Operating a digital-asset custody business without the right regulatory authorisation is not a theoretical risk. In Gibraltar, custodians holding client keys or controlling access to digital assets require a licence under the Distributed Ledger Technology (DLT) Providers regime – the regulatory framework administered by the Gibraltar Financial Services Commission (GFSC) that has governed crypto businesses since 2018. A custody service launched without that authorisation faces enforcement, restricted access to banking rails and the prospect of unwinding a business that took months to build. This page maps the Gibraltar custody-licensing process, the cross-border interactions that most inbound operators miss and the decision points that determine whether Gibraltar is the right home for your operation.
Gibraltar's DLT Providers Regime: The Regulated Perimeter
Gibraltar's GFSC operates the world's first purpose-built statutory framework for businesses using distributed ledger technology to store or transmit value belonging to others. The DLT Providers regime came into force in January 2018, predating MiCA by several years and establishing a principles-based authorisation structure that has attracted custody operators, exchanges and payment processors. The GFSC issues a DLT Provider Licence to businesses whose core service involves using DLT in the course of a business for the storage or transmission of value. Custody – the holding of cryptographic keys on behalf of clients, whether in hot, warm or cold infrastructure – squarely fits that definition.
The regime is principles-based rather than rules-prescriptive. The GFSC publishes nine core principles covering honesty, financial soundness, risk management, cybersecurity, resilience, anti-financial-crime procedures, outsourcing, governance and consumer protection. Applicants demonstrate compliance with each principle through their governance documentation, policies and operational architecture. This approach gives flexibility to sophisticated operators but places the evidential burden firmly on the applicant.
A custody-only business and a full-service exchange both require authorisation under the same DLT Provider Licence. The activity scope is assessed at the point of authorisation, so a business adding custody to an existing exchange service must notify the GFSC and have that activity approved. The GFSC also distinguishes between custodying assets for sophisticated counterparties and operating a retail-facing service; the consumer-protection principle attracts additional scrutiny in the latter case.
For inbound operators, the critical early question is whether their custody architecture – particularly the jurisdictions where servers sit, where staff are located and where client funds flow – brings additional regulatory obligations beyond the Gibraltar licence. We examine that question in the cross-border section below.
Who Needs a DLT Provider Licence for Custody?
Any business using DLT to store or transmit value belonging to others, in the course of a business, and carrying on that activity in or from Gibraltar, requires a DLT Provider Licence from the GFSC. The "in or from" formulation is important: a business incorporated in Gibraltar but servicing clients elsewhere is caught, and so is a business with operational staff or key infrastructure in Gibraltar even if incorporated offshore.
Businesses that fall squarely within scope include standalone digital-asset custodians, exchanges offering custody as part of their service, wallet providers holding custody keys, and institutional settlement agents maintaining digital-asset positions for clients. Businesses that may be borderline include pure technology vendors providing key-management software without taking custody themselves, and DeFi protocols where custody is non-custodial by design. The GFSC has published guidance on the perimeter and expects businesses with genuine uncertainty to seek a regulatory opinion before operating.
A common mistake at the perimeter stage is assuming that because a business does not hold fiat currency it falls outside financial regulation. The DLT regime is asset-agnostic: it covers custody of any value transmitted via DLT. An operator holding stablecoins, tokenised securities or utility tokens on behalf of clients is within scope unless the GFSC has confirmed otherwise in writing.
A practical note for inbound operators: the GFSC expects the licence applicant to be the operating entity in Gibraltar. A holding-company structure with the operational entity elsewhere and only a thin presence in Gibraltar will not satisfy the "in or from" requirement for genuine substance. The GFSC assesses the actual decision-making location, the residency of senior management and the physical presence of the business.
For a scoped analysis of whether your custody architecture requires a Gibraltar DLT licence, contact OBOLUS at info@oboluslaw.com. The process above describes the standard perimeter test. Your facts – the entity structure, the client base, the server location – change the analysis. Map your options.
What Does the Gibraltar DLT Licence Application Process Involve?
The Gibraltar DLT licence application is a structured submission to the GFSC covering corporate governance, financial soundness, AML/CFT compliance, cybersecurity architecture and the fitness and propriety of key individuals. The GFSC does not publish a single fixed timeline, but in our cross-border practice we have seen well-prepared applications progress from formal submission to in-principle approval across a period of several months, with the pace heavily influenced by the quality of the initial submission and the GFSC's query cycle.
The application comprises several core workstreams. First, the corporate file: the applicant must be a Gibraltar-incorporated entity (or establish a Gibraltar branch of a foreign entity in limited circumstances). The GFSC requires evidence of directors, shareholders and beneficial owners, constitutional documents, group structure charts and evidence of registered office and genuine operational presence. Second, the business plan and financial projections: the GFSC assesses the commercial rationale, the revenue model and the applicant's financial resources. Minimum capital requirements vary by licence category and are confirmed by the GFSC on a case-by-case basis. Third, the policy and controls package: applicants submit policies covering AML/CFT, sanctions screening, cybersecurity incident response, business continuity, outsourcing and complaints handling. Each policy must be operationally credible – the GFSC expects evidence that policies have been implemented, not merely drafted.
The individual-vetting component deserves particular attention. Every director, controller and key function holder undergoes a fit-and-proper assessment. The GFSC requires detailed personal declarations, criminal-record checks, financial history and regulatory references. Delays at this stage are common when applicants have complex international backgrounds, prior regulatory interactions or cross-border enforcement history. Early identification and management of potential vetting issues is critical to programme timing.
In practice, most delays arise not from regulatory hostility but from incomplete submissions. The GFSC issues a query letter after initial review; each round of queries extends the programme. Operators who submit a complete, well-evidenced file with a credible operational plan consistently move through the process faster than those who treat the application as a formality.
AML, CFT and the Travel Rule in Gibraltar
Gibraltar's AML/CFT regime for DLT Providers is aligned with the FATF Recommendations, including FATF Recommendation 15 on virtual assets, and incorporates the Travel Rule obligation – the requirement to pass originator and beneficiary data alongside virtual-asset transfers above the applicable threshold. The GFSC expects DLT Providers to have operational Travel Rule compliance before they begin processing transfers, not as a post-launch project.
For a custody operator, Travel Rule compliance has a specific operational dimension. When a custodian moves assets on behalf of a client to a third-party address – whether an exchange wallet, a counterparty settlement address or a client self-custody wallet – it must collect and transmit the required originator and beneficiary data to the receiving VASP, and receive equivalent data from sending VASPs. Where the receiving address is an unhosted wallet, the GFSC expects a documented risk-based approach to verification.
The practical complexity arises in the cross-border context. A Gibraltar custodian receiving transfers from a Singapore exchange, a Cayman fund administrator or a US institutional client faces counterparties operating under different Travel Rule regimes – the MAS framework, the applicable Cayman provisions and the FinCEN rules respectively. Ensuring that data flows meet the Gibraltar standard even where the counterparty's domestic standard differs is an operational and legal challenge that we regularly advise on.
Gibraltar's AML supervision is conducted by the GFSC directly. Periodic thematic reviews and individual inspections form part of the ongoing supervisory cycle. DLT Providers are expected to maintain detailed transaction records, conduct enhanced due diligence on high-risk clients and jurisdictions, and file suspicious-activity reports to the Gibraltar Financial Intelligence Unit. An inadequate AML programme is one of the most common grounds for licence conditions, variation or refusal.
How Does Gibraltar Custody Licensing Interact With Other Jurisdictions?
A Gibraltar DLT licence authorises custody operations in and from Gibraltar. It does not automatically confer the right to solicit or serve clients in regulated jurisdictions that require local authorisation for custody services – and this is where many operators discover that a single licence is insufficient for their actual business model.
Consider a Gibraltar custodian whose clients include EU institutional investors. MiCA requires that custody services provided to EU clients be authorised as a CASP activity by a competent authority in an EU member state. The Gibraltar DLT licence does not provide MiCA passporting rights; Gibraltar is not an EU member state. The operator faces a choice: restructure the EU-client service through an EU-authorised entity (a MiCA CASP in, for example, a Baltic state or Malta), restrict EU clients to a non-solicitation model that relies on reverse enquiry, or cease EU institutional custody altogether. Each path has different legal, operational and commercial consequences.
A similar analysis applies to US clients. A Gibraltar custodian holding assets for US persons or entities may engage the remit of the SEC, CFTC or FinCEN depending on the nature of the assets held. The NYDFS BitLicense regime applies to businesses engaging in virtual currency business activities involving New York residents. Operating for US clients under a Gibraltar licence alone, without a clear analysis of the US regulatory position, exposes the operator to cross-border enforcement risk.
In our practice, we advise inbound Gibraltar operators to map three layers from the outset: the home jurisdiction (Gibraltar – the DLT licence), the client jurisdictions (where clients are domiciled and whether those jurisdictions require local licensing for custody services), and the banking layer (where the operator banks and which AML standards the banking relationship requires). Misalignment between any two layers creates a vulnerability that regulators in the more assertive jurisdictions will find.
The tax layer adds a further dimension. Gibraltar currently does not impose capital gains tax and operates a territorial income tax regime, which has made it attractive for certain digital-asset businesses. However, the officers and employees of a Gibraltar custodian may be tax-resident elsewhere; the beneficial owners of the entity may sit in jurisdictions with controlled-foreign-corporation rules; and the substance requirements needed to defend Gibraltar tax treatment continue to evolve in line with international BEPS standards. Structuring the custody entity without mapping the tax position of the principals and the group is a common oversight.
If prior applications have stalled or banking has been declined after authorisation, the structural reason is usually identifiable. Contact OBOLUS at info@oboluslaw.com for a second-read analysis. Map your options.
What Are the Banking Realities for a Licensed Gibraltar Custodian?
Securing a bank account for a licensed digital-asset custodian in Gibraltar is a workstream that demands as much planning as the regulatory application itself. Gibraltar has a small domestic banking sector, and global correspondent banks apply intensive due-diligence requirements to digital-asset businesses regardless of their regulatory status. A DLT Provider Licence from the GFSC is a necessary condition for banking access; it is not sufficient on its own.
Banks that engage with Gibraltar DLT Providers typically require a complete regulatory file including the licence certificate, the AML policy suite, the business plan with projected transaction flows, details of the source-of-funds framework for client onboarding and evidence of Travel Rule compliance systems. Some banks require an independent AML audit before account opening. The timeline from licence grant to operational bank account can extend the overall programme significantly if banking preparation is not run in parallel with the licensing process.
We have seen operators who obtained their DLT licence without a banking strategy in place face months of delay before becoming operationally live. The practical lesson is clear: begin bank-relationship mapping at the pre-application stage, identify the likely correspondent-bank chain and engage early with the compliance teams of prospective banking partners. A Gibraltar custodian that can demonstrate a clean regulatory file, a well-documented AML programme and a credible institutional client base is materially better positioned than one presenting to a bank cold after licence grant.
For custody operators holding stablecoins – particularly USDT and USDC – the operational infrastructure extends to the issuer layer. Tether and Circle maintain contract-level freeze authority over their issued tokens and act on court orders, law-enforcement designations and OFAC requests. A custodian holding large stablecoin balances on behalf of clients must understand the conditions under which that freeze authority can be exercised and factor that risk into its custody architecture and client disclosures.
A Recent Custody-Licensing Matter: The Gibraltar Entry Decision
In a recent licensing matter, a digital-asset fund administrator domiciled in a mid-Atlantic offshore jurisdiction sought Gibraltar authorisation to expand its custody service to European institutional clients. We conducted a pre-application regulatory analysis, identifying that the entity's existing shareholder structure included a passive investor with a prior regulatory caution in a non-EU jurisdiction – a factor that would have triggered a protracted fit-and-proper inquiry had it emerged mid-application. We restructured the shareholder layer before submission, prepared the full policy suite and coordinated the individual-vetting declarations for four directors across three jurisdictions. The application proceeded to in-principle approval without a material query round. The operator has since appointed a banking partner and is preparing to commence live custody operations. Separately, we advised on the MiCA interface, identifying that a thin-presence EU entity would be required to serve certain regulated institutional clients without relying on reverse enquiry.
Which Operator Profile Is Best Suited to a Gibraltar DLT Custody Licence?
The Gibraltar DLT regime suits a specific set of operator profiles. Understanding where your business fits determines whether Gibraltar is the optimal licensing home or a sub-optimal choice that will require supplementary authorisations at significant additional cost.
Profile A – Institutional-facing custodian with a global but non-EU client base. An operator serving hedge funds, family offices and corporate treasuries domiciled outside the EU – in the Gulf, Asia-Pacific or the Americas – can operate effectively under a Gibraltar DLT licence without the MiCA passporting constraint. Gibraltar's common-law legal environment, its English-language regulatory process and its proximity to London financial infrastructure are genuine advantages. The licensing timeline is manageable, and the principles-based regime rewards operators with strong institutional governance. The key risk is banking: the operator must invest early in the banking strategy.
Profile B – Operator building toward EU institutional business. A business that expects EU-regulated institutional clients to form a significant part of its revenue should consider whether a Gibraltar licence alone will sustain that model. The absence of MiCA passporting is a structural constraint. The more cost-efficient path for this profile may be a dual structure: a Gibraltar DLT licence for the non-EU book alongside a MiCA-authorised CASP entity in an EU member state for the EU-regulated institutional mandate. We have seen this dual structure become the default for ambitious custody operators in the post-MiCA environment.
Profile C – Technology-first operator with an evolving custody model. An operator whose custody activity is secondary to a primary service (such as a DeFi protocol adding institutional custody functionality) faces a complex perimeter question. The GFSC's principles-based regime may treat that evolving model as within scope from the point at which custody of client value becomes a material activity. Early regulatory engagement – ideally before product launch – is essential for this profile. Proceeding without guidance and later discovering that the activity has been in scope for months is a scenario we have seen play out poorly.
A Common Assumption About Gibraltar Licensing
A common assumption among inbound operators is that obtaining a Gibraltar DLT licence is sufficient to operate a custody business serving clients in any jurisdiction. This assumption is incorrect, and acting on it creates the precise enforcement exposure that the licensing process is designed to avoid. The Gibraltar DLT licence authorises the business to operate in and from Gibraltar. It does not override the licensing requirements of client jurisdictions. An operator serving EU institutional clients without MiCA authorisation, or engaging US persons without addressing the applicable federal and state requirements, is operating unlicensed in those markets regardless of its Gibraltar status. The licensing stack – home jurisdiction, client jurisdictions, banking jurisdiction – must be assessed as a whole. We map that stack before our clients commit to a structure, not after a problem arises.
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – how we structure the full licensing mandate across jurisdictions and activity layers
- CASP Authorisation Under MiCA – the EU passporting regime for crypto-asset service providers and the authorisation process
- Fiat On/Off-Ramp Banking in Lithuania – the EU banking interface for digital-asset businesses and the VASP-banking interaction
FAQ
How long does a crypto licence take to obtain?
In Gibraltar, a well-prepared DLT Provider Licence application typically progresses from formal submission to in-principle approval across a period of several months. The GFSC does not publish a fixed timeline; the actual duration depends on the completeness of the initial submission, the complexity of the applicant's ownership structure and the pace of the individual fit-and-proper vetting process. Incomplete applications that generate multiple query rounds materially extend the programme. Preparation – including pre-application engagement with the GFSC – is the most effective way to manage the timeline.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. The optimal licensing jurisdiction depends on the activity (custody, exchange, payment, issuance), the client base (retail or institutional, EU or non-EU), the banking strategy and the tax position of the principals. Gibraltar suits institutional-facing custodians with non-EU client books. An operator targeting EU institutional clients needs a MiCA-authorised CASP alongside any offshore licence. The right answer is a licence-stack analysis, not a single jurisdiction recommendation. We conduct that analysis before an operator commits capital to any structure.
Do I need a separate custody licence?
In Gibraltar, the DLT Provider Licence covers custody as a regulated activity; there is no separate standalone custody licence category distinct from the main DLT authorisation. However, the scope of your licence is assessed against the activities you declare. An exchange operator adding custody services must have that activity within the authorised scope; the GFSC does not automatically extend coverage. In other jurisdictions – MiCA being the clearest example – custody of crypto-assets on behalf of third parties is an explicitly enumerated CASP activity requiring separate authorisation if not covered by a prior authorisation. Cross-border operators should not assume their home licence covers custody in every market they serve.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, banking and tax stack across operating, custody and payment layers before our clients commit to a structure – rather than treating those workstreams as three disconnected mandates. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialist in digital-asset regulatory authorisation across common-law and civil-law regimes, with a focus on inbound licensing strategy for custody and exchange operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.