Licensing, Capital, Compliance and Market-Entry Requirements for Exchanges, Wallets, Brokers, Payment Platforms, Stablecoins and Tokenisation Businesses

A founder arrives in Nairobi with an idea that appears simple.

Her company wants to help Kenyan customers buy stablecoins, store them in a mobile wallet and send them across borders. The platform is already operating in another country. The technology works. Investors are interested. The commercial team has identified local partners.

The founder assumes that the Kenyan launch will involve three tasks:

  1. incorporate a company;
  2. connect the platform to local payment channels; and
  3. begin onboarding customers.

Then the legal review starts.

The proposed platform does not perform only one activity. It facilitates crypto purchases, controls customer wallets, processes fiat-to-virtual-asset transactions and earns fees from Kenyan customers. Depending on its exact structure, it may require approvals covering wallet services, payment processing and virtual asset trading.

The founder’s question changes immediately.

It is no longer:

“How quickly can we launch?”

It becomes:

“How do we build a business that Kenya is prepared to license?”

That is the central question facing every entrepreneur seeking to start a crypto business in Kenya in 2026.

Kenya now has a dedicated regulatory framework for virtual asset businesses. The Virtual Asset Service Providers Act, 2025, together with the Virtual Asset Service Providers Regulations, 2026, establishes licensing, governance, capital, cybersecurity, consumer protection, market conduct and enforcement requirements for businesses providing virtual asset services in or from Kenya.

The framework covers far more than traditional cryptocurrency exchanges. It also reaches custodial wallets, crypto payment processors, brokers, investment advisers, virtual asset managers, tokenisation providers, token issuance platforms, initial coin offerings and stablecoin issuers.

This guide explains what founders, investors and international crypto companies need to know before entering the Kenyan market.

1. Is It Legal to Start a Crypto Business in Kenya?

Yes—but regulated virtual asset services must be conducted through an appropriately licensed business.

Kenya has not chosen to ban virtual assets. Instead, it has created a formal regulatory framework intended to license and supervise virtual asset service providers, promote responsible innovation, protect consumers and address risks involving financial crime, market abuse, cybersecurity and financial stability.

The Virtual Asset Service Providers Act entered into force on 4 November 2025. Its central purpose is to establish a legislative framework for licensing and regulating virtual asset service providers operating in and from Kenya.

The Regulations subsequently established the detailed rules governing:

  • licence applications;
  • regulatory fees;
  • capital and liquidity;
  • ownership and governance;
  • fit-and-proper assessments;
  • operational policies;
  • cybersecurity;
  • safeguarding of customer assets;
  • advertisements;
  • market conduct;
  • token offerings;
  • stablecoin issuance;
  • regulatory reporting; and
  • enforcement.

Therefore, the relevant question is not whether crypto is generally legal in Kenya.

The correct question is:

Does the activity your company intends to conduct fall within one of Kenya’s regulated virtual asset service categories?

Where the answer is yes, a Kenya crypto licence will generally be required before the business launches or markets that service.

2. Who Regulates Crypto Businesses in Kenya?

Kenya uses a dual-regulator model.

The two principal authorities are:

  • the Central Bank of Kenya; and
  • the Capital Markets Authority.

The applicable regulator depends on the nature of the proposed activity.

Central Bank of Kenya

CBK is responsible for activities that are closely connected to payments, custody and stable-value virtual assets.

These include:

  • virtual asset wallet providers;
  • virtual asset payment processors; and
  • stablecoin issuers.

Capital Markets Authority

CMA regulates virtual asset activities involving trading, brokerage, investment management, advice and token offerings.

These include:

  • virtual asset exchanges;
  • virtual asset brokers;
  • virtual asset investment advisers;
  • virtual asset managers;
  • initial coin offering providers;
  • virtual asset tokenisation providers; and
  • token issuance platforms.

The Act gives the regulators licensing, supervision, monitoring and enforcement powers. They are also expected to support financial stability, market integrity, innovation, transparency and protection of Kenya’s financial reputation.

Why selecting the correct regulator matters

A founder may describe a platform as a “crypto app”, but the legal structure may involve several regulated activities.

For example, a single application may allow customers to:

  • purchase Bitcoin using Kenyan shillings;
  • store it in a hosted wallet;
  • exchange it for USDT;
  • send it to another user; and
  • use it to pay a merchant.

That one customer journey may involve trading, custody and payment processing.

The business should therefore complete a regulatory perimeter assessment before deciding which authority to approach.

3. Which Crypto Businesses Require a Licence in Kenya?

Kenya regulates activities rather than marketing labels.

Calling a company a “blockchain technology provider” does not prevent it from being regulated where the underlying service amounts to custody, exchange, payment processing, brokerage or other licensed activity.

The following categories are especially important.

3.1 Virtual Asset Exchange

A virtual asset exchange generally facilitates the purchase, sale or exchange of virtual assets.

The activity may include:

  • crypto-to-fiat trading;
  • fiat-to-crypto trading;
  • crypto-to-crypto trading;
  • matching buyers and sellers;
  • operating an order book;
  • providing trading infrastructure;
  • clearing and settlement; or
  • purchasing an asset from a seller and reselling it to a matched buyer.

An exchange is more than a website displaying prices. The regulator will examine who receives orders, how prices are determined, who executes transactions, where assets are held and how the platform earns revenue.

A business planning to start a crypto exchange in Kenya will generally need a licence from CMA.

It may also require additional approval if it provides hosted wallets or payment-processing functionality.

3.2 Virtual Asset Broker

A broker facilitates virtual asset transactions for clients.

This category may include:

  • OTC crypto desks;
  • client order execution;
  • sourcing liquidity;
  • introducing buyers and sellers;
  • arranging large private trades;
  • purchasing or selling assets for clients;
  • earning commissions or spreads; and
  • executing transactions through third-party exchanges.

A founder may assume that an OTC desk is outside regulation because it does not operate an open order book. That assumption can be dangerous.

Where the business arranges or facilitates transactions for a fee, it may fall within the virtual asset broker category.

3.3 Custodial Wallet Provider

A custodial wallet provider holds or manages private keys for customers.

The activity may include:

  • hosted retail wallets;
  • institutional custody;
  • hot and cold wallet services;
  • transaction authorisation;
  • safeguarding virtual assets;
  • withdrawal processing; and
  • recovery or key-management services.

The important question is control.

Where the customer does not have exclusive control over the private keys, the provider may be carrying on custodial wallet activity.

A purely non-custodial wallet may fall outside this category, but the assessment must consider whether the provider controls transaction approvals, recovery functions, smart-contract administration or access to customer funds.

Wallet providers are regulated by CBK.

3.4 Virtual Asset Payment Processor

A virtual asset payment processor arranges transactions involving fiat currency and virtual assets or transactions between virtual assets.

This may include:

  • merchant crypto-payment gateways;
  • crypto-to-fiat settlement;
  • fiat-to-crypto payment conversion;
  • cross-border virtual asset payments;
  • payment routing;
  • merchant collection services;
  • crypto on-ramp services; and
  • crypto off-ramp services.

A company may still fall within the payment-processing category even where conversion or custody is outsourced.

The regulator will examine the customer-facing service and determine who is responsible for arranging or facilitating the payment.

3.5 Virtual Asset Investment Adviser

A licence may be required where a company provides advice or recommendations concerning virtual assets.

This could include:

  • personalised token recommendations;
  • portfolio-allocation advice;
  • crypto investment research tailored to clients;
  • advice relating to initial coin offerings;
  • advice relating to NFTs with investment features; or
  • recommendations to buy, hold or sell specific virtual assets.

General education may be treated differently from regulated investment advice.

However, placing a disclaimer stating “not financial advice” does not automatically protect a business where the actual service is personalised and recommendation-based.

3.6 Virtual Asset Manager

A virtual asset manager exercises discretion over a customer’s portfolio.

This may involve:

  • managed crypto accounts;
  • discretionary trading;
  • portfolio rebalancing;
  • execution of investment mandates;
  • virtual asset fund management; or
  • deciding when and which assets to buy or sell for clients.

Depending on the structure, the business may also fall within wider securities, collective investment or fund regulation.

3.7 Initial Coin Offering Provider

A company issuing and selling virtual assets to raise funds may require authorisation as an initial coin offering provider.

The regulatory assessment may cover:

  • the issuer;
  • promoters;
  • the white paper;
  • offering terms;
  • investor disclosures;
  • advertising;
  • subscription arrangements; and
  • admission to trading.

The company should not assume that describing the asset as a “utility token” removes it from regulation.

The substance of the token, its rights, its economic function and the way it is marketed will matter.

3.8 Tokenisation Provider

Tokenization involves converting rights in real-world assets into digital tokens recorded on distributed ledger technology.

Potential underlying assets include:

  • real estate;
  • commodities;
  • precious metals;
  • receivables;
  • intellectual property;
  • financial claims;
  • art; and
  • contractual rights.

A real estate tokenisation project may involve more than a Kenya VASP licence. The structure may also engage:

  • property law;
  • securities law;
  • collective investment rules;
  • custody;
  • valuation;
  • land-registration requirements;
  • tax; and
  • investor-protection obligations.

Tokenization providers fall under CMA.

3.9 Token Issuance Platform

A token issuance platform provides infrastructure through which third-party projects may create, offer, distribute or list virtual assets.

Examples include:

  • token launchpads;
  • digital issuance portals;
  • token subscription platforms;
  • primary issuance marketplaces; and
  • platforms facilitating token sales.

The platform may require a licence even where it is not itself the issuer.

Its responsibilities may include due diligence, disclosure review, investor onboarding, transaction processing and post-issuance monitoring.

3.10 Stablecoin Issuer

A stablecoin issuer creates a virtual asset designed to maintain a stable value relative to reserve assets.

The peg may relate to:

  • a fiat currency;
  • commodities;
  • other virtual assets; or
  • a basket of assets.

Stablecoin regulation is particularly demanding because the issuer makes an implicit or express promise about value and redemption.

The Regulations contain detailed provisions governing:

  • stablecoin licensing;
  • white papers;
  • issuance;
  • redemption;
  • reserve assets;
  • custody of reserves;
  • investment of reserve funds;
  • conflicts of interest;
  • audits;
  • public disclosures; and
  • reporting.

Stablecoin issuers are regulated by CBK.

4. Does a Foreign Crypto Company Need a Licence in Kenya?

Possibly, yes.

A major feature of the 2026 Regulations is their territorial reach.

They apply to persons offering virtual asset services in or from Kenya. A business may be regarded as operating in or from Kenya where it:

  • actively solicits or targets Kenyan consumers; or
  • derives economic benefit or income from Kenya,

even if the company has no physical presence in the country.

This means a foreign exchange, wallet, broker or payment platform should not assume it is outside Kenyan regulation simply because:

  • it is incorporated overseas;
  • its servers are outside Kenya;
  • its team works remotely;
  • it has no Nairobi office; or
  • customer assets are held abroad.

Indicators that an offshore company is targeting Kenya

A foreign provider may be brought within the Kenyan perimeter where it:

  • accepts Kenyan residents;
  • supports Kenyan shilling deposits or withdrawals;
  • runs Kenya-specific advertisements;
  • uses Kenyan influencers;
  • maintains Kenya-focused social media accounts;
  • partners with Kenyan merchants;
  • pays commissions to Kenyan affiliates;
  • earns transaction revenue from Kenyan users;
  • provides local-language or Kenya-specific customer support; or
  • otherwise structures its service around the Kenyan market.

A licence issued elsewhere may strengthen the company’s application, but it does not automatically authorise the business to operate in Kenya.

5. Which Activities May Be Outside the VASP Framework?

Not every blockchain-related activity requires a Kenya crypto licence.

The Act contains exclusions, but each exclusion must be applied carefully.

Closed-ecosystem assets

A digital asset may fall outside the framework where it operates only within a closed ecosystem and is:

  • not transferable outside the ecosystem;
  • not exchangeable for external goods, services or discounts;
  • not tradable or saleable on an external secondary market;
  • usable only for purposes determined by the issuer; and
  • not exchangeable for fiat currency or virtual assets.

A loyalty point usable only within one company’s application may qualify.

However, allowing external transfer, redemption or trading can materially change the legal position.

Virtual service tokens

A virtual service token may fall outside the definition of a virtual asset where it:

  • is not transferable or exchangeable with third parties; and
  • only provides access to a service or function.

A service-access token should not automatically be treated as exempt merely because it is called a “utility token”. Its actual functionality controls the analysis.

Certain NFTs

An NFT may fall outside the Act where it is not used for payment, investment or another financial purpose and does not represent a financial asset.

A unique digital artwork may qualify.

A fractionalised NFT representing income rights, investment exposure or ownership in property may not.

Central bank digital currencies

Digital representations of fiat currency issued by CBK or another jurisdiction are excluded.

These statutory exclusions are set out in the Act and depend on the nature and function of the asset rather than the name used by the issuer.

6. Who Is Eligible to Apply for a Kenya Crypto Licence?

An applicant must generally be:

  • a company limited by shares incorporated under Kenya’s Companies Act; or
  • a foreign company limited by shares and registered under the Companies Act.

Individuals do not ordinarily apply in their personal capacity for a VASP licence.

The applicant should establish a transparent structure showing:

  • direct shareholders;
  • significant shareholders;
  • ultimate beneficial owners;
  • group companies;
  • directors;
  • senior officers;
  • controlling persons; and
  • the source of invested funds.

The company must also identify its principal place of business and website.

Where the applicant belongs to an international group, the regulator may expect audited consolidated financial statements from the foreign parent.

The eligibility rule and prohibition against carrying on unlicensed virtual asset services are expressly contained in the Act.

7. Minimum Capital Requirements

Capital is one of the first commercial questions a founder should address.

The 2026 Regulations prescribe different minimum paid-up capital requirements for different licence categories.

Licence categoryMinimum paid-up capital
Virtual Asset Investment AdviserNo fixed minimum
Virtual Asset BrokerKSh 10 million
Virtual Asset Payment ProcessorKSh 10 million
Tokenisation ProviderKSh 10 million
Virtual Asset ManagerKSh 20 million
Initial Coin Offering ProviderKSh 20 million
Token Issuance PlatformKSh 20 million
Virtual Asset ExchangeKSh 100 million
Virtual Asset Wallet ProviderKSh 150 million
Stablecoin IssuerKSh 300 million

Paid-up capital means issued and fully paid ordinary shares contributed by shareholders.

It is not an application fee paid to the regulator.

However, the company cannot disregard the requirement when preparing its operational budget. It must maintain adequate capital while also paying for:

  • employees;
  • technology;
  • offices;
  • audits;
  • compliance systems;
  • legal support;
  • cybersecurity;
  • insurance; and
  • general operating expenses.

Liquid-capital requirements

Some categories must also maintain prescribed liquid capital.

Examples include:

  • exchanges: KSh 20 million or 8% of liabilities, whichever is higher;
  • brokers: KSh 2 million or 8% of liabilities, whichever is higher;
  • wallet providers: KSh 30 million or 100% of current liabilities for at least 30 days, whichever is higher;
  • stablecoin issuers: KSh 60 million or 100% of current liabilities for at least 30 days, whichever is higher.

A company that meets the requirement on the day of filing but falls below it immediately after paying operational expenses may become non-compliant.

Therefore, capital planning should include both:

  • the statutory minimum; and
  • a separate operating runway.

8. Kenya Crypto Licence Application and Initial Licence Fees

The regulatory fees vary by activity.

Licence categoryApplication feeInitial licence fee
Investment AdviserKSh 10,000KSh 50,000
Virtual Asset ManagerKSh 50,000KSh 200,000
Virtual Asset BrokerKSh 100,000KSh 100,000
Payment ProcessorKSh 100,000KSh 200,000
Wallet ProviderKSh 100,000KSh 500,000
Virtual Asset ExchangeKSh 100,000KSh 1 million
ICO ProviderKSh 100,000KSh 500,000
Tokenisation ProviderKSh 100,000KSh 500,000
Token Issuance PlatformKSh 100,000KSh 500,000
Stablecoin IssuerKSh 100,000KSh 2 million

The application fee is generally non-refundable. Withdrawing an application results in forfeiture of the fee.

The initial licence fee is payable after approval and before the licence is issued.

The application fee is not the real licence cost

A founder who budgets only for the statutory fee has not budgeted for the licensing project.

The full cost may include:

  • incorporation;
  • corporate structuring;
  • legal and regulatory advice;
  • compliance personnel;
  • executive appointments;
  • financial modelling;
  • AML systems;
  • blockchain analytics;
  • KYC technology;
  • Travel Rule tools;
  • platform development;
  • systems audit;
  • penetration testing;
  • insurance;
  • external audit;
  • premises; and
  • post-licensing compliance.

For complex businesses, the costs of implementation and regulatory capital will substantially exceed the application fee.

9. What Documents Are Required?

The application is document-intensive.

Under regulation 6, an applicant must provide extensive information and supporting evidence, including:

  • personal details, qualifications and experience of directors, senior officers, significant shareholders and beneficial owners;
  • a regulatory business plan;
  • fit-and-proper assessment forms;
  • proof of source of funds;
  • descriptions of systems and controls;
  • operational policies;
  • evidence of paid-up and liquid capital;
  • financial statements;
  • evidence of human and technological resources;
  • an independent information systems audit;
  • vulnerability assessment;
  • penetration testing;
  • cross-border regulatory disclosures;
  • business rules for specified activities;
  • market-integrity controls;
  • classes of virtual assets to be offered;
  • incorporation documents;
  • director and shareholder records;
  • beneficial ownership records; and
  • proof of payment of the application fee.

The regulator may also require the applicant to attend an interview.

Core policy documents

The application should include policies addressing:

  • enterprise risk management;
  • AML/CFT/CPF;
  • data protection and privacy;
  • cybersecurity and information technology;
  • complaints management;
  • market conduct;
  • consumer protection;
  • conflicts of interest; and
  • business continuity and disaster recovery.

Additional activity-specific documents may be required.

An exchange may need:

  • token admission criteria;
  • listing and delisting procedures;
  • order-execution rules;
  • market-surveillance controls;
  • settlement procedures; and
  • market-abuse monitoring.

A wallet provider may need:

  • private-key controls;
  • custody procedures;
  • hot and cold wallet management;
  • asset segregation;
  • withdrawal approval rules; and
  • recovery procedures.

A stablecoin issuer may need:

  • reserve-management policies;
  • redemption procedures;
  • reserve custody arrangements;
  • white-paper disclosures;
  • liquidity controls;
  • audit procedures; and
  • wind-down planning.

10. The Regulatory Business Plan

The business plan is one of the central documents in the application.

It should not read like an investor pitch deck.

A regulatory business plan must demonstrate that the applicant understands:

  • what activities it will conduct;
  • how those activities work;
  • who bears each risk;
  • how customers will be protected;
  • how the company will remain financially viable; and
  • how it will comply with the law.

The business plan should cover:

  • corporate background;
  • ownership structure;
  • regulated services;
  • target customers;
  • customer onboarding;
  • transaction flows;
  • fiat and virtual asset movements;
  • custody;
  • pricing;
  • revenue;
  • technology;
  • compliance;
  • cybersecurity;
  • outsourcing;
  • governance;
  • staffing;
  • risk management;
  • consumer protection;
  • capital;
  • liquidity;
  • financial projections; and
  • implementation milestones.

Consistency is critical

Every application document should tell the same story.

Common inconsistencies include:

  • the business plan says the applicant does not hold customer assets, but the technology diagram shows assets entering its wallets;
  • the financial model assumes brokerage spreads, but the legal description says the company only provides software;
  • the AML policy assumes direct customer transactions while the platform uses omnibus wallets;
  • the customer terms allocate custody to a third party, but the outsourcing agreement does not support that allocation;
  • the website advertises services not included in the licence application.

These contradictions may indicate that management does not fully understand the business model.

11. Fit-and-Proper Requirements

The regulator will assess the suitability of key persons connected to the applicant.

This may include:

  • directors;
  • the chief executive officer;
  • senior officers;
  • significant shareholders; and
  • beneficial owners.

The fit-and-proper assessment may examine:

  • honesty;
  • integrity;
  • qualifications;
  • experience;
  • competence;
  • financial soundness;
  • criminal history;
  • regulatory history;
  • insolvency;
  • conflicts of interest; and
  • capacity to perform the proposed role.

A nominee director who has little involvement in the business may create a regulatory problem.

The regulator may interview key officers and expect them to explain:

  • the company’s services;
  • customer asset arrangements;
  • compliance controls;
  • transaction monitoring;
  • capital management;
  • cyber-risk controls;
  • outsourcing;
  • complaints; and
  • incident response.

A licence application is not strengthened by giving impressive titles to individuals who cannot demonstrate actual responsibility.

12. AML, KYC and Travel Rule Compliance

Virtual asset businesses must implement robust AML/CFT/CPF controls.

This is not achieved by preparing a policy and leaving it in a folder.

The compliance framework should function across the full customer and transaction lifecycle.

It may include:

  • customer identification and verification;
  • beneficial ownership checks;
  • sanctions screening;
  • politically exposed person screening;
  • source-of-funds review;
  • source-of-wealth review;
  • wallet screening;
  • blockchain analytics;
  • transaction monitoring;
  • enhanced due diligence;
  • suspicious transaction reporting;
  • record keeping;
  • staff training; and
  • Travel Rule compliance.

Why crypto AML is different

Traditional financial compliance often focuses on bank accounts, cards and identifiable counterparties.

Crypto compliance must also address:

  • pseudonymous wallet addresses;
  • cross-chain transactions;
  • decentralised protocols;
  • mixers;
  • privacy-enhancing tools;
  • high-risk exchanges;
  • stolen assets;
  • sanctions exposure; and
  • rapid movement across jurisdictions.

Generic financial-services policies may therefore be inadequate.

The applicant must demonstrate how its systems will identify and manage crypto-specific risks.

13. Technology and Cybersecurity Requirements

Technology is not merely a commercial component of a Kenya crypto licence application.

It is a regulatory workstream.

The applicant must provide evidence of adequate technology resources and an independent information systems audit, including:

  • a vulnerability assessment; and
  • a penetration test.

The regulator may examine:

  • system architecture;
  • wallet infrastructure;
  • private-key management;
  • user authentication;
  • access controls;
  • transaction processing;
  • encryption;
  • data storage;
  • monitoring;
  • cyber-event detection;
  • third-party integrations;
  • backup systems;
  • disaster recovery; and
  • incident response.

Do not apply with a concept-only platform

A licence application should not be based only on mock-ups, slides and future development promises.

The system should be sufficiently developed to allow meaningful testing and assessment.

Critical or high-risk vulnerabilities should be remediated before filing, with evidence showing how the issues were resolved.

The 2026 Regulations contain dedicated obligations concerning cybersecurity strategy, systems and controls, cybersecurity audits and reporting of cybersecurity risks.

14. Consumer Protection and Safeguarding

A licensed VASP must protect customer funds and virtual assets.

Depending on the business model, the firm may need controls relating to:

  • segregation of customer assets;
  • reconciliation;
  • custody;
  • private-key protection;
  • customer agreements;
  • disclosures;
  • transaction confirmations;
  • complaint handling;
  • insolvency protection;
  • prevention of third-party claims;
  • operational transparency; and
  • record keeping.

The firm should clearly explain:

  • who holds customer assets;
  • whether assets are pooled;
  • which wallets are used;
  • whether assets may be transferred to third parties;
  • what happens if a custodian fails;
  • how withdrawals are authorised;
  • what fees apply;
  • what risks customers bear; and
  • how complaints escalate.

A customer agreement that uses vague language such as “assets may be held by trusted partners” will not adequately explain the legal and operational arrangement.

15. Advertising and Marketing Restrictions

Marketing should not begin before the regulatory perimeter has been resolved.

The Regulations contain a full regime governing advertisements and promotions of virtual assets and virtual asset products.

The rules address:

  • prohibitions on unauthorised advertising;
  • content requirements;
  • performance information;
  • fees and commissions;
  • risk warnings;
  • third-party marketers;
  • internet advertising;
  • prohibited digital-marketing practices; and
  • record keeping.

Promotional materials should be:

  • fair;
  • accurate;
  • identifiable;
  • transparent; and
  • not misleading.

A crypto company should therefore review:

  • its website;
  • social media;
  • influencer campaigns;
  • referral programmes;
  • affiliate marketing;
  • token promotions;
  • performance claims; and
  • customer-acquisition materials.

Language such as “guaranteed returns”, “risk-free”, “fully protected” or “the safest token” may create serious regulatory concerns unless objectively supportable and legally permissible.

The Regulations expressly govern advertisements and promotions as part of the licensed framework.

16. The Step-by-Step Kenya VASP Application Process

A practical licensing project may be divided into the following stages.

Step 1: Conduct a regulatory perimeter assessment

Map every product, customer flow, transaction and revenue stream.

Determine:

  • which activities are regulated;
  • whether more than one licence is required;
  • whether CBK, CMA or both are relevant;
  • whether any exclusion applies; and
  • whether the foreign business is targeting Kenya.

Step 2: Structure the applicant

Establish or register the appropriate company.

Finalise:

  • ownership;
  • beneficial ownership;
  • governance;
  • directors;
  • senior management;
  • principal business address; and
  • group relationships.

Step 3: Assess licensing readiness

Review:

  • capital;
  • staffing;
  • policies;
  • technology;
  • AML systems;
  • financial projections;
  • contracts;
  • outsourcing; and
  • operational readiness.

Prepare a gap analysis and remediation plan.

Step 4: Capitalise the company

Inject genuine paid-up capital and establish the required liquid-capital position.

Prepare:

  • bank evidence;
  • share records;
  • source-of-funds documentation; and
  • financial statements.

Step 5: Appoint key personnel

Identify suitable persons for roles such as:

  • chief executive officer;
  • compliance officer;
  • money laundering reporting officer;
  • finance officer;
  • risk officer;
  • technology lead; and
  • internal auditor.

Step 6: Prepare the application documents

Draft:

  • the business plan;
  • financial model;
  • policies;
  • fit-and-proper files;
  • governance documents;
  • customer terms;
  • outsourcing agreements;
  • business rules; and
  • technical documentation.

Step 7: Conduct systems testing

Complete:

  • information systems audit;
  • vulnerability assessment;
  • penetration testing;
  • remediation; and
  • final audit reporting.

Step 8: Submit the application

File the prescribed application with supporting documents and pay the application fee.

Step 9: Respond to regulatory enquiries

The regulator may request:

  • additional evidence;
  • clarifications;
  • interviews;
  • technology demonstrations;
  • source-of-funds documents;
  • policy revisions; or
  • additional financial analysis.

Step 10: Receive approval and pay the licence fee

Where approved, the applicant pays the relevant licence fee before the licence is issued.

The Regulations provide that the authority should determine the application within 30 days after receiving all required documents and information and completing due diligence. This does not mean every application will be concluded within 30 days of initial submission.

Step 11: Prepare for launch

The company must implement its approved framework and commence business within 12 months of the licence grant.

17. How Long Does It Take to Get a Crypto Licence in Kenya?

The practical timeline depends on:

  • the licence category;
  • the complexity of the business;
  • the applicant’s readiness;
  • the number of regulated activities;
  • the ownership structure;
  • availability of qualified personnel;
  • technology maturity;
  • capital;
  • quality of the documents; and
  • speed of responses to regulatory questions.

An indicative project timetable may be:

WorkstreamIndicative period
Regulatory mapping and structuring2–4 weeks
Readiness assessment3–6 weeks
Policy and application preparation8–16 weeks
Technology audit and testing4–10 weeks
Regulatory reviewDependent on completeness and due diligence
Licence-condition closure and launch4–12 weeks

Some workstreams can proceed simultaneously.

A simple investment-advisory application may be less demanding than a multi-activity exchange with custody, payments and several foreign affiliates.

18. Common Reasons Applications Are Delayed or Rejected

The Regulations allow the regulator to reject an application where, among other things:

  • the applicant fails to respond to requests for clarification;
  • the applicant refuses or fails to attend an interview;
  • directors, senior officers or beneficial owners fail fit-and-proper requirements;
  • the applicant has a record of regulatory or AML non-compliance; or
  • the application may pose a risk to financial stability.

Other common weaknesses include:

Applying for the wrong activity

The application says “broker”, but the platform operates as an exchange.

Incomplete ownership transparency

The regulator cannot clearly identify the ultimate beneficial owners.

Weak source-of-funds evidence

The applicant cannot trace the capital to a credible and lawful source.

Nominal management

Key officers are appointed only for licensing purposes and do not control the business.

Generic policies

The documents do not reflect the company’s actual technology or transaction flows.

Immature technology

The system is not ready for testing or contains unresolved vulnerabilities.

Unrealistic forecasts

The company predicts rapid growth but budgets inadequately for compliance, customer support and technology.

Insufficient working capital

The company meets the regulatory minimum but lacks enough funding to operate sustainably.

Inconsistent application documents

The business plan, website, policies, agreements and technology diagrams describe different models.

19. Ongoing Obligations After Licensing

A Kenya VASP licence is not a one-time registration.

The licensed company enters a continuing supervisory relationship.

Ongoing obligations may include:

  • annual renewal;
  • capital maintenance;
  • regulatory reporting;
  • audited financial statements;
  • cybersecurity audits;
  • AML monitoring;
  • customer due diligence;
  • record keeping;
  • complaints management;
  • consumer disclosures;
  • asset safeguarding;
  • market-abuse prevention;
  • incident reporting;
  • outsourcing oversight;
  • staff training; and
  • notification of material changes.

The licence must be renewed annually, and the renewal application must be submitted at least two months before expiry.

Changes requiring regulatory attention

The company may need to notify or obtain approval before changing:

  • ownership;
  • control;
  • directors;
  • senior officers;
  • business activities;
  • principal business address;
  • critical technology providers;
  • outsourcing arrangements;
  • custody structure;
  • trade names; or
  • financial position.

A licensed company should therefore maintain a formal regulatory-change procedure.

20. What Is the Real Cost of Starting a Crypto Business in Kenya?

The cost should be divided into four categories.

Regulatory fees

These include application, initial licence, renewal and any activity-specific approval fees.

Regulatory capital

This includes paid-up and liquid capital.

Capital is not paid away to the regulator, but it must be maintained by the business.

Pre-licensing implementation

This may include:

  • legal advisory;
  • compliance documentation;
  • corporate structuring;
  • executive recruitment;
  • technology development;
  • KYC systems;
  • blockchain analytics;
  • cybersecurity testing;
  • audit;
  • offices; and
  • insurance.

Ongoing operations

Recurring costs may include:

  • salaries;
  • licences for compliance technology;
  • external audit;
  • penetration testing;
  • regulatory reporting;
  • premises;
  • insurance;
  • training;
  • renewal fees; and
  • legal and compliance support.

A serious applicant should prepare:

  • a licensing budget;
  • a 12-month operating budget;
  • a three-year financial forecast;
  • a capital-maintenance plan; and
  • a contingency reserve.

21. Can a Crypto Startup Obtain a Kenya VASP Licence?

Yes, but being a startup does not reduce the regulatory standard.

A startup may be smaller than an established international exchange, but it must still demonstrate:

  • transparent ownership;
  • credible funding;
  • competent management;
  • adequate technology;
  • suitable AML controls;
  • consumer protection;
  • sufficient capital; and
  • financial sustainability.

The applicant should scale its model realistically.

A founder with limited capital may consider whether the initial business should focus on a narrower regulated activity rather than launching an exchange, wallet, payment gateway and token platform simultaneously.

The legal structure should follow the genuine business strategy—not an attempt to avoid requirements artificially.

22. How CRYPTOVERSE Can Help

Starting a crypto business in Kenya requires coordination across law, regulation, finance, governance, technology and operations.

CRYPTOVERSE Legal Consultancy can assist with:

  • Kenya crypto regulatory perimeter assessments;
  • CBK and CMA licence mapping;
  • entity and ownership structuring;
  • capital and liquidity planning;
  • licensing-readiness reviews;
  • regulatory business plans;
  • financial projections;
  • fit-and-proper applications;
  • AML/CFT/CPF frameworks;
  • governance and operational policies;
  • customer agreements;
  • outsourcing arrangements;
  • coordination of cybersecurity and systems-audit workstreams;
  • licence application preparation;
  • regulatory information requests;
  • interview preparation;
  • post-approval implementation; and
  • ongoing compliance.

The objective is not merely to assemble documents.

It is to structure a credible and sustainable virtual asset business capable of obtaining and maintaining the relevant licence.

Conclusion: Build the Licence Into the Business Model

The founder introduced at the beginning of this guide could have launched first and asked legal questions later.

Many businesses take that approach.

They build the application, advertise to customers, connect payment channels and begin earning revenue. Only when a bank, investor or regulator asks for a licence do they confront the true complexity of their model.

By then, correcting the structure may involve:

  • changing the applicant entity;
  • replacing shareholders;
  • appointing new management;
  • redesigning transaction flows;
  • rebuilding custody arrangements;
  • rewriting customer agreements;
  • changing marketing materials;
  • raising additional capital; and
  • suspending customer onboarding.

The better approach is to treat regulation as a core part of product design.

Before launching a crypto business in Kenya, founders should determine:

  1. what the company will actually do;
  2. which activities are regulated;
  3. whether CBK, CMA or both are relevant;
  4. what capital must be maintained;
  5. which personnel must be appointed;
  6. what technology and cybersecurity controls are required;
  7. how customer assets will be protected;
  8. what documents must be prepared;
  9. how much the complete project will cost; and
  10. how ongoing compliance will be managed.

Kenya has created a clear opportunity for responsible virtual asset businesses.

But it is not an invitation to launch first and regularise later.

It is an invitation to build properly.

For founders prepared to meet the requirements, a Kenya crypto licence can provide a regulated pathway into one of Africa’s most important digital-finance markets.

The real question is therefore not simply:

“How do I start a crypto business in Kenya?”

It is:

“How do I create a crypto business that customers, banks, investors and Kenyan regulators can trust?”

FAQs

1. What licence do I need to start a crypto business in Kenya?

The licence depends on the activity. CBK regulates wallet providers, virtual asset payment processors and stablecoin issuers. CMA regulates exchanges, brokers, investment advisers, virtual asset managers, ICO providers, tokenisation providers and token issuance platforms.

2. Can a foreign company apply for a Kenya VASP licence?

Yes. A foreign company limited by shares may apply if it is registered under Kenya’s Companies Act and satisfies the applicable ownership, governance, capital, operational and licensing requirements.

3. How much capital is required for a Kenya crypto licence?

The minimum ranges from no fixed capital for an investment adviser to KSh 300 million for a stablecoin issuer. The precise amount depends on the licence category, and separate liquid-capital requirements may also apply.

4. How long does a Kenya crypto licence application take?

The practical timeline depends on the applicant’s readiness, business complexity and regulatory due diligence. The 30-day determination period applies only after all required documents and information have been received and due diligence has been completed.

5. Does an offshore crypto exchange need a licence in Kenya?

Potentially, yes. A foreign provider may fall within the regime where it actively targets Kenyan consumers or derives income or economic benefit from Kenya, even without a physical presence.