Vietnam has still not issued its first crypto exchange license, but the licensing race has already become one of APAC’s most important VASP compliance tests. According to the latest policy event record available to APAC FINSTAB, five companies have passed an initial assessment. The next hurdles are material: applicants must meet Level 4 information-system security requirements and contribute at least VND 10 trillion in capital, while new virtual-asset market penalties take effect on September 1.
That combination matters beyond Vietnam. For institutional crypto compliance teams, exchange listing committees, custodians, AML officers and APAC policy readers, Vietnam is not just another emerging-market licensing file. It is an example of a regional policy pattern: regulators are increasingly asking whether a crypto venue can prove operational resilience, financial substance, local accountability and enforceable user controls before it is allowed to scale.
The strongest compliance signal is not simply that Vietnam is moving toward licensing. It is that approval appears to be tied to infrastructure-grade security and balance-sheet commitment, not only registration paperwork. That changes how APAC VASPs should think about market-entry planning. A firm may be able to show product demand, liquidity, custody integrations and token coverage, but still fail if it cannot evidence cyber controls, capital support, incident response, customer protection, governance and legal accountability in a regulator-ready format.
This deep dive frames Vietnam’s licensing delay as an APAC benchmark. It does not assume facts beyond the supplied policy context. Where this article draws broader lessons for other jurisdictions, those points are labelled as interpretation.
Hook: Vietnam’s first crypto exchange license is still pending, but the compliance bar is already visible
The latest Vietnam policy update has three core facts for compliance teams to track:
- Vietnam has not yet issued its first crypto exchange license.
- Five companies have passed an initial assessment.
- Applicants must next meet Level 4 information-system security requirements and contribute at least VND 10 trillion in capital.
- New virtual-asset market penalties take effect on September 1.
Each element points to a different part of the VASP control stack. The absence of a first license means the market remains in a pre-approval phase, where regulator expectations are still being translated into practical evidence. The fact that five companies have passed an initial assessment suggests that screening is staged rather than purely binary. The Level 4 security requirement places cybersecurity and systems governance at the center of the license file. The VND 10 trillion capital requirement makes financial capacity a front-door issue. The September 1 penalty start date raises the cost of operating without a defensible legal position.
For APAC FINSTAB’s audience, the key question is not whether Vietnam will approve one applicant before another. The more important question is what the process tells exchanges and VASPs about the next generation of licensing controls across the region. Vietnam’s model, based on the supplied context, appears to link approval to institutional-grade security, capital depth and enforceable market discipline. That is relevant to firms serving or planning to serve customers in fast-growing APAC markets where regulators are still defining the boundary between innovation and public-risk containment.
Interpretation: Vietnam’s licensing process may become a regional reference point for jurisdictions that want to permit regulated virtual-asset markets without relying only on light-touch registration. Even if other APAC regulators do not copy the exact capital threshold or security classification, they can still draw from the same logic: a crypto exchange should be treated as critical financial-market infrastructure once it serves enough users, handles fiat flows or becomes a price-discovery venue.
Problem definition: licensing is no longer just a legal-form question
Older crypto market-entry strategies often treated licensing as a legal perimeter exercise. A business would ask whether it had local customers, whether the token product was in scope, whether marketing triggered local rules and whether an offshore entity could serve users under existing exemptions. That analysis remains necessary, but it is no longer sufficient.
Vietnam’s pending approval process highlights a broader problem: regulators increasingly want to know whether the operator can withstand the operational, cyber, liquidity, governance and enforcement risks that come with exchange activity. For a VASP, this shifts the licensing file from a legal memorandum into a multi-disciplinary control file.
The practical licensing problem now has at least six dimensions:
- Legal authority: Does the entity have the right form, local approvals and accountable governance to provide covered virtual-asset services?
- Cybersecurity: Can the exchange evidence information-system controls, penetration testing, incident response, privileged-access management and resilience?
- Capital and financial resources: Does the applicant have sufficient committed capital to support operations, customer protection, wind-down planning and stress scenarios?
- AML and market integrity: Can the venue monitor onboarding, suspicious activity, sanctions exposure, market abuse, wash trading and manipulation risks?
- Customer access and disclosures: Can the venue prove who is allowed to use the platform, what products they can access and what risks they have acknowledged?
- Regulatory reporting and penalties: Can the business respond to supervisory requests, preserve evidence and avoid unlicensed activity once penalties apply?
Vietnam’s Level 4 security and capital requirements speak directly to the second and third dimensions. The September 1 penalties speak to the sixth. But a serious exchange license file should connect all six. A regulator reviewing a crypto venue will not evaluate cybersecurity in isolation from custody, access controls, transaction monitoring or governance. A breach can become a market-integrity event. A weak capital position can become a customer-protection event. A poor access-control framework can become an unlicensed-service event.
For APAC VASPs, the main risk is treating these workstreams as separate compliance projects. Legal may prepare the license narrative. Security may maintain technical policies. Finance may document capital. Operations may handle incident workflows. AML may monitor suspicious transactions. But regulators increasingly expect a joined-up operating model. If the business cannot show how a cyber incident affects withdrawals, customer notifications, suspicious-activity review, market suspension and regulatory reporting, the license file will look incomplete.
APAC analysis: why Vietnam matters for regional VASPs
Vietnam’s crypto market has long attracted attention from global exchanges and wallet operators because of user activity, developer participation and retail demand. The supplied context does not provide user figures, licensing names or market-size data, so this article does not rely on those claims. The APAC relevance instead comes from the regulatory design signal: Vietnam is moving toward formal exchange licensing while imposing high security and capital expectations.
That matters for at least four APAC stakeholder groups.
1. Exchanges seeking local market access
For exchanges, Vietnam’s process shows that market access may require more than geofencing decisions and legal opinions. If a firm wants to operate under a local license, it may need to localize governance, evidence security maturity and allocate meaningful capital. If it does not want to operate locally, it still needs evidence that it is not providing covered services into the market once penalties begin.
That creates a two-sided control problem. Licensed applicants need approval evidence. Non-applicants need exclusion evidence. Both should be board-visible.
2. Custodians and wallet infrastructure providers
A crypto exchange license is rarely only about the matching engine. It depends on custody architecture, hot-wallet limits, private-key governance, transfer approval rules and incident recovery. Level 4 information-system security requirements, as referenced in the policy event, put infrastructure providers in the licensing perimeter even if they are not the applicant of record.
Interpretation: APAC custodians supporting Vietnam-facing exchanges should expect due diligence requests on access controls, key-management procedures, breach reporting, vendor oversight and disaster recovery. A venue that cannot evidence its custody controls may struggle to satisfy broader system-security requirements.
3. Token listing and market-surveillance teams
A licensed market will need defensible token admission and monitoring standards. Vietnam’s supplied policy event does not specify listing rules. However, the existence of a licensing process and new penalties means exchanges should expect scrutiny over which assets are offered, how risks are disclosed and how abusive trading is detected.
For APAC listing teams, Vietnam’s licensing delay is a reminder that the listing file should be compatible with the licensing file. A token approved for trading should have documented legal risk analysis, liquidity review, custody support, issuer or protocol disclosures where relevant, surveillance parameters and delisting triggers. If those files are not regulator-ready, they can weaken the broader VASP approval narrative.
4. AML officers and financial-crime teams
The policy event focuses on licensing, security, capital and penalties, not AML details. But in APAC practice, exchange licensing and AML controls are inseparable. A regulated exchange that onboards users, handles fiat flows or permits stablecoin transfers needs customer due diligence, sanctions screening, transaction monitoring, suspicious-activity escalation, travel-rule workflows where applicable and law-enforcement response procedures.
Vietnam’s new penalties raise the urgency. Once a penalty regime is active, AML evidence is not only a supervisory expectation; it becomes part of the defense file if a firm is questioned about activity in the market.
Evidence and policy signals from the latest events
Today’s policy events show that Vietnam is part of a wider shift toward harder controls around crypto market infrastructure. Several non-Vietnam developments help frame the direction of travel, even though Vietnam is the focus of this article.
| Policy signal | Event from latest context | Compliance relevance for APAC VASPs |
|---|---|---|
| Licensing plus security and capital | Vietnam has not issued its first crypto exchange license; five companies passed initial assessment; next steps include Level 4 information-system security and at least VND 10 trillion capital. | Exchange approval is tied to operational resilience and financial substance, not only corporate registration. |
| AML enrollment and enforcement pressure | AUSTRAC reminded businesses that enrolment is the first step toward AML/CTF obligations, following recent section 167 notice activity against unregistered designated services. | APAC regulators are pushing firms to evidence whether they are in scope, enrolled or properly excluded from local services. |
| Stablecoin payment controls | Circle deployed USDC, EURC, CCTP and Bridge Kit on Plasma; Japan retail stablecoin POS trials continued through Lawson and NetStars. | Payment use cases increase the importance of issuer controls, wallet eligibility, redemption cutoffs, failed-transfer evidence and merchant monitoring. |
| Tokenized money competition | BIS comments favored tokenized deposits for large-scale payments; US bank tokenized-deposit clearing work highlighted interbank netting. | Licensed exchanges may face more scrutiny when offering stablecoins, tokenized deposits or bank-linked settlement products. |
| Exchange product perimeter expansion | Bitget and Coinbase stock-linked perpetual activity raised oversight questions around synthetic securities and index-linked contracts. | APAC venues need product-governance files that explain geographic access, suitability, leverage disclosure and surveillance. |
The Vietnam event stands out because it brings several of these themes into one licensing gate. A regulator does not need to wait for a stablecoin failure, a custody breach or a market-manipulation case if it can require the exchange to prove resilience before launch. That is the preventive logic of a higher licensing threshold.
Interpretation: The September 1 penalty start date may also change market behavior. Firms that previously relied on ambiguity may need to decide whether to apply, withdraw, geofence, restructure or document why their services are not in scope. In compliance terms, the transition from draft rules to penalties is the point where policy monitoring becomes operational risk management.
The Level 4 security question: what APAC exchanges should prepare
The supplied context says applicants must meet Level 4 information-system security requirements. It does not list the detailed technical criteria. APAC FINSTAB therefore does not claim a specific Vietnam checklist beyond that phrase. However, institutional VASPs can still prepare a regulator-ready evidence pack around the standard categories that commonly matter in exchange security reviews.
A practical Level 4-style readiness file should include the following control domains:
| Control domain | Evidence APAC VASPs should prepare | Why it matters for licensing |
|---|---|---|
| System inventory | Architecture diagrams, critical-system register, data-flow maps, third-party dependencies and production environment boundaries. | Regulators need to know what systems support trading, custody, onboarding, monitoring and reporting. |
| Identity and access management | Privileged-access procedures, multi-factor authentication, role-based access control, joiner-mover-leaver logs and emergency-access records. | Unauthorized access is a direct cyber, custody and market-integrity risk. |
| Private-key and wallet security | Key-generation procedures, signing policies, hot-wallet limits, cold-storage controls, withdrawal approvals and exception logs. | Exchange security cannot be separated from customer-asset protection. |
| Change management | Code review records, release approvals, segregation of duties, rollback plans and emergency patch documentation. | Poor change control can create outages, erroneous orders, custody failures or exploitable vulnerabilities. |
| Monitoring and incident response | Security-event logs, alert triage workflows, incident playbooks, breach-notification procedures and post-incident review templates. | Licensing authorities need confidence that the firm can detect, contain and report incidents. |
| Business continuity | Disaster recovery plans, recovery-time objectives, backup testing, alternative communications and crisis governance minutes. | An exchange is market infrastructure; outages can become customer-protection and systemic-confidence events. |
| Vendor and cloud oversight | Due diligence files, service-level agreements, audit reports, data-location analysis and concentration-risk reviews. | Regulators increasingly expect control over outsourced technology risks. |
| Independent assurance | Penetration-test results, remediation trackers, internal audit reports and board reporting on residual risks. | Self-attestation is weaker than evidence of testing, remediation and oversight. |
For a Vietnam applicant, these files should not sit only with the security team. They should be cross-referenced to legal, compliance, custody and operations documents. For example, an incident-response playbook should state when withdrawals are paused, when regulators are notified, when customers are informed, when suspicious-activity review is triggered and who approves reopening. A capital plan should state how the firm funds remediation, customer communications, technology recovery and wind-down if necessary.
That is the difference between having controls and having a licensable control system.
The capital threshold: why VND 10 trillion changes the approval conversation
The latest event states that applicants must contribute at least VND 10 trillion in capital. APAC FINSTAB does not convert that figure here because exchange rates fluctuate and the supplied context does not provide a conversion. The compliance implication is still clear: the threshold is designed to test financial seriousness.
Capital requirements can serve several regulatory purposes. They can screen out under-resourced applicants. They can support operational continuity. They can provide a buffer for technology investment, compliance staffing and customer-protection processes. They can also signal that an exchange license is not a low-cost option for lightly governed operators.
For APAC exchanges, the capital file should answer five regulator questions:
- Source: Where does the capital come from, and can the firm evidence lawful origin and ownership?
- Availability: Is the capital genuinely committed to the licensed entity or only available elsewhere in the group?
- Use: What parts of the operating model does the capital support, including compliance, cybersecurity, custody, staffing and continuity?
- Stress: How does the firm remain solvent and operational during market shocks, cyber incidents, liquidity stress or withdrawal surges?
- Governance: Who controls capital allocation, and what board approvals are required for material changes?
The capital requirement also interacts with group structure. Many global exchanges operate through multiple entities for technology, IP, treasury, custody, regional marketing and customer contracting. A Vietnamese licensing process that requires significant capital at the applicant level may force groups to decide how much substance they are willing to locate in the market. A thin local entity backed only by offshore service agreements may not be enough if the regulator wants accountable financial resources.
Interpretation: Vietnam’s capital threshold may encourage fewer but more institutionally resourced applicants. That could support stronger supervision, but it may also limit smaller domestic innovators unless they can partner, consolidate or raise sufficient capital. Compliance teams should prepare for both outcomes: higher institutional standards and more competitive pressure around approved market access.
New penalties from September 1: the market-access control test
The policy event states that new virtual-asset market penalties take effect on September 1. It does not specify the penalty amounts or covered violations. Even without those details, the timing matters. A penalty start date creates a hard compliance checkpoint.
APAC VASPs should treat penalty commencement as a trigger for market-access review. The board and compliance committee should be able to answer:
- Do we provide any products or services that could be viewed as available to Vietnam users?
- Do we market, advertise, localize language, support local payment methods or run campaigns that target Vietnam?
- Do we onboard Vietnam residents or accept Vietnam-linked identity documents, phone numbers, IP addresses, bank accounts or payment instruments?
- Do we have a legal opinion on whether our services fall inside or outside the licensing perimeter?
- If we are not applying, what technical and operational controls prove exclusion?
- If we are applying, what interim controls apply before approval?
- What is the escalation process if a regulator contacts the firm?
Market-access evidence should be specific. A policy that says “we do not target restricted jurisdictions” is not enough. Firms need logs, rules, screenshots, product-permission matrices, onboarding rejection records, campaign approval files, affiliate restrictions and customer-support scripts. If penalties apply, the question is not only what the firm intended. It is what the evidence shows.
For exchanges operating across APAC, this is especially important because user access can be created indirectly. An offshore platform might not run a Vietnam office, but it may still have app-store availability, referral programs, influencer campaigns, local-language support, peer-to-peer trading, stablecoin ramps or customer-service workflows that create regulatory exposure. Compliance teams should map these channels before a penalty regime becomes active, not after receiving a notice.
APAC compliance checklist for Vietnam-facing VASPs
The following checklist translates the Vietnam licensing signal into a practical control framework for exchanges, brokers, wallet operators, custodians and stablecoin desks. It is designed for APAC teams assessing whether to apply, partner, pause or exclude access.
| Workstream | Control question | Evidence to keep | Owner |
|---|---|---|---|
| Licensing perimeter | Are our products or services potentially in scope of Vietnam virtual-asset rules? | Legal opinion, product map, customer-location analysis, board minutes. | Legal / Compliance |
| Application strategy | Are we applying, partnering with an applicant, waiting or excluding the market? | Strategy memo, risk assessment, regulator engagement log, decision record. | Board / Regional Management |
| Security readiness | Can we evidence Level 4-style information-system controls? | Architecture diagrams, IAM files, incident playbooks, penetration tests, remediation tracker. | CISO / Technology Risk |
| Capital planning | Can we meet and maintain the required capital contribution? | Capital proof, source-of-funds files, treasury policy, stress plan. | Finance / Treasury |
| Custody governance | Are wallet, key and withdrawal controls suitable for a licensed exchange? | Key-management procedures, signing logs, wallet-limit approvals, custody audit reports. | Custody / Operations |
| AML controls | Can we monitor users, transactions, sanctions exposure and suspicious activity? | CDD procedures, screening logs, monitoring rules, suspicious-activity escalation records. | AML / Financial Crime |
| Market integrity | Can we detect manipulation, wash trading, abusive accounts and disorderly markets? | Surveillance alerts, investigation files, account-action records, listing review files. | Market Surveillance |
| Token listing | Are listed assets supported by legal, liquidity, custody and disclosure review? | Listing committee minutes, risk memos, issuer/protocol files, delisting triggers. | Listing Committee |
| Customer access | Can we prove who may access Vietnam-related services? | Geo-controls, KYC rules, IP logs, onboarding decisions, product-permission matrix. | Compliance Operations |
| Penalty response | Can we respond quickly to supervisory contact or suspected breach? | Regulator-response playbook, document-retention plan, escalation tree, counsel contacts. | Legal / Compliance |
This checklist should be turned into a dated evidence pack. Regulators and enforcement teams rarely evaluate controls in the abstract. They ask what the firm knew at a specific time, what decision it made, who approved that decision and what systems enforced it. A Vietnam-facing VASP should therefore maintain version control over legal opinions, access rules, product permissions and board decisions.
Market implications: fewer shortcuts, more infrastructure discipline
Vietnam’s licensing delay may frustrate market participants waiting for legal clarity. But from a compliance perspective, the delay also reveals the direction of travel. The first approved crypto exchange will likely set a benchmark for others, not only in Vietnam but across APAC markets watching how to supervise VASPs without shutting down innovation.
Several market implications follow.
Licensed status may become a distribution advantage
If Vietnam grants licenses only after security and capital checks, approved venues may gain a trust advantage with banks, payment partners, institutional clients and token issuers. For APAC exchanges, licensing is becoming part of commercial credibility. A venue that can show regulator-approved controls may have an easier time negotiating fiat rails, custody partnerships and institutional onboarding.
Unlicensed access may become harder to defend
Once penalties are active, offshore access becomes a higher-risk decision. Firms that continue to serve users without approval or exclusion evidence may face questions about customer targeting, marketing, onboarding, local payment support and affiliate activity. The burden shifts from “the rules were unclear” to “show the controls you implemented when penalties became effective.”
Security investment becomes a licensing asset
Cybersecurity is often treated as a cost center. Vietnam’s Level 4 requirement reframes it as a market-access asset. Exchanges that have already invested in mature security governance, independent testing, incident response and custody controls will be better positioned to respond to licensing requests. Firms that deferred security investment may find that product speed cannot compensate for missing evidence.
Capital structure becomes a regulatory issue
The VND 10 trillion capital requirement means finance and treasury teams must be inside the licensing process from the start. Capital cannot be an afterthought. A VASP that wants APAC licenses should maintain clear records on entity funding, intercompany support, liquidity buffers, insurance arrangements if any, and wind-down planning.
Board-level questions before entering or serving Vietnam
Before an APAC VASP makes a Vietnam market decision, the board should receive a concise but evidence-backed paper addressing these questions:
- What is our current Vietnam exposure across users, traffic, app access, marketing, affiliates, payments and support?
- Are we seeking a local license, partnering with a licensed applicant, maintaining restricted access or exiting?
- What is the legal basis for that decision?
- Can we meet Level 4 information-system security expectations, and what gaps remain?
- Can we meet the VND 10 trillion capital requirement if applying, and where will that capital sit?
- What controls are in place before and after the September 1 penalty date?
- How will we evidence customer exclusion or eligibility?
- What tokens, stablecoins, derivatives or yield products would be unavailable until approved?
- Who owns regulator engagement and document production?
- What is the exit plan if approval is delayed or denied?
These questions are not theoretical. They determine whether the firm can show a deliberate compliance position. In a penalty environment, silence or ambiguity is dangerous. A board-approved strategy, supported by technical controls and dated evidence, is much stronger than informal assumptions by regional growth teams.
Conclusion: Vietnam turns APAC VASP licensing into a proof-of-resilience test
Vietnam’s pending crypto exchange licenses are important because the market has not yet crossed the approval line. The first license will matter, but the pre-license conditions already matter more for compliance planning. Five companies have passed an initial assessment. Applicants must next meet Level 4 information-system security requirements and contribute at least VND 10 trillion in capital. New virtual-asset market penalties take effect on September 1.
For APAC exchanges and VASPs, the lesson is clear: licensing is becoming a proof-of-resilience exercise. Legal eligibility, cybersecurity, capital, AML, custody, market surveillance and customer access must be presented as one coherent control system. A firm that cannot prove its systems, funding and access boundaries may struggle even if it has strong user demand or product capability.
Vietnam also offers a wider regional warning. APAC regulators are converging on a harder question: not simply whether crypto activity should be allowed, but which operators have the governance, technology and financial substance to run it safely. That question will shape exchange approvals, stablecoin distribution, token listings, fiat partnerships and enforcement risk across the region.
The practical response is not to wait for the first license announcement. VASPs should build the file now: licensing perimeter, Level 4-style security evidence, capital proof, AML controls, custody governance, listing standards, market-access logs and penalty-response procedures. In Vietnam, the approval race is still open. For APAC compliance teams, the readiness test has already started.