← Regulations / Germany / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Germany

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Germany with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • KYC verification of all transaction parties' identities under GwG (German Money Laundering Act)
  • Transaction monitoring obligations per GwG AML/CFT requirements
  • Travel rule compliance under KryptoWTransferV (Crypto Asset Transfer Regulation) — originator/beneficiary identification for crypto transfers
  • Full adherence to German Money Laundering Act (GwG) for customer identification and transaction monitoring
  • BaFin supervision for AML compliance as CASP/custody licensee

Key Restrictions

  • Must be licensed as a crypto custodian (Kryptoverwahrgeschaeft) under KWG § 1(1a) Sentence 2 No. 6 — EUR 125,000 minimum capital
  • Must establish a German legal entity (GmbH, AG, or bank) with proper corporate governance
  • Complete segregation of client and proprietary crypto assets required (no co-mingling)
  • Professional liability insurance minimum €1,000,000 covering custody service operation risks
  • IT security procedures per BAIT (BaFin Guidance on IT Requirements) including encryption, access controls, and incident response
  • CASP authorization under MiCA is also applicable — transition from pre-MiCA KWG regime to MiCA within 12-month transition period

Key Risks

  • BaFin known for thorough/slow processing — 6-12 month licensing timeline
  • AML obligations apply to the licensed custodian (SaaS operator); white-label clients may introduce shared AML responsibility and regulatory uncertainty regarding cascading KYC
  • IT security and BAIT/DORA compliance burdens are high — operational complexity for SaaS operators managing multi-tenant key infrastructure
  • Ambiguity around whether the SaaS operator's corporate clients need separate CASP licenses if they control the wallet front-end
  • €125,000 minimum capital may be insufficient for operational scale, BaFin may require higher capital on assessment

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 40% confidence

BaFin — CASP authorization (MiCA), crypto custody licensing (Kryptoverwahrgeschaeft) — pioneer since Jan 2020, ~40 entities hold/applied

licensing 20% confidence

Kreditwesengesetz (KWG) — Banking Act (2020) — Crypto custody license (Kryptoverwahrgeschaeft) — EUR 125,000 minimum

licensing 20% confidence

VASP: CASP authorization under MiCA via BaFin. Pre-MiCA crypto custody license also in effect. BaFin 12-month transition period. 6-12 months (BaFin known for thoroughness/slower processing). Requires detailed business plans and IT security concepts (BAIT/DORA).

licensing 20% confidence

CUSTODY: Crypto custody license (Kryptoverwahrgeschaeft) under KWG — EUR 125,000 minimum capital. ~40 entities hold or have applied.

licensing 20% confidence

German Banking Act (KWG): Since January 2020, crypto custody has been regulated as a financial service requiring a BaFin license.

licensing 20% confidence

Markets in Crypto-Assets Regulation (MiCAR): Applies EU-wide as of the end of 2024, establishing harmonized licensing requirements for crypto-asset service providers throughout the EU.

licensing 20% confidence

Safekeeping, administration, and safeguarding of crypto assets or private keys

licensing 20% confidence

Fit-and-proper requirements: At least one managing director must be reliable, sufficiently qualified, and experienced in crypto custody business.

licensing 20% confidence

Professional liability insurance: Minimum €1,000,000 covering custody service operation risks.

licensing 20% confidence

IT security procedures: Per BAIT (BaFin Guidance on IT Requirements), including encryption, access controls, and incident response.

licensing 20% confidence

Customer asset segregation: Complete separation of client and proprietary crypto assets required.

licensing 20% confidence

AML/CFT compliance: Full adherence to the German Money Laundering Act (GwG) with customer identification and transaction monitoring.

licensing 20% confidence

Know Your Customer (KYC): Verification of all transaction parties' identities.

licensing 20% confidence

Establishing a German legal entity (GmbH, AG, or bank) with proper corporate governance

licensing 20% confidence

Preparing a comprehensive business plan describing crypto custody offerings, technology platform, and security procedures

licensing 20% confidence

Documenting capital adequacy with €125,000 minimum through bank accounts and audited financial statements

licensing 20% confidence

German Banking Act (KWG): § 1(1a) Sentence 2 No. 6

licensing 20% confidence

Markets in Crypto-Assets Regulation: EU 2023/1114

aml 40% confidence

GwG (Money Laundering Act): Core national law incorporating EU AML Directives (e.g., AMLD5), covering obliged entities like CASPs for ML/TF prevention.

aml 40% confidence

KWG (Banking Act): Requires BaFin licensing (section 32) for crypto custody business, exchange services, and related financial activities.

aml 40% confidence

KMAG (Crypto Markets Supervision Act): Implements MiCAR domestically, granting BaFin powers for CASP licensing, supervision, and public warnings.

aml 40% confidence

KryptoWTransferV (Crypto Asset Transfer Regulation): Enforces the EU "travel rule" for crypto transfers, requiring originator/beneficiary identification.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
high

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet/SaaS operators must obtain a KWG crypto custody license (Kryptoverwahrgeschaeft) from BaFin with €125k minimum capital, establish a German legal entity, segregate client assets, carry €1M professional liability insurance, and comply with full GwG AML obligations including travel rule; transition to MiCA CASP authorization applies.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?