[codicts-css-switcher id=”346″]

Global Law Experts Logo
crypto custody licensing

Talk with Our Expert

Legal professional smiling at desk with a globe and legal-themed decor in modern office setting.

Jonathon Richards

Global Law Experts

Lead Enquiries Qualification
Delete Article

Crypto Custody Licensing: a Global Guide for Custodians and Service Providers

By Jonathon Richards
– posted 2 hours ago

Crypto custody licensing has become one of the most consequential regulatory workstreams for any organisation that safeguards digital assets on behalf of clients in 2026. As harmonised frameworks such as the EU’s Markets in Crypto-Assets Regulation (MiCA) take full effect and regimes in Dubai, Singapore, Hong Kong and the United States tighten their approach to digital asset custodian regulation, custodians face a rapidly shifting compliance landscape. This guide sets out, in practical terms, what a crypto custody licence entails, who needs one, and how to secure and maintain authorisation across the world’s leading jurisdictions.

Illustration: Global Map With Vaults And Digital Assets Representing Cross-Jurisdiction Crypto Custody Licensing

Introduction, What “crypto custody licensing” means in 2026

Crypto custody licensing refers to the authorisation a business must obtain before it can hold, control or safeguard digital assets, private keys, tokens and related instruments, on behalf of third parties. In 2026, this is no longer a niche question. Regulators now treat custody as a distinct, high-risk activity with its own safeguarding, prudential and operational-resilience expectations, separate from trading or exchange functions. The result is a matrix of overlapping regimes that a serious custodian must navigate with precision.

Why custodians need to act now

The 2024–2026 period brought a wave of rule changes. MiCA’s provisions for crypto-asset service providers, including custody and administration of crypto-assets on behalf of clients, became directly applicable across the EU, driving post-MiCA harmonisation and a passportable licence. Dubai’s Virtual Assets Regulatory Authority (VARA) continued rolling out its activity-based licence classes, the Monetary Authority of Singapore (MAS) refined safeguarding expectations for digital payment token service providers, Hong Kong’s Securities and Futures Commission (SFC) advanced custody-focused consultations, and New York’s regulator maintained intense scrutiny of trust charters and BitLicence holders. Custodians who delay risk being locked out of key markets or forced into expensive retrofits.

Who this guide is for

This guide is written for C-suite executives, compliance officers, fintech founders and in-house counsel who need actionable, jurisdictionally specific guidance on crypto custody licensing. Whether you are a start-up custodian, an established financial institution adding digital asset custody, or an exchange separating its custody function, the following sections provide a step-by-step path and a comparative view of the leading regimes.

How to obtain a crypto custody licence, step-by-step process for custodians

Securing a crypto custody licence is a structured, evidence-heavy process. The steps below apply broadly across jurisdictions, though the emphasis and thresholds differ. Treat this as a project plan: each step generates artefacts, policies, financials, technical evidence, that feed directly into your application pack.

Step 1, Define your business model and activities

Before engaging any regulator, articulate precisely what you will do. Custody is not monolithic. Consider the following activity types, as they determine which permissions you need:

  • Cold storage: offline safekeeping of private keys, generally the lowest-risk model but with operational trade-offs.
  • Hot wallets: online custody enabling faster settlement but requiring stronger key-management and insurance controls.
  • Custodial staking: holding assets that participate in proof-of-stake networks, which raises questions about client asset control and rewards.
  • Nominee and omnibus custody: holding assets in the custodian’s name on behalf of clients, with segregation and record-keeping implications.

Your activity definition drives everything downstream, the licence class, capital, safeguarding model and technical baseline.

Step 2, Map jurisdictions and passporting options

Identify where your clients are and where you must be authorised. Under MiCA, a custody authorisation obtained in one EU member state can be passported across the bloc, materially reducing the cost of pan-European access. Outside the EU, each of VARA (Dubai), MAS (Singapore), the SFC (Hong Kong) and US state and federal regulators requires separate authorisation. Build a jurisdiction map that ranks markets by commercial priority, regulatory complexity and available passporting or mutual-recognition routes.

Step 3, Build corporate, governance and compliance frameworks

Regulators expect a substantive corporate presence and a mature governance structure. Establish a board with relevant expertise, appoint qualified compliance and risk officers, and document your KYC/AML and counter-terrorist-financing (CFT) programmes in line with the FATF guidance on virtual assets and VASPs. Complaints handling, conflicts management, outsourcing policies and supervisory reporting frameworks must all be in place before you file.

Step 4, Prepare safeguarding and capital plans

Safeguarding is the heart of crypto custody licensing. Document how client assets are segregated from firm assets, how you will maintain proof-of-reserves, and what insurance coverage protects against loss or theft. Build a capital plan that meets the minimum net-worth thresholds of each target jurisdiction and demonstrates ongoing solvency under stress scenarios.

Step 5, Technical and security baseline

Custody is ultimately a security discipline. Establish key-management infrastructure, hardware security modules (HSMs), multi-party computation (MPC) or a combination, and secure independent assurance such as SOC 2 Type II or ISO/IEC 27001 certification. Regulators increasingly ask for evidence of these controls as part of the fitness assessment.

Step 6, Compile the application pack

The application pack typically includes completed regulator forms, a detailed business plan, all policies and procedures, audited financial statements or projections, and fitness-and-propriety evidence for directors, controllers and key persons. Incomplete packs are the most common cause of delay, so treat completeness as a gating criterion before submission.

Step 7, Engage local counsel and regulator liaison

Local counsel translate your model into the regulator’s language, anticipate queries and manage the consent process. Expect iterative rounds of questions, on capital, safeguarding ratios, key-person suitability and technology, and resource a dedicated team to respond quickly and consistently. Proactive, transparent engagement materially shortens timelines.

Step 8, Post-authorisation obligations and supervisory reporting

Authorisation is the beginning, not the end. Ongoing obligations include periodic prudential and safeguarding reporting, notification of material changes, continued fitness assessments, audit and attestation cycles, and incident reporting. Build these into business-as-usual operations from day one to avoid supervisory friction.

Jurisdiction comparison: crypto custody licensing requirements, costs and timelines

The table below summarises the leading crypto custody licensing regimes. Figures are indicative ranges drawn from official regulator materials and should be verified against the primary source for each jurisdiction before you file, as fees and thresholds are periodically revised.

Comparison table: MiCA vs VARA vs MAS vs Hong Kong SFC vs US

Jurisdiction Licensing route Safeguarding (segregation/insurance) Minimum capital / net worth Typical timeline Indicative cost bracket
EU (MiCA) CASP authorisation for custody and administration of crypto-assets; passportable across the EU Segregation of client assets; liability for loss; operational controls Tiered own-funds requirement based on service class Approx. 3–6+ months Mid-to-high six figures (application, capital, ongoing)
UAE (VARA, Dubai) Activity-based Virtual Asset Custody Services licence Robust custody controls, segregation and record-keeping; local presence expected Category-specific paid-up capital thresholds Approx. 4–9 months High six figures including local establishment
Singapore (MAS) Payment Services Act licence covering digital payment token services / custody Safeguarding of customer assets, techno-security and insurance expectations Base capital and financial soundness thresholds Approx. 6–12+ months High six figures
Hong Kong (SFC) Custody licensing under proposed / consulted framework; VATP-linked custody Strong investor-protection and segregation focus per consultations Thresholds to be confirmed via final rules Subject to final framework To be confirmed; expect substantial spend
US (New York) NY Trust charter and/or BitLicence via NYDFS Segregation, insurance and cybersecurity expectations Capital determined case-by-case by NYDFS Approx. 6–18+ months High six to seven figures

Key takeaways from the table

Three themes emerge. First, MiCA offers the strongest efficiency play through passporting, making a single EU authorisation attractive for pan-European reach. Second, the Gulf and Asian regimes reward genuine local substance, physical presence, local key persons and jurisdiction-specific controls, over box-ticking. Third, the US remains the most fragmented and time-intensive market, where the NY Trust charter and BitLicence sit within a broader federal overlay. Budget and timeline planning should assume the longest, most demanding jurisdiction in your rollout, not the shortest.

Key requirements and eligibility for crypto custody licensing

Across regimes, regulators converge on a common set of eligibility criteria for custodians. Understanding these before you apply prevents costly missteps.

Corporate and ownership requirements

Regulators scrutinise legal structure, ownership and control. Expect requirements around a locally incorporated entity, transparent beneficial ownership, and clear group structures. Controllers and significant shareholders are typically subject to their own suitability review, and opaque or highly leveraged ownership chains are a red flag.

Management and fit-and-proper standards

Directors, senior managers and key function holders must pass fit-and-proper tests covering honesty, integrity, competence and financial soundness. For custody specifically, regulators want to see demonstrable experience in security, risk and regulated financial services. Weak or thin management teams are among the most common reasons applications stall.

Financial and prudential thresholds

Minimum capital and ongoing own-funds requirements ensure a custodian can absorb operational losses and wind down in an orderly way. Under MiCA, own-funds requirements are tiered by service class; other jurisdictions set base capital thresholds and expect evidence of ongoing solvency. Capital planning must account not only for the entry threshold but for buffers that satisfy supervisors over time.

Operational resilience and custody-specific controls

Because custody is a technology-intensive activity, regulators demand robust operational resilience: business continuity, disaster recovery, incident response, and controls over key generation, storage and use. The concept of a “qualified custodian”, an entity that meets a defined standard of regulatory oversight and asset protection, features across several regimes, though its precise definition varies significantly by jurisdiction, as discussed in the sections that follow.

MiCA custody requirements (EU), what custodians must expect

MiCA created a harmonised, EU-wide framework for crypto-asset service providers, including those offering custody and administration of crypto-assets on behalf of clients. For custodians targeting Europe, MiCA custody requirements are now the reference point.

Scope (custody wallets, safeguarding, segregation)

Under the MiCA Regulation, custody and administration of crypto-assets is a distinct authorised service. Custodians must hold client assets separately from their own, maintain accurate records and registers of positions, and establish clear custody policies. The regulation also addresses liability for the loss of crypto-assets held in custody, sharpening the commercial importance of insurance and safeguarding.

Prudential and governance highlights

MiCA imposes tiered own-funds requirements calibrated to the services provided, alongside governance, conflicts-of-interest and operational-resilience obligations. Custodians must demonstrate sound administrative arrangements, secure IT systems and effective control functions. These prudential and governance highlights make MiCA one of the more comprehensive crypto custody licensing frameworks globally.

Passporting and supervisory structure

A key advantage of MiCA is passporting: once authorised in one member state, a custodian can provide services across the EU under a notification procedure, subject to home-state supervision with host-state cooperation. This single-market access is a decisive factor for firms weighing where to establish their European custody hub.

VARA custodian licence (UAE, Dubai), 2024–2026 roll-out

Dubai’s VARA has established itself as a leading Gulf regime for digital assets, with an activity-based licensing model that treats custody as a discrete category.

Licence classes and acceptable activities

Under the VARA regulatory framework, custody is licensed as a specific virtual asset service, with rulebooks setting out permitted activities, conduct expectations and safeguarding standards. Applicants must map their intended activities precisely to VARA’s categories, as the licence granted governs exactly what the custodian may do and how it must operate.

Safeguarding and local presence requirements

VARA emphasises genuine local substance. Expect requirements around a Dubai-established entity, qualified local personnel, robust segregation of client assets, and detailed technology and security controls. The 2024–2026 roll-out has consistently reinforced that a VARA custodian licence rewards operational maturity and demonstrable safeguarding capability over minimal-footprint applications.

MAS crypto custody requirements (Singapore)

Singapore remains a strategically important custody hub, with MAS crypto custody requirements sitting within its broader payment services regime.

Licensing framework for payment token services and custody

Custody activities relating to digital payment tokens fall within the licensing perimeter administered by the Monetary Authority of Singapore. Applicants must satisfy base capital and financial-soundness criteria, demonstrate competent management, and operate comprehensive AML/CFT controls consistent with international standards.

Safeguarding, insurance and techno-security expectations

MAS has progressively refined its safeguarding expectations, focusing on the protection of customer assets, segregation, and techno-security. Custodians should expect scrutiny of key-management arrangements, technology risk management and the resilience of their custody infrastructure. Building an application that anticipates these expectations is central to a successful MAS crypto custody licensing outcome.

Hong Kong SFC custody proposals and status

Hong Kong has moved decisively toward a comprehensive virtual asset regime, with custody a central pillar of the SFC’s approach.

SFC consultation highlights

The Securities and Futures Commission has issued consultation materials addressing custody licensing and investor protection, reflecting a focus on segregation of client assets, robust custody controls and clear accountability. These proposals signal that custody in Hong Kong will be a distinctly regulated activity with strong safeguarding obligations.

Expected timelines and implications for custodians

As the framework moves from consultation to implementation, custodians should track final rules closely, since thresholds and timelines will crystallise only when the SFC finalises its approach. Industry observers expect that firms which prepare governance and safeguarding documentation early will be best positioned when the licensing window opens. Early engagement is a prudent posture for any custodian targeting the Hong Kong market.

US state vs federal landscape, NY Trust, BitLicense and federal overlays

The United States presents the most complex crypto custody licensing landscape, defined by the interplay of state-level regimes and federal oversight.

New York Trust charter vs BitLicense, which custodians need which

New York, through NYDFS, operates two principal routes. A BitLicence applies to certain virtual currency business activities involving New York or New York residents, while a limited-purpose trust company charter allows an entity to act as a fiduciary custodian. Many institutional custodians pursue the NY Trust charter precisely because it confers “qualified custodian”-style standing and fiduciary powers. Which route fits depends on your activities, client base and whether you need fiduciary capacity, a decision best taken with counsel.

Federal overlay, FinCEN, SEC, OCC expectations

Above the state layer sits a federal overlay. Custodians handling money transmission must consider FinCEN registration and AML obligations; those custodying assets that may be securities must weigh SEC expectations; and nationally chartered institutions engage with the OCC. This multi-regulator environment makes early legal analysis of asset classification and activity scope essential.

Cross-state considerations and preemption risks

Because money transmission and custody are largely regulated state-by-state, a custodian serving a national US client base may need multiple state licences in addition to its home charter. Preemption is not comprehensive, so custodians must map each state’s requirements or restrict their footprint accordingly. This fragmentation is the single largest driver of cost and time in US crypto custody licensing.

Safeguarding and capital rules playbook for crypto custody licensing

Safeguarding and capital are the twin pillars regulators examine most closely. This playbook distils practical approaches that recur across MiCA, VARA, MAS, Hong Kong and the US.

Segregation models (legal segregation vs technological segregation)

Two complementary concepts matter. Legal segregation ensures client assets are ring-fenced from the custodian’s estate so they are protected on insolvency, typically through trust structures, clear account titling and enforceable client agreements. Technological segregation separates keys and holdings at the infrastructure level, using dedicated wallets, address hierarchies and access controls. Robust safeguarding requires both: legal protection that survives insolvency and technical controls that prevent commingling in practice.

Insurance and explicit warranty language

Insurance is increasingly expected rather than optional. Custodians should secure specie or crime cover appropriate to their hot and cold holdings and articulate coverage clearly to clients. Contractual warranty language must accurately describe what is and is not covered, overstating protection creates conduct and liability risk, particularly under MiCA’s liability provisions for lost crypto-assets.

Proof-of-reserves and attestations

Proof-of-reserves has moved from best practice toward baseline expectation. Best-in-class custodians combine cryptographic attestation of holdings with independent audit or agreed-upon-procedures engagements, and publish attestations on a regular cadence. Transparency here supports both regulatory confidence and client trust.

Capital planning approaches across jurisdictions

Because thresholds differ, custodians operating in multiple markets should plan capital at group and entity level. Model the highest applicable threshold, add buffers for supervisory comfort, and stress-test against operational-loss and wind-down scenarios. Treating capital as a dynamic, forward-looking discipline, not a one-off entry ticket, is central to sustainable crypto custody licensing.

Technical and security standards custodians must meet

Technology is where custody risk concentrates, and regulators expect demonstrable, independently assured controls.

Key management (HSMs, MPC)

Key-management architecture is foundational. Hardware security modules and multi-party computation each offer strong protection; many custodians combine them with quorum-based approvals and geographic distribution of key shares to eliminate single points of failure.

Operational resilience (backup, recovery, incident response)

Custodians must maintain tested backup and recovery procedures, documented incident-response playbooks and business-continuity arrangements. The ability to recover keys and resume operations after a disruption is a direct regulatory concern.

Certifications (SOC 2, ISO 27001)

Independent certifications such as SOC 2 Type II and ISO/IEC 27001 provide external assurance that controls operate effectively. Increasingly, these are treated as expected evidence within a crypto custody licensing application rather than a differentiator.

Cross-border licensing strategy and market access

For custodians with international ambitions, licensing strategy is as much a commercial decision as a legal one.

Single-licence vs multi-licence models

A single-licence model, for example, an EU MiCA authorisation with passporting, minimises cost and complexity for a bloc-wide footprint. A multi-licence model is unavoidable where target markets require standalone authorisation, as in the Gulf, Asia and the US. Most global custodians end up with a hybrid: a passported hub plus targeted standalone licences.

Passporting, MOUs, and local agent approaches

Where passporting is unavailable, custodians rely on local establishment, local agents or reliance on regulator memoranda of understanding to smooth supervisory cooperation. Structuring these arrangements correctly avoids inadvertent unlicensed activity in a target market.

Tax, AML and reporting coordination

A multi-jurisdiction footprint multiplies AML, tax and reporting obligations. Coordinate AML programmes to the FATF risk-based standard across entities, align reporting calendars, and manage transfer-pricing and permanent-establishment questions early to avoid downstream surprises.

Typical timelines and cost considerations

Realistic planning depends on candid timeline and budget assumptions, which vary widely across the crypto custody licensing landscape.

Application lead times by jurisdiction

Lead times range broadly. MiCA authorisations may complete in roughly three to six months where applications are complete; VARA and MAS processes commonly run several months to a year; and US routes, particularly a NY Trust charter, can take well over a year. Completeness and responsiveness are the biggest levers on speed.

Indicative spend (application fees, legal, capital, tech)

Total cost comprises regulator fees, legal and advisory fees, minimum capital, technology build and independent assurance. For a multi-jurisdiction launch, custodians should plan for high six-figure and, in the US, potentially seven-figure budgets once capital is included. Ongoing compliance and audit costs must be budgeted year on year.

Practical checklist, immediate next steps for custodians

Use this 10-point checklist to assess licensing readiness (a downloadable one-page cross-jurisdiction checklist is planned as a companion resource):

  • Define activities: document cold storage, hot wallet, staking and nominee models.
  • Map jurisdictions: rank markets and identify passporting options.
  • Confirm licence routes: match each market to its correct licence class.
  • Build governance: appoint qualified board, compliance and risk functions.
  • Draft safeguarding policy: segregation, insurance and proof-of-reserves.
  • Plan capital: meet the highest applicable threshold with buffers.
  • Establish tech baseline: HSM/MPC, backup, incident response.
  • Secure certifications: SOC 2 and ISO 27001 assurance.
  • Compile application pack: forms, financials, fit-and-proper evidence.
  • Engage local counsel: manage regulator liaison and post-authorisation reporting.

Conclusion

Crypto custody licensing in 2026 rewards custodians who treat authorisation as a strategic, evidence-driven programme rather than a compliance afterthought. Across MiCA, VARA, MAS, the Hong Kong SFC and the US, the common threads are clear: rigorous safeguarding, credible capital, mature governance and independently assured technology. By defining activities precisely, mapping jurisdictions intelligently, and building safeguarding and security to the highest applicable standard, custodians can convert a fragmented regulatory landscape into durable, licensed market access.

Sources

FAQs

What is a crypto custody licence and who needs one?
A crypto custody licence authorises a business to hold or safeguard digital assets on behalf of customers. Entities offering third-party safekeeping, hosted wallets, or custodial staking services typically need a licence wherever custody activities are regulated. If you control client private keys or assets, assume authorisation is required and confirm the position with local counsel.
Map your business model, identify licensing routes per jurisdiction, prepare governance, compliance and safeguarding documentation, engage local counsel, and submit applications with audited financials and key-person evidence. Then respond promptly to regulator queries. Consider a coordinated rollout and passporting options, such as MiCA’s EU passport, to reduce cost where available.
Requirements vary. MiCA mandates segregation, liability for lost assets and tiered own-funds; VARA and MAS require robust custody controls and financial thresholds; Hong Kong’s SFC proposals emphasise investor protection; and US regimes such as NYDFS trust charters and the BitLicence impose capital and insurance expectations. See the jurisdiction sections and comparison table for detail.
It depends on your activities and customer location. A New York trust charter is required to operate as a trust company offering fiduciary custody in New York, while a BitLicence can apply to certain virtual currency businesses transacting with New York residents. Many institutional custodians pursue the trust charter for its fiduciary standing; evaluate based on your model with counsel.
“Qualified custodian” definitions differ. Some regimes require regulated trust or banking entities; others permit licensed third-party custodians that meet specified controls. These differences shape permissible custody arrangements and client protections, so the same business model may require different authorisations depending on where clients are located.
Timelines typically range from three to twelve-plus months depending on jurisdiction and application completeness, with US trust charters often taking longer. Costs include regulator fees, legal and advisory fees, minimum capital and technology spend; multi-jurisdiction launches should budget for high six-figure and potentially seven-figure totals once capital is included.
Key developments include full MiCA implementation and harmonisation across the EU, continued VARA licence roll-outs in Dubai, MAS refinements to safeguarding expectations in Singapore, Hong Kong SFC custody consultations, and sustained US scrutiny of NY Trust and BitLicence frameworks. These 2024–2026 rule updates make proactive crypto custody licensing planning essential.

Our Expert

Legal professional smiling at desk with a globe and legal-themed decor in modern office setting.

Jonathon Richards

Global Law Experts

Car Accident Lawyer | Global Law Expert news
By Jonathon Richards

posted 4 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Crypto Custody Licensing: a Global Guide for Custodians and Service Providers

Send welcome message

Custom Message