Firms tend to approach the BitLicense as a form. Long, demanding, expensive — but fundamentally a document to be completed and submitted.
NYDFS approaches it as an examination. The application is the vehicle; what is being assessed is whether a functioning compliance, cybersecurity, and custody program already exists inside your business. Firms that build the program in order to answer the questions do considerably better than firms that answer the questions and promise to build the program.
The framework sits at 23 NYCRR Part 200, effective June 2015 and supplemented since by substantial NYDFS guidance on custody, coin listing, stablecoin issuance, and the use of blockchain analytics.
Who needs one
Virtual currency business activity involving New York or a New York resident generally triggers the requirement. That covers receiving or transmitting virtual currency, storing or controlling it on behalf of others, buying and selling as a customer business, exchanging virtual currency, and issuing or administering it.
Two exclusions matter: merchants using virtual currency solely to buy or sell goods and services for their own account, and entities chartered under New York Banking Law.
The territorial reach catches people out. "Involving New York or a New York resident" is broad. A firm with no New York office, no New York entity, and no intention of targeting the state can still fall inside the perimeter through its customer base. Geofencing is a decision requiring genuine technical implementation, not a terms-of-service clause.
BitLicense and money transmitter licensing are separate
This is the most common structural misunderstanding, and it is expensive because it surfaces mid-process.
New York regulates virtual currency business activity under Part 200 and fiat money transmission under the Banking Law. They are distinct regimes with distinct applications. A platform that lets customers deposit dollars, exchange them for virtual currency, and withdraw either may need both authorisations.
New York has also not adopted the CSBS Money Transmission Modernization Act. Firms that built their multi-state licensing plan around MTMA-harmonised requirements will find New York's capital, net worth, and permissible-investment standards diverge. Section 651 of the Banking Law requires money transmitters to maintain permissible investments equal to their outstanding transmission liabilities — an ongoing obligation, not a one-time threshold.
Determine which authorisations your model requires before drafting anything. Discovering a second licensing requirement partway through a review resets your timeline and undermines your credibility with the examiner reviewing your file.
The six pillars NYDFS assesses
Part 200 and the guidance built on it define what a licensee's program must contain. Treat these as the structure of the work rather than as application sections.
1. Anti-money laundering
A full BSA/AML program: written policies calibrated to your actual risk, a designated compliance officer, customer identification and risk-based due diligence, ongoing transaction monitoring, suspicious activity reporting, OFAC sanctions screening, training, and independent testing.
What distinguishes this from a generic AML program is that NYDFS expects blockchain analytics to be integrated into it. The department has issued explicit guidance on using on-chain analysis for AML and sanctions purposes. A program that monitors fiat rails and treats on-chain activity as out of scope will not survive review.
Practically, this means a named analytics provider, documented risk-scoring methodology, defined thresholds and escalation paths, and evidence that alerts are worked and dispositioned by people who understand them.
2. Cybersecurity
A written cybersecurity program, covered in detail below. New York's expectations here are among the most specific in US financial regulation — and they come from two regulations at once, which is where firms get caught.
3. Custody and consumer protection
How customer assets are held, segregated, and protected — including in insolvency. Covered below.
4. Capital and financial condition
NYDFS sets capital requirements based on the licensee's specific business model, risk profile, and activity. There is no universal figure. Expect audited financials, detailed projections, and a demonstrated ability to fund the compliance program you are proposing.
5. Governance and control persons
Background investigation of principals, officers, directors, and control persons. Fingerprinting, personal financial disclosure, and a review of the actual governance structure — who has authority, who oversees compliance, and whether the compliance function has independence and access.
6. Disclosure, reporting, and recordkeeping
Consumer disclosures, complaint handling, transaction records, quarterly and annual reporting, and prior approval requirements for material changes to your business, control, or product set.
Cybersecurity: two regulations, not one
This is consistently where otherwise-credible applications thin out, and there is a specific structural reason.
A BitLicensee is subject to both the virtual-currency-specific cybersecurity requirements at 23 NYCRR § 200.16 and, as a Covered Entity, the general Cybersecurity Regulation at 23 NYCRR Part 500. The two contain substantially similar requirements, which is exactly what makes the trap effective.
Filing your Part 500 annual certification does not satisfy the Part 200 obligation. DFS has said so directly in its own reporting. Firms that certify under Part 500 and consider the matter closed are carrying an open deficiency they do not know about — and the department's enforcement record in this area is not theoretical. Prior consent orders against virtual currency licensees have cited cybersecurity failures under both regulations.
A New York State Comptroller follow-up audit found licensees not in compliance with the department's cybersecurity regulations even where they had self-certified compliance — which tells you how closely this is now scrutinised. Note also that BitLicensees are examined at least once every two calendar years, so a gap does not sit undiscovered indefinitely.
A program that will hold up includes:
- A written program with a named owner — a CISO or equivalent with defined authority
- A current risk assessment that actually drives control selection rather than sitting alongside it
- Access controls with least privilege, documented reviews, and multi-factor authentication
- Penetration testing and vulnerability assessment on a defined cycle, with remediation tracked to closure
- An incident response plan that has been exercised, with the exercise documented
- Third-party and vendor risk management, including custody and infrastructure providers
- Audit trails sufficient to reconstruct material events
- Business continuity and disaster recovery, tested rather than drafted
- Annual certification under Part 500 — which means someone signs their name to it, and which does not by itself discharge § 200.16
Examiners distinguish quickly between a program that exists on paper and one that runs. Evidence of operation — completed access reviews, closed remediation items, a documented incident with a documented response — carries more weight than the quality of the policy document.
Custody and consumer protection
NYDFS has issued updated guidance for virtual currency entities providing custody services, reflecting the growth of sub-custodial arrangements and heightened attention to what happens to customer assets in insolvency.
Core expectations:
- Segregation. Customer virtual currency held separately from the licensee's own, on-chain and in the books and records
- No unauthorised use. Customer assets not lent, pledged, rehypothecated, or otherwise used without explicit authorisation
- Clear legal characterisation. Disclosure of how customer entitlements are structured and how they would be treated if the licensee failed
- Sub-custodian oversight. Where custody is delegated, documented diligence and ongoing monitoring of the sub-custodian
- Key management. Generation, storage, quorum structure, and recovery — with the same rigour a custodian bank would apply
- Reconciliation. Regular reconciliation of customer entitlements against on-chain holdings
Coin listing and delisting
NYDFS maintains a framework governing which virtual currencies licensees may support, including a greenlist of coins pre-approved for specified uses, and requires licensees to maintain their own coin-listing and coin-delisting policies.
The department has also issued specific requirements for US dollar-backed stablecoin issuance, covering reserve composition, redeemability, and attestation.
What this means operationally: adding an asset is a governed decision requiring documented analysis, defined approval, and in some cases prior notice or approval. Delisting needs an equivalent process, including customer notification and orderly wind-down. Firms accustomed to listing assets on a product manager's judgement need to rebuild that process before applying.
Timeline, deficiency cycles, and cost
Reviews commonly run beyond a year. The mechanic driving that is the deficiency letter: NYDFS reviews, identifies gaps, and issues a request. You respond. They review again. Each cycle adds weeks or months.
Two variables sit within your control:
- Initial completeness. Every gap in the first submission becomes a deficiency item. Applications assembled to answer questions rather than describe an operating program generate long first deficiency letters.
- Response quality and speed. Substantive responses that resolve the underlying issue close items. Responses that restate the original position generate follow-ups.
On cost, budget beyond the application. NYDFS implemented a virtual currency assessments rule at 23 NYCRR 102, shifting the cost of supervision and examination onto licensees through direct assessments. Add the ongoing compliance program, cybersecurity testing, independent AML testing, analytics tooling, and audit — the licence is the beginning of the cost, not the end of it.
The limited purpose trust charter
The alternative route is a limited purpose trust company charter under New York Banking Law. Several significant virtual currency businesses operate this way.
| BitLicense | Limited purpose trust charter | |
|---|---|---|
| Authority | Virtual currency business activity under Part 200 | Trust powers, including fiduciary custody |
| Custody | Permitted, non-fiduciary | Fiduciary custody available |
| Chartering standard | High | Higher — this is a bank charter |
| Ongoing supervision | Substantial | Heavier, bank-style examination |
| Money transmission | May need separate MTL | Chartered entities are outside the BitLicense requirement |
The trust charter suits firms whose core business is custody, or who want fiduciary standing for institutional clients. It is a materially heavier lift. The decision belongs at the start of the process, because the two paths diverge early.
How to approach it
The firms that get through in reasonable time do the same things:
- Settle the perimeter first. Which authorisations, which entity, which jurisdictions, which activities.
- Build the program before drafting the application. The application should describe something that exists.
- Staff compliance genuinely. A named compliance officer with real authority, real access, and enough seniority to say no.
- Generate operating evidence. Run the program long enough to produce completed reviews, worked alerts, and a tested incident response.
- Have someone independent read the file before submission, specifically looking for what an examiner would question.
- Resource the deficiency response. The people who can answer substantively need to be available, not mid-fundraise.
The department's framework is demanding by design, and it is unlikely to loosen. Firms that treat that as a barrier tend to struggle. Firms that treat the resulting program as an asset — one that makes every subsequent state application, institutional counterparty review, and allocator diligence easier — get more out of the same spend.
Common questions
Who needs a BitLicense?
Generally, any business conducting virtual currency business activity involving New York or a New York resident — receiving, transmitting, storing, buying, selling, exchanging, controlling, or issuing virtual currency. Merchants using crypto only for their own purchases and chartered banking organizations are excluded.
How long does a BitLicense take?
Reviews commonly run beyond a year. NYDFS typically issues one or more deficiency letters, and each cycle adds time. A complete, well-documented initial submission and fast, substantive responses are the main levers you control.
Do I need a money transmitter license as well?
Possibly. New York treats virtual currency business activity and fiat money transmission as separate regimes. A firm handling both may need both authorisations. This is a frequent mid-application surprise.
What is the alternative to a BitLicense?
A limited purpose trust company charter under New York Banking Law. It permits virtual currency activity and carries custody and fiduciary powers a BitLicense does not, but the chartering standard is higher and ongoing supervision is heavier.
Does New York follow the Money Transmission Modernization Act?
No. New York has not adopted the CSBS model act and maintains its own framework, so net worth, bond, and liquidity standards differ from the thirty-one states that have adopted it in whole or in part.
Does a Part 500 cybersecurity certification cover a BitLicensee's obligations?
No. A BitLicensee is subject both to 23 NYCRR Part 500 as a Covered Entity and to the virtual-currency-specific requirements at 23 NYCRR § 200.16. The requirements are substantially similar, but certifying under Part 500 does not by itself satisfy Part 200.
Building toward a BitLicense application?
We build the compliance, AML, and governance program that the application is assessed against — and prepare the firm for what follows approval.
Discuss an engagementThis page is general information about regulatory frameworks, not legal advice, and does not create an attorney-client relationship. Licensing requirements, thresholds, and agency guidance change frequently and vary by state. Verify current requirements against the relevant regulator, NMLS, and qualified counsel before relying on anything here.
