
If you carry out a virtual asset activity by way of business anywhere in Dubai outside the DIFC, you need a VARA licence, and the licence drags in four compulsory rulebooks plus one for each activity you are licensed to do. This guide walks the requirements that actually bind you, with the rule reference for each one.
Who needs a VARA licence
VARA was established under Dubai Law No. (4) of 2022 Regulating Virtual Assets in the Emirate of Dubai. Its jurisdiction is set out plainly on its own rulebook portal: VARA "is the sole authority regulating virtual assets across Dubai's free zones and mainland, except within the jurisdiction of Dubai International Financial Centre (DIFC)". Firms inside the DIFC answer to the DFSA instead.
The licence trigger is in Regulation III.A.1 of the Virtual Assets and Related Activities Regulations 2023: "No Entity may carry out any VA Activity by way of business, or purport to do so, in the Emirate, unless it is authorised and Licensed by VARA for the VA Activity", is an employee of a licensed VASP, or is an Exempt Entity. Regulation III.A.2 gives VARA sole discretion over what counts as "by way of business", looking at whether you hold yourself out as doing it, the regularity, scale and continuity of the activity, and whether there is a commercial element.
You need a licence per activity, not one licence for the firm. Regulation IV.A.1.b requires entities to "apply for, obtain and maintain a Licence issued by VARA in order to be permitted to carry out each VA Activity that it will conduct in the Emirate". Schedule 1 of the Regulations defines the VA Activities:
- Advisory Services - personal recommendations to a client on actions or transactions in virtual assets.
- Broker-Dealer Services - arranging or matching orders, dealing on own account, market making using client assets, or placement and distribution services for issuers.
- Category 1 VA Issuance - as defined in the Virtual Asset Issuance Rulebook.
- Custody Services - safekeeping virtual assets for another entity and acting only on verified instructions. Only VASPs that segregate each client's assets in separate VA Wallets qualify for a Custody licence.
- Exchange Services - exchanging virtual assets against fiat or other virtual assets, matching orders, or maintaining an order book.
- Lending and Borrowing Services - contracts under which a virtual asset is lent and the borrower commits to return it.
- VA Management and Investment Services - managing, administering or disposing of another entity's virtual assets, including taking responsibility for staking.
- VA Transfer and Settlement Services - transmission, transfer or settlement of virtual assets between entities or wallets.
One rule that catches groups with operations elsewhere: Regulation IV.A.4 says that if a VASP carries out a licensed activity outside Dubai, it must apply the VARA rules as a minimum standard there too, and "VASPs are obligated to meet the higher of the two regulatory standards at all times".
Which rulebooks bind you
Regulation V.1 makes four rulebooks compulsory for every VASP regardless of activity: the Company Rulebook, the Compliance and Risk Management Rulebook, the Technology and Information Rulebook, and the Market Conduct Rulebook. Regulation V.2 adds the activity-specific rulebook for each activity you are licensed to carry out, and issuers must also comply with the Virtual Asset Issuance Rulebook.
The Technology and Information Rulebook is the one that carries the security, key management, resilience and data protection obligations. The version in force is dated 19 June 2025. Everything below cites it as the TIR.
The real section map of TIR Part I
Part I of the TIR runs from section A to section K. Getting this map right matters, because VARA assessment questions and your own evidence index should follow it.
| Rule | Section | What it obliges you to do |
|---|---|---|
| I.A | Technology Governance and Risk Assessment Framework | Implement a framework proportionate to the nature, scale and complexity of the business, covering development, maintenance and testing, operations controls, back-up controls, capacity and performance planning, and availability testing. Review, update and test it periodically. |
| I.B | Cybersecurity Policy | Create a Cybersecurity Policy, submit it to VARA as part of licensing and on request, have the CISO review and update it at least annually, and address the 19 minimum criteria in Rule I.B.3. |
| I.C | Cybersecurity: other legal and regulatory obligations | Comply with the Dubai Electronic Security Center standards under Law No. (9) of 2022, the PDPL (Federal Decree-Law No. (45) of 2021) and UAE Data Office requirements, and the CBUAE Consumer Protection Regulation under Notice No. (444) of 2021. |
| I.D | Cryptographic Keys and VA Wallets Management | No single point of failure in access to virtual assets, key backups stored separately from the primary key or seed phrase, audit-logged access changes, immediate revocation procedures, and quarterly internal audits of user access removal. |
| I.E | Testing and Audit | Engage a qualified, independent third-party auditor for vulnerability assessments and penetration testing, including smart contract audits where relevant, at least annually and before introducing any new systems, applications or products. TLPT applies where VARA notifies you. |
| I.F | Virtual Asset Transactions | Controls against manipulation and collusion of automated systems, and distributed ledger tracing software screening incoming and outgoing transactions and wallet addresses. |
| I.G | Algorithm Governance | Board and Senior Management oversight of algorithm design, testing, performance, deployment and maintenance, with documentation of the logic, data, assumptions and biases. |
| I.H | Business Continuity, Cybersecurity Events and Risk | Implement, maintain, test and update a BCDR Plan annually, covering triggers, resources, recovery priorities, communications, integrity validation, an alternative site, and post-event remediation. |
| I.I | Chief Information Security Officer and Management | Appoint a CISO responsible for compliance with Parts I and III. The CISO must be a separate individual from the Compliance Officer, and may also be the Data Protection Officer. |
| I.J | Staff Competency | Keep all staff aware of the latest cybersecurity risks and developments, including those specific to virtual assets and DLT. |
| I.K | Notification to VARA | Report a material cybersecurity event, or an event triggering the BCDR Plan that materially impacts operations, as soon as reasonably practicable and no later than 72 hours from detection. |
The Cybersecurity Policy: 19 minimum criteria, not 18
Rule I.B.3 says the Cybersecurity Policy "must address the following minimum criteria" and then lists them from (a) to (s). That is 19 criteria in the version in force. The count moved: the 7 February 2023 rulebook stopped at (r), which is where the widely repeated figure of 18 comes from. The current text adds (s), sharing cyber threat information and intelligence with other VASPs and entities where doing so serves the virtual asset market as a whole and does not increase risk to the sharing VASP.
Two procedural duties travel with the policy. Under Rule I.B.1 you must submit it to VARA for assessment as part of the licensing process and at any later time on request. Under Rule I.B.2 the CISO must review and update it at least annually. The full breakdown of all 19 criteria is here.
The obligations that bite hardest
A CISO who is not the Compliance Officer
Rule I.I.1 requires every VASP to appoint a CISO responsible for compliance with Part I and Part III of the TIR. The rule is explicit that "The CISO must be a separate individual from the CO", and equally explicit that the CISO may take on the Data Protection Officer role under Rule II.B.2. Rule I.I.2 adds only that the CISO must be "of sufficiently good standing and appropriately experienced". The rulebook does not set a minimum number of years for the CISO, unlike the Compliance Officer, who under Rule I.C.1 of the Compliance and Risk Management Rulebook needs at least five years of relevant compliance experience, must be a UAE resident or passport holder, must be full time, and must report directly to the Board.
Annual independent testing, plus a test before every launch
Rule I.E.1 requires a qualified and independent third-party auditor to conduct vulnerability assessments and penetration testing, including comprehensive audits of the effectiveness, enforceability and robustness of all smart contracts where relevant, "at least on an annual basis and prior to the introduction of any new systems, applications and products". The second half of that sentence is the one firms miss. A product launch is a testing trigger, not just the calendar.
Rules I.E.5 to I.E.10 add threat-led penetration testing, but only where VARA notifies you that it is necessary and proportionate, taking into account your specific risks, the criticality of your business and activities, and other relevant risks. Where TLPT is required, it must be carried out by an external tester, may cover Critical or Important Functions on live production systems, and the summary of findings, remediation plans and supporting documentation must be provided to VARA.
Key management with no single point of failure
Rule I.D.2 requires VASPs to "ensure that there is no single point of failure in the VASP's access to, or knowledge of, Virtual Assets held by the VASP", to store backups of keys and seed phrases in a separate location from the primary key or seed phrase, and to keep an audit log of every change of access to keys. If a staff member with key access leaves, the VASP must assess whether a new key must be generated. Rule I.D.2.d.ii requires internal audits "on a quarterly basis concerning the removal of user access by reviewing access logs and verifying access as appropriate".
Two notification clocks, not one
Rule I.K.1 gives you 72 hours from detection to report a material cybersecurity event, or an event triggering the BCDR Plan that materially impacts business operations. Rule II.C.2 is a separate and shorter clock: where you notify a data regulator or a data subject of an incident affecting, or potentially affecting, personal data, you must notify VARA "as soon as possible and in any event within twenty-four (24) hours" of that notification. The incident reporting article works through both.
Schedule 1 is five risk domains, not a risk rating
Schedule 1 of the TIR is guidance on building the Technology Governance and Risk Assessment Framework. It sets out five categories of risk, and they are thematic domains rather than tiers. VARA does not assign your firm a Schedule 1 number.
| Risk Category | Representative standards inside it |
|---|---|
| 1. Organisational | Comprehensive security framework, secure development lifecycle with mandatory security review gates, workforce security including background checks and endpoint protection, infrastructure management with asset inventories and data flow maps, and third-party technology service provider controls. |
| 2. Technical | Key generation using HSMs where possible, wallet creation with separation of duties, key storage using defence in depth, smart contract security, multi-signature security where the minimum number of signers M is greater than the total signatories N divided by two, transaction verification, key compromise response, authentication controls, developer workstation controls, security testing, secure media disposal, and audit logging that keeps logs "for a minimum of one year". |
| 3. Detection and Response | Transaction monitoring, internal user activity monitoring, enhanced monitoring of developer and signing systems, tactical hardening with emergency access revocation, investigation capability including forensics and chain of custody, on-chain analysis, and remediation requiring "complete rotation of all secret components" after incidents. |
| 4. Customer VAs | Customer authentication, withdrawal controls with tiered limits and cooling periods, user education, and wallet concentration risk controls. |
| 5. Digital Operational Resilience | A digital operational resilience testing programme with tests undertaken by independent external parties, and appropriate tests "conducted at least yearly on all systems and applications supporting Critical or Important Functions". |
Two concrete numbers in Schedule 1 are worth lifting out because they are testable. The security testing standard in Risk Category 2 expects "annual penetration testing by qualified third parties" plus "quarterly vulnerability assessments". The audit logging standard in the same category expects logs to be stored securely with tamper-evidence and retained for a minimum of one year.
What the other three compulsory rulebooks add
Technology compliance is not the whole licence. The three other compulsory rulebooks carry hard numbers of their own.
- Paid-up capital (Company Rulebook VI.B.1). AED 100,000 for Advisory Services. For Custody Services, the higher of AED 600,000 or 25% of fixed annual overheads. For Exchange Services, the higher of AED 1,500,000 or 25% of fixed annual overheads, dropping to the higher of AED 800,000 or 15% where the VASP uses a VARA-licensed custodian. A VASP licensed for more than one activity holds the amount for each activity and reconciles monthly.
- Net liquid assets (Company Rulebook VI.C). Current liquid assets in surplus over current liabilities of at least 1.2 times monthly operating expenses, reconciled daily and reported to VARA monthly.
- Reserve assets (Company Rulebook VI.E). Reserve assets equal to 100% of the liabilities owed to clients, held one to one in the same virtual asset, reconciled daily and audited by an independent third-party auditor no less than every six months.
- Regulatory reporting (Compliance and Risk Management Rulebook I.H). Monthly balance sheet, profit and loss, cash flow and VA wallet addresses. Quarterly board minutes, financial projections and the risk exposure report. Annual audited financial statements with an attestation on the effectiveness of the internal control structure.
- Records (Compliance and Risk Management Rulebook I.F.2). Keep books and records for no less than eight years, or indefinitely where they may relate to UAE national security.
- Immediate breach reporting (Compliance and Risk Management Rulebook I.I.2). "VASPs shall submit a report to VARA immediately upon the discovery of any violation or breach of any law, Regulation, Rule or Directive related to the conduct of any VA Activity."
A sensible sequence
The rulebook does not prescribe an implementation order and any timeline you see quoted is somebody's guess, not a VARA rule. What the text does imply is a dependency chain.
- Fix the activities you will be licensed for, because that decides which activity rulebook and which paid-up capital line applies.
- Appoint the CISO and the Compliance Officer as separate people, since the CISO owns Parts I and III of the TIR and the annual policy review.
- Build the Technology Governance and Risk Assessment Framework first, because Rule I.B and Schedule 1 both hang off it.
- Write the Cybersecurity Policy against all 19 criteria in Rule I.B.3, since it is submitted to VARA during licensing.
- Stand up the BCDR Plan and the incident escalation path, because the 72 hour and 24 hour clocks assume both exist.
- Book the independent testing, remembering that it is required annually and before any new system, application or product goes live.
- Collect the evidence as you go. Rule I.E.3 requires evidence of tests and audits to be "documented by VASPs and made immediately available by them for inspection by VARA, upon VARA's request".
Frequently Asked Questions
Who has to hold a VARA licence?
Any entity carrying out a VA Activity by way of business in Dubai, unless it is an employee of a licensed VASP or an Exempt Entity, under Regulation III.A.1 of the Virtual Assets and Related Activities Regulations 2023. VARA is the sole authority across Dubai's mainland and free zones except the DIFC, which is regulated by the DFSA. A separate licence is required for each VA Activity.
How many criteria must a VARA cybersecurity policy address?
Nineteen. Rule I.B.3 of the Technology and Information Rulebook in force since 19 June 2025 lists minimum criteria (a) through (s). The figure of 18 that circulates online comes from the 7 February 2023 version, which ended at (r) and did not include the cyber threat intelligence sharing criterion.
Can the CISO also be the Compliance Officer?
No. Rule I.I.1 of the Technology and Information Rulebook requires the CISO to be a separate individual from the Compliance Officer. The same rule allows the CISO to take on the Data Protection Officer role under Rule II.B.2.
How quickly must a VASP report an incident to VARA?
Rule I.K.1 requires a report as soon as reasonably practicable and no later than 72 hours from detection of a material cybersecurity event, or of an event triggering the BCDR Plan that materially impacts business operations. Rule II.C.2 imposes a separate 24 hour clock: once you notify a data regulator or a data subject about an incident affecting personal data, VARA must be told within 24 hours of that notification.
Does VARA assign my firm a risk category?
Not through Schedule 1 of the Technology and Information Rulebook. Schedule 1 is guidance that groups technology risks into five domains: organisational, technical, detection and response, customer VAs, and digital operational resilience. It is not a tiering system, and VASPs are expected to consider all five when building their Technology Governance and Risk Assessment Framework.
How often must penetration testing be done?
At least annually, by a qualified and independent third-party auditor, and also before the introduction of any new systems, applications and products, under Rule I.E.1. The Schedule 1 security testing standard also expects quarterly vulnerability assessments. Threat-led penetration testing is separate and applies only where VARA notifies you under Rule I.E.5.
Running a VARA programme in Venvera
Venvera does not ship a VARA control catalogue today, so treat this as what the platform can carry rather than a one-click VARA module. What it does give a VASP is a single place to hold the artefacts the rulebook asks for and to produce them on request:
- The policy module keeps a versioned Cybersecurity Policy through draft, review and approval with a named approver and an approval date, which is what Rule I.B.2's annual CISO review has to leave behind (verified in product).
- The incident register records incidents with notification deadlines and shows the hours remaining against each reporting step (verified in product). The built-in clocks are configured for the EU DORA and NIS2 regimes, so a VARA 72 hour deadline is tracked as a deadline you set, not as a preloaded VARA timer.
- The evidence library and evidence requests hold the test reports, audit reports and BCDR test records that Rule I.E.3 says must be made immediately available to VARA (verified in product).
- The crosswalk engine lets controls and evidence be reused across the frameworks that are in the catalogue, including UAE IA and ISO 27001, which is where most of the underlying security work for a Dubai VASP already sits (verified in product).
If you want a fast read on where you stand before the licence application, run a free compliance check.

Keep the licence evidence in one place
Policies, incidents, test reports and control mappings, kept audit-ready and reusable across your other obligations.
Book a demo →Primary sources
Every rule reference above is taken from VARA's published rulebooks. Always confirm the current text before relying on a specific rule.
- VARA Technology and Information Rulebook - effective 19 June 2025. Rules I.A to I.K, Part II, Part III and Schedule 1.
- Virtual Assets and Related Activities Regulations 2023 - Regulation III (general prohibition), Regulation IV (licensing), Regulation V (rulebooks), Schedule 1 (VA Activities).
- VARA Company Rulebook - Part VI, paid-up capital, net liquid assets, insurance and reserve assets.
- VARA Compliance and Risk Management Rulebook - Compliance Officer duties, risk management, regulatory reporting and notifications, records retention.
- VARA Laws and Regulations index - Law No. (4) of 2022 Regulating Virtual Assets in the Emirate of Dubai.
Last updated: July 2026. This article is general information, not legal advice. Confirm your obligations with VARA or qualified counsel.




