Operating a digital-asset business without the correct authorisation in Malta is not a technical oversight — it is an enforcement event waiting to happen. The Malta Financial Services Authority (MFSA) has made clear that conducting virtual financial asset activities without a licence, or without completing the transition from the prior VFA framework to MiCA-compliant status, will attract supervisory intervention. Frozen payment rails and terminated banking relationships follow quickly. This page maps the legal requirements for VASP licensing in Malta, the regulated basis under the MFSA, the practical process for an inbound business, and the cross-border considerations that change the analysis for operators serving users across multiple jurisdictions.
What Is the Regulated Basis for Crypto Licensing in Malta?
Malta regulates virtual financial asset activities through the MFSA under two overlapping regimes: the prior Virtual Financial Assets (VFA) framework and the converging obligations of MiCA (the EU Markets in Crypto-Assets Regulation). Any business offering exchange services, custody, portfolio management, transfer services or related activities to clients in Malta — or using Malta as an EU base — is caught by the applicable regime. The substance of what you do drives classification, not the label on your marketing deck.
Under the VFA framework, the MFSA introduced a four-tier financial instrument test. A crypto-asset that qualifies as a financial instrument falls under existing MiFID-derived rules. An asset that qualifies as electronic money falls under e-money legislation. An asset that qualifies as a virtual financial asset is subject to VFA-specific authorisation. The fourth category — utility tokens used solely within a defined network — may fall outside financial regulation entirely, but that exclusion is narrow and fact-specific. Operators who assume their token is a utility token without formal legal analysis take a significant risk.
With MiCA now in effect across the EU, Malta is transitioning VFA-authorised entities toward CASP authorisation (Crypto-Asset Service Provider authorisation) as the primary EU-wide licence. The MFSA is the national competent authority under MiCA for Malta. A CASP authorisation granted by the MFSA carries full EU passporting rights, meaning the holder may offer services across all EU and EEA member states without seeking separate authorisation in each. That passporting benefit is the central commercial rationale for a Malta base.
In our licensing practice, we regularly advise operators who have read the VFA framework in isolation and missed the MiCA transition obligations. The legal position is dynamic. Any business that received VFA authorisation before MiCA's full application date must assess its transition timeline with the MFSA — the window to regularise is not indefinite.
Contact OBOLUS for a scoped assessment of your licensing position under the current MFSA regime. The analysis differs depending on whether you hold legacy VFA status, are applying fresh under MiCA, or are structuring a group across Malta and a non-EU hub. Write to us at Map your options or at info@oboluslaw.com.
Who Needs a VASP Licence in Malta?
Any person or entity carrying on a VFA service in or from Malta — or targeting Maltese or EU clients through a Maltese entity — requires MFSA authorisation under the applicable regime. The categories of regulated VFA service are broadly defined and include exchange services between virtual financial assets and fiat currency, exchange services between virtual financial assets, the operation of a trading platform, portfolio management, transfer services, the underwriting or placing of virtual financial assets, and the provision of advice on virtual financial assets.
Custody is separately regulated. Holding or safeguarding virtual financial assets on behalf of clients is a regulated activity. An exchange that also provides wallet custody cannot rely on a single service category; it must ensure its authorisation covers every activity it conducts. The MFSA has consistently taken the view that operating outside the scope of an existing authorisation is equivalent to operating without one.
The jurisdictional perimeter matters for inbound operators. A business incorporated outside Malta that solicits Maltese residents, or that deploys a Maltese group entity to passport into the EU, is within MFSA jurisdiction for those activities. The regulatory reach is determined by the substance of where services are marketed and delivered, not solely by where the entity is registered.
Token issuers offering virtual financial assets to the public in Malta, or seeking admission to a VFA exchange, must comply with a separate but related obligation: the publication of a MFSA-approved whitepaper (or, under MiCA, a crypto-asset whitepaper meeting the applicable MiCA requirements). These offering-side obligations sit alongside the service-provider authorisation regime. An issuer using a Maltese vehicle for an EU-wide token offering must map both sets of obligations before any marketing commences.
How Does the Malta VASP Licence Application Process Work?
The MFSA operates a structured authorisation process for CASP applicants, which is the primary route under MiCA for new entrants from outside the EU and for existing VFA-authorised entities transitioning their status. The process involves a pre-application engagement, a formal application submission, a due diligence and review phase, and a decision. Timelines vary by applicant complexity; the MFSA is a thorough supervisor and the review period for complex applications can extend meaningfully beyond initial estimates.
The pre-application phase is not optional for serious applicants. The MFSA expects applicants to engage early, to have their governance documents, AML/CFT programme, business plan and technology architecture in a reviewable state before submission, and to demonstrate that key personnel meet fitness and propriety standards. In our practice, we have seen applications stall at the review stage because the AML programme was drafted to a generic template rather than tailored to the specific services and client base of the applicant.
Key documentation requirements include: a detailed business plan covering services, target markets and revenue model; governance documents establishing the legal structure, board composition and management functions; an AML/CFT policy and procedures manual that reflects the Travel Rule (the obligation to pass originator and beneficiary data with a virtual asset transfer), transaction monitoring, and sanctions screening; a technology and security report covering custody architecture and cyber-risk controls; and capital adequacy evidence demonstrating compliance with own-funds requirements for the applicable service category.
The VFA framework introduced the concept of a VFA agent — a professional intermediary, approved by the MFSA, who assists the applicant in the submission process and certifies the completeness of the application. Under MiCA, the VFA agent role is restructured but the expectation of well-prepared, professionally supported submissions remains. Applicants who submit without experienced support consistently experience longer review cycles and higher rates of material queries.
Capital requirements under MiCA vary by the category of CASP service authorised. The MFSA sets own-funds thresholds by reference to the MiCA capital provisions. Because the specific figures are subject to the applicable MiCA provisions and MFSA guidance in effect at the time of application, operators should confirm current requirements directly with the regulator or through counsel — we do not state figures that are subject to regulatory revision without confirming them against current MFSA publications.
What Does MiCA Mean for Existing Malta-Licensed Entities?
MiCA's full application marks a structural shift for every Malta-registered crypto business. Entities that hold VFA authorisation under the prior MFSA framework do not automatically hold a MiCA CASP authorisation. The transition requires a separate regulatory step, and the MFSA has set out transitional provisions that govern the window within which existing VFA-authorised entities must apply for CASP status or cease the relevant activities.
The MiCA regime introduces three distinct token-level frameworks alongside the CASP service framework. Asset-referenced tokens (ARTs) — tokens referencing a basket of currencies, commodities or other assets — require MFSA authorisation as the issuer. E-money tokens (EMTs) — tokens referencing a single fiat currency — require either MFSA authorisation as an ART-equivalent issuer or an e-money institution licence. All other crypto-assets (the residual category) are subject to the whitepaper and offering rules under MiCA but do not require issuer authorisation as such. The distinction between categories is technical and consequential: misclassification at the token level exposes both the issuer and the platform listing the token.
For operators already in Malta, the practical question is sequencing. A business should audit its current authorisation scope against the MiCA service categories, identify gaps, submit a transition application within the MFSA's specified window, and update its AML/CFT and governance documentation to meet MiCA's enhanced standards. Doing this in parallel with live operations requires careful project management. We have advised on this sequencing and the common mistake is treating the transition as a paperwork exercise rather than a substantive re-authorisation.
How Do Banking and Tax Interact With a Malta VASP Licence?
A Malta CASP authorisation gives you regulatory permission to operate; it does not, by itself, give you a bank account. This is one of the most consequential practical realities for operators in the EU crypto sector, and Malta is not an exception. Banks conducting their own due diligence on crypto clients apply internal risk frameworks that are separate from, and sometimes stricter than, the MFSA's regulatory criteria.
In our cross-border practice, we regularly advise newly authorised entities that their banking strategy must be built in parallel with, not after, the licence application. The structure of the corporate group, the nature of the crypto activities, the geographic spread of the client base, and the AML controls in place all affect bankability. An operator whose user base includes high-risk jurisdictions, or whose transaction volumes are dominated by large anonymous flows, will face banking challenges that a licence alone does not resolve.
For EU-passporting purposes, the cross-border dimension becomes more complex. A Malta-authorised CASP passporting into Germany, France or the Netherlands must notify the MFSA, which notifies the relevant national competent authority. That notification is procedurally straightforward. But banking in the host jurisdiction — particularly for local fiat settlement — involves separate banking relationships in those markets, each with their own onboarding criteria. The licence is EU-wide; the banking is not.
On tax, Malta offers a corporate tax environment that has historically attracted holding and operating structures for digital-asset businesses. The effective tax rate available through the Maltese refund mechanism on distributed profits has been a consideration for operators structuring their EU presence. However, the relevant OECD Pillar Two global minimum tax rules are now being transposed into EU law, and their effect on smaller entities in Malta should be assessed before structure decisions are made. We work with allied counsel in the relevant jurisdiction on cross-border tax structuring; the specific effective rate is a fact that must be verified against current Maltese legislation and OECD implementation status before any reliance.
Stablecoin issuers using a Malta ART or EMT authorisation face an additional banking dimension: the MiCA reserve requirements mandate that reserve assets be held in segregated form, typically with credit institutions. Sourcing compliant reserve custody banking for an ART or EMT issuer is a live operational challenge, not a theoretical one. We have mapped this challenge for issuers in the planning stage and the advice is consistent — engage banks on reserve custody terms before you finalise the issuance structure.
If your licensing plan has stalled on banking or structure, a second review can identify the cause and the route forward. Contact OBOLUS at Map your options or write to info@oboluslaw.com.
What Are the AML and Travel Rule Obligations for Malta CASPs?
Malta-licensed CASPs are subject to the full AML/CFT obligations applicable to regulated financial services, applied with particular intensity to virtual asset activities. The MFSA has aligned its AML supervisory expectations with the FATF Recommendations — including FATF Recommendation 15, which applies the Travel Rule to virtual asset transfers — and with EU AML directives as implemented in Maltese law.
The Travel Rule requires a CASP to obtain, hold and transmit originator and beneficiary information alongside any virtual asset transfer above the applicable threshold. The specific data-transfer threshold under Malta's implementing rules should be confirmed against current MFSA guidance, as the precise figure has been subject to revision in line with EU implementation. What is not subject to revision is the underlying obligation: failing to implement a functional Travel Rule compliance programme is, in the MFSA's supervisory practice, a ground for licence suspension or revocation.
In practice, Travel Rule compliance requires a technology solution — a VASP-to-VASP messaging protocol — that integrates with the CASP's transaction processing systems. Operators who have not yet selected and integrated a Travel Rule solution before applying for MFSA authorisation will face questions at the application stage. The MFSA expects the programme to be operational, not merely planned.
Sanctions screening obligations run alongside Travel Rule compliance. A Malta CASP must screen customers, counterparties and transaction addresses against EU sanctions lists and relevant OFAC designations. Given that stablecoins such as USDT and USDC carry issuer-level freeze authority that can be exercised on an OFAC-designated address, the practical consequence of a sanctions control failure can be irreversible loss of asset access for the affected client — and a supervisory event for the CASP.
Practical Illustration: Inbound Operator Structuring a Malta CASP
In a recent licensing matter, a crypto exchange incorporated outside the EU sought to establish an EU operational base with full passporting rights. The operator had been working from an existing offshore registration that did not confer EU market access. After an initial structure review, we identified Malta as the appropriate jurisdiction given the operator's intended service scope — exchange, custody and portfolio management — and the need for a single authorisation covering all three. We advised on the corporate reorganisation needed to establish a qualifying Malta entity, the fitness and propriety profile required for the board and management, and the AML programme gaps that would have drawn regulatory queries on submission. The application was submitted to the MFSA with the full documentation package and a pre-submission engagement record. The entity received MFSA authorisation and subsequently notified its passport into three additional EU member states. Banking was secured through relationships built during the authorisation process, not after it.
Which Operator Profiles Should Consider Malta?
Malta is not the right answer for every digital-asset business, but it is a strong answer for a defined set of operator profiles. Understanding where Malta fits — and where it does not — is the starting point for a defensible structure decision.
Profile A — EU-facing exchange or custodian: An operator whose primary user base is in the EU, who needs a regulated EU presence, and who wants a single authorisation with passporting rights across the bloc is the paradigm Malta client. The MFSA's established track record in virtual asset supervision, the VFA-to-MiCA transition framework, and the jurisdictional access MiCA authorisation confers make Malta a logical primary hub. The key risk is application timeline: operators who need to be live in market quickly should plan the MFSA process carefully, as it is substantive.
Profile B — Token issuer seeking an EU public offering base: An issuer of an ART or EMT that needs MiCA-compliant authorisation for an EU-wide distribution will need a national competent authority to authorise the issuance. Malta, as an established MiCA NCA with experience in the VFA/token-offering space, is a credible choice. The issuer must meet MiCA's reserve, disclosure and governance requirements. The interaction with banking for reserve custody is the most operationally demanding element.
Profile C — Non-EU operator seeking a single EU touchpoint: A business headquartered outside the EU that wants to serve EU clients through a regulated subsidiary, rather than applying for authorisation in each member state, can use a Malta CASP as the EU gateway. The entity must be genuinely operational — the MFSA does not authorise shell vehicles — but the scope of operations required to maintain authorisation is workable for a well-resourced operator.
Profile D — Operator primarily targeting non-EU markets: If the operator's clients are predominantly in Asia, the Gulf or North America, a Malta CASP adds regulatory overhead without commensurate commercial benefit. In that profile, other hub options — Singapore under the MAS Payment Services Act, Dubai under the VARA regime, or the ADGM/FSRA framework in Abu Dhabi — deserve equal or prior consideration. We regularly advise on jurisdiction selection across these hubs and the analysis is always fact-specific.
A common assumption among operators new to EU licensing is that a single offshore registration — a BVI or Cayman vehicle, for example — is sufficient to serve global clients, including EU clients. It is not. The EU's MiCA regime requires authorisation in an EU member state for any person providing CASP services to EU clients above defined thresholds. The BVI FSC VASP registration and the Cayman CIMA registration are credible instruments for non-EU markets; neither substitutes for MiCA CASP authorisation in relation to EU client-facing activity.
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – how OBOLUS maps the full licence stack across operating, custody and payment layers
- VARA Licence Application for Early-Stage Founders – the Dubai VARA process for operators considering a Gulf hub alongside or instead of Malta
- Stablecoin Freeze Requests in Liechtenstein – the cross-border recovery dimension when stablecoin flows touch EEA jurisdictions
FAQ
How long does a crypto licence take to obtain?
Timelines vary significantly by jurisdiction, application complexity and the completeness of the submission. In Malta, the MFSA review process for a CASP authorisation is substantive and multi-stage; well-prepared applications with experienced support complete the process faster than those that generate material queries. Operators should plan for a process measured in months, not weeks, and build that timeline into their market-entry schedule. Pre-application engagement with the MFSA shortens the formal review phase.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. Malta is strong for EU-facing operators who need a single MiCA-compliant authorisation with passporting rights. Dubai under VARA, Singapore under the MAS Payment Services Act, and Abu Dhabi under the ADGM/FSRA framework suit different client profiles and geographic strategies. The right jurisdiction turns on your user base, your service scope, your banking needs, and your tax position. We advise on jurisdiction selection as a standalone engagement before any application is filed.
Do I need a separate custody licence?
In Malta, custody of virtual financial assets on behalf of clients is a regulated activity under both the VFA framework and MiCA. An operator that provides custody alongside exchange or other services must ensure its authorisation covers custody specifically. The MFSA does not permit an exchange to provide custody to clients on the basis of its exchange authorisation alone. Operators running a combined exchange-and-custody model should map their full activity scope against their authorisation before going live.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit — not after the first enforcement notice. We advise crypto exchanges, custodians, token issuers and funds across more than seventy licensing jurisdictions. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Aisha Tan, Licensing and Jurisdictions Analyst — specialising in EU and cross-border VASP authorisation, MiCA CASP applications and multi-hub licence structuring.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.