Cryptoassets Regulatory Intelligence cryptoassets.gi
GI · run crypto-compose-GI-2026-08-03 v13.3.0
content: not recorded not recorded sources retrieved model not recorded ·

Gibraltar

GI schema crypto-v2.0.0 trajectory: not recordedregulatedoverlaps: FIM, WPM

Last updated · 7 categories · 24 sourced findings · not recorded sources in the cumulative register

7Categoriesbaseline.
24Findings.claims[]
2Tier-1 sourcesrun_metadata.t1_source_count
Confidence mix (sums to 7 rendered categories; click to filter)
No categories moved this cycle.

Jurisdiction lead brief

Lead Signal

Gibraltar's crypto licensing perimeter has materially widened. Effective 27 October 2025, the Financial Services (Regulated Activities) (Amendment) Regulations 2025 inserted a second regulated activity into the Financial Services Act 2019: Virtual Asset Arrangement Providers (VAAPs), covering by-way-of-business exchange of virtual assets for fiat currency or for other virtual assets. Firms conducting this activity now require Part 7 permission from the Gibraltar Financial Services Commission (GFSC), in addition to -- and distinct from -- the pre-existing Distributed Ledger Technology (DLT) Provider licensing route that has governed custodial value-transmission activity since 2018. The amendment carries a 14-day notification window and a six-month application transition period for firms already conducting the newly captured activity. This is the first time Gibraltar's licensing perimeter has been expanded to reach exchange-type activity as a standalone regulated category, rather than folding it into the general DLT Provider license by inference. The finding currently rests on secondary law-firm commentary (Hassans, Triay Lawyers, IR Global) rather than the primary statutory instrument or GFSC guidance-note text, and is held at Probable confidence pending that primary-source confirmation -- a gap that should be closed before the finding is treated as settled for licensing-scope determinations.

7 of 7 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Gibraltar operates a mature, principles-based DLT Provider licensing regime under the Financial Services (Distributed Ledger Technology Providers) Regulations 2020, requiring firms that use distributed ledger technology to store or transmit value belonging to others to obtain a GFSC license before operating. Licensing is structured around ten guiding regulatory principles as of 2022, covering honesty/integrity, customer asset protection, cybersecurity, financial crime prevention and market integrity, with fees and supervisory scrutiny scaling with activity complexity. On 27 October 2025, the Financial Services (Regulated Activities) (Amendment) Regulations 2025 brought Virtual Asset Arrangement Providers into the Financial Services Act 2019 as a second regulated activity, requiring Part 7 GFSC permission for by-way-of-business exchange of virtual assets for fiat or other virtual assets, alongside the pre-existing DLT Provider custody licensing perimeter, with a 14-day notification and six-month application transition window. This latest expansion currently rests on secondary law-firm reporting rather than the primary statutory text.

Standing sub-brief535 words · last cycle cry-2026-08-03

Crypto Licensing

Gibraltar's crypto licensing framework centres on the Financial Services (Distributed Ledger Technology Providers) Regulations 2020, made under the Financial Services Act 2019, which requires any firm using distributed ledger technology to store or transmit value belonging to others to obtain a GFSC license before commencing operations. This DLT Provider licensing requirement has been in force since 2018 and represents Gibraltar's foundational crypto regulatory perimeter -- a firm-agnostic, technology-defined trigger rather than an activity-by-activity licensing menu. Licensing conditions are structured around a set of guiding regulatory principles rather than a prescriptive rulebook: as of the 2022 update, ten principles apply, covering honesty and integrity, customer asset protection, cybersecurity, financial-crime prevention, and market integrity, up from nine principles at the framework's founding. This principles-based approach gives the GFSC latitude to apply licensing conditions proportionately, and fee/scrutiny levels scale with activity complexity -- higher-risk categories such as crypto derivatives trading (category three) have historically carried substantially higher application fees and closer supervisory scrutiny than lower-risk custodial activity.

No periodic updates recorded against this sub-brief.

Sources and findings (4)
  1. T4Gibraltar Financial Services Commission (GFSC)DLT providers using distributed ledger technology to store or transmit value belonging to others to obtain a license before operatingretrieved M5bindingin force
  2. T4GFSC DLT guiding principlesten guiding regulatory principles (expanded from nine in 2022) covering honesty/integrity, customer asset protection, cybersecurity, financial crime prevention and market integrityretrieved M4bindingin force
  3. T4GFSC license category frameworkactivity complexity, with higher-risk categories (e.g. category three crypto derivatives trading) carrying substantially higher application fees and scrutinyretrieved M3bindingin force
  4. T3Financial Services (Regulated Activities) (Amendment) Regulations 2025Part 7 permission from the GFSC for Virtual Asset Arrangement Providers (VAAPs) conducting by-way-of-business exchange of virtual assets for fiat or other virtual assets, in addition to the pre-existing DLT Provider custody licensing perimeter; brings VAAs into the Financial Services Act 2019 (Part 16 Schedule 2, new paragraphs 139A/139B) as a second regulated activity, with a 14-day notification and 6-month application transition windowretrieved M4bindingin forcenew

#

Gibraltar has not adopted a codified statutory token classification scheme equivalent to MiCA. GFSC guidance distinguishes 'virtual assets' from higher-risk 'virtual asset denominated instruments' (VADIs) without creating a formal taxonomy. A subsequent GFSC Guidance Note on Scope of the DLT Framework, reportedly updated after the October 2025 VAA amendment, further distinguishes the DLT Provider pathway from the Virtual Asset Arrangement Provider pathway, though this development is not yet independently confirmed against primary sourcing. Separately, at least one Gibraltar-incorporated 2018 security-token-style offering was structured under general Gibraltar company and contract law rather than a dedicated statutory security-token regime, and the GFSC's 2020 guidance update restricts DLT providers from counting reserves of internally generated tokens toward regulatory capital following a public token offering, while adding stablecoin-specific risk-management content.

Standing sub-brief396 words · last cycle cry-2026-08-03

Token Classification

Gibraltar has not adopted a codified statutory token classification scheme comparable to the EU's MiCA taxonomy of asset-referenced tokens, e-money tokens, and other crypto-assets. Instead, the GFSC operates through guidance: its framework distinguishes "virtual assets" from a higher-risk category termed "virtual asset denominated instruments" (VADIs), a distinction introduced in the GFSC's 2020 guidance update aligning the DLT framework with FATF crypto-asset standards. This distinction functions as a risk-tiering device within guidance rather than a formal legal classification with attached statutory consequences, meaning classification outcomes for any given token remain a matter of GFSC case-by-case guidance application rather than rule-based self-assessment.

No periodic updates recorded against this sub-brief.

Sources and findings (3)
  1. T4GFSC guidance on virtual assets vs VADIs'virtual assets' from higher-risk 'virtual asset denominated instruments' (VADIs) without creating a formal statutory classification scheme equivalent to MiCAretrieved M4non-binding
  2. T32018 Gibraltar-incorporated security-token-style offeringgeneral Gibraltar company and contract law rather than a dedicated statutory security token regimeretrieved M2non-binding
  3. T4GFSC 2020 guidance updateDLT providers from counting reserves of internally generated tokens toward regulatory capital following a public token offering, and adds stablecoin-specific risk-management contentretrieved M3bindingin force

#

Gibraltar has no activity-specific licensing category for staking, DeFi lending, or decentralized exchange (DEX) operation distinct from the general DLT/VAA licensing perimeter. The GFSC signalled intent in November 2022 to focus further regulatory development on DeFi lending without enacting a dedicated licensing category. Staking activity conducted for third parties would likely fall under the general DLT provider license, though no dedicated staking category exists. Similarly, no dedicated category exists for DEX operation beyond general DLT provider licensing, though this framing should be read alongside the October 2025 Virtual Asset Arrangement Provider amendment, which may bring by-way-of-business exchange/arrangement-of-exchange activity -- potentially including DEX-facilitation models -- within the regulated perimeter; this has not yet been independently confirmed against primary GFSC guidance.

Standing sub-brief334 words · last cycle cry-2026-08-03

On-Chain Activity Regime

Gibraltar's DLT framework does not contain activity-specific licensing categories for staking, DeFi lending, decentralized exchange (DEX) operation, mining, or validator/node operation. The GFSC signalled supervisory intent in November 2022 -- following that year's market turmoil -- to focus further regulatory development on DeFi lending, but no dedicated DeFi lending licensing category has since been enacted; this remains a stated area of supervisory interest rather than a rule. Staking-related services conducted for third parties would most likely fall under the general DLT Provider license by virtue of the license's technology-defined, value-transmission trigger, though no staking-specific guidance or category has been separately identified, and this finding is grounded in a GFSC reference-anchor source rather than a specific staking guidance page. Decentralized exchange operation similarly lacks a dedicated category beyond general DLT provider licensing on the same reference-anchor basis.

No periodic updates recorded against this sub-brief.

Sources and findings (3)
  1. T4GFSCdecentralized finance (DeFi) lending as a focus area for further regulatory development (Nov 2022), without enacting a dedicated DeFi lending licensing categoryretrieved M3non-binding
  2. T2Gibraltar DLT frameworkstaking activity; staking-related services would likely fall under the general DLT provider license if conducted for third partiesretrieved M2non-binding
  3. T2Gibraltar DLT frameworkdecentralized exchange (DEX) operation beyond general DLT provider licensingretrieved M2non-binding

#

Gibraltar lacks a dedicated statutory stablecoin issuance authorisation regime comparable to MiCA's e-money/asset-referenced token framework. The GFSC's 2020 guidance update added a dedicated section on stablecoin-specific risks within broader token-issuance guidance for DLT providers, and in November 2022 the GFSC signalled intent to further develop stablecoin-specific rules, but no codified reserve-composition or reserve-adequacy requirement specific to stablecoin issuers has been identified, and no enacted rule has been confirmed as of this cycle.

Standing sub-brief237 words · last cycle cry-2026-08-03

Stablecoin Regime

Gibraltar has not enacted a dedicated statutory stablecoin issuance authorisation regime comparable to MiCA's e-money-token or asset-referenced-token frameworks. The closest existing coverage is guidance-level: the GFSC's 2020 guidance update added a dedicated section addressing stablecoin-specific risks within its broader token-issuance guidance for DLT providers, covering risk-management expectations for issuers rather than establishing a licensing or authorisation gate specific to stablecoin issuance. In November 2022, the GFSC signalled intent to develop stablecoin-specific rules further, in the same statement in which it flagged DeFi lending as a focus area, but no enacted issuance-authorisation or reserve-adequacy rule has been identified as having followed from that stated intent. No codified reserve-composition or reserve-adequacy requirement specific to stablecoin issuers exists in Gibraltar's DLT framework as currently documented, and this absence is grounded in a GFSC reference-anchor source rather than a dedicated reserve-requirement guidance page.

No periodic updates recorded against this sub-brief.

Sources and findings (3)
  1. T4GFSC 2020 guidance updatea dedicated section detailing stablecoin-specific risks as part of broader token-issuance guidance for DLT providersretrieved M3bindingin force
  2. T4Gibraltar stablecoin regimea dedicated statutory stablecoin issuance authorisation regime akin to MiCA's e-money/asset-referenced token framework; GFSC signalled 2022 intent to further develop stablecoin-specific rulesretrieved M4non-binding
  3. T2Gibraltar DLT frameworka codified reserve-composition or reserve-adequacy requirement specific to stablecoin issuersretrieved M3non-binding

#

Gibraltar's consumer protection framework for crypto activity rests on the GFSC's principles-based DLT licensing conditions rather than a standalone crypto consumer-protection statute. Customer asset protection is a mandatory condition of holding a DLT Provider license under the founding guiding principles, and the tenth guiding principle added in 2022 requires DLT providers to maintain market integrity, including measures against price/liquidity/information manipulation and insider trading by employees. The GFSC has also issued an investor warning on ICO risks, developed alongside complementary token-sale guidance aligned with the DLT framework. No dedicated crypto-specific complaint-handling rule distinct from Gibraltar's general financial-services complaint-handling framework has been identified.

Standing sub-brief269 words · last cycle cry-2026-08-03

Consumer Protection

Gibraltar addresses crypto consumer protection through the same principles-based licensing conditions that govern DLT Provider licensing generally, rather than through a standalone crypto consumer-protection statute. Customer asset protection has been a mandatory condition of holding a DLT Provider license since the framework's founding guiding principles took effect in 2018, meaning licensed firms are required to protect customer assets as a baseline licensing obligation rather than as a supplementary conduct rule. The tenth guiding principle, added in the 2022 principles expansion, requires DLT providers to maintain market integrity, implementing measures against price, liquidity and information manipulation and against insider trading by employees -- extending consumer-protection-adjacent obligations into market-conduct territory. Separately, the GFSC has issued an investor warning addressing initial coin offering (ICO) risks, developed prior to, and complementary to, token-sale guidance aligned with the broader DLT framework, giving retail investors a documented risk-warning reference point specific to token-sale participation.

No periodic updates recorded against this sub-brief.

Sources and findings (4)
  1. T4GFSC founding DLT guiding principlesDLT providers to protect customer assets as a mandatory condition of holding a DLT Provider licenseretrieved M4bindingin force
  2. T4GFSC tenth guiding principle (2022)DLT providers to maintain market integrity, implementing measures against price/liquidity/information manipulation and insider trading by employeesretrieved M4bindingin force
  3. T4GFSCan investor warning on initial coin offering (ICO) risks prior to developing complementary token-sale guidance aligned with the DLT frameworkretrieved M3bindingin force
  4. T2Gibraltar DLT provider frameworka dedicated crypto-specific complaint-handling rule distinct from Gibraltar's general financial-services complaint-handling frameworkretrieved M2non-binding

#

Gibraltar's general tax regime structurally excludes capital gains from taxable corporate profit, per an EU Commission review of Gibraltar's corporate tax reform -- a general corporate finding rather than a crypto-specific ruling. No crypto-specific income tax guidance has been issued by the Gibraltar Income Tax Office, meaning crypto-asset trading businesses would generally fall within ordinary Gibraltar income/corporate tax rules absent such guidance. Crypto-specific VAT/GST treatment of digital-asset transactions has not been confirmed, nor has a crypto-specific tax reporting obligation distinct from general Gibraltar tax filing requirements been issued.

Standing sub-brief257 words · last cycle cry-2026-08-03

Tax Treatment

Gibraltar's general tax regime structurally excludes capital gains from the calculation of taxable corporate profit, a finding drawn from an EU Commission review of Gibraltar's corporate tax reform. This is a general corporate-tax structural feature rather than a crypto-specific ruling, and it applies to corporate profit generally rather than being framed by Gibraltar's Income Tax Office as a digital-asset-specific exemption. Beyond this structural feature, no crypto-specific income tax guidance has been issued by the Gibraltar Income Tax Office; in the absence of such guidance, crypto-asset trading businesses would generally be expected to fall within ordinary Gibraltar income and corporate tax rules, though this is an inference from the absence of specific guidance rather than a confirmed Income Tax Office position. Crypto-specific VAT/GST treatment of digital-asset transactions has not been confirmed one way or the other, and no crypto-specific tax reporting obligation distinct from Gibraltar's general tax filing requirements has been issued.

No periodic updates recorded against this sub-brief.

Sources and findings (4)
  1. T1Gibraltar general tax regimecapital gains from the calculation of taxable corporate profit, per an EU Commission review of Gibraltar's corporate tax reform (general corporate finding, not a crypto-specific ruling)retrieved M3bindingin force
  2. T2Gibraltar Income Tax Officecrypto-specific income tax guidance; crypto-asset trading businesses would generally fall within ordinary Gibraltar income/corporate tax rules absent such guidanceretrieved M3non-binding
  3. T2Gibraltar VAT/indirect tax regimecrypto-specific VAT/GST treatment of digital-asset transactionsretrieved M2non-binding
  4. T2Gibraltar Income Tax Officea crypto-specific tax reporting obligation distinct from general Gibraltar tax filing requirementsretrieved M2non-binding

#

Gibraltar-licensed DLT providers are not subject to a dedicated statutory outbound-restriction regime specific to cryptoasset transfers beyond general AML/sanctions-screening obligations under the Proceeds of Crime Act framework; substantive AML/CTF analysis of this framework is addressed separately under the financial-integrity monitor's aml_cft_regime subscription. Gibraltar's FATF/MONEYVAL follow-up assessment has not identified virtual-asset-transfer-specific cross-border sanctions provisions distinct from its general financial sanctions regime, and no cryptoasset-specific cross-border reporting threshold for outbound transfers has been identified.

Standing sub-brief188 words · last cycle cry-2026-08-03

Cross-Border Transfer

Gibraltar-licensed DLT providers are not subject to a dedicated statutory outbound-restriction regime specific to cryptoasset transfers, beyond general AML/sanctions-screening obligations arising under the Proceeds of Crime Act framework. The substance of that AML/sanctions framework is addressed separately under the financial-integrity monitor's aml_cft_regime subscription and is out of scope for this module beyond this disambiguating finding. Gibraltar's FATF/MONEYVAL follow-up assessment (December 2021) has not identified virtual-asset-transfer-specific cross-border sanctions provisions distinct from Gibraltar's general financial sanctions regime, suggesting that cryptoasset transfers are currently treated under Gibraltar's general sanctions architecture rather than a bespoke virtual-asset sanctions nexus. No cryptoasset-specific cross-border reporting threshold for outbound transfers has been identified in Gibraltar's cryptoasset framework.

No periodic updates recorded against this sub-brief.

Sources and findings (3)
  1. T1Gibraltar-licensed DLT providersa dedicated statutory outbound-restriction regime specific to cryptoasset transfers beyond general AML/sanctions-screening obligations under the Proceeds of Crime Act framework (addressed separately under the financial-integrity aml_cft_regime subscription)retrieved M3non-binding
  2. T1Gibraltar sanctions frameworkvirtual-asset-transfer-specific cross-border sanctions provisions distinct from its general financial sanctions regime, per its FATF/MONEYVAL follow-up assessmentretrieved M3non-binding
  3. T2Gibraltar cryptoasset frameworka cryptoasset-specific cross-border reporting threshold for outbound transfersretrieved M2non-binding
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Gibraltar
FieldValue
trust.lawyer_review.statusnot recorded
trust.lawyer_review.reviewernot recorded
trust.content_sourcenot recorded

Provenance and declared absence

Disclosure model: module cards load OPEN; standing positions render in full; sub-briefs and jurisdiction briefs load as a clamped teaser with an explicit “read full” control carrying the true word count; earlier updates stay collapsed behind a counted summary. No text is hidden without disclosing how much of it there is.

Sentinel-fed modules receive no special rendering treatment. sentinel_feed is an attribution chip only: it does not suppress content, does not generate an absence reason code, and does not exclude the module from any count, filter, search index or export on this page.

Family taxonomy is renderer-level presentation config, not a JID field. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; per-module RAG traffic light; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-17. A year-precision row is never promoted into a tighter band.

Orphan deltas: 0 cycle_delta row(s) target non-module objects and are listed in the rail rather than attached to a card.

Envelope: baseline resolved at jurisdiction_json.baseline; 7 module(s), 24 finding(s), 30 source(s) in the cumulative register.