How to Get a Crypto License for Your Business: A Complete Guide

Intro
Look up any authorised European crypto firm on ESMA's public register and you will find a column that most licensing conversations skip entirely: which specific services that firm is permitted to provide. Not "crypto licence." Not "exchange licence." A named subset drawn from ten defined crypto-asset services, listed firm by firm. Two companies on the same register, both described in the press as licensed crypto exchanges, can hold permissions that do not overlap.
That register held more than 300 authorised providers by mid-2026, up from roughly 17 in early 2025, after national transitional regimes for existing providers ran out on 1 July 2026.
(Source: ESMA, Markets in Crypto-Assets Regulation — register and transitional arrangements under Article 143 — https://www.esma.europa.eu/esmas-activities/digital-finance-and-innovation/markets-crypto-assets-regulation-mica)
The Europe-specific detail matters less than the structural lesson, which applies everywhere: regulators authorize activities, not companies. That is why the question businesses usually start with — "how do I get a crypto license?" — is the wrong first question.
"Crypto License" is an umbrella term, not a legal category. Depending on the business model and the jurisdiction, regulatory status can take the form of an authorization, a VASP licence, a CASP authorization, an AML registration, an MSB registration, a money-transmitter licence, or an activity-specific financial authorization sitting inside an existing financial services regime. These are not variants of one thing. They are different legal instruments with different scopes, different obligations and different consequences for what the business may lawfully do.
So the real first question is: what regulated services does the business actually provide? Only once that is answered can a company work out which regime applies, which regulator is responsible, what legal entity is required, what capital and governance requirements attach, and what compliance framework has to exist before an application is credible.
Crypto licensing starts with the business model, not with a jurisdiction shortlist. It is also worth setting expectations about what these regimes now involve. Frameworks have matured considerably. A business entering a regulated market in 2026 typically faces not only AML and KYC requirements but also expectations around governance, capital, operational resilience, safeguarding of client assets, cybersecurity, regulatory reporting and continuing supervision after authorization is granted. The days when a crypto authorization meant filing an AML policy and a company extract are largely over in the markets most businesses want to serve.
What a "Crypto License" Actually Means
"Crypto License" is a convenient commercial phrase. It is not a single legal category, and treating it as one causes real planning errors.
Different frameworks use different instruments: licensing, authorization, registration, approval, or activity-specific permissions bolted onto an existing financial services regime. The distinction matters because the instruments do different work.
An AML registration may primarily establish regulatory status, impose AML/CFT obligations and create reporting responsibilities. A broader authorization may additionally assess governance arrangements, the suitability of management, financial resources, customer protection, operational controls, custody arrangements and market conduct.
What you should not take from that is a universal rule that registration is light and a licence is strict. Some AML registration regimes are demanding and heavily supervised; some licensing regimes are narrower than their name suggests. The actual scope always comes from the law that creates the instrument, not from the word used to describe it.
The terminology varies internationally as well. VASP — Virtual Asset Service Provider — is the term used widely in the FATF and international context, and being classified as one can itself trigger licensing or registration duties depending on the country. CASP — crypto-asset service provider — is the term used in frameworks such as MiCA. MSB and money transmitter terminology appears in other regulatory systems, particularly in North America. These labels overlap but are not synonyms, and a definition that captures a business in one framework may not capture it in another.
Which Crypto Activities Usually Require Authorization
Regulators increasingly classify crypto businesses by the services actually performed rather than by how the company describes itself. The activities that commonly fall inside a regulated perimeter include:
- custody and administration of customer crypto-assets;
- exchange of crypto for fiat currency;
- exchange of crypto for other crypto-assets;
- operating a trading platform;
- execution of customer orders;
- reception and transmission of orders on behalf of clients;
- brokerage or dealing on own account;
- transfer services for crypto on behalf of customers;
- portfolio management;
- crypto investment advice;
- placement or distribution of crypto-assets;
- certain issuance and stablecoin-related activities.
The critical point is that one product usually contains several of these at once. A platform marketed simply as a crypto exchange may simultaneously hold customer funds in custody, operate an order book, execute trades, exchange assets between pairs, and process outbound transfers. That is five regulated activities inside a single product, potentially attracting five different sets of requirements within one authorization — or, in some regimes, requiring more than one authorization.
Authorization scope therefore cannot be determined from the website category, the pitch deck or the company name. It comes from a service-by-service mapping of what actually happens when a customer uses the product.
The distinction that does the most work here is custodial versus non-custodial. A business that controls customer assets or private keys is in a fundamentally different regulatory position from a software provider whose users retain sole control of their own keys. Not every wallet provider needs a crypto licence; some are regulated as financial institutions and others sit outside the perimeter entirely, and the difference usually turns on control rather than on the product name. That said, non-custodial does not automatically mean unregulated — some frameworks reach further than others, and the analysis has to be done against the specific law rather than assumed.
MiCA is a useful illustration of activity-based licensing because it makes the structure explicit: it defines ten crypto-asset services, and a CASP authorization specifies which of those ten a firm may provide. A firm authorised for custody and exchange is not thereby authorised to operate a trading platform. Other frameworks organise the same logic differently, but the underlying approach — permission scoped to named activities — is now common.
What Regulators Usually Assess Before Granting Authorization
Assessment areas differ by regime, and it is a mistake to present one jurisdiction's requirements as a global standard. That said, the areas regulators commonly examine cluster into a recognizable set:
- the business model and the regulated services within it;
- corporate structure, shareholders and beneficial owners (UBOs);
- source of capital;
- directors and senior management, including fit-and-proper assessment;
- governance arrangements and internal controls;
- the AML/CFT framework;
- customer onboarding, KYC and KYB procedures;
- sanctions screening controls;
- transaction monitoring and suspicious-activity escalation;
- capital and financial resources;
- safeguarding and segregation of customer assets;
- cybersecurity and operational resilience;
- outsourcing arrangements and third-party dependencies;
- conflicts of interest and business continuity;
- financial projections.
Not every jurisdiction assesses these in the same way, at the same depth, or at all. Three areas in particular are routinely generalized in licensing content, so they are worth separating out.
Capital
There is no global capital range for crypto businesses. Figures quoted as universal — including the "€50,000 to €150,000" range that circulates widely — are usually MiCA figures presented without their source, and they do not describe requirements in most non-EU regimes.
Used properly as one concrete example, MiCA sets permanent minimum capital by service class at €50,000, €125,000 or €150,000, with the applicable tier depending on which crypto-asset services the CASP is authorised to provide. The detail that gets dropped from most summaries matters more than the tiers themselves: prudential safeguards must be the higher of that class minimum or one quarter of the preceding year's fixed overheads, reviewed annually, with newly authorised firms using the projected overheads submitted in their application. For a growing business, the overhead-based figure overtakes the class floor without any change to the product. The mechanics of MiCA CASP authorization requirements are worth reading in full if the EU is a target market.
Other regimes calculate financial resources completely differently, or set no fixed minimum at all and assess adequacy against the business plan instead.
Local Substance
It is not universally true that regulators require a physical office and local staff. Some authorization regimes can require a locally incorporated entity, a registered office, effective management located in the jurisdiction, resident directors, local compliance functions, or demonstrable economic substance. Others operate on different models, and the substance expectation often scales with the risk of the activity rather than applying uniformly.
Where substance requirements do exist, they tend to be enforced seriously, and thin substance is a common reason applications fail. But "regulators now require local presence everywhere" is not an accurate planning assumption.
Banking
A fiat banking or payment relationship is frequently essential to operating a crypto business — particularly anything involving fiat on- and off-ramps. That is an operational reality, not a universal licensing prerequisite. Some regimes require evidence of a bank account or of paid-up capital held in a specific way before an application is accepted; others do not, and in several markets banking is easier to secure once authorization is in progress or granted. Sequencing this correctly matters, because assuming banking must come first can stall a project for months unnecessarily. Across all three areas, the same underlying expectation applies: the documentation submitted has to describe a compliance framework that will actually operate, staffed by people who can explain it. Regulators increasingly test whether policies match the product rather than whether policies exist, which is where structured crypto compliance consulting for licensing preparation tends to earn its place — translating an operating model into evidence a supervisor will accept.
How to Prepare and Apply for a Crypto License
The sequence below matters as much as the content. A large share of failed or stalled applications come from doing these steps in the wrong order — most often by choosing a jurisdiction or incorporating a company before anyone has established which activities the business performs.
1. Map the business model. Document the products, customer types (retail, professional, institutional), the custody model, transaction flows, whether and how fiat is involved, key counterparties, and the countries where customers will actually be served. This is a factual exercise, not a strategic one.
2. Map the regulated activities. Work out which parts of that product may qualify as custody, exchange, brokerage, transfer, trading platform operation, advisory or another regulated service. One legal entity can perform several. Expect this step to surface activities nobody thought of as regulated.
3. Determine the required authorization. Only now identify the applicable regulatory regime, the responsible regulator, the licence or registration type, the service scope you need covered, entity and substance requirements, capital requirements, and any restrictions on serving customers cross-border.
4. Build the legal and governance structure. Depending on the regime this may involve incorporation, setting the ownership and UBO structure, appointing directors and key function holders, allocating compliance responsibility to a named person, arranging financial resources, and establishing local substance where required.
5. Build the compliance framework. Prepare the controls that will actually run: AML/CFT, KYC and KYB, business-wide risk assessment, sanctions screening, transaction monitoring, escalation and reporting, recordkeeping, cybersecurity, outsourcing oversight, business continuity, and custody or safeguarding arrangements where relevant. The governing principle here is simple and frequently ignored — policies must describe how the actual product works. Generic templates copied from another company are visible to supervisors almost immediately, because the described customer journey does not match the one in the application.
6. Prepare the application evidence. Depending on the regime this can include a business plan, corporate documents, shareholder and UBO information, management CVs, financial projections, evidence of capital, AML policies and risk assessment, organisational structure, technology and security descriptions, custody architecture, outsourcing arrangements, the customer journey and transaction flow documentation. Treat this as regime-specific rather than as a universal checklist.
7. Submit and respond to regulatory review. Expect the regulator to request explanations, challenge assumptions in the business model, ask for updated documentation, test whether management actually understands the framework being submitted, and probe how controls operate in practice rather than on paper. Timelines vary widely by jurisdiction, authorization type and application quality, and anyone quoting a fixed number of months is guessing.
8. Prepare for launch and ongoing supervision. Before authorization arrives, the business should already understand its reporting schedule, ongoing capital requirements, notification duties toward the regulator, monitoring obligations, audit expectations, recordkeeping requirements and change-management rules.
The framing that helps most: a crypto licence application is an assessment of whether the business can operate compliantly, not whether it has assembled enough documents.
How to Choose the Right Crypto Licensing Jurisdiction
Jurisdiction choice should follow from the business model and the commercial strategy, which is why it appears here rather than at step one.
The factors worth weighing include target customer markets and where services will actually be offered; the types of regulated activity involved; the licensing model and regulatory reputation; application complexity, capital requirements and local substance expectations; realistic licensing timelines; initial application cost against ongoing compliance cost; banking and payment-provider availability; access to institutional partners; tax structure; reporting requirements; the ability to serve customers cross-border, including passporting where it exists; restrictions on specific activities; and what investors and counterparties will expect to see.
One distinction deserves particular attention: the easiest jurisdiction to obtain authorization in may not be the easiest jurisdiction to operate from.
A lower-cost offshore authorization can offer faster setup, lower capital requirements and lighter substance obligations. The same business may then encounter harder banking, limited payment rails, friction in counterparty due diligence, restrictions when trying to serve customers in tightly regulated markets, and weaker institutional acceptance.
A more demanding major-market authorization typically brings higher application costs, a heavier ongoing compliance burden and stricter governance expectations — potentially alongside better market access, easier banking, stronger institutional credibility and smoother partner onboarding.
Neither route is automatically better. The right comparison is not between application fees but between the total cost of operating the business under each licence, including the cost of the customers and partnerships that a given authorization does or does not unlock.
The other principle that resolves most of these debates: jurisdiction choice should follow the target market. If customers are primarily located in a tightly regulated market, obtaining an inexpensive authorization somewhere else does not automatically give the business legal access to those customers. Cross-border service provision usually triggers its own licensing, registration or notification requirements in the customer's jurisdiction, regardless of where the company holds a licence.
A Crypto License Is Only the Start of Compliance
Authorization answers one narrow question: can this business legally perform these specified regulated activities under this regulatory framework? It does not certify that the business is well run, that its customers are safe, or that its compliance work is finished. It is permission to start, granted on the basis of what the business said it would do.
What follows is continuous. Ongoing requirements commonly include AML/CFT controls, customer due diligence, transaction monitoring, sanctions screening, Travel Rule obligations where applicable, suspicious activity reporting, regulatory reporting, recordkeeping, safeguarding of client assets, capital monitoring, governance, operational resilience and cybersecurity, audits, and notifications to the regulator.
That last item is where otherwise well-run businesses get into trouble, because authorization is scoped to a described business model and business models change. Launching a new service, adding custody, listing new asset types, entering new countries, changing payment flows, switching an outsourcing provider, completing an acquisition, changing ownership, or onboarding a materially different class of counterparty can all take the business outside what was assessed. Each of those events raises the same question: Does the existing authorization still cover what we now do, and does the regulator need to be told?
A licence should be treated as permission to operate a defined business model, not as permanent approval for every future crypto service.
The strongest licensing strategy starts by defining the business, mapping the regulated activities, choosing a jurisdiction that fits the target market, and building compliance controls that will continue working after authorization is granted.

FAQ
What Is a Crypto License?
"Crypto License" is a general term for regulatory authorization or registration that allows a business to perform specified crypto-related activities. The exact legal status can be a VASP licence, CASP authorization, AML registration, MSB registration, money-transmitter licence, or another form of permission depending on jurisdiction.
Does Every Crypto Business Need a License?
No. Whether authorization is required depends on the services provided, where the business operates, who controls customer assets, and the laws of the relevant jurisdiction. Pure technology or non-custodial services may be treated differently from custody, exchange, brokerage, or customer transfer services.
Which Crypto Activities Usually Require Regulatory Authorization?
Common regulated activities include custody, crypto exchange, operating trading platforms, executing customer orders, brokerage, transferring crypto on behalf of customers, portfolio management, and certain token or stablecoin services. The exact scope varies by jurisdiction, and one product often contains several regulated activities at once.
What Do Regulators Check Before Issuing a Crypto License?
Regulators may assess the business model, ownership, beneficial owners, management, governance, AML/CFT controls, customer onboarding, transaction monitoring, sanctions procedures, capital, safeguarding, cybersecurity, outsourcing, operational resilience, and financial projections. Depth of assessment varies significantly between regimes.
How Long Does It Take to Get a Crypto License?
There is no universal timeline. Processing time depends on the jurisdiction, authorization type, regulated activities, complexity of the business, quality of the application, and how many questions or revisions the regulator requires. Incomplete applications extend timelines more than regulator workload does.
How Much Does a Crypto License Cost?
There is no single cost. Businesses should consider application and regulatory fees, capital requirements, legal and compliance work, local substance, staff, audits, technology, banking, and ongoing regulatory costs rather than only the initial licence fee.
Do I Need a Local Company to Get a Crypto License?
Sometimes. Some regimes require a locally incorporated company, registered office, resident management, or other economic substance. Other frameworks use different requirements, so the answer depends on the jurisdiction and the regulated activity.
Is the Cheapest Crypto Licensing Jurisdiction the Best Option?
Not necessarily. A low-cost authorization can be attractive at the application stage but may create problems with banking, payment providers, institutional counterparties, market access, or customer geography. The total operating model matters more than the licence fee alone.
Can One Crypto License Be Used Worldwide?
Generally no. Regulatory authorization is tied to a particular legal framework and set of activities. Serving customers in another jurisdiction can trigger additional licensing, registration, notification, or cross-border requirements. Regional arrangements such as EU passporting are exceptions within a defined bloc, not global permissions.
What Happens After a Crypto License Is Granted?
The business normally remains subject to ongoing requirements such as AML/CFT controls, transaction monitoring, sanctions screening, reporting, recordkeeping, capital requirements, governance, audits, regulatory notifications, and supervision. Material changes to the business model may require notifying the regulator or extending the authorization.