Global Law Experts Logo
malta vfa license

Talk with Our Expert

Jonathon Richards

Global Law Experts

Lead Enquiries Qualification
Delete Article

Malta VFA Licence (mica Transition): MFSA Guidance, Eligibility and Application Steps

By Jonathon Richards
– posted 11 minutes ago

Introduction

Malta has long been regarded as a pioneer in digital-asset regulation, and the Malta VFA license regime introduced under the Virtual Financial Assets Act of 2018 established the island as one of the first jurisdictions worldwide to offer a comprehensive licensing framework for crypto-asset service providers. With the EU-wide Markets in Crypto-Assets Regulation (MiCA) now fully applicable, Malta has transposed MiCA into national law through the Markets in Crypto-Assets Act (Chapter 647), fundamentally reshaping how firms obtain and maintain authorisation to provide crypto-asset services from Malta.

The Malta Financial Services Authority (MFSA) has published detailed guidance on the VFA licence transition to CASP authorisation under MiCA, setting out migration routes for legacy licence holders and a clear application pathway for new entrants. This page consolidates the MFSA’s official guidance, eligibility criteria, step-by-step application process, costs, timelines and migration checklist into a single authoritative resource.

Whether you are a founder building a crypto exchange, a custody provider expanding into Europe, a compliance officer managing a legacy VFA licence, or in-house counsel evaluating Malta as a gateway to EU passporting, this guide is designed for you.

Quick Summary Who This Page Is For

This guide addresses the practical needs of the following groups:

  • Founders and start-ups building crypto trading platforms, wallets, custody solutions or token-based products and seeking a Malta crypto licence under MiCA.
  • Existing VFA licence holders needing to understand their migration obligations and the VFA to MiCA transition pathway before transitory provisions expire.
  • Crypto exchanges and trading venues planning to operate an EU-regulated trading platform for crypto-assets from Malta.
  • Custody and administration providers offering safekeeping of crypto-assets or private keys on behalf of clients.
  • Token issuers considering Malta for the issuance of asset-referenced tokens (ARTs) or e-money tokens (EMTs).
  • Compliance officers and in-house counsel conducting due diligence on the MFSA VFA framework and MiCA CASP Malta requirements for board-level reporting.

Quick decision points: Do you need to apply for a new CASP authorisation? Must you migrate an existing VFA licence? Are you unsure which MiCA service categories apply to your business model? The sections below answer each question with MFSA-sourced guidance.

What the VFA Framework Was and Why MiCA Matters

Origins: The VFA Act Malta’s Legacy Framework

Malta enacted the Virtual Financial Assets Act in November 2018, becoming one of the first EU member states to create a bespoke regulatory framework for distributed ledger technology (DLT) assets. The MFSA VFA framework introduced four distinct licence classes covering VFA exchanges, VFA brokers, portfolio managers and custodians along with a mandatory “VFA Agent” gatekeeper model. The framework governed initial VFA offerings (IVFAOs), ongoing issuer obligations and market conduct standards for VFA service providers established in Malta.

Why MiCA (EU Level) Matters

Regulation (EU) 2023/1114 commonly known as MiCA replaced the patchwork of national frameworks across the EU with a single, harmonised rulebook for crypto-asset issuers and crypto-asset service providers (CASPs). MiCA introduces uniform prudential, governance and consumer-protection standards, and critically, it grants authorised CASPs a passport to provide services across the entire European Economic Area without requiring separate national licences. For firms already licensed in Malta, MiCA means adapting to a new and in several areas more demanding regulatory standard. For new entrants, it makes Malta a strategic EU gateway.

How Malta Aligned: The Markets in Crypto-Assets Act (Chapter 647)

Malta transposed MiCA into domestic law through the Markets in Crypto-Assets Act (Chapter 647), which simultaneously amended the legacy VFA Act. Chapter 647 designates the MFSA as the competent authority for CASP authorisation, sets out the VFA Amendment Act Malta provisions for transitioning legacy licence holders, and establishes the local enforcement regime including administrative penalties that complements MiCA’s directly applicable requirements.

Current MFSA Position and Legal Basis

The MFSA has published a series of circulars and rulebook chapters to operationalise MiCA in Malta. The key procedural document is the Circular on the Authorisation Process for MiCA Applicants (December 2024), which sets out the MFSA’s expectations for pre-application engagement, documentation standards, review timelines and post-authorisation obligations.

The MFSA’s position can be summarised as follows:

  • New CASP applications all new applicants must apply under MiCA/Chapter 647 via the MFSA’s Licensee Hub (LH) Portal. The legacy VFA Act application route is closed for new entrants.
  • Legacy VFA holders existing VFA licence holders benefit from transitory provisions under Chapter 647 and may continue to operate during a defined transition window, provided they submit a migration application to the MFSA within the prescribed timeframe.
  • Regulatory perimeter the MFSA’s Crypto-Assets guidance clarifies which activities and asset types fall within the MiCA perimeter, and when firms should seek a formal classification determination.
  • Technology and ICT expectations the MFSA has issued an addendum to its guidance on technology arrangements, ICT risk management and outsourcing, which applies to all MiCA applicants and must be addressed in the application documentation pack.

The legislative architecture is therefore layered: EU MiCA (directly applicable) is supplemented by Chapter 647 (national transposition and enforcement), MFSA rulebook chapters and regulatory circulars (procedural detail), and subsidiary legislation on fees.

Who Is Eligible and Which Services Require CASP Authorisation

Eligible Entities

Under MiCA and Chapter 647, CASP applicants must be legal persons or undertakings established (or willing to establish a registered office) in Malta. The entity must have its head office and effective management in the EU with at least some senior management resident in Malta or conducting business from Malta. The MFSA assesses the applicant’s corporate structure, governance arrangements, ownership transparency and the fitness and propriety of all qualifying shareholders, directors and senior management.

Services Requiring Authorisation

MiCA defines ten categories of crypto-asset services. A Malta VFA license applicant (now CASP applicant) must identify which services it intends to offer, as each service category triggers specific prudential and organisational requirements:

  • Custody and administration of crypto-assets safekeeping or controlling clients’ crypto-assets or private keys.
  • Operation of a trading platform managing a multilateral system for crypto-asset trading.
  • Exchange of crypto-assets for funds or other crypto-assets executing client orders for exchange.
  • Execution of orders concluding agreements to buy or sell crypto-assets on behalf of clients.
  • Placing of crypto-assets marketing newly issued crypto-assets to buyers.
  • Reception and transmission of orders receiving client orders and transmitting them for execution.
  • Providing advice on crypto-assets offering personalised recommendations.
  • Portfolio management of crypto-assets discretionary management of client portfolios.
  • Transfer services for crypto-assets transferring crypto-assets on behalf of clients between addresses or accounts.
  • Issuance of asset-referenced tokens (ARTs) or e-money tokens (EMTs) subject to additional requirements under MiCA Titles III and IV.

Common Edge Cases

Certain asset types including genuinely unique, non-fungible tokens (NFTs), pure utility tokens that are not transferable, and fractional NFTs that may function as financial instruments present classification challenges. Where uncertainty exists, industry observers recommend seeking a formal determination from the MFSA before proceeding to application.

Step-by-Step MFSA Application Process and Timeline

The MiCA CASP Malta application process follows a structured workflow mandated by the MFSA. Firms should engage experienced regulatory counsel early, as the MFSA expects applications to be substantially complete upon submission. The following steps reflect the MFSA’s published guidance.

Step 1: Pre-Application and Regulatory Engagement

Applicants are strongly encouraged to request an introductory meeting with the MFSA before formal submission. This meeting allows the MFSA to understand the applicant’s business model, confirm the applicable service categories, identify potential regulatory concerns and advise on documentation expectations. The MFSA’s December 2024 Circular recommends this engagement as a critical first step. Pre-application typically takes two to six weeks.

Step 2: Corporate Structure, Governance and Local Establishment

Applicants must establish (or confirm) a legal entity in Malta with appropriate governance. This includes appointing a board of directors with adequate collective knowledge and experience, designating an AML/CFT compliance function and ensuring the company’s articles of association permit the proposed crypto-asset activities. A registered office and local substance including locally resident directors or officers are expected by the MFSA.

Step 3: Preparing the Documentation Package

The MFSA requires a comprehensive documentation package. Applicants should prepare the following (non-exhaustive), referencing the MFSA’s Authorisations page and application forms:

  • Corporate documents memorandum and articles of association, certificate of incorporation, shareholder register, group structure chart.
  • Fit and proper evidence detailed CVs, PQs (personal questionnaires), police conduct certificates and declarations for all directors, beneficial owners and qualifying shareholders.
  • Business plan including a description of services, target markets, marketing strategy, client onboarding and operational workflows.
  • Financial projections three-year financial forecasts demonstrating viability and capital adequacy compliance.
  • AML/CFT policies and procedures risk assessment, customer due diligence procedures, transaction monitoring, suspicious transaction reporting, MLRO appointment.
  • IT and security documentation technology architecture, ICT risk management framework, business continuity plan, disaster recovery and outsourcing arrangements.
  • Systems auditor statement an independent assessment of the applicant’s technology and security arrangements.

Download the full VFA to MiCA migration checklist for a complete list of required documents and templates.

Step 4: Capital and Prudential Requirements

MiCA prescribes minimum initial capital requirements that vary by service category. For example, CASPs providing custody, exchange or trading-platform services face higher minimum capital thresholds than those offering advisory or order-transmission services. Applicants must also demonstrate ongoing capital adequacy typically a combination of fixed overheads requirements and, where applicable, a percentage of safeguarded client assets. The specific thresholds are set out in MiCA Articles 67–68 and transposed via Chapter 647.

Step 5: Fit and Proper Assessments

All directors, senior managers, beneficial owners and qualifying shareholders undergo MFSA fit and proper checks. The MFSA evaluates competence, integrity, financial soundness and any previous regulatory history. This process can introduce delays if information is incomplete, so applicants should compile declarations and supporting evidence before formal submission.

Step 6: Technology and Security Arrangements

The MFSA places significant emphasis on technology governance. Applicants must address the requirements set out in the MFSA’s Technology Arrangements, ICT and Security Risk Management guidance, including penetration testing, vulnerability assessments, key management procedures, outsourcing controls and incident reporting protocols. An independent systems auditor report is typically required.

Step 7: AML/CFT Compliance

Robust AML/CFT arrangements are non-negotiable. Applicants must demonstrate an enterprise-wide business risk assessment, customer due diligence procedures calibrated to the risk profile of crypto-asset activities, ongoing transaction monitoring, and a designated Money Laundering Reporting Officer (MLRO). The MFSA reviews AML/CFT documentation in detail during the substantive review phase.

Step 8: Submission via the LH Portal and MFSA Review Phases

Formal applications are submitted via the MFSA’s Licensee Hub (LH) Portal. The MFSA’s review proceeds in stages:

  1. Completeness check the MFSA confirms the application is substantially complete; incomplete applications may be returned.
  2. Substantive review the MFSA evaluates the merits of the application against MiCA, Chapter 647 and applicable rulebook requirements.
  3. Clarification requests the MFSA may issue rounds of questions or request supplementary documentation.
  4. Approval in principle once satisfied, the MFSA may issue an approval in principle, subject to any outstanding conditions.
  5. Licence grant upon satisfaction of all conditions, the CASP authorisation is formally granted.

Step 9: Typical Timelines and Milestones

Based on MFSA guidance and industry experience, realistic timelines are as follows:

  • Pre-application engagement: 2–6 weeks.
  • Document preparation: 6–12 weeks (depending on readiness).
  • MFSA substantive review: 4–6 months (typical), though complex applications may take longer if significant clarifications are needed.
  • Post-approval conditions: 2–4 weeks to satisfy conditions precedent to licence issuance.

Total elapsed time from engagement to licence grant typically ranges from six to twelve months. The most common sources of delay are incomplete documentation, deficiencies in AML/CFT frameworks and unresolved fit and proper issues.

Step 10: Post-Authorisation Obligations

Once authorised, CASPs must comply with ongoing obligations including regulatory reporting and returns, annual supervisory fees, continuous AML/CFT compliance, material change notifications, client asset segregation and safeguarding, and timely disclosure of outsourcing arrangements. Failure to meet post-authorisation requirements can result in supervisory action.

Download the detailed migration checklist including a post-authorisation obligations summary for a printable reference.

Costs, Ongoing Obligations and EU Passporting

Fee Structure Overview

Malta’s MiCA fee framework comprises application fees, annual supervisory fees and professional costs. The table below summarises the main fee categories. Applicants should budget for the following (indicative ranges; confirm current amounts with the MFSA and applicable subsidiary legislation):

Fee category Indicative range Notes
MFSA application fee €5,000 – €25,000+ Varies by service category and complexity; payable on submission.
Annual supervisory fee €5,000 – €30,000+ Determined by MFSA fee regulations; risk-based component possible.
Minimum initial capital €50,000 – €150,000 Depends on MiCA service categories applied for.
Professional advisory costs €30,000 – €100,000+ Legal, compliance, systems auditor and accounting advisory.
Ongoing compliance costs Variable MLRO, auditor, IT security, regulatory reporting.

Note: fee amounts are indicative and subject to change. Always consult the latest MFSA fee regulations and subsidiary legislation for current amounts.

Ongoing Obligations

Authorised CASPs must comply with continuous obligations including the filing of periodic returns and financial statements, maintaining adequate capital at all times, segregating and safeguarding client assets, conducting ongoing AML/CFT monitoring, notifying the MFSA of material changes in governance, ownership or outsourcing, and complying with conduct-of-business rules under MiCA.

EU Passporting Under MiCA

One of the most commercially significant advantages of a Malta VFA license (now CASP authorisation) under MiCA is the ability to passport crypto-asset services across the entire EEA through a notification procedure without obtaining separate national licences in each member state. For firms targeting cross-border clients, the compliance investment required for a Malta CASP licence is likely to deliver substantial commercial value compared to the alternative of licensing in multiple jurisdictions. Industry observers expect Malta’s regulatory experience and established MFSA processes to make it a preferred EU entry point for non-EU firms seeking a single licence with pan-European reach.

Migration Routes for Existing VFA Licence Holders

Who Must Migrate and What Are the Options

All existing holders of a Malta VFA license must transition to the MiCA/CASP framework. The MFSA’s transition guidance sets out the following routes:

  • Conversion/re-authorisation submit a MiCA CASP application and, upon authorisation, surrender the legacy VFA licence.
  • Restrict services limit operations to activities that fall outside MiCA’s perimeter (rare in practice).
  • Wind down cease regulated activities and voluntarily surrender the VFA licence.

The transitory provisions under Chapter 647 allow legacy VFA licence holders to continue operating during the transition window, provided they submit their migration application within the mandated deadline.

Practical Migration Checklist

The following ordered checklist summarises the key steps for VFA to MiCA transition:

  1. Conduct a gap analysis comparing current VFA licence conditions against MiCA/Chapter 647 requirements.
  2. Amend the corporate structure and governance documents (articles of association, board composition, committee mandates).
  3. Update or create AML/CFT policies, risk assessments and transaction monitoring systems to MiCA standards.
  4. Re-classify tokens and services under MiCA categories where tokens were classified under the legacy Financial Instrument Test, verify their classification under MiCA.
  5. Prepare or commission a systems auditor report addressing the MFSA’s updated technology and ICT risk guidance.
  6. Compile the complete MFSA documentation package (see Step 3 above).
  7. Submit the migration application via the LH Portal within the transitory deadline.
  8. Engage with the MFSA during the substantive review and address clarification requests promptly.
  9. Satisfy any conditions for approval in principle, then obtain the CASP authorisation and surrender the VFA licence.

A downloadable PDF version of this migration checklist with document templates and expanded guidance notes is available for download.

Common Friction Points and Mitigations

  • Technology audit gaps legacy VFA holders may find their existing systems auditor reports insufficient for MiCA’s enhanced ICT and security expectations. Mitigation: commission an early independent review against the MFSA’s latest technology guidance addendum.
  • AML/CFT deficiencies transaction monitoring and customer due diligence procedures designed for the VFA framework may not meet MiCA’s heightened standards. Mitigation: engage specialist compliance advisers to upgrade frameworks before submission.
  • Capital shortfalls MiCA’s minimum capital requirements may exceed those under the legacy VFA regime for certain service categories. Mitigation: plan capital-raising early and include projections in the business plan.
  • Timeline pressure the transition window is finite, and MFSA review capacity is shared across all applicants. Mitigation: submit early and ensure the application is complete to avoid return or deprioritisation.

Comparison: Legacy VFA Licence vs MiCA CASP Authorisation

The following table summarises the key differences between Malta’s legacy VFA framework and the new MiCA CASP authorisation regime:

Feature Legacy VFA Licence MiCA CASP Authorisation
Regulatory basis Virtual Financial Assets Act (2018) Markets in Crypto-Assets Act (Chapter 647) + EU MiCA Regulation
Scope of services Four VFA licence classes (exchange, broker, custodian, portfolio manager) Ten defined crypto-asset service categories
Minimum capital Varied by class; generally lower thresholds €50,000 – €150,000 (depending on service category)
EU passporting Not available (Malta-only licence) Full EEA passporting via notification procedure
VFA Agent requirement Mandatory VFA Agent gatekeeper No VFA Agent requirement; direct MFSA engagement
Key documentation VFA Act application forms, whitepaper, VFA Agent report MiCA documentation package via LH Portal (business plan, fit & proper, AML/CFT, IT/systems auditor)
Technology standards MFSA technology guidance (original) Enhanced ICT risk, outsourcing and security guidance (MFSA addendum)
Typical application timeline 6–9 months 6–12 months (pre-application to licence grant)
AML/CFT framework Malta PMLFTR-aligned Enhanced MiCA + Travel Rule + Malta PMLFTR obligations

The practical effect of this transition is that Malta CASP authorisations carry greater regulatory weight, broader geographic reach, and higher compliance demands than the legacy VFA licence but also significantly greater commercial value through EU passporting.

Client Case Study Successful MFSA Submission

A digital-asset exchange headquartered outside the EU sought to establish a licensed operation in Malta to serve European clients. The firm’s existing compliance framework was designed for a non-EU jurisdiction and required significant adaptation to meet MFSA and MiCA standards. Global Law Experts was engaged to manage the end-to-end application.

Challenge: The client’s AML/CFT framework, corporate governance structure and technology documentation did not meet MFSA expectations. Capital planning had not accounted for MiCA’s service-category-specific minimums. The client also lacked a local establishment in Malta.

Actions taken: Global Law Experts conducted a comprehensive gap analysis, assisted in establishing a Maltese subsidiary with locally resident directors, prepared the complete documentation package including a three-year business plan, restructured AML/CFT policies, and commissioned a systems auditor report and managed the pre-application meeting with the MFSA. During the substantive review, Global Law Experts co-ordinated responses to two rounds of MFSA clarification requests within the recommended timeframes.

Outcome: The CASP authorisation was granted within approximately nine months from the initial pre-application engagement. The client is now authorised to provide exchange and custody services across the EEA. Global Law Experts has supported multiple MFSA submissions for crypto-asset service providers, drawing on deep cross-border crypto licensing experience and established regulatory relationships.

Next Steps

Obtaining a Malta VFA license now a MiCA CASP authorisation is a substantial regulatory undertaking, but it unlocks access to the world’s largest single market for regulated crypto-asset services. The practical next steps for prospective applicants are:

  1. Determine which MiCA service categories apply to your business model.
  2. Conduct a preliminary readiness assessment against MFSA requirements.
  3. Download the VFA to MiCA migration checklist for a complete document and action list.
  4. Book a confidential intake consultation to discuss your application strategy.

What to prepare for your first consultation:

  • KYC documents for directors and beneficial owners passports, proof of address, CVs.
  • Corporate charter and shareholder structure group chart and constitutional documents.
  • Business plan including target markets, services and revenue model.
  • Token whitepaper (if applicable) describing the crypto-asset and its functionality.
  • IT architecture summary high-level diagram of technology stack, hosting and security measures.

Appendix: Downloads and Resources

The following resources support your Malta CASP application:

  • VFA to MiCA migration checklist comprehensive PDF with document requirements, timeline guidance and post-authorisation obligations summary (available for download).
  • MFSA Authorisations and Application Forms access the LH Portal guidance and current application forms at mfsa.mt/our-work/authorisations.
  • MFSA Crypto-Assets guidance mfsa.mt/our-work/crypto-assets.
  • MiCA Regulation (EU) 2023/1114 full text and summary at EUR-Lex.
  • Malta Markets in Crypto-Assets Act (Chapter 647) legislation.mt.

Sources

FAQs

Is the Malta VFA licence still valid for new applicants?
No. Following the enactment of the Markets in Crypto-Assets Act (Chapter 647) and the full application of MiCA, the MFSA no longer accepts new applications under the legacy VFA Act. All new applicants must apply for CASP authorisation under the MiCA framework. Existing VFA licence holders continue to operate under transitory provisions while they complete the migration process.
Existing VFA licence holders must submit a CASP authorisation application to the MFSA via the LH Portal within the transition window specified in Chapter 647. The MFSA’s published transition guidance outlines the required documentation, gap-analysis steps and recommended sequencing. Upon receiving CASP authorisation, the legacy VFA licence is surrendered.
Applicants must demonstrate a sound corporate structure with local establishment in Malta, adequate initial capital, fit and proper directors and beneficial owners, robust AML/CFT policies, comprehensive technology and security arrangements, and a viable business plan. All requirements are detailed in the MFSA Authorisations guidance and applicable MiCA provisions.
Total costs depend on the service categories applied for and the complexity of the business model. Applicants should budget for MFSA application and supervisory fees, minimum capital requirements, and professional advisory costs. The overall investment typically ranges from approximately €85,000 to over €275,000 when including all cost components. The application timeline from pre-application engagement to licence grant is typically six to twelve months.
Yes. A CASP authorised in Malta under MiCA (Regulation (EU) 2023/1114) can provide its authorised crypto-asset services across all EEA member states through a notification (passporting) procedure, without needing separate national authorisations. This is one of MiCA’s most commercially significant features.
The MFSA requires corporate constitutional documents, a detailed business plan and financial projections, fit and proper evidence for all key individuals, AML/CFT policies and procedures, technology architecture and ICT risk documentation, a systems auditor report, and evidence of adequate capital. Detailed requirements are published on the MFSA Authorisations page.
The MFSA expects CASPs to maintain robust ICT governance, including penetration testing, vulnerability assessments, cryptographic key management, incident reporting protocols, business continuity plans, and documented outsourcing controls. These requirements are detailed in the MFSA’s Technology Arrangements and ICT Risk Management addendum.

Our Expert

Jonathon Richards

Global Law Experts

Find the right Advisory Expert for your business

The premier guide to leading advisory professionals throughout the world

Specialism
Country
Practice Area
ADVISORS RECOGNIZED
0
EVALUATIONS OF ADVISORS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Join
who are already getting the benefits
0

Sign up for the latest advisor briefings and news within Global Advisory Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.

Naturally you can unsubscribe at any time.

About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Global Law Experts App

Now Available on the App & Google Play Stores.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Contact Us

Stay Informed

Join Mailing List
About Us

Global Advisory Experts is dedicated to providing exceptional advisory services to clients around the world. With a vast network of highly skilled and experienced advisors, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Global Law Experts App

Now Available on the App & Google Play Stores.

Contact Us

Stay Informed

GAE

Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Malta VFA Licence (mica Transition): MFSA Guidance, Eligibility and Application Steps

Send welcome message

Custom Message