CGA Crypto Policy 2026: What Curaçao Operators Must Do Before June 2027

Vladyslav Drapii
Vladyslav Drapii
Published: 7 min read
Last updated:
Curaçao

The Curaçao Gaming Authority has spent the last two years reshaping what it means to hold a gaming licence on the island. The new licensing framework, stricter change-of-control requirements, and enhanced AML obligations have already changed the baseline for operators. As of June 2026, a new chapter opens: mandatory crypto governance for every licensed company group that processes virtual asset transactions.

This is not a future concern. The clock is already running.

What the new crypto policy actually requires

The CGA’s updated framework aligns Curaçao’s virtual asset handling with global AML/CFT standards — the same standards that FATF, the EU’s MiCA regulation, and most mature jurisdictions now apply to crypto activity. In practical terms, this means every licensee that touches crypto — whether for deposits, withdrawals, treasury management, or intercompany transfers — must now govern that activity through a documented, approved internal policy.

The policy is not a template you fill in. It has to reflect the actual structure of the company group: which wallets are used, which Virtual Asset Service Providers (VASPs) the business relies on, what the transaction flows look like, and how AML controls are applied at each point. The CGA portal is the submission channel, and submissions are reviewed, not filed and forgotten.

For the licensing backdrop, see our guide to the Curaçao licensing process.

The compliance timeline: three checkpoints

The CGA has structured the rollout in three stages, which gives operators a roadmap — but also means there is no single “compliance date” to aim for. Each stage has its own deadline, and missing the first one creates a cascade.

Within 3 months of June 2026 — crypto policy submission

Licensees must submit their crypto governance policy through the CGA portal. This document covers the company’s approach to virtual assets, the controls in place, and the organisational structure responsible for overseeing them. Companies that have not yet mapped their crypto activity should treat this deadline as urgent: the drafting process alone — if done properly — takes several weeks.

Within 6 months of June 2026 — risk assessment, VASP due diligence, staff training

By December 2026, operators must complete a formal risk assessment of their crypto-related operations and conduct due diligence on all VASP partners. This means knowing — and documenting — the compliance standing of every exchange, payment processor, or custodian the business works with. The FATF Travel Rule requirements apply here: counterparty VASPs must be identified and vetted.

Alongside this, staff involved in any part of the crypto workflow need to be trained. The CGA’s expectation is not a box-ticking exercise but demonstrated understanding of AML/CFT obligations specific to virtual assets.

By June 2027 — full operational compliance

The final stage requires three things to be in place simultaneously: wallet segregation (client funds in wallets distinct from operational funds), blockchain analytics tooling (transaction monitoring that can identify suspicious patterns, mixer usage, or high-risk wallet interactions), and transaction reconciliation procedures that create a complete, auditable record.

This is the stage that most commonly catches operators off guard, because each of these three elements requires its own implementation effort, and they are interdependent. You cannot meaningfully reconcile transactions without analytics. You cannot rely on analytics if wallets are not segregated. The sequence matters.

The bigger picture: CGA is no longer a passive regulator

It would be a mistake to treat this as a standalone crypto requirement. The crypto policy framework is part of a broader shift in how the CGA operates. The same pattern appeared in the change-of-control rules introduced earlier: rather than relying on operators to self-report material changes, the CGA now expects documentation, advance notice, and formal approval at each significant step.

What used to be a relatively permissive jurisdiction — one that many operators chose precisely for its light-touch approach — is becoming an active supervisory authority. The expectations are rising, the documentation requirements are increasing, and the consequences of non-compliance are no longer theoretical. Licence suspensions and revocations have become real enforcement outcomes, not just policy language.

Operators who have built their compliance function around Curaçao’s old reputation will find the new environment more demanding. Those who update their internal frameworks now — ahead of each deadline, not in response to it — will find the process manageable.

This sits alongside the broader regulatory overhaul — see our analysis of Curaçao’s LOK reform.

What to do right now

If your company group holds a Curaçao gaming licence and processes any crypto transactions, the immediate priority is an internal audit of your current position:

Which wallets does the group operate, and how are they structured? Are client funds already segregated? Which VASPs do you rely on, and have any of them been assessed against FATF criteria? Is there a designated person responsible for virtual asset compliance, or does the function sit loosely across the finance and compliance teams?

The answers to these questions will determine how much work the September 2026 submission requires — and whether the December 2026 and June 2027 deadlines are achievable on your current trajectory.

Starting the process in August rather than September is not conservatism. It is the difference between a managed submission and a rushed one.

Frequently Asked Questions

What is the CGA crypto policy and who has to submit it?

Any company group holding a Curaçao gaming licence that processes virtual asset transactions — deposits, withdrawals, treasury, or intercompany — must submit a formal crypto governance policy to the CGA portal within three months of June 2026. This applies regardless of the volume of crypto activity.

Does this apply if crypto is only a small part of our payment mix?

Yes. The CGA’s framework does not include a de minimis threshold. If the company group touches virtual assets in any operational context, the policy, risk assessment, and June 2027 technical requirements all apply.

What counts as a VASP under the new framework?

A Virtual Asset Service Provider is any entity that offers exchange, transfer, custody, or issuance of virtual assets on behalf of others. This includes exchanges, payment processors that handle crypto, and custodians. All VASP counterparties must be identified and due-diligenced by December 2026.

What does wallet segregation actually mean in practice?

Client funds held in crypto must be kept in wallets that are separate from the operator’s own operational or treasury wallets. The segregation must be documented, auditable, and verifiable through the blockchain analytics tooling the operator implements.

What happens if we miss the September 2026 submission deadline?

Non-compliance with CGA regulatory requirements is grounds for formal supervisory action, including licence suspension. Given the CGA’s shift toward active enforcement, treating this deadline as approximate is a significant risk.

The timeline is not flexible. Your preparation can be.

Curaçao remains a commercially viable and well-recognised jurisdiction for online gaming. The new crypto compliance requirements do not change that — but they do change what it takes to operate there responsibly. Operators that approach these deadlines as a compliance exercise will get through them. Those that approach them as a governance upgrade will come out stronger.

Legarithm works with Curaçao-licensed operators on crypto policy drafting, VASP due diligence frameworks, and June 2027 readiness assessments — see our Curaçao gaming licence service. If you want to understand where your current setup stands before the September deadline, reach out via Telegram or WhatsApp.

This article is general information, not legal, tax, or compliance advice. Rules change — confirm current requirements with the regulator or a qualified adviser. See our Editorial Policy.

Source: FATF (Financial Action Task Force).