classification before the formal dossier is prepared.

The second stage is the preparation of the application dossier. BaFin's requirements are extensive. The dossier must include a detailed business plan covering the services to be provided, the client base, the revenue model, the governance structure and the IT and operational architecture. It must cover the applicant's own-funds position by reference to the capital requirements applicable to the relevant service categories. Shareholder and management fitness and propriety – the "fit-and-proper" assessment – requires personal questionnaires, criminal record checks and, for senior management, documented competency evidence. The AML/CFT programme must be fully articulated, with documented policies covering customer due diligence, transaction monitoring, suspicious activity reporting and – critically – the Travel Rule (the FATF obligation to pass originator and beneficiary data with each qualifying transfer). BaFin will scrutinise the Travel Rule implementation in detail; a reference to a future solution is not sufficient.

The third stage is the formal submission and BaFin's assessment period. The MiCA-mandated assessment timeline is measured in months rather than weeks. BaFin may pause the clock with requests for information, and each RFI response restarts a sub-period. Operators should plan for a realistic end-to-end timeline that is measured in multiples of the nominal assessment period, accounting for RFI cycles. The pace of the process depends materially on the completeness and technical quality of the initial submission.

The fourth stage is authorisation, conditional or unconditional. BaFin may impose conditions on authorisation – for example, requiring remediation of a specific governance gap before a service goes live. Conditions are not unusual; they are a normal feature of a technically demanding regime. The authorised entity may then passport its services across EU and EEA member states by notifying BaFin and the competent authority of the host state.

CTA #1 — OBOLUS Assessment

The process above describes the standard path. Your facts – the entity structure, the user base, the activity set and the banking – change the analysis materially. For a scoped pre-application assessment of your German licensing position, contact OBOLUS at info@oboluslaw.com or map your options here.

What does the cross-border reality look like for an inbound operator?

Operating a German CASP in an internationally structured group is rarely as clean as the licence diagram suggests. The cross-border reality introduces friction at three points: entity structure, banking access and tax residency.

On entity structure, BaFin requires the applicant entity to be a legal person established in Germany or, for passporting purposes, in another EU member state. A Cayman holding company with a German subsidiary seeking the licence is a common structure; but BaFin will look through the German entity to the wider group and will expect the German subsidiary to have genuine substance – senior management resident in Germany, governance bodies that meet in Germany, core decisions made in Germany. The shell-subsidiary model does not pass BaFin's substance test. We regularly advise on what genuine substance requires in practice: it is more than a registered address and a nominal director.

On banking, correspondent banking access for digital-asset businesses in Germany is constrained. Domestic banks have historically been cautious about crypto-related clients; a number have applied internal risk appetites that effectively exclude CASP applicants. A German CASP needs an operational bank account for client-money segregation, fee collection and own-funds custody. In our cross-border practice, we see operators consistently underestimate the banking stack challenge relative to the licence challenge. The two processes need to run in parallel, not sequentially.

On tax, a German-incorporated CASP is within the scope of German corporate tax and trade tax on its German-sourced profits. The applicable VAT treatment of crypto-asset services follows both EU guidance and the position developed by the German tax authorities; the treatment differs by service type and warrants early analysis. Transfer pricing – particularly for intra-group service agreements between the German operating entity and a non-EU parent or affiliated service provider – will be examined closely by German tax authorities, and the documentation obligations are stringent. Operators we advise routinely build the tax structure in parallel with the licence application: leaving tax architecture to a post-authorisation phase creates avoidable risk.

How does AML and the Travel Rule apply to a German CASP?

BaFin applies AML and Travel Rule obligations with particular rigour, and the German regulatory environment has consistently been at the stricter end of European implementation. The Travel Rule – derived from FATF Recommendation 15 – requires a German CASP to collect, verify and transmit originator and beneficiary information for qualifying virtual asset transfers. The precise data threshold above which the Travel Rule obligation is triggered is set by the applicable EU and German implementing provisions; operators should verify the current figure against the regime as it stands at the time of application rather than relying on an historical number.

BaFin expects the Travel Rule solution to be operational before the licence goes live. A commitment to implement the Travel Rule post-authorisation is likely to generate a licence condition or an RFI delay. The market infrastructure for Travel Rule compliance has matured; there are several interoperable solutions. The selection of a solution needs to be documented in the application, with evidence that the chosen solution covers the CASP's specific counterparty landscape – including relationships with unhosted wallets and with counterparty VASPs in non-Travel-Rule jurisdictions. BaFin's supervisory expectations on unhosted wallet due diligence are detailed and should be addressed explicitly in the AML programme.

German AML law also imposes obligations beyond the FATF baseline. Beneficial ownership transparency, politically exposed person screening and the suspicious transaction reporting chain are all subject to BaFin examination. CASPs with a significant retail business will additionally be examined on their transaction monitoring calibration; threshold-based rules are expected to be supplemented by behaviour-based detection.

In practice: a recent cross-border licensing engagement

In a recent licensing matter, an institutional digital-asset exchange headquartered outside the EU sought to establish a German-regulated entity as its EU passporting base. The business had an existing offshore registration but had concluded – correctly – that European institutional clients required a MiCA-authorised counterparty. We advised on entity structuring to satisfy BaFin's substance requirements, prepared the pre-application engagement materials, and mapped the AML programme against BaFin's published Travel Rule expectations. The application proceeded to the formal submission stage with a complete dossier and no pre-submission RFIs. The primary timeline driver proved to be banking – not BaFin – and a parallel banking mandate ran from the outset. The client obtained a conditional authorisation in a timeline consistent with a well-prepared application of that complexity.

How should an operator assess the Germany BaFin route against alternatives?

Germany is not the right base for every inbound operator, and a realistic decision requires comparing the German CASP route against the alternatives on three axes: regulatory burden, strategic value and execution risk.

A large institutional operator targeting EU clients – particularly German institutional clients, who often require a locally regulated counterparty – will find that the regulatory burden of a BaFin authorisation is justified by the commercial access it creates. The EU passporting right compounds that value: a single German authorisation supports operations in all EU member states without additional licences. For this profile, Germany is frequently the correct answer.

A mid-size operator primarily targeting retail clients across the EU, with a simpler activity set and a shorter timeline requirement, may find a faster MiCA authorisation route in another EU member state – historically, Lithuania and Malta have offered shorter timelines under their respective pre-MiCA regimes. Under the converging MiCA framework, those timeline differences are narrowing; but the residual gap in BaFin's application depth remains material for operators without the governance infrastructure to support a German-standard dossier on day one. For this profile, a phased approach – an EU licence in a faster member state first, with a German variation or passporting notification later – may be the better path.

A custody-only provider for institutional or fund clients has a narrower activity set that reduces the BaFin dossier scope; Germany is a natural fit where the client base demands it. The same provider with an ambition to expand into trading or management services should anticipate a variation application and factor that into the initial architecture.

Operators outside the EU – whether in the UAE under VARA, in Singapore under the MAS Payment Services Act, or in the UK under FCA registration – should assess whether their existing licence provides a sufficient basis for cross-border EU service in the specific activity set they are conducting. In many cases it does not: MiCA imposes strict third-country requirements on EU-bound services, and reliance on a non-EU licence for EU clients is a material enforcement risk that we see overlooked in the market.

CTA #2 — Prior Application or Stalled Process

If a prior application to BaFin has stalled, or a banking relationship was declined during a German licensing process, a second read of the structural assumptions can surface the underlying issue and the route forward. Write to OBOLUS at info@oboluslaw.com or map your options here.

What are the most common mistakes in a BaFin crypto-asset application?

A common assumption in the market is that a single offshore registration covers all global activity and renders a BaFin authorisation unnecessary. That assumption is wrong, and acting on it creates enforcement exposure under both the applicable MiCA provisions and BaFin's domestic supervisory powers. BaFin has a track record of issuing cease-and-desist notices to entities providing crypto-asset services to German clients without appropriate authorisation.

Beyond the jurisdictional misread, the following errors appear consistently in applications that run into difficulty. First, underspecified governance documentation: BaFin expects a clear audit trail from the board's digital-asset risk appetite down to the operational procedures. Generic AML policies imported from a non-EU jurisdiction and not adapted to the German regulatory environment will generate RFIs. Second, incomplete fit-and-proper documentation for key function holders: personal questionnaires submitted without adequate background documentation cause delays that can extend the overall timeline significantly. Third, a Technology and IT security section that describes architecture at a conceptual level without operational specificity: BaFin's IT supervisory team expects documentation of key-management procedures, disaster-recovery architecture, outsourcing risk assessments and – for custody applicants – safeguarding technology in granular detail. Fourth, the Travel Rule implementation gap described above. Fifth, and most consequently, treating banking as a post-licence project.

In our practice, the applications that progress with the fewest RFI cycles share three characteristics: they are structured around a genuine understanding of BaFin's supervisory priorities for the specific activity set in question; they are complete on governance and AML from day one; and they are accompanied by a parallel banking process already in progress.

Self-assessment: is your business ready for a BaFin application?

Before engaging with BaFin, an applicant should be able to answer yes to the following questions. Honest engagement with each is more useful than optimistic assumptions.

  • Does the German entity have genuine management substance – resident senior management, a functional board, and a governance structure that operates in Germany rather than being administered from offshore?
  • Is the AML programme documented, jurisdiction-specific and operational – including a Travel Rule solution that covers the relevant counterparty landscape?
  • Has the own-funds position been assessed against the capital requirements applicable to each service category in the target authorisation?
  • Has fit-and-proper documentation been assembled for all proposed key function holders, including senior management, internal audit and compliance functions?
  • Has the IT and key-management architecture been documented at the level of operational specificity BaFin's IT supervisors expect?
  • Is a banking process running in parallel with the licence application, with contingency options identified if the primary bank declines?
  • Has the tax structure – including transfer pricing documentation for intra-group arrangements – been reviewed by counsel familiar with the German position on digital-asset services?

An applicant that cannot answer yes to most of these questions should treat the gap as the pre-application workstream, not as a matter to be addressed reactively after submission.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

The timeline varies by jurisdiction and the complexity of the activity set. Under MiCA, the assessment period for a CASP authorisation runs to a defined number of months from a complete application; but BaFin's RFI process can pause and extend that clock. In practice, a well-prepared application to BaFin for a mid-complexity activity set takes longer than the nominal assessment period allows for, when pre-application engagement and RFI cycles are included. Operators should plan accordingly and not assume the nominal period is the realistic one.

Which jurisdiction is best for licensing my crypto business?

There is no universal answer. The right jurisdiction depends on your activity set, client base, entity structure and banking position. Germany and the EU MiCA regime suit operators needing EU passporting and institutional client access. Other EU member states may offer a faster initial authorisation for simpler activity sets. Non-EU hubs – Singapore, the UAE, Switzerland, the UK – serve different strategic profiles. The decision is a matrix of regulatory burden, market access, banking availability and tax cost. OBOLUS maps that matrix before you commit to a jurisdiction.

Do I need a separate custody licence?

Custody and administration of crypto-assets on behalf of clients is a distinct regulated activity under MiCA and requires its own CASP authorisation scope. An exchange licence does not automatically include custody. Conversely, a custody-only authorisation does not permit trading or execution activities. If your business model involves both holding client assets and executing trades, both activities must be covered in the authorisation, and BaFin will scrutinise each independently. Operators that conflate custody and trading in the same legal entity without the correct combined authorisation face enforcement risk.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions – including BaFin CASP authorisations and EU passporting strategy – on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before our clients commit. Digital assets are the entirety of our practice, and we act only for businesses. To discuss your situation, contact info@oboluslaw.com or message us via t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in CASP authorisation strategy and EU passporting for inbound digital-asset operators.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours