If you’re trying to launch or expand a crypto business in the UAE, the first question everyone asks is the same: who actually licenses you? The answer isn’t one regulator. It’s three, and your choice shapes everything from your product scope to bank accounts and hiring plans.

Here’s a practical walkthrough of how the UAE splits crypto oversight between Dubai’s VARA, Abu Dhabi’s ADGM/FSRA, and the federal SCA that covers the rest of the country. No hype, just the map, the trade-offs, and the gotchas people keep tripping on.

We’ll also point to what’s been approved lately — because recent licences and in‑principle approvals show how the process works in the real world, not just on paper.

Point Details Three regulators, three perimeters Dubai’s VARA covers the Emirate of Dubai (not DIFC), ADGM’s FSRA covers its free zone in Abu Dhabi, and the federal SCA regulates virtual-asset activity elsewhere onshore. Location and business model decide your path Your entity’s legal home and product set determine whether you fall under VARA, ADGM/FSRA, or SCA — you don’t “pick” a regulator without picking a jurisdiction and scope. Licensing steps are staged In‑principle approvals come first, then conditions, then a full operational licence. Recent examples: Revolut and Triple‑A received IPAs from VARA, while Flipster earned a full exchange licence. Substance matters Expect local incorporation, real decision-makers in the UAE, and a named compliance lead. Paper entities and light headcount plans don’t clear review. Compliance is non‑negotiable AML/CTF, Travel Rule, custody controls, market abuse, incident response — you need the stack documented and implemented before going live. Active pipeline More than 100 UAE VASPs are licensed across the three regimes, signaling room to get approved if you meet the bar.

Three supervisors, one map: VARA, ADGM/FSRA, and SCA

Dubai’s VARA

VARA is Dubai’s dedicated virtual-asset regulator. It oversees crypto activity across the Emirate of Dubai, including most free zones, but not the DIFC. Licences are activity-based — think advisory, broker‑dealer, custody, exchange, lending/borrowing, management and investment services, and transfer/settlement. If you want to run a consumer exchange or broker for Dubai residents, this is usually where you land.

Recent moves show the cadence: on July 15, 2026, Triple‑A said it received an In‑Principle Approval from VARA for broker‑dealer services (Triple‑A (company newsroom)). The same day, Revolut’s in‑principle approval across broker‑dealer, management and investment, and exchange activities was reported (GulfBusiness). And by July 28, 2026, Flipster announced it had secured a full operational Exchange licence from VARA (PR Newswire (Flipster announcement)). That’s a neat snapshot of “IPA to full” in practice.

ADGM’s FSRA

Up in Abu Dhabi, the ADGM free zone has its own financial regulator, the FSRA. If you incorporate inside ADGM and target institutional or retail clients (subject to permissions), the FSRA is your supervisor. The toolkit mirrors traditional markets: exchanges are usually authorised as Multilateral Trading Facilities, brokers as dealing/arranging entities, and custodians under the custody permission. The FSRA regime is mature, prescriptive, and tends to feel familiar to firms with prior securities regulation experience.

The federal SCA

Outside Dubai/VARA and outside ADGM, the federal Securities and Commodities Authority (SCA) is the perimeter. If you operate onshore in the other emirates or in free zones that don’t have their own virtual-asset regulator, you’re likely looking at SCA permissions for exchanges, brokers, custodians, and related services, paired with local economic licences.

Zooming out, there’s real activity across all three regimes. As of August 1, 2026, a UAE VASP Licence Tracker counted 100+ licensed virtual-asset entities overall, including 50+ under VARA and 35+ under ADGM/FSRA (NeosLegal (UAE VASP License Tracker)).

Pro tip: Pick the regulator by first picking your customer base and your entity’s legal home. The perimeter follows those two decisions, not the other way around.

Which licence fits your business model?

Think activity first. Regulators care about what you actually do, who you do it for, and how you custody client assets. Here’s the shorthand most teams use when scoping.

Business activity Typical permission name Where this often sits Spot exchange for retail Exchange/MTF (Virtual Assets) VARA or ADGM/FSRA; SCA for onshore outside these zones Order-routing, RFQ, OTC Broker‑Dealer / Dealing as Agent VARA or ADGM/FSRA; SCA if onshore elsewhere Investment products, staking‑like yields Management & Investment / Dealing VARA or ADGM/FSRA, with tight disclosure and risk controls Custody for institutions Custody (Virtual Assets) VARA, ADGM/FSRA, or SCA depending on client base and entity location Wallets and settlement rails Transfer & Settlement / Money Services tie‑ins Often paired with payments permissions; mind Central Bank interfaces

Two design questions decide half your application:

  • Do you hold client assets or run non‑custodial flows? Custody flips your risk profile, capital, insurance, and tech controls up several notches.

  • Are your clients retail, pro/qualified, or purely institutional? Expect sharper suitability, disclosures, and product limits for retail.

In‑principle to full licence: what the UAE process looks like

Across VARA, ADGM/FSRA, and SCA, the rhythm is similar: pre‑application chats, formal submission, an in‑principle approval with conditions, then go‑live authorisation after you meet those conditions. The labels differ slightly, but the checkpoints rhyme.

  1. Scope and scoping call. You confirm your activity set, target market, and group structure. Expect early feedback if your plan obviously mismatches the perimeter.

  2. Entity and people. You incorporate in the relevant jurisdiction and propose your board, senior management, and compliance lead. Regulators in the UAE evaluate individuals, not just entities.

  3. Application pack. Business plan, risk assessment, compliance program, AML/CTF framework, product disclosures, client asset model, tech architecture, vendor list, incident response, outsourcing register, and financial resources plan.

  4. In‑principle approval. If the plan holds water, you’ll receive an IPA that spells out conditions to meet before going live. Recently, both Triple‑A and Revolut announced VARA IPAs, an example of this step in motion (Triple‑A (company newsroom); GulfBusiness).

  5. Conditions phase. Typical asks include final policies, data‑loss playbooks, Travel Rule integration, chain analytics agreements, sandbox/UAT results, external audits of security controls, and proof of key hires on payroll.

  6. Operational authorisation. Once conditions are closed, you receive the full licence to launch. Flipster’s July 28, 2026 announcement of a full VARA exchange licence is a clean example (PR Newswire (Flipster announcement)).

  7. Post‑launch supervision. Periodic reporting, capital/solvency monitoring where applicable, product change notifications, and on‑site reviews.

Timelines vary wildly. Teams that show working code, a production‑ready compliance stack, and experienced control functions tend to move faster. Greenfield builds or complex cross‑border groups should budget more time.

Pro tip: Treat the IPA like a binding term sheet. If conditions require you to change the product, plan for that early — retrofitting later burns runway.

Entity setup, substance, and people

Regulators in the UAE want real firms, not letterheads. That’s good for market integrity but it means more upfront work.

  • Local incorporation and office. You’ll need an entity in the chosen jurisdiction and an office that fits your size. Virtual offices don’t cut it once you scale.

  • Board and senior management. Expect fitness and propriety checks. The chair, CEO/GM, MLRO/Head of Compliance, and CTO/CISO equivalents should be named and available for interviews.

  • Headcount and org chart. Map control functions to humans, not just vendors. Outsourcing is fine, but accountability can’t be outsourced.

  • Policies that match reality. Regulators will ask how you actually do onboarding, monitoring, key management, and incident response. Copy‑paste manuals get spotted.

  • Group clarity. If you’re part of a global group, show who does what, where assets sit, and how intra‑group outsourcing and data flows are controlled.

Pro tip: Put the MLRO/Head of Compliance in seat early. Nothing unblocks an application faster than having the person who will run controls help design them.

Compliance stack: AML, Travel Rule, custody, and tech controls

This is where applications live or die. Build your control stack like you’ll actually have to use it on a bad day, because you will.

  • Customer due diligence. Risk‑based KYC with enhanced checks for PEPs, high‑risk geographies, mixers, and privacy tools. Document your non‑face‑to‑face controls.

  • Sanctions and screening. Real‑time screening, list management, and alert triage. Cover UN and local lists at a minimum; tune for false positives now, not later.

  • Travel Rule compliance. Plan for VASP discovery, secure data exchange, and fallbacks when counterparties can’t receive. UAE regulators expect working solutions, not promises.

  • On‑chain monitoring. Use analytics to score deposits, detect peel chains, and flag scam typologies. Ring‑fence risky flows or route to manual review.

  • Custody and key management. Segregate client assets from firm assets, use multi‑sig or HSMs, define key ceremonies, and keep a disaster recovery drill log.

  • Market integrity. Surveillance for spoofing, layering, wash trades, and cross‑venue manipulation — even if you’re spot only. Write it down, wire it in.

  • Incident response. Who declares an incident, who talks to clients, how you freeze accounts, and when you notify the regulator. Make the runbook readable.

  • Reporting. Prepare to file suspicious transaction reports via the UAE FIU portal and to deliver periodic regulatory reports as required by your licence.

Pro tip: Test your Travel Rule and sanctions stack against your own deposit addresses and a few “messy” test flows. Better to break it in staging than on a Thursday at 11 p.m.

Banking and fiat rails: what changes under central bank oversight

Crypto licences don’t automatically grant banking powers. If you want to hold client fiat, issue stored value, or provide payment services, you’ll interface with the Central Bank of the UAE, either directly (if you pursue payments permissions) or indirectly through sponsor banks and authorised payment providers.

Three practical realities to plan for:

  • Bank selection is a project. Some banks are building crypto risk teams; others are not there yet. Start early and expect detailed onboarding due diligence.

  • Product design matters. If your flow looks like remittance or e‑money, expect central‑bank‑style controls layered on top of your VASP obligations.

  • Reconciliations and trust accounts. Map how you segregate client fiat, who can touch it, and how you reconcile daily. Auditors will ask, and so will supervisors.

Risk reminder: Even with local permissions, cross‑border fiat or stablecoin flows can trigger overseas rules. Sanctions, reporting, and promotional restrictions don’t stop at the UAE border.

Common pitfalls that slow or sink applications

  • “We’ll build it after IPA.” Regulators expect working controls before going live. Use the conditions phase to finish, not to start.

  • Vague custody plans. If you say “cold storage,” show the flow, the quorum, and the vault. If you use a third‑party custodian, show the contract and audits.

  • Global products, local rules. Marketing from overseas into Dubai or onshore UAE usually needs local authorisation. Don’t assume passporting.

  • Under‑scoped headcount. A part‑time MLRO won’t fly if you plan retail scale. Right‑size compliance and security early.

  • Messy group structures. Hidden control, opaque funding, or offshore‑only governance sets off alarms.

  • Ignoring Travel Rule reality. If your counterparties can’t receive Travel Rule data, what’s your policy? You need one.

Pro tip: Run a red‑team review of your own application. Ask someone uninvolved to poke holes in policies, diagrams, and staffing. Fix the gaps before the regulator finds them.

“UAE LICENSED VASPs – ECOSYSTEM MAP” (updated Aug 1, 2026) — visual map showing licensed VASPs by activity and regulator (VARA, ADGM/FSRA, DFSA/DIFC, CMA, CBUAE), useful to see which firms are licensed where and how licensing responsibilities are split. — Source: NeosLegal

Costs, timing, and roadmap planning

No two applications take the same path. A lean OTC desk for professional clients is not the same lift as a retail exchange with custody. That said, a few planning anchors help:

  • Budget for multiple rounds of Q&A. Detailed follow‑ups are normal. Treat them like design reviews, not hurdles.

  • Expect several months from scoping to decision, longer if your product or group is complex. Build buffers; don’t plan launches to the week.

  • Stage your market entry. Many firms start with broker‑dealer permissions, then add exchange or custody once the core stack and team are bedded in.

  • Sequence vendors. Pick Travel Rule, analytics, and custody technology early so you can evidence integration during review.

  • Keep a change log. When the product inevitably shifts, update your risk assessment and manuals. Surprises are a bad look in supervision.

If you need a sanity check on whether the path is actually viable right now, the licensing tape helps. New IPAs and a steady drip of full licences — from Revolut and Triple‑A’s VARA IPAs to Flipster’s operational approval — suggest the door is open for teams who can meet the standard (GulfBusiness; Triple‑A (company newsroom); PR Newswire (Flipster announcement)).

Frequently Asked Questions

Do I need licences from more than one UAE regulator?

Usually no. You’re supervised by the regulator where your licensed entity sits and where your activity occurs. If you operate in Dubai, VARA is your venue; in ADGM, the FSRA; onshore elsewhere, the SCA. Groups with multiple entities might hold more than one licence if they serve different segments.

Can an ADGM‑licensed firm serve customers in Dubai?

It depends on permissions, client type, and marketing rules. Cross‑border servicing within the UAE can be sensitive. Many firms set up the entity in the jurisdiction where their target clients are based to avoid gray areas. If you plan to market to Dubai residents, talk to VARA early.

What’s the practical difference between an in‑principle approval and a full licence?

An IPA means the regulator is comfortable with your plan but you still have conditions to meet before going live. A full licence means you’ve met those conditions and can operate. Examples: Revolut and Triple‑A reported VARA IPAs in July 2026, while Flipster announced a full VARA exchange licence later that month.

Do I need local staff, or can I outsource everything?

Expect meaningful substance. Key roles — senior management and compliance in particular — should sit in the UAE. Outsourcing is fine for tooling and some functions, but accountability and decision‑making must live inside the licensed entity.

How are client assets protected under UAE licences?

Rules require segregation of client assets from firm assets, documented key management, and robust custody controls. Many firms supplement this with insurance and third‑party audits. Your exact obligations depend on your permission set.

How long does licensing take?

There’s no standard clock. Factors include product complexity, readiness of your compliance and tech stack, and responsiveness to regulator Q&A. Plan for months, not weeks, and build buffer into your roadmap.

Where does DIFC fit into this?

DIFC is a separate financial free zone in Dubai with its own regulator. VARA does not cover DIFC. If you’re considering DIFC, check its current scope carefully, as its treatment of virtual‑asset activities differs from VARA and ADGM.

Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.