EST · MMXXVI
Home/Jurisdictions/Malta/Crypto exchange setup in Malta: Legal Requirements for Businesses
Licensing & Registration

Crypto exchange setup in Malta: Legal Requirements for Businesses

Crypto exchange setup in Malta. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Operating a crypto exchange without the correct regulatory authorisation in Malta exposes the business to enforcement action, frozen payment rails and the near-certain loss of banking relationships. As the MFSA (Malta Financial Services Authority) completes the transition from its domestic VFA framework (Virtual Financial Assets framework) to full MiCA (Markets in Crypto-Assets Regulation) alignment, the regulated perimeter is tightening – not widening. Businesses that secured registration under the earlier regime cannot assume that registration carries forward automatically. This page sets out the legal requirements, the process, and the decisions an inbound operator must take before committing capital to a Maltese structure.

Malta remains one of the most structurally coherent EU access points for a crypto exchange. A CASP authorisation obtained here passes across the entire EU/EEA under the MiCA passporting mechanism, meaning a single competent authority relationship can underwrite a multi-territory operating footprint. That advantage does not come without friction: the MFSA applies substantive scrutiny to governance, capital adequacy and AML/CFT systems. The sections below explain what that scrutiny looks like in practice.

What activities require authorisation under Malta crypto law?

Any business that operates a crypto exchange, provides custody, executes orders, operates a trading platform, or places crypto-assets for clients in Malta – or that is incorporated in Malta and serves users elsewhere in the EU – requires CASP authorisation (Crypto-Asset Service Provider authorisation) under the applicable MiCA provisions as administered by the MFSA. The prior VFA agent model, which allowed a lighter-touch supervised entry, is being phased out as MiCA's transitional provisions run their course.

The core activity that most inbound operators are building toward is operation of a trading platform for crypto-assets – the equivalent of what the VFA framework called a "VFA Exchange." Under MiCA, this is a defined CASP service. It requires full authorisation, not mere registration. The distinction matters enormously at the banking stage: correspondent banks and payment processors routinely check CASP status before onboarding, and an entity holding only a legacy registration will increasingly find those checks failing.

MiCA defines ten CASP services, and an entity must be authorised for each service it intends to provide. An exchange that also offers custody – a common design choice – needs authorisation for both the trading platform and the custody service. Bundling those activities under a single MFSA application is possible, but the capital and governance requirements stack accordingly.

One category that operators sometimes underestimate is the issuance of ARTs (asset-referenced tokens) or EMTs (e-money tokens). If the exchange plans to issue a stablecoin or a platform token that qualifies as an ART or EMT, a separate issuer authorisation is required. The MFSA has made clear it will apply the whitepaper and reserve requirements under the applicable MiCA provisions with full force.

How does the MFSA CASP application process work?

The MFSA application for CASP authorisation is a structured, document-intensive process that rewards thorough pre-application preparation. The authority operates a pre-licensing engagement model: operators are expected to submit a pre-application pack before lodging the formal file. That pack covers the intended service scope, the ownership and governance structure, and a preliminary AML/CFT framework description.

Once the pre-application is accepted, the formal submission must include a comprehensive regulatory business plan, financial projections, a detailed AML/CFT policy manual, compliance arrangements (including the appointment of a resident compliance officer), and fit-and-proper documentation for all qualifying shareholders and senior management. The MFSA may request supplementary information at any point, and the clock on the assessment period effectively restarts with each material information request. Operators who treat the process as a document-submission exercise rather than a substantive regulatory dialogue consistently underestimate the elapsed time.

Under the MiCA transitional provisions, existing VFA-registered entities in Malta have a defined window to seek full CASP authorisation before their prior status lapses. The MFSA has communicated expectations through supervisory guidance. A new entrant with no prior Malta footprint starts the CASP process from scratch and should plan for a timeline measured in months, not weeks – the precise duration turns on application quality, the complexity of the service scope and the MFSA's own supervisory queue.

In our licensing practice, we structure the pre-application package before a client approaches the MFSA. That sequence matters: the questions the authority asks in pre-application dialogue are the same questions that determine application quality. Arriving with a completed governance framework and a live AML manual – not a draft – shortens the substantive review period materially.

CTA #1 — The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. For a scoped assessment of your Malta licensing position, contact OBOLUS at info@oboluslaw.com. Or map your options online.

What governance and compliance systems does the MFSA expect?

The MFSA expects a resident governance presence, not a brass-plate structure. A CASP applicant must demonstrate that its mind and management operates from, or has meaningful operational ties to, Malta. The compliance function must be headed by a qualified, MFSA-approved compliance officer who is accessible to the authority in real time. The MLRO (Money Laundering Reporting Officer) role may be combined with the compliance officer function for smaller entities, but the individual must satisfy the MFSA's fitness and propriety criteria independently.

Internal governance requirements include a documented risk appetite, a board-approved AML/CFT policy, transaction monitoring procedures calibrated to the exchange's specific user and product profile, and a Travel Rule compliance programme. The Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer) applies under the applicable EU provisions, and the MFSA has signalled that Travel Rule readiness is assessed as part of the authorisation process, not deferred to post-licensing supervision.

For exchanges with a cross-border user base – which describes virtually every Malta-based operator in practice – the compliance architecture must address the EU's AML/CFT baseline derived from FATF Recommendation 15, the applicable Travel Rule data threshold (which varies by jurisdiction for transfers outside the EU), and any enhanced due diligence obligations triggered by the user's home jurisdiction. A compliance system designed only for Maltese users will not survive MFSA scrutiny once the authority reviews the actual transaction profile.

How does EU passporting work for a Malta-authorised exchange?

A CASP authorised by the MFSA under MiCA may passport its services across every EU and EEA member state by notifying the MFSA and following the prescribed passporting procedure, without needing separate national authorisations in each target market. This is the structural argument for Malta as an EU licensing base, and it is a real one – but its practical value depends on the operator understanding what passporting covers and what it does not.

Passporting covers the CASP services listed in the authorisation. It does not override local consumer protection rules, local financial promotion regimes or local tax treatment of crypto transactions in the target state. A Malta-licensed exchange marketing to German retail users must comply with German financial promotion requirements even while relying on its MFSA authorisation for service delivery. The same principle applies across the bloc. Operators who treat the passport as a licence to ignore host-state rules consistently encounter enforcement attention from host NCAs (national competent authorities).

The cross-border tax interaction is equally non-trivial. A Malta-incorporated exchange typically benefits from Malta's participation-exemption regime for dividend distributions and may achieve a relatively efficient effective corporate tax rate through the refundable tax credit system – but the precise tax outcome depends on the shareholding structure, the nature of the income and the tax residency of the operating entity. These are not defaults; they require deliberate structuring. We regularly advise operators who arrive with a Malta company already formed but without a tax opinion, and the structural choices that were obvious on day one have become expensive to undo.

How does a Malta crypto exchange access banking and payment rails?

Banking is the practical chokepoint for most Malta-based crypto exchange setups, and it is the issue that a regulatory authorisation alone does not solve. The MFSA's authorisation satisfies the regulatory precondition that most EU banks require before even entering into AML due diligence on a crypto business. It does not guarantee account approval. Maltese domestic banks have historically been cautious toward crypto businesses; the more active banking relationships for Malta-licensed exchanges tend to run through EMI (electronic money institution) accounts or through EU banking relationships in jurisdictions with more established crypto-banking infrastructure.

A well-structured Malta exchange will typically layer its payment architecture: a primary banking relationship for corporate treasury and fiat settlement, an EMI account for client fiat flows, and potentially a direct SEPA participant relationship for high-volume operations. Each layer has its own onboarding process and its own AML questionnaire. The MFSA authorisation document and the approved compliance manual are the two materials that move EMI onboarding conversations forward most efficiently.

Operators with a non-EU parent or a significant proportion of non-EU users will face enhanced due diligence at the banking stage. The bank's correspondent network – not just the bank itself – must be comfortable with the originating entity's AML posture. We have seen well-structured Malta applications stall at the banking stage because the parent-company AML framework had not been updated to reflect the subsidiary's regulated status. The solution is to treat banking onboarding as a parallel workstream to the MFSA application, not a sequential step after authorisation.

CTA #2 — If a prior application stalled or a banking relationship was declined, a second read of the structure often surfaces the cause. To map the licence, banking and payment stack for your Malta build, write to OBOLUS at info@oboluslaw.com. Or map your options online.

A recent structuring instruction

In a recent licensing instruction, an exchange operator incorporated outside the EU sought to establish a Malta CASP entity as the regulated hub for EU-facing services. The operator had an existing VASP registration in a non-EU jurisdiction and assumed it could be presented to the MFSA as evidence of regulatory standing. We advised that the MFSA treats prior non-EU VASP registrations as background context only – not as a substitute for satisfying the MiCA authorisation criteria. We rebuilt the governance structure from the compliance officer level up, mapped the Travel Rule programme to the operator's actual transfer profile, and structured the banking onboarding as a concurrent workstream. The application was submitted in a complete state on the first lodgement, materially reducing the risk of information-request delays. The entity is in active MFSA review.

Which operator profile should choose Malta?

Malta is the right primary licensing jurisdiction for a specific set of operator profiles. It is not the right choice for every crypto business seeking EU access, and the decision should be made against the alternatives rather than in isolation.

Profile A – the EU-first exchange: an operator whose primary user base is EU/EEA residents, whose founders have a demonstrable connection to a EU regulatory environment, and whose governance team can provide a genuine Malta presence. For this profile, a Malta CASP authorisation with full MiCA passporting is the efficient path. The timeline is measured in months; the principal risk is application quality.

Profile B – the globally distributed exchange: an operator with significant non-EU user volume, complex token products and multi-jurisdiction banking needs. For this profile, a Malta CASP authorisation remains useful for the EU segment, but it should sit alongside – not substitute for – authorisations in the jurisdictions where the core user base resides. VARA in Dubai, the MAS Payment Services Act regime in Singapore, or the SFC's VATP licensing in Hong Kong may each be necessary for the non-EU book. Treating Malta as the single global answer will create regulatory gaps that enforcement bodies in other markets are increasingly willing to act on.

Profile C – the token issuer adding exchange functionality: an operator whose primary activity is token issuance under MiCA's ART or EMT regime, who wants to offer secondary trading. This profile faces the most complex MFSA engagement: issuer authorisation and CASP authorisation are distinct processes, and the compliance architecture must satisfy both. The capital requirements stack. The governance burden is materially higher. Early counsel engagement – before structuring decisions are made – is non-negotiable for this profile.

A common assumption is that a single offshore registration is sufficient to serve clients globally. It is not. The determining factor is where the users are located, not where the entity is incorporated. An exchange incorporated in a low-scrutiny jurisdiction but actively serving EU retail users is within scope of MiCA enforcement regardless of where the server or the bank account sits. We address this myth directly with every inbound client who arrives with an existing structure built on that assumption.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

In Malta, a CASP authorisation under the applicable MiCA provisions typically takes several months from formal submission to decision. The elapsed time depends on application completeness, the scope of services being authorised, and the MFSA's current supervisory workload. Applications that require multiple rounds of supplementary information requests can take considerably longer. Pre-application engagement and submitting a complete file on first lodgement are the two most effective ways to manage the timeline.

Which jurisdiction is best for licensing my crypto business?

There is no universal answer. The right jurisdiction depends on where your users are located, the services you provide, your governance capacity and your banking strategy. Malta offers MiCA passporting across the EU/EEA and is well-suited for EU-facing exchanges. VARA in Dubai, the MAS regime in Singapore and the SFC regime in Hong Kong serve different geographic and product profiles. Many established operators hold authorisations in more than one jurisdiction. We assess the full stack before recommending a primary hub.

Do I need a separate custody licence?

Under MiCA, custody and administration of crypto-assets on behalf of clients is a distinct CASP service that requires separate authorisation. An exchange authorisation does not automatically cover custody. If your exchange holds client assets – including during the settlement window – you are likely providing custody within the meaning of the applicable regime and must be authorised accordingly. The precise scope of what constitutes custody under your specific operating model should be assessed by counsel before you structure the entity.

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com or message us via t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in CASP and VASP authorisation for crypto exchanges across EU and multi-hub structures.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours