EST · MMXXVI
Home/Jurisdictions/Malta/Digital-asset custody authorisation in Malta
Licensing & Registration

Digital-asset custody authorisation in Malta

Digital-asset custody authorisation in Malta. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Custody of client digital assets is a regulated activity in Malta. Any business holding, safeguarding or controlling cryptographic keys on behalf of third parties requires formal authorisation from the Malta Financial Services Authority (MFSA) before operations begin. The applicable regime has shifted materially as the EU's Markets in Crypto-Assets Regulation (MiCA) displaces the prior Virtual Financial Assets (VFA) framework — and a business that structured its licence plan even eighteen months ago may be working from an outdated map. This page sets out what custody authorisation now requires, how the application process runs, where cross-border complexity accumulates, and the decision points that matter most for an inbound operator.

What is the regulated basis for digital-asset custody in Malta?

Digital-asset custody in Malta is a licensed financial-services activity under both the transitional VFA regime and, going forward, the CASP authorisation (Crypto-Asset Service Provider) introduced by MiCA. The MFSA is the national competent authority (NCA) for Malta under MiCA and supervises the transition from VFA to CASP authorisation. Custody is expressly enumerated as a crypto-asset service under MiCA, meaning a firm that holds or controls crypto assets on behalf of clients must obtain a CASP authorisation covering that activity — it cannot be bundled informally into another licence category without explicit regulatory consent.

Malta's VFA framework was one of the first purpose-built crypto-licensing regimes in the EU. It introduced the concept of a VFA agent — a licensed intermediary that sponsors and submits licence applications to the MFSA on behalf of applicants. Under the MiCA transition, that VFA-agent concept does not carry forward in the same structural form, but the practical expectation that applicants engage experienced regulatory counsel before submitting remains firmly in place. The MFSA has signalled clearly that incomplete or insufficiently substantiated applications will not advance.

The substance-over-label principle governs classification. Whether an arrangement constitutes custody turns on the actual control a firm exercises over client assets — not on how the relationship is documented commercially. A firm acting as a "technical administrator" that controls private keys in practice is a custodian in regulatory terms, regardless of contractual framing.

How does the MiCA transition affect existing and new applicants?

MiCA's CASP authorisation regime is now the operative pathway for new custody applicants in Malta, with the prior VFA authorisation track closing to new entrants under the MFSA's transition timetable. Firms that held a VFA licence before MiCA's CASP provisions became directly applicable benefit from a grandfathering window, but that window is time-limited and conditional on the firm meeting MiCA's substantive requirements within the prescribed period. New applicants have no access to the legacy VFA route — they apply directly under MiCA via the MFSA.

The practical significance for an inbound operator is considerable. MiCA imposes a standardised authorisation framework across all EU member states, meaning a CASP authorisation granted by the MFSA carries passporting rights throughout the EU and EEA. A custody business authorised in Malta can provide custody services to clients across the EU without a separate licence in each member state. That passporting logic is one of the primary reasons a Malta CASP authorisation remains commercially attractive despite the heavier regulatory burden MiCA introduces compared with the legacy VFA regime.

In our practice, we see applicants underestimate the time required to assemble MiCA-compliant governance documentation — the policies, procedures and organisational frameworks that the MFSA reviews before it accepts an application as complete. Treating the documentation phase as a back-office task, rather than a substantive legal and compliance exercise, is the single most reliable way to extend an application timeline unnecessarily.

If you are structuring a custody operation for the EU market and need to map the MiCA authorisation path accurately, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts — the entity structure, the user base, the custody model — change the analysis meaningfully.

What does the CASP authorisation process involve for a custody applicant?

A CASP authorisation application for custody in Malta proceeds through several structured stages, each requiring substantive preparation before submission to the MFSA. The process begins well before a formal file is lodged.

The pre-application phase involves scoping the business model against MiCA's custody service definition, assessing whether additional activity categories (exchange, transfer, administration) are needed alongside custody, and establishing the Maltese legal entity that will hold the authorisation. An entity incorporated in Malta — typically a private limited liability company — must exist before an application can be submitted. That incorporation step, including the opening of a local corporate bank account, can itself consume meaningful time and requires a banking relationship with an institution willing to serve a crypto-business client. Banking access for digital-asset firms in Malta and across the EU generally is not guaranteed and warrants early parallel attention.

The application file itself addresses the firm's legal and ownership structure, the fitness and propriety of all qualifying shareholders and senior management, the governance framework (board composition, internal controls, risk management), the AML/CFT programme, the custody-specific operational policies (key management, segregation, insurance or alternative cover), the business plan and financial projections, and the IT security and business continuity arrangements. MiCA sets out the categories of information required; the MFSA may specify additional local requirements or request supplementary material during its review.

The MFSA issues an acknowledgement once an application is submitted and is permitted under MiCA's procedural rules to request clarifications during the assessment period. The assessment clock runs from the date the application is deemed complete — not from the date of first submission. Practically, that distinction matters: an application submitted with gaps will not start the formal assessment period and will instead sit in a pre-completeness phase while the MFSA requests and the applicant provides missing material.

Applicants we advise routinely find that the fitness-and-propriety assessment of controllers and senior managers — which requires detailed personal questionnaires, criminal record checks and financial soundness declarations from multiple jurisdictions — is the stage most likely to introduce delays if not prepared systematically in advance.

What are the capital and governance requirements for a Malta custody CASP?

MiCA sets minimum own-funds requirements that vary by the category of crypto-asset service being provided, with custody services carrying a specific capital threshold distinct from, for example, exchange or advisory services. Because the MFSA has not publicly fixed a single definitive number independent of the MiCA text and its own supervisory guidance — and because the relevant figures are subject to supervisory interpretation — this page describes the structure rather than states a specific amount. In practice, the minimum is meaningful for a start-up business and warrants early financial modelling. Where a firm provides multiple CASP services simultaneously, the applicable capital requirement reflects the combined activity profile.

Governance requirements under MiCA for a custody CASP are substantive. The firm must have at least two mind-and-management individuals based in Malta — the "two directors" principle — who collectively possess demonstrable experience relevant to the firm's activities. The MFSA expects genuine local substance, not a brass-plate presence. Board oversight of the custody function, documented delegation of authority, and clear lines of responsibility between the compliance, risk and operations functions are minimum expectations.

The AML/CFT framework for a custody CASP must satisfy both MiCA's requirements and Malta's own anti-money-laundering legislation, which implements the EU's AML directives. The Travel Rule — the obligation under FATF Recommendation 15 to pass originator and beneficiary information alongside virtual-asset transfers — applies to transfers connected with custody operations above the applicable de-minimis threshold. The threshold varies by jurisdiction and is set qualitatively in the current supervisory environment; operators should treat any threshold as potentially low and build Travel-Rule capability into the technical architecture from the outset.

How does a Malta custody authorisation interact with cross-border operations?

The EU passporting right that accompanies a Malta CASP authorisation is the most commercially significant cross-border feature, but it does not resolve every jurisdiction question an operator faces. Passporting permits the provision of custody services to clients across the EU from the Malta-authorised entity. It does not authorise custody services to clients in third-country jurisdictions — the UK, the US, Switzerland, Singapore, the UAE, or any non-EEA market — where separate registration, licensing or regulatory engagement may be required.

Operators we advise regularly discover this gap at a late stage in their commercial planning. A custody firm with a Malta CASP authorisation and clients in the UK is providing a regulated service in the UK to FCA-supervised counterparts; the Malta authorisation provides no cover in that context. The analysis differs for each additional market. The US presents a particularly layered picture, involving federal-level oversight by FinCEN and the SEC or CFTC depending on asset classification, state money-transmitter licensing across relevant states, and potential NYDFS BitLicense requirements for New York-connected activity.

The tax dimension of a Malta structure is separate from the licensing analysis and requires its own assessment. Malta operates a full-imputation corporate tax system with significant refund mechanics for qualifying shareholders; the application of that system to crypto-asset income, staking rewards and custody fees involves a classification exercise that should be completed before the entity structure is finalised. VAT treatment of custody services in Malta aligns with EU VAT directives, though the characterisation of specific fee types warrants confirmation with tax counsel.

Banking for the Malta custody entity is a practical constraint that the regulatory analysis does not resolve. Malta-incorporated digital-asset businesses have found the local banking environment cautious; correspondent banking access for the custody entity and for its clients' fiat on-ramp and off-ramp requirements needs to be assessed in parallel with, not after, the licence application process. We map the banking dimension alongside the licensing analysis as a matter of course — a licence without banking rails is commercially inoperable.

If a prior Malta application stalled or a banking relationship has closed, there is usually a structural explanation and a route forward. Write to info@oboluslaw.com for a second read. Identifying the structural reason for the impasse is the first step; addressing it before resubmission is the second.

A cross-border custody matter: passporting assumptions tested

In a recent licensing matter, a payments business incorporated in a major EU member state sought to extend its custody offering to institutional clients across three additional EU markets. The business had operated under a transitional authorisation in its home jurisdiction and assumed that passporting would apply automatically once MiCA's CASP provisions took full effect. We reviewed the transitional authorisation's scope and identified that it did not, on its terms, extend to custody as a separately enumerated service — only to the exchange activity the firm had licensed originally. A supplementary application to add custody to the authorised perimeter was required before any passporting notification could be filed. The matter was resolved without enforcement exposure, but the timeline to expand into the target markets was extended by a material number of months that the business had not planned for. The lesson is structural: passporting rights follow the scope of the authorisation as granted, not the scope of the business as operated.

Which operator profile should choose Malta for digital-asset custody?

The Malta CASP authorisation suits a distinct set of operator profiles. It is not the right answer for every digital-asset custody business, and approaching it as a default EU entry point without assessing the alternatives produces suboptimal outcomes.

Profile A is the EU-focused institutional custody operator — a firm whose clients are predominantly EU-based institutional counterparts (funds, family offices, exchanges) and for whom EU passporting is the primary commercial driver. For this profile, Malta's MFSA supervision, EU regulatory standing and the passporting regime align well. The application burden is material, but the commercial return justifies it. The indicative path from entity incorporation to authorisation decision, assuming a well-prepared application file, runs to a number of months that should be modelled conservatively in the business plan.

Profile B is the global multi-hub operator — a custody business serving clients in the EU, the UK, the UAE and Asia simultaneously. For this profile, Malta provides the EU layer, but allied counsel in each additional jurisdiction must be engaged to address the FCA requirements, the VARA or ADGM regime in the UAE, and the SFC or MAS requirements in Asia. The Malta entity is one node in a multi-licence structure, not a global umbrella. Treating it as the latter is the most common and costly structural mistake we encounter.

Profile C is the early-stage custody start-up seeking a lighter-touch EU entry. For this profile, the MiCA CASP requirements — capital, governance, AML, local substance — may represent a disproportionate burden at the current stage of the business. A staging strategy, potentially involving initial registration in a jurisdiction with a proportionate regime and a planned upgrade to full CASP authorisation as the business scales, may be more appropriate. The AIFC/AFSA regime in Kazakhstan, the BVI VASP regime, or a Cayman CIMA registration each present different cost-benefit profiles for a custody business that is not yet ready for full EU authorisation.

What are the most common mistakes in Malta custody applications?

Incomplete governance documentation is the leading cause of application delays. Applicants frequently submit a business plan and a draft AML policy without the supporting operational procedures — key-management policies, safeguarding frameworks, incident-response plans — that the MFSA expects to see alongside the high-level documentation. The MFSA is explicit that it assesses substance, and a bare framework document without operational depth does not meet that standard.

A second common mistake is the fitness-and-propriety gap. Controllers and directors who hold or have held positions in multiple jurisdictions must provide personal declarations and supporting checks from each relevant country. Gaps in that chain — typically a jurisdiction where obtaining a clean criminal-record certificate involves procedural complexity — delay the completeness assessment materially. Preparing these documents early, before the application is otherwise ready, is consistently the right call.

A third mistake involves the custody-specific technical documentation. MiCA's requirements for custody CASPs include policies governing key management, the segregation of client assets from firm assets, the procedures for responding to a loss event, and the insurance or alternative financial-resilience arrangements. Applicants that apply the same documentation to custody that they use for an exchange application — treating custody as a minor add-on — consistently encounter substantive requests from the MFSA at the review stage.

A common assumption is that a single offshore registration is sufficient to serve EU clients in custody. It is not. A firm holding client digital assets for EU-based clients from an offshore entity — even one with a recognised VASP registration — is providing a regulated custody service within the EU and may be doing so without authorisation under MiCA. The MFSA and ESMA have both signalled that reverse-solicitation exceptions are narrow and fact-specific. Building a custody business on that basis is a structural risk, not a planning strategy.

When and how should an inbound operator engage counsel for Malta custody authorisation?

Engaging counsel at the entity-incorporation stage, before the application file is assembled, produces materially better outcomes than engaging after a first submission has encountered regulatory questions. The reason is structural: the decisions made about entity form, shareholder structure, director profiles and governance design at incorporation are difficult and expensive to unwind once the MFSA has begun its assessment. Getting those decisions right at the outset is both faster and cheaper than correcting them mid-process.

The scope of counsel engagement for a Malta CASP custody application typically covers the pre-application regulatory assessment, the entity incorporation and governance design, the preparation of the application file (including all required policies and procedures), liaison with the MFSA during the assessment period, and the post-authorisation compliance design (ongoing reporting, supervisory notifications, Travel Rule implementation). For a business entering the EU market for the first time, the cross-border analysis — which of the firm's activities touch which jurisdictions, what those contacts trigger, and how the Malta entity interacts with operating entities elsewhere in the structure — is a necessary part of that scope, not an optional extension.

We regularly advise inbound operators on the full authorisation path, from the first regulatory scoping call through to the receipt of the MFSA decision. Our practice covers the licensing layer, the banking and payment-rails question, and the tax and structuring dimension in parallel — because those three components interact, and addressing them sequentially introduces avoidable delays and structural risk.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timelines vary significantly by jurisdiction and application complexity. Under MiCA, the MFSA's formal assessment period runs from the date an application is deemed complete — not from first submission. In practice, the preparation phase before submission, combined with the MFSA's completeness assessment and formal review, means a well-prepared applicant should plan for a multi-month process. Applicants with gaps in governance documentation or fitness-and-propriety materials consistently experience longer timelines. Realistic planning and early document preparation are the most effective timeline-management tools available.

Which jurisdiction is best for licensing my crypto business?

There is no universal answer. The right jurisdiction depends on where your clients are, which activities you are conducting, the capital and governance resources available to the business, and the banking and tax stack you intend to build around the licence. Malta with EU passporting suits an EU-focused custody or exchange operator; the VARA regime in Dubai suits a business targeting the MENA market with a mainland UAE presence; Singapore's MAS Payment Services Act suits operators serving Asia-Pacific institutional clients. A structured jurisdiction-selection exercise, not a default to the most familiar name, produces better outcomes.

Do I need a separate custody licence?

Under MiCA, custody of crypto assets on behalf of clients is a separately enumerated CASP service. If your business model involves holding or controlling client assets — including controlling private keys — you need your authorisation to cover custody expressly. An exchange licence, an advisory licence or a transfer-and-settlement licence does not cover custody unless custody is specifically included in the authorised perimeter. Operating custody services under an authorisation that does not cover them is a regulatory breach. The answer is almost always: yes, a separate coverage of custody in the authorisation is required.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit — so the structure is right before the regulatory clock starts. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in CASP authorisation strategy and multi-hub licence structuring for digital-asset custody and exchange operators.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours