Choosing a licence

Key points

  • Classification comes before jurisdiction — always, and it is where files fail
  • The same product can fall into different categories in different regimes
  • Holding client assets is usually the single most decisive fact
  • Customer location, not company location, drives which rules apply
  • One business often needs two permissions, and a licence does not stretch

The question is never which licence is best. It is which regulated activity you are actually carrying on — because that is what determines which permissions exist for you at all. Answer five questions first: what the product does, how funds move, who holds client assets, where your customers legally are, and where revenue comes from. The jurisdiction question only becomes answerable afterwards.

Almost every conversation starts the same way: which licence should we get? It is the wrong first question, and answering it directly is how expensive mistakes begin. The right first question is which regulated activity you are carrying on — because until that is settled, the list of licences that exist for you cannot be drawn.

What are the five questions?

The five questions that settle it

  • What does the product actually do, described in a regulator's vocabulary rather than a pitch deck's?
  • How do funds move through it — every hop, including the ones that are technically instantaneous?
  • Who holds client assets, from what moment, and in what form: fiat, tokens, or both?
  • Where are your customers legally resident, and are you already serving any of them?
  • Where does revenue come from — spread, fee, interest, float — and who are the ultimate beneficial owners?

The checklist above is what we work through in a first assessment, and it is deliberately about mechanics rather than category names. Founders reach for labels — we're an exchange, we're a wallet — and labels are precisely what regulators ignore. What a supervisor cares about is what happens to money and to customer assets, moment by moment.

Take the third question. "Who holds client assets, from what moment, and in what form?" A business that never takes custody, matching two counterparties and settling directly between them, sits in a different world from one that takes deposits into a pooled account for even a few seconds. That few seconds is often the whole difference between a light registration and a full authorisation with capital requirements, safeguarding obligations and audited segregation.

The fourth question is the one people get wrong most confidently. Which rules apply is driven by where your customers are, not where your company is incorporated. Incorporating somewhere permissive and onboarding customers in a strict jurisdiction does not import the permissive rules; it means operating without permission in the strict one.

Why does the same product land differently?

Two businesses that look identical from the outside can fall into different regulated categories, because the categories are drawn around what happens to money rather than around what the product is called.

Because the categories are drawn differently in each regime, and the boundaries fall in different places. A single product can be a virtual asset service in one jurisdiction, a payment service in another, and both in a third.

What the business doesUsually regulated asThe fact that decides it
Matches buyers and sellers, never touches assetsBrokerage or arrangingWhether you ever control the assets
Swaps tokens for customers from your own inventoryExchange or conversionWhether the counterparty is you
Holds tokens in wallets you controlCustodyWho holds the private keys
Holds customer fiat that can be spent laterElectronic moneyWhether the balance is redeemable
Settles merchant payments in stablecoinPayments, plus a crypto permissionWhether you hold funds between legs
Issues a token or a stablecoinIssuanceWhether there is a redemption claim against you

Read that table as a starting point rather than an answer. Every row has jurisdiction-specific exceptions, thresholds and carve-outs, which is exactly why the classification work happens before the country is chosen.

Which categories exist?

The categories you are most likely to land in

Exchange or conversion

Swapping between crypto assets, or between crypto and fiat, for third parties. Almost universally regulated, under various names.

This guide covers

Custody

Holding or controlling assets on behalf of others. Often the highest-obligation category in any regime, and the hardest to argue you are outside.

Transfer and remittance

Moving value between parties. Usually caught by payments or money-service rules rather than crypto-specific ones.

Electronic money

Issuing balances customers can spend later. Triggers safeguarding obligations that are stricter than most founders expect.

Issuance

Creating and offering an asset, including stablecoins. Rules here have moved faster than anywhere else in the last two years.

Advisory and brokerage

Arranging or advising on transactions without touching assets. Lighter, but not automatically unregulated.

The six cards above cover the categories most businesses land in. Two general observations about them.

Custody is stickier than founders expect. "We don't hold customer assets" is asserted far more often than it is true. If you control the keys, if you can move assets without a customer's per-transaction authorisation, or if a customer's balance is an entry in your database rather than an on-chain position they control, a supervisor is likely to disagree with you.

Issuance moved fastest. Rules around token and stablecoin issuance have changed more in the past two years than any other area. Under MiCA the EU now has dedicated regimes for asset-referenced and e-money tokens, distinct from crypto-asset service provision, and the transitional period ended on 1 July 2026. Anything written before that date should be read with suspicion.

Which mistake costs the most?

Needing two permissions and obtaining one. It is worth being concrete about how this plays out. A team builds a trading product, correctly identifies that it needs a crypto permission, obtains one, launches — and then adds the ability for customers to leave fiat on account between trades, because it improves the experience. That single feature is very likely electronic money, a separate regulated activity with its own authorisation, its own capital threshold and its own safeguarding rules. The existing licence does not cover it. Now the business is either operating partly unauthorised or rebuilding a feature it has already shipped.

The second-costliest is the mirror image: obtaining a permission whose scope is wider than needed, and carrying the ongoing obligations of activities you never perform.

How does the jurisdiction question become answerable?

Once you know which activity you are carrying on, the jurisdiction comparison is tractable. Three filters do most of the work. Does the regime have a category that matches, with a scope you can actually operate inside? Can you meet its substance requirements honestly — a real entity, a verifiable address, a compliance officer who can genuinely perform the role? And will the resulting permission be accepted by the banks and counterparties you need, which is a commercial question no regulator answers?

The standards underlying nearly every regime trace back to the FATF recommendations, with each jurisdiction adding its own detail — which is why the frameworks rhyme without matching. Where the comparison narrows to the three routes we are asked about most, they are set side by side on Swiss SRO vs MiCA vs El Salvador. The Swiss path in full is on the Swiss SRO route, the full geography is on jurisdictions, and what each route demands on the ground is on substance, cost and risk.

What this stage is worth

Classification is the cheapest work in a licensing project and the most consequential. It costs a conversation and some document review. Getting it wrong costs the application fee, the professional fees, the months, and — because a withdrawn or refused application sits in your history where every future regulator and counterparty will ask about it — something that is not recoverable at all.

Definitions for the terms used here are on the glossary, which is written specifically around the fact that the same abbreviation means different things in different places. Nothing on this page is legal advice, and no approval can be guaranteed: regulators retain full discretion. CryptoLicense is an advisory firm, not a regulator and not a law firm. Positions stated here reflect the framework as at August 2026.

Start by finding out which licence you actually need

Tell us your business model and target markets and we will set out the jurisdictions that fit, the stages on each route, and what you will need to prepare. Free consultation. Approval is at the regulator's discretion and we promise nothing about it.

Book a call