DLT Providers in Gibraltar are authorized and supervised by the Gibraltar Financial Services Commission — GFSC.
DLT Provider Authorization in Gibraltar
Obtain a DLT Provider Authorization in Gibraltar for your crypto exchange, custody, wallet infrastructure, virtual asset platform or DLT-based business with full legal, regulatory and compliance support from Manimama.
Gibraltar has a dedicated regulatory framework for businesses that use distributed ledger technology to store or transmit value belonging to others. A DLT Provider Authorization, supervised by the Gibraltar Financial Services Commission, gives crypto and virtual asset businesses a regulated foundation focused on governance, client asset protection, AML/CFT controls, cybersecurity, operational resilience and long-term regulatory supervision.
Key regulatory highlights of DLT Provider Authorization in Gibraltar
Gibraltar offers a dedicated and principles-based regulatory framework for businesses using distributed ledger technology to store or transmit value belonging to others. The authorization process is supervised by the Gibraltar Financial Services Commission (GFSC). It focuses on the applicant’s real business model, governance, capital, financial crime controls, technology, cybersecurity, safeguarding of customer assets, and operational resilience.
The regime is based on the Financial Services Act 2019 and the Financial Services (DLT Providers and VAA Providers) Regulations 2020.
Authorization may be required where a business uses DLT, in or from Gibraltar, to store or transmit value belonging to others.
The framework may apply to crypto exchanges, custodial wallet providers, institutional custody businesses and platforms that hold, control, safeguard or transfer virtual assets for clients.
A business does not require DLT Provider Authorization merely because it develops or uses blockchain technology, if it does not store, control or transmit value belonging to others.
The GFSC uses a staged application process covering business model, capital, key individuals, risk management, IT systems, governance, financial crime controls, compliance and operational readiness.
The GFSC aims to progress applications through the first three stages within a maximum period of 9 months, depending on application quality and responsiveness.
A private company must have at least 1 director, while other companies must have at least 2 directors.
The standard corporate income tax rate in Gibraltar is 15%.
Gibraltar does not operate a VAT system and does not impose capital gains tax.
Why crypto and DLT businesses may need authorization in Gibraltar
A DLT Provider Authorization in Gibraltar gives businesses a regulated legal basis to use distributed ledger technology to store or transmit value belonging to others. It helps companies demonstrate regulatory credibility, governance maturity, AML/CFT readiness, customer asset protection, and operational resilience under the supervision of the Gibraltar Financial Services Commission (GFSC).
Authorization confirms that the business is permitted to operate within Gibraltar’s DLT regulatory framework.
The framework is especially relevant for businesses that hold, control, safeguard or transfer value belonging to clients or third parties.
GFSC authorization can strengthen the company’s profile when working with banks, institutional clients, investors and professional counterparties.
The authorization process helps determine whether the business falls within the DLT Provider regime based on its actual operating model, not just its commercial name.
Gibraltar can be suitable for exchanges, custodial wallet providers, custody businesses, settlement platforms and other DLT-based structures involving third-party value.
The framework requires effective corporate governance, risk management, internal controls and oversight of outsourced or material outsourced functions.
Applicants must demonstrate financial crime controls, customer due diligence, transaction monitoring and AML/CFT procedures appropriate to the risks of the business.
For businesses prepared to establish a substantive regulated operation, Gibraltar can provide a stable framework for scaling DLT-based activities under ongoing GFSC supervision.
What activities can be covered by a Gibraltar DLT Provider Authorization?
A Gibraltar DLT Provider Authorization allows a business to operate under GFSC supervision where it uses distributed ledger technology, in or from Gibraltar, to store or transmit value belonging to others. The exact scope depends on the substance of the business model, including who controls client assets, who manages private keys, how transactions are executed and what role the Gibraltar entity performs in the overall value flow.
Authorization may be relevant for crypto exchanges that use DLT to transmit or store value belonging to clients or other third parties.
The framework may apply to wallet providers that hold, control or safeguard client assets or private keys.
Businesses providing custody infrastructure for institutional clients may fall within the DLT Provider regime if they control or safeguard third-party value.
Authorization may be required where the Gibraltar entity is involved in transmitting value between parties using DLT.
Platforms that hold, control, safeguard or transfer virtual assets on behalf of clients may require DLT Provider Authorization.
The regime may apply to settlement or transaction-flow models where the Gibraltar entity plays a role in the storage or transmission of third-party value.
The authorization can support group models where the Gibraltar company performs a regulated DLT function within a broader crypto or fintech structure.
Where the business controls customer value, the authorization framework requires proper safeguarding arrangements, including controls over wallets, private keys, custody infrastructure and third-party providers.
Who regulates DLT Providers in Gibraltar?
DLT Providers in Gibraltar are authorized and supervised by the Gibraltar Financial Services Commission — GFSC. The regime is based on the Financial Services Act 2019 and the Financial Services (DLT Providers and VAA Providers) Regulations 2020, creating a dedicated framework for businesses that use distributed ledger technology to store or transmit value belonging to others.
Regulatory authority
The competent authority for DLT Provider Authorization is the Gibraltar Financial Services Commission (GFSC).
Legal basis
The framework operates under the Financial Services Act 2019 and the Financial Services (DLT Providers and VAA Providers) Regulations 2020.
Principles-based regulation
Gibraltar applies a principles-based approach, meaning the GFSC assesses the substance of the business model rather than only the name or category of the service.
Regulatory perimeter
Authorization may be required where a business uses DLT, in or from Gibraltar, for the storage or transmission of value belonging to others.
Business model assessment
The GFSC reviews the applicant’s services, group structure, target market, transaction flows, strategy and the role of the Gibraltar entity.
Governance review
The regulator assesses controllers, shareholders, directors, key individuals, internal governance, risk management and oversight arrangements.
Financial crime controls
Applicants must demonstrate AML/CFT controls, customer due diligence, transaction monitoring and other financial crime prevention measures.
Technology and resilience
The framework requires detailed attention to IT infrastructure, cybersecurity, systems architecture, outsourcing, business continuity and disaster recovery.
Customer asset protection
Where the business holds or controls customer assets, the GFSC expects clear safeguarding arrangements, including wallet access controls, private key management and custody procedures.
Ongoing supervision
After authorization, the DLT Provider remains subject to GFSC supervision and may be reviewed through reporting, regulatory engagement and post-authorization onsite visits.
Who needs a Gibraltar DLT Provider Authorization?
A Gibraltar DLT Provider Authorization may be required for businesses that use distributed ledger technology, in or from Gibraltar, to store or transmit value belonging to others. The requirement depends on the actual operating model, including whether the company holds, controls, safeguards or transfers client assets, rather than on the commercial name of the service.
Businesses that facilitate crypto or virtual asset exchange and are involved in storing, controlling or transmitting client value.
Wallet businesses that hold or control client assets, private keys or instruments enabling access to virtual assets.
Companies offering custody infrastructure for funds, institutions, professional investors or other clients.
Platforms that hold, control, safeguard or transfer virtual assets on behalf of clients or third parties.
Businesses that use distributed ledger technology to transmit value between parties in or from Gibraltar.
DLT-based settlement or transaction-flow structures where the Gibraltar entity plays an active role in storing or transmitting third-party value.
International crypto or fintech groups where the Gibraltar entity performs the regulated DLT function inside a broader operating model.
Any business model where the key regulatory question is who controls client assets, private keys, transaction execution and value flow.
How Manimama supports Gibraltar DLT Provider Authorization applicants
Manimama provides end-to-end legal, regulatory and compliance support for businesses applying for DLT Provider Authorization in Gibraltar. We help assess whether the business falls within the DLT regulatory perimeter, prepare the staged GFSC application package, structure governance and compliance frameworks, and support the applicant through the authorization process and post-authorization readiness.
Business model assessment
We analyze the proposed DLT business model, services, transaction flows, target markets, and the role of the Gibraltar entity to determine whether DLT Provider Authorization is required.
Regulatory perimeter analysis
We assess whether the company stores, controls, safeguards or transmits value belonging to others, and whether the model falls within the Gibraltar DLT Provider regime.
Authorization roadmap
We prepare a clear authorization roadmap covering Stage 1, Stage 2, Stage 3, possible GFSC presentation, mobilization and post-authorization readiness.
Business plan preparation
We assist with preparing the bespoke DLT Comprehensive Business Plan, including business model, group structure, strategy, services, target market and financial projections.
Controllers and key persons support
We help prepare Controller Forms, source of wealth and source of funds materials, and supporting information for shareholders, controllers, directors and key individuals.
Governance and risk framework
We support the preparation of governance documents, internal controls, risk methodology, risk register, management responsibilities and oversight procedures.
AML/CFT and financial crime documentation
We prepare or review AML/CFT policies, customer due diligence procedures, transaction monitoring controls and financial crime prevention documents.
Technology and cybersecurity support
We assist with documentation on IT infrastructure, systems architecture, cybersecurity, business continuity, disaster recovery and operational resilience.
Customer asset safeguarding
For custody or client asset control models, we help document safeguarding arrangements, private key management, wallet access controls, hot and cold storage setup and custody procedures.
How Manimama guides you through the Gibraltar DLT Provider Authorization process
We follow a structured process that helps DLT and crypto businesses move from initial regulatory assessment to GFSC application preparation, staged review, authorization and post-authorization readiness. Each step is designed to align the business model, governance, financial crime controls, technology, customer asset safeguarding and operational framework with Gibraltar’s DLT Provider requirements.
1. Initial consultation
We discuss your business model, DLT use case, target markets, client asset flow, custody setup, technology infrastructure and the role of the Gibraltar entity.
3. Authorization roadmap
We prepare a clear roadmap for the staged GFSC process, including Stage 1, Stage 2, Stage 3, possible presentation, mobilization and post-authorization readiness.
5. Stage 1 application support
We assist with the application form, Stage 1 DLT Comprehensive Business Plan, Controller Forms, source of wealth and source of funds materials.
7. Stage 3 operational readiness support
We assist with conduct of business documents, terms and conditions, risk warnings, fee schedule, compliance structure, conflicts of interest, complaints handling and operational policies.
2. Regulatory perimeter assessment
We determine whether the company uses DLT in or from Gibraltar to store or transmit value belonging to others and whether DLT Provider Authorization is required.
4. Business model and structure preparation
We help define the business model, group structure, services, target market, transaction flows, capital position and role of key individuals.
6. Stage 2 documentation support
We prepare or review documentation covering risk management, governance, AML/CFT, financial crime controls, IT systems, cybersecurity, outsourcing, business continuity and customer asset safeguarding.
8. GFSC communication support
We help coordinate communication with the GFSC, prepare responses to regulator comments and support the applicant throughout the staged review process.
Start Your Gibraltar DLT Provider Authorisation Process Today
Receive complete legal and regulatory support for your Gibraltar DLT Provider Authorisation — from regulatory perimeter assessment and business model structuring to staged GFSC application preparation, AML/CFT documentation, cybersecurity framework, customer asset safeguarding and post-authorisation readiness.
Manimama helps crypto exchanges, custodial wallet providers, institutional custody businesses, DLT-based platforms and virtual asset infrastructure providers prepare for Gibraltar authorisation with clear governance, suitable controllers and key individuals, financial crime controls, outsourcing oversight, operational resilience and customer asset protection measures.
Get Free ConsultationGibraltar DLT Provider Authorization Requirements & Application Roadmap
Understand the key business models, company requirements, personnel obligations, capital, documents, timelines, tax rules, and practical risks before applying for a Gibraltar DLT Provider Authorization.
What business models are suitable for a Gibraltar DLT Provider Authorization?
A Gibraltar DLT Provider Authorization may be suitable for businesses that use distributed ledger technology to store, control, safeguard or transmit value belonging to clients or other third parties. The GFSC assesses the substance of the operating model, including control over client assets and private keys, transaction execution, value flow and the role of the Gibraltar entity within the wider business structure.
Crypto exchange business
Suitable for exchanges that use DLT infrastructure and are involved in storing, controlling or transmitting client value.
Custodial wallet provider
Suitable for wallet businesses that hold client assets, manage private keys or provide infrastructure enabling control over virtual assets.
Institutional custody business
Suitable for companies providing custody or safeguarding services for funds, institutions, professional investors or other third-party clients.
Virtual asset platform
Suitable for platforms that hold, control, safeguard or transfer virtual assets on behalf of clients or counterparties.
DLT settlement infrastructure
Suitable for businesses using DLT to support settlement, transfer or value-flow arrangements involving third-party assets.
Group operating structure
Suitable for international crypto or fintech groups where the Gibraltar entity performs the regulated DLT function within a broader corporate structure.
Wallet infrastructure with control over assets
Suitable for infrastructure providers that are not merely technical vendors, but have operational control over client assets, wallet access or transaction execution.
Complex DLT business models
Suitable for models involving exchanges, custody, wallet infrastructure, settlement or other arrangements where the business stores or transmits third-party value using DLT.
What company structure and local presence are required for a Gibraltar DLT Provider Authorization?
To obtain DLT Provider Authorization in Gibraltar, the applicant must demonstrate that its corporate structure, ownership, key individuals, governance arrangements and operational presence are suitable for a regulated DLT business. The GFSC assesses the substance of the business model, who controls the company, who manages the regulated activity, and whether the applicant has sufficient financial and non-financial resources to operate in or from Gibraltar.
Gibraltar operating substance
The business must carry on, or propose to carry on, DLT Provider business in or from Gibraltar and maintain sufficient substance appropriate to its business model.
Director requirement
A private company must have at least 1 director, while other companies must have at least 2 directors.
Controllers and shareholders
The applicant must provide detailed information on controllers, shareholders and ownership structure as part of the GFSC assessment.
Key individuals
Directors, controllers and other key individuals must demonstrate relevant skills, experience and suitability for the proposed regulated business.
Source of wealth and funds
Shareholders and controllers may need to provide evidence of source of wealth and source of funds.
Governance arrangements
The company must establish effective corporate governance, internal control and risk management arrangements.
Operational resources
The applicant must demonstrate sufficient financial and non-financial resources, including suitable personnel, a compliance structure, and audit, accounting, and banking arrangements.
Outsourcing oversight
Where material functions are outsourced, the applicant must maintain proper contracts, risk assessment, oversight and an outsourcing register.
What personnel and compliance requirements apply to a Gibraltar DLT Provider?
A Gibraltar DLT Provider applicant must demonstrate that it has suitable controllers, shareholders, directors, key individuals, compliance resources and internal control systems to operate as a regulated business. The GFSC assesses not only the people involved, but also the company’s governance, AML/CFT framework, risk management, technology resilience, outsourcing controls and customer asset protection arrangements.
Controllers and shareholders
The applicant must provide detailed information on controllers, shareholders and ownership structure, including evidence of source of wealth and source of funds where required.
Directors and key individuals
Directors and other key individuals must demonstrate appropriate skills, experience, integrity and suitability for managing a regulated DLT business.
Compliance structure
The company must have an appropriate compliance structure with sufficient resources to monitor regulatory obligations and internal controls.
AML/CFT controls
The applicant must maintain effective financial crime controls, including AML/CFT policies, customer due diligence, transaction monitoring and risk-based procedures.
Risk management framework
The company must establish a clear risk methodology, risk register, internal control framework and oversight of key business risks.
Technology and cybersecurity
The GFSC expects detailed information on IT infrastructure, systems architecture, cybersecurity, operational resilience and protection of technology systems.
Business continuity and disaster recovery
The applicant must maintain appropriate business continuity and disaster recovery arrangements to support stable regulated operations.
Customer asset safeguarding
Where the business holds or controls customer assets, it must demonstrate proper safeguarding arrangements, wallet access controls, private key management and custody procedures.
Outsourcing oversight
Material outsourcing must be documented, risk-assessed and monitored through effective oversight, contracts and an outsourcing register.
Conduct and customer protection
The company must prepare appropriate terms and conditions, risk warnings, fee arrangements, complaints handling procedures and conflict-of-interest controls.
Audit, accounting and banking arrangements
The applicant should demonstrate effective arrangements for audit, accounting, banking and operational financial management.
Operational readiness
Before authorization, the company must show that its documented policies, systems, controls and personnel arrangements can operate effectively in practice.
What documents are required for a Gibraltar DLT Provider Authorization?
The Gibraltar DLT Provider application is document-heavy and submitted through a staged GFSC process. The file must explain the business model, ownership and control structure, capital position, key individuals, governance, AML/CFT controls, technology, cybersecurity, outsourcing, customer asset safeguarding and operational readiness.
Stage 1 application form
The applicant submits the initial application form together with the required Stage 1 information and application fee.
DLT Comprehensive Business Plan — Stage 1
The business plan must describe the business model, services, group structure, target market, strategy, transaction flows and the role of the Gibraltar entity.
Controller Forms
Controller Forms must be prepared for each controller involved in the applicant’s ownership or control structure.
Source of wealth and source of funds
Shareholders and controllers must provide evidence of source of wealth and source of funds where required.
Capital and financial projections
The applicant must provide financial projections and demonstrate adequate capital and financial resources for the nature, scale and complexity of the business.
Governance and risk management documents
The file should include governance arrangements, internal controls, risk methodology, risk register, management responsibilities and oversight procedures.
AML/CFT and financial crime documents
The applicant must prepare AML/CFT policies, customer due diligence procedures, transaction monitoring controls and financial crime prevention documentation.
Technology and cybersecurity documentation
The GFSC expects information on IT infrastructure, systems architecture, cybersecurity, operational resilience and technology controls.
Business continuity and disaster recovery plans
The application should include business continuity and disaster recovery arrangements showing how the business can continue operating under disruption.
Customer asset safeguarding documents
Where the business holds or controls customer assets, the file should explain private key management, wallet access controls, hot and cold storage arrangements and custody safeguards.
Outsourcing documents
Material outsourcing arrangements must be documented through contracts, risk assessments, oversight procedures and an outsourcing register.
Conduct of business documents
The Stage 3 package may include terms and conditions, risk warnings, proposed fee schedule, conflicts of interest framework and complaints handling policy.
Compliance and operational readiness documents
The applicant should provide documents covering compliance structure, conduct risk framework, KPIs, remuneration policy, liquidity and solvency policies and relevant governance materials.
Regulated individual and NED forms
Where applicable, completed forms for regulated individuals and non-executive directors may be required as part of the GFSC review.
What are the capital and financial requirements for a Gibraltar DLT Provider Authorization?
Gibraltar does not assess DLT Provider applicants only by a fixed capital number. The GFSC reviews whether the applicant has sufficient capital, financial resources, and operational resources for the nature, scale, and complexity of its business model, including its governance, technology, cybersecurity, financial crime controls, outsourcing arrangements, and customer asset safeguarding framework.
Adequate capital requirement
The applicant must demonstrate that it has sufficient capital for the proposed DLT activities, taking into account the size, risk and complexity of the business.
Financial resources assessment
The GFSC reviews whether the company has enough financial resources to operate safely, sustainably and in line with its regulatory obligations.
Financial projections
Financial projections form part of the authorization assessment and must be consistent with the business model, growth strategy and planned operations.
Application fee
The Stage 1 application package includes payment of the application fee. The exact amount should be confirmed based on the current GFSC fee schedule and the applicant’s business model.
Operational resource costs
Applicants should budget for compliance, AML/CFT controls, governance, audit, accounting, banking, IT systems, cybersecurity, business continuity and professional support.
Customer asset safeguarding costs
Where the business holds or controls customer assets, additional costs may arise for custody infrastructure, wallet controls, private key management, insurance, third-party provider due diligence and safeguarding procedures.
Outsourcing and provider costs
Material outsourcing arrangements must be properly documented, risk-assessed and monitored, which may require external technology, custody, compliance or operational providers.
Professional indemnity and risk coverage
Where applicable, the GFSC may review professional indemnity insurance and other risk coverage arrangements as part of operational readiness.
Corporate income tax
The standard corporate income tax rate in Gibraltar is 15%.
Tax position
Gibraltar does not operate a VAT system, does not impose capital gains tax, and generally does not impose withholding tax on dividends, interest or royalties paid by Gibraltar companies to non-residents.
How does the Gibraltar DLT Provider Authorization process work?
The Gibraltar DLT Provider Authorization process follows a staged GFSC review, starting with pre-application engagement and moving through business model, capital, key individuals, risk management, IT systems, governance, financial crime controls, conduct of business and operational readiness. The process is designed to assess not only whether the applicant fits the DLT regulatory perimeter, but also whether the company is ready to operate as a regulated business in practice.
1. Pre-application engagement
Before submitting a formal application, the applicant is encouraged to engage with the GFSC’s DLT team to discuss the proposed business model, services and activities.
2. Stage 1 — Business model and key individuals
The applicant submits Stage 1 information, including the application form, application fee, Stage 1 DLT Comprehensive Business Plan, Controller Forms, source of wealth and source of funds evidence, and information on the business model, ownership, capital and key persons.
3. GFSC Stage 1 assessment
At this stage, the GFSC focuses on understanding the proposed business model, control structure, capital position and individuals responsible for the business before allowing the application to move forward.
4. Stage 2 — Risk, IT, governance and financial crime
The applicant submits Stage 2 documentation covering risk management, corporate governance, AML/CFT, financial crime controls, IT systems, cybersecurity, business continuity, outsourcing, disaster recovery and customer asset safeguarding.
5. GFSC Stage 2 review
The GFSC reviews the applicant’s control environment and operational infrastructure, including private key management, hot and cold wallet arrangements and third-party provider due diligence where custody-related models are involved.
6. Stage 3 — Conduct, compliance and operational readiness
The applicant submits Stage 3 materials, including terms and conditions, risk warnings, fee schedule, compliance structure, conduct risk framework, KPIs, remuneration policy, conflicts of interest framework, complaints handling policy, liquidity and solvency policies.
7. Comprehensive presentation to the GFSC
Applicants may be invited to deliver a presentation covering key individuals, business model, group structure, products and services, target market, strategy, financial projections and how the company will meet the DLT regulatory principles.
8. GFSC authorization decision
Once the GFSC is satisfied with the Stage 3 information and the application as a whole, the application proceeds to a formal authorization decision.
9. Mobilization period, where applicable
Where relevant, a mobilization period may follow authorization and include systems testing, implementation checks, and further assessment of operational readiness.
10. Post-authorization onsite visit
After permission is granted, the GFSC may carry out an on-site visit to verify that the systems, processes and controls described during the application process are implemented and operating effectively.
How long does the Gibraltar DLT Provider Authorization process take?
The GFSC aims to progress DLT Provider applications through the first three stages of the authorization process within a maximum of 9 months. The actual timeline depends on the complexity of the business model, quality and completeness of the application package, readiness of the applicant’s systems and controls, and timely responses to GFSC requests.
1. Pre-application engagement
Before formal submission, the applicant may engage with the GFSC’s DLT team to discuss the proposed business model, services, activities and regulatory perimeter.
2. Stage 1 — up to 5 months
The GFSC reviews the business model, capital position, ownership and control structure, shareholders, controllers and key individuals responsible for the business.
3. Stage 2 — up to 2 months
The regulator assesses risk management, financial crime controls, business continuity, corporate governance, IT systems, cybersecurity, outsourcing and customer asset safeguarding.
4. Stage 3 — up to 2 months
The GFSC reviews non-financial resources, compliance structure, conduct of business, Consumer Duty, operational resilience and readiness to operate as a regulated business.
5. Comprehensive presentation
Applicants may be invited to present the business model, group structure, key people, target market, financial projections, products and regulatory approach to the GFSC.
6. Authorization decision
Once the GFSC is satisfied with the Stage 3 information and the application as a whole, the process moves to the formal authorization decision.
7. Mobilization period
Where applicable, a discretionary mobilization period may follow authorization and include systems testing, implementation checks and further operational readiness assessment.
8. Post-authorization onsite visit
After permission is granted, the GFSC may conduct an on-site visit to verify that the systems, processes and controls described in the application operate effectively in practice.
What are the tax and ongoing obligations after Gibraltar DLT Provider Authorization?
Gibraltar offers a clear tax framework for regulated DLT businesses, including 15% corporate income tax, no VAT, no capital gains tax, and generally no withholding tax on dividends, interest or royalties paid by Gibraltar companies to non-residents. However, after authorization, the DLT Provider remains subject to GFSC supervision and must maintain governance, AML/CFT controls, cybersecurity, customer asset safeguarding, outsourcing oversight and operational resilience on an ongoing basis.
Corporate income tax
The standard corporate income tax rate in Gibraltar is 15% for most companies.
No VAT system
Gibraltar does not operate a VAT system, which may simplify the tax position for certain business models.
No capital gains tax
Gibraltar does not impose capital gains tax.
Withholding tax position
Gibraltar generally does not impose withholding tax on dividends, interest or royalties paid by Gibraltar companies to non-residents.
Tax treatment depends on structure
The actual tax treatment depends on where the company’s income is accrued or derived and on the wider operating and group structure.
Ongoing GFSC supervision
After authorization, the DLT Provider remains supervised by the Gibraltar Financial Services Commission and must continue meeting regulatory expectations.
AML/CFT compliance
The company must maintain effective AML/CFT controls, customer due diligence, transaction monitoring and financial crime prevention procedures.
Governance and risk management
The provider must maintain effective corporate governance, internal controls, risk methodology, risk register and management oversight.
Technology and cybersecurity
The company must keep appropriate IT infrastructure, cybersecurity controls, systems architecture, business continuity and disaster recovery arrangements.
Customer asset safeguarding
Where the business holds or controls customer assets, it must maintain safeguarding arrangements, including wallet access controls, private key management and custody procedures.
Outsourcing oversight
Material outsourcing arrangements must remain documented, risk-assessed and monitored through contracts, oversight procedures and an outsourcing register.
Post-authorization verification
The GFSC may carry out an on-site visit after authorization to confirm that the systems, processes and controls described during the application are actually implemented and working in practice.
What should businesses consider before applying for Gibraltar DLT Provider Authorization?
Gibraltar is a strong jurisdiction for substantive DLT and crypto businesses, but the authorization should not be treated as a light-touch registration. The GFSC assesses the actual business model, control over client assets, governance, capital, key individuals, AML/CFT controls, technology, cybersecurity, outsourcing, customer protection and operational readiness before granting authorization.
Regulatory perimeter risk
A business may need authorization if it uses DLT in or from Gibraltar to store or transmit value belonging to others. The assessment depends on substance, not on the commercial name of the service.
Non-custodial model limitation
A company does not need DLT Provider Authorization only because it develops blockchain software or uses DLT. If it does not store, control or transmit third-party value, it may fall outside the regime.
No EU / EEA passporting
Gibraltar is not part of the EU or EEA MiCA passporting framework. DLT Provider Authorization does not automatically allow the company to provide regulated crypto-asset services across the EU or EEA.
Client asset control risk
If the business holds or controls customer assets, it must demonstrate strong safeguarding arrangements, including private key management, wallet access controls and custody infrastructure.
Technology and cybersecurity burden
The GFSC expects detailed information on IT infrastructure, cybersecurity, systems architecture, business continuity, disaster recovery and operational resilience.
AML/CFT and financial crime expectations
The applicant must maintain effective AML/CFT controls, customer due diligence, transaction monitoring and financial crime prevention measures proportionate to the risks of the business.
Outsourcing risk
Material outsourcing is allowed, but the DLT Provider remains responsible for regulated activities and must maintain risk assessment, contracts, oversight and an outsourcing register.
Operational readiness check
After authorization, the GFSC may carry out an onsite visit to verify that the systems, processes and controls described in the application are actually implemented and working in practice.
Application complexity
The process is staged and document-heavy. Applicants move to the next stage only when the GFSC is satisfied with the current stage materials and responses.
Token sale limitation
ICOs and token sales do not automatically fall within the DLT Provider framework only because tokens are issued using DLT. Depending on the token and structure, other financial services rules or AML/CFT registration may apply.
Tax structuring risk
Gibraltar’s tax treatment depends on where income is accrued or derived and on the company’s operating and group structure.
Substance requirement
The business must carry on, or propose to carry on, DLT Provider business in or from Gibraltar and maintain sufficient substance, governance and operational presence appropriate to its model.
Expert view on Gibraltar DLT Provider Authorization
“Gibraltar is not a jurisdiction for a purely formal crypto setup. It works best for businesses that are ready to demonstrate substance, strong governance and real control over operational risks. The key question is whether the company stores or transmits value belonging to others — and if it does, the application must clearly explain how client assets are protected, how private keys and wallets are managed, how AML/CFT controls work, and how the business will remain operationally resilient under GFSC supervision.”
Ganna Voievodina
CEO & Co-founder of Manimama
Frequently asked questions about Gibraltar DLT Provider Authorization
This section answers the most common questions about Gibraltar DLT Provider Authorization, including who needs authorization, what activities may fall within the regime, how the GFSC process works, whether EU/EEA passporting applies, and what compliance, substance, tax and outsourcing requirements businesses should consider.
It is a regulatory permission granted by the Gibraltar Financial Services Commission (GFSC) to businesses carrying on DLT Provider business in or from Gibraltar, including the use of DLT for the storage or transmission of value belonging to others.
DLT Providers are authorized and supervised by the GFSC under Gibraltar’s dedicated DLT regulatory framework.
The framework is based on the Financial Services Act 2019 and the Financial Services (DLT Providers and VAA Providers) Regulations 2020.
Depending on the business model, the regime may apply to crypto exchanges, custodial wallet providers, institutional custody businesses, and platforms that hold, control, safeguard, or transfer third-party value using DLT.
No. A business does not need authorization only because it develops or uses blockchain technology. A non-custodial software or technology provider may fall outside the regime if it does not store, control or transmit value belonging to others.
The main question is whether the business uses DLT in or from Gibraltar for the storage or transmission of value belonging to others. The GFSC assesses substance, including who controls client assets, private keys, transaction execution and value flow.
The GFSC aims to progress applicants through Stages 1–3 within up to 9 months, depending on the complexity of the business and the quality and completeness of the application.
The process includes pre-application engagement; Stage 1 business model and key individuals review; Stage 2 risk management and IT systems review; Stage 3 conduct and operational readiness review; a possible GFSC presentation; an authorization decision; and a possible post-authorization on-site visit.
No. Gibraltar is not part of the EU or EEA MiCA passporting framework, so the authorization does not automatically allow the company to provide regulated crypto-asset services across the EU or EEA.
Yes. Foreign ownership is generally possible, but shareholders, controllers and key individuals are subject to GFSC suitability and regulatory assessment.
The business must carry on, or propose to carry on, DLT Provider business in or from Gibraltar and should maintain sufficient substance, governance and operational presence appropriate to its business model.
Yes. Certain functions may be outsourced, but the DLT Provider remains responsible for its regulated activities and must maintain effective oversight, risk management and control over outsourced arrangements.
Gibraltar generally applies 15% CIT, has no VAT, no CGT, and generally does not impose withholding tax on dividends, interest or royalties paid by Gibraltar companies to non-residents.
ICOs and token sales do not generally fall within the DLT Provider framework only because tokens are issued using DLT. However, depending on the token and offering structure, other financial services rules or AML/CFT registration may apply.
Ready to Move Forward with Your Gibraltar DLT Provider Authorization?
Tell us about your crypto exchange, custodial wallet, institutional custody, virtual asset platform or DLT-based business model. Manimama will assess whether your activity falls within the Gibraltar DLT Provider framework and prepare a clear roadmap for GFSC authorization.