A Practical Guide to Kenya VASP Licensing, CBK and CMA Applications, Capital, Compliance and Launch Readiness
A founder may believe the difficult part of launching a crypto business is building the technology.
The exchange engine must execute trades quickly. The wallet must protect private keys. The mobile application must be simple enough for new users. Banking, payment, custody and liquidity partners must all connect to the platform.
Yet in Kenya, building the product is only one part of the journey.
Before launching a regulated virtual asset service, the founder must also answer a more fundamental question:
Can this business satisfy the licensing standards imposed by the Central Bank of Kenya or the Capital Markets Authority?
Kenya now regulates virtual asset businesses under the Virtual Asset Service Providers Act, 2025, together with the Virtual Asset Service Providers Regulations, 2026. The Act establishes the licensing framework, while the Regulations set out detailed application, capital, governance, cybersecurity, safeguarding, consumer-protection and market-conduct requirements.
A company may require a crypto licence in Kenya where it plans to operate:
- a cryptocurrency exchange;
- an OTC crypto brokerage;
- a custodial wallet;
- a crypto payment gateway;
- a fiat-to-crypto or crypto-to-fiat service;
- a virtual asset investment business;
- a tokenisation platform;
- a token launchpad;
- an initial coin offering; or
- a stablecoin.
The application process is not simply a matter of submitting a company certificate and paying a government fee. The regulator will assess whether the applicant has the ownership, funding, management, systems and controls necessary to operate a credible financial-services business.
This guide explains how to get a crypto licence in Kenya, step by step, with particular focus on exchanges, wallet providers and crypto startups.
1. Understand What a Kenya Crypto Licence Actually Authorises
A Kenya crypto licence is formally a Virtual Asset Service Provider licence, commonly called a VASP licence.
It permits an eligible company to conduct one or more regulated virtual asset services in or from Kenya.
The licence is separate from:
- company incorporation;
- tax registration;
- a county business permit;
- registration of a trade name;
- opening a corporate bank account;
- signing an agreement with a payment provider; or
- holding a crypto licence in another country.
A company may be validly incorporated in Kenya but still lack authority to offer regulated virtual asset services.
For example, incorporating a company with business objects covering “blockchain technology”, “financial technology” or “digital assets” does not permit that company to:
- receive customer funds for crypto purchases;
- operate a crypto exchange;
- safeguard private keys;
- facilitate OTC transactions;
- issue a stablecoin; or
- manage virtual asset portfolios.
The licence follows the substance of the activity, not the wording used in the company’s registration documents or marketing materials.
2. Determine Whether the Business Falls Within Kenya’s Regulatory Perimeter
The first formal step should be a regulatory perimeter assessment.
This is a legal and operational review of the entire business model to determine:
- whether the company provides a regulated virtual asset service;
- which licence category applies;
- whether CBK, CMA or both will supervise the business;
- whether more than one regulated activity is involved; and
- whether any statutory exclusion genuinely applies.
The assessment should follow the complete transaction lifecycle.
For each product, the founder should identify:
- who contracts with the customer;
- who receives fiat currency;
- who receives virtual assets;
- who controls the private keys;
- who quotes the transaction price;
- who matches or executes the order;
- who provides liquidity;
- who completes settlement;
- who handles refunds or failed transactions; and
- which company earns the fee, commission or spread.
Example: A “simple” crypto application
Suppose a startup develops an application through which Kenyan customers can:
- deposit Kenyan shillings;
- purchase USDT;
- store USDT in an in-app wallet;
- exchange USDT for Bitcoin; and
- use crypto to pay participating merchants.
Although the founder may view this as one product, it could involve:
- virtual asset payment processing;
- custodial wallet services;
- virtual asset exchange; and
- potentially brokerage.
The applicant must identify these functions before selecting a licence.
3. Confirm Whether the Company Is Targeting Kenya
The final Regulations apply to persons offering virtual asset services in or from Kenya.
A business is considered to operate in or from Kenya where it actively solicits or targets Kenyan consumers or derives economic benefit or income from Kenya, whether or not it has a physical presence in the country.
An offshore exchange may therefore require a Kenya VASP licence even if:
- it is incorporated abroad;
- its management is outside Kenya;
- its servers are located overseas;
- it uses a foreign custodian;
- its customer agreement is governed by foreign law; or
- It has no Kenyan office.
Indicators that an overseas platform is targeting Kenya may include:
- accepting Kenyan residents as customers;
- supporting Kenyan shilling deposits or withdrawals;
- offering local mobile-money or bank-payment options;
- using Kenyan influencers;
- conducting Kenya-specific advertising;
- operating a Kenyan social-media page;
- providing Kenyan customer support;
- partnering with Kenyan merchants; or
- generating transaction income from Kenyan users.
A foreign licence may demonstrate regulatory experience, but it does not automatically authorise Kenyan market access.
4. Identify the Correct Regulator
Kenya uses a dual-regulator model.
The relevant authorities are:
- the Central Bank of Kenya; and
- the Capital Markets Authority.
The correct authority depends on the proposed service.
Central Bank of Kenya
CBK regulates:
| Activity | Typical business model |
| Virtual asset wallet provider | Hosted wallets, institutional custody, private-key control and safekeeping |
| Virtual asset payment processor | Merchant payments, on-ramps, off-ramps, remittances and settlement |
| Stablecoin issuer | Issuing and redeeming reserve-backed virtual assets |
Capital Markets Authority
CMA regulates:
| Activity | Typical business model |
| Virtual asset exchange | Crypto trading platforms and marketplaces |
| Virtual asset broker | OTC dealing, arranging and executing customer trades |
| Virtual asset investment adviser | Personalised crypto investment advice |
| Virtual asset manager | Discretionary management of crypto portfolios |
| Initial coin offering provider | Fundraising through token issuance |
| Tokenisation provider | Tokenising real-world assets |
| Token issuance platform | Launchpads and primary token-distribution infrastructure |
The Act designates CBK and CMA as relevant regulatory authorities and assigns them licensing and supervisory functions over the activities listed in the statutory framework.
Could both regulators be involved?
Yes.
A crypto exchange that also holds customer private keys may involve both:
- CMA-regulated exchange activity; and
- CBK-regulated wallet activity.
Similarly, a payment application may facilitate conversions executed through an exchange while also maintaining custodial wallets.
The licence architecture should be settled before incorporation, capitalisation and policy drafting.
5. Select the Correct Licence Category
Crypto exchange
A business is likely to require a crypto exchange licence in Kenya where it operates a digital platform facilitating the exchange or trading of virtual assets for fiat currency or other virtual assets.
An exchange may:
- operate an order book;
- match buyers and sellers;
- provide peer-to-peer trading;
- offer instant conversion;
- purchase assets from matched sellers for resale;
- set or display market prices; or
- facilitate trades for a commission or spread.
The Act defines a virtual asset trading platform by reference to a platform facilitating trading for a fee or other benefit and either controlling customer assets or purchasing assets following the matching of transactions.
Custodial wallet provider
A wallet provider will generally require CBK authorisation where it holds or manages customer private keys.
The analysis should consider whether the provider can:
- access the customer’s assets;
- authorise transfers;
- block withdrawals;
- recover the account;
- reconstruct keys;
- change administrative permissions; or
- move assets during an emergency.
A product labelled “non-custodial” may still raise licensing issues if the provider retains meaningful control.
Virtual asset broker
An OTC desk may require a broker licence where it:
- receives customer instructions;
- sources crypto from liquidity providers;
- negotiates prices;
- arranges transactions;
- executes trades for customers; or
- earns a commission or spread.
Operating without a public order book does not make the service unregulated.
Crypto payment processor
A payment processor may facilitate:
- merchant crypto payments;
- stablecoin settlement;
- fiat-to-crypto purchases;
- crypto-to-fiat conversions;
- crypto remittances; or
- payment collection and routing.
Outsourcing conversion or custody does not automatically remove the customer-facing company from the regulatory perimeter.
6. Check Whether an Exclusion Applies
Some activities and digital assets fall outside the VASP framework.
The Act excludes specified categories, including:
- certain closed-ecosystem assets;
- central bank-issued digital representations of fiat currency;
- qualifying non-financial NFTs;
- virtual service tokens that are non-transferable and non-exchangeable with third parties; and
- other categories expressly excluded by the regulator.
A business should not rely on an exclusion merely because it calls its asset:
- a utility token;
- a loyalty point;
- an NFT;
- a gaming token; or
- an access token.
The regulator will examine what the asset actually does.
A token may fall within regulation where it can be:
- traded;
- transferred outside its original platform;
- redeemed for fiat or crypto;
- used for investment;
- linked to financial rights;
- used to raise capital; or
- marketed with an expectation of returns.
A written regulatory opinion is advisable where the business intends to rely on an exclusion.
7. Establish an Eligible Applicant Company
An applicant must generally be:
- a company limited by shares incorporated in Kenya; or
- a foreign company limited by shares and registered under Kenyan company law.
The licensing entity should be the company that genuinely controls and conducts the regulated activity.
It should ordinarily:
- contract with customers;
- receive the regulated revenue;
- employ or engage key personnel;
- maintain the regulatory capital;
- control or lawfully use the technology;
- enter into custody, banking and outsourcing agreements;
- implement compliance controls; and
- bear responsibility to the regulator.
Avoid the “empty licence company”
A weak structure may place the licence in a Kenyan entity while:
- technology is entirely controlled offshore;
- another company earns the transaction fees;
- customer assets are held by an undisclosed affiliate;
- decisions are made outside the applicant;
- the local board lacks authority; and
- The applicant has few resources of its own.
The regulator may question whether such an applicant has genuine operational substance.
8. Finalise Ownership and Beneficial Ownership
The applicant must disclose:
- shareholders;
- significant shareholders;
- directors;
- senior officers;
- beneficial owners;
- group companies;
- parent entities;
- affiliates; and
- controlling persons.
Under the Regulations, a significant shareholder includes a person holding, directly or indirectly, more than 10% of the company’s share capital.
The ownership chart should trace each corporate shareholder to the ultimate natural-person owners.
Supporting records may include:
- incorporation certificates;
- shareholder registers;
- beneficial ownership registers;
- constitutional documents;
- shareholder agreements;
- trust records;
- nominee declarations;
- organisational charts;
- passports;
- address evidence; and
- corporate registry extracts.
Complex international ownership is not automatically prohibited. However, the structure must be transparent and commercially explainable.
9. Appoint Fit-and-Proper Management
The regulator will assess whether directors, senior officers, significant shareholders and beneficial owners are fit and proper.
The review may examine:
- honesty;
- integrity;
- competence;
- relevant qualifications;
- professional experience;
- financial soundness;
- criminal history;
- regulatory history;
- insolvency;
- civil proceedings;
- disciplinary matters;
- conflicts of interest; and
- previous involvement in failed or sanctioned businesses.
The application must include completed fit-and-proper forms, together with the personal, professional and business details of relevant individuals. The regulator may also require applicants and their officers to attend interviews.
Key roles
Depending on the activity, the company may require:
- a board of directors;
- chief executive officer;
- compliance officer;
- money laundering reporting officer;
- finance officer;
- risk officer;
- technology lead;
- cybersecurity officer;
- operations manager; and
- internal audit support.
The proposed officers must understand the business. A nominal director who cannot explain the custody model, transaction monitoring or financial forecasts can weaken the application.
10. Calculate the Required Regulatory Capital
Capital requirements vary by licence category.
| Licence category | Minimum paid-up capital |
| Virtual Asset Investment Adviser | No prescribed fixed minimum |
| Virtual Asset Broker | KSh 10 million |
| Virtual Asset Payment Processor | KSh 10 million |
| Virtual Asset Tokenisation Provider | KSh 10 million |
| Virtual Asset Manager | KSh 20 million |
| Initial Coin Offering Provider | KSh 20 million |
| Token Issuance Platform | KSh 20 million |
| Virtual Asset Exchange | KSh 100 million |
| Virtual Asset Wallet Provider | KSh 150 million |
| Stablecoin Issuer | KSh 300 million |
The Regulations define paid-up capital as issued and fully paid ordinary shares paid for by the company’s shareholders.
Capital is not the application fee
Regulatory capital remains within the applicant company. It is intended to support financial resilience.
However, the applicant must generally maintain the required capital after paying for:
- salaries;
- rent;
- systems;
- compliance vendors;
- legal support;
- audits;
- insurance;
- cybersecurity; and
- other operating expenses.
The company should therefore raise more than the statutory minimum.
A practical funding plan should cover:
minimum regulatory capital + applicable liquidity requirement + licensing expenditure + platform completion + at least 12 months of operating expenses + contingency funding.
The application must include evidence of paid-up capital and liquid capital at the levels specified in the Regulations.
11. Prove the Source of Funds
The regulator will not be satisfied merely because the required amount appears in the applicant’s bank account.
The applicant must explain:
- who supplied the money;
- how that person acquired it;
- how it moved to the applicant;
- whether it is equity or debt; and
- whether the funding is lawful and commercially genuine.
Evidence may include:
- bank statements;
- salary records;
- audited financial statements;
- dividend records;
- investment statements;
- asset-sale agreements;
- loan documentation;
- tax records;
- business-income evidence; and
- inheritance documents.
Where the investment originated in virtual assets, the regulator may expect:
- wallet addresses;
- transaction hashes;
- exchange statements;
- blockchain-analytics reports;
- evidence of wallet ownership; and
- records linking the crypto disposal to the fiat funds invested.
Temporary capital transfers or unexplained third-party funding may materially delay the application.
12. Prepare the Regulatory Business Plan
A regulatory business plan is more detailed than an investor pitch deck.
The Regulations require a business plan prepared in accordance with the prescribed schedule.
It should explain:
- ownership and group structure;
- proposed licensed activities;
- products and services;
- target customers;
- customer onboarding;
- transaction flows;
- custody and settlement;
- technology;
- outsourcing;
- governance;
- AML controls;
- risk management;
- cybersecurity;
- consumer protection;
- fees and revenue;
- capital and liquidity;
- financial forecasts;
- implementation milestones; and
- business continuity.
Exchange business plan
An exchange applicant should clearly address:
- trading model;
- order types;
- matching engine;
- liquidity providers;
- settlement;
- supported assets;
- listing and delisting;
- custody;
- market surveillance;
- conflicts of interest;
- proprietary trading; and
- market-abuse controls.
Wallet business plan
A wallet provider should address:
- wallet architecture;
- private-key generation;
- hot and cold storage;
- multi-signature controls;
- withdrawal approvals;
- wallet recovery;
- reconciliation;
- safeguarding;
- cyber incident response; and
- third-party custody.
Startup financial forecasts
Forecasts should be realistic and internally consistent.
The regulator may question a model that predicts:
- rapid customer growth;
- large transaction volumes;
- minimal staffing;
- unusually low compliance costs; or
- profitability immediately after launch.
The financial model should show that the company can remain solvent and adequately capitalised under both expected and stressed scenarios.
13. Build the AML and Compliance Framework
A Kenya crypto licence applicant must establish controls for:
- customer identification;
- identity verification;
- beneficial ownership;
- customer-risk classification;
- sanctions screening;
- politically exposed persons;
- source of funds;
- source of wealth;
- enhanced due diligence;
- transaction monitoring;
- suspicious transaction reporting;
- record keeping;
- blockchain analytics; and
- Travel Rule compliance.
The application package must include the applicant’s AML/CFT/CPF policies and relevant systems and controls.
Crypto-specific risk indicators may include:
- sanctioned wallet exposure;
- mixers and tumblers;
- stolen assets;
- darknet markets;
- rapid movement across chains;
- structuring of transactions;
- use of multiple linked accounts;
- high-risk peer-to-peer activity;
- unregulated counterparties; and
- transactions inconsistent with the customer’s profile.
A generic AML manual designed for an ordinary trading company will not be adequate.
14. Complete the Technology and Cybersecurity Workstream
The applicant must provide an independent information systems audit report that includes:
- a vulnerability assessment; and
- a penetration test.
The report must be prepared by a suitably qualified and competent person.
The review may address:
- platform architecture;
- cloud infrastructure;
- encryption;
- user authentication;
- privileged access;
- secure coding;
- transaction approval;
- key management;
- wallet security;
- monitoring and logging;
- data protection;
- backups;
- incident response;
- disaster recovery; and
- third-party integrations.
Do not file with unresolved critical vulnerabilities
A serious cybersecurity weakness may indicate that the applicant is not ready to hold customer assets or operate a public trading platform.
The applicant should:
- complete testing;
- classify findings;
- remedy critical and high-risk issues;
- conduct retesting;
- document closure; and
- formally accept any remaining low-level risks.
The platform should also be sufficiently developed for demonstrations and meaningful technical review.
15. Prepare the Required Policies and Contracts
The Regulations require operational policies covering areas including:
- risk management;
- AML/CFT/CPF;
- data protection and privacy;
- cybersecurity and information technology;
- complaints management;
- market conduct;
- consumer protection;
- conflicts of interest; and
- business continuity and disaster recovery.
Depending on the licence, the applicant may also require:
- custody policy;
- wallet-management policy;
- token listing and delisting rules;
- order-execution policy;
- market-surveillance policy;
- outsourcing policy;
- personal-account dealing policy;
- incident-response procedure;
- stablecoin reserve policy;
- redemption policy;
- token-admission standards; and
- orderly wind-down plan.
Material contracts may include:
- banking agreements;
- custody agreements;
- liquidity arrangements;
- cloud-service contracts;
- KYC and sanctions-screening contracts;
- blockchain-analytics agreements;
- Travel Rule arrangements;
- software licences;
- intra-group service agreements;
- outsourced support agreements; and
- customer terms.
Outsourcing a function does not outsource regulatory responsibility.
16. Ensure Customer Assets Are Properly Protected
Applicants that hold customer fiat or crypto must establish safeguarding arrangements.
The framework should cover:
- segregation of customer assets;
- reconciliation;
- custody records;
- wallet controls;
- bank-account arrangements;
- protection against third-party claims;
- insolvency treatment;
- withdrawal authorisation;
- shortage escalation; and
- incident handling.
The final Regulations contain dedicated requirements on safeguarding strategies, consumer agreements, management and safekeeping of customer funds and assets, systems and controls, protection from third-party claims, and records and accounts.
The applicant should be able to demonstrate at any time:
- which assets belong to each customer;
- where those assets are held;
- who controls them;
- whether they are pooled;
- how balances are reconciled; and
- what happens if the company or custodian becomes insolvent.
17. Submit the Application to CBK or CMA
An application for one or more permissible activities must be submitted in the prescribed form.
The filing must include, among other matters:
- details of directors, officers, significant shareholders and beneficial owners;
- regulatory business plan;
- fit-and-proper forms;
- source-of-funds evidence;
- systems and controls;
- operational policies;
- material contracts;
- capital evidence;
- audited or opening financial statements;
- human and technological resource evidence;
- systems-audit and penetration-test reports;
- cross-border disclosures;
- activity-specific business rules;
- market-integrity controls;
- details of supported virtual assets;
- corporate documents;
- beneficial ownership records; and
- proof of payment of the application fee.
The application should be checked for consistency before filing.
The following must describe the same business:
- application form;
- business plan;
- financial model;
- organisation chart;
- policies;
- customer terms;
- technical diagrams;
- service-provider contracts;
- website; and
- management interview responses.
Contradictions can create doubts about whether the applicant understands its own model.
18. Respond to Regulatory Enquiries and Interviews
After filing, the regulator may request:
- additional ownership information;
- source-of-funds clarification;
- revised financial projections;
- policy amendments;
- platform demonstrations;
- cybersecurity evidence;
- service-provider contracts;
- explanations of customer-asset flows; or
- interviews with directors and senior officers.
The applicant should respond:
- completely;
- accurately;
- within the required period;
- through an organised response matrix; and
- with documents approved by the appropriate officers.
The Regulations permit rejection where the applicant fails to respond to requests for clarification or fails to attend a requested interview. They also permit rejection where key persons are not fit and proper, the applicant has an adverse regulatory record, or approval would pose a financial-stability risk.
19. Understand the Regulatory Timeline
The regulator must determine the application within 30 days after:
- receiving all required documents and information; and
- completing due diligence on the applicant.
This is not necessarily 30 days from the first filing.
The statutory period may not begin while:
- required documents remain missing;
- due diligence is incomplete;
- interviews are outstanding;
- cyber findings remain unresolved;
- financial information requires revision; or
- regulatory questions have not been answered.
A practical end-to-end project may take several months.
| Workstream | Indicative period |
| Regulatory perimeter assessment | 2–4 weeks |
| Structuring and ownership finalisation | 3–8 weeks |
| Capitalisation and recruitment | 4–12 weeks |
| Business plan and policy preparation | 8–16 weeks |
| Systems testing and remediation | 4–10 weeks |
| Regulatory review | Depends on completeness and due diligence |
| Approval-condition closure | 4–12 weeks |
Several workstreams can proceed simultaneously, but premature filing may lengthen rather than shorten the process.
20. Pay the Licence Fee and Satisfy Approval Conditions
Where the applicant satisfies the statutory requirements, the regulator may issue the VASP licence after payment of the applicable licence fee.
Typical initial licence fees include:
| Licence category | Initial licence fee |
| Virtual Asset Investment Adviser | KSh 50,000 |
| Virtual Asset Broker | KSh 100,000 |
| Virtual Asset Manager | KSh 200,000 |
| Virtual Asset Payment Processor | KSh 200,000 |
| Virtual Asset Wallet Provider | KSh 500,000 |
| Initial Coin Offering Provider | KSh 500,000 |
| Tokenisation Provider | KSh 500,000 |
| Token Issuance Platform | KSh 500,000 |
| Virtual Asset Exchange | KSh 1 million |
| Stablecoin Issuer | KSh 2 million |
Government fees are only a small part of the total Kenya crypto licence cost. The applicant must also budget for capital, staffing, systems, audits, compliance vendors, premises, insurance and ongoing professional support.
21. Launch Only the Approved Activities
A licensed company must commence its virtual asset business within 12 months of receiving the licence.
The business should launch only:
- the authorised services;
- the approved customer types;
- the approved virtual assets;
- the approved transaction model; and
- the systems and arrangements presented to the regulator.
It should not quietly introduce additional services after licensing.
For example, an authorised broker should not automatically add:
- custody;
- merchant payments;
- discretionary portfolio management;
- token issuance; or
- an exchange order book.
A new or materially altered service may require prior approval or a variation of the licence.
22. Maintain Ongoing Compliance
Obtaining a Kenya VASP licence is the beginning of regulatory supervision.
The licensed company must maintain compliance with requirements concerning:
- capital and liquidity;
- governance;
- fit-and-proper status;
- AML/CFT/CPF;
- sanctions;
- cybersecurity;
- consumer protection;
- safeguarding;
- complaints;
- market conduct;
- record keeping;
- audit;
- outsourcing;
- reporting; and
- business continuity.
Licences are renewed annually, and a renewal application must be filed at least two months before expiry.
Material developments should also be escalated promptly. During the application stage, changes such as ownership alterations, liquidity problems, enforcement action, cyber incidents and changes to the business model must be notified to the regulator within the prescribed period.
Common Mistakes to Avoid
Applying for the wrong activity
A company applies as a broker while its system actually matches orders and operates as an exchange.
Treating incorporation as licensing
A certificate of incorporation does not authorise regulated crypto services.
Using nominal directors
Key officers cannot explain the business or exercise genuine control.
Filing before the platform is ready
The applicant cannot complete meaningful penetration testing or demonstrate its transaction flows.
Underestimating capital
The company raises only the minimum statutory amount and has no separate operating runway.
Using generic policies
Policies do not reflect the platform’s customers, assets, wallets, risks or systems.
Failing to trace source of funds
Shareholder capital arrives without a credible documentary trail.
Ignoring outsourced functions
The applicant assumes that using a foreign custodian or exchange removes its licensing responsibilities.
Inconsistent application documents
The business plan, financial model, website and customer agreement describe different services.
Marketing before approval
The company represents itself as licensed or invites Kenyan customers before receiving authorisation.
How CRYPTOVERSE Can Help
CRYPTOVERSE Legal Consultancy can support founders, exchanges, wallet businesses and international VASPs through the complete Kenya licensing process, including:
- regulatory perimeter assessments;
- CBK and CMA licence mapping;
- market-entry and applicant structuring;
- beneficial ownership review;
- capital and liquidity planning;
- source-of-funds preparation;
- licensing-readiness assessments;
- regulatory business plans;
- financial projections;
- fit-and-proper applications;
- governance frameworks;
- AML/CFT/CPF policies;
- sanctions and Travel Rule procedures;
- consumer-protection frameworks;
- customer agreements;
- custody and safeguarding documentation;
- outsourcing agreements;
- exchange and wallet business rules;
- coordination of systems audits and penetration testing;
- application preparation and submission;
- responses to regulatory enquiries;
- management interview preparation;
- approval-condition closure; and
- ongoing regulatory compliance support.
The objective should not be to submit the application as quickly as possible.
It should be to build and present a coherent, properly capitalised and operationally credible crypto business that can withstand regulatory scrutiny.
Conclusion: The Licence Must Be Built Into the Business
The founders most likely to struggle with the Kenya crypto licensing process are those who treat regulation as the final paperwork stage.
They build the product first.
They select service providers second.
They begin marketing third.
Only afterwards do they ask whether the transaction model is licensable.
By that stage, a legal review may require them to:
- change the applicant entity;
- restructure ownership;
- raise additional capital;
- replace nominal officers;
- redesign custody;
- alter customer-asset flows;
- amend outsourcing arrangements;
- rebuild compliance controls;
- remediate technology weaknesses; or
- suspend launch plans.
A stronger approach begins with regulatory design.
Before developing the complete platform, establish:
- which regulated activities the business performs;
- whether CBK, CMA or both will supervise it;
- which company will hold the licence;
- who will own and control the applicant;
- how customer assets will move;
- how much capital and operating funding are required;
- which officers must be appointed;
- how AML and blockchain monitoring will operate;
- how the platform will protect customer assets; and
- how ongoing compliance will be maintained.
Getting a crypto licence in Kenya is not simply about completing the prescribed form.
It is about demonstrating that the applicant has become the kind of institution that can safely serve customers, safeguard assets and operate within Kenya’s regulated virtual asset market.
FAQs
1. Which regulator issues a crypto licence in Kenya?
CBK regulates custodial wallet providers, virtual asset payment processors and stablecoin issuers. CMA regulates exchanges, brokers, investment advisers, virtual asset managers, ICO providers, tokenisation providers and token issuance platforms.
2. How much capital is required for a Kenya crypto licence?
The requirement depends on the activity. It ranges from no prescribed fixed minimum for an investment adviser to KSh 300 million for a stablecoin issuer. Exchanges require KSh 100 million, while custodial wallet providers require KSh 150 million.
3. Can a foreign crypto company apply?
Yes. A foreign company limited by shares may apply after being properly registered in Kenya and satisfying the relevant ownership, capital, governance, technology and compliance requirements.
4. How long does the licence application take?
The regulator’s 30-day determination period begins only after all required information has been received and due diligence has been completed. The full preparation and review process may take several months.
5. Can a startup apply before its platform is complete?
The platform does not necessarily have to be commercially launched. However, it must generally be sufficiently developed for independent systems auditing, penetration testing, transaction-flow review and regulatory demonstration.