Bitcoin custody licensing in the Middle East has, over the last five years, fragmented into a small set of structurally distinct regimes. A regulator-aware reading of these regimes is the prerequisite for any institution choosing where its assets will be held. This article situates the Central Bank of Bahrain’s Crypto-Asset Module (CBB Rulebook Volume 6, in force since April 2023) against four other regimes that practitioners commonly compare against it: the Abu Dhabi Global Market’s FSRA Crypto-Asset framework, the Dubai International Financial Centre’s DFSA Crypto Token regime, the federal Capital Markets Authority (CMA, the successor to the Securities and Commodities Authority since 1 January 2026) applicable outside the UAE financial free zones, and Dubai’s Virtual Assets Regulatory Authority (VARA).

This framing matters because Bitcoin custody is not a service one chooses purely on commercial terms. The choice of jurisdiction encodes assumptions about the supervising regulator’s posture, the client perimeter the regime permits, the operational obligations attached to a licence, and, most consequentially, the liability and legal-recourse architecture available if something goes wrong. Each of the five regimes below answers these questions differently. The differences are not always obvious from the licence designations themselves.

The regimes are described as of May 2026. Several were introduced or amended within months of writing; where a measure is very recent, it should be read as announced and confirmed against the current rulebook before any reliance.

1. The five regimes at a glance

A reader new to the region can think of the five regimes as occupying four distinct structural positions:

  • CBB Volume 6 (Crypto-Asset Module): a domestic, central-bank-supervised regime with a Cat-2 custody licence path explicitly contemplated for institutional custody. Custody, conduct, capital, technology, outsourcing, and conflicts rules are codified at module level (CRA). Bahrain.
  • ADGM FSRA Crypto-Asset regime: a financial-free-zone regime under the Abu Dhabi Global Market Financial Services Regulatory Authority. English common-law foundation. Custody fits inside the existing FSMR custodian regime, with virtual-asset-specific operational requirements layered on top through guidance.
  • DFSA Crypto Token regime: a financial-free-zone regime in the Dubai International Financial Centre. Reformed substantially on 12 January 2026, replacing the prior list of “Recognised Crypto Tokens” with a firm-led “Suitable Crypto Token” assessment under General Module Rule 3A.
  • UAE federal CMA regime: the federal authority for virtual-asset investment activities outside the financial free zones, reconstituted from the SCA on 1 January 2026 under Federal Decree-Law No. 32 of 2025. CMA Decision No. 4/R.M/2026 establishes eight licensed activity categories, including a Custody Service licence.
  • VARA: the Dubai-emirate-level authority governing virtual assets within Dubai outside the financial free zones, established under Dubai Law No. 4 of 2022. Activity-based licensing under a dedicated set of rulebooks (Custody Services, Compliance and Risk, Technology, Marketing, and others). The most prescriptive of the five on operational architecture and on marketing.

The table below summarises the five positions at a glance; the sections that follow examine each dimension in turn. Figures are the licence-level minimums each regime publishes, and should be read alongside the discussion of what each is designed to do.

RegimeRegulatorBase capital floorClient perimeterGoverning law and courtCustody rules
CBB Volume 6Domestic central bankBHD 100k (~USD 265k) plus risk add‑onsInstitutional and professionalBahraini law; Bahrain‑seated arbitrationModule‑level (CRA Module); in force since Apr 2023
ADGM FSRAFinancial free‑zone regulatorUSD 4m plus risk add‑onsProfessional and market counterpartyEnglish common law; ADGM CourtsFSMR custodian regime plus COBS 15 and VA guidance (Dec 2023)
DFSAFinancial free‑zone regulatorSame order of magnitude as ADGMProfessionalEnglish‑style; DIFC CourtsExisting categories plus GEN 3A (reformed Jan 2026)
UAE CMAFederal market authorityAED 0.5m to 4m (tiered)Retail permittedUAE federal law; federal courtsActivity categories; Decision 4/R.M/2026 (Feb 2026)
VARADubai emirate authorityAED 1m paid‑up; 2–5% of AUCRetail permittedDubai Law 4/2022; English‑law contractsDedicated rulebooks; most prescriptive on operations

2. Custody-specific provisions: where the regimes diverge

Each of the five regimes treats crypto-asset custody as a regulated activity, but the depth of codification differs sharply. Two of the five (Bahrain’s CBB Volume 6 and the FSRA’s regime in ADGM) codify custody-specific obligations at module level. The other three rely on extensions of pre-existing rulebooks, on activity-based instruments layered over a younger statute, or on a federal regime that sits alongside parallel emirate-level supervisors.

Licence designation and codification depth. Bahrain treats custody as one of the regulated activities under a single Crypto-Asset Module (CRA), with custody-specific obligations set out in CRA-8 alongside conduct, capital, and risk rules in their own chapters [1]. ADGM does not have a dedicated crypto custody licence at all: an applicant requests Financial Services Permission to “Provide Custody” under the Financial Services and Markets Regulations 2015 (FSMR Schedule 1), with virtual-asset custody fitting inside the existing custodian regime alongside mature COBS Chapter 15 client-asset rules and the FSRA’s Guidance – Regulation of Virtual Asset Activities in ADGM (VER07, December 2023) layering crypto-specific operational requirements on top [2]. The DFSA reformed its regime on 12 January 2026; custody activity itself sits inside the existing Authorised Firm Category 4 (Providing Custody) classification with crypto extensions delivered through GEN 3A, COB 6, and the December 2025 Supervisory Guidelines on Assessing the Suitability of Crypto Tokens [3]. The federal CMA — which succeeded the SCA on 1 January 2026 — sets out eight licensed activity categories including a Custody Service licence under Decision No. 4/R.M/2026, effective February 2026 [4]. VARA operates an activity-based licensing model with a dedicated Custody Services Rulebook setting prescriptive operational standards, supplemented by the Technology and Information Rulebook [5].

The practical consequence: a Bahrain-licensed custodian and an ADGM-licensed custodian both work from a defined and stable rule set written specifically for custody. A DFSA, CMA, or VARA-licensed custodian works from a younger or more recently amended set of rules whose operational interpretations are still settling.

Capital adequacy. CBB Cat-2 sets minimum paid-up capital at BHD 100,000 (about USD 265,000), per CRA-1.1.12, with the CBB retaining discretion to require additional risk-adjusted capital based on the licensee’s activities [1, 6]. ADGM Category 3B Custodian capital is structurally higher: a base capital floor of USD 4 million with risk-based add-ons under the Funds Prudential Rules [2]. DFSA Category 4 sits in the same order of magnitude as ADGM, with crypto-specific adjustments under the PIB Module to reflect operational and cyber risk weights [3]. The federal CMA regime tiers capital from AED 500,000 to AED 4 million across its eight activity categories [4]. VARA requires AED 1 million in paid-up capital for a Custody Services licence, AED 1.5 million in base capital resources, and 2–5% of assets-under-custody in risk-adjusted terms [5].

The Bahrain figure is the lowest in absolute terms, which is occasionally misread as a sign of regulatory laxity. It reflects, instead, the CBB’s decision to use ongoing supervisory oversight, prescribed segregation, and risk-adjusted capital add-ons as the binding constraint, rather than a high static base. The counter-view is legitimate and worth stating plainly: behind a custodian that may hold nine-figure client assets, the gap between a roughly USD 265,000 base and ADGM’s USD 4 million is a real signal, and a risk-averse board may reasonably prefer the higher static floor as a visible buffer. The two designs place the protection in different places — a large static buffer on one side, supervision plus segregation plus risk-adjusted add-ons on the other — and an institution should judge which it trusts more for its own risk, rather than reading the lower base as laxity or the higher one as sufficiency.

Segregation, proof of reserves, and key-management governance. All five regimes require segregation of client assets from the licensee’s own assets. The differences are in operational granularity. CBB CRA-8 prescribes specific custody controls for keys and segregation, and CRA-12.2 governs conflicts of interest including how related-party fees may be structured [1]. ADGM’s COBS Chapter 15 mirrors UK-style CASS rules, with daily reconciliation, monthly attestation, and annual audit obligations supplemented by FSRA crypto-specific guidance on cold storage, multi-signature governance, and proof of reserves [2]. VARA is the most prescriptive on operational architecture: the Custody Services Rulebook requires a minimum of 95% of client assets in cold storage, mandates multi-signature governance for any material transfer, and obliges monthly proof-of-reserves attestations published publicly [5]. The DFSA’s COB Module Rule 6.11 imposes segregation and reconciliation obligations, with crypto-specific operational expectations introduced through the December 2025 Supervisory Guidelines and the new Client Asset Crisis Preparedness Pack [3]. The CMA regime is the least prescriptive on operational architecture; the published Decision references segregation and safekeeping in principle but does not codify wallet-allocation thresholds or attestation cadence at the same depth [4].

A custodian designing a 2-of-3 multi-institution architecture, with cold-only signing, geographically distributed shards, and monthly attestations against on-chain holdings, can map every operational element to a specific provision in the CBB and ADGM rule sets. The same architecture works under VARA. Under the CMA’s current text, the custodian is operating to a higher self-imposed standard than the regime presently requires.

Outsourcing. All five regimes require licensee accountability to remain in-jurisdiction, and none permits the substantive outsourcing of regulated functions. CBB CRA-6.6 names specific functions that cannot be outsourced and requires CBB approval for material outsourcing [1]. ADGM GEN Chapter 5 sets equivalent rules with sub-outsourcing prohibited absent consent [2]. The DFSA, CMA, and VARA regimes each impose comparable obligations through their own outsourcing provisions, with VARA’s Compliance and Risk Management Rulebook setting the tightest documentation standard.

3. Client perimeter and access rules

The five regimes part company most cleanly on the question of who is allowed to be a client.

The CBB Cat-2 custody path is oriented to institutional and professional participation: corporates, family offices, trusts and SPVs, and professional and eligible counterparties [1]. It is not built around retail access. ADGM’s FSRA regime is similarly bounded for virtual-asset custody: under the December 2023 Guidance, retail clients are not permitted; service is restricted to Professional Clients and Market Counterparties as defined in COBS Chapter 3, with the August 2023 enhancements raising the Professional Client portfolio threshold to USD 500,000 [2]. The DFSA regime operates the same way: crypto-token activity, including custody, is restricted to Professional Clients in the DIFC’s classification system [3].

The federal CMA regime and VARA both permit retail participation. Under CMA Decision No. 4/R.M/2026, retail clients are permitted across the licensed activity categories subject to enhanced disclosure obligations and pre-transaction risk warnings [4]. VARA is the most explicit on retail: retail access is permitted across custody, exchange, and brokerage, with the Exchange Services Rulebook (March 2026) capping retail derivatives leverage at 5:1, requiring suitability assessments, and mandating negative-balance protection [5]. Professional and qualified-investor categories receive higher access ceilings and reduced disclosure obligations.

This is the structural difference that matters most for a custodian making a positioning choice. A regime that permits retail participation builds its operational and supervisory expectations around retail protection: marketing rules tighten, disclosure obligations expand, and suitability assessments become mandatory. Over time, a supervisor’s caseload in such a regime is likely to skew towards retail matters, and the rule set can be expected to evolve in that direction — an inference from how retail-inclusive regimes tend to develop, rather than a documented finding. A regime that excludes retail can keep its rule set in calibration with institutional and professional client expectations: terms negotiated at arm’s length, custody architectures specified in service agreements rather than retail-protection rulebooks, and disclosure obligations matched to the sophistication of the counterparty.

For an institutional Bitcoin custody operation, the consequences are direct. Under CBB Cat-2, ADGM FSRA, and DFSA, the licensee is in a regime calibrated to institutional behaviour. Under CMA and VARA, the licensee is in a regime where retail considerations dominate the operating tempo, even if the licensee elects not to take on retail clients itself.

A second, narrower divergence concerns cross-border solicitation. The CBB and the financial-free-zone regulators in ADGM and DIFC each operate within a defined jurisdictional perimeter; cross-border solicitation into other GCC markets requires either a passport arrangement (rare in crypto) or local licensing. Arrangements for coordination between VARA and the federal authority have moved toward allowing a VARA-licensed VASP to operate more widely across the UAE [5]. CBB-licensed entities solicit cross-border on a country-by-country basis under the rules of the destination jurisdiction.

4. Liability and recourse architecture

The choice of jurisdiction is also a choice of legal recourse. If something goes wrong (a hack, a counterparty failure, an insolvency, a contested instruction), the architecture of liability depends on which court hears the dispute, which law governs the agreement, and which insolvency regime attaches to the licensee.

The CBB Cat-2 regime sits within Bahraini law. The Kingdom of Bahrain governs all licensed-entity contracts; arbitration is typically seated in Bahrain under the BCDR-AAA rules. The CBB itself is a domestic central bank with statutory powers under the Central Bank of Bahrain and Financial Institutions Law [1]. Insolvency of a Cat-2 licensee falls under Bahraini commercial bankruptcy law as modified by the financial-institution provisions in the CBB Law. Client-asset segregation under CRA-8 is the structural protection against pooling in an insolvency.

ADGM operates under English common law. The ADGM Courts have jurisdiction within the financial free zone and apply English contract and insolvency law as adopted by ADGM’s regulations [2]. This is a familiar architecture for international counterparties: contracts are interpreted by judges trained in English commercial law, and insolvency proceedings follow patterns recognisable to anyone who has dealt with English administration or liquidation. The DIFC operates the same architecture: DIFC Courts, English-style commercial law, and a financial-free-zone insolvency regime [3]. Both ADGM and DIFC are common attractive choices for cross-border counterparties for exactly this reason.

The CMA regime sits within UAE federal law, with disputes typically heard before UAE federal courts or, where contracts so provide, before arbitral tribunals seated in the UAE under DIAC or ADCCAC rules. UAE federal commercial and bankruptcy law applies. The Crypto-Asset Reporting Framework (CARF) implementation, with first information exchanges expected in 2028 following the UAE’s signature of the Multilateral Competent Authority Agreement on 20 September 2025, will add automatic exchange of crypto-asset tax information into the federal compliance picture [4]. VARA-licensed entities are governed by Dubai Law No. 4 of 2022 and the VARA Rulebooks, supplemented by UAE federal law where relevant; commercial contracts are commonly written under English law with Dubai-seated arbitration [5].

The practical question for a counterparty considering where to hold custody assets is which of these recourse architectures it wants to be in if the worst happens.

A Bahraini custody contract gives the counterparty access to a domestic central-bank supervisor with direct authority over the licensee, a court system used to commercial disputes, and a defined statutory regime for the segregation of client assets in insolvency. The recourse path is short: regulator complaint, court proceeding, or arbitration, all within a single jurisdiction with one supervisor and one applicable law. An ADGM or DIFC custody contract gives the counterparty an English-law contractual structure and access to the respective free-zone courts, which is structurally familiar and well-served by international counsel; recourse outside the free zone requires onshore enforcement procedures that are increasingly straightforward but add a step. A CMA contract gives access to UAE federal courts; a VARA contract gives access to Dubai-emirate-level proceedings under a younger rulebook with less testing in dispute.

None of these architectures is inherently weak. The differences are not about whether recourse exists; they are about how it is structured and which counterparties find each structure most legible. In Onramp MENA’s own experience of the market — a professional observation, not a surveyed finding — sovereign-affiliated capital, regional family offices, and Gulf-headquartered corporates often express a preference for Bahraini, ADGM, or DIFC supervision over the federal or emirate-level alternatives. Where that preference appears, it tends to reflect the legibility of the regulator-court-statute trio each of those three regimes presents rather than novelty avoidance.

5. Matching regime to mandate

The four dimensions above — regulator posture, codification depth, client perimeter, and recourse architecture — are the axes on which an institution can match a regime to its own mandate. No single regime leads on all four; the right choice depends on which of them a given operation most needs. For an institutional-only Bitcoin custody operation focused on the GCC, they weigh as follows.

Domestic central-bank supervision. This is the one feature genuinely unique to the CBB among the five. The CBB carries direct statutory authority over the licensee, with conduct, capital, and risk rules set in a single rulebook and applied through a single supervisor. ADGM and DIFC are well-supervised but operate within financial free zones; the CMA is a federal market regulator structurally distinct from the central bank; VARA is an emirate-level authority with statutory authority of its own but no central-bank affiliation. For an institution whose mental model of “regulator” is “central bank,” the CBB position is the most legible — though an institution that values common-law familiarity above central-bank affiliation may reasonably weigh this differently.

Module-level codification. Here the CBB is among the strongest rather than alone. The CRA Module sets crypto-asset rules in their own structure — licensing, conduct, custody, capital, technology, outsourcing, conflicts of interest, and reporting all sit in chapters dedicated to the activity — so a custodian maps each control to a named rule rather than to a layered combination of original rule plus crypto guidance plus supervisory letter. ADGM reaches comparable depth by a different route, through the FSMR custodian regime and the mature COBS Chapter 15 client-asset rules; the DFSA, CMA, and VARA regimes rely more on recent extensions and amendments whose operational interpretations are still settling.

Institutional client perimeter. On this axis the CBB, ADGM, and DFSA sit together: each is oriented to institutional and professional clients rather than retail. The CMA and VARA regimes permit retail and, as Section 3 discusses, can be expected to calibrate their rule tempo around retail protection over time — a consideration for any custodian operating inside them, even one that serves no retail clients itself.

Short recourse architecture. A Bahraini licensee gives a counterparty a single supervisor, one governing law, one arbitration seat, and a statutory segregation regime: a short recourse path within one jurisdiction. ADGM and DIFC offer an English-common-law path that many cross-border counterparties find more familiar, at the cost of an additional step for onshore enforcement. Which structure is preferable is a function of the counterparty, not a ranking.

Read together, the CBB Cat-2 regime is distinctive on domestic central-bank supervision and strong on the other three axes, which is what makes it a natural fit for a GCC-focused, institutional-only Bitcoin custody mandate. It is not the only defensible choice, and it is genuinely weaker on some dimensions: it does not offer an English common-law foundation, the domestic market is smaller than the UAE’s, its cross-border reach is country-by-country rather than passported, and its crypto-specific case law is as young as everywhere else in the region. An institution that most values common-law contracting, the widest UAE market access, or the highest static capital floor may rationally prefer ADGM, the CMA, or VARA respectively. The purpose of the comparison is not to declare a winner but to make the axes explicit, so that the decision is taken on regulator posture, codification depth, client perimeter, and recourse path rather than on licence labels.

Conclusion

The choice of jurisdiction is the choice of regulator, the choice of client perimeter, and the choice of legal recourse. The five regimes surveyed here each answer those three questions differently, and their answers do not converge over time; they diverge.

For institutional Bitcoin custody focused on the GCC, the CBB Cat-2 regime offers a particularly legible match between regulator posture, codification depth, institutional client architecture, and recourse path. ADGM and DIFC remain serious alternatives with English common-law foundations valued by cross-border counterparties, and each is strong on several of the same axes. The CMA and VARA regimes are calibrated to broader, retail-inclusive operating models, each with its own strengths, rather than to an institutional-only Bitcoin custody mandate. An institution should test this reading against its own priorities — insurance, counterparty strength, and independent diligence on the custodian itself sit alongside the regime and are not settled by the choice of jurisdiction.

The application of this reading to a specific operation, Onramp MENA’s 2-of-3 multi-institution architecture under CBB Cat-2 supervision, is treated separately on the custody architecture page.

References

  1. Central Bank of Bahrain, CBB Rulebook Volume 6, Crypto-Asset Module (CRA Module), 2024 edition. cbb.gov.bh.
  2. Abu Dhabi Global Market Financial Services Regulatory Authority, Guidance – Regulation of Virtual Asset Activities in ADGM (VER07), 18 December 2023; Conduct of Business Rulebook (COBS), Chapter 15 (Client Assets); General Rulebook (GEN), Chapter 5 (Outsourcing) and Chapter 7 (Risk Resources). adgm.com.
  3. Dubai Financial Services Authority, General Module (GEN) Rule 3A; Conduct of Business Module (COB), Rule 6.11; Prudential – Investment, Insurance Intermediation and Banking Module (PIB); Supervisory Guidelines on Assessing the Suitability of Crypto Tokens, 15 December 2025. dfsa.ae.
  4. UAE Capital Markets Authority, Decision No. 4/R.M/2026, February 2026; Federal Decree-Law No. 32 of 2025; Multilateral Competent Authority Agreement on the Automatic Exchange of Information under the Crypto-Asset Reporting Framework, signed 20 September 2025.
  5. Virtual Assets Regulatory Authority, Custody Services Rulebook; Compliance and Risk Management Rulebook; Marketing Rulebook; Technology and Information Rulebook; Exchange Services Rulebook (Version 2.0, in force from 19 June 2025; Exchange Services updated 31 March 2026), pursuant to Dubai Law No. 4 of 2022. rulebooks.vara.ae.
  6. Trowers & Hamlins LLP, Bahrain – Amendments to the Crypto Assets Rules. trowers.com.
Disclosure

This article is published as research and analysis. It does not constitute legal, regulatory, financial, or investment advice and should not be relied upon in connection with any specific transaction or licensing strategy. Readers should seek their own qualified counsel. Where specific products, providers or jurisdictions are named, they are referenced factually on the basis of public information, for analysis, and not as endorsements.