If you are planning to launch a token in Dubai, one of the first practical documents you need to think about is the whitepaper.

But under the VARA framework, a whitepaper is not just a marketing deck, a token explainer, or a product brochure.

It is a regulated disclosure document.

That distinction matters because many founders still approach token launches with the wrong assumption:

  • “We’ll write a whitepaper later.”
  • “We already have a litepaper, so that should be enough.”
  • “The whitepaper is mostly for users and community.”
  • “The legal work is separate from the token paper.”

Under VARA, that is the wrong sequence.

The current VA Issuance Rulebook says that all entities in the Emirate issuing a Virtual Asset must comply with Part III and publish both a Whitepaper and a Risk Disclosure Statement. The only exception is for Exempt VAs, whose issuers do not need to publish a whitepaper or risk disclosure statement for those Exempt VAs.

That means for most token issuers in Dubai, the whitepaper is not optional. It is a core regulatory requirement.

This guide explains:

  • when a whitepaper is required under VARA,
  • what the whitepaper must contain,
  • how it differs from a marketing document,
  • what extra disclosures FRVA and ARVA issuers must add,
  • how the whitepaper fits with the wider token issuance framework,
  • and what token issuers should prepare before filing or launching.

1) The first rule: most token issuers in Dubai need a whitepaper

The starting point is straightforward.

Part III of the VA Issuance Rulebook states that all entities in the Emirate issuing a Virtual Asset must publish both a Whitepaper and a Risk Disclosure Statement. The same provision says the only exception is for issuers of Exempt VAs, who do not need to publish those documents in respect of the exempt token itself.

That means the right founder question is not:

“Should we prepare a whitepaper?”

It is:

“Are we issuing a token that is not an Exempt VA?”

If the answer is yes, then a whitepaper requirement is likely already in play.

This is one reason token issuance in Dubai should not be treated like a pure commercial launch. Under VARA, token issuance sits within a formal disclosure framework. The whitepaper is one of the main ways that framework becomes visible.

2) Why the whitepaper matters so much under VARA

A lot of token founders think the whitepaper is mainly about:

  • product storytelling,
  • community building,
  • tokenomics marketing,
  • or explaining why the token matters.

Those things may appear in a whitepaper, but under VARA that is not its primary function.

The whitepaper is part of the regulated issuance architecture. The VA Issuance Rulebook places whitepapers in Part III – Whitepapers and Public Disclosures, and the rulebook also gives VARA supervision, examination, and enforcement powers in relation to issuers and virtual assets.

That means the whitepaper is meant to help:

  • token holders,
  • distributors,
  • and the regulator

understand what is being issued, how it works, and what risks attach to it.

So if your team still thinks of the whitepaper as “basically a narrative PDF,” that is usually the first mistake. Under VARA, it is part of the compliance and disclosure package around issuance.

3) The whitepaper requirement sits inside a bigger issuance framework

To understand the whitepaper properly, you also need to understand where it sits in the broader issuance regime.

The current VA Issuance Rulebook categorizes issuances in the Emirate as:

That categorization matters because:

  • Category 1 includes FRVAs and ARVAs and requires a VARA Licence,
  • Category 2 does not require a VARA licence or prior approval if all placement and distribution is done by or through a Licensed Distributor,
  • Exempt VAs can be issued without prior approval, but the issuer remains subject to the general rulebook and supervision.

The whitepaper obligation then sits on top of that structure:

  • for most issued VAs, the whitepaper is required,
  • for Exempt VAs, it is not.

So the practical sequence is:

  1. classify the token,
  2. identify the issuance pathway,
  3. then prepare the required whitepaper and risk disclosure if applicable.

That is why the whitepaper should be drafted as part of regulatory planning, not as a late-stage communications exercise.

4) What VARA says a whitepaper must be

The VA Issuance Rulebook states that, before issuing a Virtual Asset, entities in the Emirate issuing a Virtual Asset shall provide the relevant disclosures set out in Schedule 1 – VA Whitepaper Requirements in a machine-readable format and make that whitepaper publicly available. The rulebook also states that the whitepaper must be kept available for at least ten years from the date the Virtual Asset ceases to be in circulation.

That already gives you several practical requirements:

The whitepaper must be prepared before issuance

It is not something to fix after launch.

The whitepaper must include the relevant disclosures in Schedule 1

So the content is not left entirely to issuer preference.

The whitepaper must be publicly available

This is not meant to be an internal-only document.

The whitepaper must be retained for a long period

Ten years after the token ceases to circulate is a significant recordkeeping horizon.

This is one of the clearest indications that VARA treats the whitepaper as a durable disclosure record, not merely as launch collateral.

5) The whitepaper is separate from the risk disclosure statement

Another important point is that the whitepaper is not the same thing as the Risk Disclosure Statement.

Part III of the VA Issuance Rulebook requires both documents. The risk-disclosure page says issuers must publish a statement that includes a detailed description of all material risks related to the virtual assets being issued, in a machine-readable format, and that it must be written in a concise, clear, non-technical, and comprehensible manner. The risk disclosure must also be made available in the same easily accessible location as, but remain separate from, the whitepaper.

This matters because many teams try to solve risk disclosure by inserting a few disclaimer pages into the whitepaper itself.

Under VARA, that is not enough.

The framework contemplates:

  • a Whitepaper
    and
  • a separate Risk Disclosure Statement.

So a proper issuer-preparation checklist should always include both.

6) What the whitepaper must help the reader understand

Even where every line of Schedule 1 is not reproduced in public snippets, the structure of the rulebook makes the whitepaper’s purpose clear.

It is meant to provide the disclosures relevant to the token being issued before issuance. The fact that VARA also requires a separate risk-disclosure statement suggests the whitepaper itself should help a reader understand:

  • what the token is,
  • who is issuing it,
  • how it works,
  • what rights or references it involves,
  • how it is used or distributed,
  • and how the issuance fits into the broader product and business model.

In practical drafting terms, a strong VARA whitepaper should usually make it easy to understand:

  • the issuer,
  • the token category,
  • the mechanics of issuance,
  • the utility or reference model,
  • the tokenomics or circulation logic where relevant,
  • governance or control around the token,
  • and the material facts a holder or participant would need to assess the token responsibly.

This is another reason not to draft it as hype material. If a whitepaper is flashy but unclear, it may be a poor marketing document and a poor regulatory document at the same time.

7) Category 1 issuers have extra whitepaper obligations

This is one of the most important practical points for stablecoin-style and asset-referenced token projects.

Both:

  • Annex 1: Fiat-Referenced Virtual Assets Issuance Rules
  • Annex 2: Asset-Referenced Virtual Assets Issuance Rules

contain a section titled Additional Whitepaper Disclosures.

That means FRVA and ARVA issuers are not expected to stop at the general whitepaper requirements in Part III / Schedule 1 of the VA Issuance Rulebook.

They must also include category-specific additional disclosures.

This is a major distinction between:

  • a lighter non-Category-1 issuance, and
  • a stablecoin-style or asset-referenced issuance.

If your token is an FRVA or ARVA, the whitepaper burden becomes heavier because the regulator expects the disclosure document to address the specific risks and structure of that class.

So when people ask about “VARA stablecoin whitepaper requirements,” the right answer is:

  • the general whitepaper rules still apply,
  • but FRVA and ARVA issuers must also satisfy additional whitepaper disclosure requirements under their annexes.

8) What FRVA whitepapers need to address

The FRVA annex helps show what VARA is worried about in fiat-referenced tokens.

The FRVA rules include additional whitepaper disclosures as well as:

  • stable backing,
  • reserve assets,
  • redemptions,
  • audits and reporting.

That means an FRVA whitepaper should not just explain:

  • the peg,
  • and the token’s market use.

It should also be built to support a reader’s understanding of:

  • how the fiat reference works,
  • what backs the token,
  • how reserves are maintained,
  • what redemption rights exist,
  • and what ongoing assurance or reporting framework surrounds the product.

This is especially important because the FRVA ongoing-disclosure rule requires licensed issuers to disclose at least monthly whether the FRVA is at least 100% backed by Reserve Assets, including:

  • the number and value of FRVAs in circulation,
  • and the value and composition of reserve assets,
    as independently audited.

So the whitepaper for an FRVA is not just a launch document. It is part of a broader transparency architecture around backing and confidence.

9) What ARVA whitepapers need to address

The ARVA annex reveals a similar but distinct logic.

The ARVA rules include additional whitepaper disclosures as well as:

  • value of an ARVA,
  • direct right of ownership,
  • reserve assets,
  • redemptions,
  • audits and reporting.

This tells you that an ARVA whitepaper needs to help explain more than token utility. It should support understanding of:

  • the type and composition of reference assets,
  • whether the reference asset may change,
  • how value is determined,
  • whether holders have direct rights in relation to the underlying assets,
  • how reserves or backing are handled,
  • and what redemption mechanics apply.

That is a very different disclosure challenge from an ordinary utility-token pitch.

In practical terms, ARVA whitepapers need to read more like structured regulated-product disclosures than community launch narratives.

10) Whitepaper compliance also matters for Licensed Distributors

Another practical point is that whitepaper compliance is not only an issuer concern.

Where a Category 2 issuance is distributed through or by a Licensed Distributor, the rulebook says the Licensed Distributor is responsible for validating, among other things:

  • that the Virtual Asset complies with the distributor’s VA Standards,
  • that the Whitepaper complies with Part III.B of the VA Issuance Rulebook,
  • that the Risk Disclosure Statement complies with Part III.C,
  • and that investor-classification requirements under Part IV of the Market Conduct Rulebook are satisfied.

This is a very important practical insight.

It means even where the issuer itself is not following the Category 1 licensing route, the whitepaper still has to be good enough to satisfy a regulated distributor that must validate it.

So a weak whitepaper can still block or slow a token launch because the distributor cannot responsibly validate it under the rulebook framework.

That is one more reason whitepaper drafting should not be left until the last moment.

11) The whitepaper must stay current and supported by ongoing disclosures

VARA’s framework is not only about the moment of issuance.

The FRVA and ARVA annexes both include Additional Ongoing Disclosures.

That means the whitepaper should not be drafted as if it exists in a vacuum. It should fit into a broader lifecycle of public disclosure.

For example:

  • FRVA issuers must make monthly website disclosures about circulation and reserve composition, with independent audit linkage.
  • ARVA issuers are also subject to additional ongoing disclosures under their annex.

This means token issuers should prepare not just:

  • a launch whitepaper,
    but
  • a disclosure framework that can continue supporting public transparency after launch.

A whitepaper that cannot be maintained or aligned with later public disclosure usually reflects a token design or governance model that is not mature enough yet.

12) Common whitepaper mistakes under VARA

A lot of the mistakes token issuers make are predictable.

Treating the whitepaper like marketing collateral

Under VARA, it is a disclosure document.

Assuming one generic whitepaper fits all token types

FRVAs and ARVAs have additional whitepaper requirements.

Folding risk disclosure into the whitepaper and stopping there

VARA requires a separate Risk Disclosure Statement.

Drafting the whitepaper before classifying the token

Category 1, Category 2, and Exempt VAs follow different pathways.

Ignoring the broader issuance context

For stablecoin-style or asset-referenced tokens, the whitepaper sits within a more robust reserve, redemption, audit, and disclosure framework.

Leaving the document too late

Because issuers must publish the whitepaper before issuance, leaving it as a late-stage branding task is risky.

The strongest issuers treat the whitepaper as a core regulatory deliverable from the beginning.

13) What token issuers should prepare before drafting

Before drafting the whitepaper itself, a serious issuer should be able to answer these questions:

  • What category is the token under VARA: Category 1, Category 2, or Exempt VA?
  • If Category 1, is it an FRVA or ARVA?
  • What rights, references, reserve logic, or redemption features attach to the token?
  • What separate Risk Disclosure Statement will accompany it?
  • If Category 2, which Licensed Distributor will validate and distribute it?
  • What ongoing public disclosure obligations will follow launch?

If those questions are still unresolved, the whitepaper drafting process is probably starting too early — or at least too blindly.

Final takeaway

If you want the clearest practical answer to:
“What must token issuers prepare for VARA whitepaper compliance?”

it is this:

Under VARA, most token issuers in Dubai must publish a Whitepaper and a separate Risk Disclosure Statement before issuance, unless the token is an Exempt VA. The whitepaper must include the relevant disclosures under the VA Issuance Rulebook, be publicly available in machine-readable form, and remain available for a long retention period. For FRVAs and ARVAs, the burden is heavier because the relevant annexes impose additional whitepaper disclosures and sit inside a broader framework covering reserves, redemptions, audits, and ongoing disclosure.

So the right founder question is not:

“Do we have a token paper?”

It is:

“Do we have a VARA-ready whitepaper and risk disclosure package that matches the token’s true category and disclosure obligations?”

How CRYPTOVERSE Legal Can Help

At CRYPTOVERSE Legal Consultancy, we help founders, token issuers, exchanges, and digital asset businesses prepare VARA-ready whitepapers and risk disclosure statements that align with the token’s correct regulatory category, distribution pathway, and ongoing disclosure obligations. We support token classification, whitepaper and risk-disclosure review, FRVA and ARVA disclosure analysis, Licensed Distributor coordination, and broader VARA token-issuance strategy.

CTA: If you want tailored guidance on VARA whitepaper requirements and what your token project must prepare before launch in Dubai, contact CRYPTOVERSE Legal Consultancy to discuss your regulatory strategy.

FAQs

1. Is a whitepaper mandatory for token issuers under VARA?

Yes. Under VARA’s VA Issuance Rulebook, entities issuing a Virtual Asset in the Emirate generally must publish a Whitepaper and a separate Risk Disclosure Statement. The main exception is for Exempt VAs.

2. When must a VARA whitepaper be published?

The whitepaper must be provided and made publicly available before the Virtual Asset is issued. It must also be maintained in a machine-readable format and retained for the required period.

3. Is the VARA whitepaper the same as a Risk Disclosure Statement?

No. VARA treats them as separate documents. The Whitepaper contains the required token and issuance disclosures, while the Risk Disclosure Statement must separately explain all material risks in a clear, concise, non-technical, and comprehensible manner.

4. Do FRVA and ARVA issuers have additional whitepaper requirements?

Yes. Fiat-Referenced Virtual Asset (FRVA) and Asset-Referenced Virtual Asset (ARVA) issuers must comply with the general whitepaper requirements and provide additional disclosures in their respective VARA annexes.

5. What should a token issuer prepare before drafting its whitepaper?

An issuer should first determine the token’s VARA classification, including whether it is a Category 1, Category 2, or Exempt VA. The issuer should also identify applicable rights, reserves, redemption arrangements, distribution structure, risk disclosures, and ongoing disclosure obligations.