What digital-asset custody licensing actually requires
Digital-asset custody licensing is the process by which a firm obtains regulatory authorisation to hold, safeguard or control cryptographic keys on behalf of clients – and in most leading jurisdictions, operating that service without the right authorisation carries direct enforcement risk. With VASP supervision tightening across the major hubs, a custodian that treated registration as optional is now routinely finding its banking relationships suspended before regulators even issue a formal notice. The purpose of this page is to map the regulated perimeter, the process and the cross-border decisions that custody-specific licensing demands.
Custody is a regulated activity under MiCA (the EU's Markets in Crypto-Assets Regulation, supervised by ESMA and national competent authorities), under the VARA regime in Dubai, under the FSRA framework within ADGM in Abu Dhabi, under the MAS Payment Services Act in Singapore, and under the SFC's VASP regime in Hong Kong. Each regime draws the perimeter differently. Getting that perimeter wrong – treating a service as out-of-scope when it is not – is the single most expensive mistake we see.
The sections below walk through the regulated basis, the typical application process, the cross-border reality, common structural mistakes, and a decision matrix by operator profile. A mid-page micro-matter illustrates what happens when the analysis is done late.
Who needs a custody licence – and who is mistaken about it
Any firm that takes unilateral control of a client's private keys – even temporarily, even as a product feature rather than a standalone service – is almost certainly inside the regulated perimeter in every major hub. The legal question is not whether custody is the firm's primary activity; it is whether the firm has the technical ability to move client assets without the client's independent authorisation.
Under MiCA, crypto-asset custody is defined broadly enough to capture arrangements that most operators call "hot-wallet management," "key recovery services" or "institutional safekeeping." ESMA has signalled that substance, not labelling, governs. A firm providing wallet infrastructure to retail or professional clients in an EU member state without CASP authorisation is exposed from the moment the first client key is accepted.
In Dubai, VARA's activity-based licence map lists custody and transfer as a discrete regulated activity. A firm authorised only for exchange or advisory services in Dubai cannot bolt on custody without an amended or additional approval. We have seen firms discover this mid-product-launch, after banking onboarding has already begun.
A common assumption is that operating through a non-custodial interface removes the obligation entirely. That is sometimes true – but the assessment turns on whether the firm ever holds keys, controls a smart contract with withdrawal authority, or manages a multi-party-computation arrangement where the firm's shard is necessary for execution. Where the firm's participation is required for a transaction to complete, most regulators treat that as functional custody.
CTA #1If you are mapping whether your product architecture triggers a custody licence in one or more jurisdictions, the analysis depends on your specific key-management design. The standard perimeter test above describes the general approach; your technical stack, your user base and your entity structure change the answer. Map your options with OBOLUS before committing to an architecture or a jurisdiction.
What does the custody licence application process look like?
The custody licensing process in most flagship regimes follows a structured sequence: regulatory scoping, entity preparation, document assembly, submission and review, and post-authorisation conditions. Each stage has dependencies that, if missed, reset the clock.
The first stage is regulatory scoping – confirming which activities require authorisation in which jurisdictions and which licence category or activity class captures custody. Under MiCA, custody falls within the CASP authorisation framework; under VARA, it is a discrete licence activity; under the MAS Payment Services Act, it intersects with the digital payment token service categories. The scoping memo is not optional. Firms that skip it and proceed directly to document assembly routinely find they have prepared for the wrong licence class.
Entity preparation follows. Most custodians need a locally incorporated or registered entity in the licensing jurisdiction, a local presence (a qualifying officer or at least a registered address), and internal policies that meet the applicable AML/CFT standards, including compliance with FATF Recommendation 15 on virtual assets and, where the Travel Rule applies, a technically compliant data-transmission solution. Regulators in the leading hubs increasingly expect that the compliance infrastructure is operational, not merely drafted, at the point of submission.
Document assembly for a custody-specific application typically covers: a detailed business plan with financial projections; key-management and safeguarding policies; a cybersecurity framework; AML/KYC and transaction-monitoring policies; fit-and-proper submissions for directors and beneficial owners; and, in some regimes, a technology audit or third-party assessment of the custody architecture. The volume is significant. Incomplete submissions are the primary cause of prolonged review timelines.
Post-authorisation, custody licences in most regimes carry ongoing obligations: regular regulatory reporting, client-asset segregation requirements, capital adequacy maintenance, and – under MiCA – specific rules around liability for loss of crypto assets held in custody. Non-compliance with post-authorisation conditions is treated by regulators as a separate enforcement trigger, distinct from the initial licensing failure.
How long does authorisation take in practice?
Custody licensing timelines vary materially by jurisdiction, completeness of the submission and regulator workload – and any adviser who quotes a precise timeline without knowing the specific regime, the specific activity class and the current review queue is speculating. That said, there are practical ranges that operators can plan around.
In the EU under MiCA, the CASP authorisation process operates against a statutory review period, but that period begins only when the competent authority deems the application complete. Pre-submission engagement with the relevant NCA – and in some member states a formal pre-application meeting – compresses the clock materially. Firms that submit without prior engagement routinely receive completeness queries that add months. The effective timeline from first submission to authorisation, in our experience, runs considerably longer than the statutory review window when pre-work has been skipped.
In Dubai under VARA, the activity-licence process is iterative. VARA engages actively during review, and the pace is partly a function of the firm's responsiveness to information requests. Firms that retain local counsel and maintain a dedicated regulatory contact point move faster than those managing the process remotely.
Singapore's MAS is known for thorough vetting. The DPT service licensing process under the Payment Services Act is detailed and the review is substantive. Operators entering Singapore should plan for a process measured in months, not weeks, and should not assume that a prior authorisation in another jurisdiction shortens the review.
The BVI's VASP Act 2022 operates a registration model that is structurally less demanding than a full authorisation process. That speed has made the BVI attractive for firms seeking a fast initial registration, often as part of a broader multi-jurisdiction stack. Cayman operates a similar registration/licensing split under CIMA.
How does cross-border service delivery complicate custody licensing?
A custodian serving clients across multiple jurisdictions faces a licensing stack problem that no single authorisation resolves. The EU's MiCA passporting mechanism – under which a CASP authorised in one member state may passport custody services across the EU and EEA – is the most developed example of a cross-border solution, but it applies only within the single market. A custodian serving institutional clients in Singapore, corporate clients in Dubai and funds domiciled in the Cayman Islands from a single EU-authorised entity is almost certainly operating outside its authorised perimeter in at least two of those markets.
The key analytical question for a multi-jurisdiction custodian is not "where is our licence?" but "where does each regulated service activity touch a regulated person or a regulated market?" The answer turns on where the client is located, where the assets are technically held, where the contractual relationship is governed, and whether a local licence exemption applies. None of those questions has a universal answer.
Banking adds a further layer. Custody businesses – particularly those holding fiat alongside digital assets on behalf of clients – find that banking access is directly correlated with regulatory status. A custodian with a strong VARA authorisation but no MiCA footprint will struggle with EU correspondent banking. A BVI-registered entity holding a CAYMAN CIMA registration will face different banking constraints again. We map the licence, banking and tax stack together before a client commits to a structure.
In a recent custody matter, a fund administrator had established custody operations in a free-zone jurisdiction and assumed the authorisation covered the management of client assets in two additional markets where clients were resident. A cross-border perimeter analysis identified three separate licensing obligations that the existing authorisation did not satisfy. The firm restructured its entity model and obtained supplementary registrations before the product launch, avoiding what would otherwise have been an unlicensed-activity exposure in two jurisdictions simultaneously.
CTA #2If your custody operation already has a primary authorisation and you are expanding your client base or product set, a second-opinion perimeter review is the fastest way to surface unlicensed exposure before regulators do. If a prior application stalled or a banking relationship was closed without explanation, the structural cause is usually identifiable. Map your options with the OBOLUS licensing desk.
What are the most common custody licensing mistakes?
The most costly mistake in custody licensing is treating authorisation as a single event rather than an ongoing compliance obligation. Firms that obtain a licence and then allow their policies, personnel or technology to drift without notifying the regulator – or without updating their authorisation to cover new activities – accumulate latent enforcement risk that typically crystallises at the worst possible moment: a bank review, a fundraising round or an acquisition.
The second most common mistake is scope creep without regulatory mapping. A custodian that adds staking services, lending against custody balances, or a token-issuance function for a client is adding regulated activities that may not be covered by the existing authorisation. Under MiCA, the provision of custody services and the provision of other CASP services are discrete authorisation categories. Adding one without notifying the NCA is a compliance failure.
The third mistake is the "offshore licence covers everything" assumption – the belief that a BVI or Cayman registration is sufficient to serve institutional clients globally. It is not. Those registrations satisfy local AML/VASP obligations in the BVI or Cayman. They do not authorise custody services in the EU, the UAE, Singapore or Hong Kong. A firm using an offshore registration as a substitute for regulated-market authorisation is trading on borrowed time.
Fourth: inadequate beneficial-owner and fit-and-proper preparation. Most custody licence applications require detailed submissions on all persons with significant control, including in-depth background disclosures. Firms that discover a regulatory or reputational issue in a controlling shareholder's history after submission lose months. That preparation belongs at the start, not the end, of the process.
Which licensing profile fits your custody operation?
The right licensing approach depends on the operator's client profile, geographic scope and technology model. The following matrix illustrates the principal decision branches in qualitative terms.
Profile A – Institutional custodian serving EU clients: The primary authorisation target is CASP custody under MiCA, in a member state with an efficient NCA. Lithuania remains a fast EU entry point under the MiCA transition; Malta's MFSA offers an established VFA-to-CASP pathway. Once authorised, MiCA passporting addresses the EU-wide service footprint. The principal risk is timeline: EU authorisation processes are substantive, and rushed submissions extend the clock. Engage counsel early, before entity incorporation.
Profile B – Regional custodian anchored in the Gulf: The primary targets are VARA (Dubai mainland) or ADGM/FSRA (Abu Dhabi). VARA's activity-based structure means the custody licence is discrete from any exchange or advisory authorisation; both activities require separate approval. For a firm serving both UAE and offshore institutional clients, a VARA authorisation plus a Cayman CIMA registration is a frequently used stack, though banking access for each requires separate verification.
Profile C – Asian institutional custodian: MAS in Singapore and the SFC in Hong Kong are both demanding and credible. A Singapore DPT licence under the Payment Services Act is well-regarded by institutional counterparties. Hong Kong's SFC VATP regime extends to custody functions within a broader platform authorisation. A firm building for both markets should plan for sequential rather than parallel applications; the document and personnel demands overlap but the timelines are independent.
Profile D – Global fund-services custodian using an offshore base: BVI (VASP Act 2022) or Cayman (CIMA VASP) registration gives a compliant offshore base for fund-administration custody. Those registrations do not substitute for regulated-market authorisations in the EU, UAE or Asia. A fund-services custodian in this profile typically needs the offshore registration plus at least one major-hub authorisation, with the choice of hub driven by the banking and counterparty requirements of the funds it services.
Related Services at OBOLUS
Related at OBOLUS
- Licensing & Registration for Digital-Asset Businesses – full practice overview covering all licence categories and jurisdictions
- Economic Substance for Licensed VASPs in the British Virgin Islands – post-authorisation substance obligations for BVI VASP licence holders
- MLRO and Compliance Officer Function – building the AML/compliance infrastructure that custody licensing requires
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than seventy jurisdictions – mapping the licence, banking and tax stack before clients commit to a structure. We also advise on disputes and on-chain asset recovery across more than twenty-five forums, and on the compliance infrastructure that custody and payment licences require. Digital assets are the whole of our practice. We have seen the full range of custody perimeter questions – from single-hub authorisations to multi-jurisdiction restructurings – and we bring that depth to every scoping engagement. To discuss your situation, contact info@oboluslaw.com.
FAQ
How long does a crypto licence take to obtain?
Timelines vary substantially by jurisdiction, licence category and submission quality. In the EU under MiCA, the statutory review clock starts only when the competent authority deems the application complete – meaning pre-submission preparation directly controls the effective timeline. In Dubai under VARA, the process is iterative and pace depends on the firm's responsiveness. In Singapore, MAS vetting is thorough and measured in months. BVI and Cayman registration processes are structurally faster. For any specific timeline, the relevant regime and your submission readiness must be assessed together.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. The right jurisdiction depends on where your clients are located, which banking relationships you need, the tax treatment of your revenues, and whether a passportable authorisation adds long-term value. EU MiCA CASP authorisation delivers passporting across the single market. VARA and ADGM/FSRA carry strong institutional credibility in the Gulf. MAS and SFC are the tier-one Asian hubs. BVI and Cayman work well as offshore components of a broader stack. We map the full picture before a recommendation is made.
Do I need a separate custody licence?
In most leading regimes, yes – custody is a discrete regulated activity that is not automatically covered by an exchange, brokerage or advisory authorisation. Under MiCA, custody of crypto-assets on behalf of clients is a separate CASP service category. Under VARA, custody and transfer is a distinct activity class. Under the MAS Payment Services Act, the custody function intersects with specific DPT service categories. Whether your existing authorisation covers a custody function requires a direct perimeter analysis; a blanket assumption that it does is a common and costly error.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in multi-jurisdiction VASP authorisation strategy and custody perimeter analysis for digital-asset firms.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.