Introduction: Why This Guide, Who It’s For, and the Regulatory Snapshot
Quick Summary
Anyone exploring crypto licensing Philippines routes in 2026 faces two distinct pathways: onshore registration with the Bangko Sentral ng Pilipinas (BSP) to obtain a Certificate of Authority (COA) as a Virtual Asset Service Provider (VASP), or an offshore licence through the Cagayan Economic Zone Authority (CEZA). Each route targets a different business model, customer base, and risk profile. This guide breaks down both options with step-by-step checklists, realistic timelines, a side-by-side comparison table, and a decision matrix so founders, compliance leads, and in-house counsel can determine the right path and move quickly.
The regulatory landscape is shifting fast. Three developments frame every licensing decision in mid-2026:
- BSP Circular No. 1108 (26 January 2021): Established the comprehensive registration and supervisory framework for VASPs operating in the Philippines, requiring a COA before any entity may offer virtual asset exchange, transfer, custody, or related services to the public.
- BSP Memorandum M-2026-003 (January 2026): Reinforced supervisory expectations and signalled heightened scrutiny of unlicensed operators, with industry observers interpreting the memorandum as a de facto tightening of the approval pipeline.
- Enforcement headline 11 June 2026: The BSP publicly confirmed that Binance and its local partner lacked authorisation to operate, underscoring the regulator’s willingness to act against high-profile platforms.
These events have pushed commercial teams to weigh onshore compliance barriers against the CEZA offshore alternative. The sections below provide the analytical framework and practical detail needed to make that decision.
Regulatory Timeline: Key Dates Shaping Crypto Licensing Philippines
2021 BSP Circular No. 1108
On 26 January 2021, the BSP published Circular No. 1108, replacing earlier guidance that had treated virtual currency exchanges as remittance agents. The circular formally defined “virtual asset service providers,” imposed a COA requirement, and brought VASPs under the BSP’s prudential and anti-money-laundering supervision. It established minimum capitalisation thresholds, corporate governance standards, and ongoing reporting obligations effectively setting the regulatory baseline that still governs onshore crypto operations today.
2024–2026 Key SEC, AMLC, and BSP Memoranda
Between 2024 and early 2026, several supervisory developments refined the compliance landscape. The Securities and Exchange Commission (SEC) issued advisories clarifying that tokens meeting the definition of securities require separate SEC registration. The Anti-Money Laundering Council (AMLC) published its Third National Risk Assessment, which flagged VASPs as a high-risk sector and tightened Travel Rule expectations for wire-transfer equivalents. BSP Memorandum M-2026-003, released in January 2026, reiterated the moratorium-like posture toward new VASP applications by directing examiners to apply enhanced scrutiny to pending applications and by requesting additional technical and compliance documentation from applicants already in the pipeline.
June 11, 2026 Enforcement Headlines
On 11 June 2026, multiple outlets reported that the BSP had declared Binance and its Philippine partner unlicensed, ordering the entities to cease marketing and onboarding activities directed at Philippine residents. Industry observers view this enforcement action as a signal that the BSP intends to maintain a strict gatekeeping posture, elevating the urgency for any operator targeting Philippine retail customers to secure proper authorisation or to structure operations through an alternative licensing route such as CEZA.
At-a-Glance Decision Matrix: When to Choose BSP (Onshore) vs CEZA (Offshore)
Quick Rules of Thumb
| Factor |
Choose BSP Onshore COA |
Choose CEZA Offshore Licence |
| Target customers |
Philippine residents (retail and institutional) |
Non-Philippine customers only |
| Fiat on-ramp (PHP) |
Required / permitted |
Not permitted for Philippine peso transactions |
| Retail access in the Philippines |
Yes |
No restricted to offshore clients |
| AML/KYC intensity |
Full BSP and AMLC compliance framework |
CEZA-mandated AML programme; lighter local reporting |
| Banking access (local peso accounts) |
Available to authorised VASPs |
Typically limited to CEZA zone accounts; no direct peso clearing |
| Timeline to approval |
6–12+ months (industry estimates) |
3–6 months (industry estimates) |
Typical Business Models and Recommended Route
- Spot exchange serving Filipino retail traders: BSP COA is the only legally permissible route. CEZA will not cover domestic customer-facing activity.
- Non-custodial wallet or DeFi aggregator with no Philippine customer solicitation: A CEZA offshore licence may suffice, provided no marketing or services are directed at Philippine residents.
- International OTC broker or institutional trading desk: CEZA is typically faster and less capital-intensive; however, if the desk handles any PHP settlement, a BSP COA is required.
- Payments or remittance layer integrating virtual assets: BSP COA, as the service involves money-service-business functions subject to BSP oversight.
Operators with hybrid models serving both domestic and international customers may need to maintain parallel structures: a BSP-registered entity for Philippine operations and a CEZA-licensed entity for offshore activity. GLE can advise on the corporate structuring needed to satisfy both regulators simultaneously.
How to Register a VASP with the BSP Step-by-Step (Onshore COA)
Pre-Application Checklist
Before filing, applicants must establish the foundational corporate and operational elements the BSP expects to see:
- Philippine-incorporated entity: Register a corporation with the SEC. The Articles of Incorporation must include “virtual asset services” or equivalent language in the corporate purpose clause.
- Minimum paid-up capital: Circular No. 1108 sets capitalisation thresholds that vary by service type. Applicants should confirm exact figures with the BSP or qualified counsel, as requirements have been adjusted through subsequent memoranda.
- Physical office in the Philippines: The BSP requires a principal office within the country. Remote-only or virtual-office arrangements are generally insufficient.
- Local directors and compliance officer: At least one director must be a Philippine resident. A dedicated compliance officer and money-laundering reporting officer (MLRO) must be appointed before application.
- Board-approved business plan: A multi-year plan covering projected volumes, revenue model, target market, and risk appetite must be prepared and signed by the board.
Technical and Compliance Requirements
The BSP expects applicants to demonstrate a mature compliance infrastructure at the point of application, not merely a commitment to build one later:
- KYC / KYB programme: Robust customer and counterparty due diligence procedures aligned with AMLC guidelines, including enhanced due diligence for high-risk customers.
- AML / CFT programme: Written policies, board-approved risk assessment, suspicious transaction reporting (STR) procedures, and a sanctions-screening framework.
- Travel Rule implementation: In line with AMLC risk-assessment guidance, VASPs must transmit originator and beneficiary information for qualifying virtual asset transfers. A technology solution (e.g., TRISA, Sygna, Notabene) should be selected and documented.
- Transaction monitoring: Real-time or near-real-time monitoring with rules calibrated to the applicant’s risk profile.
- AMLC registration and reporting: Separate registration with the AMLC as a covered person and readiness to file covered transaction reports (CTRs) and STRs electronically.
Documentation Checklist
Applicants should prepare the following for submission with the COA application:
- SEC Certificate of Incorporation and Articles
- Audited financial statements (at least one fiscal year, or pro-forma if newly incorporated)
- Board-approved AML/CFT manual
- IT security and architecture documentation (network topology, data-flow diagrams, encryption standards)
- Third-party penetration test or SOC 2 report
- Business continuity and disaster-recovery plan
- Custody model description (hot/cold wallet architecture, key-management procedures, insurance coverage if any)
- Internal audit charter and compliance testing plan
- Fit-and-proper declarations for directors, officers, and significant shareholders
Application Submission and Review Process
The COA application is submitted to the BSP’s Technology Risk and Innovation Supervision Department (TRISD). The review typically proceeds as follows:
- Completeness check: BSP staff verify that all required documents are present. Incomplete filings are returned without prejudice.
- Substantive review: Examiners evaluate the business plan, governance structure, AML programme, and technical controls. Requests for information (RFIs) are common applicants should budget time for at least two rounds of clarificatory questions.
- On-site or virtual inspection: The BSP may conduct an on-site visit to verify physical office arrangements, IT infrastructure, and compliance team readiness.
- Monetary Board approval: The final COA decision rests with the BSP Monetary Board. Applicants are notified in writing.
Estimated Costs and Timing
The following are industry estimates only applicants should verify current figures with the BSP or qualified counsel:
- Timeline: 6–12 months from complete submission to Monetary Board decision. Complex applications or those submitted during periods of heightened scrutiny may take longer.
- Professional fees (legal, compliance, technical): Estimated ranges vary widely. Low-end engagements (where the applicant has in-house compliance capacity) may start at approximately USD 50,000–80,000; comprehensive advisory mandates covering corporate structuring, AML programme design, IT audit coordination, and application management can reach USD 150,000–250,000 or more.
- Regulatory fees: BSP application and supervisory fees are set by the regulator and subject to change. Confirm current schedules directly with the BSP.
Obtaining a CEZA (Cagayan) Offshore Crypto Licence Step-by-Step
When CEZA Is Appropriate
The CEZA route is designed for enterprises that wish to operate within a Philippine special economic zone but serve exclusively non-Philippine customers. Typical use cases include offshore spot or derivatives exchanges, payment processors routing cross-border crypto settlements, and custody platforms targeting institutional clients outside the Philippines. CEZA-licensed entities may not solicit, onboard, or serve Philippine residents for crypto-related services.
Corporate and Jurisdictional Requirements
Applicants must register an enterprise within the Cagayan Special Economic Zone and Freeport (CSEZFP). Key structural elements include:
- CEZA enterprise registration: The entity is incorporated or registered as a CEZA locator, subject to the zone’s fiscal incentives and regulatory framework.
- Local registered agent or representative: A Philippine-based agent must be designated to receive regulatory correspondence and facilitate inspections.
- Minimum capitalisation: CEZA has imposed capitalisation requirements that differ by licence category. Applicants should confirm current thresholds directly with CEZA, as these have been revised periodically.
Documentation Checklist
- CEZA application forms (available through the CEZA registrar)
- Proof of capitalisation (bank certificates, escrow arrangements)
- AML / KYC policies (adapted for the offshore customer base)
- Technology and security documentation (infrastructure overview, penetration test results)
- Corporate governance documents (board resolutions, shareholder registry, fit-and-proper declarations)
- Business plan with projected volumes and target markets
Application Workflow and Expected Timeline
- Pre-qualification meeting: Informal engagement with CEZA officers to confirm eligibility and licence category.
- Enterprise registration: File corporate registration documents with CEZA and obtain locator status.
- Licence application: Submit the complete application package, including AML programme and technical documentation.
- Due diligence and review: CEZA conducts background checks on beneficial owners and reviews the compliance framework.
- Provisional licence: Upon initial approval, a provisional licence may be issued, allowing the applicant to begin limited operations while final conditions are met.
- Final licence: Issued after all conditions precedent are satisfied.
Estimated Costs and Timing
These are estimates only verify with CEZA or qualified counsel:
- Timeline: 3–6 months from complete submission to provisional licence; final licence may follow within an additional 1–3 months.
- Licence and registration fees: CEZA publishes a schedule of fees for enterprise registration and annual licence renewal. Fees have historically ranged from approximately USD 20,000–100,000 depending on licence category, though these figures should be confirmed with CEZA directly.
- Professional and setup costs: Legal, compliance advisory, and local agent fees typically range from USD 30,000–80,000.
- Annual renewal and operating costs: Ongoing licence renewal fees, local representative costs, and compliance maintenance should be budgeted annually.
Comparison Table: BSP COA vs CEZA Licence
| Criterion |
BSP Certificate of Authority (Onshore) |
CEZA Offshore Licence |
| Regulatory authority |
Bangko Sentral ng Pilipinas (BSP) |
Cagayan Economic Zone Authority (CEZA) |
| Allowed customer base |
Philippine residents and international clients |
Non-Philippine customers only |
| Fiat on-ramp (PHP) |
Permitted |
Not permitted |
| AML / KYC / Travel Rule |
Full BSP + AMLC framework; Travel Rule mandatory |
CEZA-mandated AML programme; Travel Rule advisable |
| Minimum capital |
Set by Circular 1108 (verify current thresholds) |
Set by CEZA fee schedule (verify current thresholds) |
| Typical timeline |
6–12+ months |
3–6 months |
| Enforcement risk |
High BSP actively enforces (see June 2026 action) |
Moderate CEZA oversight is less publicised |
| Ongoing compliance obligations |
Regular BSP examinations, AMLC reporting, annual audits |
Annual renewal, AML programme maintenance, CEZA reporting |
| Best for… |
Exchanges, wallets, payments serving Philippine retail |
Offshore exchanges, international OTC desks, non-PH custody |
Note: All capital, fee, and timeline figures in this table are estimates based on publicly available guidance and industry experience. Confirm current requirements with the relevant authority or with GLE.
Key Requirements and Eligibility for Crypto Licensing Philippines
AML / CDD / Travel Rule
Both the BSP and CEZA expect applicants to maintain comprehensive AML programmes. Under the BSP framework, VASPs must register with the AMLC as covered persons, file CTRs and STRs, and implement the Travel Rule for qualifying transfers. The AMLC’s Third National Risk Assessment has classified VASPs as inherently high-risk, meaning examiners apply enhanced scrutiny to customer due diligence (CDD) processes, transaction monitoring rules, and sanctions-screening procedures.
Corporate Governance and Technical Controls
Regulators expect documented custody models distinguishing between hot and cold wallet infrastructure, multi-signature key-management procedures, and independent security audits. Smart contract audits are increasingly expected where platforms deploy on-chain logic. Board-level oversight of cyber-security risk and incident-response protocols is a baseline expectation for both BSP and CEZA applications.
Local Presence, Directors, and Representative Obligations
BSP-registered VASPs must maintain a physical office in the Philippines and appoint at least one resident director. CEZA locators must designate a local registered agent within the Cagayan zone. In both cases, a named compliance officer with demonstrable AML/CFT expertise is required.
Key Risks and How GLE Mitigates Them
Enforcement and Revocation Risk
The June 2026 enforcement action against Binance’s local partner demonstrates that the BSP is prepared to act publicly and swiftly. Operators without a COA face cease-and-desist orders, reputational damage, and potential criminal referrals. GLE mitigates this risk by conducting pre-application regulatory gap assessments, ensuring the application package meets BSP expectations before submission, and providing ongoing compliance monitoring after the COA is granted.
AML / Travel Rule Non-Compliance Risk
Failure to comply with AMLC reporting requirements or the Travel Rule can result in administrative penalties, licence suspension, and sanctions exposure. GLE designs bespoke AML programmes, assists with Travel Rule vendor selection, and conducts periodic compliance health checks to identify gaps before regulators do.
Reputational and Banking-Access Risk
Philippine banks increasingly require counterpart VASPs to hold valid BSP authorisation before opening or maintaining accounts. Unauthorised operators face de-banking. GLE structures client entities to maximise bankability through clean corporate governance documentation, escrow arrangements, and proactive engagement with banking partners’ compliance teams.
Next Steps: Why Global Law Experts
Navigating crypto licensing Philippines requirements demands more than document preparation it requires regulatory strategy, technical compliance design, and ongoing supervisory engagement. Global Law Experts provides end-to-end support across both the BSP and CEZA pathways:
- Regulatory strategy and route selection: Detailed assessment of your business model, customer base, and risk profile to determine the optimal licensing route.
- Corporate structuring: Philippine incorporation, CEZA enterprise registration, and dual-entity architectures for hybrid onshore-offshore models.
- Licence application management: Preparation, submission, and BSP/CEZA liaison through the full review cycle, including RFI responses and examiner coordination.
- AML programme design: Board-ready AML/CFT manuals, Travel Rule implementation, sanctions screening, and transaction monitoring rule calibration.
- Technical and compliance audits: Pre-application gap assessments, penetration test coordination, custody model review, and SOC 2 readiness support.
- Ongoing compliance and examination support: Post-licence regulatory reporting, BSP examination preparation, and AMLC filing support.
For a confidential assessment of your licensing options, reach out to the GLE licensing team.
Sources