The UAE has not tweaked its crypto rules - it has rewritten them. On 13 February 2026, the Capital Markets Authority (CMA) issued Decision No. 4/R.M/2026, replacing the country's federal framework for virtual asset service providers (VASPs) in its entirety. This is not an amendment to the old regime; it is a ground-up reconstruction of how virtual assets are licensed, governed, and supervised at the federal level.
The regulator itself is new. Under Federal Decree-Law No. 32 of 2025, the Securities and Commodities Authority was reconstituted as the Capital Markets Authority on 1 January 2026, with a companion law - Federal Decree-Law No. 33 of 2025 - formally bringing virtual assets within the scope of regulated financial activities. In short, both the rulebook and the rule-maker changed at once.
For any firm operating onshore in the UAE, this is the single most consequential regulatory development of the year. Having worked alongside firms navigating exactly this transition, we have found that the businesses moving early are the ones treating the detail below as a roadmap, not a warning.
Three Modules, One Rulebook
The new framework is organised across three interlocking modules, each governing a distinct layer of compliance:
- General Framework Module: definitions, scope, and the licensing regime itself.
- Business Regulation Module: the day-to-day operational rules - client classification, records, margin, and staking.
- Alternative Trading System (ATS) Module: the requirements for multi-party trading platforms and their technology governance.
Together they form a single, consolidated rulebook - a marked shift from the broader, less structured categories of the prior regime.
Eight Licensed Activities - Each One Standalone
The framework defines eight licensed virtual asset activities, including dealing as principal, dealing as agent, custody, operating a multilateral trading facility, portfolio management, investment advice, and arranging investment transactions. The critical point is that each activity is licensed on a standalone basis - you must hold authorisation for every activity you conduct. Operating any of them without a valid licence is prohibited and triggers sanctions under Cabinet Resolution No. 99 of 2024.
Capital: Floors, Not Ceilings
The revised capital architecture is one of the framework's sharpest changes. Fixed minimums range from around AED 500,000 for a trading platform to roughly AED 4 million for dealing as principal - but these are floors, not final figures. The CMA may additionally require capital calculated at 25–35% of projected annual expenses, or on a risk-based basis, whichever is higher. Where a firm runs multiple activities, the highest applicable requirement governs.
On top of that, firms must hold liquid financial resources covering at least six months of operating expenses. The intent is deliberate: only well-capitalised, operationally mature firms should participate at federal level. For trading-heavy or institutional businesses, the effective requirement can therefore sit well above the headline floor.
Governance: Six Roles and Real Residency
The CMA expects accountability to live in the UAE, not offshore. Licensed firms must appoint six senior roles at all times - CEO, Senior Executive Officer, Compliance Officer, MLRO, Finance Director, and Internal Auditor - with the CEO, Compliance Officer, and MLRO required to reside in the UAE. Firms running compliance remotely will need to restructure before they can hold a licence.
What's Banned Outright
Three categories are prohibited with no exceptions: privacy tokens and privacy-enhancing techniques (such as Monero, Zcash, and Dash), algorithmic tokens (a direct response to past stablecoin collapses), and discretionary, organised trading facilities - all crypto trading must occur on non-discretionary, rules-based platforms. Utility tokens and NFTs sit in a narrow restricted zone, permitted only with the CMA's prior approval.
The Day-to-Day Obligations That Catch Firms Out
Beyond licensing and capital, the Business Regulation Module imposes detailed ongoing duties that are easy to underestimate:
- Client classification: every client categorised as Retail, Professional, or Counterpart before service, reviewed every three years.
- Six-year record retention: agreements, transactions, suitability reports, and complaints - a hard legal requirement.
- Annual technology audit: platform operators and custodians must appoint an external auditor, reporting to the CMA within four months of year-end.
- Cybersecurity: board-level adoption, annual penetration testing, and 72-hour incident reporting.
- Controller pre-approval: prior written CMA approval before crossing 30% or 50% ownership thresholds.
Defined Timelines - and a Hard Deadline
There is genuine good news for applicants. For the first time, the framework sets defined processing timelines - in the region of 45 working days for preliminary approval and 60 working days for the full licence decision. For founders accustomed to waiting a year or more elsewhere, this predictability is a meaningful advantage.
But existing licensees should not mistake structure for leniency. Firms already holding a licence have until 13 February 2027 to comply, and those still in the application stage have a shorter window. The penalties for getting it wrong are severe: operating without authorisation can attract imprisonment and fines of up to AED 250 million under Federal Decree-Law No. 33 of 2025.
Where It Sits With VARA, ADGM, and DIFC
The CMA framework is a federal baseline, not a single national regime. It sits alongside VARA in Dubai, the FSRA in ADGM, the DFSA in DIFC, and the CBUAE for payment tokens. Compliance with one does not substitute for another - a VARA licence does not satisfy the CMA, and vice versa.
Key Takeaways
- It's a rebuild, not a revision: Decision No. 4/R.M/2026 replaced the federal regime entirely, under a newly reconstituted regulator.
- Licence every activity: eight standalone activities, each requiring its own authorisation.
- Budget beyond the floor: the binding capital figure is the highest of fixed, expense-based, and risk-based tests, plus six months of liquidity.
- Bring accountability onshore: six senior roles, with CEO, CO, and MLRO resident in the UAE.
- The deadline is closer than it looks: existing licensees must comply by 13 February 2027 - and gap analysis takes time.
The new framework rewards firms that move deliberately - mapping activities, modelling capital, and closing governance gaps well ahead of the deadline. CFC MENA is actively supporting firms through exactly this transition, from activity mapping and capital modelling to gap analysis and regulatory submissions. If you hold or are pursuing a UAE licence, speak to our team to build your path to compliance before February 2027.

Jun 2, 2026
Beat the February 2027 DeadlineExisting UAE crypto licensees must comply with the CMA's new framework by 13 February 2027. Use this gap-analysis checklist to migrate before time runs out.
.png)

.png)
