Licensing & Registration for Digital-Asset Businesses
Operating a digital-asset business without the correct regulatory authorisation is not a grey-area risk – it is an existential one. Enforcement actions, frozen banking rails, and mandatory wind-downs follow businesses that launch first and licence later. VASP registration and crypto licence applications are now required across virtually every significant financial centre, and the regime map shifts faster than most in-house compliance calendars can track. This page is the hub for OBOLUS's licensing and regulatory authorisation practice: the regulated perimeter, how instruments differ across hubs, the cross-border realities that a single-jurisdiction reading misses, and when a specialist cross-border counsel team changes the outcome.
The licensing requirements that apply to your business depend on what you do, where your entity sits, where your users are, and where your banking clears. No single offshore registration satisfies that four-part question for a business operating across borders.
What Activities Trigger Licensing Requirements for Digital-Asset Businesses?
The regulated perimeter for digital-asset businesses is defined by activity, not by the label a business applies to itself. Across leading regimes – MiCA in the European Union, the VARA regime in Dubai, MAS's Payment Services Act in Singapore, and the SFC's VASP licensing framework in Hong Kong – the trigger is whether a business provides a service to third parties involving virtual assets: exchange, transfer, custody, lending, brokerage, or investment management. Calling the activity a "protocol," a "platform," or a "technology service" does not move it outside the perimeter if the economic substance is a regulated function.
In our practice, the most common blind spot is the custody function. Operators that self-describe as exchanges frequently hold client assets – even temporarily during settlement – in a manner that triggers custody regulation independently of the exchange authorisation. Under MiCA, CASP authorisation (crypto-asset service provider authorisation) covers a defined menu of services, and holding or administering crypto-assets on behalf of clients is a discrete regulated activity within that menu. VARA in Dubai operates on a similarly activity-specific model: its rulebooks address advisory, broker-dealer, custody, exchange, lending, management, and transfer/settlement as separate licence permissions.
The cross-border complication is immediate. An exchange incorporated in a favourable jurisdiction may still trigger the financial-promotion regime of the FCA in the United Kingdom if it markets to UK users, or face MiCA passporting obligations if EU-resident clients use its platform. The entity's home jurisdiction is only one point on the regulatory map.
Token issuers face a distinct sub-question. Whether an issued token is a security token (carrying investment rights that engage securities regulation), an asset-referenced token or e-money token under MiCA, or a utility token with no financial rights is a substance-over-label analysis. The classification determines not just the regulator but the disclosure obligations, the reserve requirements, and the authorisation category. Regulators across the leading hubs increasingly resist the utility-token characterisation where the token carries an expectation of profit derived from the efforts of others.
The Cross-Border Reality: Why One Registration Is Never Enough
A common assumption in the market is that a single offshore registration – a BVI VASP Act registration, a Cayman CIMA licence, or an early EU VASP registration obtained before MiCA – is sufficient to serve a global client base. It is not, and acting on that assumption is one of the most frequent causes of regulatory enforcement we observe in cross-border digital-asset businesses.
The structure that actually works requires disaggregating the business by function. The trading or exchange layer, the custody layer, the payment or transfer layer, and the token-issuance layer may each require separate authorisations – potentially in separate jurisdictions. A business that passports a MiCA CASP authorisation across the EU still needs to address its banking relationships (which often sit in jurisdictions with their own VASP supervision expectations), its custody sub-custodians (who may be in Singapore under the MAS Payment Services Act), and its marketing into the UK (which engages the FCA's financial-promotion rules independently).
We regularly advise businesses that have cleared EU authorisation under MiCA only to discover that their institutional counterparties in Switzerland require FINMA comfort, and that their banking partner's compliance team will not proceed without a clear home-jurisdiction regulatory status. These are not corner cases. They are the normal condition of a business with an international user base and a multi-jurisdictional banking stack.
The AIFC and AFSA in Kazakhstan represent an example of the emerging-hub dynamic. Businesses seeking to serve clients in Central Asia and the CIS corridor find that AFSA authorisation within the AIFC – a common-law jurisdiction sitting within Kazakhstan – provides a credible regulatory anchor that their banking partners recognise. But it does not substitute for authorisation in the hubs where the end-users sit. The layering logic applies at every scale.
For a scoped assessment of your cross-border licence requirements, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options
How Do the Major Licensing Instruments Differ Across Jurisdictions?
The major licensing instruments for digital-asset businesses differ significantly in scope, process weight, and operational permission, and the right choice for a business depends on its user base, revenue model, and growth trajectory – not on which jurisdiction is currently perceived as the fastest or most permissive.
Under MiCA and the ESMA supervisory architecture, CASP authorisation in a single EU member state carries a passport across the EU and EEA. This is structurally valuable for any business with a pan-European user base. Lithuania has historically attracted applications as a gateway market with a responsive national competent authority and a well-developed fintech infrastructure. Malta's MFSA supervises a transition from the prior VFA framework to the MiCA CASP regime. The authorisation process is substantive: business plan review, fitness and propriety assessment of management, own-funds requirements that vary by service category, and ongoing supervisory reporting. Timeline varies by the completeness of the application and the NCA's queue, but operators should plan for a process measured in months, not weeks, in most EU member states.
In Dubai, VARA's activity-based model means that a business providing exchange and custody services acquires separate permissions for each. VARA's rulebook structure is detailed and operationally demanding: marketing, technology governance, and prudential requirements all sit within the applicable rules. The DIFC financial free zone operates its own regulatory perimeter under the DFSA, distinct from mainland VARA. Businesses must determine which jurisdiction within Dubai is appropriate for their structure before they begin an application.
Singapore's MAS Payment Services Act establishes three licence tiers – money-changing, standard payment institution, and major payment institution – each with different transaction volume thresholds and capital expectations. The Digital Payment Token service is the relevant regulated activity for most crypto-asset businesses. MAS has a reputation for thorough vetting; timeline expectations should be set accordingly. ADGM and the FSRA in Abu Dhabi operate a parallel framework for virtual assets, with a recognised virtual assets concept that determines what may be traded or custodied under a given permission.
The BVI FSC operates VASP registration under the VASP Act 2022 as a lighter-touch regime suited to fund structures and holding vehicles rather than retail-facing exchanges. Similarly, CIMA in the Cayman Islands offers both registration and licensing tracks under the applicable VASP Act provisions. Both are frequently used as components of a wider structure rather than as standalone regulatory anchors for operational businesses.
In Japan, the FSA and the JVCEA self-regulatory body jointly supervise crypto-asset exchange services under a well-developed and demanding regime. For businesses with a Japanese user base, local authorisation is non-negotiable; the FSA's requirements around system resilience, custody segregation, and cold-wallet ratios are among the most prescriptive in any major jurisdiction.
AML Compliance and the Travel Rule: the Licence Is Not the Finish Line
Obtaining a crypto licence is necessary but not sufficient; the Travel Rule (the obligation under FATF Recommendation 15 to pass originator and beneficiary data with a virtual-asset transfer) and full AML/CFT programme implementation must be operational before – not after – the business goes live. Regulators across the leading hubs increasingly treat Travel Rule compliance as a condition of authorisation maintenance, not a post-launch obligation. A business that holds a CASP authorisation under MiCA but has not built out its Travel Rule messaging infrastructure is in technical breach and exposed to supervisory action.
In our cross-border practice, we see the Travel Rule create friction at the banking layer most acutely. Banking partners conduct their own assessments of a VASP client's Travel Rule posture, and a well-documented AML programme with clear Travel Rule protocols substantially reduces the time to a live banking relationship. Conversely, businesses that arrive at a bank with a licence but without a Travel Rule solution find that the compliance conversation restarts from the beginning.
The worldwide freezing order risk is also relevant here. A business that operates without proper AML controls – even if it holds a registration – may find its accounts frozen by a court or regulator in a jurisdiction it did not think was relevant. England & Wales courts, the DIFC Courts, and Singapore courts have all demonstrated willingness to grant freezing orders that reach assets and accounts held outside their primary jurisdiction where the legal nexus is established.
What Does the Licence Application Process Actually Involve?
A well-run licence application is a structured project with defined workstreams, not a form-filling exercise. The process for a substantive CASP authorisation under MiCA or a VARA licence in Dubai involves, at minimum: entity structuring and corporate governance documentation; a detailed business plan addressing the regulated activities, technology architecture, and risk management; fit and proper assessments for management and beneficial owners; an AML/CFT programme with policies, controls, and a designated compliance officer; a technology governance framework; and own-funds or capital documentation. For issuers of asset-referenced or e-money tokens under MiCA, a whitepaper must be prepared, notified, and in certain cases approved before publication.
The application is not a one-way submission. Regulators ask questions, request supplementary documents, and expect responsive engagement from a team that understands the substance. Applications that stall typically stall because the applicant cannot answer a follow-up question about their custody model, their liquidity risk management, or their outsourcing arrangements. Preparing for likely regulatory questions is as important as the initial submission.
In a recent matter, a payments company seeking MiCA CASP authorisation in an EU member state had its application suspended after the NCA raised questions about the governance of its technology outsourcing arrangements. We were engaged after the suspension and worked with the company to restructure its outsourcing documentation and governance framework; the application was resubmitted and progressed to authorisation within a defined timetable. This is not an unusual pattern – late-stage structural issues are common, and early engagement of experienced licensing counsel avoids them.
For businesses applying to VARA in Dubai, the rulebook review process is distinct: VARA publishes detailed activity-based rulebooks, and an application must demonstrate compliance with the applicable rulebook for each requested permission. The technology governance requirements under VARA are among the most operationally detailed in any active licensing regime, and a business that has not mapped its technology stack against those requirements before filing will face a prolonged dialogue post-submission.
Which Licence Structure Should Your Business Choose?
The right licensing structure depends on four variables: what the business does, who its users are, where it banks, and what its growth path looks like. No single answer applies across operator profiles, and any adviser who recommends a jurisdiction without asking those questions first is working from insufficient information.
Profile A – EU-focused retail exchange with a European user base and European banking. The priority instrument is MiCA CASP authorisation in a member state with a responsive NCA and an established fintech supervisory infrastructure. Passporting across the EEA eliminates the need for separate national registrations. The timeline should be planned over a realistic multi-month horizon. The key risk is underestimating the own-funds and governance requirements for a full exchange permission.
Profile B – Regional hub operator in the Gulf seeking institutional and retail business. VARA authorisation for the specific activities the business conducts in Dubai (mainland) is the primary instrument, with ADGM/FSRA as the alternative or parallel hub for Abu Dhabi-focused activity. The key risk is the breadth of VARA's rulebook obligations, particularly around marketing and technology governance. Banking should be scoped before application, not after.
Profile C – Asia-Pacific exchange targeting Singapore, Hong Kong, and regional markets. MAS Payment Services Act licensing at the appropriate tier is the Singapore anchor. SFC VATP licensing is required for any business offering crypto trading to Hong Kong retail investors. The key risk is the sequential timing: both processes are substantial, and running them in parallel requires dedicated project resourcing.
Profile D – Fund or investment vehicle with no retail-facing activity, seeking a clean offshore registration for institutional counterparty comfort. BVI VASP Act registration or Cayman CIMA registration under the applicable VASP Act provisions provides the structural anchor. These are lighter-touch regimes appropriate to the function. The key risk is assuming the registration covers downstream operational activities it was not designed to address.
Profile E – Token issuer targeting a global audience with a mixed token structure. This profile requires the most complex legal analysis. MiCA whitepaper obligations apply to tokens offered to EU users regardless of issuer jurisdiction. The classification of the token – ART, EMT, other crypto-asset, or security token – determines the regime. A pre-issuance legal opinion on token classification is not optional for a serious launch.
If a prior application stalled or a banking relationship was closed, a fresh structural review can surface the underlying reason and the route forward. Write to info@oboluslaw.com. Map your options
What Are the Most Common Licensing Mistakes Digital-Asset Businesses Make?
The most consequential licensing mistakes are structural, not administrative – and they are made before a single document is filed. In our practice, we encounter the same failure patterns repeatedly across different hubs and business models.
The first is treating the licence as separable from the banking question. A business that secures a CASP authorisation under MiCA, a VARA licence, or an MAS digital payment token licence has cleared the regulatory hurdle but has not solved the banking problem. Banking partners conduct independent compliance assessments of VASP clients, and the regulatory authorisation is a necessary but not sufficient condition for a live banking relationship. Businesses that defer the banking conversation until after authorisation frequently find themselves with a licence and no operational account.
The second is building the corporate structure around the licence application rather than around the business's operational and tax needs. A holding structure that minimises the ownership disclosure required for a particular jurisdiction's fit-and-proper assessment may create tax inefficiencies, banking friction, or conflicts with substance requirements in the entity's tax residence jurisdiction. The licence, the banking, and the tax optimisation must be designed as an integrated structure.
The third is underestimating the ongoing compliance obligations. A licence is not a one-time cost; it is a recurring operational obligation. Supervisory reporting, AML programme reviews, Travel Rule compliance, and technology governance obligations continue throughout the life of the authorisation. Businesses that staff the compliance function at launch-level and do not scale it with the business accumulate regulatory risk that eventually surfaces in an examination or an enforcement action.
The fourth – and most expensive – is operating in a jurisdiction without authorisation while relying on the logic that the regulator has not yet acted. Regulators in the leading hubs now have dedicated digital-asset supervision teams, blockchain analytics partnerships, and inter-agency information-sharing arrangements. The enforcement gap that existed in the early years of the industry has materially narrowed.
A Common Assumption: "We Don't Need a Licence Because We're Decentralised"
A common assumption among DeFi operators and protocol developers is that decentralisation removes the business from the regulated perimeter. Regulators in the leading hubs are actively contesting this position. The relevant test – under MiCA, under VARA, and increasingly under MAS – is not whether the protocol is decentralised but whether identifiable persons or entities control, profit from, or facilitate the regulated activity on behalf of users. A front-end operator, a governance token holder with material control, or a development company that deploys and maintains a protocol that functions as an exchange or lending facility may be within the regulated perimeter regardless of the on-chain architecture.
The FCA in the United Kingdom has taken the clearest public position: entities that have a UK user base and provide a service that falls within the financial-promotion perimeter must comply with the financial-promotion rules, irrespective of where the entity is incorporated or whether its technology is described as decentralised. ESMA has published guidance under MiCA that applies a functional test to DeFi protocols with identifiable controlling parties.
This does not mean every DeFi project requires a CASP authorisation. Genuinely decentralised protocols with no identifiable governing entity may fall outside the current perimeter in several jurisdictions. But that conclusion requires a legal analysis of the specific governance structure, not a general assumption about the technology model. We advise protocol operators to document the governance and control analysis before launch, not after a regulator inquires.
When Should a Digital-Asset Business Engage Licensing Counsel?
The answer is consistently earlier than most businesses do. The structural decisions that determine licensing cost, timeline, and operational flexibility – entity jurisdiction, governance design, token classification, custody model – are made in the first weeks of building a business. They are very difficult and expensive to reverse once the business has users, banking, and counterparty relationships built on a particular structure.
Licensing counsel should be engaged at the point where the business model is defined and the target user base is identified – before entity formation, before banking discussions, and before any token design is finalised. At that stage, counsel can map the licence, banking, and tax stack as an integrated question, identify the jurisdictions that require authorisation given the target market, and design a corporate structure that supports both compliance and operational efficiency.
The second engagement trigger is a change in the business: a new product line (launching custody when previously only offering exchange), a new geography (onboarding users in a jurisdiction that triggers a new authorisation requirement), or a new counterparty relationship (an institutional partner whose compliance team requires a specific regulatory status). Each of these is a trigger for a fresh licensing analysis, not an assumption that the existing authorisation covers the new activity.
In a recent mandate, an exchange holding an existing VASP registration in a common-law offshore hub sought to expand its product offering to include staking services and a lending product. We advised that the staking and lending functions engaged distinct regulatory categories under the applicable regime and in the EU under MiCA – and that the expansion required both an application to vary the existing authorisation and a MiCA CASP authorisation in an EU member state before the product could be marketed to EU users. The business adjusted its product launch sequencing accordingly. Early engagement avoided a post-launch regulatory conversation.
Self-Assessment: Is Your Licence Stack Complete?
Before engaging counsel or filing an application, a digital-asset business should be able to answer the following questions clearly. If any answer is uncertain, it signals a gap in the current regulatory analysis.
- Have you identified every jurisdiction in which your business has users, banking, or operational substance – not just the jurisdiction of incorporation?
- Have you mapped the specific regulated activities your business conducts in each of those jurisdictions – exchange, custody, lending, transfer, advisory, management – and identified the authorisation required for each?
- Has your token been subject to a formal legal classification analysis that addresses MiCA (if EU users are involved), the applicable securities law in your primary operating jurisdictions, and the tax treatment?
- Is your AML/CFT programme operational, documented, and tested – including a Travel Rule solution for virtual-asset transfers?
- Have you confirmed that your banking partner's compliance team has reviewed and approved your VASP status, your AML programme, and your Travel Rule posture – and that the account will remain open at scale?
- Do you have a compliance calendar that captures the ongoing supervisory reporting, AML programme review, and licence renewal obligations for every authorisation you hold?
A business that can answer each of these questions affirmatively, with supporting documentation, is in a materially stronger position than one that cannot – both with regulators and with institutional counterparties.
Related Practices at OBOLUS
Related at OBOLUS
- VASP Licensing in the Cayman Islands – licensing requirements, process and structure for Cayman Islands VASP registration under CIMA supervision.
- Staking Service Legal Framework in Hong Kong – how the SFC's licensing regime applies to staking services offered to Hong Kong users and institutions.
- Exchange Disclosure Orders in the EU under MiCA – the intersection of MiCA's supervisory obligations and court-directed disclosure orders targeting exchange operators.
FAQ
How long does a crypto licence take to obtain?
Timeline varies significantly by jurisdiction, licence category, and application quality. A well-prepared MiCA CASP application in a responsive EU member state is typically measured in months; VARA applications in Dubai and MAS Payment Services Act applications in Singapore are similarly substantive processes. Lighter-touch registrations – BVI VASP Act, Cayman CIMA registration – may proceed more quickly but cover a narrower scope of activity. The single most reliable accelerator is a complete, internally consistent application with no gaps that require regulatory follow-up.
Which jurisdiction is best for licensing my crypto business?
There is no universally correct answer. The right jurisdiction depends on where your users sit, what your business does, where your banking clears, and your growth trajectory. A business targeting EU retail users needs MiCA CASP authorisation regardless of where it is incorporated. A Gulf-focused exchange evaluates VARA and ADGM/FSRA on their operational merits. We map the licence, banking, and tax stack as an integrated analysis before recommending a primary hub, because the authorisation and the operating environment must work together.
Do I need a separate custody licence?
In most leading regimes, yes. Holding or administering virtual assets on behalf of clients is a regulated activity distinct from exchange or transfer services. Under MiCA, custody is a separate CASP service category. VARA treats custody as a discrete licence permission. MAS addresses custody of digital payment tokens within its Payment Services Act framework. Even businesses that consider custody incidental to their primary activity – briefly holding assets during settlement, for example – should analyse whether that function crosses the regulatory threshold in their authorised jurisdictions.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance structures that sit around them. We map the licence stack across operating, custody and payment layers before our clients commit to a structure – because the authorisation, the banking, and the tax question are one question, not three. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Marisa Holt, Partner – Licensing & Regulatory – cross-border digital-asset authorisation, CASP structuring, and VASP registration across the EU, Gulf, and Asia-Pacific hubs.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.