Exchange or conversion
Swapping between crypto assets, or between crypto and fiat, for third parties. Almost universally regulated, under various names.

The question is never which licence is best. It is which regulated activity you are actually carrying on — because that is what determines which permissions exist for you at all. Answer five questions first: what the product does, how funds move, who holds client assets, where your customers legally are, and where revenue comes from. The jurisdiction question only becomes answerable afterwards.
Almost every conversation starts the same way: which licence should we get? It is the wrong first question, and answering it directly is how expensive mistakes begin. The right first question is which regulated activity you are carrying on — because until that is settled, the list of licences that exist for you cannot be drawn.
The five questions that settle it
The checklist above is what we work through in a first assessment, and it is deliberately about mechanics rather than category names. Founders reach for labels — we're an exchange, we're a wallet — and labels are precisely what regulators ignore. What a supervisor cares about is what happens to money and to customer assets, moment by moment.
Take the third question. "Who holds client assets, from what moment, and in what form?" A business that never takes custody, matching two counterparties and settling directly between them, sits in a different world from one that takes deposits into a pooled account for even a few seconds. That few seconds is often the whole difference between a light registration and a full authorisation with capital requirements, safeguarding obligations and audited segregation.
The fourth question is the one people get wrong most confidently. Which rules apply is driven by where your customers are, not where your company is incorporated. Incorporating somewhere permissive and onboarding customers in a strict jurisdiction does not import the permissive rules; it means operating without permission in the strict one.

Because the categories are drawn differently in each regime, and the boundaries fall in different places. A single product can be a virtual asset service in one jurisdiction, a payment service in another, and both in a third.
| What the business does | Usually regulated as | The fact that decides it |
|---|---|---|
| Matches buyers and sellers, never touches assets | Brokerage or arranging | Whether you ever control the assets |
| Swaps tokens for customers from your own inventory | Exchange or conversion | Whether the counterparty is you |
| Holds tokens in wallets you control | Custody | Who holds the private keys |
| Holds customer fiat that can be spent later | Electronic money | Whether the balance is redeemable |
| Settles merchant payments in stablecoin | Payments, plus a crypto permission | Whether you hold funds between legs |
| Issues a token or a stablecoin | Issuance | Whether there is a redemption claim against you |
Read that table as a starting point rather than an answer. Every row has jurisdiction-specific exceptions, thresholds and carve-outs, which is exactly why the classification work happens before the country is chosen.
Swapping between crypto assets, or between crypto and fiat, for third parties. Almost universally regulated, under various names.
Holding or controlling assets on behalf of others. Often the highest-obligation category in any regime, and the hardest to argue you are outside.
Moving value between parties. Usually caught by payments or money-service rules rather than crypto-specific ones.
Issuing balances customers can spend later. Triggers safeguarding obligations that are stricter than most founders expect.
Creating and offering an asset, including stablecoins. Rules here have moved faster than anywhere else in the last two years.
Arranging or advising on transactions without touching assets. Lighter, but not automatically unregulated.
The six cards above cover the categories most businesses land in. Two general observations about them.
Custody is stickier than founders expect. "We don't hold customer assets" is asserted far more often than it is true. If you control the keys, if you can move assets without a customer's per-transaction authorisation, or if a customer's balance is an entry in your database rather than an on-chain position they control, a supervisor is likely to disagree with you.
Issuance moved fastest. Rules around token and stablecoin issuance have changed more in the past two years than any other area. Under MiCA the EU now has dedicated regimes for asset-referenced and e-money tokens, distinct from crypto-asset service provision, and the transitional period ended on 1 July 2026. Anything written before that date should be read with suspicion.
Needing two permissions and obtaining one. It is worth being concrete about how this plays out. A team builds a trading product, correctly identifies that it needs a crypto permission, obtains one, launches — and then adds the ability for customers to leave fiat on account between trades, because it improves the experience. That single feature is very likely electronic money, a separate regulated activity with its own authorisation, its own capital threshold and its own safeguarding rules. The existing licence does not cover it. Now the business is either operating partly unauthorised or rebuilding a feature it has already shipped.
The second-costliest is the mirror image: obtaining a permission whose scope is wider than needed, and carrying the ongoing obligations of activities you never perform.
Once you know which activity you are carrying on, the jurisdiction comparison is tractable. Three filters do most of the work. Does the regime have a category that matches, with a scope you can actually operate inside? Can you meet its substance requirements honestly — a real entity, a verifiable address, a compliance officer who can genuinely perform the role? And will the resulting permission be accepted by the banks and counterparties you need, which is a commercial question no regulator answers?
The standards underlying nearly every regime trace back to the FATF recommendations, with each jurisdiction adding its own detail — which is why the frameworks rhyme without matching. Where the comparison narrows to the three routes we are asked about most, they are set side by side on Swiss SRO vs MiCA vs El Salvador. The Swiss path in full is on the Swiss SRO route, the full geography is on jurisdictions, and what each route demands on the ground is on substance, cost and risk.
Classification is the cheapest work in a licensing project and the most consequential. It costs a conversation and some document review. Getting it wrong costs the application fee, the professional fees, the months, and — because a withdrawn or refused application sits in your history where every future regulator and counterparty will ask about it — something that is not recoverable at all.
Definitions for the terms used here are on the glossary, which is written specifically around the fact that the same abbreviation means different things in different places. Nothing on this page is legal advice, and no approval can be guaranteed: regulators retain full discretion. CryptoLicense is an advisory firm, not a regulator and not a law firm. Positions stated here reflect the framework as at August 2026.
Tell us your business model and target markets and we will set out the jurisdictions that fit, the stages on each route, and what you will need to prepare. Free consultation. Approval is at the regulator's discretion and we promise nothing about it.
Book a call