Stop Delays: NYDFS BitLicense Requirements NMLS Ready for Counsel

If your business touches virtual currency and involves New York or a New Yorker, you almost certainly need a BitLicense. Under 23 NYCRR Part 200, five specific activities trigger the requirement, and once you’re in scope, you’re signing up for NMLS filing, a Superintendent-set capital number, a customer-protection bond or trust account, a board-approved AML program, and full Part 500 cybersecurity compliance. There’s no partial version of this.
TL;DR:
- Out-of-state firms onboarding New York residents are fully subject to the BitLicense requirements, regardless of where they are incorporated.
- The minimum capital benchmark is roughly $500,000 for small firms, with larger companies often needing above $2 million, but the actual amount depends on risk and volume.
- Robust AML, cybersecurity, and business continuity plans, with detailed control mapping and documented testing, are crucial to avoid application delays.
- Incomplete or generic documentation, especially in AML programs, cybersecurity policies, and control person background checks, accounts for most licensing timeouts.
- Building a comprehensive evidence repository and early planning for key documents like AML manuals and cybersecurity controls significantly accelerates approval processing.
Table of Contents
- What Are the NYDFS BitLicense Requirements and Who Actually Needs One?
- Core BitLicense Requirements: Capital, Bonding, AML, Cybersecurity, and More
- How to Apply for a BitLicense: NMLS Filing Steps and Timeline
- Trust Charter or BitLicense: Which Fits Your Business Model?
- What Happens After Approval: Supervision, Reporting, and Governance
- The Application Mistakes That Cost the Most Time
- How DARE Readiness Evaluations Map to the BitLicense Checklist
- Why Most BitLicense Advice Focuses on the Wrong Thing
- Sources
What Are the NYDFS BitLicense Requirements and Who Actually Needs One?
The BitLicense requirement applies to anyone conducting “virtual currency business activity” that touches New York State or a New York resident. That single sentence has generated more compliance headaches than almost any other line in U.S. crypto regulation, mostly because “touches New York” is a lower bar than most founders assume. You don’t need an office in Manhattan. One customer with a New York address can pull your entire platform into scope.
Section §200.2(q) defines five activities that trigger licensure:
- Receiving virtual currency for transmission or transmitting it, except for non-financial purposes.
- Storing, holding, or maintaining custody or control of virtual currency on behalf of others.
- Buying and selling virtual currency as a customer business (as opposed to personal trading).
- Performing exchange services as a customer business.
- Controlling, administering, or issuing a virtual currency.
Each one has real-world edge cases. A payments company routing stablecoins for merchants is transmitting. A custodian holding wallet keys for institutional clients is custodying. A market maker quoting two-sided prices to retail customers is exchanging. None of that is exotic; it’s the daily operation of most digital asset businesses that serve New York customers.
What doesn’t trigger the license is just as important. Merchants and consumers who use virtual currency to buy goods or services are exempt. Pure software developers who build wallets, protocols, or infrastructure without taking custody or facilitating transactions for others generally fall outside the definition. Mining, standing alone, isn’t automatically licensable activity, though miners who also custody or exchange on behalf of third parties can trip into scope through a different door. Private, noncommercial transfers between individuals don’t count either.
Out-of-state and even non-U.S. firms aren’t off the hook. If a Delaware-incorporated exchange onboards New York residents, New York’s jurisdictional reach applies regardless of where the company is headquartered. This is the single most common misunderstanding among founders building outside New York: geography of incorporation is irrelevant. Geography of the customer is what matters.
Core BitLicense Requirements: Capital, Bonding, AML, Cybersecurity, and More
Once you’ve confirmed you’re in scope, the real work starts. NYDFS evaluates BitLicense applicants and licensees across seven interlocking areas, and weakness in any one of them can stall an application or trigger supervisory action later.
Capital determination and the customer-protection bond
Section §200.8 requires the Superintendent to determine adequate capital on a case-by-case basis, factoring in the nature and volume of your business, the risk profile of your activities, and your customer base. There’s no published formula. Market guidance commonly cites a starting floor around $500,000 for smaller applicants, with mid-size operations often modeling closer to $2 million and large custodians well above $10 million, but treat these as planning scenarios, not statutory numbers. The Superintendent’s discretion under §200.4 means your actual figure could land anywhere depending on your transaction volume and risk exposure.

Paired with capital is §200.9’s requirement for a customer-protection instrument, typically a surety bond or trust account sized to cover customer virtual currency and cash holdings. NYDFS wants to see that if your business fails, customer funds are recoverable independent of your general balance sheet.
Pro Tip: Build your capital and bond justification around three documented scenarios (conservative, expected, and stress case) rather than a single number. Examiners respond better to a modeled range with assumptions than a flat figure with no backup.
AML and BSA program
NYDFS expects a written, board-approved anti-money-laundering program mapped explicitly to Bank Secrecy Act and FinCEN obligations, not just a generic policy pulled from a template, as outlined in AITHEA’s AI-powered AML and compliance consulting resources. That means a designated BSA officer, ongoing transaction monitoring, suspicious activity reporting procedures, customer due diligence tiers, and periodic independent testing. Examiners will ask who approved the program, when it was last updated, and how alerts get escalated.
Cybersecurity under Part 500
This is where BitLicense compliance and 23 NYCRR Part 500 (New York’s separate cybersecurity regulation) intersect directly. Because virtual currency licensees are covered entities under Part 500, you need:
- A designated Chief Information Security Officer (CISO), whether in-house or a qualified third party.
- Multi-factor authentication for internal and third-party access to sensitive systems.
- Encryption of nonpublic information, at rest and in transit.
- An annual cybersecurity certification submitted to NYDFS confirming compliance.
- A 72-hour notification requirement for qualifying cybersecurity events.
Generic cybersecurity policies are the single most common failure point here. NYDFS wants controls mapped to your actual systems and data flows, with named individuals responsible for each control and evidence of testing like penetration tests or tabletop exercises available on request. A policy that says “we encrypt sensitive data” without naming which systems, which encryption standard, and who verifies it will bounce back with a deficiency letter.
Business continuity and disaster recovery
Your BCP/DR plan needs to address system outages, cyber incidents, and operational disruptions with defined recovery time objectives. NYDFS expects periodic testing, not a document that sits untouched after approval.
Consumer disclosures and recordkeeping
Licensees must give customers clear disclosures on fees, risks, and liability for unauthorized transactions before they transact. Recordkeeping rules require retention of transaction and compliance records in native format for a baseline of seven years, accessible for examination on request.
A licensee’s compliance posture is judged as much by document retrieval speed during an exam as by the policies themselves. Firms that can pull a specific transaction record in minutes tend to move through supervisory review far faster than those digging through email threads.
Reporting and examination scope
Reporting isn’t a one-time event. NYDFS conducts periodic examinations that can extend to affiliate records where the affiliate’s operations bear on the licensee’s compliance, and the frequency of these examinations often correlates with a licensee’s transaction volume and prior deficiency history.
How to Apply for a BitLicense: NMLS Filing Steps and Timeline
Applications for virtual currency business activity licenses run through the Nationwide Multistate Licensing System (NMLS), the same infrastructure used for state money transmitter licensing across the country. Here’s the sequence that actually gets applications through review.
- File the MU1 company form on NMLS, covering entity structure, ownership, business model, and financial condition.
- File MU2 forms for every control person, including background information, employment history, and consent for fingerprint-based background checks.
- Pull the NY Virtual Currency Business Activity (VCBA) checklist from NMLS and treat it as your master document tracker, not a formality to skim once.
- Assemble high-priority attachments: audited financial statements, tax verification, completed background checks for all control persons, your written AML manual, a Part 500 cybersecurity control mapping, your BCP/DR plan, and evidence of your surety bond or trust commitment.
- Pay the $5,000 application fee at filing. This is a flat statutory cost; your real expense driver is everything around it, legal counsel, audit fees, staffing for compliance functions, and the capital and bond amounts the Superintendent ultimately sets.
- Respond to the informational completeness review. NYDFS won’t begin substantive review until your application is deemed informationally complete. Incomplete files sit in a queue rather than move forward.
- Address deficiency letters promptly. NYDFS issues these when specific items are missing or inadequate; multiple unresolved cycles can lead to denial.
- Watch for a conditional license option. Under §200.4, the Superintendent has discretion to issue conditional licenses, sometimes through a partnership arrangement with an already-licensed entity, while a full application matures.
Timelines vary enormously based on how complete your first submission is. Applicants who front-load a pre-submission internal audit, engage experienced regulatory counsel, and proactively communicate with DFS staff during preparation tend to move faster than those who file first and fix later.
Pro Tip: Draft your BSA/AML manual and Part 500 cybersecurity mapping before you touch the NMLS forms. These two documents cause more deficiency letters than any other part of the file, and they take the longest to build properly.
Trust Charter or BitLicense: Which Fits Your Business Model?
Not every digital asset business needs a BitLicense. New York also offers a limited-purpose trust company charter under the Banking Law, and for certain business models it’s the smarter path.
- A trust charter grants fiduciary powers, letting you act as custodian, trustee, or fiduciary for digital assets, and it can avoid the need for a separate money transmitter license depending on your activity mix.
- BitLicense fits narrower crypto-native activities, exchange, transmission, custody, without fiduciary ambitions.
- Trust charters suit custody-heavy or fiduciary-services businesses, think institutional custodians or firms offering trust administration alongside digital asset services.
- BitLicense suits firms whose core business is transacting in virtual currency rather than holding assets in a fiduciary capacity.
If you’re unsure which route fits, the right first move is mapping every product feature you plan to launch against §200.10’s material-change rules. A business that starts narrow and adds custody or new asset classes later will need approval for each material change regardless of which charter it holds, so it pays to model your two-year product roadmap before choosing the licensing route, not after.
What Happens After Approval: Supervision, Reporting, and Governance
Getting licensed is the beginning of an ongoing relationship with NYDFS, not the finish line.
- Quarterly and annual financial reports keep the Superintendent’s capital determination current as your business scales.
- A supervisory assessment fee funds NYDFS’s oversight function and is billed to licensees based on examination and regulatory costs attributable to your business.
- Annual cybersecurity certification under Part 500 must be resubmitted every year, confirming your program still matches your actual systems.
- Coin-listing and coin-delisting policies need NYDFS approval before you can self-certify new virtual currencies for New York customers, and any update to those policies also requires review.
- Material changes to your business, ownership, or product line trigger a separate approval process under §200.10.
- Examinations can reach into affiliate records where affiliate operations bear on your compliance posture, and their frequency tends to track transaction volume and any history of deficiencies.
Boards that treat licensure as a live governance obligation, with regular executive attestations and an internal audit cadence tied to the annual cybersecurity certification, tend to handle supervisory requests with far less scrambling than boards that revisit compliance only when a letter arrives.
The Application Mistakes That Cost the Most Time
NYDFS guidance is consistent about where applications stall: BSA/AML gaps, weak cybersecurity mapping, and incomplete background checks account for most deficiency letters.
- Missing or unaudited financial statements. Get audited financials done before you file, not after a deficiency letter asks for them.
- AML programs that don’t map to specific FinCEN obligations. Generic templates get flagged fast.
- Cybersecurity policies with no named systems or control owners. Tie every Part 500 control to a specific system and a specific person.
- Incomplete MU2 filings or missing fingerprint documentation for control persons. Track this per person, not as a single checklist line.
Remediation moves faster when one person owns the entire process, a compliance evidence repository holds every document with version control, and the team runs a mock review internally before submitting anything to NYDFS.
Pro Tip: Assign a single application owner with authority to pull documents from legal, finance, and security teams on demand. Applications that stall usually have three or four people each owning a piece, with no one accountable for the whole file.
How DARE Readiness Evaluations Map to the BitLicense Checklist
Some digital asset readiness evaluations cover control categories similar to those NYDFS checks: governance, AML program design, cybersecurity mapping, BCP/DR, and documentation management. Each module produces the kind of organized evidence trail examiners look for, executive attestations, a remediation tracker, and version-controlled policy documents, rather than a scattered folder assembled the week before filing.
An annual renewal cycle for readiness evaluations can help teams avoid rebuilding their compliance file from scratch every year. For firms preparing an application or maintaining an existing license, such a structure can help create a repeatable evidence-organization habit. Wush’s readiness guidance on licensing requirements and its AML compliance checklist walk through the same mapping in more detail.
Why Most BitLicense Advice Focuses on the Wrong Thing
Most guides to this process obsess over the $5,000 filing fee and the capital number, as if the hard part is writing a check. It isn’t. The hard part is informational completeness, and NYDFS has said as much directly: applications don’t even enter substantive review until the file is complete, which means a sloppy submission doesn’t just risk denial, it risks sitting untouched for months before anyone at DFS reads it closely.

The conventional advice, “hire a lawyer and file,” undersells how much of this is document logistics. The applicants who move fastest treat the NY VCBA checklist as a project plan with a named owner per line item, not a form to fill out once. They build their AML manual and Part 500 cybersecurity mapping before touching NMLS, because those two documents generate the most deficiency letters industry-wide.
If there’s one thing to prioritize first, it’s building an evidence repository before you write a word of the application narrative. A structured readiness evaluation, whether internal or through a program like DARE, forces that discipline early instead of after the first deficiency letter arrives.
— Gregg
Sources
- Virtual Currency Business Licensing | Department of Financial Services
- N.Y. Comp. Codes R. & Regs. Tit. 23 § 200.4 - Application
- Notice of Virtual Currency Business Activity License Application Procedures | NYDFS (June 24, 2020)
