← Regulations / Germany / Operating Models / On-shore VASP

On-shore VASP in Germany

Locally-incorporated VASP that operates under full local jurisdiction, holding all required licenses and registrations.

Conditional AI-Generated · Unreviewed

On-shore VASP is conditionally permitted in Germany with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Full adherence to the German Money Laundering Act (GwG) for obliged entities like CASPs — customer identification and transaction monitoring required.
  • KYC: Verification of all transaction parties' identities.
  • Travel Rule compliance under KryptoWTransferV (Crypto Asset Transfer Regulation) — no threshold (EUR 0); must share originator's account/public key and beneficiary's name and account/public key.
  • AML/CFT compliance supervised by BaFin under KMAG (Crypto Markets Supervision Act).
  • Criminal Code (StGB) sanctions apply for violations.

Key Restrictions

  • Must establish a German legal entity (e.g., GmbH, AG, or bank) with proper corporate governance.
  • BaFit-and-proper requirement: at least one managing director must be reliable, sufficiently qualified, and experienced in crypto custody business.
  • Professional liability insurance of minimum €1,000,000 required.
  • IT security procedures per BAIT (BaFin Guidance on IT Requirements) — encryption, access controls, incident response.
  • Customer asset segregation: complete separation of client and proprietary crypto assets required.
  • Minimum capital requirements vary by activity type: €125,000 for custody (Kryptoverwahrgeschaeft) under KWG, €150,000 for trading platforms under MiCA CASP authorization.
  • Transition arrangements: Pre-MiCA license holders benefit from a 12-month BaFin transition period under MiCA.

Key Risks

  • BaFin is known for thoroughness and slower processing — authorization can take 6–12 months.
  • Dual regulatory framework (KWG pre-MiCA + MiCA CASP) creates complexity and potential gaps during transition.
  • High IT security and operational resilience expectations (BAIT/DORA) impose significant compliance cost.
  • Travel Rule compliance without standardized protocols may require bespoke technical solutions with risk of BaFin scrutiny.
  • Corporate taxation (15% + trade tax) and FIFO accounting for crypto inventory create administrative burden for VASPs.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 40% confidence

BaFin — CASP authorization (MiCA), crypto custody licensing (Kryptoverwahrgeschaeft) — pioneer since Jan 2020, ~40 entities hold/applied

licensing 20% confidence

MiCA Regulation (EU) (2023) — CASP authorization, comprehensive crypto regulation

licensing 20% confidence

Kreditwesengesetz (KWG) — Banking Act (2020) — Crypto custody license (Kryptoverwahrgeschaeft) — EUR 125,000 minimum

licensing 20% confidence

VASP: CASP authorization under MiCA via BaFin. Pre-MiCA crypto custody license also in effect. BaFin 12-month transition period. 6-12 months (BaFin known for thoroughness/slower processing). Requires detailed business plans and IT security concepts (BAIT/DORA).

licensing 20% confidence

CUSTODY: Crypto custody license (Kryptoverwahrgeschaeft) under KWG — EUR 125,000 minimum capital. ~40 entities hold or have applied.

licensing 20% confidence

EXCHANGE: CASP authorization under MiCA — EUR 150,000 minimum capital for trading platforms

licensing 20% confidence

Federal Financial Supervisory Authority (BaFin): Germany's primary financial regulator responsible for licensing and supervising all crypto-asset service providers, including exchanges and custodians. BaFin enforces compliance with national laws and EU regulations, focusing on consumer protection and anti-money laundering measures.

licensing 20% confidence

German Banking Act (KWG): Since January 2020, crypto custody has been regulated as a financial service requiring a BaFin license.

licensing 20% confidence

Fit-and-proper requirements: At least one managing director must be reliable, sufficiently qualified, and experienced in crypto custody business.

licensing 20% confidence

Professional liability insurance: Minimum €1,000,000 covering custody service operation risks.

licensing 20% confidence

IT security procedures: Per BAIT (BaFin Guidance on IT Requirements), including encryption, access controls, and incident response.

licensing 20% confidence

Customer asset segregation: Complete separation of client and proprietary crypto assets required.

licensing 20% confidence

AML/CFT compliance: Full adherence to the German Money Laundering Act (GwG) with customer identification and transaction monitoring.

licensing 20% confidence

Know Your Customer (KYC): Verification of all transaction parties' identities.

licensing 20% confidence

Establishing a German legal entity (GmbH, AG, or bank) with proper corporate governance

licensing 20% confidence

Preparing a comprehensive business plan describing crypto custody offerings, technology platform, and security procedures

licensing 20% confidence

Documenting capital adequacy with €125,000 minimum through bank accounts and audited financial statements

aml 40% confidence

GwG (Money Laundering Act): Core national law incorporating EU AML Directives (e.g., AMLD5), covering obliged entities like CASPs for ML/TF prevention.

aml 40% confidence

KWG (Banking Act): Requires BaFin licensing (section 32) for crypto custody business, exchange services, and related financial activities.

aml 40% confidence

KMAG (Crypto Markets Supervision Act): Implements MiCAR domestically, granting BaFin powers for CASP licensing, supervision, and public warnings.

aml 40% confidence

KryptoWTransferV (Crypto Asset Transfer Regulation): Enforces the EU "travel rule" for crypto transfers, requiring originator/beneficiary identification.

aml 40% confidence

Additional: Criminal Code (StGB) for sanctions; MiCAR for EU-wide standards (phased in by end-2024).

travel-rule 20% confidence

Travel Rule adopted — threshold: EUR 0 (no threshold under TFR recast)

travel-rule 60% confidence

§3 KryptoTransferV mandates sharing: originator's account (e.g., public key), beneficiary's name and account (e.g., public key).

travel-rule 60% confidence

In absence of standardized protocols, VASPs can receive grace periods up to one year, with risk mitigation like restricting transfers; no suspension if technical setup exists.

travel-rule 60% confidence

Based on EU Regulation 2015/847, prohibiting unaccompanied client/recipient info transmission.

travel-rule 60% confidence

Crypto Securities Transfer Regulation (KryptoTransferV): Primary law, detailed in German Federal Ministry of Finance draft (English translation via DeepL).

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
high

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a locally-incorporated on-shore VASP may operate in Germany, but must obtain either a crypto custody license under KWG (€125k capital) or CASP authorization under MiCA (€150k for trading) from BaFin, with a 6–12 month application process, full AML/GwG compliance, travel rule adherence, €1M professional liability insurance, BAIT IT security, fit-and-proper management, and customer asset segregation.

Questions this verdict aims to answer

  • What license(s) are required to operate locally?
  • What capital, governance, and reporting obligations apply?
  • What is the application process and timeline?