Vara licence application in Malta: Legal Requirements for Businesses
Operating a digital-asset business in Malta without the right authorisation exposes the company to enforcement action, terminated banking relationships and the loss of access to EU clients overnight. Malta's transition from the Virtual Financial Assets framework to MiCA (Markets in Crypto-Assets Regulation) – supervised by the MFSA (Malta Financial Services Authority) – has reset the compliance baseline. Businesses that structured around the prior VFA regime now face a recalibration, and those entering Malta for the first time must understand that the country now sits squarely inside the EU's CASP authorisation architecture. This page maps the legal requirements, the application process and the cross-border considerations that determine whether a Malta authorisation delivers the outcome a business actually needs.
What is the regulatory basis for crypto licensing in Malta?
Malta's crypto licensing regime is anchored in the MFSA, which acts as the national competent authority under MiCA and previously administered the VFA (Virtual Financial Assets) framework – a Malta-first regulatory architecture that predated the EU-wide regime. Under MiCA, the operative licence is a CASP (Crypto-Asset Service Provider) authorisation, issued by the MFSA and conferring an EU-wide passport. The VFA framework is being phased out as transitional periods expire; businesses that held a VFA licence must migrate to the CASP structure within the timelines prescribed by the applicable MiCA transitional provisions.
The MFSA was among the first EU regulators to develop a bespoke crypto licensing architecture. That history means the authority is operationally experienced in the sector. It also means the MFSA's expectations around substance, governance and AML are well developed and are applied rigorously. A crypto licence Malta application is not a paper exercise.
Three token regimes remain live under MiCA: ART (asset-referenced tokens), EMT (e-money tokens) and other crypto-assets. The authorisation required turns on which regime applies to the assets in scope and which activities the business intends to conduct. CASP authorisation in Malta permits passporting across all EU and EEA member states – a material commercial benefit for operators targeting the European market from a single regulated entity. The MFSA reviews applications against the MiCA requirements, which include governance, capital adequacy, AML/CFT programme quality and operational resilience.
Who needs a VASP registration or CASP authorisation in Malta?
Any business operating within the MiCA perimeter from a Malta-domiciled entity – or actively targeting EU persons from a non-EU entity – must hold a CASP authorisation or equivalent transitional registration. The key question is whether the business performs a regulated crypto-asset service, not whether it calls itself an "exchange" or a "wallet provider." The MFSA applies a substance-over-label analysis.
Regulated services under the applicable MiCA provisions include exchange services (crypto-to-fiat and crypto-to-crypto), custody and administration, the operation of a trading platform, reception and transmission of orders, execution of orders, portfolio management, advice on crypto-assets, transfer services and placing services. A business that performs any one of these from Malta – or directs services at EU-resident clients from elsewhere – is within scope.
Several operator profiles come to us with the same misreading: that a token issued under a "utility" label falls outside the regime. Token classification under MiCA turns on the rights the instrument actually confers, not the marketing term attached to it. An instrument that functions as an ART or an EMT – or that functions as a financial instrument under MiFID II – triggers the relevant authorisation requirement regardless of how the issuer characterises it. In our practice, we see this misclassification risk most acutely in operators migrating from earlier offshore structures.
Businesses that passported services into Malta from another EU jurisdiction before MiCA's application date are not automatically authorised. The passport follows the issuing jurisdiction's CASP status. A Malta-headquartered operation must hold its own Malta authorisation.
How does the MFSA CASP application process work?
The CASP application process in Malta follows a structured pre-submission and formal review sequence administered by the MFSA. Preparation is the determinative phase. Applicants that submit incomplete or internally inconsistent files extend their own timelines significantly.
The process proceeds through the following steps.
Pre-application engagement. The MFSA operates a pre-application phase in which the applicant presents the proposed business model, the services to be licensed and the key personnel. This engagement surfaces classification questions early and allows the regulator to confirm the applicable authorisation category before significant preparation cost is incurred. We regularly use this stage to stress-test the business model against the MFSA's current supervisory expectations.
Programme of Operations and governance documentation. The formal application requires a detailed programme of operations covering the services, the intended markets, the governance structure, the outsourcing arrangements, the IT and security architecture and the AML/CFT programme. The Programme of Operations is the centrepiece of the file. It must demonstrate that the applicant has operational substance in Malta – not a brass-plate holding entity – and that key decision-making genuinely occurs within the jurisdiction.
Fit and proper assessment. Every member of the management body, every qualifying shareholder and every key function holder is subject to a fit and proper review. The MFSA's assessment is thorough. Undisclosed prior regulatory actions or adverse court findings in other jurisdictions are a common reason for extended review periods or refusals. Non-EU shareholders and ultimate beneficial owners require particular attention in the disclosure package.
Capital adequacy and financial resources. The application must demonstrate that the entity meets the minimum own-funds requirement applicable to its CASP category. These figures are prescribed by MiCA and vary by service category; they must be met at authorisation and maintained on a continuous basis post-authorisation. Because the registry marks the specific figures as requiring current verification, we describe the requirement qualitatively: the capital threshold is meaningful, scales with the scope of activities and must be evidenced by audited or certified financial statements.
AML/CFT programme and Travel Rule readiness. Malta applies the Travel Rule (the obligation, drawn from FATF Recommendation 15, to pass originator and beneficiary data with a virtual-asset transfer). The application file must demonstrate a credible, implemented AML/CFT framework. The MFSA will probe the effectiveness of the programme, not merely its existence.
Formal decision period. Following submission of a complete file, the MFSA reviews the application within the timeframe prescribed by the applicable MiCA provisions. The timeline is measured in weeks from completeness, not from initial submission. Regulatory queries interrupt the clock. In our experience, operators that invest adequately in preparation move through this stage materially faster than those that submit prematurely.
A VFA agent is no longer a standalone pathway for new applicants; that concept operated under the prior VFA framework and is being absorbed into the MiCA CASP architecture.
For a scoped assessment of your Malta application readiness and a realistic timeline estimate, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your entity structure, key personnel profiles and the specific services in scope will change the analysis – sometimes materially.
How does a Malta crypto licence interact with other jurisdictions?
A Malta CASP authorisation passports across the EU and EEA, which is its principal commercial attraction. The business can service clients in France, Germany, the Netherlands and other member states from the Malta entity without a second licence in each country – subject to notification obligations under the applicable MiCA passporting provisions. That passport is real and significant, but it is not absolute.
Cross-border complexity arises on three axes that operators routinely underestimate.
UK clients. Post-Brexit, the EU passport does not extend to the United Kingdom. A Malta CASP serving UK-resident clients must comply with the FCA (Financial Conduct Authority) regime – including the cryptoasset financial promotions rules and, depending on activities, registration under the Money Laundering Regulations. The UK is a distinct regulatory perimeter. Operators who assume a Malta licence covers UK business are exposed to FCA enforcement.
US nexus. A Malta entity that accepts US-resident clients triggers federal and state-level obligations under the SEC, CFTC, FinCEN and potentially NYDFS BitLicense requirements. Geographic restrictions in the terms of service are not sufficient mitigation unless they are operationally enforced. In our cross-border practice, we regularly advise Malta-licensed businesses to implement credible geo-blocking and to review their US-nexus exposure before launch.
Banking and payments infrastructure. Holding a CASP authorisation does not guarantee access to euro-denominated banking. EU banks remain selective about digital-asset clients, and the risk-appetite of Maltese-licensed credit institutions varies. The practical path for most operators involves a combination of an EMI (electronic money institution) relationship for payment rails, direct banking for the licensed entity's corporate accounts and, in some cases, a separate EMI (electronic money institution) licence held by a related entity. The interaction between the CASP authorisation and the payment layer is a structural decision that affects the whole operating model. We map the licence, banking and payment stack as a single mandate.
Tax residence and substance. A Malta entity is a Malta tax resident only if management and control is genuinely exercised in Malta. A business that holds a Malta CASP licence but runs its operations from elsewhere faces both a substance challenge at the MFSA level and a tax residence question that can recharacterise the group's profit allocation. Malta's corporate tax regime is attractive – including the refund mechanism for qualifying shareholders – but the benefit accrues only to entities with genuine operational presence.
In a recent cross-border licensing matter, a token-exchange operator sought to use a Malta entity as the EU-facing entity while maintaining its actual operations offshore. We identified that the proposed structure would fail the MFSA's substance test, expose the entity to deemed tax residence challenges in the operational jurisdiction, and leave the UK client base unserviced by a compliant licence. We restructured the group to place substance in Malta, introduced a separate FCA-registered entity for UK business and aligned the banking layer with the operational reality. The authorisation was granted, and the structure has remained compliant through subsequent supervisory reviews.
To map the licence, banking and tax stack for your Malta build, write to info@oboluslaw.com. If a prior application stalled or a bank account was closed, a fresh structural read often surfaces the reason and the route forward.
What are the most common mistakes in Malta CASP applications?
The most preventable cause of MFSA application delays is submitting a file that does not reflect how the business actually operates. Regulators are experienced at identifying the gap between a well-drafted programme of operations and an entity with no operational reality behind it.
Several patterns recur across applications we have reviewed or corrected.
Insufficient substance. The MFSA expects local decision-makers, physical premises and a genuine management presence. An application built around a single non-executive director and a registered-office address will not pass the substance test. Substance is not a checklist item; it is a credibility assessment.
AML programme gaps. A copied-in AML policy from a template provider – or one adapted from a prior VFA-framework file without updating for MiCA's requirements – will draw detailed MFSA queries. The programme must be tailored to the specific products, client types and jurisdictions the business serves. Travel Rule implementation must be live, not prospective.
Fit and proper disclosure shortfalls. Applicants that fail to disclose historical regulatory matters, civil proceedings or prior licence refusals in other jurisdictions create a credibility problem that is very difficult to recover from once the MFSA discovers the omission independently. Full disclosure, with context, is always the better path.
Misunderstanding passporting scope. Operators frequently assume that a Malta authorisation covers activity directed at clients in non-EU jurisdictions. The passport is an EU instrument. Third-country activity must be assessed against each target jurisdiction's own regime.
Deferring the banking conversation. Banking onboarding for a Malta CASP entity can take as long as the regulatory application itself. Starting the banking process after receiving the licence creates an operational gap. The two workstreams should run in parallel from the outset.
Which operator profile should consider Malta for crypto licensing?
Malta is not the right jurisdiction for every digital-asset business. The value proposition is specific, and the decision should be made against a clear profile analysis.
Profile A – EU-focused exchange or custody operator. A business whose primary market is the EU, whose clients are EU-resident and whose operational team can be placed in Malta will generally find the CASP authorisation in Malta competitive. The passport access is immediate across the EU, the MFSA is experienced and the corporate tax environment rewards genuine presence. The key risk is that substance expectations are real and ongoing.
Profile B – Global operator seeking an EU anchor. A business with a global client base and operations across multiple time zones may find that Malta provides the EU-facing licence it needs, while other jurisdictions – the AIFC/AFSA in Kazakhstan, or the VARA framework in Dubai – serve other geographic markets. This multi-licence architecture is viable but requires careful design to avoid regulatory arbitrage claims and to manage the cross-border tax consequences.
Profile C – Token issuer. A business issuing tokens that qualify as ARTs or other crypto-assets under MiCA must issue a whitepaper and, depending on the volume and type of issuance, seek MFSA authorisation as issuer. Malta has experience with this issuer population from the VFA framework period. The MFSA's familiarity with token structures is a practical advantage.
Profile D – Business already licensed elsewhere in the EU. A business with an existing CASP authorisation in another EU member state may explore whether a Malta entity offers any operational or structural advantage. In most cases, a second CASP authorisation in Malta adds cost without adding materially to the passport already held. The decision usually turns on tax and banking considerations rather than regulatory ones.
Is a single offshore licence enough to serve clients globally?
A common assumption among inbound operators is that a single offshore registration – whether in the BVI, the Cayman Islands or a lightly regulated third country – provides a serviceable global licence. It does not. The assumption misunderstands how jurisdiction of service is determined.
Regulatory perimeter analysis starts with where the client is, not where the operator is incorporated. An operator incorporated in a third country but actively marketing to EU-resident clients is within MiCA's scope. An operator serving UK-resident clients through an offshore entity is within the FCA's scope. The relevant test in most major regimes is whether the activity is directed at persons in the jurisdiction – not whether the operator holds a local licence or has a local address.
The practical consequence is that an operator relying on a single offshore licence and serving a geographically diverse client base is, at best, unregulated in every jurisdiction its clients sit in and, at worst, in active breach of multiple licensing regimes simultaneously. Enforcement actions against offshore operators by the FCA, ESMA's national competent authorities and the SEC have consistently demonstrated that regulators pursue cross-border enforcement against businesses that are materially present in their markets without authorisation.
The licence stack – the combination of the entity's domicile licence, any passported EU authorisation, and any additional jurisdiction-specific licences – must be designed to match the business's actual client geography. In our practice, we map the client and revenue geography first, then build the licence stack around it. The Malta CASP authorisation is a strong EU-perimeter solution. It is one component of a wider structure, not a substitute for one.
Related at OBOLUS:
- Licensing & Registration for Digital-Asset Businesses – how we scope and manage licence applications across 70+ jurisdictions
- Economic Substance for Licensed VASPs in Poland – substance requirements in the EU context and what regulators actually inspect
- EMI Onboarding for VASPs in Malta – the banking and payment-rail layer that sits alongside a Malta CASP authorisation
FAQ
How long does a crypto licence take to obtain?
Timelines vary materially by jurisdiction and by the completeness of the application file at submission. Under MiCA, the MFSA reviews a complete CASP application within the timeframe prescribed by the applicable MiCA provisions; regulatory queries pause the clock and are common on first submission. Well-prepared applicants move through the formal review stage in a matter of weeks. Preparation – governance, AML programme, substance documentation – typically takes several months before a credible file is ready.
Which jurisdiction is best for licensing my crypto business?
There is no single answer. The right jurisdiction depends on the client geography, the services offered, the operator's ability to demonstrate substance, the available banking relationships and the group tax structure. Malta is a strong choice for EU-facing businesses that can establish genuine substance. Operators with a global client base often need a multi-licence architecture. OBOLUS maps these variables as a single mandate before any commitment is made to a specific jurisdiction.
Do I need a separate custody licence?
Under MiCA, custody and administration of crypto-assets on behalf of clients is a regulated CASP service. If your business holds client assets in any form, that activity is within the licensed perimeter and must be covered by your CASP authorisation. Whether you need a standalone custody authorisation – or whether custody is covered under a broader CASP authorisation that includes other services – depends on the scope of the specific activities and should be confirmed with the MFSA during the pre-application phase.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams – mapping the licence stack across operating, custody and payment layers before you commit. To discuss your situation, contact info@oboluslaw.com or message us via t.me/oboluslaw.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in EU CASP authorisation, MFSA applications and cross-border licence stack design for digital-asset operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.