New York BitLicense
The New York BitLicense: The Most Rigorous Crypto License in America
The definitive guide to New York’s virtual currency business license — regulatory requirements, real costs, competitive advantages, and strategic pathway.
Last Updated: July 2026 · Regulatory Authority: New York State Department of Financial Services (NYDFS) · Governing Law: 23 NYCRR Part 200 & Part 500
You Need to Understand What the BitLicense Really Is
The BitLicense is not a money transmitter license. It’s not a quick state approval you obtain alongside other licenses. It is the most comprehensive, rigorous, and expensive virtual currency regulatory license in the United States — and one of the most demanding in the world.
Created by Benjamin Lawsky in 2015 following the Mt. Gox collapse, the BitLicense combines custody requirements, cybersecurity standards, capital adequacy expectations, AML/KYC procedures, consumer protection obligations, and operational controls into a single integrated regulatory framework. Obtaining one requires 12–30+ months, costs $500,000–$2,000,000+ in the first year, demands executive-level commitment to compliance, and results in continuous, rigorous NYDFS oversight.
But the BitLicense is also a competitive moat. Companies that hold one — Circle, Coinbase, Robinhood Crypto, BitPay, Bitstamp, and others — enjoy regulatory clarity, banking credibility, institutional trust, and the ability to serve the world’s largest financial center without fear of enforcement action.
This page explains what you’re walking into, what it costs, what NYDFS requires, and why the BitLicense matters.
BitLicense at a Glance
Parameter | Reality |
|---|---|
Regulatory Issuer | New York Department of Financial Services (NYDFS) |
Legal Framework | 23 NYCRR Part 200 (Virtual Currency Business Activities) + 23 NYCRR Part 500 (Cybersecurity) |
Application Method | Filed through NMLS (Company Form MU1 / Individual Form MU2); substantive review by NYDFS |
Application Fee | $5,000 (23 NYCRR §200.5 — not refunded if denied or withdrawn) |
Processing Timeline | 12–30+ months (NYDFS publishes no service standard; completeness drives duration) |
First-Year Cost | $500,000–$2,000,000+ (legal, compliance, tech, staffing, bond) — market estimate, not an NYDFS figure |
Surety Bond / Trust Account | Form and amount set by the Superintendent (§200.9(a)); NYDFS states the general minimum is $500,000 and rises with the business model |
Capital Requirement | Set case-by-case by the Superintendent (§200.8) — NYDFS publishes no fixed figure or sliding scale |
License Expiration | Part 200 sets no fixed term or renewal date — the liecnese continues subject to ongoing compliance, NMLS record maintenance and annual assessment |
Covers | All five enumerated virtual currency business activities (receiving/transmitting, storing, buying/selling, exchanging, controlling/administering/issuing) |
Known Holders | Circle, Coinbase, Robinhood Crypto, Ripple Markets, BitPay, Bitstamp, Anchorage Digital NY, PayPal, and others (NYDFS publishes the full list) |
Why It Matters | Regulatory credibility, banking relationships, competitive moat, institutional trust, federal-state coordination |
What Is the BitLicense? Historical Context and Purpose
Benjamin Lawsky’s Vision (2015)
In July 2014, New York Superintendent of Financial Services Benjamin Lawsky observed the devastation caused by virtual currency platform collapses — most notably Mt. Gox, where customers lost nearly $500 million in Bitcoin due to inadequate security, poor custody practices, and lack of regulatory oversight.
Lawsky proposed a new regulatory framework: a purpose-built license for virtual currency businesses that would address the unique risks of crypto, not force crypto businesses into generic money transmitter licensing.
On June 24, 2015, after an extended regulatory development process involving public hearings, industry feedback, consumer advocate input, and federal regulator coordination, the BitLicense became effective under 23 NYCRR Part 200. It was revolutionary because:
It was the first comprehensive virtual currency license in the US (and influenced global regulation)
It addressed Mt. Gox-style risks with specific custody and security requirements
It separated software from financial intermediation (developers don’t need licenses; custodians do)
It combined regulatory authority — crypto licensing under one regulator, not fragmented across banking and securities divisions
It set global precedent — Singapore’s Payment Services Act, the EU’s MiCA regulation, and other jurisdictions drew directly from NY’s framework
Five Core Purposes of the BitLicense
The BitLicense exists to serve five critical functions:
1. Consumer Protection — Virtual currency platforms fail. BitLicense requires:
Custody standards to prevent asset loss
Capital adequacy to cover customer protection
Segregation of customer funds
Insurance coverage for digital asset losses
Business continuity and disaster recovery procedures
2. Anti-Money Laundering & Know-Your-Customer Compliance — Crypto became a vehicle for financial crime. BitLicense mandates:
Customer identification and verification
Enhanced due diligence for high-risk customers
Transaction monitoring
Suspicious activity reporting to FinCEN
OFAC sanctions screening
3. Cybersecurity Standards — Crypto businesses face sophisticated attacks. 23 NYCRR Part 500 requires:
Chief Information Security Officer oversight
Multi-factor authentication
Encryption (data at rest and in transit)
Penetration testing
Incident response procedures
72-hour breach notification
4. Operational Reliability — NYDFS ensures crypto businesses have:
Adequate management experience
Sound technology infrastructure
Business continuity and disaster recovery
Appropriate compliance staffing
Clear corporate governance
5. Federal-State Coordination — New York established state-level enforcement authority while coordinating with FinCEN, Federal Reserve, OCC, SEC, and CFTC to avoid regulatory gaps and create a cohesive financial services oversight framework.
The Five Enumerated Virtual Currency Business Activities
Under 23 NYCRR §200.2(q), if you engage in ANY of these five activities involving New York residents, you need a BitLicense:
1. Receiving Virtual Currency for Transmission, or Transmitting It
Accepting or moving customer cryptocurrency — whether Bitcoin, Ethereum, stablecoins, or other virtual currency. The regulation carves out transactions undertaken for non-financial purposes that do not involve more than a nominal amount.
Examples:
Cryptocurrency exchange accepting customer deposits
Crypto wallet service receiving funds for deposit
Lending platform accepting crypto collateral
Crypto payment processor receiving funds from customers
2. Storing, Maintaining Custody, or Controlling Virtual Currency
Holding customer cryptocurrency on the customer’s behalf — whether in hot wallets, cold storage, hardware security modules, or other arrangements.
Examples:
Crypto custodian holding digital assets
Exchange maintaining customer account balances
Wallet provider controlling private keys
Custody service provider managing institutional assets
3. Buying and Selling Virtual Currency
Trading virtual currency as principal or agent — whether for customer accounts or proprietary trading.
Examples:
Cryptocurrency exchange facilitating trades
Broker buying/selling crypto
Market maker providing liquidity
Proprietary trading firm
4. Performing Exchange Services
Converting virtual currency to fiat currency or other virtual currencies — the core activity of any exchange.
Examples:
Crypto-to-USD conversion
Bitcoin-to-Ethereum swap
Stablecoin redemption
Exchange desk converting between virtual currencies as a customer business
5. Controlling, Administering, Issuing, or Distributing Virtual Currency
Creating, managing, or distributing virtual currency — whether new coins, tokens, stablecoins, or wrapped tokens.
Examples:
Stablecoin issuer creating USD-backed token
Token sale manager (ICO operator)
Wrapped token manager (e.g., wBTC operator)
Administrator of a centrally issued virtual currency
No catch-all — but note the software carve-out: §200.2(q) lists five activities and no more. It closes with an express exclusion: “The development and dissemination of software in and of itself does not constitute Virtual Currency Business Activity.” NYDFS applies this literally — writing a self-custody wallet is not licensable; operating a wallet service that holds other people’s funds is. The line is custody and intermediation, not code.
Real Costs: $500,000–$2,000,000+ First Year (Not Including Capital)
The BitLicense is expensive. Here’s what applicants actually spend, broken into three realistic scenarios:
One-Time Application & First-Year Costs
Cost Category | Low Estimate | Medium Estimate | High Estimate |
|---|---|---|---|
NYDFS Application Fee | $5,000 | $5,000 | $5,000 |
External Legal Counsel | $150,000 | $300,000 | $500,000+ |
Compliance Program Development | $75,000 | $150,000 | $300,000+ |
Technology & Cybersecurity | $50,000 | $150,000 | $300,000+ |
Audits & Financial Statements | $40,000 | $80,000 | $150,000+ |
Background Investigations | $5,000 | $10,000 | $25,000+ |
Surety Bond or Trust Account | $50,000 | $500,000 | $2,000,000+ |
Custody Infrastructure | $100,000 | $250,000 | $500,000+ |
Insurance (Cyber, E&O) | $30,000 | $75,000 | $150,000+ |
Consulting & Expert Advisors | $25,000 | $75,000 | $150,000+ |
Internal Staffing (CISO, Compliance) | $200,000 | $400,000 | $600,000+ |
Ongoing Compliance Support | $50,000 | $100,000 | $200,000+ |
Miscellaneous | $10,000 | $25,000 | $50,000+ |
TOTAL YEAR 1 | $790,000 | $2,120,000 | $4,930,000+ |
Ongoing Annual Costs (Years 2+)
After approval, expect:
Cost Item | Annual Range |
|---|---|
Compliance Officer Salary | $150,000–$300,000 |
AML/BSA Program Maintenance | $50,000–$100,000 |
Cybersecurity & Penetration Testing | $100,000–$250,000 |
Independent Annual Audits | $40,000–$100,000 |
Insurance | $30,000–$150,000 |
Legal Retainer | $50,000–$150,000 |
Technology Maintenance | $50,000–$200,000 |
SUBTOTAL | $470,000–$1,250,000+ |
NYDFS Annual Assessment (23 NYCRR Part 102) | Varies — billed by NYDFS, see below |
The assessment is the line most budgets miss. In April 2022 the Legislature amended Financial Services Law §206 to direct the Superintendent to assess virtual currency businesses for the cost of their own supervision, and 23 NYCRR Part 102 (adopted April 2023) set the mechanics. Licensees are billed five times per state fiscal year (April 1–March 31): four estimated quarterly bills, then a final true-up against the Virtual Currency Unit’s actual expenses. Your share is driven by a regulatory component split evenly across licensees plus a supervisory component keyed to your custody balances and New York transaction volume. There is no published dollar figure to plan against — NYDFS posts the quarterly calculation charts after each billing. Payment is due 30 days from the billing date, and non-payment draws penalties, interest and regulatory action.
What These Numbers Mean
Low Estimate ($790,000):
Early-stage company with minimal staff
Leveraging existing technology
Single business line
Experienced internal team
No major delays
Medium Estimate ($2,120,000):
Mid-size company with multiple business lines
Building compliance infrastructure from scratch
Hiring dedicated staff
Typical 18–24 month timeline
Standard application review
High Estimate ($4,930,000+):
Large, complex organization
Enterprise-grade infrastructure
Significant management team
Extended review period (24–36 months)
Multiple deficiency letter rounds
Key Insight: Surety Bond and Capital Are NOT All “Costs”
Two of the biggest numbers on any BitLicense budget are the ones NYDFS refuses to publish. Under §200.8, capital is whatever the Superintendent determines is sufficient for your risk profile — there is no published minimum, no sliding scale, and no tangible-net-worth test to plan against. Under §200.9(a), the bond or trust account is likewise “in such form and amount as is acceptable to the superintendent”; NYDFS states the general minimum is $500,000 and that it rises with the business model. Treat any figure above that floor as a negotiation, not a lookup.
Note also what these numbers are not. A bond premium is a real annual expense, but the capital and the funded trust account are not “spent” — they are reserved for customer protection. The opportunity cost of that reserved capital is the number that belongs in your model, and you cannot size it until NYDFS tells you what it expects.
Timeline: 12–30+ Months from Start to Approval
The BitLicense application process is lengthy. Here’s what to expect:
Application Phases
Phase | Duration | Activities |
|---|---|---|
Pre-Application Prep | 3–6 months | Business plan finalization, compliance program drafting, technology assessment, management hiring, capitalization |
Application Drafting | 1–3 months | Assembling components, legal review, financial statements, supporting documentation |
NYDFS Initial Review | 1–2 months | Completeness check, clarification requests |
NYDFS Substantive Review | 6–18 months | Compliance program review, financial adequacy, cybersecurity assessment, background investigations, business plan viability |
Conditional/Final Approval | 1–3 months | Conditions remediation (if conditional approval), final examination, license issuance |
TOTAL TIMELINE | 12–30+ months | Average: 18–24 months |
What Drives the Clock
NYDFS does not publish a processing-time standard, and the phase durations above are practitioner estimates rather than Department commitments — treat them as planning assumptions and verify current expectations with NYDFS directly.
What the Department does say is more useful than any average. NYDFS states that most delays are caused by applications submitted with elements missing, and that it will not begin substantive review until the application is informationally complete — every document submitted, responsive, and adequately organised and detailed. An application that does not contain all items described in the BitLicense Application Checklist “may be delayed indefinitely, and ultimately be denied for insufficiency.”
NYDFS has also stood up an internal program it calls VOLT — Vision, Operations, Leadership, Technology — expressly aimed at addressing delays in regulatory processes across its Virtual Currency unit, while stating it will not sacrifice regulatory rigour to do so.
Pro Tip: Quality preparation during the pre-application phase is the single biggest lever on timeline. Read the Application Checklist before you draft anything. If DFS staff suggest a pre-application call, take it.
Cybersecurity Requirements: 23 NYCRR Part 500
New York’s cybersecurity framework is the most comprehensive in the nation. All BitLicensees must comply with 23 NYCRR Part 500, which requires:
Mandatory Controls
Chief Information Security Officer (CISO)
A qualified CISO must be designated — may be employed by you, an affiliate, or a third-party service provider
Reports in writing at least annually to the board/senior governing body
Annual compliance certification due April 15, signed by both the CISO and the highest-ranking executive
Responsible for overseeing and enforcing the cybersecurity program
Multi-Factor Authentication (MFA)
Since November 1, 2025, required for any user accessing any information system — not just employees, not just systems holding nonpublic information
The regulation does not mandate a specific form; NYDFS guidance favours token-based MFA over push or SMS, and cautions on biometrics given deepfake risk
The CISO may approve reasonably equivalent or more secure compensating controls, reviewed at least annually
Encryption
Nonpublic information encrypted in transit over external networks and at rest
Where encryption is infeasible, CISO-approved compensating controls, reviewed at least annually
Part 500 sets the obligation, not a named cipher — verify your specific configuration expectations with NYDFS rather than assuming a minimum standard
Access Control
Least-privilege principle; privileges limited to those necessary to perform the job
User access privileges reviewed at least annually; disable or remove accounts no longer needed
Privileged access management (PAM) for “Class A” firms
Written procedures for asset inventory of information systems (since November 1, 2025)
Penetration Testing & Vulnerability Assessment
Annual penetration testing from inside and outside system boundaries, by a qualified internal or external party
Automated vulnerability scans, at a frequency set by your risk assessment, plus manual review of systems not covered by scanning
Documented, prioritised remediation of findings
Incident Response Plan
Written procedures for detecting, containing, investigating incidents
72-hour notification to NYDFS after determining a cybersecurity incident has occurred; separately, 24-hour notice of any extortion payment made, with a written explanation within 30 days
Customer notification procedures
Annual testing of incident response and business continuity plans
Business Continuity & Disaster Recovery
Written BCP covering critical functions
Recovery Time Objective (RTO) and Recovery Point Objective (RPO) defined
Annual testing documented
Recent Enhancements (November 2023 Amendment)
NYDFS issued Part 500 Second Amendment requiring enhanced controls for “Class A” companies (large entities):
Class A Enhanced Requirements:
Endpoint Detection and Response (EDR) — mandatory for large firms
Privilege Access Management (PAM) — automated access controls
SIEM or equivalent centralized logging — mandatory 24/7 monitoring
Independent annual cybersecurity audit — in addition to self-certification
Automated password controls — blocking of commonly used passwords
Implementation Timeline:
The Second Amendment was adopted November 1, 2023 and phased in over two years. The 72-hour incident notification itself is not new — it has applied since the original Part 500 took effect in 2017; the amendment added extortion-payment reporting
Class A technical requirements (EDR/SIEM, PAM) and annual penetration testing: May 1, 2025
Final tranche — MFA for all users and asset inventory procedures: November 1, 2025. These are covered by the April 15, 2026 certification for calendar year 2025
BitLicense vs. Limited Purpose Trust Charter (LPTC): Choosing Your Path
New York offers two regulatory pathways for cryptocurrency businesses. Understanding the differences is critical for strategy.
Comparison Table
Factor | BitLicense | Limited Purpose Trust Charter |
|---|---|---|
Issuer | NYDFS (under the Financial Services Law) | NYDFS (chartered under the New York Banking Law) |
Application Fee | $5,000 | $12,500 |
Capital Requirement | Set case-by-case by the Superintendent | Set case-by-case by the Superintendent |
Best For | Exchanges, payment processors, stablecoin issuers, multi-service platforms | Cryptocurrency custodians, institutional asset managers |
Scope | All virtual currency business activities | Virtual currency business activity with Superintendent’s approval, plus trust powers |
Fiduciary Powers | No — §200.3(a) expressly bars BitLicensees from exercising fiduciary powers | Yes — can exercise fiduciary powers |
Money Transmission | Needs a separate NY money transmitter liecnese to transmit fiat | Can engage in money transmission in NY without a separate money transmitter liecnese |
Companies Using | Circle, Coinbase, Robinhood Crypto, Ripple Markets, BitPay, Bitstamp, Anchorage Digital NY | Gemini, Coinbase Custody, BitGo NY, Fireblocks, NYDIG Trust, PayPal Digital |
Advantage | Broader activity scope; lower application fee; serves more business models | Fiduciary powers; no separate MTL needed; institutional credibility |
Disadvantage | No fiduciary powers; separate MTL usually required | Bank-style chartering process and supervision |
When to Choose Each Path
Choose BitLicense if:
You’re operating an exchange, trading platform, or multi-service crypto business
You want regulatory clarity for all virtual currency activities
You plan to grow beyond custody into trading, payment processing, or stablecoin issuance
You accept that you will likely need both the BitLicense and a New York money transmitter liecnese — see below
Choose Limited Purpose Trust Charter if:
You’re building a cryptocurrency custody business focused on institutional assets
You need to exercise fiduciary powers — a BitLicensee cannot
You want to transmit fiat without standing up a separate New York money transmitter liecnese
You can meet bank-style chartering scrutiny and whatever capitalisation the Superintendent sets
The Question Most Applicants Get Wrong: Do You Also Need a Money Transmitter liecnese?
A BitLicense authorises virtual currency business activity involving New York or a New York resident. It does not replace any other liecnese required under New York law — and this catches people.
The moment you transmit fiat currency — US dollars in and out of customer accounts, which is what almost every exchange, on-ramp and payment processor does — you are conducting money transmission under New York Banking Law Article 13-B, and that requires a separate money transmitter liecnese. NYDFS says so plainly in its own BitLicense FAQs. This is why the Department’s regulated-entity list shows so many firms holding “Virtual Currency and Money Transmitter Licenses” as a pair: Coinbase, Circle, Robinhood Crypto, PayPal, Block, eToro NY, MoonPay USA, Bullish, zerohash and others.
Three practical consequences:
Budget for two liecneses, not one. If your model touches fiat, assume the BitLicense is half the New York project.
The trust charter collapses the two. A New York limited purpose trust company can engage in money transmission without a separate money transmitter liecnese. That is a genuine structural advantage, and it is the single most under-weighted factor in the BitLicense-versus-charter decision.
Federal registration changes nothing. Being registered with FinCEN as an MSB has no bearing on whether you need a BitLicense. Neither does holding liecneses in other states.
Note also who is not caught. Under §200.3© only two categories are exempt: entities chartered under the New York Banking Law with the Superintendent’s approval to engage in virtual currency business activity, and merchants and consumers using virtual currency solely to buy or sell goods and services or for investment. That list is exhaustive. There is no exemption for broker-dealers, insurers, charitable organisations, or funds — and per NYDFS, charities are expressly not exempt, though merely accepting donations of virtual currency does not itself require a liecnese. Mining for your own account, writing software, and giving investment advice do not require a liecnese either; custody of someone else’s assets does.
The Conditional BitLicense Program
The Superintendent has always had authority under 23 NYCRR §200.4© to approve an application “by granting a conditional license.” In June 2020 NYDFS published a proposed framework built on that authority and requested public comment. Understand what it actually is before you build a strategy on it.
How It Works
The conditional pathway is not a standard liecnese issued with a punch-list of defects to fix. It is a collaboration model:
The applicant identifies an authorised VC Entity — an existing BitLicensee or New York limited purpose trust company — to work with
The applicant contacts NYDFS and submits a draft service level agreement with that VC Entity. Signing an SLA is not, by itself, sufficient for NYDFS to grant anything
The applicant submits the documents and information the VC Regulation requires for its business and risk profile
Once NYDFS finds the submission informationally complete, substantive review begins
NYDFS and the applicant enter a supervisory agreement setting out permitted activities, requirements, and how responsibilities and liabilities are divided with the VC Entity
If approved, NYDFS issues a Conditional License. The holder may then engage in virtual currency business activity as approved
What the Framework Actually Requires
A working relationship with an authorised VC Entity for structure, capital, systems, personnel or other support
A supervisory agreement with NYDFS — the conditions are negotiated into that document, not issued as a generic checklist
Acceptance of heightened review, in scope and frequency of examination or otherwise, under §200.4©
An expectation that you will eventually seek and obtain a full BitLicense
Read the Fine Print
Two cautions matter more than anything else on this page. First, NYDFS stated plainly that it may at any time discontinue the conditional licensing approach — this is a discretionary accommodation, not an entitlement. Second, the Superintendent can suspend or revoke a Conditional License and impose “any reasonable condition” on its holder.
NYDFS does not publish a roster of conditional licensees, and public reporting on which firms hold or held one is unreliable. The Department’s own records do note that PayPal, Inc. was granted a conditional virtual currency liecnese in October 2020. Do not assume a given exchange’s liecnese is conditional because a secondary source says so — check the Department’s regulated-entity list, which shows liecnese type and grant date.
Who Holds a BitLicense? The Current Holders
The most prominent BitLicense holders include:
Exchanges & Trading Platforms
Coinbase, Inc. — Major cryptocurrency exchange serving retail and institutional customers; holds both a virtual currency liecnese and a money transmitter liecnese (granted January 2017); arguably the highest-profile holder due to its NASDAQ listing
Bitstamp USA, Inc. — Longtime bitcoin trading platform; virtual currency liecnese granted April 2019
Note on Kraken: Kraken does not hold a BitLicense and does not appear on the NYDFS regulated-entity list. It publicly declined the regime and does not serve New York under one. Several secondary sources wrongly list it as a conditional holder — it is not one. This matters if you are benchmarking competitors.
Payment & Processing
Bitpay, Inc. — Cryptocurrency payment processor; virtual currency liecnese granted July 2018; enables merchants to accept crypto
Ripple Markets DE LLC (f/k/a XRP II LLC) — Virtual currency liecnese granted June 2016, among the earliest issued
Crypto Services
Circle Internet Financial, LLC — Payments platform and USDC issuer; holds virtual currency and money transmitter liecneses, granted September 2015 — one of the first BitLicenses ever issued, years before any conditional pathway existed
Robinhood Crypto, LLC — Crypto trading subsidiary of Robinhood Markets; virtual currency and money transmitter liecneses, granted January 2019
Anchorage Digital NY, LLC — Institutional platform; granted a virtual currency liecnese in December 2024 (not a trust charter — its federally chartered bank affiliate is a separate entity)
PayPal, Inc. — Granted a conditional virtual currency liecnese in October 2020; held a money transmitter liecnese since October 2013
Alternative Pathway (Limited Purpose Trust Charter, Not BitLicense)
Gemini Trust Company, LLC — Crypto custodian (Winklevoss twins); LPTC granted October 2015
Coinbase Custody Trust Company, LLC — Institutional custody; LPTC granted October 2018
BitGo New York Trust Company, LLC — Institutional custody; LPTC granted March 2021
Fireblocks Trust Company, LLC — LPTC granted August 2024
PayPal Digital, Inc. — LPTC granted May 2024
Note on Paxos: Paxos Trust Company held a New York LPTC from 2015 and issued the first DFS-approved stablecoin, but it converted to an OCC national trust charter in December 2025 and no longer appears on the NYDFS list. Pages that still cite Paxos as a New York LPTC are out of date.
Why the distinction? Custody-focused firms often choose the LPTC because it is designed for trust companies, permits fiduciary powers a BitLicensee cannot exercise, allows money transmission without a separate MTL, and carries strong institutional credibility. Multi-service platforms (exchanges, payment processors) choose the BitLicense because it maps to their activity set at a lower application fee.
Why the BitLicense Is a Competitive Moat
Despite its cost and complexity, obtaining a BitLicense creates significant competitive advantages:
1. Regulatory Clarity and Certainty
Once you hold a BitLicense, you have explicit regulatory authority to operate in New York. Competitors without licenses face uncertain enforcement risk. You can serve New York residents without fear of cease-and-desist orders or license denial.
2. Banking Credibility
Counterintuitively, BitLicense holders find banking relationships EASIER than unlicensed competitors:
Banks view BitLicense as evidence of rigorous regulatory vetting
NYDFS approval signals compliance competence
Banks reduce their own compliance burden (lower due diligence on BitLicensee)
Correspondent banking relationships become more accessible
De-banking risk is reduced
Without a BitLicense, many banks refuse to serve crypto businesses entirely.
3. Institutional & Investor Trust
Institutional investors, hedge funds, and corporate customers prioritize BitLicense holders:
Insurance companies, pension funds, endowments trust regulated platforms
Institutional custody requirements often mandate BitLicense or equivalent
Venture capital investors prefer BitLicense holders (regulatory risk mitigation)
Corporate partnerships require regulated counterparties
4. Global Regulatory Precedent
BitLicense status carries weight internationally:
Singapore, EU, and other jurisdictions view BitLicense as gold standard
International partnerships and integrations favor BitLicense holders
Institutional customers worldwide trust BitLicense-regulated entities
BitLicense is model regulation cited by FATF and other bodies
5. High Barriers to Entry for Competitors
The cost and timeline of BitLicense ($500K–$2M+, 18–24 months) mean:
Few startups can justify the expense
Venture-backed companies must commit capital early
Competitive field is limited to well-capitalized firms
Existing BitLicense holders enjoy protected market position
6. Premium Valuation Multiple
BitLicense holders command higher valuations:
Investors value regulatory clarity
BitLicense reduces regulatory risk premium
Acquisition targets with BitLicense valued higher
Initial public offering prospects improved with BitLicense
Stablecoin Guidance: Additional Requirements
On June 8, 2022, NYDFS issued guidance on the issuance of U.S. dollar-backed stablecoins. Note the scope carefully: it applies to BitLicensees and New York limited purpose trust companies, but only to stablecoins backed by the U.S. dollar and only to those issued under DFS supervision. It requires:
Regulatory Pre-Approval
Before issuing any stablecoin, obtain written NYDFS approval
Application must describe stablecoin mechanics, redemption processes, reserve backing
100% Reserve Requirement
Market value of the reserve must at least equal the nominal value of all outstanding units as of the end of each business day
Reserve assets must be segregated from the issuer’s proprietary assets and held with FDIC-insured US depository institutions and/or DFS-approved custodians
The permitted asset list is exhaustive: US Treasury bills acquired three months or less from maturity; overnight reverse repos fully collateralised by US Treasuries; government money-market funds; and deposit accounts at US chartered depository institutions — each subject to DFS-approved caps and restrictions
Monthly Attestations
The reserve must be examined at least once per month by an independent US-licensed CPA applying AICPA attestation standards, with the CPA and engagement letter approved by DFS in advance
Plus an annual attestation on the effectiveness of internal controls
Monthly reports must be made public and produced to DFS within 30 days of period end; the annual report within 120 days
Redemption
Holders must have a right to redeem at par (1:1 for USD, net of well-disclosed fees) under DFS-approved policies
Default timing is T+2 — not more than two full business days after a compliant redemption order
This guidance has effectively made many innovative stablecoin designs (overcollateralized, partially backed, algorithmic) non-compliant with New York regulation.
Coin Listing: The Greenlist and Self-Certification
Holding a BitLicense does not mean you can list whatever you like. A licensee may only offer or use coins that fall into one of three buckets, and getting this wrong is a material-change violation.
The Three Paths to Listing a Coin
1. Specific DFS approval — apply to the Department for approval of a material change of business covering that coin.
2. Self-certification — submit a coin-listing policy to DFS. Once DFS approves the policy, you may self-certify coins against it by filing a self-certification form through the DFS Portal. The current framework comes from guidance DFS issued in November 2023, which replaced its September 2023 proposal.
3. The Greenlist — coins DFS has pre-cleared. Any entity licensed or chartered by DFS for virtual currency business activity may list a Greenlist coin without having its own DFS-approved coin-listing policy. You must notify DFS at least ten days before offering the coin in New York.
What Is Actually on the Greenlist
The Greenlist is short. As published by DFS it comprises Bitcoin (BTC) and Ethereum (ETH), plus a set of stablecoins approved for issuance in New York by DFS-regulated entities: Gemini Dollar (GUSD), GMO JPY (GYEN), GMO USD (ZUSD), Ripple USD (RLUSD), WisdomTree Dollar (USDW) and WisdomTree Gold (GOLD).
If your business plan assumes a broad token menu on day one, reset that assumption now. The Greenlist is a starting point for majors and DFS-approved stablecoins, not a substitute for a listing policy.
The Discretion Clause Everyone Skips
DFS reserves the right, at any time and in its sole discretion, to prohibit or limit a coin’s use before or after you begin using it, to require you to delist or halt activity in any coin, to remove any coin from the Greenlist, to decline to add one — and to discontinue the Greenlist process entirely. Build your listing roadmap with that in mind. DFS has also signalled its posture on newer asset classes: in January 2025 it issued a notice on rapidly proliferating, sentiment-based virtual currencies.
Cybersecurity Incident Reporting: 72-Hour Requirement
If a BitLicensee experiences a cybersecurity incident (breach, hacking, ransomware, data loss), NYDFS must be notified within 72 hours of determining an incident occurred.
Notification Must Include
Nature and scope of incident
Data or systems affected
Customer/asset impact assessment
Preliminary root cause analysis
Remediation steps taken or planned
Any ransom demands or extortion attempts
Status of law enforcement notification
Consequences of Non-Compliance
Failure to report within 72 hours can result in:
Civil penalties under Financial Services Law §408 — up to $5,000 per offense for intentional fraud or intentional misrepresentation of a material fact, and up to $1,000 for any other violation of the chapter or its regulations
Corrective action plan
Consent orders
License suspension or revocation in severe cases
Do not read the statutory per-violation figures as a cap on exposure. Penalties are assessed per offense, and NYDFS’s crypto settlements have run to eight figures once conduct is aggregated across a period. The enforcement risk is the multiplier, not the unit price.
This requirement reflects NYDFS’s position that transparency and rapid notification are critical to consumer protection.
AML/KYC Compliance: Federal Framework + NY Enhancements
BitLicensees must comply with the full federal BSA/AML framework (FinCEN) PLUS additional New York requirements:
Federal Requirements (FinCEN)
Customer Identification Program (CIP)
Know Your Customer (KYC) procedures
Enhanced Due Diligence (EDD) for high-risk customers
Suspicious Activity Reporting (SAR) — the MSB threshold is $2,000 (31 CFR 1022.320), not $5,000. $5,000 is the bank threshold, and confusing the two is one of the most common and most expensive errors in crypto compliance build-outs. A BitLicensee operating as a federally registered MSB calibrates to $2,000. New York does not set its own SAR threshold
Currency Transaction Reporting (CTR) for cash over $10,000
OFAC sanctions screening
Transaction monitoring
New York Enhancements
BitLicensees must maintain a dedicated Compliance Officer
Annual BSA/AML program audit required
Written AML/KYC policies and procedures
Staff training program (annual refresher)
Customer risk categorization procedures
Source of funds/wealth verification for customers
Beneficial ownership identification for corporate customers
Material change reporting to NYDFS
The Application Process: What NYDFS Actually Wants
BitLicense applications require extensive documentation across multiple categories:
Corporate & Governance Documentation
Articles of incorporation/organization
Bylaws and board resolutions
Organizational chart
Beneficial ownership documentation
Affiliate disclosures
Management & Personnel
Curriculum vitae for all officers/directors
Individual History Questionnaires (detailed background forms)
FBI fingerprinting for all principals
Credit checks and criminal history review
5+ year employment history for key personnel
Compliance Program
Written BSA/AML program (comprehensive)
Customer Identification Program (CIP)
Know Your Customer (KYC) procedures
Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD)
Suspicious Activity Reporting (SAR) procedures
OFAC screening procedures
Transaction monitoring procedures
Complaint handling procedures
Annual training program outline
Cybersecurity Program
Comprehensive written cybersecurity policy
CISO job description and hiring plan
Penetration testing procedures
Incident response plan
Business continuity and disaster recovery plan
Data classification and handling procedures
Financial Documentation
Audited financial statements (2 years if entity has history; pro forma if startup)
Proof of capital — the amount is determined by the Superintendent under §200.8 against your specific risk profile, and must be held in cash, virtual currency, or high-quality, highly liquid, investment-grade assets in proportions acceptable to the Superintendent
3-year tax returns (personal and business)
Cash flow projections
Business plan and financial projections (3–5 years)
Operational & Technology
Detailed business plan
Description of each product/service offered
Technology stack documentation
System architecture diagrams
Custody procedures and infrastructure
Customer fund segregation procedures
Insurance documentation
Customer Protection
Terms of Service and Customer Agreement
Privacy policy
Fee schedule
Risk disclosure materials
Customer complaint procedures
Advertising/marketing materials
The application typically spans 200+ pages of exhibits and documentation. Hiring specialized BitLicense counsel is virtually essential.
After Approval: Ongoing Obligations
Obtaining a BitLicense is step one. Maintaining it requires continuous compliance:
Annual Obligations
Quarterly Financial Statements — Due within 45 days of the close of the fiscal quarter (§200.14(a))
Statement of financial condition: balance sheet, income statement, statement of comprehensive income, changes in ownership equity, cash flow, net liquid assets
A statement demonstrating compliance with the Part’s financial requirements
Financial projections and strategic business plans, off-balance-sheet items, chart of accounts, and a report of permissible investments
Annual Audited Financials — §200.14(b)
Auditor’s opinion and an attestation on the effectiveness of your internal control structure
Management’s statement of responsibility, management’s assessment of compliance during the year, and officer/director certification of the statements
Part 200 does not fix a filing deadline in the text — confirm your date with NYDFS rather than assuming 90 days
Annual Compliance Report — Confirm scope and timing with NYDFS
Part 200 does not itself prescribe a 120-day compliance report; your obligations are driven by §200.14, §200.15 and your supervisory agreement
Do not calendar a deadline off a template — get it from the Department
Cybersecurity Certification — Due April 15 annually (Part 500)
Certification of material compliance with Part 500, signed by both the highest-ranking executive and the CISO
Or a written acknowledgement of non-compliance identifying the gaps and a remediation timeline
NMLS Record Maintenance
The BitLicense is applied for and managed through NMLS; keep the company record, contacts and control-person information current
Note that this is record maintenance and annual assessment, not a term renewal — Part 200 sets no expiry date
Continuous Obligations
Suspicious Activity Reporting (SAR)
File within 30 days of detecting suspicious activity (federal: 30 days; NY oversight)
Examples: structuring (intentionally breaking up transactions), matching customer to sanctions list, high-risk transaction patterns
Material Change — Prior Written Approval, Not Notice
§200.10 requires NYDFS’s written approval before you introduce a materially new product, service or activity, or materially change an existing one. This is a permission, not a notification — treat it as a gating item in any product roadmap. Change of control and mergers are governed separately by §200.11
Matters to raise with NYDFS include:
Ownership/control changes
Officer/director changes
New business lines or products
Technology changes
Merger, acquisition, or significant corporate event
Relocation or facility changes
Cybersecurity Incident Reporting
Report within 72 hours of determining cybersecurity incident occurred
Includes breaches, hacks, ransomware, unauthorized access, data loss
Record Retention
Maintain books and records in original form or native file format for at least seven years from creation (§200.12(a))
Records of non-completed, outstanding or inactive accounts: at least five years after the virtual currency is deemed abandoned property
Customer identification records, risk assessment documentation, AML/KYC files
NYDFS must be given immediate access on request to facilities, books and records — including those of affiliates, wherever located
NYDFS Examinations
The Department conducts regular examinations of BitLicensees:
Examination Frequency: §200.13(a) requires you to permit and assist examination whenever the Superintendent judges it necessary or advisable, but not less than once every two calendar years. That is a floor, not a cap — and the Superintendent may examine your books at any time, and may examine an affiliate. Licensees also bear the cost of their supervision through the Part 102 annual assessment.
Examination Scope:
Financial statements and capital adequacy
Transaction records and processing controls
AML/KYC program effectiveness and SAR filing history
Customer complaint handling
Technology security and data protection
Cybersecurity controls and incident response
Custody and asset protection procedures
Examination Findings:
NYDFS may issue examination findings
Applicants provide written responses
Corrective action plans required for significant findings
Failure to remediate can trigger enforcement action
Stablecoin Issuance: Special Framework
BitLicensees issuing stablecoins face additional requirements:
Pre-Issuance Approval Required
Before issuing any stablecoin, obtain written NYDFS approval. Application must address:
Stablecoin description and mechanics
Redemption process and terms
Collateral/reserve backing
Insurance coverage
Custody procedures
Stabilization mechanisms (if any)
Reserve Requirements
100% Reserve Backing
One stablecoin unit = one unit of backing, measured at market value at the end of each business day
Backing may consist only of:
US Treasury bills acquired three months or less from maturity
Overnight reverse repurchase agreements fully collateralised by US Treasuries
Government money-market funds, subject to DFS-approved caps
Deposit accounts at US state or federally chartered depository institutions, subject to DFS-approved restrictions
Prohibited Collateral:
Because the permitted list above is exhaustive, everything else is out — including equities and corporate securities, crypto or digital assets, illiquid investments, junk bonds and other speculative assets, and derivative instruments.
Monthly Attestations
Monthly examination of management’s assertions by an independent CPA licensed in the US, applying AICPA attestation standards
The CPA and the engagement letter must be approved by DFS in advance
Reports made available to the public and produced to DFS within 30 days of period end
A separate annual attestation on internal controls, produced to DFS within 120 days
Consumer Disclosures
Clear disclosure that stablecoin is not insured
Risk disclosures (regulatory, technical, operational risks)
Description of redemption process and timeline
Fee disclosures
This framework has effectively prevented most innovative stablecoin designs (algorithmically stabilized, partially backed, crypto-collateralized) from operating in New York.
Why BitLicense Holders Beat the Competition (Even Though It’s Expensive)
Despite the cost and complexity, BitLicense holders enjoy durable competitive advantages:
1. Regulatory Risk Eliminated
Competitors without BitLicense face perpetual enforcement uncertainty. NYDFS could issue cease-and-desist orders at any time. BitLicense holders have explicit regulatory authority.
2. Banking Relationships Enabled
Counterintuitive but true: BitLicense holders have easier access to banking than competitors. Banks view BitLicense as regulatory vetting, reducing their own compliance burden. De-banking risk is lower.
3. Institutional & Enterprise Customers
Institutional investors, corporations, and wealth managers require BitLicense or equivalent from crypto service providers. Large customer contracts depend on it.
4. Capital-Light Competitive Moat
The high cost of BitLicense ($500K–$2M+ startup cost) means few competitors can enter the market. Existing holders enjoy protected market position.
5. Valuation Premium
BitLicense holders command higher acquisition valuations and IPO multiples because regulatory risk is removed. Exit multiples increase.
6. Global Regulatory Credibility
BitLicense status is recognized worldwide. International partnerships, institutional relationships, and regulatory cooperation improve with BitLicense.
7. Ability to Innovate Within Regulatory Framework
Once licensed, BitLicense holders can evolve their business model while remaining compliant. They know NYDFS’s expectations. Unlicensed competitors face constant uncertainty.
Download the Complete BitLicense Guide
This page covers the essentials of New York virtual currency licensing. The complete guide goes deeper — 2,000+ lines covering every section of the licensing process, from regulatory history to AML program architecture to examination preparation to strategic pathways.
Get Expert Guidance on Your BitLicense Application
Faisal Khan LLC is a cross-border payments and licensing consultancy specializing in virtual currency business licensing. We help crypto exchanges, custodians, payment processors, stablecoin issuers, and DeFi platforms navigate BitLicense applications, multistate licensing strategy, and regulatory compliance.
If you’re considering a BitLicense application — or you’re building a regulatory strategy for national/international crypto operations — get in touch for a confidential consultation.
© 2026 Faisal Khan LLC. All rights reserved. This page is for informational purposes only and does not constitute legal, financial, or regulatory advice. Cryptocurrency regulation is actively evolving — always verify current requirements directly with NYDFS. See our full disclaimer for details.
← See all US money transmitter license guides (all 50 states, DC & US territories)
