If you are a founder building in Web3, there is one question that can save you months of wasted work:
What does VARA actually require before I issue a token in Dubai?
That question sounds simple, but the answer is where many startups get stuck.
Some teams assume every token needs a full VARA licence.
Others assume “utility tokens” are automatically unregulated.
Some believe they can launch first, grow the community, and sort out compliance later.
And many do not realise that in Dubai, the legal treatment of a token depends less on what you call it and more on what it actually does.
That is exactly why the Virtual Asset Issuance Rulebook matters.
VARA has given the market a structured framework for token issuance in Dubai. It explains when a token issuance requires a licence, when it does not, when a licensed distributor must be involved, what founders must disclose before launch, what special rules apply to stablecoins and asset-referenced tokens, and why token changes after launch can trigger fresh regulatory consequences.
The later Guidance on the Virtual Asset Issuance Rulebook then makes the practical position even clearer. It explains how VARA expects issuers to interpret the rules in the real world, especially on matters like what counts as issuing “in the course of a business,” what makes a token Category 1, how whitepapers should be approached, and why token design changes can completely alter the compliance path.
This article is written for the people who actually need to use the framework:
- startup founders,
- protocol teams,
- token issuers,
- exchange-linked projects,
- RWA ventures,
- launchpads,
- and early-stage Web3 companies entering Dubai.
The goal here is not to drown you in legal language.
The goal is to explain, in practical terms, the VARA token issuance requirements founders and startups need to understand before launching a token in Dubai.
Why founders in Dubai need to care about token issuance rules early
Startups usually move fast.
That is part of the culture. Teams build, test, iterate, pivot, and optimise. In most markets, founders are already used to the idea that regulation may be unclear, inconsistent, or lagging behind technology.
Dubai is different.
Dubai has chosen to regulate token issuance with structure.
That means the biggest founder mistake in this market is not failing to innovate. It is failing to sequence things properly.
A lot of startups ask questions like:
- What should our tokenomics look like?
- Should we launch with a private sale?
- Can we market before launch?
- Should the token be transferable on day one?
- Can we tie it to revenue later?
Those are important business questions.
But under the VARA framework, the more urgent questions are:
- Does this token fall within Category 1, Category 2, or exempt treatment?
- Do we need a VARA licence?
- Do we need a Licensed Distributor?
- Are we accidentally building a stablecoin?
- Are we accidentally creating an asset-referenced token?
- What has to go into the whitepaper?
- What risks do we need to disclose?
- Could future product changes move the token into a more heavily regulated category?
That is why token issuance compliance is not a legal clean-up exercise in Dubai.
It is part of launch design.
1. The first requirement: know whether VARA’s issuance framework applies to you
The starting point in the Rulebook is scope.
VARA says that all entities in the Emirate that issue a virtual asset in the course of a business must comply with the Rulebook. It then gives a non-exhaustive set of factors for assessing whether the issuance is in the course of a business, including:
- whether the entity holds itself out as issuing the token in the course of a business,
- the regularity and scale of issuance,
- whether there is any direct or indirect commercial element,
- whether the entity receives remuneration or other value,
- whether the activity is related to a business,
- and whether even a non-profit, foundation, or association is involved.
The Guidance makes this broader in practical effect. It explains that an issuance can still be “in the course of a business” even if the token is not sold for money or other value in a traditional sense. Any direct or indirect commercial element may be enough. It also says that Category 1 issuances are always deemed to be carried out in the course of a business, without exception.
What this means for founders
If your token launch is connected to:
- a platform,
- a startup venture,
- a protocol,
- a growth model,
- an incentive structure,
- a monetisation plan,
- or any organised economic activity,
you should assume VARA’s framework is potentially relevant.
The idea that “we are just a community project” is not, on its own, a legal answer.
2. The second requirement: classify the token properly
This is the most important requirement in the whole framework.
Everything else flows from token classification.
The Rulebook divides token issuance in Dubai into three categories:
- Category 1
- Category 2
- Exempt VAs
Category 1
Category 1 includes:
- Fiat-Referenced Virtual Assets (FRVAs)
- Asset-Referenced Virtual Assets (ARVAs)
- and any other virtual assets VARA may designate from time to time.
If your token falls into Category 1, you need a VARA licence before issuance.
Category 2
Category 2 includes any token that is not:
- Category 1, and
- not exempt.
If your token falls into Category 2, the issuer does not need a VARA licence for the issuance itself, but all placement and distribution must be carried out through or by a Licensed Distributor.
Exempt VAs
The exempt category currently includes:
- Non-Transferable Virtual Assets
- Redeemable Closed-Loop Virtual Assets
- and any other exempt type VARA may later determine.
These do not require prior approval before issuance, but they are still subject to general conduct rules and VARA oversight.
Why founders get this wrong
Founders often assume classification depends on branding:
- “It’s a utility token.”
- “It’s just a governance token.”
- “It’s really just points.”
- “It’s not security.”
But that is not how VARA approaches it.
The Rulebook says VARA may consider:
- the nature of the token,
- the rights and value it represents or purports to represent,
- and the underlying business model.
The Guidance reinforces that the regulator is looking at the actual characteristics of the token.
So the requirement for founders is clear:
Classify before you code, not after you market.
3. The third requirement: know when a licence is mandatory
If the token is Category 1, licensing is not optional.
The Rulebook states that no entity in the Emirate may carry out a Category 1 issuance unless it is authorised and licensed by VARA for that issuance. Category 1 issuance is itself a VA Activity.
That means stablecoins and many real-world asset-linked structures do not sit in the “launch first, discuss later” zone.
They sit squarely in regulated territory.
FRVAs: stablecoin-type structures
If your token purports to maintain stable value against fiat, you are likely in FRVA territory.
The Rulebook defines an FRVA as a token that purports to maintain stable value in relation to one or more fiat currencies or one or more FRVAs, but does not have legal tender status in the UAE and is not issued for use as a means of payment for goods or services in the UAE.
The FRVA annex then adds major compliance obligations, including:
- approval for each FRVA before issuance,
- stable backing requirements,
- reserve assets of at least 100%,
- reserve asset composition and custody rules,
- redemption at par,
- monthly disclosures on circulating supply and reserve assets,
- and audit-related reporting.
The Rulebook also says that any token maintaining stable value against the AED is not approved under the VARA FRVA framework and remains under the sole and exclusive regulatory purview of the Central Bank of the UAE.
ARVAs: real-world asset and income-linked structures
The ARVA definition is broad and catches far more than many founders expect.
It includes tokens representing or purporting to represent:
- ownership of RWAs,
- entitlement to receive or share income,
- stable reference to RWAs or income,
- value derived from or backed by RWAs or income,
- or wrapped, duplicated, fractionalised, securitised, or derivative versions of other ARVAs.
The Guidance explains that ARVAs may take different legal and economic forms. Some may grant direct ownership. Others may merely give exposure to value or redemption rights linked to underlying assets.
For founders, the warning sign is simple:
if your token touches real-world assets or income in a meaningful way, you need a serious ARVA analysis.
4. The fourth requirement: understand that “no licence” does not mean “no regulation”
This is the point many startups misunderstand.
If your token is Category 2, you do not need a VARA issuer licence.
But that does not mean you are free to launch casually.
The Rulebook says Category 2 issuers may only issue tokens if all placement and distribution is carried out by a Licensed Distributor.
The Guidance explains that Licensed Distributors:
- conduct due diligence on both the issuer and the token,
- are responsible for assuring and validating compliance,
- and must continue to monitor the token throughout the relationship. If they know or ought reasonably to know that the token no longer meets the required standards, they may need to suspend or cease distribution services.
What this means for startups
A Category 2 route still requires:
- proper token classification,
- a credible issuer structure,
- a compliant whitepaper,
- a compliant risk disclosure statement,
- and a project strong enough for a regulated intermediary to stand behind.
In practical terms, “no licence required” is not the same as “no gatekeeper.”
The Licensed Distributor becomes that gatekeeper.
5. The fifth requirement: know when a token may be exempt
Exempt status can reduce the regulatory burden, but only in narrow circumstances.
The current exempt categories are:
- Non-Transferable Virtual Assets
- Redeemable Closed-Loop Virtual Assets
Non-Transferable Virtual Assets
These are tokens that:
- are not sold by the issuer for, and cannot be converted into, exchanged, or redeemed for fiat, virtual assets, or value in kind,
- are not redeemable or exchangeable for goods, services, discounts, purchases, or otherwise have no market, use, or application,
- and cannot be transferred between VA wallets.
The Guidance suggests badges and commemorative tokens as possible examples.
Redeemable Closed-Loop Virtual Assets
These are tokens redeemable for goods, services, discounts, or purchases with the issuer or designated merchants, provided they:
- are not sold or exchanged for fiat or virtual assets,
- cannot be used outside the closed loop,
- and cannot be transferred between wallets except for redemption purposes.
The Guidance points to loyalty schemes and discount systems as likely examples, provided they do not become tradable.
Important founder warning
Exempt does not mean invisible.
Exempt issuers still need to comply with the general rules in Part II and remain subject to VARA supervision, examination, and enforcement.
And if the token evolves in a way that allows a market to form around it, the exemption may disappear.
6. The sixth requirement: publish a compliant whitepaper
For all non-exempt issuances, a whitepaper is mandatory.
The Rulebook requires issuers to publish the relevant disclosures in a single easily accessible location in a machine-readable format before the token is made available to the public, including any offer or marketing.
What founders must include
Schedule 1 requires extensive disclosure on:
- the issuer,
- the token,
- the rights and obligations attached to the token,
- the technology used,
- the licensed distributor where relevant,
- and the public offer details where relevant.
That includes matters such as:
- issuer identity and structure,
- management and ownership,
- prior financial condition,
- governance arrangements,
- token features and uses,
- supply and allocation,
- transferability and redemption rights,
- insolvency treatment,
- technology stack,
- audit information,
- and environmental impact.
The Guidance says founders and their distributors must exercise careful professional judgment when deciding what is applicable. If relevant information is left out and later found to have been applicable, the whitepaper is non-compliant.
Why this matters for startups
The whitepaper in Dubai is not just a launch document.
It is a liability document, a transparency document, and a regulatory document.
7. The seventh requirement: do not try to disclaim away liability
This is one of the sharpest parts of the Rulebook.
It says no issuer may exclude or attempt to exclude any form of actual or potential civil liability in respect of information in any whitepaper or other disclosure or communication.
The Guidance reinforces this principle across whitepapers and risk disclosures.
What this means for founders
You cannot rely on generic disclaimer culture to rescue weak disclosure.
If the whitepaper is misleading, incomplete, or unclear, the legal problem remains.
8. The eighth requirement: publish a Risk Disclosure Statement
A separate Risk Disclosure Statement is also required for non-exempt tokens.
It must:
- describe all material risks,
- be concise,
- be written in clear, non-technical language,
- and be available in the same accessible location as the whitepaper, while remaining separate from it.
The Guidance explains that founders should focus on material risks only and avoid generic or vague statements. Risks should reflect the actual token design and be grouped and ranked by relevance.
What startups often get wrong
A lot of early-stage teams use boilerplate risk statements that could apply to any token anywhere.
That is not the standard VARA is pointing toward.
The relevant risks are the risks of your token:
- liquidity risk,
- redemption risk,
- custody risk,
- reserve asset risk,
- market risk,
- counterparty risk,
- legal enforceability risk,
- technology risk,
- governance risk,
- and whatever else is actually material to the structure.
9. The ninth requirement: maintain good governance and adequate resources
The VARA framework does not look only at the token.
It also looks at the issuer.
Part II of the Rulebook requires issuers to act with:
- integrity, honesty, and fairness,
- due skill, care, and diligence,
- adequate capabilities and resources,
- effective communication and disclosures,
- legal and regulatory compliance,
- and environmental responsibility.
The Guidance adds that governance disclosures should be detailed enough to allow readers to assess how the issuer manages operational, regulatory, and token-specific risks. For Category 1 issuers, VARA expects detailed governance information around structure, committees, risk functions, amendment processes, and compliance controls.
Why this matters for founders
A startup cannot treat token issuance as something detached from the company behind it.
If governance is weak, lines of responsibility are unclear, or the team lacks the resources to support the project, that becomes part of the compliance risk.
10. The tenth requirement: keep disclosures accurate after launch
This is where many projects relax too early.
The Rulebook requires the whitepaper to remain accurate and complete at all times. The same applies to the Risk Disclosure Statement. Updates must be dated, prior versions must remain easily accessible, and records must be kept for at least eight years from when the token ceases circulation.
The Guidance makes it clear that this is an ongoing requirement for as long as the token is available to the market.
What founders should do
Treat your whitepaper and risk disclosure statement as living compliance documents, not static PDFs.
11. The eleventh requirement: notify holders of token changes
The Rulebook requires issuers to take all reasonable steps to notify owners of changes to a token before those changes take effect, except where urgent security or integrity reasons justify immediate implementation.
The Guidance explains that this allows holders time to react where a change could affect value, rights, or core functionality.
For startups, this matters because token design often evolves quickly.
But in Dubai, token changes are not just product events.
They can also be legal and disclosure events.
12. The twelfth requirement: reassess classification before changing token features
This is one of the most practical founder requirements in the whole framework.
If a token changes in a way that may move it out of its original category, the issuer must comply with the requirements of the new category before the change takes effect. That may include licensing and whitepaper approval.
The Guidance gives useful examples:
- an exempt token that becomes transferable may cease to be exempt,
- a Category 2 token that becomes asset-referenced may need to move into Category 1 before the change is implemented.
Founder takeaway
Do not assume your launch-day classification lasts forever.
In Dubai, token evolution can create fresh regulatory obligations.
13. The thirteenth requirement: be prepared for VARA supervision and enforcement
Finally, founders need to remember that VARA’s powers do not stop at launch.
Part IV of the Rulebook says VARA has supervisory, examination, and enforcement powers in relation to all virtual assets and VA activities in the Emirate. It may:
- require an issuer to suspend issuing a token or issuing further tokens,
- impose additional conditions,
- take enforcement action,
- require books and records,
- and demand access to data, premises, and systems.
This is why founder compliance should include:
- internal recordkeeping,
- version control,
- governance documentation,
- and a defensible explanation of how the token was classified and structured.
Practical founder checklist: what VARA expects before you issue a token
If you want the short founder version, here it is:
- Check whether the issuance is in the course of a business.
- Confirm the token is not prohibited.
- Classify the token properly.
- Assess whether it is FRVA or ARVA.
- Choose the correct route: licence, Licensed Distributor, or exemption.
- Draft a compliant whitepaper.
- Draft a real Risk Disclosure Statement.
- Ensure governance, resources, and controls are credible.
- Do not market before disclosures are ready.
- Keep the disclosures updated after launch.
- Notify holders of relevant changes.
- Reassess classification before upgrading token features.
- Stay ready for VARA supervision and enforcement.
Final conclusion
For founders and startups, VARA’s token issuance framework is not something to fear.
But it is something to respect.
Dubai is not saying that token issuance is impossible. It is saying that token issuance must be structured properly. That means founders need to think early about:
- what their token represents,
- how it will be classified,
- whether it needs a licence,
- whether it needs a Licensed Distributor,
- what has to be disclosed,
- and how the project will remain compliant after launch.
The startups that get this right are usually not the ones moving slowest.
They are the ones sequencing properly.
They do not leave legal analysis until the launch date is already on the calendar.
They build the token, the documentation, and the route to market together.
That is how serious token issuance works in Dubai.
Why work with CRYPTOVERSE Legal
At CRYPTOVERSE Legal, we help founders, startups, token issuers, VASPs, and Web3 businesses understand and navigate the VARA token issuance framework from the beginning.
Our support can include:
- token classification analysis,
- FRVA and ARVA assessment,
- Category 1 vs Category 2 structuring,
- whitepaper and Risk Disclosure Statement review,
- launch-readiness legal checklists,
- and ongoing compliance strategy for token evolution.
When launching a token in Dubai, the most expensive legal mistakes are usually the ones made before anyone realises they are mistakes.
Legal disclaimer: This article is provided for general informational purposes only and does not constitute legal advice. The regulatory treatment of any token under VARA depends on the specific facts, rights, value mechanics, business model, market structure, and operational design of the relevant project. Independent legal advice should be obtained before issuing, marketing, distributing, or modifying any virtual asset in or from Dubai.
FAQs
1. What are VARA token issuance requirements in Dubai?
VARA token issuance requirements include proper token classification, licensing assessment, whitepaper preparation, risk disclosures, and compliance with the Virtual Asset Issuance Rulebook.
2. Does every token require a VARA licence?
No. Only certain tokens, such as Category 1 virtual assets, require a VARA licence before issuance. Other categories may require a Licensed Distributor or qualify for exemptions.
3. What is a Category 1 token under VARA?
Category 1 tokens include Fiat-Referenced Virtual Assets (FRVAs), Asset-Referenced Virtual Assets (ARVAs), and other tokens designated by VARA that require regulatory approval before issuance.
4. Do startups need a whitepaper before launching a token in Dubai?
Yes. Non-exempt token issuers must publish a compliant whitepaper and Risk Disclosure Statement before offering or marketing the token to the public.
5. Can a token’s classification change after launch?
Yes. Changes to token features, transferability, or value structure may change its regulatory classification and create new VARA compliance obligations.