What Exchanges, Wallet Providers, Brokers, Payment Platforms, Tokenisation Businesses and Stablecoin Issuers Need to Know

For years, a crypto business could look at Kenya and see opportunity everywhere.

A young, digitally active population. Strong mobile-money adoption. Growing demand for cross-border payments. Increasing interest in Bitcoin, stablecoins, tokenisation and blockchain-based financial products.

But one question remained difficult to answer:

What does a crypto company need to do to operate legally in Kenya?

That question now has a clearer answer.

Kenya has established a comprehensive virtual asset regulatory framework through:

The Act creates the legal foundation. It defines the regulatory perimeter, prohibits unlicensed virtual asset services, designates the responsible regulators and establishes the principal obligations and enforcement powers.

The Regulations provide the operating rulebook. They address licence applications, capital, governance, cybersecurity, customer protection, virtual asset offerings, stablecoins, tokenisation, financial reporting and continuing compliance.

Together, these instruments move Kenya from a period of regulatory uncertainty into a formal licensing regime for virtual asset service providers.

The framework applies to VASPs offering virtual asset services in Kenya and establishes exclusions for specified closed-ecosystem instruments, certain non-financial NFTs, central-bank-issued digital representations of fiat currency and qualifying virtual service tokens.

This guide explains what the Kenya crypto regulations 2026 mean in practice and what founders should do before launching or continuing a virtual asset business in the country.

1. The Structure of Kenya’s Crypto Regulatory Framework

Kenya’s framework is built around two complementary legal instruments.

The Virtual Asset Service Providers Act, 2025

The Act is the primary legislation.

It establishes:

  • the legal meaning of virtual assets and virtual asset services;
  • the persons and activities falling within the regime;
  • the licensing prohibition;
  • the functions of the regulators;
  • the broad licensing criteria;
  • AML/CFT/CPF supervision;
  • virtual asset offering requirements;
  • regulatory inspection and enforcement powers; and
  • the legal basis for detailed Regulations.

The Act also amended related financial-sector legislation so that CBK and CMA can regulate VASPs within their respective mandates.

The Virtual Asset Service Providers Regulations, 2026

The Regulations operationalise the Act.

They provide the detailed requirements for:

  • licence applications;
  • regulatory fees;
  • approval and rejection;
  • commencement of business;
  • licence transfers and changes;
  • continuing obligations;
  • governance;
  • consumer protection;
  • asset safeguarding;
  • market conduct;
  • virtual asset offerings;
  • tokenisation;
  • stablecoin issuance;
  • capital and liquidity;
  • insurance;
  • audit;
  • financial records;
  • cybersecurity;
  • outsourcing;
  • regulatory reporting; and
  • enforcement.

The Regulations therefore convert the Act’s legal principles into requirements that an applicant can be assessed against. Kenya Law records the final Regulations as Legal Notice 134 of 2026.

2. Who Is Covered by the VASP Act?

The Act applies to persons offering virtual asset services in Kenya.

A company does not escape the law merely because:

  • it is incorporated abroad;
  • its platform is hosted outside Kenya;
  • it has no physical shop in the country;
  • it calls itself a technology company;
  • customers access the service through an app;
  • crypto is only one part of its business; or
  • regulated functions are outsourced.

The relevant question is whether the company is providing virtual asset services within the scope of the Act.

The Act prohibits a person from carrying on, purporting to carry on or holding itself out as carrying on virtual asset services without the required licence. 

The regulator looks at substance, not labels

A business may describe itself as:

  • a blockchain platform;
  • a digital marketplace;
  • a Web3 company;
  • a settlement solution;
  • a liquidity platform;
  • a fintech application; or
  • a software provider.

None of those labels determines the regulatory outcome.

The authorities will examine:

  • what customers can do;
  • who contracts with them;
  • who receives money or virtual assets;
  • who controls private keys;
  • who determines prices;
  • who matches orders;
  • who executes transactions;
  • how assets are settled;
  • how the company earns revenue; and
  • which entity performs each regulated function.

A genuine software provider that merely licenses technology may fall outside the VASP perimeter. But a company that operates the platform, controls transactions or contracts with customers may require a licence even where third-party technology is used.

3. What Is a Virtual Asset?

Broadly, a virtual asset is a digital representation of value that can be transferred, stored or traded electronically and used for payment, investment or another regulated financial purpose.

The concept may include:

  • cryptocurrencies;
  • exchange tokens;
  • payment tokens;
  • investment tokens;
  • asset-backed tokens;
  • tokenised financial or real-world assets; and
  • stablecoins.

The definition is functional.

Calling a token a “utility token”, “membership token” or “digital point” does not automatically remove it from regulation.

Its actual characteristics matter.

Relevant questions include:

  • Can it be transferred to another person?
  • Can it be traded?
  • Can it be exchanged for fiat or another virtual asset?
  • Can it be used as payment?
  • Does the purchaser expect financial returns?
  • Does it represent an underlying asset or right?
  • Is there a secondary market?
  • Can the issuer redeem it for money or value?

4. What Is Excluded?

The Act contains important exclusions.

Closed-ecosystem instruments

A digital representation may fall outside the Act where it operates solely within the issuer’s closed ecosystem and satisfies the prescribed conditions.

Those conditions include restrictions such as:

  • no transfer outside the ecosystem;
  • no external secondary trading;
  • no exchange for fiat or virtual assets;
  • use only for the issuer-defined purpose; and
  • no broader payment or investment functionality.

Examples may include a genuinely closed loyalty point or internal game credit.

However, once the instrument can be externally traded, redeemed or used as an investment, the exclusion may no longer apply.

Central bank digital currency

Digital representations of fiat currency issued by the Central Bank of Kenya or another central bank are excluded.

Certain NFTs

A non-fungible token may be excluded where it is not used for:

  • payment;
  • investment;
  • another financial purpose; or
  • representing a financial asset.

The regulator will examine the NFT’s substance and function rather than its name.

A unique digital artwork may fall outside the regime. A fractionalised NFT representing income-producing property may not.

Virtual service tokens

The Act also excludes qualifying virtual service tokens and businesses dealing only with such instruments.

These exclusions should be applied cautiously. A written regulatory-perimeter analysis is advisable where the business model relies on an exemption.

5. Kenya’s Ten VASP Licence Categories

The Regulations establish detailed requirements for ten categories of virtual asset activity.

Licence categoryTypical business modelPrimary regulator
Virtual Asset Wallet ProviderCustodial wallets and private-key controlCBK
Virtual Asset Payment ProcessorCrypto payment and merchant settlementCBK
Stablecoin IssuerIssuance and redemption of stable-value tokensCBK
Virtual Asset ExchangeOperation of a trading venue or matching platformCMA
Virtual Asset BrokerArranging or executing transactions for customersCMA
Virtual Asset Investment AdviserAdvice on virtual asset investmentsCMA
Virtual Asset ManagerDiscretionary management of virtual asset portfoliosCMA
Initial Coin Offering ProviderSupporting or conducting public token offeringsCMA
Virtual Asset Tokenisation ProviderTokenising real-world or financial assetsCMA
Token Issuance PlatformInfrastructure for issuing and distributing tokensCMA

The correct classification must be determined by analysing the entire customer journey.

A platform may require more than one category.

For example, a customer may deposit money, buy Bitcoin, trade it and retain it in a hosted wallet. That model may involve:

  • exchange activity;
  • payment or settlement functions; and
  • custodial wallet services.

Multi-activity platforms should therefore assess whether they need:

  • multiple permissions;
  • engagement with both regulators;
  • separate legal entities;
  • a phased launch; or
  • changes to the original product design.

6. CBK and CMA: How Regulatory Responsibility Is Divided

Kenya applies a dual-regulator model.

Central Bank of Kenya

CBK’s mandate generally covers activities connected with:

  • custody;
  • payments;
  • settlement;
  • liquidity;
  • monetary stability; and
  • stable-value instruments.

It is the relevant authority for:

  • wallet providers;
  • payment processors; and
  • stablecoin issuers.

Capital Markets Authority

CMA’s mandate generally covers:

  • trading;
  • brokerage;
  • investment services;
  • capital raising;
  • token offerings;
  • market conduct; and
  • investor protection.

It is the relevant authority for:

  • exchanges;
  • brokers;
  • investment advisers;
  • virtual asset managers;
  • ICO providers;
  • tokenisation providers; and
  • token issuance platforms.

The Act gives the relevant regulatory authorities responsibility for licensing, supervision, monitoring of virtual asset offerings, enforcement and promoting financial soundness within their mandates.

The regulators may also cooperate with supervisory bodies, investigative agencies and other authorities.

7. Who Is Eligible to Apply?

An applicant must use a qualifying corporate form.

The framework contemplates a company limited by shares incorporated in Kenya or an eligible foreign company limited by shares registered in Kenya, subject to the Act and the applicable licensing requirements.

The applicant entity should be the company that genuinely conducts and controls the regulated business.

It should ordinarily:

  • contract with customers;
  • receive regulated revenue;
  • hold the regulatory capital;
  • employ or engage key officers;
  • maintain the required systems and controls;
  • enter into banking and provider agreements;
  • supervise outsourced functions; and
  • remain accountable to CBK or CMA.

A locally registered shell company that has no personnel, authority, systems or financial substance may face significant regulatory questions.

Ownership transparency

The applicant must fully disclose:

  • direct shareholders;
  • indirect shareholders;
  • significant shareholders;
  • beneficial owners;
  • voting rights;
  • economic interests;
  • parent companies;
  • trusts;
  • nominees; and
  • other control arrangements.

The ownership structure should be traced through every corporate layer to the relevant natural persons.

8. The Licence Application Process

The Regulations require a comprehensive application package.

A successful application is not merely a completed form. It is a coordinated regulatory submission covering the applicant’s legal, financial, operational and technological readiness.

The application is expected to address:

  • personal and professional details of key persons;
  • the applicant’s business plan;
  • ownership and beneficial ownership;
  • fit-and-proper information;
  • source of funds;
  • capital and liquidity;
  • governance;
  • risk management;
  • AML/CFT/CPF;
  • cybersecurity;
  • complaints handling;
  • technology architecture;
  • outsourcing;
  • financial statements;
  • material contracts;
  • customer documentation;
  • systems testing; and
  • proof of payment of applicable fees.

The Regulations also require an independent information-systems audit incorporating vulnerability assessment and penetration testing.

Regulatory business plan

The business plan should explain:

  • the exact regulated services;
  • customer segments;
  • customer journey;
  • fiat and virtual asset flows;
  • custody model;
  • revenue model;
  • governance;
  • staffing;
  • technology;
  • liquidity;
  • outsourcing;
  • risk management;
  • compliance;
  • implementation timetable;
  • financial projections; and
  • orderly wind-down.

An investor pitch deck is not sufficient.

The regulator must be able to understand how the business will operate as a supervised institution.

9. Fit-and-Proper Requirements

The regulators assess the persons who own, direct or manage the VASP.

This may include:

  • directors;
  • chief executive officer;
  • senior officers;
  • significant shareholders;
  • beneficial owners;
  • compliance officers; and
  • other key function holders.

The assessment may examine:

  • honesty;
  • integrity;
  • reputation;
  • competence;
  • qualifications;
  • relevant experience;
  • financial soundness;
  • criminal history;
  • civil litigation;
  • insolvency;
  • disciplinary history;
  • previous regulatory breaches; and
  • conflicts of interest.

The Act specifically gives the regulatory authorities powers to vet significant shareholders, beneficial owners, directors and senior officers as part of their AML/CFT/CPF supervisory functions.

Material adverse matters should be disclosed and explained.

A historic issue may be manageable. Concealing it may create a separate concern about honesty and regulatory openness.

10. Paid-Up and Liquid Capital

Kenya applies activity-specific prudential requirements.

The capital framework reflects the risk created by each business model.

Licence categoryMinimum paid-up capital
Virtual Asset Investment AdviserNo prescribed fixed minimum
Virtual Asset BrokerKSh 10 million
Virtual Asset Payment ProcessorKSh 10 million
Virtual Asset Tokenisation ProviderKSh 10 million
Virtual Asset ManagerKSh 20 million
Initial Coin Offering ProviderKSh 20 million
Token Issuance PlatformKSh 20 million
Virtual Asset ExchangeKSh 100 million
Virtual Asset Wallet ProviderKSh 150 million
Stablecoin IssuerKSh 300 million

The Regulations also impose liquid-capital requirements for the relevant categories.

Paid-up capital and liquid capital are not the same.

Paid-up capital

This is the qualifying equity contributed by shareholders and represented by fully paid shares.

It is intended to absorb business losses and support the financial resilience of the VASP.

Liquid capital

This measures whether the business has sufficient accessible financial resources to meet liabilities.

Some requirements are fixed. Others increase by reference to liabilities.

Capital must be maintained

The capital threshold is not merely an entry test.

A licensee must remain above the required amount after:

  • paying operating expenses;
  • incurring losses;
  • hiring staff;
  • funding systems;
  • paying vendors; and
  • completing the regulatory process.

A startup should therefore raise more than the minimum statutory figure.

The real funding requirement should include:

paid-up capital + liquid capital + implementation expenses + operating runway + contingency.

11. AML/CFT/CPF Obligations

VASPs are brought within Kenya’s anti-money laundering framework.

The Act gives the relevant regulator responsibility for supervising and enforcing VASP compliance with AML/CFT/CPF requirements. The supervisory powers include onsite inspections, offsite surveillance, group supervision, information demands and oversight of significant shareholders, beneficial owners and management.

A licensed VASP should establish controls covering:

  • enterprise-wide risk assessment;
  • customer identification and verification;
  • beneficial ownership;
  • sanctions screening;
  • politically exposed persons;
  • customer risk rating;
  • enhanced due diligence;
  • source-of-funds checks;
  • ongoing monitoring;
  • fiat transaction monitoring;
  • blockchain analytics;
  • suspicious transaction reporting;
  • record keeping;
  • staff training; and
  • the Travel Rule.

Crypto-specific monitoring

Traditional transaction monitoring is not enough.

The VASP may need to assess exposure to:

  • mixers or tumblers;
  • sanctioned addresses;
  • darknet markets;
  • ransomware;
  • scams;
  • stolen assets;
  • high-risk exchanges;
  • unhosted wallets; and
  • chain-hopping activity.

The compliance programme must match the actual assets, customer types, transaction flows and jurisdictions used by the business.

12. Governance and Management

The applicant must demonstrate credible governance.

A regulated virtual asset business should have:

  • an effective board;
  • clear reporting lines;
  • competent senior management;
  • defined control functions;
  • conflict-management procedures;
  • delegated authorities;
  • board and committee terms of reference;
  • risk oversight;
  • compliance oversight; and
  • independent assurance.

The board should understand the business rather than merely approve documents prepared by external advisers.

Directors should be able to explain:

  • the licensing category;
  • customer flows;
  • custody;
  • financial crime risks;
  • capital;
  • liquidity;
  • cybersecurity;
  • outsourcing;
  • complaints;
  • business continuity; and
  • wind-down arrangements.

Nominal directors or senior officers who lack authority and understanding may undermine the application.

13. Cybersecurity and Technology Requirements

Technology is not treated as a secondary support function.

For many VASPs, the technology is the regulated operating environment.

Applicants should expect to document:

  • system architecture;
  • network architecture;
  • data flows;
  • wallet infrastructure;
  • cloud services;
  • access controls;
  • privileged accounts;
  • encryption;
  • authentication;
  • APIs;
  • logging;
  • change management;
  • incident response;
  • backup;
  • disaster recovery; and
  • third-party integrations.

The Regulations require independent systems assurance, including vulnerability assessment and penetration testing. 

The testing should examine the actual platform intended for launch.

Critical and high-risk findings should be remediated and retested before the application is treated as ready.

Wallet and key-management controls

A custodial business should address:

  • key generation;
  • hot and cold storage;
  • multi-signature controls;
  • withdrawal approval;
  • access segregation;
  • wallet recovery;
  • address allowlisting;
  • reconciliation;
  • transaction limits; and
  • incident containment.

The regulator will want evidence that customer assets cannot be moved through the unilateral action of an unauthorised employee or compromised administrator.

14. Customer Asset Protection

Where a VASP holds or controls customer money or virtual assets, safeguarding becomes a central obligation.

The business should be able to explain:

  • where customer fiat is held;
  • where virtual assets are held;
  • whether accounts are segregated;
  • who controls private keys;
  • how individual entitlements are recorded;
  • how reconciliations are performed;
  • what happens if a third-party custodian fails;
  • whether customer assets can be lent, pledged or reused;
  • how insolvency affects customer rights; and
  • how assets will be returned during wind-down.

Customer assets must not be treated as the VASP’s working capital.

A credible safeguarding framework should include:

  • legal analysis;
  • account structures;
  • wallet diagrams;
  • reconciliation procedures;
  • custody agreements;
  • customer terms;
  • insolvency arrangements;
  • internal controls; and
  • audit trails.

15. Consumer Protection and Market Conduct

Kenya’s framework is not limited to licensing and AML.

The Regulations also seek to protect customers and investors through requirements relating to disclosure, safeguarding, complaints and responsible market conduct. The regulatory impact documentation identified consumer and investor protection as a core objective of the framework. 

VASPs should provide customers with clear information on:

  • services;
  • fees;
  • spreads;
  • execution arrangements;
  • custody;
  • conflicts;
  • risks;
  • transaction finality;
  • supported assets;
  • complaints;
  • suspension or termination;
  • loss allocation; and
  • recovery procedures.

Risk disclosures

Customers should understand that virtual assets may involve:

  • price volatility;
  • loss of capital;
  • cyberattacks;
  • smart-contract failure;
  • blockchain congestion;
  • irreversibility;
  • custody failure;
  • liquidity problems;
  • delisting;
  • legal uncertainty; and
  • stablecoin de-pegging.

Risk warnings should be prominent and tailored to the service.

Generic statements hidden within lengthy customer terms are unlikely to demonstrate meaningful disclosure.

Marketing

Marketing should not be:

  • false;
  • misleading;
  • exaggerated;
  • incomplete; or
  • designed to conceal material risks.

Claims such as “guaranteed returns”, “risk-free crypto” or “fully protected investment” may create serious market-conduct concerns.

16. Virtual Asset Exchanges

Exchange operators face heightened obligations because they operate trading infrastructure.

An exchange should establish controls for:

  • asset admission;
  • listing and delisting;
  • order handling;
  • matching;
  • execution;
  • settlement;
  • market surveillance;
  • manipulation;
  • insider dealing;
  • wash trading;
  • conflicts of interest;
  • proprietary trading;
  • market making; and
  • operational outages.

The exchange should also disclose:

  • how prices are determined;
  • whether it acts as principal;
  • whether affiliates trade on the platform;
  • how orders are prioritised;
  • how market makers are supervised; and
  • how suspicious trading activity is escalated.

Adding hosted wallets may trigger separate custody or wallet licensing considerations.

17. Brokers, Advisers and Virtual Asset Managers

Brokers

A broker arranges or executes virtual asset transactions for customers.

The business should define whether it acts:

  • as agent;
  • as principal;
  • on an execution-only basis;
  • through an OTC model; or
  • through third-party venues.

The broker should address best execution, pricing, conflicts, counterparties, settlement and customer communications.

Investment advisers

An investment adviser provides recommendations or advice concerning virtual assets.

The firm should establish:

  • client classification;
  • suitability or appropriateness;
  • conflict management;
  • research controls;
  • risk disclosures;
  • record keeping; and
  • restrictions on personal dealing.

Virtual asset managers

A manager exercises discretion over customer portfolios.

Its framework should cover:

  • investment mandate;
  • portfolio restrictions;
  • risk limits;
  • valuation;
  • custody;
  • liquidity;
  • performance reporting;
  • conflicts;
  • asset selection; and
  • termination arrangements.

A company that chooses investments for the customer may require management authorisation even if it describes itself as an advisory platform.

18. ICOs and Token Issuance Platforms

The Act prohibits unapproved virtual asset offerings in or from Kenya and regulates applications for admission of virtual assets to trading.

A token-offering project may need to address:

  • issuer identity;
  • promoter background;
  • token rights;
  • token supply;
  • use of proceeds;
  • technical architecture;
  • smart-contract audit;
  • governance;
  • risk factors;
  • financial information;
  • custody of proceeds;
  • marketing;
  • conflicts;
  • distribution;
  • lock-ups;
  • secondary trading;
  • redemption; and
  • project failure.

Token issuance platforms

A launchpad or issuance platform should establish standards for:

  • issuer onboarding;
  • due diligence;
  • token admission;
  • disclosure review;
  • smart-contract review;
  • fundraising;
  • custody;
  • investor eligibility;
  • ongoing monitoring; and
  • removal of non-compliant projects.

A platform cannot assume that the issuer alone bears responsibility for the offering.

19. Real-World Asset Tokenisation

The Regulations recognise tokenisation as a distinct regulated activity.

Potential assets may include:

  • real estate;
  • commodities;
  • receivables;
  • investment funds;
  • debt instruments;
  • shares;
  • revenue interests;
  • infrastructure; and
  • intellectual property.

A tokenisation project must distinguish between:

  1. the underlying asset;
  2. the legal rights represented by the token;
  3. the issuer;
  4. the token holder;
  5. the custody or trustee structure;
  6. the blockchain record; and
  7. any secondary trading arrangement.

The token does not create ownership by magic

A digital token is only as strong as the legal structure behind it.

For example, a real-estate token may represent:

  • direct ownership;
  • shares in a property-owning company;
  • units in an investment structure;
  • a debt claim;
  • a contractual revenue right; or
  • no enforceable property interest at all.

The offering documents must accurately explain what the investor acquires.

Tokenisation providers should also consider property, securities, tax, insolvency, trust and data-protection laws in addition to the VASP framework.

20. Stablecoin Regulation

Stablecoin issuers fall under CBK and face the highest capital threshold within the framework.

A stablecoin model must address:

  • issuance;
  • reserve assets;
  • custody;
  • redemption;
  • liquidity;
  • valuation;
  • attestations;
  • audits;
  • marketing;
  • distribution;
  • operational resilience;
  • de-pegging;
  • wind-down; and
  • financial stability.

Three separate financial resources

A stablecoin issuer should distinguish between:

ResourceFunction
Regulatory capitalAbsorbs business losses
Liquid capitalSupports short-term corporate obligations
Reserve assetsBack outstanding stablecoin liabilities

The same funds should not be counted in all three categories.

The reserve should be structured so that token holders can redeem in accordance with the stablecoin’s terms.

The issuer must also explain:

  • what assets support the token;
  • where they are held;
  • who owns them legally;
  • how frequently they are valued;
  • whether they are segregated;
  • whether they can be invested;
  • how redemption requests are funded; and
  • what happens during insolvency.

21. Outsourcing and Third-Party Providers

VASPs commonly rely on:

  • banks;
  • custodians;
  • cloud providers;
  • liquidity providers;
  • KYC vendors;
  • blockchain analytics;
  • payment processors;
  • white-label technology;
  • cybersecurity firms;
  • software developers; and
  • data centres.

Outsourcing does not transfer regulatory accountability.

The licensed VASP remains responsible for ensuring that outsourced functions meet applicable requirements.

A critical outsourcing framework should address:

  • provider due diligence;
  • written agreements;
  • service levels;
  • audit rights;
  • regulatory access;
  • confidentiality;
  • data location;
  • cybersecurity;
  • incident notification;
  • subcontracting;
  • business continuity;
  • termination; and
  • migration or exit.

The regulator may question a model where the applicant cannot replace, supervise or audit a provider performing a critical function.

22. Data Protection and Record Keeping

VASPs process substantial amounts of personal and financial information.

This may include:

  • identity documents;
  • biometric information;
  • addresses;
  • source-of-funds records;
  • wallet addresses;
  • transaction histories;
  • device information;
  • geolocation indicators;
  • risk scores; and
  • sanctions or adverse-media results.

The business should align its operations with Kenya’s data-protection framework and implement:

  • privacy notices;
  • lawful processing;
  • access controls;
  • data minimisation;
  • retention schedules;
  • breach response;
  • cross-border transfer controls;
  • vendor due diligence; and
  • data-subject rights procedures.

The Regulations also contemplate secure records, transaction audit trails, confidentiality and appropriate handling of customer information.

Records should be sufficient to reconstruct:

  • customer onboarding;
  • approvals;
  • orders;
  • wallet transfers;
  • screening decisions;
  • alerts;
  • investigations;
  • complaints; and
  • regulatory reports.

23. Ongoing Regulatory Obligations

Obtaining the licence is the beginning of supervision—not the end.

A licensed VASP must continue maintaining:

  • capital and liquidity;
  • fit-and-proper management;
  • AML controls;
  • technology security;
  • customer asset protection;
  • accurate records;
  • effective governance;
  • regulatory reporting;
  • audited financial statements;
  • compliant marketing;
  • complaints handling;
  • business continuity; and
  • current provider oversight.

Material changes may require notification or prior regulatory approval.

These may include changes to:

  • ownership;
  • beneficial ownership;
  • directors;
  • senior officers;
  • business model;
  • technology;
  • capital;
  • liquidity;
  • key outsourcing;
  • custody;
  • supported products; or
  • control of the licence holder.

The licence should never be treated as a static permission that automatically covers every future product.

24. Enforcement and Consequences of Non-Compliance

The regulatory authorities have broad powers under the Act.

They can:

  • demand information;
  • conduct inspections;
  • issue directions;
  • supervise groups;
  • investigate misconduct;
  • impose restrictions;
  • take enforcement action; and
  • address AML/CFT/CPF failures.

Operating without the required licence creates legal and commercial exposure.

Potential consequences may include:

  • rejection of the application;
  • licence conditions;
  • suspension;
  • revocation;
  • financial penalties;
  • criminal consequences where applicable;
  • restrictions on directors or officers;
  • interruption of banking relationships;
  • customer claims;
  • reputational damage; and
  • forced cessation of services.

The Act expressly authorises regulators to issue directives and take enforcement action for non-compliance. 

Providing false, incomplete or misleading information during the application can also compromise the suitability assessment.

25. What Existing and Prospective VASPs Should Do Now

A practical implementation plan should follow ten steps.

Step 1: Complete a regulatory-perimeter assessment

Map every service, customer flow, asset flow and revenue stream.

Step 2: Identify the correct licence categories

Determine whether CBK, CMA or both authorities are relevant.

Step 3: Select the applicant structure

Confirm the Kenyan entity, ownership chain, group relationships and technology rights.

Step 4: Calculate capital and funding

Separate regulatory capital, liquid capital, operating cash, customer assets and reserves.

Step 5: Appoint credible management

Identify directors, senior officers and control-function leaders early.

Step 6: Prepare the regulatory business plan

Document the complete operational model.

Step 7: Build compliance systems

Implement AML, sanctions, blockchain monitoring, complaints and reporting processes.

Step 8: Complete technology testing

Conduct independent systems review, vulnerability assessment and penetration testing.

Step 9: Finalise critical contracts

Complete banking, custody, liquidity, technology and outsourcing arrangements.

Step 10: Conduct a pre-submission readiness review

Test every document and system against the Act, Regulations and actual business model.

Kenya VASP Readiness Checklist

WorkstreamCore question
Regulatory perimeterAre all regulated activities identified?
RegulatorIs the CBK/CMA pathway confirmed?
Corporate structureDoes the applicant control the regulated business?
OwnershipAre all beneficial owners fully disclosed?
ManagementAre key persons competent and fit and proper?
CapitalAre paid-up and liquid capital fully funded?
Source of fundsCan all shareholder contributions be traced?
Business planDoes it reflect the actual operating model?
AMLAre controls implemented and tested?
TechnologyIs the platform ready for independent review?
CybersecurityAre material vulnerabilities remediated?
SafeguardingAre customer assets properly segregated and reconciled?
Consumer protectionAre fees, risks and complaints processes transparent?
OutsourcingCan critical providers be supervised and replaced?
Financial runwayCan the company operate for at least 12–18 months?

A significant number of negative answers indicates that the applicant is not yet ready to file.

How CRYPTOVERSE Can Help

CRYPTOVERSE Legal Consultancy supports crypto and virtual asset businesses entering Kenya through:

  • regulatory-perimeter assessments;
  • CBK and CMA activity mapping;
  • licence-category analysis;
  • applicant and group structuring;
  • beneficial ownership reviews;
  • capital and liquidity planning;
  • source-of-funds preparation;
  • regulatory business plans;
  • fit-and-proper files;
  • governance frameworks;
  • AML/CFT/CPF policies;
  • Travel Rule procedures;
  • cybersecurity and systems-audit coordination;
  • custody and safeguarding frameworks;
  • exchange and brokerage documentation;
  • stablecoin structuring;
  • ICO and token issuance support;
  • real-world asset tokenisation;
  • customer terms and risk disclosures;
  • outsourcing agreements;
  • licence application preparation;
  • regulatory response management;
  • management interview preparation; and
  • post-licensing compliance.

The objective is to turn an innovative crypto concept into a business model that CBK or CMA can understand, supervise and approve.

Conclusion: Kenya Has Moved From Regulatory Uncertainty to Regulatory Execution

Kenya’s crypto regulatory conversation has changed.

The question is no longer whether virtual asset businesses will be regulated.

The question is whether each business can satisfy the requirements applicable to its activity.

The VASP Act establishes the perimeter.

The Regulations establish the operational standards.

Together, they require crypto businesses to demonstrate:

  • transparent ownership;
  • competent management;
  • adequate capital;
  • lawful funding;
  • strong governance;
  • effective AML controls;
  • secure technology;
  • customer asset protection;
  • fair market conduct;
  • credible consumer protection; and
  • continuing financial and operational resilience.

This creates a more demanding environment—but also a more credible market.

A licensed exchange can engage customers, banks and institutional partners from a clearer legal position.

A regulated wallet provider can demonstrate that custody is supported by formal controls.

A tokenisation business can structure offerings within an identifiable framework.

A stablecoin issuer can build around defined capital, reserve, redemption and governance expectations.

But authorisation will not be achieved through a template application.

The strongest applicants will begin by designing the regulated institution itself.

They will ensure that the business model, ownership, capital, technology, contracts, compliance systems and management team all tell the same story.

Kenya’s 2026 crypto regulations therefore represent more than a licensing requirement.

They mark the transition of virtual assets from an informal digital market into a supervised part of Kenya’s financial system.

For serious founders, that transition creates a clear strategic message:

Build for regulation from the beginning—or expect regulation to redesign the business later.

FAQs

1. Are cryptocurrencies legal in Kenya in 2026?

Kenya has established a formal legal framework for virtual asset services. A business conducting regulated VASP activities must obtain the applicable licence and comply with the Act and Regulations.

2. Which regulator licenses crypto businesses in Kenya?

CBK generally supervises wallets, payment processors and stablecoin issuers. CMA generally supervises exchanges, brokers, investment advisers, managers, ICO providers, tokenisation providers and token issuance platforms.

3. Can an offshore crypto company serve Kenyan customers without a licence?

The Act applies to VASPs offering virtual asset services in Kenya. An offshore company targeting or serving the Kenyan market should complete a regulatory-perimeter assessment rather than assume that foreign incorporation removes it from the regime.

4. Does every blockchain or token project require a VASP licence?

No. Genuine software providers, qualifying closed-ecosystem instruments, certain non-financial NFTs and virtual service tokens may fall outside the regime. The exemption depends on actual functionality, not the label used.

5. Can one company hold more than one Kenya VASP licence?

A multi-service business may require several permissions. The applicant should assess whether the activities can sit within one entity, require engagement with both CBK and CMA, or should be introduced through a phased structure.