EST · MMXXVI
Home/Services/Licensing Registration/VASP licence application for Established Operators
Licensing & Registration

VASP licence application for Established Operators

Vasp licence application for Established Operators. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

A VASP licence (virtual asset service provider authorisation) is no longer a regulatory formality — it is the operational foundation that determines where an established operator can bank, what products it can offer and which users it can legally serve. Regulators across the major hubs have raised their authorisation expectations sharply in recent cycles, and the operators most exposed are not early-stage startups. They are businesses that built scale first and left the licensing stack incomplete. Operating without the right authorisation today risks enforcement action, correspondent-banking termination and the permanent loss of a market position that took years to build.

This page sets out the regulated basis for VASP licensing, the practical application process, the cross-border pressures that established operators consistently underestimate and the decision matrix we apply when mapping a licence strategy for a business with existing users, revenue and infrastructure.

Who Needs a VASP Licence — and Why Established Operators Face the Highest Stakes

Any business operating as an exchange, custodian, transfer service or broker for virtual assets requires regulatory authorisation in every jurisdiction where it solicits or services clients in a meaningful way. This is not limited to the jurisdiction of incorporation. Under MiCA, VARA, the Singapore Payment Services Act and the BVI VASP Act 2022, the activity test — not the registered address — determines whether an authorisation is needed. An established operator with a large existing user base in the EU, for example, cannot rely on a single offshore registration to satisfy its MiCA obligations once the relevant transitional windows close.

The stakes for an established operator are structurally higher than for a new entrant. A new entrant has no users to protect, no banking relationships at risk and no revenue stream that enforcement action can interrupt. An established operator faces all three simultaneously. In our practice, we see businesses that have operated under grandfathering provisions or informal tolerance reach a threshold moment — a banking review, a regulatory inquiry or an exchange listing due-diligence questionnaire — that forces immediate remediation across multiple jurisdictions at once.

The loss-aversion framing is correct. The question is never just "do we need this licence?" The question is "what happens to the business tomorrow if we do not have it?" Enforcement, frozen rails and the loss of institutional banking are the answers regulators have demonstrated they are willing to impose.

For a first assessment of your licence exposure across your operating footprint, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts — the entity, the user base, the banking — change the analysis. Map your options

What the Regulatory Regime Map Actually Looks Like

For an established operator, the licence stack is rarely a single instrument. It is a map across the entity structure, the service layers and the user geography. The primary regimes relevant to most multi-jurisdictional operators are as follows.

MiCA / ESMA applies across the EU and EEA. A CASP (crypto-asset service provider) authorisation issued by a national competent authority in one member state passports across the bloc. This is commercially significant: an authorisation from one EU regulator can satisfy the licensing requirement for all EU user-facing activity. The choice of member-state applicant — and the operational substance that must sit there — is a structuring decision, not a formality.

VARA in Dubai operates on an activity-based model. Exchange, custody, lending, management, advisory, transfer and settlement are separately licensed activities. An operator offering multiple services in or from Dubai must obtain each relevant activity endorsement. VARA's mainland-Dubai scope means it does not cover DIFC-regulated entities, which fall under a separate regulatory regime.

In Singapore, the Monetary Authority of Singapore administers the Payment Services Act, under which a Digital Payment Token service licence is required for entities conducting exchange, transfer or custody of digital payment tokens. The MAS applies a tiered licence model, and the applicable tier — standard payment institution or major payment institution — turns on transaction volume thresholds that the regulator sets and reviews.

The BVI Financial Services Commission and CIMA in the Cayman Islands each have their own VASP registration and licensing tracks under their respective VASP Acts. These are not equivalent instruments to a full CASP authorisation under MiCA, and an operator cannot use a BVI or Cayman registration as a substitute for an EU or UAE authorisation when serving clients in those jurisdictions.

What the Application Process Looks Like for an Established Operator

The application process for an established operator differs materially from a greenfield submission. Regulators ask about the existing business: its user base, its transaction history, its current AML programme and its governance structure. A business that has operated for several years has answers to all of those questions — but those answers may reveal gaps that a new entrant simply does not have.

The standard application process across the leading regimes involves five practical stages.

First, a pre-application assessment. The operator maps its existing activities against the activity categories in each target regime and identifies where authorisation is required, where it is currently absent and where transitional protections may apply. This is the stage that most established operators skip and most regret.

Second, entity and governance alignment. Most regulators expect the applicant entity to have sufficient operational substance — controllers, compliance officers, capital and systems — in the jurisdiction. An established operator must determine whether an existing group entity can apply or whether a new subsidiary must be established. This decision has tax, transfer-pricing and banking implications that run in parallel to the licensing process.

Third, document compilation. A full application for a CASP authorisation under MiCA, a VARA licence or a Singapore DPT licence typically requires a comprehensive business plan, AML/CFT policies, a risk assessment framework, governance documentation, systems descriptions, financial projections and evidence of the personnel who will operate the licensed entity. For an established operator, this material exists — but it must be presented in the format and at the standard the target regulator expects.

Fourth, regulator engagement. Pre-application meetings with the regulator are available in most flagship jurisdictions and are strongly advisable. The substance of those conversations — the questions the regulator focuses on, the areas it wants clarified — shapes the final application. In our practice, operators who bypass pre-submission engagement consistently produce applications that require more remediation rounds.

Fifth, post-submission management. Most regulators issue information requests during the review period. The speed and quality of responses to those requests directly affects the timeline to authorisation. Delays at this stage are almost always document-quality or responsiveness failures, not substantive regulatory objections.

What Established Operators Consistently Miss on the Cross-Border Dimension

A single offshore licence is not enough to serve clients globally. This is the most common assumption we encounter, and it is the one that creates the most acute remediation situations. The rule, stated plainly: authorisation is required in each material market, and the definition of "material" is expanding as regulators develop supervisory cooperation frameworks and information-sharing protocols.

The cross-border issues that established operators most often underestimate fall into three practical areas.

The first is EU passporting mechanics under MiCA. An established operator already serving EU clients through an unregulated entity must select a member state for its CASP authorisation, ensure operational substance in that state and manage the transition of its existing EU user book to the licensed entity. The choice of member state is not arbitrary. It determines the supervisory relationship, the local AML reporting obligations and, in practice, the speed of future regulatory interactions.

The second is the interaction between licensing and banking. Correspondent banks and payment processors increasingly require proof of authorisation in the operator's primary jurisdictions before onboarding or maintaining an account. An established operator that begins a licensing process without coordinating with its banking relationships risks a gap period in which its banking is at risk before the licence is issued. We have seen this gap create acute liquidity pressure for otherwise well-run businesses.

The third is the Travel Rule (the obligation, under FATF Recommendation 15, to pass originator and beneficiary data with a virtual asset transfer). Compliance with the Travel Rule across multiple jurisdictions — where the data threshold and the acceptable technical standard can differ — requires a coordinated technical and legal approach that touches every jurisdiction in which the operator sends or receives transfers. An established operator with high transfer volumes cannot treat this as a single-jurisdiction compliance item.

If a prior application stalled, a banking relationship is under review, or your existing registration no longer covers your operating footprint, a structural re-read can identify the route forward. Write to info@oboluslaw.com. Map your options

Five Application Mistakes Established Operators Make

Established operators fail licensing applications for reasons that are structurally different from those that trip up first-time applicants. The following are the most frequently encountered failure modes in our practice.

The first is treating the AML programme as a document rather than a system. Regulators expect to see an AML/CFT framework that is embedded in the operator's technical and operational architecture — not a policy document that was drafted for the application. An established operator with transaction history can demonstrate this. An established operator that cannot demonstrate it has a material problem.

The second is misaligned entity structure. Submitting an application from a holding company with no operational substance, or from an entity whose directors and controllers are not acceptable to the target regulator, is a common cause of rejection or extended delay. The entity that applies must be the entity that will actually conduct the licensed activity, with the governance the regulator expects in place before submission.

The third is inadequate systems disclosure. Regulators in the leading hubs — VARA, MAS, the SFC in Hong Kong — apply detailed scrutiny to the technical systems the operator uses for custody, matching, settlement and surveillance. An established operator must be prepared to describe those systems at a level of specificity that most compliance teams are not accustomed to producing for a regulatory audience.

The fourth is underestimating the timeline. Application timelines across the flagship regimes vary — the specific duration in any given jurisdiction depends on the regulator's current queue, the completeness of the application and the pace of information-request responses. Operators who assume a short timeline and restructure their user-facing business around an expected licence date create operational risk when the process extends beyond that date.

The fifth is failing to align the licensing process with the tax and structuring workstream. A CASP authorisation in an EU member state, a VARA licence in Dubai and a Singapore DPT licence each create a taxable presence, a transfer-pricing obligation and, potentially, a permanent establishment in the relevant jurisdiction. Managing those consequences requires that the licensing process and the tax-structuring process run in parallel, not sequentially.

Decision Matrix: Which Licence Strategy Fits Which Operator Profile

Not every established operator faces the same licensing question. The right strategy depends on the operator's existing entity structure, its primary user base and its service offering. The following profiles illustrate how we approach the analysis.

Profile A — The EU-focused exchange with existing users and no MiCA authorisation. The immediate priority is selecting a member-state NCA and initiating the CASP authorisation process under MiCA. The entity structuring question — new subsidiary versus adaptation of an existing entity — must be resolved first. The timeline to authorisation varies by member state and application completeness; the process is measured in months, not weeks, and the earlier it begins the lower the transitional risk to the existing user book.

Profile B — The multi-product operator with a DIFC or Cayman entity serving global retail. This operator is typically not covered by an EU or UAE mainland authorisation and may face licensing requirements in multiple jurisdictions simultaneously. The priority is a multi-regime gap analysis: mapping the user book by jurisdiction, identifying which jurisdictions have reached an enforcement threshold and sequencing the applications accordingly. An allied-counsel network is essential here; no single filing jurisdiction covers the global exposure.

Profile C — The institutional-only platform seeking a flagship authorisation for counterparty confidence. For an operator serving only institutional or professional counterparties, the licensing objective is as much reputational as it is regulatory. ADGM/FSRA, MAS and the SFC are the most commonly sought authorisations for this profile, as they carry the greatest weight in institutional due-diligence processes. The application process for each is substantive and demanding; the regulator's expectation of governance maturity is high.

In each profile, the decision matrix includes the entity question, the capital question, the banking question and the timeline question. We map all four before recommending a filing jurisdiction or sequence.

In Practice: Remediation Across Two Regimes

In a recent engagement, a mid-size exchange operating across European and Gulf markets retained OBOLUS after its primary banking partner initiated a de-risking review tied to the operator's incomplete licensing status. The operator held a legacy registration in one EU member state that predated the MiCA transition and an informal tolerance arrangement in a second market. Neither position was defensible under the incoming regulatory standard. We conducted a full activity-map across the entity structure, identified the two filing jurisdictions that would resolve the greatest regulatory exposure most efficiently and coordinated the pre-application submissions in parallel. The banking relationship was stabilised during the process through a structured regulatory-disclosure letter prepared for the bank's compliance team. The operator entered the formal application process with a clean entity structure and a coordinated timeline across both regimes. The outcome was a resolved banking risk and a defined path to dual authorisation.

Self-Assessment: Is Your VASP Licence Stack Complete?

Before committing to an application process, an established operator should work through the following questions.

First: in which jurisdictions do you currently have users, and does each of those jurisdictions have a VASP or equivalent licensing requirement for the activities you conduct? Second: does your current regulatory status — registration, authorisation, exemption or transitional tolerance — cover those activities in each relevant market? Third: does your applicant entity have the operational substance, governance and capital position the target regulator expects? Fourth: is your AML programme documented, embedded in your technical systems and capable of surviving regulatory scrutiny? Fifth: have you mapped the interaction between the licensing process and your banking relationships, tax structure and transfer-pricing obligations?

A "no" or "uncertain" answer to any of these questions indicates an exposure that should be addressed before, not after, the next regulatory interaction.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timelines vary materially by jurisdiction, regulator workload and application quality. In the leading hubs — including EU member states under MiCA, VARA in Dubai and MAS in Singapore — the process is typically measured in months from a complete submission. Applications that are incomplete or require significant remediation extend that timeline. Pre-application engagement with the regulator and thorough document preparation are the most reliable means of reducing the review period.

Which jurisdiction is best for licensing my crypto business?

There is no single answer. The right jurisdiction depends on your user base, service offering, entity structure and banking requirements. An EU CASP authorisation under MiCA offers passporting across the bloc. VARA in Dubai suits operators with Gulf and international institutional clients. MAS in Singapore is widely respected for Asia-Pacific market access. The correct answer requires a multi-axis analysis across regulatory cost, banking access, tax treatment and operational substance obligations.

Do I need a separate custody licence?

In most flagship regimes, custody of virtual assets is a separately regulated activity. Under MiCA, custody and administration of crypto-assets for third parties is a distinct CASP service requiring specific authorisation. VARA treats custody as a separately licensed activity category. An operator that holds client assets as part of a broader service offering typically needs authorisation for the custody component, not only for the exchange or transfer activity. This should be assessed at the entity-mapping stage.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions. We map the licence, banking and tax stack across operating, custody and payment layers before you commit — identifying the exposures and sequencing the filings that protect the business. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums where recovery is required alongside licensing remediation. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst — specialist in multi-regime VASP authorisation strategy and entity structuring for established digital-asset operators.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours