Why the VARA Regime Is the First Thing Every Dubai-Based Founder Should Understand
Operating a virtual-asset business in Dubai without a VASP licence (virtual asset service provider authorisation) from VARA – the Virtual Assets Regulatory Authority exposes the entity to enforcement, banking denial and forced exit from the market before the product reaches scale. For an early-stage founder, that is not a theoretical risk. It is the most predictable way to lose the runway you spent months raising. VARA was established by Decree No. 4 of 2022 and sits as the world's first dedicated standalone virtual-asset regulator operating across mainland Dubai. Its activity-based licensing architecture means that every commercially significant digital-asset function – exchange, custody, lending, advisory, transfer and settlement, broker-dealer, investment management – carries its own regulated perimeter. Founders who build first and licence later routinely discover that their technical stack crosses two or three activity categories simultaneously, compounding the authorisation burden. This guide maps that terrain and explains how to approach the process from day one.
The core answer is direct: a VARA licence application for an early-stage founder in Dubai involves selecting the correct activity category under the VARA rulebooks, preparing a compliant business plan and governance architecture, satisfying AML/CFT and compliance-officer requirements, and submitting through VARA's portal. Timelines vary by activity complexity and completeness of the application file. Cross-border businesses – those with a UAE operating entity but a global user base or foreign banking arrangements – face an additional layer of analysis because VARA's jurisdiction covers mainland Dubai only and sits alongside, not above, the DIFC's separate financial-services regime.
The sections below take you through the regulated perimeter, the application process, the structural mistakes founders make, the cross-border question and a decision matrix by operator profile.
What Does VARA Actually Regulate – and Where Does the Line Fall?
VARA licenses virtual-asset activities, not entities in the abstract. The distinction matters enormously at the application stage. A founder building an exchange that also holds client assets in omnibus wallets is, in VARA's analytical frame, conducting both exchange and custody activities. Each requires its own authorised activity endorsement within the licence. Understanding the perimeter before filing saves months of back-and-forth with the regulator.
VARA has published rulebooks covering seven principal activity categories: VA Advisory Services, VA Broker-Dealer Services, VA Custody Services, VA Exchange Services, VA Lending and Borrowing Services, VA Management and Investment Services, and VA Transfer and Settlement Services. A single legal entity may hold authorisation for multiple activities, but each carries independent capital, systems and governance requirements. The regulator reviews each activity stream on its own merits. A robust exchange application will not carry a weak custody application across the line.
A point that trips up many early-stage founders is the concept of "Minimum Viable Product" launches in Dubai. VARA does not recognise a soft-launch exemption for commercial virtual-asset services. Once an entity offers a service to users in Dubai for value – whether beta users, presale participants or referral-invited testers – the relevant activity authorisation is required. The commonly heard assumption that beta revenue escapes regulation is inaccurate.
One additional structural point: VARA's jurisdiction covers the Emirate of Dubai and does not extend to the Dubai International Financial Centre (DIFC), which operates its own financial-services regulatory framework under the DFSA. A founder choosing between mainland Dubai and DIFC establishment is making a substantive regulatory choice, not merely an administrative one. We address that choice in the decision matrix below.
How Does the VARA Licence Application Process Work Step by Step?
The VARA licence application follows a structured multi-stage process, and the quality of the file submitted at each gate determines how quickly the regulator progresses the matter. Early-stage founders consistently underestimate the documentation burden. The process, in broad terms, runs as follows.
Step 1 – Activity scoping and entity structure. Before anything is filed, founders must confirm which activity categories their business model engages and whether the proposed Dubai entity is the right vehicle. A British Virgin Islands holding structure with a UAE subsidiary, for example, creates questions about beneficial ownership disclosure, group-level capital adequacy and the extent to which the Dubai entity can satisfy VARA's substance requirements. Getting this wrong at stage one means restructuring mid-application.
Step 2 – Pre-application engagement. VARA operates a formal engagement pathway before the main application. This stage allows founders to present a summary of their business model, the proposed activities and the governance structure. Regulator feedback at this stage is genuinely valuable. We have seen founders avoid significant rework by surfacing structural concerns early rather than after full documentation has been prepared.
Step 3 – Initial approval and Minimum Viable Licence (MVL) status. VARA introduced the MVL concept to allow companies to establish and begin preparatory activities while the full licensing review proceeds. MVL status is not a licence to serve clients commercially. It is an establishment permit. Founders who begin acquiring customers under MVL status risk enforcement.
Step 4 – Full application file submission. The full file includes a comprehensive business plan, financial projections, AML/CFT policy documentation, technology and cyber-security assessments, governance manuals, fit-and-proper documentation for all senior individuals, and capital evidence. VARA's requirements for each activity category are detailed in the relevant rulebook, and no section can be treated as boilerplate. Regulators in the leading hubs – including VARA – increasingly expect bespoke policies that map directly to the applicant's actual business model rather than generic templates.
Step 5 – Regulatory review and Q&A phase. After submission, VARA may issue rounds of questions. Response quality and speed at this stage are material to the overall timeline. A poor response – one that is too brief, inconsistent with the earlier business plan or drafted without reference to the relevant rulebook provisions – will extend the process. In our practice, we treat each Q&A round as a second filing, not an administrative formality.
Step 6 – Licence issuance and post-authorisation obligations. Upon approval, the entity receives its VASP licence with the authorised activities listed. Post-authorisation obligations include ongoing regulatory reporting, annual compliance reviews, maintenance of the required capital and adherence to the VARA rulebooks on an ongoing basis. A licence is not a permanent asset – it can be suspended or revoked for non-compliance.
The process above describes the standard path. Your facts – the entity structure, the user base geography, the banking relationships, the technical architecture – change the analysis materially. For a scoped assessment of where your build sits in the VARA activity framework, contact OBOLUS at info@oboluslaw.com.
What Are the Most Expensive Mistakes Founders Make in a VARA Application?
The most expensive mistake in a VARA application is underestimating it. Most founders who approach us after a stalled or rejected application made the same errors. None of them were complex legal problems in isolation. Together, they were fatal to the timeline.
Mistake one: scoping the wrong activities. A founder building an aggregator that routes orders through third-party exchange APIs may believe they are not conducting exchange activity themselves. VARA's analysis focuses on economic function, not on how the technology is labeled. If the entity is effectively matching buyers and sellers and taking spread or commission, the exchange activity category applies.
Mistake two: appointing a compliance officer who lacks digital-asset experience. VARA requires a qualified Compliance Officer whose credentials must satisfy the regulator's fit-and-proper standards. A general AML officer from a traditional financial institution without demonstrable virtual-asset exposure is frequently questioned. The compliance function must also be operationally independent from the business line it supervises – a CTO who doubles as CCO will not pass review.
Mistake three: ignoring substance requirements. VARA expects the Dubai entity to have genuine operational presence. Founders who incorporate a UAE entity but keep all employees and systems elsewhere create a substance problem. The regulator expects key decision-makers, at minimum the CEO and the Compliance Officer, to be present and exercising authority from the UAE.
Mistake four: submitting generic documentation. A business plan that reads like a pitch deck, AML policies copied from a template, and a technology assessment that describes the system in general terms rather than identifying specific controls – these collectively signal to VARA that the applicant has not achieved operational readiness. The regulator will ask for substantive rewrites, which add weeks to the timeline.
Mistake five: under-capitalisation. VARA's capital requirements are activity-specific and are set to reflect the risk profile of each category. Founders who structure the company with nominal paid-in capital and plan to inject further capital post-authorisation will find that the application does not progress until capital requirements are demonstrably met or a credible, documented capital-raising plan is in place.
How Does a Global User Base Complicate a VARA Licence?
A VARA licence covers activities conducted from mainland Dubai. It does not constitute regulatory authorisation in the jurisdictions where the platform's users are located. This is the core cross-border tension every early-stage founder building for a global audience must resolve before onboarding a single user outside the UAE.
Consider the EU dimension. MiCA – the Markets in Crypto-Assets Regulation – applies to crypto-asset service providers offering services to EU/EEA users, regardless of where the provider is established. A Dubai-licensed exchange serving German retail clients without a MiCA authorisation is operating unlawfully in the EU, a fact that VARA's licence does nothing to cure. The same logic applies to the UK under FCA regulations, to Singapore under the Monetary Authority of Singapore's Payment Services Act regime, and to other leading hubs that have adopted territorial reach for their regulatory perimeters.
Banking further complicates the picture. Many founders assume that a VARA licence automatically unlocks UAE banking. In practice, UAE banks conduct their own correspondent-banking risk assessments of virtual-asset businesses, and a VARA licence is necessary but not always sufficient. Banking relationships for a UAE-licensed entity with a global user base require a documented jurisdictional-reach analysis – banks need to understand which regulatory regimes the business is subject to across its user footprint before opening settlement accounts.
In our cross-border practice, we regularly advise founders on what we call the "licence, banking and tax stack" – the three interdependent decisions that must be mapped in advance rather than resolved sequentially after the first failure. Getting the UAE entity right is the first layer. Addressing the regulatory exposure in the EU, UK, Asia or the Americas is the second. Structuring the group to hold those licences efficiently from a tax and capital perspective is the third.
A practical note on the DIFC vs. mainland Dubai question: a founder targeting institutional counterparties, asset managers and professional investors may find that the DIFC's financial-services framework – regulated by the Dubai Financial Services Authority (DFSA) – provides a better structural fit than the mainland VARA regime, which has broader retail and commercial reach. The two regimes do not overlap. A business that needs to operate in both mainland Dubai and the DIFC requires both authorisations. Allied counsel in the relevant jurisdiction can provide advice specific to DFSA matters where the engagement requires it.
If a prior application stalled or a banking relationship was declined after incorporating in Dubai, a second read of the structure can surface the cause and the route back. Write to OBOLUS at info@oboluslaw.com or reach us at t.me/oboluslaw.
From the Practice: An Early-Stage Exchange in Mainland Dubai
In a recent licensing matter, a fintech founder had incorporated a Dubai mainland entity, appointed a technology team and was six weeks from a planned public launch. The company had engaged a local firm to handle what it believed was a straightforward VASP registration. On review, the business model – a spot exchange with an integrated non-custodial wallet and a referral-based yield product – engaged three separate VARA activity categories. The original filing had scoped only one. We rebuilt the application file, restructured the compliance function and engaged with VARA through the pre-application pathway to surface and resolve the multi-activity question before submission. The company obtained its licence ahead of the revised internal timeline. The founder avoided a post-launch enforcement action that would have required a product shutdown and a fresh application from a standing start.
Which Operator Profile Should Choose Which Approach?
Not every early-stage founder faces the same VARA application. The appropriate strategy depends on the business model, the investor timeline and the intended user base. The following profiles describe the most common situations we encounter.
Profile A – The pure-play spot exchange targeting UAE retail and GCC institutional clients. This operator needs a VARA Exchange Services authorisation as the primary licence. If the platform holds client assets, Custody Services authorisation runs alongside it. The application file is substantive but well-precedented. The principal risks are capital adequacy, technology-risk assessment quality and substance. Indicative timeline from a well-prepared file to authorisation varies by application completeness and the Q&A cycle with the regulator – founders should plan conservatively and not schedule commercial launch dates against regulatory milestones.
Profile B – The DeFi-adjacent protocol with a Dubai operational entity. This operator faces the hardest scoping analysis. VARA's activity categories are written for intermediated financial services. A protocol that does not take custody of client funds and does not act as a counterparty may sit outside the regulated perimeter, or it may not – depending on governance structure, fee flows and the degree to which the "Dubai entity" exercises functional control over the protocol. The risk of mis-scoping is highest here. A formal regulatory-perimeter opinion from counsel, obtained before any public statements about the entity's regulatory status, is essential.
Profile C – The multi-jurisdictional fund manager or asset manager establishing a Dubai presence. This operator needs VA Management and Investment Services authorisation and is likely also subject to ADGM/FSRA requirements if the fund structure is domiciled in Abu Dhabi Global Market, or to DFSA requirements if it operates within the DIFC. The licence stack is the most complex of the three profiles. The UAE component is a necessary but partial solution; the fund domicile, the investor base jurisdiction and the administrator's location each add a regulatory dimension.
Are You Ready to File? A Pre-Application Checklist for Founders
An honest self-assessment before engaging with VARA saves significant time and cost. Based on our advisory work with early-stage founders approaching the VARA process, the following questions surface the most common readiness gaps.
- Have you mapped every commercial activity your platform conducts against VARA's seven activity categories – including planned features that will launch within twelve months of authorisation?
- Does your legal entity structure give the Dubai entity genuine operational substance – employed key personnel, local decision-making authority, documented processes run from the UAE?
- Has your Compliance Officer been identified, and do their credentials reflect demonstrable virtual-asset AML/CFT experience?
- Is your AML/CFT policy documentation specific to your business model and user base, including documented Travel Rule procedures for wallet-to-wallet transfers above the applicable threshold?
- Have you commissioned an independent technology and cybersecurity assessment that maps to VARA's technology governance requirements?
- Can you evidence the required minimum capital for each activity category you are applying to conduct, or do you have a documented and credible capital-injection plan?
- Have you conducted a jurisdictional-reach analysis for your intended user base, identifying which additional regulatory authorisations are required in user-base jurisdictions beyond the UAE?
- Do your banking relationships – or your banking prospects – align with the regulatory footprint your business will carry post-authorisation?
A "no" or "not yet" answer to any of these questions identifies work that the regulator will surface in the Q&A phase anyway. Doing it before filing is always faster.
Related at OBOLUS
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – a full map of licence categories, regimes and entry strategies across 70+ jurisdictions.
- VASP Licence Application in Australia – AUSTRAC – a jurisdiction-specific guide to the AUSTRAC registration process and its cross-border implications.
- Cross-Chain Bridge Legal Risk: The Compliance Burden in Practice – analysis of the regulatory treatment of bridge protocols and the compliance questions operators face.
FAQ
How long does a crypto licence take to obtain?
Timelines vary materially by jurisdiction, activity category and application quality. In a well-prepared VARA application from a fully documented file, the process typically takes a number of months rather than weeks – the regulator's Q&A phase and capital review add time that is difficult to predict precisely. Founders should treat regulatory timelines as a planning variable and build contingency into commercial launch schedules. Filing an incomplete application to meet an investor milestone typically extends the total timeline rather than shortening it.
Which jurisdiction is best for licensing my crypto business?
There is no single answer. The optimal jurisdiction depends on the business model, the user base, the banking relationships, the investor profile and the tax structure. Dubai under VARA suits businesses targeting the GCC and seeking a well-resourced, activity-based regulatory framework. Singapore under MAS suits businesses targeting Southeast Asia and institutional counterparties. EU CASP authorisation under MiCA is required for businesses serving EU/EEA users at scale. A common assumption is that a single offshore licence covers global operations – it does not. We map the full licence stack before any application is filed.
Do I need a separate custody licence?
Under VARA, custody is a distinct regulated activity. If your platform holds, stores or controls client virtual assets – even briefly during a transaction – the Custody Services activity category applies and must be included in your licence scope. This is one of the most frequently misscoped elements in early-stage applications. Founders who rely on third-party custodians need to document that relationship carefully to demonstrate they are not themselves conducting custody. The answer depends on the technical architecture of your specific platform and is not a generic yes or no.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance structures that sit around them. We map the licence, banking and tax stack across operating, custody and payment layers before you commit – so the structure you build is one you can sustain under regulatory scrutiny. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialist in VARA, MiCA and APAC licensing strategies for early-stage digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.