FOR SALE: B2B Malta Gaming Licence (MGA) | issued in 2024 | valid for 10 years | active bank account | FOR SALE: B2C Malta Gaming Licence (MGA) | Type 1 Casino | active bank account | licence renewal July 2026 | FOR SALE: Curacao Gaming Licence (CGA) | Curacao entity | CY payment agent | active bank account |

Contact Us

Curacao Crypto Policy for B2C Gaming Operators 2026

Explore the Curacao crypto policy and understand its impact on digital currencies. Stay informed about emerging regulations.

A Curacao crypto policy is a mandatory compliance document for any B2C operator that accepts cryptocurrency, and the Curacao Gaming Authority (CGA) now requires it under the National Ordinance on Games of Chance (LOK). If you take deposits or pay withdrawals in Bitcoin, Ethereum, stablecoins, or any other digital asset, you must hold a CGA-compliant crypto policy and reflect crypto-specific terms in your player terms and conditions. The CGA sets a phased deadline running to mid-2027 for full compliance. This guide explains who needs a crypto policy, what the document must contain, how wallet and token rules work, and how the requirement connects to the terms and conditions you publish to players.

Key takeaways

  • Every Curacao B2C licensee that offers crypto payments must hold a crypto policy that meets the CGA requirements.
  • A licensee may accept crypto only for gambling. It cannot act as a crypto exchange, custodian, or virtual asset service provider.
  • The CGA requires wallet segregation into operational, treasury, and player-flow wallets, and it prohibits personal wallets and wallets linked to ultimate beneficial owners.
  • Sanctioned wallets, mixers, and exchange-style activity are prohibited outright.
  • Your player terms and conditions must address crypto funds on account closure, crypto remittance, and prize money paid in cryptocurrency.
  • The compliance timeline is staggered: a crypto policy filed within three months, risk assessments and training within six months, and full compliance by mid-2027.
  • A Curacao licence does not grant access to the EU, the UK, or the United States. Those markets require their own authorisations.

Do Curacao B2C operators need a crypto policy?

Yes. If your brand accepts cryptocurrency from players in any form, the CGA requires a crypto policy as part of your compliance framework. The requirement flows from the LOK, which came into force on 24 December 2024, and from the licence conditions the CGA attaches to every B2C authorisation. The policy sits alongside your AML programme, your responsible gaming policy, and your player terms and conditions.

The obligation applies to the operating company and to any group entity involved in crypto transactions. It covers deposits, withdrawals, and any prize money settled in digital assets. If you operate several brands or domains under one licence, each one that touches crypto falls inside the same requirement.

Operators that accept fiat only do not need a crypto policy, though they still meet the CGA’s standard AML, KYC, and terms and conditions rules. If you plan to add crypto payments later, build the policy before you switch the payment method on rather than after. For the wider licence context, see our guide to the Curacao B2C gaming licence and the steps that sit around this obligation.

What the CGA crypto policy covers

The crypto policy sets out how you handle digital assets across their full lifecycle, from the moment a player deposits to the point you pay a withdrawal. The CGA expects the document to reflect your real operations, not a generic template. A compliant policy addresses the following areas at minimum:

  • The scope of your crypto activity and confirmation that you accept crypto for gambling only
  • Which digital assets you accept and how you assess each one for risk
  • Wallet structure and segregation, with named controls over who can access each wallet
  • Blockchain analytics and screening applied at both deposit and withdrawal
  • Transaction monitoring, reconciliation, and record-keeping that supports an audit
  • Due diligence on any virtual asset service provider or third party in your crypto flow
  • Sanctions and PEP screening of player wallets and counterparties

One point defines the whole framework. A Curacao licensee accepts crypto to let players gamble. It does not exchange one asset for another as a service, hold assets on behalf of players as a custodian, or perform virtual asset service provider functions. Your policy states that boundary and your operations stay within it. The FATF’s standards on virtual assets and virtual asset service providers set the international baseline the CGA aligns with, including customer due diligence, record keeping, and suspicious transaction reporting.

Wallet segregation and banned practices

The CGA requires you to separate crypto holdings by function rather than pool them in one place. The policy divides wallets into three types:

  • Operational wallets handle day-to-day transactions.
  • Treasury wallets hold strategic reserves.
  • Player-flow wallets process player deposits and withdrawals.

Segregation gives the regulator a clear view of where player money sits and keeps it distinct from company funds. You document who controls each wallet, how access is granted, and how balances reconcile.

Several practices are prohibited. You cannot use personal wallets for any part of the operation, and wallets linked directly to ultimate beneficial owners are banned. You cannot process transactions to or from sanctioned addresses. Mixers or tumblers that obscure the source of funds cannot be used. You cannot run exchange-style activity where players swap assets outside the act of gambling. Building screening that catches these cases at the point of deposit and withdrawal is the practical way to hold the line. Your banking and payment partners will ask about the same controls, which is one reason choosing a bank for a gaming business gets easier when your crypto controls are already documented.

Restricted tokens and blockchain analytics

Not every token clears the same way. The CGA singles out privacy coins, meme coins, and wrapped tokens of unclear origin as assets you must either assess or exclude. If you want to accept a token in one of these categories, your policy needs a documented assessment that shows how you judged its risk and why you can monitor it. If you cannot support that assessment, you exclude the token. Recording the reasoning matters as much as the decision, because the CGA can review it.

Manual checks do not meet the standard on their own. The CGA expects blockchain analytics capability that runs wallet screening, risk scoring, and transaction monitoring at the time of both deposit and withdrawal. In practice that means a screening tool that flags exposure to sanctioned addresses, mixers, and high-risk services before funds move. You apply the same AML and KYC discipline to crypto that you apply to fiat: identity verification, source-of-funds checks where risk indicators appear, and reporting of suspicious activity. Crypto oversight continues to tighten worldwide, and the European Union’s framework for crypto-assets now places crypto-asset service providers among obliged entities for AML purposes, which shapes what banks and processors expect from you too.

How crypto obligations appear in your player T&Cs

The crypto policy is an internal compliance document. Players see the terms and conditions, while the CGA Policy Guideline on Terms and Conditions for B2C Operators, issued in April 2026, explains how crypto must appear there. The two documents work together. The policy governs operations, and the terms and conditions explain the crypto rules to players.

Your terms and conditions must address several crypto points directly:

  • Any specific terms on crypto funds, deposits, and withdrawals, stated as subject to the CGA crypto policy.
  • What happens to funds in a player account, fiat or crypto, when an account is suspended or terminated, and the process for returning them.
  • Crypto-specific remittance situations, including delisted tokens, chain forks, and sanctioned or blocked addresses, plus what happens when a wallet is lost, unavailable, deactivated, or non-compliant.
  • Whether prize money is credited in the same currency the bet was placed in, including cryptocurrencies.
  • Identity verification tied to withdrawals, particularly where cumulative deposits and withdrawals exceed XCG 4,000, which is around EUR 2,000.

Your terms and conditions must also state that the licensee is not a financial institution and pays no interest on deposited funds. The current version has to be uploaded to the CGA portal, with every brand version submitted where terms differ. Keep the policy and the published terms aligned: when one changes, update the other. For the data-handling side of the same rulebook, our guide to gaming operator data protection compliance covers the retention and disclosure duties that run alongside these terms.

Curacao crypto policy comparison chart showing fiat-only and crypto-enabled operator compliance requirements.
Curacao crypto policy requirements add crypto-specific controls on top of standard B2C gaming compliance obligations.

Compliance timeline and the 2027 deadline

The CGA phases the crypto requirements rather than switching them on at once. The requirements take effect from June 2026, and licensees have a staggered path to full compliance. The table below sets out the stages.

StageWhat you complete
Within 3 monthsSubmit a compliant crypto policy to the CGA portal.
Within 6 monthsComplete risk assessments, due diligence on virtual asset service providers, and staff training on the new requirements.
Within 12 months (mid-2027)Reach full compliance: wallet segregation, blockchain analytics, transaction reconciliation, and audit-ready records.

Two points sit outside the headline dates. The CGA can require faster action where significant risks emerge. Therefore, the staggered path is a maximum window, not a guaranteed grace period. Internal work behind each stage also takes time. This includes selecting a blockchain analytics tool, restructuring wallets, writing procedures, and training staff before the deadline arrives. Treat the three-month policy filing as the near-term task and start the operational build in parallel. New operators applying now should prepare the crypto policy as part of the application rather than after licensing, a sequence we cover in the Curacao online gaming licence guide.

What crypto compliance costs to set up

The crypto policy itself carries no CGA filing fee separate from your licence, but meeting the standard has real costs that sit outside the headline licence tariff. Budget for these categories from the start:

  • Blockchain analytics subscription. A screening and monitoring tool priced by transaction volume or on an annual licence.
  • Policy and terms drafting. Legal preparation of the crypto policy and the crypto clauses in your player terms and conditions.
  • VASP and counterparty due diligence. Checks on any third party in your crypto flow.
  • Compliance officer time. Ongoing monitoring, reconciliation, and reporting.
  • Staff training. Bringing operations and support teams up to the required standard.
  • Wallet infrastructure. The technical setup that keeps operational, treasury, and player-flow wallets separate and controlled.

These are recurring in most cases, not one-off. The analytics subscription, the compliance officer, and the audit-record keeping continue for as long as you accept crypto. Public guides tend to list these as “varies by provider” and stop there, which understates the planning they need. Price them against your expected transaction volume before you commit to a crypto launch, and factor the recurring cost into your operating model rather than your setup budget alone.

Common mistakes that delay crypto compliance

Most delays come from the same handful of gaps. A generic crypto policy often causes problems when it does not match the actual wallet structure or token list. The CGA reviews the document against live operations, so the policy must reflect the real setup. Weak AML controls are another common issue. This happens when crypto is treated as an afterthought instead of applying full transaction monitoring and screening.

Other recurring issues include restricted tokens, such as privacy coins, staying on the deposit list without a documented assessment. Some operators also rely on manual checks instead of blockchain analytics. Others publish player terms and conditions that do not explain crypto remittance or crypto funds on account closure. In addition, operators often underestimate the time needed to select and integrate an analytics tool. As a result, the six-month and twelve-month stages can arrive before the build is ready.

The fix in each case is the same: align the written policy, the published terms, and the live operation so all three say the same thing. If crypto and the choice of Curacao versus another jurisdiction depend on your specific model, book a consultation rather than deciding from a checklist. Operators weighing a crypto-first offshore route also look at the Mwali crypto casino gaming licence alongside Curacao, and the right fit depends on your target markets and payment mix.

Frequently asked questions

Do Curacao B2C operators need a crypto policy?

Yes. Any B2C licensee that accepts cryptocurrency for deposits, withdrawals, or prize money must hold a crypto policy that meets the Curacao Gaming Authority requirements. Operators that accept fiat only do not need one, though they still meet the standard AML, KYC, and terms and conditions rules.

What must a Curacao crypto policy contain?

It must set out the scope of your crypto activity, the assets you accept and how you assess them, your wallet segregation, blockchain analytics and screening at deposit and withdrawal, transaction monitoring and reconciliation, and due diligence on any virtual asset service provider. The document has to reflect your real operations rather than a generic template.

When is the Curacao crypto policy deadline?

The requirements take effect from June 2026. Licensees submit a compliant crypto policy within three months, complete risk assessments and staff training within six months, and reach full compliance by mid-2027. The Curacao Gaming Authority can require faster action where significant risks emerge.

Can a Curacao licensee act as a crypto exchange or custodian?

No. A licensee may accept crypto only for gambling. It cannot operate as a crypto exchange, hold assets as a custodian, or perform virtual asset service provider functions. The crypto policy states that boundary and operations must stay within it.

Which crypto wallets are banned under the CGA crypto policy?

Personal wallets and wallets linked directly to ultimate beneficial owners are prohibited, as are sanctioned addresses and mixers. The Curacao Gaming Authority requires wallets to be segregated into operational, treasury, and player-flow structures, each with documented access controls.

How must crypto obligations appear in player terms and conditions?

Under the CGA Policy Guideline on Terms and Conditions for B2C Operators, your terms must cover crypto deposits and withdrawals as subject to the crypto policy, what happens to crypto funds on account closure, crypto remittance situations such as delisted tokens and blocked addresses, and prize money paid in cryptocurrency. The current terms must be uploaded to the CGA portal.

Are privacy coins and meme coins allowed?

The Curacao Gaming Authority treats privacy coins, meme coins, and wrapped tokens of unclear origin as assets you must either assess or exclude. To accept one, you need a documented risk assessment showing how you judged and can monitor it. Without that assessment, you exclude the token.

Does the crypto policy apply if we only accept fiat?

No. The crypto policy applies to operators that accept cryptocurrency. If you accept fiat only, you meet the standard AML, KYC, responsible gaming, and terms and conditions requirements without a separate crypto policy. Build the policy before you add crypto payments if you plan to accept them later.

Not sure which licence is right for your situation?

Book a consultation and get a clear jurisdiction recommendation for your situation.

Get a Recommendation

Share this article

← Back to iGaming News
Denitza Dimitrova, Managing Partner

Reviewed by Denitza Dimitrova, Managing Partner. Former Manager for Legal and Enforcement at the Malta Gaming Authority. About the team