EST · MMXXVI
Home/Jurisdictions/Germany/VASP licensing in Germany (BaFin): Legal Requirements for Businesses
Licensing & Registration

VASP licensing in Germany (BaFin): Legal Requirements for Businesses

Vasp licensing in Germany (BaFin). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

VASP licensing in Germany (BaFin): Legal Requirements for Businesses

Operating a virtual asset business in Germany without the correct authorisation from BaFin (Bundesanstalt für Finanzdienstleistungsaufsicht) is not a grey area. The regulator treats unauthorised crypto custody, exchange and brokerage as unlicensed financial services – triggering enforcement powers that include business prohibition, asset freezes and criminal referral. For any business directing services at German users, or incorporated in Germany, the licensing question must be answered before operations begin, not after the first regulatory inquiry arrives.

VASP licensing in Germany sits within a dual-layer regime. The national framework under BaFin defines the regulated perimeter for crypto custody and exchange. At the EU level, the MiCA (Markets in Crypto-Assets Regulation) regime, supervised by ESMA and the national competent authority, is now the governing framework for the broader category of crypto-asset service providers (CASPs). Understanding where these two layers interact – and what the transition means for an inbound operator – is the starting point for any Germany entry strategy. This page explains the regulated perimeter, the application process, the cross-border banking and tax reality, and where operators commonly miscalculate.

What Does BaFin Actually Regulate for Crypto Businesses?

BaFin regulates crypto custody and exchange as financial services under the German Banking Act and the applicable investment services framework, covering custody of cryptoassets on behalf of others and the brokerage and exchange of cryptoassets as principal or agent. Any business holding client crypto keys, operating an order book, or providing portfolio management over digital assets for German-domiciled customers falls within that perimeter – regardless of where the operator itself is incorporated.

The crypto custody business (Kryptoverwahrgeschäft) was introduced as a distinct regulated category, making Germany one of the first major EU jurisdictions to give custody explicit statutory recognition. This matters for two reasons. First, a business that only manages keys – with no exchange function – still requires authorisation. Second, the custody category is not merged with the exchange category: an operator running both functions needs its authorisation to cover both. In our practice, the most common structural error we encounter from inbound operators is assuming a single broadly-worded licence covers every business line they intend to run.

Under MiCA, the CASP authorisation framework is now layered over the domestic regime. ESMA and BaFin, acting as the national competent authority, are coordinating the transition from the prior domestic registration to full MiCA CASP authorisation. Businesses already registered under the earlier BaFin regime must assess their transition obligations under MiCA's grandfathering provisions. New entrants seeking to passport services across the EU/EEA from a German entity will pursue CASP authorisation through BaFin under MiCA.

Who Needs a BaFin Licence or Registration?

Any business providing regulated crypto activities to clients located in Germany – whether the operator is German or foreign – falls within BaFin's supervisory reach. The extraterritorial dimension is significant for inbound operators who believe that a non-EU licence insulates them from German requirements when serving German users.

The perimeter covers: custody of cryptoassets on behalf of third parties; operating a cryptoasset trading platform; exchanging cryptoassets for fiat or for other cryptoassets as principal; executing orders for cryptoassets; placing cryptoassets on behalf of issuers; and receiving and transmitting orders. Portfolio advice and management over digital assets also trigger regulated-activity analysis.

Exemptions are narrow. Intragroup activity, where no third-party client relationship exists, may fall outside scope. Purely technical service providers – hosting infrastructure, running nodes – do not automatically become VASPs. But the line between technical service and regulated activity is drawn by function, not by label. A platform that routes client funds, holds client keys even temporarily, or makes investment decisions over client assets is on the wrong side of that line. BaFin has made clear that substance governs, not the terminology an operator uses to describe itself.

CTA #1 – For operators assessing their position early

The analysis above describes the standard perimeter. Your product architecture – how keys are held, how orders are matched, where client money sits – shifts the analysis materially. The process of determining whether you need a licence, and in which category, is the first engagement most clients have with us. Map your options

How Does the BaFin Licensing Application Process Work?

The BaFin authorisation process for a crypto custody or exchange business is a structured document-intensive review covering the applicant's legal form, governance, fit-and-proper assessment of management, capital adequacy, AML/CFT systems, IT security and outsourcing arrangements. Under MiCA, the CASP authorisation process runs through BaFin as the national competent authority and includes a formal coordination window with ESMA.

Applicants must typically present: a detailed business plan with revenue projections and a client-acquisition strategy; organisational charts and governance documentation; personal questionnaires and criminal-background information for all directors and key function holders; a description of custody arrangements and key management procedures; AML/CFT policies and a risk assessment; and evidence of capital adequacy appropriate to the licence category sought. For businesses with third-country ownership or management, BaFin conducts additional scrutiny of the ownership chain.

Timeline from filing a complete application to authorisation decision varies by category, by the completeness of the submission and by BaFin's current workload. Operators we advise regularly underestimate the pre-submission preparation phase. A well-prepared submission – with all fit-and-proper documentation in order, policies reviewed, and the business plan stress-tested against BaFin's expectations – takes several months to assemble before the formal clock starts. The formal review period under MiCA runs from the submission of a complete file. BaFin will request additional information if the submission is incomplete; each such request pauses the clock and resets the preparation calendar.

A common operational error is submitting before key infrastructure decisions are finalised. BaFin expects the custody architecture, banking arrangements and outsourced-function governance to be resolved at the point of submission, not described as future intentions. In our practice, we advise clients to treat the application as a full regulatory audit of the business, not a paperwork exercise.

What AML and Travel Rule Obligations Apply?

Every German-authorised VASP is subject to the Travel Rule – the obligation, derived from FATF Recommendation 15 and transposed into EU law, to pass originator and beneficiary data with each virtual-asset transfer at or above the applicable threshold. Under MiCA and the Transfer of Funds Regulation (TFR), the Travel Rule applies to all transfers regardless of value for transactions between CASPs, and with certain conditions for transfers to or from unhosted wallets.

BaFin expects a functioning Travel Rule compliance programme at the point of authorisation. This means a technical solution for data transmission, written policies for handling transfers where counterparty information is absent or incomplete, and a risk-based process for assessing unhosted wallet interactions. The unhosted wallet rules under the EU framework are among the strictest globally, and operators coming from lighter-touch regimes regularly find this a structural challenge.

AML/CFT obligations include customer due diligence, enhanced due diligence for higher-risk relationships and jurisdictions, ongoing transaction monitoring calibrated to crypto-specific typologies, and suspicious transaction reporting to the Financial Intelligence Unit. Germany sits within the EU AML framework; the Anti-Money Laundering Authority (AMLA), which will assume direct supervisory responsibility for the highest-risk CASPs across the EU, adds a further supervisory layer that operators should anticipate in their compliance architecture.

What Is the Cross-Border Banking and Tax Reality for a Germany-Licensed Business?

For an inbound crypto business seeking BaFin authorisation, the practical constraint is often not the licence itself but banking. German and EU-licensed banks remain cautious toward crypto clients, particularly for settlement accounts holding client money or large fiat balances linked to exchange activity. Operators that arrive in Germany with a licence plan but no banking plan routinely discover that the regulated entity cannot open an operational account in a timeframe consistent with the licence timeline.

We regularly advise clients on the banking layer in parallel with the licence application. The realistic option set includes: specialist crypto-friendly EU payment institutions; EMI-authorised entities in other EU member states (whose payment services can passport into Germany); and, for custody-only businesses, custody-specific settlement arrangements. The key point is that the banking structure needs to be compatible with the licence category held. A CASP with a custody authorisation operating settlement flows through an unregulated account creates a compliance gap that BaFin will identify during supervision.

On tax, a German corporate entity holding the CASP authorisation is subject to standard German corporate income tax and trade tax on its income. The tax treatment of specific crypto activities – staking rewards, exchange spreads, token inventory – is a specialist area. Germany has developed relatively settled administrative guidance on certain personal crypto-tax questions, but the corporate-layer treatment of a licensed exchange or custodian requires dedicated structuring work. VAT treatment of crypto exchange services also diverges from some other EU member states. The interaction between the German entity and any parent, holding or treasury entity in another jurisdiction creates transfer-pricing exposure that must be anticipated at the design stage.

CTA #2 – For operators who have already begun the process and hit a structural obstacle

If a banking relationship has fallen through, or a prior submission was returned incomplete, the structural reason is usually identifiable – and often correctable. A scoped review of the file typically surfaces the issue within a defined timeframe. Map your options

A Licensing Scenario in Practice

Earlier this year, a digital-asset custody operator incorporated outside the EU approached OBOLUS after losing its primary banking relationship and receiving an informal inquiry from BaFin regarding the scope of its services to German institutional clients. The business had been operating under a light-touch offshore registration and had not sought EU authorisation. We mapped the regulated perimeter against the actual service architecture, advised on a restructuring of the entity structure to establish a MiCA-eligible German vehicle, prepared the fit-and-proper documentation for the management team, and coordinated with an EU payment institution to provide a bridge settlement account while the authorisation process proceeded. The business achieved a compliant operational structure without interrupting service to its existing institutional clients.

A Common Assumption About Offshore Licences

A widespread belief among crypto operators is that a single offshore registration – in a lighter-touch jurisdiction – is sufficient to serve clients globally, including clients in Germany. This is incorrect. BaFin applies a market-access analysis based on where services are directed and where clients are located, not solely where the operator is registered. An operator directing marketing at German residents, maintaining a German-language platform, or onboarding German institutional clients is providing regulated services in Germany regardless of where the corporate entity sits.

The EU passporting system provides a structured path for inbound operators: authorisation in one EU member state as a CASP under MiCA permits cross-border service into Germany without a separate German authorisation. But that passport requires a genuine and substantive authorisation in the home member state – not a nominal registration. BaFin has coordinated with peer regulators to identify letterbox structures, and the MiCA framework includes explicit requirements for genuine establishment in the authorising member state. Operators building an EU access strategy around a minimal-footprint vehicle in a small member state should assess that structure carefully before relying on it.

How Should an Inbound Operator Approach the Germany Decision?

The entry decision for a non-EU crypto business targeting German or broader EU clients turns on three questions: the nature of the activity, the preferred entity structure, and the timing relative to the MiCA transition calendar.

An operator whose primary business is custody for institutional clients, with no retail ambition, is a different profile from an exchange seeking to serve both institutional and retail users under a full CASP authorisation. The licence scope, governance requirements and capital expectations differ across those profiles. Both differ again from a stablecoin issuer, whose obligations under MiCA's ART or EMT framework are more demanding still – with reserve requirements, redemption rights and issuer authorisation obligations applied at the token level, not just the service-provider level.

Profile A – Institutional custody operator: pursues a focused German entity with custody-scope CASP authorisation, builds a governance structure appropriate to BaFin's fit-and-proper expectations, and sources a specialist EU settlement account. Timeline to a complete application is typically measured in months; authorisation thereafter depends on BaFin's review. Key risk: capital adequacy and outsourcing governance.

Profile B – Full-service exchange targeting EU retail and institutional: establishes a well-capitalised German or other EU entity with full CASP scope, invests heavily in AML/CFT infrastructure including a compliant Travel Rule solution, and plans banking from day one as part of the licence strategy. Key risk: the breadth of governance and compliance infrastructure required before BaFin will issue authorisation.

Profile C – Non-EU operator seeking EU market access without a German entity: evaluates the MiCA passport route from another EU member state; assesses the genuine-establishment requirement honestly; and identifies whether a third-country exemption or reverse solicitation analysis applies to any specific client relationships. Key risk: relying on legal analysis that is not current to the MiCA transitional calendar.

In our practice, we structure the decision conversation around the actual product, the actual client base and the actual timeline – not the most convenient theoretical path. The licensing regime does not reshape itself around the operator's preference. The operator's structure must fit the regime.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timeline varies significantly by jurisdiction, licence category and the completeness of the application at submission. In Germany, the pre-submission preparation phase – assembling governance documents, fit-and-proper questionnaires, AML policies and a business plan that meets BaFin's expectations – typically takes several months before the formal review begins. The formal review period under MiCA runs from BaFin's confirmation of a complete file. Requests for additional information pause the clock. Operators should plan for a process measured in quarters, not weeks.

Which jurisdiction is best for licensing my crypto business?

There is no single best answer: the right jurisdiction depends on the activity type, the target user base, the capital position, the existing corporate structure and the banking environment. Germany under BaFin offers EU passporting rights via MiCA and is credible to institutional counterparts. Other operators benefit from a different EU member state or an offshore regime suited to their client profile. OBOLUS maps the licence stack – operating entity, custody layer, payment flow – across the options before any filing commitment is made.

Do I need a separate custody licence?

In Germany, custody of cryptoassets on behalf of third parties is a distinct regulated activity under BaFin's regime and under MiCA. An exchange authorisation does not automatically extend to custody. If your business holds client keys – even in the course of providing exchange services – the custody function needs to be within the scope of your authorisation. Businesses offering both functions must ensure both are explicitly covered. The same logic applies to any outsourcing of custody to a sub-custodian: the regulated obligation remains with the authorised entity.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before clients commit to a structure – and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when things go wrong. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing and Jurisdictions Analyst – specialising in EU and cross-border VASP authorisation strategy, including MiCA CASP applications and BaFin regulatory engagement.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours