[codicts-css-switcher id=”346″]

Global Law Experts Logo
gibraltar dlt licence

Talk with Our Expert

Jonathon Richards

Global Law Experts

Lead Enquiries Qualification
Delete Article

Gibraltar DLT Licence Complete How‑to Guide for GFSC Authorisation

By Jonathon Richards
– posted 4 hours ago

If you are planning to launch or relocate a blockchain-based business, obtaining a Gibraltar DLT licence from the Gibraltar Financial Services Commission (GFSC) remains one of the most credible paths to regulated status in a jurisdiction purpose-built for distributed ledger technology. This guide provides a regulator-first, practitioner-practical walkthrough of the entire authorisation process from the initial pre-application engagement through to post-licence compliance. It is designed for startup founders, in-house legal and compliance officers, and advisers who need an end-to-end reference covering realistic timelines, fees, document checklists, eligibility rules and the GFSC’s regulatory principles. Every factual claim is grounded in official GFSC guidance and Gibraltar legislation. Whether your project involves a custody platform, a token exchange, or a transfer-of-value service built on DLT, the structured steps and scenario-based timelines below will help you plan with confidence.

Quick At-a-Glance Summary

Key Metrics at a Glance

  • Who this guide is for: Founders, compliance officers and legal advisers preparing a DLT provider application to the GFSC.
  • Expected outcome: Full authorisation as a DLT provider under the Financial Services (Distributed Ledger Technology Providers) Regulations.
  • Estimated timeline: 9–18 months for most applicants (longer for complex or high-risk models).
  • GFSC application and annual fees: Published in the GFSC’s fees schedule; third-party costs (legal, audit, security testing) add significantly to total outlay.
  • Essential checklists: A documents checklist, sample organisational chart and staged-submission roadmap are provided below.

GFSC Staged Application Approach and Regulatory Framework

What “Staged Application” and Pre-Application Engagement Mean

The GFSC does not expect applicants to submit a single, monolithic application pack. Instead, it operates a staged application approach in which prospective DLT providers engage with the regulator early often months before a formal application is filed. During the pre-application phase, the GFSC reviews the applicant’s business model, asks targeted questions about technology architecture and governance, and provides directional feedback. This iterative process is designed to reduce the risk of a late-stage refusal and to allow applicants to build their compliance infrastructure in parallel with the regulatory review. Industry observers note that firms which engage proactively and respond quickly to GFSC queries tend to compress their overall timeline considerably.

Legislation and Statutory Basis DLT Regulations and Recent Amendments

Gibraltar’s DLT framework is anchored in the Financial Services (Distributed Ledger Technology Providers) Regulations, first enacted in 2018 under the Financial Services Act 2019. These regulations introduced a set of regulatory principles (commonly referred to as the “nine principles”) against which every applicant is assessed. The framework has been refined over time; the 2025 amendment regulations updated certain statutory obligations and definitions to reflect evolving market practices including enhanced expectations around market integrity. Applicants should always review the latest version of the regulations and any accompanying GFSC guidance notes to ensure full alignment before submitting materials.

Process Step-by-Step How to Obtain a Gibraltar DLT Licence

The Gibraltar crypto licence process follows a staged approach. While the exact sequencing may vary depending on the complexity of the proposed business model, the following nine steps represent the typical pathway from first contact to authorisation.

  1. Pre-application engagement. Contact the GFSC to arrange an initial meeting or call. Prepare a concise overview of your business model, target market, token or asset type, proposed technology stack, and corporate structure. The GFSC’s DLT providers page outlines expectations for this stage. The purpose is to establish whether your activity falls within the scope of the DLT Regulations and to receive early directional feedback. An effective pre-application pack typically runs to 10–20 pages and includes a draft organisational chart.
  2. Stage 1 initial business model and materials. Following the pre-application meeting, submit a more detailed business plan covering revenue model, customer onboarding flow, jurisdictional scope, and a preliminary risk assessment. The GFSC will review and may request clarifications or a revised model. Expect written feedback within four to eight weeks of a complete Stage 1 submission. The regulator uses this phase to flag any structural issues early for example, whether the applicant needs to establish a local entity or appoint additional key personnel.
  3. Stage 2 technical and AML/CFT documentation. This is the most documentation-intensive stage. Prepare and submit your AML/CFT policies (including customer due diligence procedures, transaction monitoring rules, and suspicious activity reporting protocols), technology architecture documentation, data-protection impact assessments, business-continuity plans, and cybersecurity policies. Include evidence of penetration testing, SOC 2 or ISMS certifications (where available), and a detailed description of custody or wallet-management arrangements if applicable.
  4. Stage 3 full operational readiness evidence. Demonstrate that personnel have been appointed (or identified), office space secured, IT systems tested, and audit trails operational. Submit proof of senior management appointments (with fit-and-proper evidence), an executed engagement letter with auditors, and evidence of adequate financial resources. For custody-offering firms, provide a walk-through of key generation, storage, and recovery procedures.
  5. Submission of the formal application and statutory documents. Once the GFSC is satisfied that the staged submissions are substantively complete, submit the formal application alongside corporate constitutional documents (certificate of incorporation, memorandum and articles, register of directors and shareholders), completed personal questionnaires for all key individuals, a capital statement, and confirmation of professional indemnity insurance arrangements where required.
  6. GFSC review, follow-up, and due diligence. The GFSC conducts its own due diligence including background checks on key persons and, potentially, on-site or virtual inspections of technology infrastructure. Anticipate one or more rounds of written questions. Complex token models (e.g., hybrid utility/security tokens, cross-chain bridges) typically trigger deeper technical review. Responsiveness to queries is one of the most significant factors in determining overall timeline.
  7. Approval, licensing conditions, and registration. On successful completion of the review, the GFSC grants a DLT provider licence, which may be subject to specific conditions (for example, restrictions on asset types, geographic scope, or customer segments). The firm is added to the GFSC’s public register of authorised DLT providers. Post-licence requirements including ongoing reporting, AML supervision, and annual fee obligations take immediate effect.
  8. Decision points for complex token models. Applicants operating across multiple verticals (custody, exchange, transfer-of-value) or using novel consensus mechanisms should expect the GFSC to involve specialist technical reviewers. It is advisable to prepare a dedicated technical exhibit including architecture diagrams, threat models, and disaster-recovery runbooks at Stage 2 to pre-empt queries. For cross-jurisdictional models, address regulatory perimeter issues early by mapping the activities that fall within and outside Gibraltar’s DLT Regulations.
  9. Practical post-submission checklist. While the GFSC reviews your application, use the waiting period productively: finalise staff onboarding and training; complete remaining IT and security testing; run a tabletop AML exercise; engage local auditors and complete the first financial-reporting dry-run; and brief the board on post-licence supervisory expectations. Maintaining an internal project tracker with clear ownership and deadlines is essential.

What success looks like: A completed Gibraltar DLT licence application results in a formal authorisation letter, inclusion on the GFSC register, and a clear set of ongoing obligations. The firm can then lawfully carry on DLT provider activities from Gibraltar.

The GFSC’s Regulatory Principles for DLT Providers Practical Explanation

The Nine Principles

The DLT Regulations set out nine regulatory principles that every applicant must demonstrate compliance with. Each principle translates into specific evidence requirements during the application:

  1. Honesty and integrity. Demonstrate that the business and its key persons conduct affairs with honesty and integrity evidenced through personal questionnaires, references, and criminal-record checks.
  2. Customer care. Show that customers’ interests are properly considered through transparent terms of service, complaints-handling procedures, and clear fee disclosure.
  3. Adequate financial and non-financial resources. Provide capital statements, audited accounts (where available), and evidence of staffing adequate to the scale and complexity of operations.
  4. Risk management. Submit a comprehensive risk-assessment framework covering operational, financial, technology, and regulatory risks.
  5. Protection of client assets. Evidence segregation of client and firm assets, custody procedures, and insurance or bonding arrangements.
  6. Corporate governance. Demonstrate a clear governance structure with appropriate board composition, committee structures, and reporting lines.
  7. Systems and security access. Provide architecture documentation, penetration-test results, access-control policies, and incident-response plans.
  8. Financial crime prevention. Submit AML/CFT policies, MLRO appointment evidence, transaction-monitoring rules, and sanctions-screening procedures.
  9. Resilience. Evidence business-continuity and disaster-recovery plans, including tested failover procedures for critical technology systems.

Note on the Market-Integrity Amendment

The GFSC has supplemented the original nine principles with additional expectations around market integrity, including guidance on the prevention of market abuse and insider dealing in DLT-related activities. Applicants should review the latest GFSC guidance notes and the 2025 amendment regulations to ensure their compliance frameworks address these evolving expectations.

Key Requirements and Eligibility Who Can Apply

Eligible Activities Under the DLT Regulations

The Gibraltar DLT licence is required for any firm that, by way of business, uses distributed ledger technology for storing or transmitting value belonging to others. This captures a wide range of activities including cryptocurrency exchanges, custodial wallet providers, DLT-based payment processors, and platforms that facilitate the transfer of digital assets. Activities that do not involve the storage or transmission of value belonging to others generally fall outside scope, though borderline cases should be discussed with the GFSC during pre-application engagement.

Local Presence and Corporate Form

An overseas company can apply for a Gibraltar DLT licence, but it must establish a meaningful local presence. This can be achieved through incorporating a Gibraltar company or registering a branch. In practice, the GFSC expects local management and control including at least one Gibraltar-resident director and locally based compliance functions. Documentation requirements include a certificate of incorporation or branch registration, a registered office address, and evidence of local substance (office lease, staff contracts).

Fit and Proper Persons, Senior Management, and AML Officer

All directors, beneficial owners, and senior managers must satisfy the GFSC’s fit-and-proper criteria, evidenced through personal questionnaires, references, and background checks. The appointment of a Money Laundering Reporting Officer (MLRO) is mandatory. The MLRO must be suitably qualified, experienced in AML/CFT compliance, and based locally or readily accessible to the GFSC.

Minimum Capital and Prudential Expectations

While the DLT Regulations do not prescribe a single minimum-capital figure applicable to all applicants, the GFSC assesses financial-resource adequacy on a case-by-case basis, taking into account the nature, scale, and complexity of the proposed business. Applicants should refer to the GFSC’s published guidance and fee schedules for further detail on prudential expectations.

Realistic Timelines Scenario-Based Guidance

Scenario A Straightforward Market-Entry or Custody-Light Provider

Estimated DLT licence application timeline: approximately 9 months. Pre-application engagement: 1–2 months. Staged submission (Stages 1–3): 3–4 months. GFSC review, queries, and final approval: 3–4 months. This scenario assumes the applicant has a well-defined business model, limited custodial activity, an experienced compliance team, and responds promptly to regulator queries.

Scenario B Technically Complex or Custody/Exchange Provider

Estimated timeline: 12–18 months. Complex technology stacks, multi-asset custody solutions, or exchange models with orderbook matching typically trigger deeper technical review by the GFSC and may require additional penetration testing or independent security audits. Allow an additional 3–6 months beyond the straightforward scenario.

Scenario C High-Risk Token Models or Cross-Jurisdictional Complications

Estimated timeline: 15–24 months. Projects involving novel token structures (e.g., algorithmic stablecoins, cross-chain interoperability layers) or with significant cross-border regulatory considerations may face extended review periods. The GFSC may engage with overseas regulators or require additional legal opinions on regulatory-perimeter questions.

Tips to shorten timelines: Submit complete and well-organised documentation at every stage. Appoint a dedicated project owner to manage regulator communications. Engage AML counsel and technical auditors early ideally in parallel with Stage 1 submissions. Respond to GFSC queries within two weeks wherever possible.

Fees and Realistic Cost Ranges

GFSC Application Fees and Annual Regulatory Fees

The GFSC publishes its fee schedule annually. Application fees and ongoing annual regulatory fees for DLT providers are detailed in the GFSC Fees Newsletter 2025/2026. Applicants should review this document for the current fee bands, which vary depending on the nature and scale of the proposed activity. Annual fees are subject to review by the GFSC in consultation with HM Government of Gibraltar.

Typical Third-Party Costs

Beyond GFSC fees, applicants should budget for significant third-party costs. These typically include:

  • Legal advisory fees: Engagement of a Gibraltar law firm for application preparation, policy drafting, and GFSC liaison estimated at £30,000–£80,000+ depending on complexity.
  • Technical audit and penetration testing: Independent security assessments estimated at £10,000–£40,000.
  • AML/compliance consultancy: Policy development, MLRO training, and transaction-monitoring setup estimated at £10,000–£30,000.
  • Company formation and local substance: Incorporation, registered office, resident director services estimated at £5,000–£20,000 per annum.

These are market estimates and will vary based on the applicant’s existing infrastructure and the complexity of the proposed DLT activities.

Ongoing Supervisory Fees

Authorised DLT providers are subject to ongoing supervisory fees, including annual regulatory fees and AML supervision charges. HM Government of Gibraltar has approved changes to the GFSC’s annual fee structure; applicants should consult the latest published rates and any trade-activity fee caps that may apply.

Documents Checklist

The following checklist covers the core documents typically required for a Gibraltar DLT licence application. Applicants should confirm the latest requirements with the GFSC’s downloads hub, which publishes application forms and guidance notes.

  • Certificate of incorporation (or branch registration certificate)
  • Memorandum and articles of association (constitutional documents)
  • Register of directors and shareholders
  • Completed personal questionnaires for all key individuals
  • Business plan including revenue model, target market, and growth projections
  • Organisational chart showing reporting lines, key functions, and outsourced roles
  • AML/CFT policies and procedures CDD, EDD, transaction monitoring, SAR reporting
  • MLRO appointment letter and CV
  • Technology architecture documentation systems diagrams, data-flow maps
  • Penetration test reports (recent, from an independent provider)
  • SOC 2 or ISMS certification evidence (if available)
  • Capital statement and proof of financial resources
  • Auditors’ engagement letter
  • Risk assessment framework
  • Business-continuity and disaster-recovery plans
  • Professional indemnity insurance details (where applicable)

Download: GFSC DLT licence documents checklist (PDF) available for download from the asset library accompanying this page.

Organisational Charts and Sample Local Management Structures

The GFSC expects clear governance and reporting structures. Below are two common models:

  • Sample A Small trading or custody-light provider: CEO (Gibraltar-resident), Head of Compliance / MLRO, Chief Technology Officer, Head of Operations. Four to five key persons; flat structure with direct board reporting.
  • Sample B Larger multi-product DLT provider: Board of Directors, CEO, Local Director (Gibraltar-resident), MLRO, Head of Risk, Head of Information Security, Head of Finance, Chief Technology Officer. Committee structure (Risk Committee, Audit Committee) reporting to the Board.

Sample organisational chart diagrams (SVG/image files) are available as downloadable assets alongside this guide.

Common Application Pitfalls and How to Avoid Them

  • Incomplete AML/CFT evidence: Policies exist on paper but lack transaction-monitoring rule sets, escalation matrices, or SAR templates. Fix: Run a mock AML audit before submission.
  • Underspecified technical architecture: Generic diagrams without data-flow detail or custody key-management descriptions. Fix: Commission an independent technical review early.
  • Insufficient senior personnel proof: Key persons appointed in principle but without fit-and-proper evidence or executed contracts. Fix: Complete personal questionnaires and background checks before Stage 3.
  • Weak corporate governance: No board minutes, no committee terms of reference, unclear reporting lines. Fix: Draft and adopt governance documents at incorporation.
  • Poor responsiveness to GFSC queries: Delays in responding to regulator questions are the single most common cause of timeline overruns. Fix: Designate a single point of contact and commit to two-week response windows.

Comparison Table Gibraltar DLT Licence vs Alternative Options

Feature Gibraltar (GFSC DLT Licence) Malta (VFA Framework) UK (FCA Registration)
Regulatory approach DLT-specific; principles-based staged application Activity-specific; VFA Agent required AML registration (not full licensing for most crypto activities)
Typical timeline 9–18 months 6–18 months 6–12+ months (registration backlogs reported)
Pre-application engagement Structured, encouraged by regulator Available but less formalised Limited formal pre-application process
DLT-specific framework Yes purpose-built since 2018 Yes VFA Act 2018 No dedicated DLT regime (evolving under FCA)
Key strength Regulatory clarity; targeted DLT principles Comprehensive token classification Access to UK/global market; established regulator

Note: This comparison addresses licensing and regulatory features only. It does not constitute advice on tax, residency, or passporting arrangements.

Sources

FAQs

How long does a Gibraltar DLT licence application take?
Most applications take between 9 and 18 months from first pre-application engagement to formal authorisation, depending on complexity and the applicant’s responsiveness. Custody-heavy or exchange models typically fall at the longer end of the range. The GFSC’s staged approach is designed to manage this timeline efficiently.
Core documents include corporate constitutional documents, a detailed business plan, AML/CFT policies, MLRO appointment evidence, technology architecture documentation, penetration-test reports, capital statements, and an organisational chart. The full checklist is outlined above and the GFSC publishes application forms and guidance on its downloads page.
GFSC application and annual regulatory fees are published in the GFSC Fees Newsletter. Total project costs — including legal, technical audit, AML consultancy, and company-formation expenses — typically range from £60,000 to £170,000 or more, depending on the scope and complexity of the application.
The GFSC assesses applicants against nine regulatory principles covering honesty and integrity, customer care, financial resources, risk management, client-asset protection, corporate governance, systems and security, financial-crime prevention, and resilience. Additional market-integrity guidance supplements these principles.
Yes. An overseas company can apply by incorporating a local Gibraltar entity or registering a branch. The GFSC requires meaningful local substance — including at least one Gibraltar-resident director and locally accessible compliance functions. Registration guidance is available on the GFSC registrations page.
The GFSC reviews the applicant’s initial business-model summary, asks targeted questions about technology and governance, and provides early directional feedback. This phase typically lasts one to two months and is designed to identify structural issues before the formal staged submission begins.

Our Expert

Jonathon Richards

Global Law Experts

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Join
who are already getting the benefits
0

Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.

Naturally you can unsubscribe at any time.

About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Global Law Experts App

Now Available on the App & Google Play Stores.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Contact Us

Stay Informed

Join Mailing List
About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Global Law Experts App

Now Available on the App & Google Play Stores.

Contact Us

Stay Informed

GLE

Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Gibraltar DLT Licence Complete How‑to Guide for GFSC Authorisation

Send welcome message

Custom Message