PAKISTAN VIRTUAL ASSET REGULATORY AUTHORITY – PVARA
SANDBOX GUIDELINES 2026
Table of Content
Contents
- Definitions 3
- Eligibility Criteria 4
- Frequency of accepting applications 5
- Application submission process: 5
- Assessment Phase 5
- Assessment will cover 5
- Timeline 6
- Undertaking 6
- Key Evaluation Criteria: 6
- Testing/ Experimentation 7
- Completion Report 7
- Exit Stage: 7
- Suspension or revocation of approval: 7
- No-Action Relief 8
Form I 8
Overview 8
A. Innovation / Virtual Asset Service Provider Proposition 8
B. Readiness for Testing 8
C. Exit Strategy & Scaling 9
D. Applicants’ Background 9
E. Applicant Particulars & Technical Details 9
F. Evaluation Criteria 10
Annexure-A 11
Annexure-B 13
Definitions
For the purposes of these guidelines, unless the context otherwise requires—
“Authority”
means the Pakistan Virtual Asset Regulatory Authority established under the Section 6, sub-section 1 of the Ordinance.
“Applicant”
means any person applying for participation in the Sandbox in accordance with Section 43 of the Ordinance.
“Board”
means the governing body of the Pakistan Virtual Asset Regulatory Authority, established under section 8 the Ordinance, and vested with the powers and functions set out therein, including the authority to constitute committees, approve membership changes, and oversee the overall operations of the Authority.
“Agile Approach”
means a process under which Applicants may submit applications at any time during the year for consideration by the Authority.
“Exit”
means the process, at the conclusion of Sandbox testing, through which a participant either transitions to full licensing, discontinues the Virtual Asset service, or takes other steps as directed by the Authority under Section 44(3) of the Ordinance.
“No-Action Relief”
means a no-action letter issued by the Authority under Section 45 of the Ordinance, indicating that the Authority does not intend to take enforcement action in respect of specified conduct for a defined period.
“Ordinance”
means the Virtual Assets Ordinance, 2025.
“Participant”
means an applicant that has been approved to operate within the Sandbox under a supervisory agreement with the Authority.
“Sandbox”
means the controlled environment established and operated by the Authority under Section 42 of the Ordinance for the purpose of fostering responsible innovation in Virtual Asset products and services.
Introduction:
These Sandbox Guidelines have been developed to operationalize the mandate conferred upon the Authority under Sections 42 to 45 of the Virtual Assets Ordinance, 2025. The Guidelines provide a structured framework to facilitate responsible experimentation of innovative Virtual Asset products and services within a controlled regulatory environment. They aim to balance the promotion of innovation with the need for investor protection, financial stability, market integrity, and risk management. Through clearly defined procedures for application, supervision, monitoring, and exit, the Guidelines ensure that sandbox participants can test new solutions under appropriate oversight while contributing to the orderly growth of Pakistan’s Virtual Asset ecosystem.
Objective:
The objective of the sandbox is:
To implement the mandate of the Authority under Sections 42–45 of the Virtual Assets Ordinance, 2025, by establishing and operating a Sandbox.
To provide a structured framework that enables responsible testing of innovative Virtual Asset products and services in a controlled environment.
To promote financial innovation while ensuring investor protection, financial stability, and market integrity.
To identify risks associated with innovative products in the Virtual Assets eco-system, in local and global context, and develop appropriate risk mitigation mechanisms.
To define clear procedures for application intake, application assessment, onboarding, supervision, monitoring, and exit of Sandbox participants.
To ensure that testing activities are conducted under appropriate oversight with due regard to risk management and consumer protection.
To coordinate and collaborate with relevant regulatory authorities operating in domestic or other jurisdictions.
Eligibility Criteria
Applicant must:
Be a fit and proper person, with no directors, sponsor shareholders, controllers or key management found liable for:
Fraud, financial crime, or misconduct.
Prior regulatory or licensing breaches including proscribed and designated persons.
Bankruptcy or insolvency proceedings (unless adequately resolved).
Demonstrate operational readiness to participate in the Sandbox, including:
A clearly defined testing plan (objectives, duration, KPIs, and target users).
Risk management and consumer protection measures (including data security, dispute resolution, and safeguarding consumer assets).
Complete governance structure (clearly identifiable Ultimate Beneficial Owner) along with risk assessment and internal control mechanism, covering; Enterprise risk assessment; identity verification (covering detailed KYC and screening mechanism) including both originator and beneficiary; complaint handling mechanism; policies and procedures for handling/segregation client money and virtual assets; liability management policies and framework to safeguard clients from fraud and/or such instances; flagging and reporting of suspicious transactions; addressing technology risk including system controls, cybersecurity and protection of the private key; complete risk disclosure to the clients and Compliance with cross border supervision and information sharing protocols, where applicable.
A sandbox exit plan specifying transition to full authorization or orderly wind-down.
Readiness for scalability (technical, financial, and human).
Conduct and submit a comprehensive regulatory and risk assessment, addressing:
Cybersecurity, data privacy, and operational risks.
market risk and systemic risks.
Ensure compliance with applicable legal framework, and confirm that the product/service is not designed for speculation, anonymity, or illicit activity.
Frequency of accepting applications
The Sandbox shall operate in an agile manner, the applicants can submit applications related to the scope envisaged under the Ordinance or as notified by the Authority, for consideration in the sandbox environment across the year.
Application submission process:
Applicant shall submit the sandbox application as per the format specified in
Form -I
of this document.
The authority may prescribe application fee, as it may deem appropriate.
Applicant shall submit the self-assessment along with application as provided in
Annexure-A.
Applications will be reviewed for all required documents and information, and shall include all the mandatory information as specified in this guideline.
Incomplete applications will be returned with a request for revisions, with up to two resubmissions permitted.
Assessment Phase
Applications passing the initial screening shall proceed to the Evaluation Phase.
If entities are regulated, the input from relevant regulator may be sought.
Assessment will cover
Assessment will be conducted, based on submission at the time of the application or any other information sought subsequently in addition to already specified document/information, in order to assess the suitability of the sandbox applicant and viability of the products/services.
Timeline
The comprehensive evaluation must be completed within sixty (60) working days from the conclusion of the initial screening unless the Authority determines that there is reasonable cause to extend timeline.
Undertaking
On approval of application, the participant shall submit an undertaking as per
Annexure B.
Key Evaluation Criteria:
Innovation and Market Impact:
Novelty of the model
:
a product, service, or business model that is not currently offered in the market.
Harnessing technology: a new application of an existing technology or a completely new, ground breaking technology.
Differentiation: The innovation represents a significant departure from or improvement on existing offerings addressing market inefficiencies.
Inclusion: A novation that helps transitions a largely informal and high-risk market into a formalized, regulated safe ecosystem and important pillar of the economy
Risk Management and Compliance:
Review of systemic, operational, and ML/TF/PF risks.
Evaluation of cybersecurity, data protection, and consumer protection frameworks.
Consultation with Shariah advisors where applicable.
Feasibility and Exit Strategy:
Technical and operational readiness, including team expertise.
Clear testing parameters.
Exit plans (winding down if unsuccessful or transitioning to licensing if successful).
The Authority may impose limits on transaction volumes, user numbers, or exposure on a case-to-case basis.
Financial Strength
Demonstration of financial capacity to undertake the proposed business model.
Tax Law Compliance
The applicant must demonstrate compliance with applicable tax laws in Pakistan, if based in Pakistan.
After the detailed assessment and evaluation, the Authority shall issue a Letter of Approval (LoA) to the successful applicants subject to the terms and conditions as may be approved by the Authority.
Testing/ Experimentation
The approved participant will be allowed to operate in the sandbox environment for the period as approved and in compliance with the requirement stated in the Ordinance
The participant will provide reports to the Authority with contents, format and frequency as agreed mutually between the participant and the Authority prior to the commencement of testing stage.
In case, the participant encounters an unexpected technical or business difficulty beyond their control, the participant may submit a request, at least two weeks prior to the expiry of the time, for extension in time for commencement of testing period to the Authority.
The participant shall inform Authority promptly, if any unforeseen circumstances have impaired its ability to commence or complete the testing. The Authority shall advise the appropriate course of action accordingly.
Completion Report
At the end of the testing period, the participant shall submit a completion report to the Authority within two weeks of close of testing period including:
The overall results and statistics of the testing.
An objective assessment of the potential impact of the solution to be scaled out which would include:
A comparison of results with objectives defined at inception;
The scope of scaling out to a larger audience in case of success;
How the Participant will fully comply with relevant legal and regulatory requirements.
Exit Stage:
The Authority will analyse the testing phase results along with the completion report submitted by the participant at the exit stage and will determine the future course of action.
Suspension or revocation of approval:
At any stage, where Authority has possible reasons to believe that the participant has failed to adhere to the details agreed or the conditions imposed during the review and selection stage:
the Authority can temporarily suspend the testing and approval until the matter in question has been fully clarified;
the Authority can completely withdraw the approval with a public notice in case a serious discrepancy has been observed related to consumer detriment or any other serious matter.
No-Action Relief
The Authority may issue a no-action letter to the participants, stating that it does not intend to take enforcement action in respect of specified conduct for the duration of the test period. However, the issuance of a no-action letter shall not constitute a legal immunity, and the Authority reserves the right to withdraw such a letter at any time by providing written notice.
Form I
Overview
These guidelines set out what information and documentation you need to submit when applying to participate in the Sandbox. The intent is to help prepare a strong, compliant, and viable application, especially with respect to virtual assets, blockchain, and cybersecurity risks, so the Authority can assess readiness, safety, consumer protection, and suitability for live testing.
A. Innovation / Virtual Asset Service Provider Proposition
Section
What to Describe / Include
Format / Length
Attachments (Y/N)
- Service to be offered including Summary of the Innovation
Concise description of your innovation.
~500-1000 words
Y
- Blockchain / Technology Stack
DLT used (public/permissioned), smart contract platform, wallet architecture, throughput, scalability.
Bullet points / table
Y
- Cybersecurity Strategy
Threat model, security controls (encryption, key management, secure coding, audits), incident response, disaster recovery, privacy/data protection.
Table + narrative
Y
- Regulatory / Legal Environment
Applicable laws/regulations, ML/TF/PF obligations, consumer protection, IP/data protection laws.
Bullet points
Y
- Risk Management
Financial, operational, cybersecurity, legal/regulatory, market and reputational risks with mitigants.
Table format
Y
B. Readiness for Testing
Area
What to Show
Format / Length
Attachments (Y/N)
- Technical Readiness
Development status (smart contracts audited, infrastructure ready), internal testing/testnet results, capacity.
Yes/No + short description
N
- Integration / Partnerships
List of partners (banks, exchanges, VASPs), integration points (APIs, oracles).
Table/bullets
N
- Operational & Financial Readiness
Budget, funding commitments, operational structures, safeguards, KPIs/KRIs.
Bullets/table
N
- Consumer / User Safety
Protection measures (risk disclosure, loss recovery, customer support, dispute resolution).
Narrative + key points
N
Virtual Asset Product being offered, if applicable
The product details, in terms of Virtual Asset Standards.
Narrative+ Table+ key points
Y
C. Exit Strategy & Scaling
Area
What to Provide
Format / Length
Attachments (Y/N)
- Exit / Termination Strategy
Conditions for stopping test, winding down operations safely, asset return.
Bullets ~300 words
Y
- Transition to Full Deployment / Scaling Up
Steps required for scaling, licensing, technological and financial requirements.
Bullets ~300 words
Y
- Communication Plan
Informing participants: disclosures, duration, termination notices, public communication.
~300-400 words
Y
D. Applicants’ Background
Area
Required Information
Format
Attachments
- Team Background
Key persons with product related and/or blockchain/cybersecurity/finance/tech experience, qualifications.
Table
N
- Operational History & Achievements
Years in operation, past projects, incubator support, awards.
Bullets ~300 words
Y
- Funding and Support
Sources of funding, grants, incubators, prior audits/certifications.
Docs/summary
N
E. Applicant Particulars & Technical Details
Area
Details to Provide
Format
Attachments (Y/N)
- Company / Entity Information, where applicable
Name, registration number, executives, VASP status.
Description
Y
- Contact Details
Focal person, alternate contact, address.
Description
Y
- Application Category
Category: As per schedule I of the Ordinance.
Select/describe
Y
In case if the applicant is not a local company, it will be required to have the company incorporated and evidence tax registration with local tax authorities as and when sandbox approval is granted.
F. Evaluation Criteria
Applications will be assessed on:
Level of Innovation & Market Relevance
Strength of Technology and Cybersecurity Measures
Compliance with Regulatory & Legal Requirements
Operational Capacity and Readiness for Testing
Safeguards for User Protection and Consumer Trust
Clarity of Exit and Transition Strategy
Submission Checklist
☐ Innovation summary with virtual asset and blockchain details
☐ Blockchain / DLT architecture description
☐ Cybersecurity plan: threat model, mitigation, audits
☐ Legal / regulatory compliance analysis (ML/TF/PF etc.)
☐ Risk management table
☐ Technical readiness statement + testing history/testnet results
☐ Partnerships and integrations details
☐ Financial readiness / budgets for test phase; KPIs / KRIs
☐ Consumer protection and user safety measures
☐ Exit strategy + scaling plan
☐ Team background, company history, support/funding documents
☐ Contact & entity information
Annexure-A
SELF-ASSESSMENT CHECKLIST
Key Question
Positive Indicators
Negative Indicators
Scope
Is the proposed business model within the scope of the Authority?
Is the proposed business model beneficial for economy and people of Pakistan?
Your project involves virtual assets and virtual asset services, or related infrastructure relevant to Pakistan’s financial system.
Not related to Virtual Asset Services or the related eco-system.
Business Scalability
Is there a clear and growing demand for the product/service?
Does the business have potential of scalability?
Target market identified with expansion potential (local,regional,global)
Weak or stagnant user adoption
Reliance on niche or unsustainable demand (e.g., speculative hype only)
Technology & Security
Is your technology secure and resilient?
Robust IT infrastructure, cybersecurity safeguards, smart contract audits, disaster recovery plans.
Independent third-party security testing performed.
Weak cybersecurity indicators, no audits, or reliance on unverified smart contracts.
Lack of safeguards to ensure custody of consumer’s funds in case of cyber intrusions.
Genuine Innovation
Does your project introduce something significantly new or different or is solving an existing problem in a novel way or efficiently?
Introduces a new use-case for virtual assets not yet tested locally.
Adaptation of proven international solutions to Pakistan’s market with significant improvements.
Numerous similar models already exist in Pakistan.
Minor tweaks to an existing product/services or business model related to virtual assets.
Consumer & Investor Benefit
How does your project benefit users, markets and national exchequer and increases financial inclusion?
Increases transparency, lowers costs, or improves efficiency for users.
Enhances financial inclusion or access to digital financial services.
Identifies and proposes mitigation for risks (ML/TF, volatility, fraud, cyber).
Limited transparency, cost inefficient
Poses high risks of consumer loss or market instability.
No clear risk mitigation strategies (e.g., for hacks, price manipulation, or data privacy).
Readiness
Are you ready to test your model under the Ordinance/ Sandbox?
You understand applicable laws, cybersecurity, data protection, etc.
Have a clear business model, technology architecture, and compliance plan.
Testing plan with objectives, success criteria, timelines, and risk controls is ready.
Adequate financial and human resources to run a pilot.
No clarity on compliance with ML/TF, KYC, cybersecurity, or custody rules.
Lack of technical or financial readiness.
No consumer protection measures in place.
Concept only on paper yet.
Genuine Need for Sandbox
Do you need regulatory flexibility to test this?
Requires regulatory flexibility to test novel mechanisms (token issuance, DeFi protocols, smart contracts, custodial services).
Live testing not necessary to answer regulatory or market questions.
ML/TF & Compliance Preparedness
How will you meet ML/TF/PF and FATF obligations?
Strong KYC/AML processes integrated into platform design.
Alignment with FATF and Pakistan’s AML laws.
Weak or no AML/KYC framework.
High risk of misuse for money laundering, terrorism financing, or fraud.
Annexure-B
Format of undertaking to be submitted by Regulatory Sandbox Applicant
We, __________________________________________________________, incorporated/constituted under the ________________________________________________________________________ (hereinafter referred to as “the applicant”) with registered office at ____________________________________________________________________ do hereby solemnly execute this undertaking in favor of Pakistan Virtual Asset Regulatory Authority (herein referred to as the “Authority”) established under Section 6 of the Virtual Assets Ordinance, 2025.
Whereas, the applicant has submitted an application to the Authority under the Guidelines for Regulatory Sandbox (hereinafter referred to as “the Guidelines”) and having met the requirements as determined by the Authority in accordance with the Guidelines intends to participate in the Sandbox to test its innovative product/service/business model/delivery mechanism in Virtual Asset products and services in a controlled environment.
AND, whereas the applicant unconditionally and irrevocably undertakes and agrees that:
It shall operate within the sandbox as per the parameters set by the Authority;
It shall adhere to the applicable laws, rules and regulations in Pakistan;
It shall ensure consumer protection, ML/TF/PF, data security, and risk management measures are in place;
It shall ensure retention and confidentiality of consumer data as per Virtual Assets Ordinance 2025.
It shall submit information and progress reports to the Authority signed by competent authority as designated by CEO and as per agreed format and timelines during the testing stage, and;
It shall allow complete access to the Authority to its core reporting/accounting/significant software
It shall maintain proper records during testing period for reviews by Authority anytime.
It shall notify within one hour, the Authority, of any material incident, risk event, or compliance breach, detailing the extent of the breach and the remediation measures undertaken.
It shall submit a detailed incident report to the Authority within 48 hours of identifying the issue, outlining nature and scope of the incident, steps taken to contain and resolve the issue and measures to prevent recurrence.
It shall keep confidential any proprietary or sensitive information shared, except as required by law, complying to applicable data protection laws and regulations governing the collection, processing, storage, and sharing of consumer data.
It shall obtain insurance coverage to indemnify clients against any losses that may be incurred as a result of fraud or gross negligence.
It indemnifies and holds harmless the Authority from any claims arising due to participation in the sandbox. The participant agrees and acknowledges that the Authority may, at any appropriate time, impose such terms and conditions, as it determines appropriate, for the limits of liability.
It agrees and acknowledges that the Authority may terminate its participation in the Regulatory Sandbox by giving written notice at least 15 days prior to the termination date, or immediately in the following circumstances:
Breach of the testing plan;
Deployment of the proposition is expected to have negative consequences for the consumers and/or overall financial stability or failure to provide requested information;
Public interest.
It agrees to abide by and execute the exit strategy in accordance with the decision of the Authority and/or its own assessment of the test results at Exit Stage.
It agrees that if the product or service is deemed successful, its rollout shall be subject to license/approval by the Authority and compliance with regulatory requirement, as issued from time to time.
It agrees that in cases where the deployment of the service is dependent upon regulatory changes, the Authority may allow it to continue provision of the service under specific terms and conditions, until the necessary regulatory amendments are adopted.
It agrees that the Authority is under no obligation to amend regulatory framework or introduce new regulatory provisions to accommodate the product or service. It further agrees that any determination regarding regulatory changes remains at the sole discretion of the Authority.
It agrees to abide by all rules and regulations set forth by Authority, as amended from time to time, regarding access to and usage of the sandbox.
It shall ensure that all consumers involved in test are afforded the highest standard of protection, fairness, and transparency throughout the Test period.
It shall not engage in any practice that may result in consumer harm, financial loss, misleading information, or unfair treatment.
It shall implement adequate risk mitigation measures, including but not limited to fraud prevention, dispute resolution, and transaction security.
It agrees that it shall, in good faith, attempt to resolve all disputes or conflicts arising of its participation in the sandbox; and the disputes if unresolved, shall be referred to competent court in Pakistan.
It agrees that the decision of Authority is final and agrees to abide the decision of the Authority.
It shall ensure that Test Users’ personal and financial data is kept secure, confidential, and protected against unauthorized access, breaches, or misuse.
It agrees that the Test Users shall have the right to access, correct, or request deletion of their personal data at any time.
It agrees that it shall provide information pertaining to the services as may be required by the Authority.
It shall fulfill all tax obligations and maintain complete financial records as required by law, and shall not engage in or facilitate any tax evasion
It shall allow the Authority to validate the transaction and trace the flow of funds.
It shall retain all the transaction record and maintain proper book of account for a period of 7 years.
It shall provide consent to the Authority to disclose or publish any information (i.e. information that does not identify the activities of the Participant) pertaining to its participation in the sandbox.
It agrees to adhere to all terms & conditions prescribed in approval and shall cease operations upon failure to meet any stipulated terms and conditions or upon direction of the Authority.
It shall cease all sandbox activities upon expiration (if the testing is unsuccessful) or as required by the Authority.
It agrees to seek license or authorization from the Authority to operate commercially after successful conclusion of its participation in the sandbox, and comply with necessary regulatory requirements.
It agrees that its signatory/ies, as under, have the requisite power of attorney/authority to execute this undertaking.
Name, CNIC, Passport/ID Number& Signature
(Participant)
Authorized Official)
In the presence of:
Witness Name & Signature Witness Name, & Signature