What the BaFin regime actually requires of a VASP applicant
Germany's crypto licensing regime is among the most demanding in the European Union, and a business that begins operating before authorisation is in place faces enforcement by the Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin) – Germany's federal financial supervisory authority – ranging from public warnings to operating bans and criminal referral. Under the German Banking Act and, from its entry into full effect, under the Markets in Crypto-Assets Regulation (MiCA), firms providing crypto-asset services to clients connected to Germany must hold a recognised authorisation before they go live. The path from corporate setup to active licence is sequential, documentation-heavy, and shaped by BaFin's well-developed expectation of institutional-grade governance – even for early-stage businesses.
This page sets out the regulatory basis, the application process, the cross-border interaction with tax and banking, and the decision points that determine whether a German authorisation is the right primary licence for your business or one layer in a broader stack.
Who needs a German crypto licence – and what triggers the requirement?
Any business offering regulated crypto-asset services on a commercial basis to persons or entities in Germany requires authorisation from BaFin – regardless of where the entity is incorporated. The obligation turns on where the service is delivered and where the client sits, not on the domicile of the server or the country on the certificate of incorporation.
Under the national transposition of the EU VASP (virtual asset service provider) framework, and now under the CASP authorisation regime introduced by MiCA, the regulated perimeter covers exchange services (crypto-to-fiat and crypto-to-crypto), transfer services, custody, brokerage, portfolio management over crypto-assets, and the operation of a trading platform. Businesses providing only one of these activities still require a licence for that activity. There is no general exemption for small operators or for businesses relying solely on a non-EU structure.
The cross-border point is critical. We regularly advise businesses incorporated in common-law offshore jurisdictions – BVI, Cayman, Seychelles – that assumed their offshore holding structure insulated German-resident users from the BaFin perimeter. It does not. The service, not the entity, determines jurisdiction. Any business with a German-language website, German payment rails, or a marketing strategy that is evidently directed at German users is operating inside the BaFin perimeter.
Under MiCA, a CASP authorised by any EU or EEA national competent authority may passport its services across the bloc, which means Germany need not be the seat of authorisation for every firm. But where the management, the technology infrastructure, or the majority of the client base sits in Germany, BaFin expects the authorisation to be German or, at minimum, expects the firm to have notified the passporting authority of its German activities before they begin.
What does the BaFin application process look like in practice?
A BaFin authorisation application is a structured submission that BaFin reviews against a defined list of requirements, and the authority runs a formal completeness check before the substantive clock starts. The key stages are entity incorporation, pre-application engagement, formal submission, BaFin review, and conditions management before the licence is issued.
The entity must be incorporated in Germany – a GmbH (Gesellschaft mit beschränkter Haftung, a private limited liability company) or an AG (Aktiengesellschaft, a joint-stock company) – before the application is submitted. BaFin will not accept an application from a foreign entity seeking to serve German clients without a German legal vehicle. The entity must have its registered office and, in practice, effective management in Germany. Nominee management structures do not satisfy the substance test BaFin applies.
The pre-application phase – an informal consultation with BaFin before formal submission – is strongly advisable. BaFin publishes guidance on what the submission must contain, but the authority's current operational priorities and areas of scrutiny are best understood through structured dialogue. We have seen applications stall at the completeness check because governance documentation was framed for a different regulatory model; the pre-application phase surfaces those gaps before they cost weeks on the timeline.
The formal submission includes: a business plan with detailed product and service descriptions; a governance and organisational structure diagram; AML/CFT policies and procedures aligned to the Travel Rule (the FATF obligation requiring originator and beneficiary data to travel with a transfer) and the German AML Act; fitness-and-propriety documentation for all members of senior management and key-function holders; an IT security concept; capital evidence; and, where custody is in scope, a client asset safeguarding plan. Each document is expected to reflect the specific German regulatory context, not to be a recycled submission from a different jurisdiction's regulator.
The timeline from formal submission to decision varies by the complexity of the business model and by BaFin's current review queue. A straightforward exchange-and-custody application at a well-governed entity has historically taken a number of months; more complex structures with multiple service lines, third-party custodians, and cross-border group arrangements have taken considerably longer. BaFin is entitled to pause the clock when it raises queries – and it routinely does so for governance and AML gaps. Writing qualitatively: applicants should budget for a process measured in quarters, not weeks.
How does the MiCA transition affect existing and new applicants?
MiCA is the EU-wide regulatory regime for crypto-asset services, and its entry into full application has reframed the BaFin licensing conversation for all market participants. Under MiCA, national VASP registrations obtained under transitional arrangements are subject to a grandfathering period that varies by member state; after that period, any firm wishing to continue operating in Germany – or anywhere in the EU – must hold a CASP (Crypto-Asset Service Provider) authorisation that meets the MiCA standard.
For new applicants, the practical implication is that starting a BaFin application now means applying for a MiCA-compliant CASP authorisation from the outset. There is no strategic value in applying for a legacy registration that will require a full re-application within a short period. BaFin has published transition guidance, and its expectation is that substantive applicants engage with the MiCA requirement directly.
The CASP authorisation framework introduces additional requirements beyond the legacy German national standard. White-paper disclosure obligations apply to most token offerings. Firms operating trading platforms face specific market-integrity obligations. Firms providing portfolio management over crypto-assets face a conduct regime with parallels to the existing MiFID II framework. For a business that has previously been regulated only under a lighter national regime, the uplift in documentation, governance, and operational standards is material.
One structural advantage of MiCA is passporting: a CASP authorised in Germany is entitled – subject to the notification procedure – to passport its services across all EU and EEA member states without a separate local authorisation in each. For a business whose primary market is German but whose client base spans the EU, this is the principal argument for a German authorisation rather than a lighter-touch EU seat. The counterargument – which we address in the decision-matrix section below – is that Germany's regulatory environment and operational requirements mean the cost of obtaining and maintaining the German authorisation is higher than the equivalent cost in several other EU member states.
AML compliance and the Travel Rule under the German regime
German AML requirements for crypto businesses are enforced by BaFin in coordination with the German Financial Intelligence Unit (the FIU), and they set a standard that is above the FATF baseline in several respects. Any firm applying for a BaFin authorisation must demonstrate, at the application stage, that its AML programme is operational, documented, and tailored to its specific service model – not that it intends to implement one post-authorisation.
The Travel Rule – the FATF Recommendation 15 obligation requiring originator and beneficiary information to accompany virtual-asset transfers – is implemented in Germany through the applicable provisions of the German AML framework. BaFin expects applicants to demonstrate a technical solution for Travel Rule compliance that is live or has a credible implementation plan with a defined go-live date. A policy document that describes the obligation in the abstract, without a technical implementation, will not satisfy the completeness check.
The AML documentation package must include: a risk assessment that covers the specific digital-asset services offered; customer due-diligence procedures calibrated to those risks; transaction-monitoring rules and escalation paths; policies for dealing with unhosted wallets (wallets not held at a regulated intermediary); a designated AML officer with demonstrable knowledge of virtual-asset-specific risks; and a documented approach to sanctions screening that covers the major designation lists, including OFAC, the EU consolidated list, and the German domestic list.
In our practice, AML documentation is the most common reason BaFin raises substantive queries during its review. The authority's examiners are experienced in crypto-specific risk patterns and they probe for substance rather than form. A policy that is clearly adapted from a generic template – without product-specific risk logic, without credible transaction-monitoring thresholds, and without evidence that senior management has engaged with the content – will generate a round of questions that delays the process significantly.
Capital adequacy and governance requirements
BaFin applies a capital requirement that varies by the type and scope of activities authorised. Because the specific thresholds are [VERIFY] placeholders in the current registry, we state them qualitatively: the minimum capital for a crypto-asset custody business differs from that required for an exchange, and a business operating multiple service lines must satisfy the highest applicable requirement. Capital must be fully paid up and evidenced before BaFin issues the authorisation; a commitment or a term sheet is not sufficient.
Governance requirements are substantive. BaFin applies a fitness-and-propriety test to each member of the management board and to key-function holders (risk, compliance, AML, IT). The test covers professional qualifications, relevant experience in financial services, absence of prior regulatory sanctions, and personal integrity. BaFin interviews key management personnel as part of its review; the interview is formal and document-supported, not conversational.
The organisational structure must demonstrate a clear separation between compliance and revenue-generating functions. For a startup-stage business, this creates a practical challenge: the team size that BaFin considers adequate is larger than what a pre-revenue operator typically employs. In our experience, businesses that attempt to satisfy BaFin's governance requirements with a two-person management team and no dedicated compliance function do not progress past the review stage. A credible application requires, at minimum, a dedicated compliance officer, a separate risk function, and a management board with at least one member whose background is directly in regulated financial services.
Cross-border banking and tax considerations
Obtaining a BaFin authorisation does not automatically solve the banking question. German and EU banks apply their own AML and de-risking policies to crypto businesses, and a newly licensed VASP – particularly one with a group structure that includes non-EU entities – may find that obtaining a Euro settlement account takes longer than the licence itself. We map the banking layer as part of the structuring analysis before a client commits to the German authorisation path, not as an afterthought.
The tax treatment of crypto-asset activities in Germany is governed by the applicable German income and corporate tax provisions and, for transaction-specific items, by BaFin's interaction with the German Federal Central Tax Office (the Bundeszentralamt für Steuern) and the relevant state tax authorities. Key issues for an inbound operator include: the treatment of token inventory on the balance sheet; the VAT characterisation of exchange fees; the withholding implications of distributed rewards; and transfer-pricing obligations where the German entity transacts with non-German group members. None of these is straightforward, and the interaction between the regulated activity and the tax position must be mapped before the corporate structure is fixed.
For businesses with holding structures in low-tax jurisdictions, the German CFC (controlled-foreign-company) rules and the EU anti-tax-avoidance directives create additional complexity. A Cayman or BVI holding entity above a German VASP is not inherently problematic, but the economics of the structure – where value is created, where risk sits, and where profit is recognised – must be defensible under both German and EU transfer-pricing principles.
The cross-border angle is one we address in every German authorisation mandate. The licence is the entry point; the banking, the tax, and the group structure are the sustained operational exposure. We structure the engagement so that all three layers are resolved before the entity is incorporated and the application clock starts.
CTA: The process above describes the standard path. Your facts – the entity, the user base, the banking, and the group structure – change the analysis materially. For a scoped assessment of your Germany authorisation options, contact OBOLUS at info@oboluslaw.com.
Which businesses should pursue a BaFin authorisation – and which should not?
A German BaFin authorisation is the right instrument for a specific profile of business; it is not the default for every European crypto operation.
Profile A – German-market-focused exchange or custodian: A business whose primary user base is German, whose management is Germany-based, and whose banking partners are EU-headquartered has strong reasons to apply to BaFin directly. The MiCA passport means that the German authorisation also opens the rest of the EU; the cost of the single high-standard application is offset by the absence of parallel applications in other member states. The indicative process is measured in quarters; the key risk is governance uplift – the team and compliance infrastructure must be built to BaFin's standard before submission.
Profile B – EU-wide operator choosing a primary licence seat: A business that wants EU passporting but whose management, technology, and day-to-day operations are not Germany-centric should evaluate whether a BaFin authorisation is the most efficient route to MiCA CASP status. Lithuania, Malta, and other EU member states offer CASP authorisation paths under MiCA with national competent authorities that have different operational profiles. The comparison is not about regulatory quality – MiCA is MiCA – but about the substance requirements, the review timelines, and the banking access in each seat. We carry out this analysis as a jurisdiction-selection exercise before any application is filed.
Profile C – Non-EU business with German users as part of a global book: This profile carries the most acute risk. Operating without the right authorisation while serving German users exposes the business to BaFin enforcement, which has been active in the crypto sector. The practical options are: authorise in Germany (or in an EU seat and passport in); geo-restrict German users with robust controls; or restructure the service offering so that the German-nexus activities fall outside the regulated perimeter. Each option has a different cost and risk profile. We regularly advise on this decision, and the answer is fact-specific.
Profile D – DeFi or token-issuer with German user exposure: The MiCA perimeter extends beyond service-provider licensing to token issuers. A business issuing tokens that are acquired by German holders may have whitepaper and disclosure obligations under MiCA regardless of whether it holds a CASP authorisation. The regulated basis varies by token type – an asset-referenced token (ART) sits in a different part of the regime from a utility token – and BaFin has published guidance on its approach to classification. This profile requires a token-specific analysis before any go-to-market decision.
An anonymized example from our practice
In a recent licensing matter, a payments technology company incorporated in a non-EU jurisdiction was expanding its stablecoin transfer service into continental Europe. The company's initial plan was to use its existing regulatory registration – obtained in a low-friction offshore regime – to serve German and Austrian users. We were retained in the early planning phase and identified that the service, as designed, fell squarely within the CASP perimeter under MiCA and that the offshore registration provided no exemption. We advised on a restructuring of the European operations into a German GmbH, mapped the governance build required to satisfy BaFin's fitness-and-propriety standard, and managed the pre-application engagement with the regulator. The business went to formal submission with a complete governance package and a credible AML implementation. The process proceeded without a completeness-check rejection – an outcome that, in our experience, is materially determined by the quality of the pre-submission preparation.
A common assumption that creates risk
A common assumption among founders and general counsel at businesses with a global user base is that a single offshore licence – typically from a jurisdiction with a lighter registration process – is sufficient to serve clients worldwide, including in Germany. That assumption is incorrect under the German and EU frameworks, and acting on it has resulted in enforcement actions, account terminations, and reputational damage for businesses that were otherwise well-run.
The source of the error is usually a misreading of the "services passporting" concept. A licence issued by a non-EU authority does not passport into the EU. MiCA does not recognise third-country registrations as equivalent to CASP authorisations. A business relying on a non-EU licence to serve German users is unregulated from BaFin's perspective, regardless of how well-regarded the issuing authority may be in its home market. The practical consequences – frozen payment rails, bank account closures, and the inability to onboard institutional clients who conduct their own regulatory due diligence – are in our experience more immediately damaging than the formal enforcement risk.
The corrective path is rarely as complex as businesses fear once the structural question is addressed properly. The EU, and Germany in particular, has a defined authorisation route; BaFin's requirements are demanding but predictable; and a business that builds to those requirements has access to the world's largest single market for financial services. The cost of getting it right upfront is lower than the cost of managing the consequences of getting it wrong.
If a prior application stalled, an account was closed, or you received a BaFin correspondence requiring a response, a scoped second review can surface the structural cause and the route forward. To discuss that situation, write to OBOLUS at info@oboluslaw.com or message us via t.me/oboluslaw.
Self-assessment checklist before filing a BaFin application
Before committing to a formal BaFin submission, a business should be able to answer affirmatively to each of the following:
- The German GmbH or AG is incorporated, with effective management resident in Germany and board members who satisfy BaFin's fitness-and-propriety standard.
- The business plan describes the service offering, the technology architecture, and the revenue model in detail sufficient for a regulator unfamiliar with your product to understand how it works and what risks it creates.
- The AML/CFT programme is fully documented, product-specific, and includes a credible Travel Rule implementation plan with a defined technical solution and go-live date.
- The capital position meets the minimum requirement for the most demanding activity in scope and is evidenced by paid-up capital in the German entity's accounts.
- The compliance function is staffed, the AML officer is appointed and appropriately qualified, and the separation between compliance and commercial functions is documented in the governance structure.
- The IT security concept has been reviewed by a qualified assessor and reflects the specific operational environment of the business.
- The banking strategy has been tested – ideally with a conditional offer from a prospective banking partner – so that the regulatory authorisation is not issued into a situation where payment rails cannot be opened.
- The group structure has been reviewed for tax and CFC implications, and transfer-pricing documentation is in place for any intra-group arrangements.
A "no" to any of the above is a pre-submission gap. BaFin will surface it during its completeness check or substantive review; addressing it before submission is faster and less costly than addressing it under examiner pressure.
Related at OBOLUS
- Licensing and registration for digital-asset businesses – how we structure the licence, banking, and compliance stack across operating jurisdictions
- VASP licensing in Singapore – the MAS Payment Services Act regime for digital payment token service providers
- Cross-chain bridge legal risk in the Czech Republic – regulatory and liability exposure for bridge operators within the EU
FAQ
How long does a crypto licence take to obtain?
In Germany, a BaFin authorisation for a crypto-asset service provider is a process measured in quarters, not weeks. The timeline depends on the complexity of the business model, the completeness of the submission, and BaFin's current review queue. BaFin may pause the statutory clock while awaiting responses to queries; applications with governance or AML gaps routinely run longer than straightforward submissions. Across other EU member states and jurisdictions such as Singapore, Lithuania, and the ADGM, timelines vary – some are materially shorter than Germany's, which is one factor in the jurisdiction-selection analysis.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. The right primary licence seat depends on where your management, users, and banking sit; on the service activities you provide; and on the regulatory standard your institutional clients and banking partners expect. Germany offers MiCA passporting across the EU but carries high governance and capital requirements. Other EU member states offer the same passport at a different operational cost. Singapore, the ADGM, and Hong Kong are appropriate for businesses with Asia-Pacific or Gulf operations. We carry out a jurisdiction-selection analysis as the first step of any licensing engagement.
Do I need a separate custody licence?
Under the German and MiCA frameworks, crypto-asset custody is a regulated activity that requires specific authorisation – it is not automatically covered by an exchange or transfer licence. A business that holds client crypto-assets on a custodial basis must have the custody activity explicitly within the scope of its authorisation, and BaFin expects dedicated safeguarding policies, client-asset segregation procedures, and capital allocated to the custody function. Where custody is provided by a third-party sub-custodian rather than by the applicant directly, the regulatory position is different but still requires documented governance over the arrangement.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – so that the authorisation you obtain matches the business you intend to run. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums where recovery is in issue. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in EU and cross-border VASP authorisation strategy, MiCA transition planning, and BaFin application management for inbound digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.