JFSA Crypto Asset Exchange Service Provider Registration
Executive summary
Japan was the first major economy to formally license cryptocurrency exchanges. The Payment Services Act amendment effective April 2017 created the Crypto Asset Exchange Service Provider (CAESP) registration regime, predating MiCA by seven years. The Coincheck hack of January 2018 — 532 million dollars in NEM stolen from an unregistered legacy operator — triggered the post-2018 reform programme that reshaped the regime: enhanced asset-segregation rules, the Japan Virtual and Crypto Assets Exchange Association (JVCEA) self-regulatory body in 2018, the 2020 separation of crypto-derivatives into the Financial Instruments and Exchange Act perimeter, the 2023 Travel Rule implementation, and the 2023 stablecoin-issuance regime under the same statute. As of Q1 2026 the JFSA register lists approximately 30 active CAESPs, the post-Coincheck stable-yen-banking architecture remains intact (real-name banking accounts, asset segregation in trust accounts), and the regime has produced one of the lowest hack-loss rates of any major exchange jurisdiction since 2019. The Japanese regime is widely regarded as the most operationally rigorous of any G20 crypto framework but commercially restrictive — pre-listing token review through JVCEA produces a narrow approved-token list and slow new-asset onboarding.
Statutory architecture
The CAESP regime sits in Articles 63-2 through 63-22 of the Payment Services Act (Act No. 59 of 2009 as amended), inserted by the 2016 amendments effective 1 April 2017 and substantially expanded by subsequent amendments. Article 63-2 requires registration with the Prime Minister (delegated to the Commissioner of the Financial Services Agency) for any person engaged in the business of crypto-asset exchange in Japan. The statute defines crypto-asset exchange business as one or more of (a) sale, purchase, or exchange of crypto-assets, (b) intermediation, brokerage, or agency for such transactions, (c) management of customer funds in connection with such transactions, and (d) management of crypto-assets for the benefit of third parties. The 2020 amendments (Act No. 28 of 2019, effective 1 May 2020) carved out crypto-derivatives from the PSA perimeter and placed them under the Financial Instruments and Exchange Act (FIEA), Article 2(24), creating a separate Crypto-Asset Derivatives Business Operator registration. The 2023 amendments (effective 1 June 2023) implemented the FATF Travel Rule with a 100,000-yen threshold (approximately 750 dollars at current rates), introduced the Stablecoin Issuance Business registration as a category of fund-transfer service under PSA Articles 36-2 through 36-15, and tightened asset-segregation rules requiring customer crypto-assets to be held in cold storage for at least 95 percent of the total customer balance. The 2025 amendments further enhanced asset-segregation requirements and introduced a JFSA-mandated insurance scheme covering certain customer losses. JVCEA — the Japan Virtual and Crypto Assets Exchange Association — operates as a Type 2 Self-Regulatory Organisation under PSA Article 87 and exercises substantial delegated authority over token-listing standards, advertising rules, and member-firm operational standards. JVCEA membership is in practice mandatory for CAESP registration, and the Association's pre-listing review is the gating mechanism for any new token to be offered to Japanese retail.
License tiers and categories
The PSA crypto perimeter recognises four registration categories. CAESP registration under Article 63-2 covers exchange, intermediation, custody, and pooled-fund management activities. Crypto-Asset Derivatives Business Operator registration under FIEA Article 2(24) covers margin trading, perpetual futures, and other derivative products; this is a separate registration with separate capital, organisational, and conduct requirements. Stablecoin Issuance Business registration under PSA Articles 36-2 through 36-15 (or equivalent fund-transfer service registration for trust-bank issuance) covers JPY-pegged or foreign-currency-pegged stablecoin issuance and is restricted to (a) banks, (b) trust banks operating under the Trust Business Act, and (c) registered fund-transfer service providers operating under PSA fund-transfer service category 1, 2, or 3. NFT Business activities sit outside CAESP registration where the asset qualifies as a 'non-fungible token' under JFSA's June 2023 guidance — substantially limited to genuinely unique items with no settlement or payment use case — but the perimeter is narrower than industry advocates had hoped. The token-listing regime is administered through JVCEA: any new asset must complete the Association's Green List or White List review before a member CAESP may offer it to customers. The Green List is the streamlined fast-track for assets already listed by other JVCEA members; the White List is the full review for assets not yet on any member's offering. White List review typically takes six to twelve months and requires substantial issuer documentation including audited financial statements, smart-contract security audits, market-cap and liquidity analysis, governance documentation, and AML risk assessment. Approximately 50 to 70 tokens are approved for major-CAESP listing as of Q1 2026, a fraction of the offerings on US, EU, or Singapore exchanges.
Capital and operational requirements
CAESP registration imposes a 10 million yen minimum capital requirement (approximately 65,000 dollars at current rates) plus a separate 10 million yen minimum net assets requirement under PSA Article 63-5. These floors are nominal — actual operational capital expectations are far higher, with the JFSA in practice expecting registered CAESPs to hold capital sufficient to fund a minimum of one year of operating costs plus a reserve against potential customer-asset shortfalls. Crypto-Asset Derivatives Business Operator registration under FIEA imposes a 50 million yen capital floor (approximately 325,000 dollars) plus net-assets requirements scaled to risk exposure. Stablecoin issuance under the trust-bank pathway requires bank or trust-bank capital floors set by the Banking Act or Trust Business Act respectively (typically 2 billion yen or higher); the fund-transfer service pathway requires 100 to 500 million yen depending on category. Operational requirements are extensive. Real-name banking integration: all CAESPs must maintain customer-fiat accounts with a Japanese bank that performs full KYC under the Customer Identification Act, with customer fiat segregated from operating funds in trust accounts. Cold storage: at least 95 percent of customer crypto-assets must be held in cold storage with multi-signature key controls and physical security audits. Internal controls: a board-level Risk Management Committee, an MLRO reporting to the board, an independent internal audit function, an external system audit annually, and a separate Customer Asset Custody Officer with personal accountability for segregation compliance. Travel Rule: the 100,000-yen threshold applies to all crypto transfers between Japanese CAESPs and to outbound transfers to overseas VASPs in jurisdictions with equivalent Travel Rule regimes; for transfers to non-equivalent jurisdictions, the JFSA has imposed a default-deny posture requiring case-by-case approval. Insurance: post-2025 amendments introduced a JFSA-mandated insurance scheme operated through JVCEA that covers up to 100 million yen per customer per CAESP for hot-wallet hacks, with member-firm contributions calibrated to assets-under-custody.
Notable licensees
The JFSA register lists approximately 30 active CAESPs as of Q1 2026. The dominant domestic firms include bitFlyer (the largest Japanese exchange by volume, registered 2017), Coincheck (registered post-acquisition by Monex Group following the 2018 hack), GMO Coin (registered 2017, GMO Internet Group affiliate), DMM Bitcoin (registered 2018, restructured following 2024 hot-wallet incident), Liquid (registered post-acquisition by FTX Japan, post-FTX-collapse restructuring), bitbank (registered 2017), SBI VC Trade (registered 2017, SBI Group affiliate), Rakuten Wallet (registered 2017, Rakuten Group affiliate), and Bitpoint Japan (registered 2017). International firms with Japanese registration include Coinbase Japan (registered 2021 after a multi-year application cycle and operating with a narrower asset offering than the US parent), Crypto.com Japan (registered 2022 following acquisition of an existing CAESP shell), and Kraken Japan (registered 2014 under predecessor regime, withdrew from Japan 2018, has not reapplied). The post-FTX restructuring of Liquid Japan was the most significant ongoing-supervision exercise in the regime's history, with the JFSA managing a substantial customer-asset shortfall through coordinated voluntary administration with the JVCEA. Notable refusals or withdrawals include OKX (which has not applied), Bybit (no Japanese registration), and several mid-tier offshore venues whose pre-application engagement signalled likely refusal. Stablecoin issuance: as of Q1 2026, the only stablecoin issuers with confirmed JFSA registration are JPYC (a JPY-pegged stablecoin issued by JPYC Inc. under a fund-transfer service registration), Mitsubishi UFJ Trust (MUFG's pilot trust-bank stablecoin issuance under the trust-bank pathway), and Progmat Coin (a SBI Holdings affiliate operating a multi-issuer infrastructure). USDC and USDT have no Japanese stablecoin registration; their offering on Japanese exchanges is structured as a non-issuance distribution model under JVCEA token-listing rules rather than direct issuance.
Enforcement actions to date
The defining enforcement action of the Japanese regime was the 2018 Coincheck case. Coincheck, then operating under transitional registration arrangements, suffered a 532 million dollar NEM hack on 26 January 2018 from a hot wallet. The JFSA issued business improvement orders, ordered the firm to reimburse customers from its own funds, and ultimately required restructuring through acquisition by Monex Group. The case produced the post-2018 reform programme — JVCEA SRO formation, asset-segregation rules, cold-storage minimums, the JFSA enhanced supervision regime — that defines the current framework. The 2024 DMM Bitcoin hack (approximately 305 million dollars in BTC from a hot wallet) was the largest post-2018 incident and triggered the 2025 asset-segregation amendments. The DMM case did not result in customer losses because DMM Bitcoin reimbursed all customers from corporate funds, but the JFSA imposed a multi-year business improvement order and ongoing supervisory restrictions. The 2022 FTX Japan case — Liquid Japan, FTX-acquired in 2022 and frozen following the FTX bankruptcy — produced one of the most coordinated asset-recovery exercises in any major jurisdiction, with Japanese customer assets fully recovered through the segregation framework. The contrast with US FTX customer outcomes was substantial and heavily cited as evidence of the Japanese regime's effectiveness. Smaller enforcement matters have included business improvement orders for AML programme deficiencies, sanctions violations, advertising-rule breaches, and listings of non-JVCEA-approved tokens. The JFSA has issued public statements against unregistered offshore exchanges marketing to Japanese residents — including a 2023 cease-and-desist against Bybit and a 2024 enforcement action against several smaller offshore platforms — but criminal enforcement against offshore operators remains limited by jurisdictional reach.
How to apply
A CAESP application is filed with the JFSA's Financial Bureau through the Local Finance Bureau in the firm's registered prefecture. Pre-application engagement is mandatory and substantive: most successful applications involve six to eighteen months of pre-application work before formal submission, including detailed scoping of business model, customer-asset segregation architecture, internal-control framework, and proposed initial token offerings. The substantive application requires a programme of operations, three-year financial projections, biographical questionnaires for every senior officer and beneficial owner, a corporate governance manual, an AML/CFT manual aligned with the Foreign Exchange and Foreign Trade Act and the Act on Prevention of Transfer of Criminal Proceeds, a Travel Rule compliance plan, an operational-resilience plan, an ICT framework, a customer-asset segregation architecture document with specific cold-storage controls, an MLRO appointment, an external system auditor appointment, and an audit framework. Statutory determination period is two months from formal complete submission but the JFSA's substantive review extends actual determination to 12 to 36 months in practice. JVCEA membership application runs in parallel and adds materially to timeline. All-in cost runs 200 million to 1 billion yen (approximately 1.3 to 6.5 million dollars) depending on complexity, including legal, system-audit, internal-control, and JVCEA membership costs. Common rejection reasons include inadequate cold-storage architecture, insufficient detail on real-name banking integration, gaps in AML programme relative to JFSA expectations, weak internal-audit independence, inadequate director and senior-officer fitness-and-propriety evidence, and insufficient capital backing for the proposed business volume.
Comparison to peer frameworks
Against MiCA, the Japanese regime is materially more rigorous on operational controls (cold storage, asset segregation, real-name banking) but materially more restrictive on token availability (50-70 approved tokens versus thousands on major MiCA-licensed venues). Against the New York BitLicense, the Japanese regime is broadly comparable in supervisory rigour but more focused on operational risk than on consumer-protection conduct rules. Against Singapore's MAS Payment Services Act, the Japanese regime has stricter operational rules but a less commercially-flexible token-listing process; MAS's Digital Payment Token Service operators face fewer constraints on listed assets. Against Hong Kong's VATP regime, the Japanese regime is older, more operationally rigorous, and produces tighter customer-asset protection. Against the FCA cryptoasset registration regime, the Japanese regime is broader in conduct scope and substantively more rigorous on operational controls. The post-FTX comparison is most instructive: Japanese FTX customers were fully made whole through the asset-segregation framework, while US FTX customers waited multiple years through bankruptcy proceedings. The trade-off is commercial: Japanese exchanges offer a narrower asset universe, slower new-token onboarding, and higher operating costs, but the regime's customer-protection track record is the best of any G20 framework.
Open questions and pending changes
Three issues dominate operator planning through 2026 and 2027. First, the FATF Recommendation 16 Travel Rule equivalence assessments: the JFSA's default-deny posture for transfers to non-equivalent jurisdictions remains contested, and several major counterparties — including some US-based VASPs in periods of regulatory uncertainty — have been treated as non-equivalent on a temporary basis. The JFSA's published equivalence determinations as of Q1 2026 cover the EU under MiCA, Singapore under MAS, Hong Kong under SFC, the UK under FCA, and certain US firms under specific equivalence findings. Second, the stablecoin perimeter: the 2023 PSA stablecoin regime is still in early operational phase, and the bank-versus-trust-bank-versus-fund-transfer-service pathways have produced different commercial outcomes that the JFSA may yet recalibrate. The Mitsubishi UFJ trust-bank stablecoin pilot is the canary, and its scaling beyond pilot phase will inform broader policy. Third, the JVCEA token-listing reform: industry advocates have pushed for streamlined listing for tokens already approved in major peer jurisdictions, and the JVCEA's 2025 consultation on listing-process reform is expected to produce updated rules during 2026. Operators should also watch the FSA's evolving guidance on DeFi (currently outside the supervisory perimeter), the post-2024 NFT-perimeter clarification, the interaction with the Bank of Japan's CBDC pilot, and the ongoing post-DMM-Bitcoin-hack supervisory programme.
Watch points
- JVCEA token-listing reform expected 2026
- Travel Rule equivalence determinations for additional jurisdictions
- Mitsubishi UFJ trust-bank stablecoin pilot scaling beyond pilot phase
- Post-2025 asset-segregation amendments full implementation timeline
- DeFi perimeter clarification under JFSA guidance
- Post-DMM-Bitcoin-hack ongoing supervisory programme outcomes
TL;DR
Oldest major crypto-exchange regime (April 2017), reshaped by post-Coincheck-hack reforms; rigorous operational controls (95% cold storage, real-name banking, JVCEA pre-listing review) produced the best customer-protection track record of any G20 jurisdiction during the FTX collapse.
Get DeFi Intel research in your inbox
Weekly long-form coverage of papers, incidents, jurisdictions, chains, tokens and the people building them. Free tier covers headlines; Pro adds the analyst-grade breakdowns.