EST · MMXXVI
Home/Services/Licensing Registration/EMI licence for crypto firms for Early-stage Founders
Licensing & Registration

EMI licence for crypto firms for Early-stage Founders

Emi licence for crypto firms for Early-stage Founders. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOL

An early-stage crypto founder planning a product launch quickly faces a problem that is simultaneously legal, commercial and operational: payments need to move, clients need to hold balances, and the architecture that makes all of it possible sits squarely inside regulated territory. In most of the leading digital-asset hubs, issuing electronic money, holding client funds or enabling fiat on-ramps requires an Electronic Money Institution (EMI) licence – an authorisation permitting a regulated entity to issue e-money, execute payment transactions and, in certain regimes, interface directly with a VASP (virtual asset service provider) stack. Getting the sequence wrong – building the product first, seeking the licence second – is the single most common structural error we see at the early stage.

For a crypto business, an EMI licence is not simply a payment credential. It is the rail that connects fiat liquidity to on-chain infrastructure, and in most jurisdictions it determines whether a firm can open institutional banking accounts, hold client e-money balances and issue prepaid instruments tied to a digital-asset wallet. Regulators across the EU under MiCA, the FCA in the United Kingdom and equivalent authorities in Singapore and the UAE all treat the payment and custody layers as distinct regulated activities – meaning a single VASP registration rarely covers the full operational picture. This page sets out what an EMI licence means for an early-stage crypto firm, where to obtain one, and how to avoid the structural traps that stall applications or, worse, invite enforcement.

What is an EMI licence and why does a crypto firm need one?

An EMI licence authorises a regulated entity to issue electronic money – a digital store of monetary value that the holder can use to make payments – and to execute payment transactions on behalf of users. For a crypto firm, this is the regulated bridge between the blockchain layer and the legacy banking system. Without it, a platform that accepts fiat deposits, holds user balances, or processes EUR/USD withdrawals is almost certainly conducting regulated payment activity without authorisation.

The distinction matters for product architecture. A pure VASP registration, available in jurisdictions such as Lithuania under the Bank of Lithuania regime or under the BVI Financial Services Commission's VASP Act, covers digital-asset exchange and transfer services. It does not, on its own, authorise the issuance of e-money or the provision of payment accounts. A crypto exchange that settles in fiat, a custodian that maintains user fiat balances or a fintech that issues a crypto-linked card therefore needs to assess the EMI layer separately from the VASP layer.

Across the EU, ESMA and national competent authorities oversee the transition to the MiCA CASP regime, but MiCA operates alongside – not instead of – the Payment Services Directive framework governing EMIs. A firm seeking to passport payment services across the EU/EEA must hold CASP authorisation for its digital-asset activities and a separate EMI authorisation for its payment and e-money functions. That dual-authorisation reality is one of the first things we map for founders who arrive with a product that crosses both regulated perimeters.

Operating without the right licence risks enforcement, frozen payment rails and lost banking. That is not a theoretical risk: regulators in the EU, UK and Singapore have taken action against payment-adjacent crypto firms operating without the relevant authorisation, and correspondent banks routinely decline to open or maintain accounts for entities whose regulatory status is ambiguous.

For a scoped assessment of your payment and licensing architecture, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options.

Which jurisdictions offer an EMI route for crypto firms?

The viable EMI jurisdictions for a crypto firm are determined by three variables: speed to authorisation, passporting reach and the regulator's appetite for business models that combine e-money and digital assets. No single jurisdiction is optimal for every profile; the right answer depends on where users are, where banking lives and what activities the product actually performs.

Lithuania has historically been a preferred EU entry point. The Bank of Lithuania processes EMI applications and has maintained a relatively predictable authorisation pathway under the EU regulatory regime. Once authorised, an EMI can passport payment services across all EU and EEA member states – a significant commercial advantage for a crypto firm targeting European retail or institutional clients. Under the MiCA transition, a Lithuanian entity seeking to provide crypto-asset services alongside payment functions will need to layer the CASP authorisation on top of its EMI status.

Malta offers an alternative EU route via the MFSA. Malta's VFA framework is transitioning to the MiCA CASP regime, and the MFSA has signalled continued openness to regulated digital-asset businesses. A Malta-authorised EMI carries the same EU passport, with the MFSA as the home regulator. In our cross-border practice, we have seen founders choose Malta where the product has a securities-adjacent component that benefits from the MFSA's familiarity with the VFA agent model.

Outside the EU, the FCA in the United Kingdom operates a separate EMI registration and authorisation regime. Post-Brexit, UK authorisation does not carry EU passporting rights, but it grants access to the UK payments ecosystem and, increasingly, to institutional counterparties who require FCA oversight as a condition of banking or custody relationships. The FCA's financial-promotion rules add a layer of marketing compliance for crypto-facing EMIs that operators should model before launch.

In the Gulf, VARA in Dubai and the FSRA within ADGM in Abu Dhabi govern virtual-asset activities separately from payment-services licensing. A crypto firm operating in the UAE will typically structure the VARA or FSRA licence for the digital-asset layer and assess whether an additional payment-institution authorisation is required for the fiat-settlement function – a determination that turns on the specific activities performed and the structure of user flows.

Singapore's MAS governs payment services under the Payment Services Act, which covers digital payment tokens as well as e-money and payment accounts. A single major payment institution licence under MAS can cover multiple regulated payment activities simultaneously – a structurally efficient outcome for a firm that needs both DPT services and e-money capabilities. Timelines and capital requirements under MAS vary by the tier and activities sought and should be confirmed against current MAS guidance.

What does the EMI application process look like for an early-stage crypto firm?

The EMI application process follows a structured sequence that typically spans several months from initial filing to authorisation, with the precise timeline varying by jurisdiction and the completeness of the application at submission. Understanding the sequence before you begin is essential: regulators in the EU, UK and Singapore operate on the principle that an incomplete application restarts the clock, and gaps in the AML/CFT framework or the governance documentation are the most common reasons for delay.

The process breaks into five stages. First, a regulatory perimeter analysis confirms which activities the product performs and which regulated permissions are required – at this stage, it is common to discover that a product crosses more than one regulated category, requiring a combined EMI and CASP or DPT application rather than a single filing. Second, the legal entity is incorporated in the target jurisdiction, with the appropriate share structure, directors and beneficial ownership documented to meet the regulator's fit-and-proper expectations. Third, the application package is assembled: business plan, financial projections, governance and control framework, AML/CFT programme, IT and security assessment, and a safeguarding or own-funds analysis.

Fourth, the application is filed and the regulator's assessment period begins. Regulators typically issue requests for information (RFIs) during this phase; the speed and quality of responses directly affects the timeline. Fifth, upon authorisation, the firm satisfies any pre-commencement conditions – commonly including evidence of minimum own funds, a live safeguarding arrangement and a designated compliance officer – before the licence becomes operational.

A common structural mistake at the early stage is to incorporate in the target jurisdiction without first confirming that the directors and senior managers meet the fit-and-proper criteria for that regulator. In our practice, we regularly advise founders who have set up the entity and then discovered that a director's background or the absence of a locally resident senior manager blocks the application. Resolving that after incorporation is time-consuming and sometimes requires restructuring the board before the application can proceed.

How does the cross-border reality complicate an EMI licence for a crypto firm?

A crypto business almost never operates in a single jurisdiction. The entity may sit in Lithuania, the technical infrastructure in Switzerland, the founding team in the UAE and the user base across multiple EU member states and Southeast Asia. Each of those facts has a regulatory consequence, and the EMI licence is only one layer of the compliance picture.

The most immediate cross-border complication is the interplay between the EU EMI passport and the VASP or CASP requirements in each member state where users are actively solicited. EU passporting covers payment services; it does not automatically cover digital-asset services under MiCA, which requires a CASP authorisation notified to the relevant national competent authority. A Lithuanian EMI providing crypto-asset services to users in Germany or France must confirm whether the MiCA CASP passport has been activated for those activities in each member state – a procedural step that is easily missed by teams focused on the payment layer.

The Travel Rule – the obligation under FATF Recommendation 15 to pass originator and beneficiary data alongside virtual-asset transfers – applies to the VASP layer but intersects operationally with the payment infrastructure the EMI provides. A firm that processes both the fiat leg and the on-chain leg of a transaction must ensure its compliance systems capture Travel Rule data at the point where value crosses between the payment and blockchain layers. We have seen firms invest in EMI infrastructure and discover, post-authorisation, that their transaction-monitoring systems were built for one layer and not the other.

Banking is a separate and frequently underestimated cross-border challenge. An EMI authorisation does not guarantee access to a correspondent bank. In our cross-border practice, we regularly advise firms who hold a valid EMI licence but cannot open a functional banking relationship because the bank's own compliance team requires evidence of the VASP or CASP layer, the AML programme and – increasingly – a demonstrated track record of regulatory engagement. The sequencing of banking outreach relative to the licence application is a strategic question, not an administrative one.

To map the licence, banking and compliance stack for your build, write to info@oboluslaw.com. If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Map your options.

What are the most common mistakes early-stage founders make in the EMI process?

Early-stage crypto founders approaching an EMI application for the first time make a predictable set of structural errors that, in aggregate, account for the majority of delayed or declined applications in the leading jurisdictions.

The first is treating the EMI licence as the finishing line rather than the starting gate. An EMI authorisation is the permission to operate; it is not, on its own, a functioning payment infrastructure, a banking relationship or a compliance framework. Founders who obtain the licence and then begin building the operational layer – safeguarding, AML systems, transaction monitoring – find themselves in breach of pre-commencement conditions before they have processed a single transaction.

The second is underestimating the governance requirements. Regulators across the EU, UK and Singapore expect a minimum governance structure at the time of application, not at the point of launch. A board without a fit-and-proper compliance officer, or a firm without a documented risk management framework, will receive an RFI that pauses the assessment clock until the deficiency is addressed.

The third – and the one most specific to crypto – is failing to model the interaction between the EMI layer and the VASP or CASP layer before choosing a jurisdiction. A founder who selects Lithuania for its EMI pathway and then discovers that the CASP authorisation timeline extends the overall programme by a substantial period has not saved time; they have consumed it. The jurisdiction decision and the activity analysis must happen together, not sequentially.

A common assumption is that a single offshore licence is enough to serve clients globally. This is incorrect. An EMI licence issued in a non-EU jurisdiction does not passport into the EU. A BVI VASP registration does not authorise payment services in Singapore. Each jurisdiction where users are actively solicited, where transactions are processed or where banking is held is a potential regulatory trigger, and the consequences of getting that analysis wrong – enforcement action, account closure, reputational damage with institutional counterparties – are disproportionately severe at the early stage when the business has little margin for operational disruption.

Decision matrix: which EMI route fits your profile?

The right EMI jurisdiction depends on the firm's operating profile, not on a generic league table. The following matrix sets out four common founder profiles and the licensing route that typically fits each one.

Profile A – EU-first crypto exchange or wallet provider: A firm primarily serving EU users and requiring EU passporting for payment services should anchor its EMI authorisation in an EU member state with a well-developed authorisation process and regulatory openness to crypto-adjacent business models. Lithuania under the Bank of Lithuania or Malta under the MFSA are the most commonly used entry points. The CASP authorisation under MiCA will need to be layered alongside the EMI. Timeline to combined operational status typically spans a meaningful number of months; the exact duration depends on the completeness of the application and the regulator's current assessment queue.

Profile B – UK-focused fintech with crypto integration: A firm whose primary market is the UK and whose institutional counterparties require FCA oversight should pursue FCA EMI authorisation. The FCA process is thorough and the financial-promotion rules for crypto add a compliance layer that must be built into the product from day one. No EU passport; banking access within the UK financial system.

Profile C – Gulf-based exchange or institutional custody provider: A firm structuring in the UAE should model the VARA or FSRA virtual-asset licence as the primary authorisation and assess the payment-services layer separately under the applicable UAE Central Bank regime. Allied counsel in the relevant jurisdiction can advise on whether a payment institution licence is required for the specific fiat-settlement flows the product performs. The DIFC Courts provide a strong dispute-resolution forum for institutional-grade counterparty arrangements.

Profile D – Asia-Pacific crypto firm needing regional reach: A firm targeting Southeast Asia with Singapore as a hub should pursue a major payment institution licence under MAS, which can cover both DPT services and e-money functions within a single authorisation. MAS's DPT licensing regime is well-developed, and Singapore's common-law courts provide strong contractual enforcement for institutional arrangements. Hong Kong under the SFC's VATP licensing regime is a parallel route for a firm whose product has a securities-adjacent component.

Micro-matter: dual-authorisation for a payments-and-crypto platform

In a recent engagement, a payments technology company sought to add a crypto on-ramp to an existing fiat wallet product. The company held a payment institution registration in one EU member state but had not assessed whether the planned crypto features required a separate CASP authorisation. We conducted a regulatory perimeter analysis and identified that the crypto features crossed the MiCA CASP perimeter in three distinct activity categories. We advised on the sequencing of the CASP application alongside a review of the existing EMI documentation to ensure the AML and safeguarding frameworks were consistent across both regulated layers. The company filed a combined application package within the target period, and the matter proceeded to assessment without an initial RFI on the governance or AML sections – an outcome that reflected the quality of the pre-submission preparation rather than any expedited process.

Self-assessment checklist: are you ready to apply?

Before filing an EMI application, an early-stage founder should be able to answer affirmatively to the following. Each gap represents a delay risk that is faster and cheaper to address before submission than after.

First: has a regulatory perimeter analysis confirmed which activities require EMI authorisation specifically, and which require a separate VASP, CASP or DPT licence? Second: is the legal entity incorporated in the target jurisdiction with directors and senior managers who meet the regulator's fit-and-proper criteria? Third: has a minimum own-funds calculation been completed and confirmed against the regulator's current requirements? Fourth: is there a documented AML/CFT programme, including a written risk assessment, customer due diligence procedures and a transaction-monitoring methodology? Fifth: has a safeguarding arrangement – segregated client funds or an equivalent insurance/guarantee structure – been identified and, if a banking relationship is required to implement it, has that relationship been at least informally confirmed?

Sixth: has the interaction between the EMI authorisation and any required VASP, CASP or DPT authorisation been modelled, with a clear sequencing plan? Seventh: has the cross-border picture been assessed – specifically, which jurisdictions where users will be solicited or transactions processed require a separate regulatory notification, registration or licence?

If any of these questions cannot be answered with confidence, the application is not ready to file. In our experience, regulators across the leading hubs are materially more receptive to applicants who demonstrate thorough preparation at the outset than to those who file early and engage with deficiencies through the RFI process.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timelines vary materially by jurisdiction, the type of authorisation sought and the completeness of the application at submission. In practice, a well-prepared EMI application in a leading EU jurisdiction typically takes several months from filing to authorisation; a combined EMI and CASP process extends that timeline further. Regulators pause their assessment clock when they issue requests for information, so preparation quality directly determines elapsed time. We advise founders to model the authorisation timeline into their product roadmap well before they need the licence to operate.

Which jurisdiction is best for licensing my crypto business?

There is no single best jurisdiction for every crypto business. The right choice depends on where your users are, what activities your product performs, where your banking will sit and how much regulatory scrutiny your investor base expects. An EU-first strategy typically points toward Lithuania or Malta for EMI authorisation and MiCA CASP passporting. A Gulf-based firm looks to VARA or the FSRA. A Southeast Asia build starts with MAS in Singapore. We map the jurisdiction decision as part of the pre-application analysis, not as a generic recommendation.

Do I need a separate custody licence?

In most flagship jurisdictions, custody of digital assets is a distinct regulated activity from payment services and must be separately authorised. Under MiCA, custody and administration of crypto-assets on behalf of clients is a CASP activity that requires explicit authorisation – it is not covered by an EMI licence. VARA in Dubai and MAS in Singapore apply similar principles: holding client assets in a custodial capacity triggers a separate regulated permission. Whether your product triggers custody obligations depends on the technical architecture of how assets are held, which is a factual analysis we conduct before advising on the applicable licence stack.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – so that the structure you build is one a regulator, a bank and an institutional counterparty can all work with. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in multi-regime digital-asset authorisation strategies for early-stage and growth-stage crypto businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours