Crypto custody licensing has become one of the most consequential regulatory workstreams for any organisation that safeguards digital assets on behalf of clients in 2026. As harmonised frameworks such as the EU’s Markets in Crypto-Assets Regulation (MiCA) take full effect and regimes in Dubai, Singapore, Hong Kong and the United States tighten their approach to digital asset custodian regulation, custodians face a rapidly shifting compliance landscape. This guide sets out, in practical terms, what a crypto custody licence entails, who needs one, and how to secure and maintain authorisation across the world’s leading jurisdictions.

Crypto custody licensing refers to the authorisation a business must obtain before it can hold, control or safeguard digital assets, private keys, tokens and related instruments, on behalf of third parties. In 2026, this is no longer a niche question. Regulators now treat custody as a distinct, high-risk activity with its own safeguarding, prudential and operational-resilience expectations, separate from trading or exchange functions. The result is a matrix of overlapping regimes that a serious custodian must navigate with precision.
The 2024–2026 period brought a wave of rule changes. MiCA’s provisions for crypto-asset service providers, including custody and administration of crypto-assets on behalf of clients, became directly applicable across the EU, driving post-MiCA harmonisation and a passportable licence. Dubai’s Virtual Assets Regulatory Authority (VARA) continued rolling out its activity-based licence classes, the Monetary Authority of Singapore (MAS) refined safeguarding expectations for digital payment token service providers, Hong Kong’s Securities and Futures Commission (SFC) advanced custody-focused consultations, and New York’s regulator maintained intense scrutiny of trust charters and BitLicence holders. Custodians who delay risk being locked out of key markets or forced into expensive retrofits.
This guide is written for C-suite executives, compliance officers, fintech founders and in-house counsel who need actionable, jurisdictionally specific guidance on crypto custody licensing. Whether you are a start-up custodian, an established financial institution adding digital asset custody, or an exchange separating its custody function, the following sections provide a step-by-step path and a comparative view of the leading regimes.
Securing a crypto custody licence is a structured, evidence-heavy process. The steps below apply broadly across jurisdictions, though the emphasis and thresholds differ. Treat this as a project plan: each step generates artefacts, policies, financials, technical evidence, that feed directly into your application pack.
Before engaging any regulator, articulate precisely what you will do. Custody is not monolithic. Consider the following activity types, as they determine which permissions you need:
Your activity definition drives everything downstream, the licence class, capital, safeguarding model and technical baseline.
Identify where your clients are and where you must be authorised. Under MiCA, a custody authorisation obtained in one EU member state can be passported across the bloc, materially reducing the cost of pan-European access. Outside the EU, each of VARA (Dubai), MAS (Singapore), the SFC (Hong Kong) and US state and federal regulators requires separate authorisation. Build a jurisdiction map that ranks markets by commercial priority, regulatory complexity and available passporting or mutual-recognition routes.
Regulators expect a substantive corporate presence and a mature governance structure. Establish a board with relevant expertise, appoint qualified compliance and risk officers, and document your KYC/AML and counter-terrorist-financing (CFT) programmes in line with the FATF guidance on virtual assets and VASPs. Complaints handling, conflicts management, outsourcing policies and supervisory reporting frameworks must all be in place before you file.
Safeguarding is the heart of crypto custody licensing. Document how client assets are segregated from firm assets, how you will maintain proof-of-reserves, and what insurance coverage protects against loss or theft. Build a capital plan that meets the minimum net-worth thresholds of each target jurisdiction and demonstrates ongoing solvency under stress scenarios.
Custody is ultimately a security discipline. Establish key-management infrastructure, hardware security modules (HSMs), multi-party computation (MPC) or a combination, and secure independent assurance such as SOC 2 Type II or ISO/IEC 27001 certification. Regulators increasingly ask for evidence of these controls as part of the fitness assessment.
The application pack typically includes completed regulator forms, a detailed business plan, all policies and procedures, audited financial statements or projections, and fitness-and-propriety evidence for directors, controllers and key persons. Incomplete packs are the most common cause of delay, so treat completeness as a gating criterion before submission.
Local counsel translate your model into the regulator’s language, anticipate queries and manage the consent process. Expect iterative rounds of questions, on capital, safeguarding ratios, key-person suitability and technology, and resource a dedicated team to respond quickly and consistently. Proactive, transparent engagement materially shortens timelines.
Authorisation is the beginning, not the end. Ongoing obligations include periodic prudential and safeguarding reporting, notification of material changes, continued fitness assessments, audit and attestation cycles, and incident reporting. Build these into business-as-usual operations from day one to avoid supervisory friction.
The table below summarises the leading crypto custody licensing regimes. Figures are indicative ranges drawn from official regulator materials and should be verified against the primary source for each jurisdiction before you file, as fees and thresholds are periodically revised.
| Jurisdiction | Licensing route | Safeguarding (segregation/insurance) | Minimum capital / net worth | Typical timeline | Indicative cost bracket |
|---|---|---|---|---|---|
| EU (MiCA) | CASP authorisation for custody and administration of crypto-assets; passportable across the EU | Segregation of client assets; liability for loss; operational controls | Tiered own-funds requirement based on service class | Approx. 3–6+ months | Mid-to-high six figures (application, capital, ongoing) |
| UAE (VARA, Dubai) | Activity-based Virtual Asset Custody Services licence | Robust custody controls, segregation and record-keeping; local presence expected | Category-specific paid-up capital thresholds | Approx. 4–9 months | High six figures including local establishment |
| Singapore (MAS) | Payment Services Act licence covering digital payment token services / custody | Safeguarding of customer assets, techno-security and insurance expectations | Base capital and financial soundness thresholds | Approx. 6–12+ months | High six figures |
| Hong Kong (SFC) | Custody licensing under proposed / consulted framework; VATP-linked custody | Strong investor-protection and segregation focus per consultations | Thresholds to be confirmed via final rules | Subject to final framework | To be confirmed; expect substantial spend |
| US (New York) | NY Trust charter and/or BitLicence via NYDFS | Segregation, insurance and cybersecurity expectations | Capital determined case-by-case by NYDFS | Approx. 6–18+ months | High six to seven figures |
Three themes emerge. First, MiCA offers the strongest efficiency play through passporting, making a single EU authorisation attractive for pan-European reach. Second, the Gulf and Asian regimes reward genuine local substance, physical presence, local key persons and jurisdiction-specific controls, over box-ticking. Third, the US remains the most fragmented and time-intensive market, where the NY Trust charter and BitLicence sit within a broader federal overlay. Budget and timeline planning should assume the longest, most demanding jurisdiction in your rollout, not the shortest.
Across regimes, regulators converge on a common set of eligibility criteria for custodians. Understanding these before you apply prevents costly missteps.
Regulators scrutinise legal structure, ownership and control. Expect requirements around a locally incorporated entity, transparent beneficial ownership, and clear group structures. Controllers and significant shareholders are typically subject to their own suitability review, and opaque or highly leveraged ownership chains are a red flag.
Directors, senior managers and key function holders must pass fit-and-proper tests covering honesty, integrity, competence and financial soundness. For custody specifically, regulators want to see demonstrable experience in security, risk and regulated financial services. Weak or thin management teams are among the most common reasons applications stall.
Minimum capital and ongoing own-funds requirements ensure a custodian can absorb operational losses and wind down in an orderly way. Under MiCA, own-funds requirements are tiered by service class; other jurisdictions set base capital thresholds and expect evidence of ongoing solvency. Capital planning must account not only for the entry threshold but for buffers that satisfy supervisors over time.
Because custody is a technology-intensive activity, regulators demand robust operational resilience: business continuity, disaster recovery, incident response, and controls over key generation, storage and use. The concept of a “qualified custodian”, an entity that meets a defined standard of regulatory oversight and asset protection, features across several regimes, though its precise definition varies significantly by jurisdiction, as discussed in the sections that follow.
MiCA created a harmonised, EU-wide framework for crypto-asset service providers, including those offering custody and administration of crypto-assets on behalf of clients. For custodians targeting Europe, MiCA custody requirements are now the reference point.
Under the MiCA Regulation, custody and administration of crypto-assets is a distinct authorised service. Custodians must hold client assets separately from their own, maintain accurate records and registers of positions, and establish clear custody policies. The regulation also addresses liability for the loss of crypto-assets held in custody, sharpening the commercial importance of insurance and safeguarding.
MiCA imposes tiered own-funds requirements calibrated to the services provided, alongside governance, conflicts-of-interest and operational-resilience obligations. Custodians must demonstrate sound administrative arrangements, secure IT systems and effective control functions. These prudential and governance highlights make MiCA one of the more comprehensive crypto custody licensing frameworks globally.
A key advantage of MiCA is passporting: once authorised in one member state, a custodian can provide services across the EU under a notification procedure, subject to home-state supervision with host-state cooperation. This single-market access is a decisive factor for firms weighing where to establish their European custody hub.
Dubai’s VARA has established itself as a leading Gulf regime for digital assets, with an activity-based licensing model that treats custody as a discrete category.
Under the VARA regulatory framework, custody is licensed as a specific virtual asset service, with rulebooks setting out permitted activities, conduct expectations and safeguarding standards. Applicants must map their intended activities precisely to VARA’s categories, as the licence granted governs exactly what the custodian may do and how it must operate.
VARA emphasises genuine local substance. Expect requirements around a Dubai-established entity, qualified local personnel, robust segregation of client assets, and detailed technology and security controls. The 2024–2026 roll-out has consistently reinforced that a VARA custodian licence rewards operational maturity and demonstrable safeguarding capability over minimal-footprint applications.
Singapore remains a strategically important custody hub, with MAS crypto custody requirements sitting within its broader payment services regime.
Custody activities relating to digital payment tokens fall within the licensing perimeter administered by the Monetary Authority of Singapore. Applicants must satisfy base capital and financial-soundness criteria, demonstrate competent management, and operate comprehensive AML/CFT controls consistent with international standards.
MAS has progressively refined its safeguarding expectations, focusing on the protection of customer assets, segregation, and techno-security. Custodians should expect scrutiny of key-management arrangements, technology risk management and the resilience of their custody infrastructure. Building an application that anticipates these expectations is central to a successful MAS crypto custody licensing outcome.
Hong Kong has moved decisively toward a comprehensive virtual asset regime, with custody a central pillar of the SFC’s approach.
The Securities and Futures Commission has issued consultation materials addressing custody licensing and investor protection, reflecting a focus on segregation of client assets, robust custody controls and clear accountability. These proposals signal that custody in Hong Kong will be a distinctly regulated activity with strong safeguarding obligations.
As the framework moves from consultation to implementation, custodians should track final rules closely, since thresholds and timelines will crystallise only when the SFC finalises its approach. Industry observers expect that firms which prepare governance and safeguarding documentation early will be best positioned when the licensing window opens. Early engagement is a prudent posture for any custodian targeting the Hong Kong market.
The United States presents the most complex crypto custody licensing landscape, defined by the interplay of state-level regimes and federal oversight.
New York, through NYDFS, operates two principal routes. A BitLicence applies to certain virtual currency business activities involving New York or New York residents, while a limited-purpose trust company charter allows an entity to act as a fiduciary custodian. Many institutional custodians pursue the NY Trust charter precisely because it confers “qualified custodian”-style standing and fiduciary powers. Which route fits depends on your activities, client base and whether you need fiduciary capacity, a decision best taken with counsel.
Above the state layer sits a federal overlay. Custodians handling money transmission must consider FinCEN registration and AML obligations; those custodying assets that may be securities must weigh SEC expectations; and nationally chartered institutions engage with the OCC. This multi-regulator environment makes early legal analysis of asset classification and activity scope essential.
Because money transmission and custody are largely regulated state-by-state, a custodian serving a national US client base may need multiple state licences in addition to its home charter. Preemption is not comprehensive, so custodians must map each state’s requirements or restrict their footprint accordingly. This fragmentation is the single largest driver of cost and time in US crypto custody licensing.
Safeguarding and capital are the twin pillars regulators examine most closely. This playbook distils practical approaches that recur across MiCA, VARA, MAS, Hong Kong and the US.
Two complementary concepts matter. Legal segregation ensures client assets are ring-fenced from the custodian’s estate so they are protected on insolvency, typically through trust structures, clear account titling and enforceable client agreements. Technological segregation separates keys and holdings at the infrastructure level, using dedicated wallets, address hierarchies and access controls. Robust safeguarding requires both: legal protection that survives insolvency and technical controls that prevent commingling in practice.
Insurance is increasingly expected rather than optional. Custodians should secure specie or crime cover appropriate to their hot and cold holdings and articulate coverage clearly to clients. Contractual warranty language must accurately describe what is and is not covered, overstating protection creates conduct and liability risk, particularly under MiCA’s liability provisions for lost crypto-assets.
Proof-of-reserves has moved from best practice toward baseline expectation. Best-in-class custodians combine cryptographic attestation of holdings with independent audit or agreed-upon-procedures engagements, and publish attestations on a regular cadence. Transparency here supports both regulatory confidence and client trust.
Because thresholds differ, custodians operating in multiple markets should plan capital at group and entity level. Model the highest applicable threshold, add buffers for supervisory comfort, and stress-test against operational-loss and wind-down scenarios. Treating capital as a dynamic, forward-looking discipline, not a one-off entry ticket, is central to sustainable crypto custody licensing.
Technology is where custody risk concentrates, and regulators expect demonstrable, independently assured controls.
Key-management architecture is foundational. Hardware security modules and multi-party computation each offer strong protection; many custodians combine them with quorum-based approvals and geographic distribution of key shares to eliminate single points of failure.
Custodians must maintain tested backup and recovery procedures, documented incident-response playbooks and business-continuity arrangements. The ability to recover keys and resume operations after a disruption is a direct regulatory concern.
Independent certifications such as SOC 2 Type II and ISO/IEC 27001 provide external assurance that controls operate effectively. Increasingly, these are treated as expected evidence within a crypto custody licensing application rather than a differentiator.
For custodians with international ambitions, licensing strategy is as much a commercial decision as a legal one.
A single-licence model, for example, an EU MiCA authorisation with passporting, minimises cost and complexity for a bloc-wide footprint. A multi-licence model is unavoidable where target markets require standalone authorisation, as in the Gulf, Asia and the US. Most global custodians end up with a hybrid: a passported hub plus targeted standalone licences.
Where passporting is unavailable, custodians rely on local establishment, local agents or reliance on regulator memoranda of understanding to smooth supervisory cooperation. Structuring these arrangements correctly avoids inadvertent unlicensed activity in a target market.
A multi-jurisdiction footprint multiplies AML, tax and reporting obligations. Coordinate AML programmes to the FATF risk-based standard across entities, align reporting calendars, and manage transfer-pricing and permanent-establishment questions early to avoid downstream surprises.
Realistic planning depends on candid timeline and budget assumptions, which vary widely across the crypto custody licensing landscape.
Lead times range broadly. MiCA authorisations may complete in roughly three to six months where applications are complete; VARA and MAS processes commonly run several months to a year; and US routes, particularly a NY Trust charter, can take well over a year. Completeness and responsiveness are the biggest levers on speed.
Total cost comprises regulator fees, legal and advisory fees, minimum capital, technology build and independent assurance. For a multi-jurisdiction launch, custodians should plan for high six-figure and, in the US, potentially seven-figure budgets once capital is included. Ongoing compliance and audit costs must be budgeted year on year.
Use this 10-point checklist to assess licensing readiness (a downloadable one-page cross-jurisdiction checklist is planned as a companion resource):
Crypto custody licensing in 2026 rewards custodians who treat authorisation as a strategic, evidence-driven programme rather than a compliance afterthought. Across MiCA, VARA, MAS, the Hong Kong SFC and the US, the common threads are clear: rigorous safeguarding, credible capital, mature governance and independently assured technology. By defining activities precisely, mapping jurisdictions intelligently, and building safeguarding and security to the highest applicable standard, custodians can convert a fragmented regulatory landscape into durable, licensed market access.
posted 14 minutes ago
posted 57 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
posted 4 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message