Manimama hero

DLT Provider Authorization in Gibraltar

Obtain a DLT Provider Authorization in Gibraltar for your crypto exchange, custody, wallet infrastructure, virtual asset platform or DLT-based business with full legal, regulatory and compliance support from Manimama.

hero-background

Gibraltar has a dedicated regulatory framework for businesses that use distributed ledger technology to store or transmit value belonging to others. A DLT Provider Authorization, supervised by the Gibraltar Financial Services Commission, gives crypto and virtual asset businesses a regulated foundation focused on governance, client asset protection, AML/CFT controls, cybersecurity, operational resilience and long-term regulatory supervision.

Key regulatory highlights of DLT Provider Authorization in Gibraltar

Gibraltar offers a dedicated and principles-based regulatory framework for businesses using distributed ledger technology to store or transmit value belonging to others. The authorization process is supervised by the Gibraltar Financial Services Commission (GFSC). It focuses on the applicant’s real business model, governance, capital, financial crime controls, technology, cybersecurity, safeguarding of customer assets, and operational resilience.

Regulator

DLT Providers in Gibraltar are authorized and supervised by the Gibraltar Financial Services Commission — GFSC.

Legal framework

The regime is based on the Financial Services Act 2019 and the Financial Services (DLT Providers and VAA Providers) Regulations 2020.

Authorisation scope

Authorization may be required where a business uses DLT, in or from Gibraltar, to store or transmit value belonging to others.

Suitable activities

The framework may apply to crypto exchanges, custodial wallet providers, institutional custody businesses and platforms that hold, control, safeguard or transfer virtual assets for clients.

Non-custodial exclusion

A business does not require DLT Provider Authorization merely because it develops or uses blockchain technology, if it does not store, control or transmit value belonging to others.

Application process

The GFSC uses a staged application process covering business model, capital, key individuals, risk management, IT systems, governance, financial crime controls, compliance and operational readiness.

Estimated timeline

The GFSC aims to progress applications through the first three stages within a maximum period of 9 months, depending on application quality and responsiveness.

Director requirement

A private company must have at least 1 director, while other companies must have at least 2 directors.

Corporate income tax

The standard corporate income tax rate in Gibraltar is 15%.

Tax position

Gibraltar does not operate a VAT system and does not impose capital gains tax.

Why crypto and DLT businesses may need authorization in Gibraltar

A DLT Provider Authorization in Gibraltar gives businesses a regulated legal basis to use distributed ledger technology to store or transmit value belonging to others. It helps companies demonstrate regulatory credibility, governance maturity, AML/CFT readiness, customer asset protection, and operational resilience under the supervision of the Gibraltar Financial Services Commission (GFSC).

Authorization confirms that the business is permitted to operate within Gibraltar’s DLT regulatory framework.

The framework is especially relevant for businesses that hold, control, safeguard or transfer value belonging to clients or third parties.

GFSC authorization can strengthen the company’s profile when working with banks, institutional clients, investors and professional counterparties.

The authorization process helps determine whether the business falls within the DLT Provider regime based on its actual operating model, not just its commercial name.

Gibraltar can be suitable for exchanges, custodial wallet providers, custody businesses, settlement platforms and other DLT-based structures involving third-party value.

The framework requires effective corporate governance, risk management, internal controls and oversight of outsourced or material outsourced functions.

Applicants must demonstrate financial crime controls, customer due diligence, transaction monitoring and AML/CFT procedures appropriate to the risks of the business.

For businesses prepared to establish a substantive regulated operation, Gibraltar can provide a stable framework for scaling DLT-based activities under ongoing GFSC supervision.

What activities can be covered by a Gibraltar DLT Provider Authorization?

A Gibraltar DLT Provider Authorization allows a business to operate under GFSC supervision where it uses distributed ledger technology, in or from Gibraltar, to store or transmit value belonging to others. The exact scope depends on the substance of the business model, including who controls client assets, who manages private keys, how transactions are executed and what role the Gibraltar entity performs in the overall value flow.

Authorization may be relevant for crypto exchanges that use DLT to transmit or store value belonging to clients or other third parties.

The framework may apply to wallet providers that hold, control or safeguard client assets or private keys.

Businesses providing custody infrastructure for institutional clients may fall within the DLT Provider regime if they control or safeguard third-party value.

Authorization may be required where the Gibraltar entity is involved in transmitting value between parties using DLT.

Platforms that hold, control, safeguard or transfer virtual assets on behalf of clients may require DLT Provider Authorization.

The regime may apply to settlement or transaction-flow models where the Gibraltar entity plays a role in the storage or transmission of third-party value.

The authorization can support group models where the Gibraltar company performs a regulated DLT function within a broader crypto or fintech structure.

Where the business controls customer value, the authorization framework requires proper safeguarding arrangements, including controls over wallets, private keys, custody infrastructure and third-party providers.

Who regulates DLT Providers in Gibraltar?

DLT Providers in Gibraltar are authorized and supervised by the Gibraltar Financial Services Commission — GFSC. The regime is based on the Financial Services Act 2019 and the Financial Services (DLT Providers and VAA Providers) Regulations 2020, creating a dedicated framework for businesses that use distributed ledger technology to store or transmit value belonging to others.

Regulatory authority

The competent authority for DLT Provider Authorization is the Gibraltar Financial Services Commission (GFSC).

Legal basis

The framework operates under the Financial Services Act 2019 and the Financial Services (DLT Providers and VAA Providers) Regulations 2020.

Principles-based regulation

Gibraltar applies a principles-based approach, meaning the GFSC assesses the substance of the business model rather than only the name or category of the service.

Regulatory perimeter

Authorization may be required where a business uses DLT, in or from Gibraltar, for the storage or transmission of value belonging to others.

Business model assessment

The GFSC reviews the applicant’s services, group structure, target market, transaction flows, strategy and the role of the Gibraltar entity.

Governance review

The regulator assesses controllers, shareholders, directors, key individuals, internal governance, risk management and oversight arrangements.

Financial crime controls

Applicants must demonstrate AML/CFT controls, customer due diligence, transaction monitoring and other financial crime prevention measures.

Technology and resilience

The framework requires detailed attention to IT infrastructure, cybersecurity, systems architecture, outsourcing, business continuity and disaster recovery.

Customer asset protection

Where the business holds or controls customer assets, the GFSC expects clear safeguarding arrangements, including wallet access controls, private key management and custody procedures.

Ongoing supervision

After authorization, the DLT Provider remains subject to GFSC supervision and may be reviewed through reporting, regulatory engagement and post-authorization onsite visits.

Who needs a Gibraltar DLT Provider Authorization?

A Gibraltar DLT Provider Authorization may be required for businesses that use distributed ledger technology, in or from Gibraltar, to store or transmit value belonging to others. The requirement depends on the actual operating model, including whether the company holds, controls, safeguards or transfers client assets, rather than on the commercial name of the service.

Crypto exchanges

Businesses that facilitate crypto or virtual asset exchange and are involved in storing, controlling or transmitting client value.

Custodial wallet providers

Wallet businesses that hold or control client assets, private keys or instruments enabling access to virtual assets.

Institutional custody providers

Companies offering custody infrastructure for funds, institutions, professional investors or other clients.

Virtual asset platforms

Platforms that hold, control, safeguard or transfer virtual assets on behalf of clients or third parties.

DLT-based transfer businesses

Businesses that use distributed ledger technology to transmit value between parties in or from Gibraltar.

Settlement infrastructure providers

DLT-based settlement or transaction-flow structures where the Gibraltar entity plays an active role in storing or transmitting third-party value.

Group crypto structures

International crypto or fintech groups where the Gibraltar entity performs the regulated DLT function inside a broader operating model.

Businesses with client asset control

Any business model where the key regulatory question is who controls client assets, private keys, transaction execution and value flow.

How Manimama supports Gibraltar DLT Provider Authorization applicants

Manimama provides end-to-end legal, regulatory and compliance support for businesses applying for DLT Provider Authorization in Gibraltar. We help assess whether the business falls within the DLT regulatory perimeter, prepare the staged GFSC application package, structure governance and compliance frameworks, and support the applicant through the authorization process and post-authorization readiness.

block

Business model assessment

We analyze the proposed DLT business model, services, transaction flows, target markets, and the role of the Gibraltar entity to determine whether DLT Provider Authorization is required.

block

Regulatory perimeter analysis

We assess whether the company stores, controls, safeguards or transmits value belonging to others, and whether the model falls within the Gibraltar DLT Provider regime.

block

Authorization roadmap

We prepare a clear authorization roadmap covering Stage 1, Stage 2, Stage 3, possible GFSC presentation, mobilization and post-authorization readiness.

Business plan preparation

We assist with preparing the bespoke DLT Comprehensive Business Plan, including business model, group structure, strategy, services, target market and financial projections.

block

Controllers and key persons support

We help prepare Controller Forms, source of wealth and source of funds materials, and supporting information for shareholders, controllers, directors and key individuals.

block

Governance and risk framework

We support the preparation of governance documents, internal controls, risk methodology, risk register, management responsibilities and oversight procedures.

block

AML/CFT and financial crime documentation

We prepare or review AML/CFT policies, customer due diligence procedures, transaction monitoring controls and financial crime prevention documents.

block

Technology and cybersecurity support

We assist with documentation on IT infrastructure, systems architecture, cybersecurity, business continuity, disaster recovery and operational resilience.

Customer asset safeguarding

For custody or client asset control models, we help document safeguarding arrangements, private key management, wallet access controls, hot and cold storage setup and custody procedures.

How Manimama guides you through the Gibraltar DLT Provider Authorization process

We follow a structured process that helps DLT and crypto businesses move from initial regulatory assessment to GFSC application preparation, staged review, authorization and post-authorization readiness. Each step is designed to align the business model, governance, financial crime controls, technology, customer asset safeguarding and operational framework with Gibraltar’s DLT Provider requirements.

1. Initial consultation

We discuss your business model, DLT use case, target markets, client asset flow, custody setup, technology infrastructure and the role of the Gibraltar entity.

3. Authorization roadmap

We prepare a clear roadmap for the staged GFSC process, including Stage 1, Stage 2, Stage 3, possible presentation, mobilization and post-authorization readiness.

5. Stage 1 application support

We assist with the application form, Stage 1 DLT Comprehensive Business Plan, Controller Forms, source of wealth and source of funds materials.

7. Stage 3 operational readiness support

We assist with conduct of business documents, terms and conditions, risk warnings, fee schedule, compliance structure, conflicts of interest, complaints handling and operational policies.

2. Regulatory perimeter assessment

We determine whether the company uses DLT in or from Gibraltar to store or transmit value belonging to others and whether DLT Provider Authorization is required.

4. Business model and structure preparation

We help define the business model, group structure, services, target market, transaction flows, capital position and role of key individuals.

6. Stage 2 documentation support

We prepare or review documentation covering risk management, governance, AML/CFT, financial crime controls, IT systems, cybersecurity, outsourcing, business continuity and customer asset safeguarding.

8. GFSC communication support

We help coordinate communication with the GFSC, prepare responses to regulator comments and support the applicant throughout the staged review process.

Start Your Gibraltar DLT Provider Authorisation Process Today

Receive complete legal and regulatory support for your Gibraltar DLT Provider Authorisation — from regulatory perimeter assessment and business model structuring to staged GFSC application preparation, AML/CFT documentation, cybersecurity framework, customer asset safeguarding and post-authorisation readiness.

Manimama helps crypto exchanges, custodial wallet providers, institutional custody businesses, DLT-based platforms and virtual asset infrastructure providers prepare for Gibraltar authorisation with clear governance, suitable controllers and key individuals, financial crime controls, outsourcing oversight, operational resilience and customer asset protection measures.

Get Free Consultation

Gibraltar DLT Provider Authorization Requirements & Application Roadmap

Understand the key business models, company requirements, personnel obligations, capital, documents, timelines, tax rules, and practical risks before applying for a Gibraltar DLT Provider Authorization.

What business models are suitable for a Gibraltar DLT Provider Authorization?

A Gibraltar DLT Provider Authorization may be suitable for businesses that use distributed ledger technology to store, control, safeguard or transmit value belonging to clients or other third parties. The GFSC assesses the substance of the operating model, including control over client assets and private keys, transaction execution, value flow and the role of the Gibraltar entity within the wider business structure.

  • Crypto exchange business

    Suitable for exchanges that use DLT infrastructure and are involved in storing, controlling or transmitting client value.

  • Custodial wallet provider

    Suitable for wallet businesses that hold client assets, manage private keys or provide infrastructure enabling control over virtual assets.

  • Institutional custody business

    Suitable for companies providing custody or safeguarding services for funds, institutions, professional investors or other third-party clients.

  • Virtual asset platform

    Suitable for platforms that hold, control, safeguard or transfer virtual assets on behalf of clients or counterparties.

  • DLT settlement infrastructure

    Suitable for businesses using DLT to support settlement, transfer or value-flow arrangements involving third-party assets.

  • Group operating structure

    Suitable for international crypto or fintech groups where the Gibraltar entity performs the regulated DLT function within a broader corporate structure.

  • Wallet infrastructure with control over assets

    Suitable for infrastructure providers that are not merely technical vendors, but have operational control over client assets, wallet access or transaction execution.

  • Complex DLT business models

    Suitable for models involving exchanges, custody, wallet infrastructure, settlement or other arrangements where the business stores or transmits third-party value using DLT.

What company structure and local presence are required for a Gibraltar DLT Provider Authorization?

To obtain DLT Provider Authorization in Gibraltar, the applicant must demonstrate that its corporate structure, ownership, key individuals, governance arrangements and operational presence are suitable for a regulated DLT business. The GFSC assesses the substance of the business model, who controls the company, who manages the regulated activity, and whether the applicant has sufficient financial and non-financial resources to operate in or from Gibraltar.

  • Gibraltar operating substance

    The business must carry on, or propose to carry on, DLT Provider business in or from Gibraltar and maintain sufficient substance appropriate to its business model.

  • Director requirement

    A private company must have at least 1 director, while other companies must have at least 2 directors.

  • Controllers and shareholders

    The applicant must provide detailed information on controllers, shareholders and ownership structure as part of the GFSC assessment.

  • Key individuals

    Directors, controllers and other key individuals must demonstrate relevant skills, experience and suitability for the proposed regulated business.

  • Source of wealth and funds

    Shareholders and controllers may need to provide evidence of source of wealth and source of funds.

  • Governance arrangements

    The company must establish effective corporate governance, internal control and risk management arrangements.

  • Operational resources

    The applicant must demonstrate sufficient financial and non-financial resources, including suitable personnel, a compliance structure, and audit, accounting, and banking arrangements.

  • Outsourcing oversight

    Where material functions are outsourced, the applicant must maintain proper contracts, risk assessment, oversight and an outsourcing register.

What personnel and compliance requirements apply to a Gibraltar DLT Provider?

A Gibraltar DLT Provider applicant must demonstrate that it has suitable controllers, shareholders, directors, key individuals, compliance resources and internal control systems to operate as a regulated business. The GFSC assesses not only the people involved, but also the company’s governance, AML/CFT framework, risk management, technology resilience, outsourcing controls and customer asset protection arrangements.

  • Controllers and shareholders

    The applicant must provide detailed information on controllers, shareholders and ownership structure, including evidence of source of wealth and source of funds where required.

  • Directors and key individuals

    Directors and other key individuals must demonstrate appropriate skills, experience, integrity and suitability for managing a regulated DLT business.

  • Compliance structure

    The company must have an appropriate compliance structure with sufficient resources to monitor regulatory obligations and internal controls.

  • AML/CFT controls

    The applicant must maintain effective financial crime controls, including AML/CFT policies, customer due diligence, transaction monitoring and risk-based procedures.

  • Risk management framework

    The company must establish a clear risk methodology, risk register, internal control framework and oversight of key business risks.

  • Technology and cybersecurity

    The GFSC expects detailed information on IT infrastructure, systems architecture, cybersecurity, operational resilience and protection of technology systems.

  • Business continuity and disaster recovery

    The applicant must maintain appropriate business continuity and disaster recovery arrangements to support stable regulated operations.

  • Customer asset safeguarding

    Where the business holds or controls customer assets, it must demonstrate proper safeguarding arrangements, wallet access controls, private key management and custody procedures.

  • Outsourcing oversight

    Material outsourcing must be documented, risk-assessed and monitored through effective oversight, contracts and an outsourcing register.

  • Conduct and customer protection

    The company must prepare appropriate terms and conditions, risk warnings, fee arrangements, complaints handling procedures and conflict-of-interest controls.

  • Audit, accounting and banking arrangements

    The applicant should demonstrate effective arrangements for audit, accounting, banking and operational financial management.

  • Operational readiness

    Before authorization, the company must show that its documented policies, systems, controls and personnel arrangements can operate effectively in practice.

What documents are required for a Gibraltar DLT Provider Authorization?

The Gibraltar DLT Provider application is document-heavy and submitted through a staged GFSC process. The file must explain the business model, ownership and control structure, capital position, key individuals, governance, AML/CFT controls, technology, cybersecurity, outsourcing, customer asset safeguarding and operational readiness.

  • Stage 1 application form

    The applicant submits the initial application form together with the required Stage 1 information and application fee.

  • DLT Comprehensive Business Plan — Stage 1

    The business plan must describe the business model, services, group structure, target market, strategy, transaction flows and the role of the Gibraltar entity.

  • Controller Forms

    Controller Forms must be prepared for each controller involved in the applicant’s ownership or control structure.

  • Source of wealth and source of funds

    Shareholders and controllers must provide evidence of source of wealth and source of funds where required.

  • Capital and financial projections

    The applicant must provide financial projections and demonstrate adequate capital and financial resources for the nature, scale and complexity of the business.

  • Governance and risk management documents

    The file should include governance arrangements, internal controls, risk methodology, risk register, management responsibilities and oversight procedures.

  • AML/CFT and financial crime documents

    The applicant must prepare AML/CFT policies, customer due diligence procedures, transaction monitoring controls and financial crime prevention documentation.

  • Technology and cybersecurity documentation

    The GFSC expects information on IT infrastructure, systems architecture, cybersecurity, operational resilience and technology controls.

  • Business continuity and disaster recovery plans

    The application should include business continuity and disaster recovery arrangements showing how the business can continue operating under disruption.

  • Customer asset safeguarding documents

    Where the business holds or controls customer assets, the file should explain private key management, wallet access controls, hot and cold storage arrangements and custody safeguards.

  • Outsourcing documents

    Material outsourcing arrangements must be documented through contracts, risk assessments, oversight procedures and an outsourcing register.

  • Conduct of business documents

    The Stage 3 package may include terms and conditions, risk warnings, proposed fee schedule, conflicts of interest framework and complaints handling policy.

  • Compliance and operational readiness documents

    The applicant should provide documents covering compliance structure, conduct risk framework, KPIs, remuneration policy, liquidity and solvency policies and relevant governance materials.

  • Regulated individual and NED forms

    Where applicable, completed forms for regulated individuals and non-executive directors may be required as part of the GFSC review.

What are the capital and financial requirements for a Gibraltar DLT Provider Authorization?

Gibraltar does not assess DLT Provider applicants only by a fixed capital number. The GFSC reviews whether the applicant has sufficient capital, financial resources, and operational resources for the nature, scale, and complexity of its business model, including its governance, technology, cybersecurity, financial crime controls, outsourcing arrangements, and customer asset safeguarding framework.

  • Adequate capital requirement

    The applicant must demonstrate that it has sufficient capital for the proposed DLT activities, taking into account the size, risk and complexity of the business.

  • Financial resources assessment

    The GFSC reviews whether the company has enough financial resources to operate safely, sustainably and in line with its regulatory obligations.

  • Financial projections

    Financial projections form part of the authorization assessment and must be consistent with the business model, growth strategy and planned operations.

  • Application fee

    The Stage 1 application package includes payment of the application fee. The exact amount should be confirmed based on the current GFSC fee schedule and the applicant’s business model.

  • Operational resource costs

    Applicants should budget for compliance, AML/CFT controls, governance, audit, accounting, banking, IT systems, cybersecurity, business continuity and professional support.

  • Customer asset safeguarding costs

    Where the business holds or controls customer assets, additional costs may arise for custody infrastructure, wallet controls, private key management, insurance, third-party provider due diligence and safeguarding procedures.

  • Outsourcing and provider costs

    Material outsourcing arrangements must be properly documented, risk-assessed and monitored, which may require external technology, custody, compliance or operational providers.

  • Professional indemnity and risk coverage

    Where applicable, the GFSC may review professional indemnity insurance and other risk coverage arrangements as part of operational readiness.

  • Corporate income tax

    The standard corporate income tax rate in Gibraltar is 15%.

  • Tax position

    Gibraltar does not operate a VAT system, does not impose capital gains tax, and generally does not impose withholding tax on dividends, interest or royalties paid by Gibraltar companies to non-residents.

How does the Gibraltar DLT Provider Authorization process work?

The Gibraltar DLT Provider Authorization process follows a staged GFSC review, starting with pre-application engagement and moving through business model, capital, key individuals, risk management, IT systems, governance, financial crime controls, conduct of business and operational readiness. The process is designed to assess not only whether the applicant fits the DLT regulatory perimeter, but also whether the company is ready to operate as a regulated business in practice.

  • 1. Pre-application engagement

    Before submitting a formal application, the applicant is encouraged to engage with the GFSC’s DLT team to discuss the proposed business model, services and activities.

  • 2. Stage 1 — Business model and key individuals

    The applicant submits Stage 1 information, including the application form, application fee, Stage 1 DLT Comprehensive Business Plan, Controller Forms, source of wealth and source of funds evidence, and information on the business model, ownership, capital and key persons.

  • 3. GFSC Stage 1 assessment

    At this stage, the GFSC focuses on understanding the proposed business model, control structure, capital position and individuals responsible for the business before allowing the application to move forward.

  • 4. Stage 2 — Risk, IT, governance and financial crime

    The applicant submits Stage 2 documentation covering risk management, corporate governance, AML/CFT, financial crime controls, IT systems, cybersecurity, business continuity, outsourcing, disaster recovery and customer asset safeguarding.

  • 5. GFSC Stage 2 review

    The GFSC reviews the applicant’s control environment and operational infrastructure, including private key management, hot and cold wallet arrangements and third-party provider due diligence where custody-related models are involved.

  • 6. Stage 3 — Conduct, compliance and operational readiness

    The applicant submits Stage 3 materials, including terms and conditions, risk warnings, fee schedule, compliance structure, conduct risk framework, KPIs, remuneration policy, conflicts of interest framework, complaints handling policy, liquidity and solvency policies.

  • 7. Comprehensive presentation to the GFSC

    Applicants may be invited to deliver a presentation covering key individuals, business model, group structure, products and services, target market, strategy, financial projections and how the company will meet the DLT regulatory principles.

  • 8. GFSC authorization decision

    Once the GFSC is satisfied with the Stage 3 information and the application as a whole, the application proceeds to a formal authorization decision.

  • 9. Mobilization period, where applicable

    Where relevant, a mobilization period may follow authorization and include systems testing, implementation checks, and further assessment of operational readiness.

  • 10. Post-authorization onsite visit

    After permission is granted, the GFSC may carry out an on-site visit to verify that the systems, processes and controls described during the application process are implemented and operating effectively.

How long does the Gibraltar DLT Provider Authorization process take?

The GFSC aims to progress DLT Provider applications through the first three stages of the authorization process within a maximum of 9 months. The actual timeline depends on the complexity of the business model, quality and completeness of the application package, readiness of the applicant’s systems and controls, and timely responses to GFSC requests.

  • 1. Pre-application engagement

    Before formal submission, the applicant may engage with the GFSC’s DLT team to discuss the proposed business model, services, activities and regulatory perimeter.

  • 2. Stage 1 — up to 5 months

    The GFSC reviews the business model, capital position, ownership and control structure, shareholders, controllers and key individuals responsible for the business.

  • 3. Stage 2 — up to 2 months

    The regulator assesses risk management, financial crime controls, business continuity, corporate governance, IT systems, cybersecurity, outsourcing and customer asset safeguarding.

  • 4. Stage 3 — up to 2 months

    The GFSC reviews non-financial resources, compliance structure, conduct of business, Consumer Duty, operational resilience and readiness to operate as a regulated business.

  • 5. Comprehensive presentation

    Applicants may be invited to present the business model, group structure, key people, target market, financial projections, products and regulatory approach to the GFSC.

  • 6. Authorization decision

    Once the GFSC is satisfied with the Stage 3 information and the application as a whole, the process moves to the formal authorization decision.

  • 7. Mobilization period

    Where applicable, a discretionary mobilization period may follow authorization and include systems testing, implementation checks and further operational readiness assessment.

  • 8. Post-authorization onsite visit

    After permission is granted, the GFSC may conduct an on-site visit to verify that the systems, processes and controls described in the application operate effectively in practice.

What are the tax and ongoing obligations after Gibraltar DLT Provider Authorization?

Gibraltar offers a clear tax framework for regulated DLT businesses, including 15% corporate income tax, no VAT, no capital gains tax, and generally no withholding tax on dividends, interest or royalties paid by Gibraltar companies to non-residents. However, after authorization, the DLT Provider remains subject to GFSC supervision and must maintain governance, AML/CFT controls, cybersecurity, customer asset safeguarding, outsourcing oversight and operational resilience on an ongoing basis.

  • Corporate income tax

    The standard corporate income tax rate in Gibraltar is 15% for most companies.

  • No VAT system

    Gibraltar does not operate a VAT system, which may simplify the tax position for certain business models.

  • No capital gains tax

    Gibraltar does not impose capital gains tax.

  • Withholding tax position

    Gibraltar generally does not impose withholding tax on dividends, interest or royalties paid by Gibraltar companies to non-residents.

  • Tax treatment depends on structure

    The actual tax treatment depends on where the company’s income is accrued or derived and on the wider operating and group structure.

  • Ongoing GFSC supervision

    After authorization, the DLT Provider remains supervised by the Gibraltar Financial Services Commission and must continue meeting regulatory expectations.

  • AML/CFT compliance

    The company must maintain effective AML/CFT controls, customer due diligence, transaction monitoring and financial crime prevention procedures.

  • Governance and risk management

    The provider must maintain effective corporate governance, internal controls, risk methodology, risk register and management oversight.

  • Technology and cybersecurity

    The company must keep appropriate IT infrastructure, cybersecurity controls, systems architecture, business continuity and disaster recovery arrangements.

  • Customer asset safeguarding

    Where the business holds or controls customer assets, it must maintain safeguarding arrangements, including wallet access controls, private key management and custody procedures.

  • Outsourcing oversight

    Material outsourcing arrangements must remain documented, risk-assessed and monitored through contracts, oversight procedures and an outsourcing register.

  • Post-authorization verification

    The GFSC may carry out an on-site visit after authorization to confirm that the systems, processes and controls described during the application are actually implemented and working in practice.

What should businesses consider before applying for Gibraltar DLT Provider Authorization?

Gibraltar is a strong jurisdiction for substantive DLT and crypto businesses, but the authorization should not be treated as a light-touch registration. The GFSC assesses the actual business model, control over client assets, governance, capital, key individuals, AML/CFT controls, technology, cybersecurity, outsourcing, customer protection and operational readiness before granting authorization.

  • Regulatory perimeter risk

    A business may need authorization if it uses DLT in or from Gibraltar to store or transmit value belonging to others. The assessment depends on substance, not on the commercial name of the service.

  • Non-custodial model limitation

    A company does not need DLT Provider Authorization only because it develops blockchain software or uses DLT. If it does not store, control or transmit third-party value, it may fall outside the regime.

  • No EU / EEA passporting

    Gibraltar is not part of the EU or EEA MiCA passporting framework. DLT Provider Authorization does not automatically allow the company to provide regulated crypto-asset services across the EU or EEA.

  • Client asset control risk

    If the business holds or controls customer assets, it must demonstrate strong safeguarding arrangements, including private key management, wallet access controls and custody infrastructure.

  • Technology and cybersecurity burden

    The GFSC expects detailed information on IT infrastructure, cybersecurity, systems architecture, business continuity, disaster recovery and operational resilience.

  • AML/CFT and financial crime expectations

    The applicant must maintain effective AML/CFT controls, customer due diligence, transaction monitoring and financial crime prevention measures proportionate to the risks of the business.

  • Outsourcing risk

    Material outsourcing is allowed, but the DLT Provider remains responsible for regulated activities and must maintain risk assessment, contracts, oversight and an outsourcing register.

  • Operational readiness check

    After authorization, the GFSC may carry out an onsite visit to verify that the systems, processes and controls described in the application are actually implemented and working in practice.

  • Application complexity

    The process is staged and document-heavy. Applicants move to the next stage only when the GFSC is satisfied with the current stage materials and responses.

  • Token sale limitation

    ICOs and token sales do not automatically fall within the DLT Provider framework only because tokens are issued using DLT. Depending on the token and structure, other financial services rules or AML/CFT registration may apply.

  • Tax structuring risk

    Gibraltar’s tax treatment depends on where income is accrued or derived and on the company’s operating and group structure.

  • Substance requirement

    The business must carry on, or propose to carry on, DLT Provider business in or from Gibraltar and maintain sufficient substance, governance and operational presence appropriate to its model.

Expert view on Gibraltar DLT Provider Authorization

“Gibraltar is not a jurisdiction for a purely formal crypto setup. It works best for businesses that are ready to demonstrate substance, strong governance and real control over operational risks. The key question is whether the company stores or transmits value belonging to others — and if it does, the application must clearly explain how client assets are protected, how private keys and wallets are managed, how AML/CFT controls work, and how the business will remain operationally resilient under GFSC supervision.”

Ganna Voievodina

CEO & Co-founder of Manimama

Frequently asked questions about Gibraltar DLT Provider Authorization

This section answers the most common questions about Gibraltar DLT Provider Authorization, including who needs authorization, what activities may fall within the regime, how the GFSC process works, whether EU/EEA passporting applies, and what compliance, substance, tax and outsourcing requirements businesses should consider.

It is a regulatory permission granted by the Gibraltar Financial Services Commission (GFSC) to businesses carrying on DLT Provider business in or from Gibraltar, including the use of DLT for the storage or transmission of value belonging to others.

DLT Providers are authorized and supervised by the GFSC under Gibraltar’s dedicated DLT regulatory framework.

The framework is based on the Financial Services Act 2019 and the Financial Services (DLT Providers and VAA Providers) Regulations 2020.

Depending on the business model, the regime may apply to crypto exchanges, custodial wallet providers, institutional custody businesses, and platforms that hold, control, safeguard, or transfer third-party value using DLT.

No. A business does not need authorization only because it develops or uses blockchain technology. A non-custodial software or technology provider may fall outside the regime if it does not store, control or transmit value belonging to others.

The main question is whether the business uses DLT in or from Gibraltar for the storage or transmission of value belonging to others. The GFSC assesses substance, including who controls client assets, private keys, transaction execution and value flow.

The GFSC aims to progress applicants through Stages 1–3 within up to 9 months, depending on the complexity of the business and the quality and completeness of the application.

The process includes pre-application engagement; Stage 1 business model and key individuals review; Stage 2 risk management and IT systems review; Stage 3 conduct and operational readiness review; a possible GFSC presentation; an authorization decision; and a possible post-authorization on-site visit.

No. Gibraltar is not part of the EU or EEA MiCA passporting framework, so the authorization does not automatically allow the company to provide regulated crypto-asset services across the EU or EEA.

Yes. Foreign ownership is generally possible, but shareholders, controllers and key individuals are subject to GFSC suitability and regulatory assessment.

The business must carry on, or propose to carry on, DLT Provider business in or from Gibraltar and should maintain sufficient substance, governance and operational presence appropriate to its business model.

Yes. Certain functions may be outsourced, but the DLT Provider remains responsible for its regulated activities and must maintain effective oversight, risk management and control over outsourced arrangements.

Gibraltar generally applies 15% CIT, has no VAT, no CGT, and generally does not impose withholding tax on dividends, interest or royalties paid by Gibraltar companies to non-residents.

ICOs and token sales do not generally fall within the DLT Provider framework only because tokens are issued using DLT. However, depending on the token and offering structure, other financial services rules or AML/CFT registration may apply.

chat

Ready to Move Forward with Your Gibraltar DLT Provider Authorization?

Tell us about your crypto exchange, custodial wallet, institutional custody, virtual asset platform or DLT-based business model. Manimama will assess whether your activity falls within the Gibraltar DLT Provider framework and prepare a clear roadmap for GFSC authorization.

What question do you want to resolve?

Other

Tokenization

Licensing

Incorporation

Other

Talk to our experts

By clicking the "Contact us" button, I confirm that I have read the Privacy Policy and agree to the collection and processing of my personal data in accordance with the General Data Protection Regulation (GDPR).