There is no single VARA rulebook. A firm authorised by VARA does not read one instrument and comply with it. It reads several at once, and its real obligation set is the sum of them.
The framework is cumulative rather than modular. Every Virtual Asset Service Provider licensed in the Emirate is bound, at all times and whatever it does, by four compulsory rulebooks. To those it adds one activity rulebook for each activity it is licensed to carry on. And where it markets in or into the UAE, the Marketing Regulations 2024 reach it as well, whether or not it holds a VARA licence at all. The architecture is set by the Regulations themselves: Part V of the Virtual Assets and Related Activities Regulations 2023 names the compulsory rulebooks that bind every VASP (V.1) and the activity-specific rulebooks that attach to each licensed activity (V.2).
The consequence is the part most often miscounted. A business holding two licences is not reading two rulebooks. It is reading the four compulsory rulebooks, plus one activity rulebook for each of its two activities, plus the Marketing Regulations if it promotes at all, plus the Regulations that sit above all of them, plus any Directives and licence conditions VARA has issued to it specifically. The obligation set is assembled, not selected from a shelf, and the assembly is where firms undercount what binds them.
What governs when two of those instruments point in different directions is a separate question, and the answer is more particular than the familiar assumption that the strictest rule wins. That is dealt with in Section V.
Four rulebooks bind every VASP, at all times, whatever it is licensed to do. The Company Rulebook makes the point in its own opening: a firm licensed for any VA Activity must “also comply with” the Compliance and Risk Management Rulebook, the Technology and Information Rulebook, the Market Conduct Rulebook, and the rulebooks specific to its licensed activities. These four are the floor. The activity rulebooks in Section III sit on top of them; they do not stand in their place.
One reading rule governs all four. Unless a provision is expressly marked as Guidance, every requirement is a Rule with binding effect. The working assumption when reading any of these rulebooks is therefore that the requirement binds, and the effort goes into finding the Guidance flag, not into establishing the obligation (Company Rulebook, Introduction, current as at 1 July 2026; the same default runs through the other three).
The Company Rulebook is the rulebook about the entity itself, whether it is built, governed and capitalised to hold a licence at all. It runs from company structure (Part I) and corporate governance (Part II) through fit-and-proper requirements for the individuals who control it (Part III), outsourcing (Part IV), environmental, social and governance obligations (Part V), capital and prudential requirements (Part VI), insolvency and wind-down (Part VII), and material change to the business or its control (Part VIII). It is the rulebook against which the question “is this firm fit to be here” is answered.
The Compliance and Risk Management Rulebook is the rulebook about controls, the compliance function and the risks the firm must hold. It covers compliance management and the Compliance Officer (Part I), tax reporting (Part II), anti-money-laundering and counter-terrorist-financing (Part III), the client money rules (Part IV) and client virtual asset rules (Part V), anti-bribery and corruption (Part VI), and the regime for sponsored VASPs (Part VII). Its anti-money-laundering layer (Part III) is the part of the framework currently in motion, because it tracks the federal AML regime, which has been overhauled; that movement is treated in its own piece.
The Technology and Information Rulebook is the rulebook about systems and data. It governs technology governance, controls and security, including the management of keys so that no single store or person can move client assets alone (Part I); the protection of personal data (Part II); and the handling of confidential information (Part III). It is where the firm’s cyber-resilience and data obligations are set, and where the Chief Information Security Officer sits.
The Market Conduct Rulebook is the rulebook about how the firm behaves toward the market and the client. It covers marketing, advertising and promotions (Part I), client agreements (Part II), complaints handling (Part III), investor classifications (Part IV), public disclosures (Part V), market transparency (Part VI), trading on own account (Part VII), and VA standards (Part VIII). Two of its parts reach beyond it. Part I carries no substantive marketing rules of its own; it points to the Marketing Regulations 2024, the perimeter dealt with in Section IV. Part IV sets the Retail, Qualified and Institutional investor classifications that a great many later obligations turn on.
Read together, the four describe a licensed firm from four angles at once: what it is, how it controls itself, how it runs and protects its systems and data, and how it conducts itself in the market. Every licensed firm carries all four. What it adds to them depends on what it is licensed to do, which is Section III.
For each activity a firm is licensed to carry on, it adds that activity’s rulebook to the compulsory four, and the activity rulebooks apply cumulatively, one for each licensed activity (Regulations 2023, Part V.2, restated in each activity rulebook’s Introduction, current as at 1 July 2026). There are eight.
The eight are: Advisory Services, for advising on virtual assets; Broker-Dealer Services, for trading, execution and the distribution of tokens; Custody Services, for holding client assets; Exchange Services, for operating a trading venue; Lending and Borrowing Services, for deploying client assets; VA Management and Investment Services, for discretionary management; VA Transfer and Settlement Services, for moving and settling assets; and Virtual Asset Issuance, for those who issue a token rather than service one.
Licences are granted per activity. A firm that wants to do two things applies for, obtains and maintains a licence for each, and reads the rulebook for each on top of the compulsory four. Counting rulebooks is the simple part. The harder part is that some activities are not free to sit alongside others in the same company.
Here the activity layer stops being a matter of addition. A firm providing Custody Services must be an independent legal entity, separate from any member of its group that provides other VA activities, with one exception: custody may be combined with VA Transfer and Settlement Services, and where it is, the firm reads that rulebook too (Custody Services Rulebook, Rule III.B.5, with the Introduction). A group that wants to custody client assets and also, say, operate an exchange cannot hold both in a single entity. The choice of activities shapes the group itself, not only the length of its reading list.
Two activities also raise the bar at board level. Custody Services and Exchange Services each carry an Additional Board Requirements part that the other six do not (Custody Services Rulebook, Part I; Exchange Services Rulebook, Part I). These are the framework’s highest-trust activities, the ones that hold client assets or stand between the parties to a trade, and the governance tier is set to match.
The activity layer therefore adds two things at once: the obligations in each activity rulebook, and, for some activities, a constraint on how the group may be built. Beyond it sits one further ring, which can attach to a firm whether or not it holds any licence at all. That is Section IV.
The widest ring in the framework is not a rulebook at all. It is the Marketing Regulations 2024, a standalone instrument that can bind a firm whether or not it holds any VARA licence. It applies to all entities, domestic or foreign, licensed or not, and it reaches them whenever their marketing is “in or targeting the UAE” (Regulations on the Marketing of Virtual Assets and Related Activities 2024, effective 1 October 2024, Part I.B, current as at 1 July 2026).
This is also where the Market Conduct Rulebook’s marketing part leads. Part I of that rulebook, noted in Section II, carries no substantive marketing rules of its own; it points to this instrument. A licensed VASP therefore meets the marketing regime here, in the Regulations themselves, not inside the rulebook that refers to them.
The reach is defined by its exit, and the exit is narrow. An entity falls outside the Marketing Regulations only if it satisfies all three conditions at once: it is not located in the Emirate, it conducts no VA activity in the Emirate, and it does no marketing of a virtual asset aimed at or within the UAE (Part I.B.5). The test is conjunctive, so failing a single limb brings the entity back in. A foreign business with no Dubai presence and no Dubai licence is still bound the moment it markets a virtual asset into the UAE. The perimeter is drawn around the audience, not the marketer.
Two prohibitions in the same part are worth stating plainly. Marketing of a VA activity may be carried out only by a VASP licensed by VARA for that activity, or on its behalf and with its approval (Part I.B.3), so a third party cannot promote a licensed activity into the UAE on its own account. And the marketing of Anonymity-Enhanced Cryptocurrencies, the privacy coins, together with any VA activity involving them, is prohibited outright in the Emirate (Part I.B.4).
There is a companion document, the Guidance on the Marketing Regulations. It is indicative and explanatory, and it is non-binding. It shows how VARA reads the Regulations; it adds nothing to them and changes nothing in them. A reader leaning on the Guidance is leaning on an aid to interpretation, not on a source of obligation.
A firm’s true perimeter, then, is wider than its licence. The compulsory rulebooks, the activity rulebooks and the Marketing Regulations can all bind the same firm at the same time. Which leaves the question this article has twice deferred: when two of these instruments point in different directions, what governs? That is Section V.
The framework does not resolve overlaps with a single rule that the strictest requirement wins. It resolves them by the status of the instruments in question, and by express precedence written into the instruments themselves, and those precedence statements do not all point the same way.
Start with the default, which is cumulative compliance. A VASP must comply at all times with the four compulsory rulebooks and with each activity rulebook for the activities it is licensed to carry on, each in addition to the others (Regulations 2023, Part V, current as at 1 July 2026). Where two requirements both apply and can both be met, both bind, and the more demanding of the two sets the effective standard. That is a consequence of applying the rulebooks together, not a separate rule of strictness. It is why “the strictest wins” reads as true in the ordinary case and misleads in the hard one, where two requirements do not simply stack but actually conflict.
When they do conflict, instrument status decides much of it before any contest begins. Rules have binding effect and are found in the Regulations, the rulebooks and other rule-making instruments; Guidance is indicative and non-binding, and VARA must identify it as such (Regulations 2023, Part I.B.2 and B.4). A Rule and a piece of Guidance therefore never genuinely conflict. Guidance cannot displace a Rule, and a reader who finds the two apparently at odds is reading the Guidance for more than it carries.
Express precedence handles the rest, and it runs in both directions. The Marketing Regulations apply in addition to all Regulations, Rules and Directives, and provide that on conflict “the Regulations and Rules shall have precedence” (Marketing Regulations 2024, Part I.A.5). There the subordinate instrument gives way. But a subordinate-looking instrument can also override. VARA may issue Directives that “waive or otherwise modify the applicability, or application, of any Regulations or Rules” (Regulations 2023, Part I.B.3.d), so a Directive addressed to a single firm can change what an otherwise-binding Rule requires of that firm. And within the rulebook stack, the activity rulebooks apply cumulatively unless a provision states otherwise, so where a rulebook expressly gives one of its provisions precedence on a point, that statement governs (Custody Services Rulebook, Introduction).
One feature sits underneath all of this: the framework is expressly mutable. VARA may interpret, waive, modify or adapt any Regulation, Rule, Directive or Guidance at any time, by publishing a revised version, announcing the change, or notifying the firms to which it applies (Regulations 2023, Part I.B.5). What governs today can be altered tomorrow by an instrument that need not be a new rulebook.
So the question this article has carried has a precise working answer. To know what governs when two provisions meet, read the express precedence and waiver language attached to the specific instruments in play, and check whether any Directive has been issued to the firm. The harsher requirement is often where a firm lands, but by the consequence of cumulative compliance rather than by a rule that declares it, and it can be displaced by an express provision or a Directive pointing the other way. Section VI puts this on a single firm.
Put the article on one firm. Take a group that wants to run a trading venue and also hold its clients’ assets in custody. The intuitive reading is two activities, so two rulebooks. The real obligation set is larger, and it begins by forcing the group into more than one company.
The structural constraint bites before any rulebook is opened. A firm providing Custody Services must be a separate legal entity from any group member carrying on other VA activities, and the only activity it may share its entity with is VA Transfer and Settlement (Custody Services Rulebook, Rule III.B.5, current as at 1 July 2026). Custody and an exchange cannot sit in the same company. So the group is not one licensed firm with two permissions; it is at least two licensed VASPs, a custody entity and an exchange entity, each authorised in its own right.
Each of those entities then assembles the full stack this article has described. Each carries the four compulsory rulebooks in full (Regulations 2023, V.1), adds the rulebook for its own activity (V.2), takes on the Marketing Regulations if it promotes at all, sits beneath the Regulations that govern them both, and lives with any Directives VARA has issued to it and any conditions on its licence. The four compulsory rulebooks are therefore read twice across the group, once inside each entity, not once for the group as a whole.
Both entities also sit at the framework’s higher governance tier. Custody Services and Exchange Services each carry an Additional Board Requirements part that the other activities do not (Custody Services Rulebook, Part I; Exchange Services Rulebook, Part I), so the raised board standard applies in both companies at once.
Counted properly, the group is not reading two rulebooks. It is running two regulated entities, each on the four compulsory rulebooks and one activity rulebook, with the Marketing Regulations across both, the Regulations above all, two sets of enhanced board requirements, and whatever Directives have been issued to either.
That count is where the commercial weight sits, because the standalone rule is a structural cost, not a filing detail. Two regulated entities means two boards meeting the enhanced tier, two compliance and risk functions, two technology and data regimes, and each entity independently meeting the Company Rulebook’s capital and prudential requirements, the figures for which are set out in their own article. None of that is a product decision. It is fixed by the choice of activities, before a single client-facing feature is designed.
Precedence then lives inside each entity rather than across the group. When two of an entity’s own obligations meet, it resolves which governs by the express precedence and waiver language, and by any Directive addressed to it (Section V), instead of treating its reading list as additive and inert. The obligation set is assembled, and the assembly starts with the shape of the group. What can still change that set, and how quickly, is Section VII.
What is settled in this framework is its shape. The design this article has described, four compulsory rulebooks beneath every firm, an activity rulebook for each licensed activity, the Marketing Regulations reaching past the licence, and precedence resolved by express provision rather than by strictness, is the stable part. What moves is the content inside that shape, and the instruments do not move together.
They are versioned one by one. As at 1 July 2026, the four compulsory rulebooks sit on their 19 June 2025 version, while the Exchange Services Rulebook sits on a later version effective 31 March 2026, each confirmed at source. A firm reading its own stack cannot assume every rulebook in it carries the same date, and a point that was current when one rulebook was last read may sit in a paragraph a newer version has already changed.
The most active edge at present is the anti-money-laundering layer, where VARA’s framework meets federal law. VARA’s own record of recent changes shows the framework’s latest movement is to the Federal AML/CFT Laws, dated 19 May 2026, and the Regulations expressly allow VARA’s requirements to be made by reference to the laws of other competent authorities (Regulations 2023, Part I.B.6.c). How that layer now reads is the subject of its own article. The point for this one is that it is where the ground is currently shifting.
Underneath the versioning is the mutability itself. VARA may interpret, waive, modify or adapt any instrument at any time (Regulations 2023, Part I.B.5), and it may change how a Rule applies to a single firm by Directive without altering any rulebook at all (Part I.B.3.d). “Current” is therefore not a state a firm reaches once and keeps. It is a property of a specific instrument at a specific moment.
Which is the practical close. Because the pieces move independently, the version that governs has to be read at source, instrument by instrument, at the point it is relied on. VARA publishes a version history on each instrument and a record of what has changed, so the operative version is always locatable. The obligation set described in this article is assembled from several instruments read together, and it is kept honest the same way, one instrument at a time, against the current text.
For your facts, in confidence, put the question to the firm.





The bench stands behind it