What digital-asset custody licensing actually requires
Digital-asset custody licensing – the regulated authorisation to hold, safeguard and administer virtual assets on behalf of clients – is now a formal requirement in every major financial hub, and early-stage founders who treat it as an afterthought face enforcement exposure before their first paying user arrives. The regulated perimeter has expanded rapidly: under MiCA (the EU's Markets in Crypto-Assets Regulation), holding crypto-assets on behalf of third parties is a named CASP (crypto-asset service provider) activity requiring prior authorisation from the relevant national competent authority. VARA in Dubai, the FSRA in Abu Dhabi's ADGM, MAS in Singapore, the SFC in Hong Kong – each treats custody as a distinct regulated activity, not an incidental operational function. A founder who builds a custody product and then seeks a licence is, in regulatory terms, already operating unlicensed. The licensing process described below is the path to correcting that exposure or, better, avoiding it entirely.
Who needs a custody licence – and when the obligation arises
The custody obligation arises the moment a business holds private keys – or controls access to a wallet – on behalf of another person or entity. The label on the product does not change that analysis. A wallet infrastructure provider that exercises discretionary control over a client's assets is a custodian. So is a yield platform that pools user funds in a smart contract the operator alone can drain, a payments business that holds settlement balances in stablecoins, and a fund administrator that maintains digital assets pending redemption. The regulatory analysis follows the substance of the arrangement, not the marketing copy.
The trigger is control, not custody in the narrow custodial-bank sense. Operators we advise routinely discover mid-build that a feature they designed for operational efficiency – a master key for emergency recovery, a fee-sweep wallet – satisfies the control test in every jurisdiction they intend to operate. Identifying that trigger early shapes both the product architecture and the licensing timeline.
The cross-border dimension is immediate. A founder incorporated in the BVI, operating servers in Frankfurt, holding client assets on behalf of users in Singapore and the EU faces, simultaneously, the MiCA CASP regime, the MAS Payment Services Act framework and the BVI VASP Act 2022. Each applies its own authorisation test. None defers to the others. The correct question is not "where is the entity?" but "where does the controlled activity occur?"
How the regulated perimeter is drawn across the leading hubs
Custody is regulated as a standalone activity – not bundled into a general VASP registration – in every hub that OBOLUS monitors for early-stage clients. The distinctions matter because an exchange licence does not automatically authorise custody services, and vice versa.
Under MiCA, custody and administration of crypto-assets on behalf of clients is one of several CASP services listed in the regulation; a firm that provides only custody must still seek full CASP authorisation from the NCA in its chosen member state, satisfy the own-funds requirement for that service class and comply with the client-asset segregation obligations. The EU passporting mechanism means that authorisation in a single member state can support operations across the EEA – a significant structural advantage for a custody-first business designing for European distribution.
In Dubai, VARA's activity-based licensing model requires a separate custody licence for any entity holding virtual assets on behalf of clients. VARA's rulebooks impose detailed obligations on key management, cold/hot storage ratios, incident reporting and client disclosure. The DIFC financial free zone operates a parallel DFSA regime and is not covered by VARA; founders choosing between mainland Dubai and the DIFC should treat them as separate licensing paths.
In Singapore, custody of digital payment tokens falls under the Payment Services Act administered by MAS. The major payment institution licence tier covers digital payment token services, including custody; the standard payment institution licence applies to lower-volume operators. MAS has been explicit that custody platforms must meet technology-risk and asset-segregation standards regardless of the tier of licence obtained.
The SFC in Hong Kong licenses virtual-asset trading platforms under its VATP regime, and custody performed in connection with a licensed platform must meet SFC requirements on safeguarding client assets. Stand-alone custody businesses must assess whether their activity engages the securities regime independently of a trading platform licence.
What the application process looks like for a custody-focused early-stage business
The custody licence application process follows a broadly consistent logic across hubs, though the documentation, timing and pre-application engagement expectations vary materially. In our practice, the applications that proceed without material delay share four characteristics: a completed corporate structure before submission, a technology and operational description that directly addresses the regulator's key-management expectations, a credible AML/CFT programme that satisfies the Travel Rule (the FATF-mandated obligation to pass originator and beneficiary data with a virtual-asset transfer), and a management team whose members individually satisfy the fit-and-proper standard in the target jurisdiction.
The pre-application engagement stage – a structured meeting with the regulator before formal submission – is expected in most flagship hubs and is not optional in practice. Regulators use it to communicate known concerns about the applicant's model. Founders who arrive at that meeting without a complete picture of their technology stack, their key-custody architecture and their proposed compliance officer invariably find the meeting is the start of a several-month remediation loop rather than the beginning of a clean application track.
Timelines vary qualitatively by jurisdiction and depend heavily on application quality. A complete, clean custody application in a well-resourced EU member state under MiCA can reach authorisation in a matter of months; applications with material deficiencies, incomplete KYC on UBOs or vague technology descriptions extend that timeline materially. Founders who conflate "filing" with "approval" consistently mis-sequence their product launch against their regulatory position.
Mid-application changes to corporate structure, beneficial ownership or key personnel trigger supplemental review in every jurisdiction OBOLUS monitors. Early-stage businesses, where cap tables and founding teams are still in motion, need to lock structure before filing – not after.
If you are mapping the custody licensing path for the first time and need to understand which jurisdictions apply to your product design, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the key-management model, the banking – change the analysis.
What early-stage founders get wrong about custody licensing
The most consistent mistake we see is treating the custody licence as the last step before launch rather than the first constraint on product design. Custody licensing is an architecture question before it is a paperwork question. The choice of key-management model – MPC, hardware security module, multi-sig, sub-custody with a licensed third party – determines which regulator accepts the application, which capital tier applies and which ongoing obligations attach. A founder who finalises the technical architecture before taking a licensing view often builds something that is expensive or structurally impossible to license in the intended jurisdiction.
The second common mistake is conflating VASP registration – a lighter-touch AML-focused registration available in some jurisdictions – with the regulatory authorisation required to hold client assets. In several EU member states under the pre-MiCA transitional regime, a VASP registration was sufficient for exchange activities but did not extend to custody. MiCA replaced that distinction with a unified CASP authorisation framework; but the muscle-memory of "registered = licensed" persists, and founders who assume registration covers custody activity are creating a gap that regulators find easily.
The third mistake is the offshore-only approach: structuring a holding entity in the BVI or Cayman and assuming that a registration there satisfies the licensing requirements of every market the business serves. The BVI VASP Act 2022 and the Cayman VASP Act establish local registration obligations but say nothing about MiCA requirements for EU clients, MAS authorisation for Singapore users or SFC licensing for Hong Kong activity. Operating across multiple markets from an offshore entity does not reduce regulatory obligations; it multiplies them.
Decision matrix: which custody structure fits which early-stage profile
Not all early-stage custody businesses face the same licensing path. The most practical way to think about structure is by the combination of user geography, asset type and intended scale.
Profile A – EU-first, institutional clients, multiple member states. The efficient structure is CASP authorisation in a single MiCA member state with passporting to other EU/EEA markets. This avoids parallel national applications and creates a single regulatory relationship. The trade-off is the MiCA own-funds requirement for custody services and the whitepaper obligation if assets serviced include regulated token classes. Timeline to authorisation is measured in months from a complete filing and depends on NCA workload and application quality.
Profile B – MENA-first, retail and institutional, Dubai as the anchor. VARA custody authorisation is the primary target. The DIFC path runs parallel but is a separate application under DFSA. Founders serving MENA clients from a Dubai entity and EU clients directly need both VARA and at least one MiCA CASP authorisation – or a sub-custody arrangement with an EU-licensed custodian for the EU leg. The key risk at this profile is assuming VARA covers the global user base.
Profile C – Asia-Pacific distribution, Singapore or Hong Kong anchor. MAS major payment institution licensing for Singapore and SFC VATP-associated custody authorisation for Hong Kong serve different markets and have different capital, technology-risk and inspection regimes. A founder choosing between them should assess user concentration, banking availability and the comparative fit-and-proper standards for the management team, not just the marketing narrative about each hub's friendliness to crypto. In our practice, founders who choose a jurisdiction based on reputation alone rather than structural fit regularly need to add a second jurisdiction within 18 months.
Profile D – global retail, limited initial capital, time-sensitive launch. Sub-custody through a licensed custodian is worth serious analysis. It avoids the regulatory timeline and capital requirement of direct licensing, transfers the custody obligation to a licensed entity and allows the product to reach market. The legal and commercial relationship with the sub-custodian needs careful drafting: liability allocation, client-asset segregation, step-in rights on insolvency and fee structures all require bespoke terms. This is a bridge, not a permanent architecture – as the business scales, direct custody licensing typically becomes commercially necessary.
AML obligations and the Travel Rule in a custody context
Custody businesses are VASPs for FATF purposes and are subject to the full AML/CFT framework – customer due diligence, transaction monitoring, suspicious activity reporting and the Travel Rule – from the first day of operation. The Travel Rule requires that originator and beneficiary information travels with a virtual-asset transfer above the applicable threshold, which varies by jurisdiction and remains a [VERIFY] figure in every major hub. What is consistent across MiCA, MAS, the FCA's UK regime and VARA is the obligation itself: a custody business that receives or sends assets on behalf of clients must implement a Travel Rule compliance solution before it handles the first client transfer.
In our cross-border practice, Travel Rule compliance is frequently the last item added to a custody licence application and the first item queried by the regulator. The compliance gap typically arises because Travel Rule solutions require integrations with counterparty VASPs, and early-stage businesses have not yet built the network of counterparty relationships that makes that integration practical. Regulators do not accept "we will build this post-licence" as a satisfactory response. The compliance programme – including the technology solution and the policies – must be complete at the point of application.
The AML programme also requires a named compliance officer who satisfies the regulator's fitness standard. For early-stage businesses, this is often the first moment the founder realises that "compliance" is a dedicated senior function, not a part-time addition to an existing role. Regulators across every hub OBOLUS monitors have rejected applications or extended review periods specifically because the proposed compliance officer lacked the experience, independence or bandwidth the role demands.
How a custody licensing matter unfolds in practice
In a recent engagement, a fintech startup with a custody-first product design engaged OBOLUS at the pre-application stage. The team had already chosen an EU member state for its initial authorisation but had not yet filed. Our review identified two structural issues: the entity's UBO disclosure did not satisfy the target NCA's beneficial-ownership documentation standard, and the proposed key-management architecture – an MPC scheme with an emergency recovery mechanism controlled by the founding team – raised a regulatory question about whether the arrangement satisfied the segregation obligation under the applicable MiCA provisions. We worked with the team to restructure the UBO disclosure chain and to revise the technical documentation to clarify the logical separation between the emergency mechanism and day-to-day custody operations. The revised application was filed in the following quarter and proceeded without a material deficiency notice. The business launched its custody product within the licensing window it had originally projected – but only because the pre-filing review compressed what would otherwise have been a multi-cycle correction process.
A common assumption: "one licence is enough to serve clients worldwide"
A common assumption among early-stage founders is that a single licence – whether from an offshore jurisdiction or a well-recognised hub – provides a compliant basis for serving a global user base. It does not. Every major custody regime is territorially focused. MiCA governs services provided to clients in the EU/EEA. VARA governs activities conducted in mainland Dubai. The MAS Payment Services Act applies to digital payment token services in Singapore. None of these regimes waives or substitutes for the others.
The practical consequence is that a custody business serving clients across the EU, the MENA region and Asia simultaneously needs at minimum three licensing engagements, not one. This is not an argument against international expansion; it is an argument for sequencing that expansion against a clearly mapped licensing timeline. Founders who launch globally on the assumption that "we'll sort the licences later" find that enforcement – in the form of account closures, banking withdrawals, regulator investigations and, in some jurisdictions, personal liability for directors – arrives faster than their licensing timeline allows.
We map the licence stack across operating, custody and payment layers before a founder commits to a jurisdiction or a product architecture. That mapping is the first deliverable in every OBOLUS custody engagement, and it is the document that shapes every subsequent decision about entity structure, banking and launch sequencing.
If a prior application stalled or a banking relationship was closed following a licensing review, write to info@oboluslaw.com. A second structural read can surface the root cause and the path to resolution.
Related at OBOLUS
- Licensing & Registration for Digital-Asset Businesses – the full regulatory authorisation practice for exchanges, custodians and token issuers
- VARA Licence Application in Czech Republic – a practical guide to VASP authorisation under the Czech MiCA implementation
- Digital-Asset Custody Licensing for Established Operators – licence maintenance, variation and cross-border expansion for businesses already authorised
FAQ
How long does a crypto licence take to obtain?
Timelines vary by jurisdiction, licence category and application quality. A complete, deficiency-free custody application in a well-resourced EU member state under MiCA typically takes a matter of months from formal submission. Applications in hubs such as Singapore or Hong Kong follow their own timetables. The most reliable predictor of a short timeline is the completeness of the application at the point of filing – corporate structure, AML programme, Travel Rule solution, fit-and-proper documentation and technology description all resolved before submission, not during review.
Which jurisdiction is best for licensing my crypto business?
There is no single best jurisdiction; the right choice depends on user geography, asset types serviced, management team composition, capital availability and banking relationships. EU authorisation under MiCA provides passporting across 27 member states. Dubai's VARA regime suits MENA-focused operators. MAS in Singapore and the SFC in Hong Kong serve Asia-Pacific distribution. The correct analysis starts with the product and user base, not the jurisdiction's marketing reputation. OBOLUS maps the decision across each of these dimensions before any filing recommendation is made.
Do I need a separate custody licence?
In most leading jurisdictions, yes. Custody – holding private keys or controlling access to client assets – is a regulated activity distinct from exchange, brokerage or payment services. An exchange licence does not automatically authorise custody. Under MiCA, custody and administration of crypto-assets is a named CASP service requiring specific authorisation. VARA, MAS and the SFC each treat custody as a standalone regulated activity. If your product exercises control over client assets, a dedicated custody licence or regulatory authorisation for that activity is required in every jurisdiction where those clients are located.
OBOLUS is an independent digital-asset law boutique acting exclusively for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance structures that sit around them. Digital assets are the whole of our practice. We map the licence, banking and custody stack before a founder commits to a structure – and we work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications when disputes arise. To discuss your custody licensing position, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in custody and exchange licence applications across MiCA, VARA, MAS and the BVI/Cayman VASP frameworks for early-stage digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.