Operating a crypto exchange (a platform that facilitates buying, selling or exchanging digital assets on behalf of users) in Gibraltar requires a formal regulatory authorisation before any commercial activity begins. Gibraltar's Distributed Ledger Technology (DLT) Provider regime, administered by the Gibraltar Financial Services Commission (GFSC), was among the first purpose-built crypto-licensing regimes in the world. For an inbound operator, the practical question is not whether to obtain a licence, but how to structure the application, the entity, the banking, and the cross-border compliance stack so that all layers hold together on day one.
The GFSC grants a DLT Provider licence to businesses that use distributed ledger technology in storage or transmission of value belonging to others. That definition captures virtually every exchange and custodial wallet service. This page sets out the regulated perimeter, the application pathway, the cross-border interactions an operator must resolve, and the decision points that separate a well-structured Gibraltar setup from one that stalls before it trades.
What activities require a DLT Provider licence in Gibraltar?
Any business using DLT to store or transmit value belonging to others on a commercial basis must obtain a DLT Provider licence from the GFSC before operating in or from Gibraltar. The scope is activity-based. It catches spot-exchange services, order-book platforms, custodial wallets, and OTC desks where the operator holds client assets at any point in the transaction flow. Advisory services and non-custodial software do not fall within the current DLT regime, though the position is evolving and operators should confirm the perimeter against their specific model before assuming an exemption applies.
Gibraltar's approach differs from the EU's MiCA (Markets in Crypto-Assets Regulation) framework, which Gibraltar is not bound to follow post-Brexit. The GFSC retains its own regulatory principles – the ten DLT regulatory principles covering conduct, financial crime, financial resilience, custody and systems. Each principle is assessed against the specific risk profile of the applicant's business model. There is no single activity-category map of the kind MiCA uses for CASPs (Crypto-Asset Service Providers); instead, the GFSC applies a principles-based supervisory test.
Operators whose services extend to users in EU member states must separately consider whether MiCA's CASP authorisation is required in a passporting jurisdiction. Gibraltar does not offer MiCA passporting. A Gibraltar DLT licence governs the Gibraltar entity; EU-facing activity may require a parallel CASP authorisation in a member state. We address that cross-border layer in the structuring section below.
Who must apply for a DLT licence – and who is exempt?
The DLT regime applies to any entity established in Gibraltar that uses DLT commercially to store or transfer value for clients, and also to foreign entities carrying on that business in or from Gibraltar. The phrase "in or from" is the critical jurisdictional hook. A company incorporated in the BVI that operates its trading infrastructure from Gibraltar – staff, servers, management – will be treated as carrying on a regulated activity in Gibraltar and must hold a DLT Provider licence from the GFSC.
Exemptions are narrow. Non-custodial DEX front-ends, pure informational platforms and licensed banks operating ancillary crypto services under their banking licence may argue outside the DLT perimeter. In our practice, these edge cases require a formal legal opinion before the business goes live. The GFSC has a track record of engaging early-stage applicants in pre-application discussions, which is a valuable mechanism an experienced operator should use before committing capital to the Gibraltar structure.
Gibraltar also requires any DLT licensee to maintain ongoing compliance with anti-financial crime obligations. These mirror the FATF Recommendations – including Recommendation 15 (the application of AML/CFT standards to virtual asset service providers) and the Travel Rule (the obligation to pass originator and beneficiary data with a virtual asset transfer). The GFSC's financial crime principles are assessed at authorisation and on a continuing supervisory basis.
For a scoped legal assessment of whether your specific business model requires a Gibraltar DLT licence, contact OBOLUS at info@oboluslaw.com. The regulated perimeter is the first question to resolve, and the answer determines everything downstream – entity structuring, capital planning, and your banking timeline.
How does the Gibraltar DLT licence application process work?
The Gibraltar DLT application process involves submitting a detailed application to the GFSC covering the business model, governance structure, key personnel, financial crime controls, and a demonstration that the applicant meets each of the ten DLT regulatory principles. The GFSC is a principles-based regulator, which means the depth of documentary evidence required depends on the complexity and risk profile of the specific model. A straightforward spot-exchange serving retail clients demands more on conduct and custody than, say, a B2B settlement infrastructure operator.
The application dossier typically includes a regulatory business plan, AML/CFT policies and procedures, a systems and controls memorandum, financial projections, fitness-and-propriety evidence for all principal persons, and a detailed custody and asset-segregation framework. Where the operator uses third-party technology providers for order-book management or wallet infrastructure, the GFSC expects evidence of due diligence on those providers. The concept of operational resilience – demonstrating continuity of service and client asset protection in a stress scenario – is embedded in the principles and will surface in any substantive GFSC review.
Timeline for a DLT licence application is not fixed by statute. In our experience of comparable principles-based regimes, well-prepared applications from established operators take a matter of months from formal submission to approval; under-prepared applications – those that require multiple rounds of information requests – can take considerably longer. The GFSC's pre-application engagement process is therefore not optional for a serious applicant: it surfaces the GFSC's likely areas of focus before the formal clock starts.
The GFSC charges application and ongoing supervision fees. Specific figures are published by the GFSC and should be confirmed directly; they vary by business category and are subject to periodic revision.
How should a crypto exchange structure its Gibraltar entity?
The standard structure for a Gibraltar-based crypto exchange is a Gibraltar private company limited by shares, incorporated at the Gibraltar Companies House and registered with the GFSC as the DLT licence holder. Directors resident in Gibraltar, or at least a majority with demonstrable substance in the jurisdiction, strengthen the fitness-and-propriety assessment and satisfy the GFSC's governance expectations.
Substance is not cosmetic under the DLT regime. The GFSC expects genuine management and control from Gibraltar. A shell company with nominee directors and no real operational footprint will not pass the principles-based assessment. This does not mean the entire global technology or commercial team must be based in Gibraltar, but the regulated entity needs a credible management layer there – compliance officer, money-laundering reporting officer (MLRO), and at least senior-level oversight of the licensed activity.
For a group operating across multiple jurisdictions – a common structure in this sector – the Gibraltar DLT entity typically sits as a regulated subsidiary of a global holding company. The holding company may be incorporated in the BVI, the Cayman Islands, or another neutral jurisdiction depending on the investor base, fund structure, and tax considerations. That holding layer is separate from the Gibraltar operating entity and must be structured so it does not inadvertently trigger regulatory requirements in its own jurisdiction or create a consolidated AML obligation that conflicts with the Gibraltar regime.
One micro-matter that illustrates the structuring challenge: in a recent licensing matter, an exchange operator had incorporated a Gibraltar company and begun pre-marketing to European users before a formal DLT application was submitted. The GFSC's pre-application engagement confirmed that the pre-marketing activity, which included collecting expressions of interest and a waiting list, was viewed as preparatory commercial activity subject to the DLT regime. We restructured the corporate timeline and the pre-launch communications strategy before the formal application was filed, preserving the Gibraltar entry without triggering an enforcement referral. The authorisation proceeded on a clean basis.
How does the cross-border tax and banking layer interact with the Gibraltar structure?
A Gibraltar DLT licence is not a banking licence, and no crypto exchange in Gibraltar should assume that holding a GFSC authorisation resolves the banking question. Banking for crypto-native businesses remains constrained across all major hubs. Gibraltar has a small domestic banking sector; most DLT licensees bank with institutions in the EU, the UK, or offshore fintech banking providers. Each banking relationship introduces its own compliance layer – the bank's own AML procedures, the jurisdiction of the correspondent bank, and the travel-rule obligations of the transfer chain.
Tax in Gibraltar is a genuine structural advantage. Gibraltar operates a territorial income tax regime: income arising in Gibraltar is taxed, but income generated outside Gibraltar by a Gibraltar company is generally not subject to Gibraltar income tax. For a crypto exchange whose clients and counterparties are predominantly non-Gibraltar, this can mean a low effective Gibraltar tax rate on trading revenue. However, this analysis depends entirely on where economic substance sits. An operator cannot post management and control in a higher-tax jurisdiction and then claim a Gibraltar tax base; substance must follow structure.
The cross-border reality for most operators is that Gibraltar is the licensing and operational hub, but revenue may flow through a payment processor regulated elsewhere, with client funds held in accounts outside Gibraltar. Each of those touchpoints – the payment processor, the custodian, the banking correspondent – is a regulatory surface. An EU payment processor will apply its own AML and Travel Rule framework. A UK-regulated custodian will apply FCA safeguarding rules. The Gibraltar entity needs to be designed so that its own compliance posture accommodates those external obligations rather than creating contradictions.
For operators with significant EU-facing volume, the question of whether to run a parallel CASP application in a MiCA-passporting member state – Lithuania, Malta, or another EU hub – is not academic. The MiCA passporting regime allows a single CASP authorisation to cover all EU/EEA markets. A Gibraltar licence does not. Operators serving EU retail clients from Gibraltar after MiCA's full application date face the risk that EU regulators treat the service as a third-country provision, subject to additional restrictions or outright prohibition depending on the member state.
If your structure spans Gibraltar and the EU, or if a banking relationship has already stalled, write to OBOLUS at info@oboluslaw.com. A second read on the cross-border architecture often surfaces the structural reason a prior application or banking onboarding failed.
What are the AML and Travel Rule obligations for a Gibraltar DLT licensee?
Gibraltar DLT licensees are subject to Gibraltar's Proceeds of Crime Act and its AML/CFT framework, which implements the FATF Recommendations. In practice this means a risk-based AML programme, customer due diligence at onboarding, enhanced due diligence for higher-risk relationships, ongoing transaction monitoring, and suspicious activity reporting to the Gibraltar Financial Intelligence Unit.
The Travel Rule requires that any virtual asset transfer above the applicable threshold is accompanied by originator and beneficiary data. Gibraltar has implemented Travel Rule obligations in line with the FATF standard. For an exchange, this means a technical solution – typically integration with a Travel Rule protocol provider – and a policy framework for handling transfers from non-compliant counterparts (the "sunrise problem" that affects all exchanges operating in jurisdictions that have implemented the rule while some counterpart jurisdictions have not).
Crypto exchanges that move stablecoins such as USDT or USDC face an additional operational layer. Tether and Circle hold contract-level freeze and blacklist authority over their issued tokens and will act on law-enforcement requests or OFAC designations. A Gibraltar exchange whose clients hold material stablecoin positions should have a clear internal protocol for responding to freeze notices – including legal review timelines, client notification obligations, and the interaction with the GFSC's own supervisory expectations. We have advised operators on those protocols and on the documentation that satisfies the GFSC's systems-and-controls review.
Which operator profile is best suited to Gibraltar, and which should look elsewhere?
Gibraltar suits a defined set of operator profiles; it is not the right structure for every digital-asset business.
Profile A – established exchange seeking a common-law English-language jurisdiction with a principles-based regulator and territorial tax: Gibraltar is a strong candidate. The GFSC has supervised DLT businesses since 2018, the legal system is English-based, the tax regime is genuinely territorial, and the jurisdiction has a track record that institutional banking counterparts recognise. The risk is the EU market-access gap – a parallel CASP structure may be required for EU-facing volume.
Profile B – early-stage exchange with limited compliance infrastructure: Gibraltar may be premature. The principles-based assessment demands documented controls and genuine substance. An operator that has not yet built its AML programme, technology stack, or compliance team will generate a prolonged GFSC information-request cycle. For this profile, a lighter-touch initial registration – BVI VASP Act, Cayman CIMA registration – may allow the business to operate while the Gibraltar application is prepared in parallel.
Profile C – operator targeting EU retail clients as the primary market: A Gibraltar DLT licence is a necessary but not sufficient structure. MiCA passporting is essential for scale EU distribution, which requires a CASP authorisation in an EU member state. Malta and Lithuania are the operationally established EU entry points. The Gibraltar entity can co-exist as a non-EU operating hub while the EU entity handles passportable EU client relationships.
Profile D – institutional exchange or OTC desk serving professional counterparties: Gibraltar's principles-based regime can accommodate complex institutional business models, and the GFSC has demonstrated willingness to engage with sophisticated applicants. The key variable is whether the client base and product set require MiCA classification as an ART or EMT issuer, which would require an EU authorisation regardless of the Gibraltar structure.
What are the most common mistakes in a Gibraltar crypto licence application?
The most common mistake is treating the DLT application as a documentation exercise rather than a regulatory engagement. The GFSC is a principles-based supervisor. It assesses whether the management team understands the risks of its business and has built controls commensurate with those risks. Applications that recite generic AML policy language without demonstrating that the policies have been calibrated to the specific business model – the asset types, the client profile, the transaction volumes, the technology stack – consistently draw detailed information requests and delay authorisation.
A second recurring issue is unresolved cross-border regulatory exposure at the time of application. Operators who have already begun serving EU clients, or who have marketing activity visible in jurisdictions where they are not yet licensed, present the GFSC with a compliance history question at the outset. A clean pre-application period – no unlicensed activity, no regulatory correspondence from foreign supervisors – materially improves the quality of the submission.
The third mistake is underestimating the substance requirement. Appointing a local compliance officer a few weeks before submission, with no real operational integration, does not satisfy the GFSC's governance expectations. Substance in Gibraltar means that the officers responsible for the regulated activities have been involved in building the controls, understand the business model, and can speak to the GFSC coherently about risk. That takes time to develop. Operators who plan the substance layer twelve months before the application consistently have a better experience than those who address it in the final weeks.
A common assumption among operators entering Gibraltar is that a single Gibraltar DLT licence is enough to serve clients globally without further regulatory engagement. That assumption is not correct. The Gibraltar licence authorises the Gibraltar entity to operate from Gibraltar; it does not override the regulatory requirements of the jurisdictions where clients are located. An exchange serving US persons needs to consider FinCEN, state money-transmitter licensing, and CFTC/SEC exposure. An exchange serving EU clients post-MiCA needs to consider CASP authorisation. The Gibraltar licence is one layer in a multi-jurisdiction stack, not a substitute for the others.
Related at OBOLUS
- Licensing and registration for digital-asset businesses – the full practice overview across 70+ jurisdictions and licence types
- VARA licence application in Singapore – a comparable analysis for operators considering the Singapore MAS regime
- DAO legal wrappers compared: foundation, LLC and association – structuring considerations where the exchange entity is DAO-adjacent
FAQ
How long does a crypto licence take to obtain?
Timeline varies significantly by jurisdiction and the maturity of the applicant's compliance infrastructure. In Gibraltar, the GFSC does not publish a fixed statutory determination period; principles-based assessment means the clock is driven by the quality of the submission and the regulator's current caseload. Well-prepared applications from operators with established controls are typically determined within a matter of months. Applications that require multiple information-request rounds can take considerably longer. Pre-application engagement with the GFSC is the most reliable way to compress the timeline.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. The right jurisdiction depends on your target user base, your operating model, your investors, your banking requirements, and your tax objectives. Gibraltar suits operators who value a common-law English-language regime, territorial tax, and a principles-based supervisor with a crypto-specific track record – but it does not provide EU MiCA passporting. EU-facing businesses typically need a MiCA CASP authorisation in an EU member state alongside any Gibraltar structure. We map the licence, banking, and tax stack as a coordinated exercise before any application is filed.
Do I need a separate custody licence?
Under Gibraltar's DLT regime, custody of client assets is addressed within the DLT Provider licence framework rather than as a separate regulatory category. The GFSC's custody-related principles – covering asset segregation, safeguarding, and operational resilience – are assessed as part of the single DLT licence application. In other jurisdictions, custody is a separately licensed activity: MiCA, for example, treats crypto-asset custody as a distinct CASP service category. If your exchange model involves holding client assets across multiple jurisdictions, each operating entity's custody posture must be assessed against the local regime. A single licence answer rarely holds across a multi-jurisdiction structure.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence stack across operating, custody and payment layers before you commit capital to a structure – because a licence obtained in the wrong sequence, or without the right cross-border architecture, rarely solves the business problem it was meant to solve. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialises in DLT regulatory authorisation, GFSC applications, and cross-border licence stack design for crypto exchanges and custodians.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.