The DFSA’s updated Crypto Token framework places responsibility for assessing most Crypto Tokens directly on the firm that intends to use them.
Since 12 January 2026, the DFSA no longer maintains a general list of Recognised Crypto Tokens. Instead, a person intending to carry on specified activities involving a Crypto Token must assess that token in advance and conclude, on reasonable grounds, that it is suitable for its proposed use. The change was introduced through the DFSA’s updated Crypto Token regulatory framework. Fiat Crypto Tokens follow a separate assessment route and are addressed in another Insight in this series.
For firms operating or planning to operate in the DIFC, token suitability is therefore no longer a preliminary external check. It is an ongoing governance, risk and compliance responsibility under the DFSA Crypto Token framework.
Which activities require a Crypto Token suitability assessment?
The suitability requirement applies before a person carries on certain activities in or from the DIFC involving a Crypto Token.
These include:
- carrying on a Financial Service relating to the Crypto Token;
- making or approving a Financial Promotion relating to it;
- offering the Crypto Token to the public;
- carrying on specified activities relating to a Fund that invests in the Crypto Token; and
- carrying on relevant activities involving a derivative or other instrument linked to the Crypto Token.
The practical starting point is therefore not simply to list the tokens held or traded by the business. A firm should identify every point at which Crypto Tokens enter its products, services or operational arrangements.
Typical touchpoints may include trading, asset management and funds, investment advice, financial promotions and, subject to the specific rules and exceptions applicable to each activity, custody.
GEN Rule 3A.2.1 contains a specific exception for an Authorised Person to the extent that it Provides Custody of a Crypto Token. This does not remove the separate regulatory, due diligence, client asset and systems-and-controls requirements applicable to Crypto Token custody.
The assessment must be connected to the activity for which the token will be used. A conclusion reached for one activity does not automatically establish suitability for another. Similarly, an assessment made by one firm is not automatically sufficient for a different firm.
What must a firm consider when assessing a Crypto Token?
GEN Rule 3A.2.1 identifies five principal areas that must be considered.
The token’s characteristics
The firm should consider the purpose of the Crypto Token, its use case, governance arrangements, founders and other persons with significant influence over its development.
Relevant questions may include whether:
- the token has a clear and credible use case;
- its documentation reflects how it operates in practice;
- its founders and core developers are identifiable;
- on-chain activity can be traced and monitored;
- token ownership is concentrated in a small number of wallets; and
- the governance and consensus arrangements are adequately explained.
The DFSA’s Supervisory Guidelines provide examples of both positive and negative indicators. These are not a substitute for the firm’s own assessment, but they help clarify the type of evidence the DFSA expects firms to consider.
Regulatory status in other jurisdictions
A firm should assess how the Crypto Token and its issuer are treated elsewhere.
An express approval or classification by another Financial Services Regulator may support the assessment. A token’s listing on an overseas exchange, however, is not equivalent to regulatory approval.
The firm should also consider whether the issuer is subject to ongoing supervision and whether the token or persons associated with it have been subject to regulatory enforcement, fines or bans.
Market size, liquidity and trading history
The assessment should consider the maturity and resilience of the market for the token, including:
- market capitalisation;
- trading volumes;
- price history and volatility;
- liquidity across relevant venues;
- circulating and maximum supply; and
- whether reliable pricing information is available.
The significance of these factors depends on the proposed activity and client base. A token considered appropriate for inclusion in a closed-ended fund offered to Professional Clients may not necessarily be suitable for a firm dealing for Retail Clients.
The technology supporting the token
The firm should examine the DLT or other technology on which the token operates.
Relevant factors include the age and resilience of the network, its number and distribution of active nodes, its history of outages or attacks, and its ability to respond to cyber incidents or technical vulnerabilities.
This assessment should not be limited to the token’s white paper. It should consider available technical evidence and whether the token’s documentation is consistent with its actual operation.
The firm’s ability to comply with DFSA requirements
Even where a token appears commercially credible, the firm must consider whether using it could prevent compliance with legislation administered by the DFSA.
This means assessing the token in the context of the firm’s own regulated activities, systems, controls, customer base and compliance and risk framework.
How should the firm document its decision?
The DFSA requires the firm to be able to demonstrate the grounds on which it concluded that a Crypto Token was suitable.
A clear written suitability memorandum is therefore central to the process. It should follow a logical sequence:
- Criteria. Identify the regulatory criteria and explain how they apply to the proposed activity.
- Evidence. Record the documents, data, reports and other information reviewed.
- Decision. State the conclusion and the reasons supporting it. Where negative indicators exist, explain why the firm considers the residual risks acceptable.
- Review triggers. Identify the events that will require the assessment to be revisited.
The memorandum should be specific to the firm and the relevant activity. External research, reports and assessments prepared by another group member may support the analysis, but responsibility remains with the DIFC firm required to make the assessment.
The firm should retain the decisions made, assessments undertaken and documents reviewed or produced by those responsible for the assessment. For an Authorised Person, the record-keeping requirements in GEN Rule 5.3.24 mean the records must be capable of reproduction within a reasonable period not exceeding three business days.
What happens when the evidence includes negative indicators?
A negative indicator does not necessarily mean that a token must always be rejected.
However, the burden is on the firm to demonstrate why the token remains suitable. Its reasoning should be documented and supported by objective evidence showing how the relevant risks were identified, assessed and found to be acceptable.
A weak or generic statement that the token is widely used is unlikely to address specific concerns involving governance, liquidity, technology, financial crime or market concentration.
The decision should reflect the nature, scale and complexity of the firm’s operations and the way in which the token will be used.
Is the assessment a one-off exercise?
No. A person using a Crypto Token must continuously monitor and regularly review its assessment.
The DFSA expects a review at least once every six months and more frequently where necessary. Events that may trigger an earlier review include:
- a protocol upgrade or fork;
- a cyberattack or operational disruption;
- a material change in token supply;
- a significant change in liquidity or volatility;
- regulatory enforcement or a prohibition in another jurisdiction;
- changes to the issuer, founders or governance arrangements; or
- new information affecting the firm’s ability to comply with DFSA requirements.
If the firm is no longer satisfied that the Crypto Token is suitable, it must cease the relevant activity or, where immediate cessation is not possible, take reasonable steps to do so.
What governance arrangements should firms put in place?
The assessment should sit within a clear and robust internal process.
The firm should determine:
Who prepares the assessment?
Responsibility may involve legal, compliance, risk, technology and investment or product specialists, depending on the activity and token.
Who approves it?
The firm should identify the appropriate sign-off authority and maintain evidence of the decision.
Who monitors the token?
Ongoing ownership should be assigned to a clearly identified function or individual. Monitoring should cover the relevant legal, regulatory, market and technology risks.
When is escalation required?
The firm should establish indicators that trigger escalation, reassessment or suspension of the relevant activity.
Clear allocation of responsibility is particularly important because the firm must be able to demonstrate its reasoning to the DFSA and maintain systems and controls that support continuing compliance.
What information must be disclosed and reported?
A person carrying on relevant activities involving a non-Fiat Crypto Token must prominently disclose to existing and prospective clients a current list of the tokens it has assessed as suitable.
The list must include:
- the name and identifier of each Crypto Token; and
- the DLT or other technology on which it operates.
Authorised Persons must also submit a monthly Crypto Token information return through the DFSA electronic portal within 14 days after the end of the relevant month.
Practical DIFC Crypto Token checklist
The proposed use
Identify each Financial Service, Fund activity, promotion, offer or related product involving the token.
The assessment criteria
Address the token’s characteristics, regulatory status, market, technology and compatibility with DFSA requirements.
The supporting evidence
Maintain the white paper, technical documentation, market data, regulatory records, audit reports and other materials relied upon.
The decision
Record a reasoned conclusion specific to the firm, activity and customer base.
Governance and ownership
Assign responsibility for preparation, approval, monitoring, review and escalation.
Review triggers
Define both the regular review timetable and the events that require an immediate reassessment.
Record keeping
Retain the assessment, supporting evidence, approvals, review history and records of the persons responsible for the decision.
Client disclosure and reporting
Maintain the current public-facing list of Suitable Crypto Tokens and complete the applicable DFSA returns.
Key takeaway
Under the updated DIFC framework, most Crypto Token suitability decisions are firm-led.
The firm must:
- assess the token before using it;
- connect the assessment to its own activity and customers;
- support its conclusion with objective evidence;
- document any negative indicators;
- monitor the token on an ongoing basis; and
- maintain clear internal ownership, record-keeping and escalation procedures.
The suitability assessment should therefore be treated as part of the firm’s continuing regulatory framework, not as a one-off product approval.
Frequently asked questions
Who decides whether a Crypto Token is suitable in the DIFC?
For most Crypto Tokens, the person proposing to undertake the relevant activity must conduct its own assessment and conclude on reasonable grounds that the token is suitable. The DFSA retains the assessment role for Fiat Crypto Tokens.
Can a DIFC firm rely on another company’s token assessment?
It may take another assessment or external research into account, but the DIFC firm remains responsible for its own conclusion.
Is Crypto Token suitability the same as client suitability?
No. This assessment concerns whether a Crypto Token is suitable for use by a person in relation to a particular activity. It is distinct from a suitability or appropriateness assessment conducted for an individual client.
How often must a Crypto Token assessment be reviewed?
The DFSA expects regular review at least once every six months, with more frequent reassessment where events change the token’s features or risk profile.
What happens if a Crypto Token is no longer suitable?
The person must cease the relevant activity or, where that is not immediately possible, take reasonable steps to cease it and address the position of affected clients.
Must firms publish the tokens they have assessed as suitable?
Yes. The current list must be prominently disclosed to existing and prospective clients and include each token’s name, identifier and underlying DLT or other technology.
Does this assessment process apply to stablecoins?
Fiat Crypto Tokens follow a separate track. Their suitability is assessed by the DFSA rather than under the standard firm-led model.
Official sources
DFSA
DFSA Rulebook
- General Module — GEN Rule 3A.2.1
- General Module — GEN Rule 3A.2.1A
- General Module — GEN Rule 5.3.24 (record keeping)
- Crypto Token requirements, including Money Services restrictions
- Transitional rules relating to Crypto Tokens
Assessing Crypto Tokens for use in the DIFC
BLegal advises firms on DIFC regulatory perimeter analysis, Crypto Token assessments, internal governance frameworks and the documentation needed to support regulatory decisions.
We also assist businesses in mapping Crypto Token touchpoints across trading, custody, funds, advice and related financial services. Contact BLegal to discuss the application of the DFSA framework to your proposed activities, including any licence or permission requirements that follow.
Last reviewed: 20 January 2026
Disclaimer. This article is provided for general information only and does not constitute legal or regulatory advice. The applicable framework depends on the specific token, activities, entity structure and jurisdictions involved. Regulatory requirements and interpretations may change. Businesses should obtain advice based on their particular circumstances before making structuring, licensing or commercial decisions.