Say you run a small e-commerce shop and started letting customers pay in Bitcoin last year. Or you're a fintech founder who added a "send crypto to a friend" button to your app. Or you operate a payments kiosk that lets people trade cash for stablecoins. As of July 1, 2026, all three of you need to ask the same question: does California think I'm running an unlicensed crypto business?
For most of the country, cryptocurrency regulation still feels like a patchwork of guidance letters and enforcement-by-lawsuit. California just ended that ambiguity for anyone touching its residents' digital assets. The state's Digital Financial Assets Law (DFAL) is now fully in force, administered by the Department of Financial Protection and Innovation (DFPI), and the penalty for operating without a license — or a pending application — can run up to $100,000 per day. This guide breaks down who's actually covered, who's exempt, and what a small business handling digital assets should do right now.
What the DFAL Actually Requires
The DFAL prohibits any person or entity from engaging in "digital financial asset business activity" with, or on behalf of, a California resident unless that entity holds a license from the DFPI or qualifies for an exemption. Critically, this applies regardless of where your business is physically located. If you have customers in California, California's rules reach you — a lesson plenty of out-of-state fintech companies are learning the hard way.
The law defines "digital financial asset business activity" around three core functions:
- Exchange — converting digital financial assets into legal tender, bank credit, or other digital assets
- Transfer — moving digital financial assets from one person to another
- Custody and storage — holding, maintaining, or controlling digital assets on behalf of someone else
The common thread across all three is control — the legal power to unilaterally execute or indefinitely block a transaction involving the asset. If your business never takes control of a customer's digital assets, you're likely outside the law's reach. If it does — even briefly, as a pass-through — you probably need to pay attention.
Holding a license in another state doesn't get you off the hook. The DFPI has been explicit that a New York BitLicense or an existing California money transmitter license does not automatically satisfy DFAL requirements. Each license covers a distinct set of activities, and DFPI expects its own application regardless of what you're already licensed to do elsewhere.
Who's Actually Exempt
Before you panic, check whether you fall into one of the law's carve-outs. The most useful one for small businesses is the merchant exemption: a business that accepts a digital financial asset as payment for goods or services — where those goods or services are not themselves digital financial assets — is not required to hold a DFAL license. In plain terms: if you're a bakery, a consulting firm, or a SaaS company that lets customers pay with Bitcoin through a payment processor, and you're not exchanging, transferring, or custodying crypto on anyone else's behalf, you're likely exempt.
There's also a de minimis exemption for anyone who reasonably expects to earn less than $50,000 annually from activity that would otherwise trigger DFAL licensure. That's a meaningful buffer for side projects, early-stage products, or hobbyist platforms still finding product-market fit — but it's a hard ceiling, not a suggestion. Once you cross it, you're in scope.
Other categorical exemptions include:
- Government entities (federal, state, and local agencies)
- FDIC-insured banks
- Federally or state-chartered credit unions with California offices
- California-licensed trust companies
Notice what's not on that list: payment processors, wallet providers, crypto-enabled fintech apps, stablecoin issuers, and Bitcoin ATM (kiosk) operators. If your product does more than let customers spend crypto on things that aren't crypto, read the statute carefully — or get a lawyer to read it for you — before assuming you're covered by an exemption.
The Businesses Most Likely to Get Caught Off Guard
The DFAL was written with crypto exchanges and Bitcoin ATM chains in mind, but its plain-language scope catches a much wider set of businesses that don't think of themselves as "crypto companies" at all. A few examples worth pressure-testing against your own operations:
- Marketplaces and gig platforms that hold crypto balances for users. If your platform lets sellers or contractors accumulate a digital-asset balance before cashing out — rather than paying out immediately through an external processor — you may be custodying assets on their behalf, which is squarely inside the DFAL's definition.
- Payroll or contractor-payment tools that offer crypto payout options. Converting a contractor's pay into a digital asset and holding or routing it for them is exchange-and-transfer activity, not merchant payment acceptance.
- Loyalty and rewards programs built on-chain. Issuing or redeeming crypto-denominated rewards points can look a lot like operating a digital asset business, even if the core product is unrelated to finance.
- SaaS or app platforms with an embedded wallet feature. Bolting on a "store your crypto here" feature to an otherwise ordinary product doesn't inherit the merchant exemption — the wallet functionality is evaluated on its own.
None of these examples automatically means you need a license; each depends on the specifics of how funds move and who controls them at each step. But they illustrate why "we're not a crypto company" isn't a safe enough answer on its own — the DFAL cares about what your product does, not what industry you'd put on a pitch deck.
The Cost of Getting This Wrong
The DFPI's enforcement authority isn't theoretical. In June 2025, the department entered a consent order with Coinme Inc., a Seattle-based Bitcoin ATM operator, resulting in a $300,000 penalty plus $51,700 in restitution to an elderly California resident — an early signal of how aggressively the state intends to police this space, even before the full licensing deadline hit.
Now that the DFAL is in force, the penalty structure is explicit:
- Up to $100,000 per day for operating without a license or a pending application
- Up to $20,000 per day, or per incident, for violations committed by businesses that are already licensed
Those numbers compound fast. A business that discovers a compliance gap and takes even a few weeks to sort it out could be looking at a penalty in the millions before the DFPI ever needs to prove intent to defraud anyone. This is a strict, activity-based licensing regime, not a "we'll get you eventually" enforcement posture — the July 1 deadline was a hard line, not a soft target.
What the Application Actually Involves
If your business is in scope, the application runs through the Nationwide Multistate Licensing System (NMLS), which the DFPI opened for DFAL applications on March 9, 2026. Expect to provide:
- Audited or unconsolidated financial statements
- Flow-of-funds documentation showing how customer assets move through your systems
- Management and ownership information, including background checks on key personnel
- An independent review of your Bank Secrecy Act / anti-money-laundering (BSA/AML) program
- A documented information security and operational security program
One piece of good news: the DFPI removed the originally proposed $500,000 surety bond requirement from the application, lowering the up-front capital bar for smaller applicants. That said, everything else on the list still requires real compliance infrastructure — the kind that takes weeks or months to build if you don't already have it, not something you assemble the week before a deadline.
For businesses operating Bitcoin ATMs or similar crypto kiosks, there's an additional layer of rules that predate the full DFAL rollout: kiosk locations must be registered with the DFPI, per-customer transactions are capped at $1,000 per day, transaction fees can't exceed the greater of $5 or 15% of the dollar value exchanged, and operators must provide pre-transaction disclosures and printed receipts.
What to Do If You're Not Sure You're Covered
The honest answer for a lot of small businesses is: it's genuinely unclear. The line between "merchant accepting crypto payments" and "business handling digital financial asset transfers" gets blurry fast once you add features like in-app wallets, peer-to-peer transfers, staking, or crypto rewards programs. A few practical steps:
- Map exactly what your product does with a customer's digital assets. Do you ever take custody, even momentarily? Do you facilitate transfers between two of your users, or only between a user and an external, unaffiliated processor?
- Estimate your California-derived revenue from any DFAL-adjacent activity. If you're comfortably under $50,000 annually and expect to stay there, document that reasoning — you may want it on hand if the DFPI ever asks.
- Don't wait for a compliance audit to find out you were wrong. Given the per-day penalty structure, the cost of confirming your status now is trivial next to the cost of being wrong for even a month.
- If you're in scope, start the NMLS application immediately — a completed-but-pending application is what keeps you on the right side of the July 1 deadline, not a finished review.
Keep Your Records Straight, Whatever You Decide
Whether you end up filing for a DFAL license or confirming you're exempt, the underlying discipline is the same: know exactly what's moving through your business and be able to prove it. Digital asset transactions — exchanges, transfers, even routine crypto payments accepted under the merchant exemption — need the same clear, auditable trail as any other transaction on your books, especially if a regulator or an accountant ever asks you to reconstruct your flow of funds.
That's precisely the kind of record-keeping plain-text accounting is built for. Beancount.io gives you transparent, version-controlled financial records — including digital asset activity — with no black boxes and no vendor lock-in. Get started for free and keep your books audit-ready no matter which side of a regulatory line your business falls on.