VARA, DFSA, FSRA, CMA, or CBUAE: Which Regulates Your Virtual Asset Activity?
Virtual asset activity in the UAE can fall under separate regulators depending on where it takes place and what the asset is used for — VARA for Dubai excluding the DIFC, the DFSA for the DIFC, the FSRA for ADGM, the federal Capital Market Authority (the SCA’s successor since 1 January 2026) for the rest of the UAE including its other free zones, and the CBUAE federally for payment tokens — each with its own licensing perimeter.
Virtual asset regulation in the UAE changed substantially through 2025 and into 2026, and the framework is genuinely fragmented by design — not an oversight, but separate regulators each covering a defined perimeter. Getting the regulator wrong isn’t a minor error: operating under VARA rules when FSRA’s actually apply, or assuming DFSA’s pre-2026 approach still holds, can mean an activity is either unlicensed where it needs to be licensed, or licensed under the wrong framework entirely. This guide sets out each regulator’s perimeter and the major 2025–2026 changes, without conflating tracks that are genuinely separate.
LAST REVIEWED 21 SEPTEMBER 2026
WHO THIS GUIDE IS FOR
Anyone building, operating, or investing in a virtual asset business connected to the UAE — exchanges, custodians, token issuers, DeFi and DLT projects — who needs to work out which regulator’s perimeter their activity actually falls within, and founders or investors trying to track the 2025–2026 changes to the onshore and DIFC frameworks specifically.
The Regulators and Their Perimeters
VARA — the Virtual Assets Regulatory Authority — covers virtual asset activity in Dubai, excluding the DIFC, under Dubai Law No. 4 of 2022, with eight licensed activities defined within its framework.
The DFSA — the Dubai Financial Services Authority — covers the DIFC specifically, and has recently shifted its approach to crypto tokens in a significant way described below.
The FSRA — the Financial Services Regulatory Authority — covers ADGM, with its own virtual asset framework built around accepted virtual assets, a fiat-referenced token regime, and a staking framework finalised on 29 April 2026. ADGM separately offers a DLT Foundations structure, which sits with ADGM’s Registration Authority rather than the FSRA — a distinction worth keeping straight, because they are different bodies doing different things.
The CMA — the Capital Market Authority — is the federal regulator for virtual asset activity in the rest of the UAE, non-financial free zones included, under Cabinet Resolution No. 111 of 2022: a virtual asset service provider operating out of an emirate other than Dubai, outside the financial free zones, needs its licence. It replaced the Securities and Commodities Authority on 1 January 2026, as described further below.
The CBUAE — the Central Bank of the UAE — has federal-level authority specifically over payment tokens, and separately has been brought into a role over decentralised finance activity through a different piece of legislation described further below.
VARA: Dubai Excluding the DIFC
VARA’s jurisdiction covers virtual asset activity taking place in Dubai outside the DIFC — the DIFC, despite being physically located within Dubai, sits under the DFSA’s separate regulatory perimeter rather than VARA’s.
VARA’s framework, under Dubai Law No. 4 of 2022, defines eight licensed activities that a virtual asset business needs to map its actual operations against — the specific activity or activities a business is conducting determine which VARA licence category is relevant, rather than a single blanket virtual asset licence covering everything.
DFSA: DIFC’s Shift to Self-Assessment
From 12 January 2026, the DFSA moved to a firm-led self-assessment model for crypto tokens — meaning firms themselves assess whether a given token meets the DFSA’s criteria, rather than relying on the DFSA to centrally review and place every token on an approved list.
As part of this shift, the DFSA retired its recognised-token list — the previous mechanism of a centrally maintained list of tokens the DFSA had specifically reviewed and recognised is no longer how the DFSA’s framework works.
The DFSA retained central approval in one specific area: fiat crypto tokens still require central DFSA approval even under the new self-assessment model — this is the one category where the DFSA has kept direct, centralised control rather than devolving the assessment to firms.
FSRA: ADGM’s Virtual Asset Framework
ADGM’s FSRA regulates virtual asset activity through a framework built around the concept of accepted virtual assets — assets that meet the FSRA’s criteria, assessed by the firm itself rather than drawn from a central list. Separately from the FSRA, ADGM’s Registration Authority administers the Distributed Ledger Technology Foundations Regulations 2023, a legal structure for decentralised protocols and projects. The two are often spoken of as one ADGM framework; they are not, and which body a question belongs to changes who answers it.
The FSRA finalised its staking rules on 29 April 2026, giving ADGM a defined regulatory position on staking clients’ virtual assets. The framework sets which categories of Authorised Person may stake client assets, limits the rewards that may be provided to clients to Accepted Virtual Assets and Accepted Fiat-Referenced Tokens, and prescribes key terms, client disclosures and client reporting. Notably it reaches beyond Proof of Stake: it extends to non-Proof-of-Stake models with materially similar characteristics. Its commencement date is not stated in the FSRA’s announcement, so anyone planning around it should confirm the current position directly.
CBUAE: Payment Tokens and the DeFi Overlay
The CBUAE holds federal-level regulatory authority specifically over payment tokens — virtual assets used or intended for use as a means of payment — a distinct category from the broader virtual asset activity VARA, DFSA, and FSRA each regulate within their own zones.
Separately, Federal Decree-Law No. 6 of 2025 (the Central Bank Law) brings decentralised finance, decentralised applications (dApps), and protocols into CBUAE’s scope at Article 62 — this is a different track from the CBUAE’s payment-token authority and should not be conflated with it; a project touching DeFi specifically needs to consider this separate basis for CBUAE involvement.
The Onshore Track: From SCA to the Capital Market Authority
The Securities and Commodities Authority (SCA), which previously held the onshore federal role for securities and virtual asset activity outside VARA, DFSA, and FSRA’s specific zones, was replaced by the Capital Market Authority (CMA) — note the singular “Market,” a deliberate naming distinction — under Federal Decree-Law No. 32 of 2025, effective 1 January 2026.
This is a genuine institutional replacement, not a rebrand of the same body under a new name — the CMA is the successor authority for the onshore federal role the SCA previously held, and references to the SCA’s prior rules and decisions should be understood in that context going forward.
CMA Board Resolution 4/R.M of 2026: A Replacement, Not a Rename
CMA Board Resolution No. 4/R.M of 2026 replaced — deliberately not merely renamed — the onshore VASP (Virtual Asset Service Provider) framework that had previously existed under the SCA. This distinction matters: it is a substantively new framework, not the old SCA rules relabelled under the CMA’s name.
The new framework expands licensed activities from three to eight, with five new modules added — a substantial broadening of what onshore virtual asset activity now falls within scope of formal CMA regulation, compared to the narrower three-activity structure that existed under the prior SCA-era VASP framework.
Fiat Crypto Tokens: DFSA’s One Retained Central Approval
Fiat crypto tokens are worth calling out specifically because they’re the exception to DFSA’s broader 2026 shift to self-assessment — while most crypto tokens under DFSA’s framework are now assessed by firms themselves, fiat crypto tokens specifically still require central DFSA approval.
Any project involving a fiat-backed token connected to DIFC should treat this as a distinct compliance step from the general self-assessment process the rest of DFSA’s token framework now uses.
Staking in ADGM: What the April 2026 Rules Actually Do
The FSRA’s staking rules, finalised 29 April 2026, restrict which categories of Authorised Person may stake clients’ virtual assets, limit client rewards to Accepted Virtual Assets and Accepted Fiat-Referenced Tokens, and prescribe key terms, disclosures and reporting to clients.
The reach is wider than the label suggests. The rules extend to non-Proof-of-Stake models that have materially similar characteristics to Proof-of-Stake staking, so a project should not assume it is outside them simply because its mechanism is not conventional staking. How particular models — liquid staking and similar arrangements among them — are treated is a question for the rule text and a lawyer, not one this guide resolves: the FSRA’s announcement names no exclusions, and the commencement date is not stated in it.
Where a Token or Platform Actually Sits
The threshold question for any virtual asset business connected to the UAE is jurisdictional: is the activity taking place in Dubai outside the DIFC (VARA), within the DIFC (DFSA), within ADGM (FSRA), or elsewhere in the UAE, non-financial free zones included (the CMA, for the activities within its scope, or the CBUAE for payment tokens specifically)?
A platform or token can, in principle, need to consider more than one of these regimes if its activity or user base spans more than one zone — this isn’t automatically an either/or choice, and assuming a single licence in one jurisdiction clears the whole UAE market is a common and consequential mistake.
Overlaps and Gaps Between Regulators
The CBUAE’s payment-token authority and its newer DeFi/dApp scope under Federal Decree-Law No. 6 of 2025 Article 62 are separate legal bases and shouldn’t be conflated — a project might trigger one, both, or neither depending on exactly what it does, and treating them as a single combined CBUAE remit risks missing which specific basis actually applies.
Similarly, DFSA’s retirement of the recognised-token list doesn’t mean DFSA oversight has disappeared for most tokens — it means the mechanism changed from central listing to firm self-assessment, which still carries real compliance obligations, just structured differently than before 12 January 2026.
Common Misconceptions
That VARA covers all of Dubai including the DIFC — it doesn’t; the DIFC sits under the DFSA’s separate perimeter despite being physically within Dubai.
That the DFSA still maintains a recognised-token list — it retired that list as part of the shift to firm-led self-assessment from 12 January 2026, retaining central approval only for fiat crypto tokens.
That the Capital Market Authority is just the SCA renamed — it’s a genuine institutional replacement under Federal Decree-Law No. 32 of 2025, and CMA Board Resolution 4/R.M of 2026 replaced, rather than merely relabelled, the onshore VASP framework itself.
That ADGM’s staking rules only reach conventional Proof-of-Stake arrangements — they extend to non-Proof-of-Stake models with materially similar characteristics, so the mechanism’s label is not what decides it.
That CBUAE’s payment-token role and its Article 62 DeFi scope under Federal Decree-Law No. 6 of 2025 are the same thing — they’re separate legal bases for CBUAE involvement and shouldn’t be conflated.
FAQ
LEXNOVA is not a law firm and does not provide legal advice, legal opinions, legal representation, or legal services. Any legal advice or representation is provided directly by the independent legal professional engaged by the client.
A connection or introduction does not constitute a guarantee, endorsement, or assurance of outcome. Users should independently confirm the professional's qualifications, authorization, fees, scope of engagement, and suitability.