Scope of the permission
Exactly which regulated activities it authorises, and whether that covers what you intend to do. A permission for one activity does not stretch to another.

Acquiring a company that already holds a permission can be materially faster than applying, and it can also mean inheriting somebody else's compliance history. The transaction is not really a company purchase — it is a regulatory change-of-control approval with a company purchase attached, and the regulator can refuse it.
We handle both sides of this: buying a licensed entity, and selling one. It is a legitimate route, and it is oversold. This page is written to make the decision, not the transaction, easier.
Sometimes, substantially. Where the target is clean, its permission genuinely covers your activity, its approved individuals will stay, and the regulator is comfortable with the new owners, a transfer can put you in the market well ahead of a fresh application.
But the comparison people make in their heads is the wrong one. They compare "buy an existing licence" against "apply from scratch" and count only the application phase. The real comparison includes the change-of-control approval, the due diligence, and the remediation of whatever the diligence uncovers. On a target with a messy history, that is longer than an application would have been — and you are now the owner of the mess.
This is the point most buyers miss. A licence is not an asset that transfers with the shares. In almost every regime, a change of controller in a licensed entity requires the regulator's approval, and the regulator assesses the incoming owners against the same fit-and-proper standards it would apply to a new applicant. It can refuse. It can also impose conditions on approval that change the economics of the deal after you have committed.
Which means the diligence a buyer needs is not ordinary M&A diligence with a regulatory annex. It is a regulatory assessment with a company attached.
Exactly which regulated activities it authorises, and whether that covers what you intend to do. A permission for one activity does not stretch to another.
Current conditions, undertakings, past correspondence, any supervisory action, and whether reporting obligations have actually been met.
Past customers, suspicious activity reporting, and any transaction the entity processed that you would not have accepted.
Liabilities, tax standing, outstanding obligations to clients, and whether the entity meets its capital requirement today.
Who the approved individuals are, whether they intend to stay, and whether the regulator will accept your proposed replacements.
Whether the entity's accounts survive a change of ownership. Frequently they do not, and the buyer discovers it after completion.
The six areas above, and the one people skip is banking. A licensed entity with a working bank account is far more valuable than one without, and account relationships very often do not survive a change of ownership — the bank re-runs its onboarding on the new beneficial owners and may decline. If the seller says the account transfers, that needs to be in writing from the bank, not from the seller.
The second most-skipped is AML history. You inherit the entity's past, including customers it onboarded and transactions it processed. A supervisor reviewing the entity after your acquisition will not treat those as somebody else's problem.
Signals that a target is not worth buying
The list above is the short version. The single strongest signal is a seller who cannot produce clean regulatory correspondence: if two years of routine filings and supervisory exchanges are not readily available, the reason is usually not administrative.
The general standards that shape all of this trace back to the FATF recommendations and, for entities inside the EU, to the MiCA framework whose transitional period ended on 1 July 2026 — a legacy national registration acquired to serve EU customers may no longer do what the seller believes it does.
For buyers: target assessment, the full regulatory due diligence, the change-of-control filing, and a remediation plan for the gaps. For sellers: getting the entity into a state where it survives a buyer's diligence, which is usually a compliance exercise rather than a sales one. The head-to-head against a fresh application is on new application versus ready-made licence.
We will recommend against a purchase, and often do. No regulator's approval — of the licence or of the change of control — can be guaranteed. This page is general information, not legal advice; CryptoLicense is an advisory firm, not a regulator and not a law firm.
Tell us your business model and target markets and we will set out the jurisdictions that fit, the stages on each route, and what you will need to prepare. Free consultation. Approval is at the regulator's discretion and we promise nothing about it.
Book a call