← Back to blog

Role of CBUAE in digital assets: 2026 compliance guide

July 12, 2026
Role of CBUAE in digital assets: 2026 compliance guide

TL;DR:

  • The Central Bank of the UAE regulates payment token services and stablecoins, focusing on dirham-backed instruments. Its authority includes issuance, custody, transfer, and conversion, with strict prohibitions on algorithmic and privacy tokens for domestic payments. Companies must obtain CBUAE licenses for payment token functions, even if they hold other UAE regulator approvals.

The Central Bank of the UAE (CBUAE) is the primary federal authority regulating payment token services and stablecoins in the UAE, making it the central institution shaping the role of CBUAE in digital assets across the country. Its statutory remit extends to the issuance, custody, transfer, and conversion of payment tokens under Circular No. 2/2024, the Payment Token Services Regulation. The CBUAE operates alongside VARA, the SCA, the DFSA, and the FSRA, but its mandate is distinct: it governs the payment-oriented dimension of digital assets and preserves monetary sovereignty over the dirham. For founders, compliance officers, and businesses entering the UAE's digital asset market, understanding the CBUAE's authority is not optional. It is the foundation of any compliant operating structure.

Infographic illustrating key CBUAE compliance steps

What regulatory powers does the CBUAE hold over digital assets?

Hands reviewing compliance checklist documents

The CBUAE's authority over digital assets derives from two principal instruments: Circular No. 2/2024 and Article 62 of the Federal Decree-Law, which extends the Central Bank's licensing and supervisory powers to all financial activities conducted via technological means, including blockchain and decentralised finance protocols. This means the CBUAE's reach applies regardless of whether a service is delivered through a centralised platform or a decentralised system.

The Payment Token Services Regulation covers the following licensable activities:

  • Issuance of payment tokens, specifically dirham-backed stablecoins
  • Custody of payment tokens on behalf of clients
  • Transfer of payment tokens between parties
  • Conversion of payment tokens into fiat currency or other assets

The CBUAE explicitly prohibits algorithmic stablecoins and privacy-centric tokens from use in domestic payment transactions. This prohibition is not a policy preference. It is a hard regulatory boundary under Circular No. 2/2024. Firms that attempt to use non-compliant token types for UAE payment rails face direct enforcement exposure.

The CBUAE coordinates with VARA and the SCA, but the division of responsibility is clear. VARA governs virtual asset service providers operating in mainland Dubai. The SCA oversees crypto asset activities at the federal securities level. The CBUAE holds exclusive jurisdiction over payment token services and the monetary integrity of any token used in domestic payments. Entities holding a VARA or SCA licence may still require separate CBUAE authorisation if their operations include payment token functions.

Pro Tip: If your business model includes any form of stablecoin issuance, wallet services, or payment settlement in the UAE, assume CBUAE authorisation is required and structure your licence applications accordingly from the outset.

How does the CBUAE regulate stablecoins and the Digital Dirham?

The CBUAE's stablecoin framework is built on a single foundational rule: only dirham-backed stablecoins are permitted for domestic payment transactions. Non-AED-backed tokens, including dollar-pegged stablecoins, are not authorised for use as a payment instrument within the UAE's onshore financial system. This restriction preserves monetary sovereignty and protects against the risk of foreign currency substitution in domestic commerce.

Reserve and structural requirements for licensed issuers

Licensed stablecoin issuers must meet the following requirements under the CBUAE framework:

  1. Maintain 100% fiat backing of all issued tokens at all times, held in segregated accounts separate from operational funds.
  2. Submit to regular reserve audits conducted by approved external auditors.
  3. Guarantee redemption of tokens at par value upon request by any token holder.
  4. Hold reserves in regulated financial institutions recognised by the CBUAE.
  5. Report reserve positions to the CBUAE on a schedule determined by the supervisory authority.

These requirements are not aspirational standards. They are minimum conditions for maintaining a licence. Any shortfall in reserve coverage triggers immediate supervisory intervention.

The Digital Dirham CBDC and its relationship with licensed stablecoins

The Digital Dirham is the CBUAE's own central bank digital currency (CBDC). Built on R3's Corda blockchain, it is designed to operate as sovereign digital money for both retail and wholesale applications. The Digital Dirham is not a stablecoin in the commercial sense. It is a direct liability of the Central Bank, carrying the full weight of sovereign backing.

FeatureLicensed AED-backed stablecoinDigital Dirham CBDC
IssuerLicensed private entityCBUAE (sovereign)
Backing100% fiat reserves in segregated accountsCentral Bank balance sheet
Use caseDomestic payments, commercial settlementRetail and wholesale sovereign payments
Regulatory basisCircular No. 2/2024CBUAE CBDC programme
CoexistencePermitted alongside Digital DirhamOperates as the sovereign layer

The two instruments are designed to coexist. Licensed stablecoins serve commercial payment needs, whilst the Digital Dirham provides the sovereign infrastructure layer. Businesses should not assume that the existence of the Digital Dirham removes the need for a private stablecoin licence. The two serve different functions in the payment ecosystem.

Federal Decree Law 6 of 2025 significantly extends the CBUAE's regulatory scope to cover DeFi protocols, tokenised assets, decentralised exchanges, wallets, and blockchain infrastructure. The compliance deadline for this law is september 2026. Any business operating in these categories that has not yet mapped its activities to the new federal framework is already behind schedule.

What are the key compliance obligations under CBUAE digital asset regulations?

Compliance with CBUAE digital asset regulations requires firms to address six distinct areas simultaneously. Treating these as sequential tasks is a common and costly mistake.

Licensing and governance

All payment token service providers must obtain a licence from the CBUAE before commencing operations. The application process requires a detailed business plan, a governance framework, and evidence of senior management fitness and propriety. Board members and senior executives are subject to individual assessment. The CBUAE applies the same fitness standards used for licensed banks and financial institutions.

Capital adequacy and prudential standards

The CBUAE sets minimum capital requirements for payment token service providers. These requirements vary by licence category and the volume of tokens in circulation. Firms must maintain capital buffers above the minimum at all times and submit regular prudential returns. Reserve audits are conducted independently of internal reporting, and any discrepancy between reported and audited reserves is treated as a material compliance failure.

AML/CFT and the travel rule

CBUAE AML/CFT requirements apply to all licensed payment token service providers and complement the obligations imposed under Federal AML Law (Decree-Law No. 20 of 2018 and its amendments). Firms must implement:

  • Customer due diligence (CDD) and enhanced due diligence (EDD) procedures
  • Transaction monitoring systems calibrated to virtual asset risk typologies
  • Suspicious transaction reporting to the UAE Financial Intelligence Unit (FIU)
  • Travel Rule compliance for transfers above the applicable threshold, requiring originator and beneficiary information to accompany each transaction

The travel rule obligation is particularly significant for firms operating cross-border payment token services. Non-compliance is treated as a financial crime control failure, not merely a technical breach.

Technology and custody controls

The CBUAE requires licensed firms to maintain cybersecurity frameworks aligned with recognised international standards. Custody arrangements must segregate client assets from proprietary holdings at both the legal and operational level. Hot wallet exposure must be minimised, and cold storage protocols must be documented and tested. Firms must also maintain business continuity plans and incident response procedures subject to CBUAE review.

Pro Tip: Map your custody model to the CBUAE's technology requirements before submitting a licence application. Regulators assess custody architecture as a proxy for overall operational risk management. A weak custody model will delay or prevent approval.

For a detailed overview of virtual asset platform compliance, the obligations extend beyond licensing to ongoing supervisory engagement.

How do CBUAE regulations affect cross-border activities and free zones?

The CBUAE's regulatory perimeter does not extend uniformly across all UAE jurisdictions. Financial free zones including ADGM and DIFC are excluded from certain CBUAE payment token regulations. Entities incorporated and operating within these zones may trade non-dirham-backed digital assets under the separate frameworks of the FSRA and DFSA respectively.

This creates a structural distinction that businesses must understand before selecting their operating jurisdiction.

JurisdictionRegulatorAED-backed stablecoin required?Non-AED tokens permitted?
UAE mainlandCBUAEYes, for domestic paymentsNo, for payment use
ADGM (Abu Dhabi)FSRANot applicableYes, under FSRA framework
DIFC (Dubai)DFSANot applicableYes, under DFSA framework
Dubai mainlandVARA / CBUAECBUAE rules apply for payment tokensVARA governs other VA activities

Cross-border settlement is an area of active development. Project mBridge, a multi-central-bank initiative involving the CBUAE, explores wholesale CBDC settlement across borders. This initiative signals the CBUAE's intent to extend its digital currency infrastructure beyond domestic payments into international trade settlement. Businesses engaged in cross-border payment flows should monitor mBridge developments closely, as they will shape future compliance requirements for correspondent banking and settlement services.

The importance of compliance in payments is amplified for firms operating across multiple UAE jurisdictions simultaneously. Dual licensing between CBUAE and other UAE regulators is common for firms offering integrated virtual asset and payment token services. A VARA licence does not substitute for CBUAE authorisation where payment token functions are involved, and vice versa.

Expert perspective on navigating CBUAE regulations in 2026

The most consistent mistake we see from businesses entering the UAE digital asset market is treating the CBUAE as a secondary regulator. Founders assume that a VARA licence covers their entire operation. It does not. The CBUAE holds exclusive authority over the payment layer, and that distinction matters the moment your product touches a dirham-denominated transaction.

Reserve management is the area where applicants most frequently underestimate the scrutiny involved. The requirement for 100% fiat backing in segregated accounts sounds straightforward. In practice, the CBUAE examines the legal structure of those accounts, the creditworthiness of the holding institution, and the operational controls preventing commingling. Firms that treat reserve management as a treasury function rather than a regulatory obligation consistently encounter problems at the audit stage.

Federal Decree Law 6 of 2025 changes the calculus for every business with DeFi, wallet, or tokenisation exposure. The september 2026 deadline is not a soft target. Firms that have not completed their compliance mapping by mid-2026 will face a compressed timeline for remediation. The practical advice is to begin the gap analysis now, identify which activities fall under the new federal scope, and engage with the CBUAE's supervisory team early. Regulators respond better to proactive disclosure than to last-minute applications.

The UAE's five-regulator structure is genuinely complex. But it is also genuinely navigable with the right legal architecture in place from the start.

— CRYPTOVERSE

How Cryptoverselawyers supports CBUAE compliance

Cryptoverselawyers advises clients across the full spectrum of CBUAE digital asset regulations, from initial licence structuring through to ongoing supervisory engagement.

https://cryptoverselawyers.io

The firm's team of crypto-native lawyers has direct experience with CBUAE Payment Token Services Regulation applications, reserve management frameworks, AML/CFT policy design, and board governance structures that meet the CBUAE's fitness and propriety standards. Cryptoverselawyers also advises on digital asset legal compliance across VARA, SCA, DFSA, and FSRA, making it possible to structure multi-regulator operations under a single, coherent legal framework. For businesses preparing for the Federal Decree Law 6 compliance deadline, the firm provides gap analysis, remediation planning, and regulator-ready documentation. Contact Cryptoverselawyers to begin your CBUAE compliance assessment.

FAQ

What is the CBUAE's role in digital assets?

The CBUAE is the federal regulator for payment token services in the UAE, holding exclusive authority over the issuance, custody, transfer, and conversion of payment tokens under Circular No. 2/2024. Its mandate focuses on monetary sovereignty and the integrity of dirham-denominated digital transactions.

Which stablecoins does the CBUAE permit for domestic payments?

Only dirham-backed stablecoins are permitted for domestic payment transactions in the UAE. Algorithmic stablecoins, privacy tokens, and non-AED-backed tokens are explicitly prohibited under the CBUAE's payment token framework.

Do VARA or SCA licences replace CBUAE authorisation?

No. Entities holding a VARA or SCA licence may still require separate CBUAE authorisation if their operations include payment token services. The CBUAE governs the payment layer independently of other UAE regulators.

What is the compliance deadline under Federal Decree Law 6 of 2025?

The compliance deadline under Federal Decree Law 6 of 2025 is september 2026. The law extends CBUAE authority to DeFi protocols, tokenised assets, decentralised exchanges, wallets, and blockchain infrastructure.

Are ADGM and DIFC subject to CBUAE payment token rules?

Financial free zones including ADGM and DIFC are excluded from certain CBUAE payment token regulations. Entities in these zones operate under the FSRA and DFSA frameworks respectively and may trade non-dirham-backed digital assets within those regulatory perimeters.