Tax & Banking

Crypto Tax Pakistan: VASP Obligations Under the Act

Section 66 of the Virtual Assets Act 2026 sends every licensed VASP to the FBR. What the Act says on crypto tax in Pakistan, and what it leaves open.

The Virtual Assets Act, 2026 runs to seventy-four sections, twelve chapters and a schedule. Exactly one of those sections deals with tax, and it is four lines long.

That brevity is not an oversight. It is a jurisdictional decision. The Pakistan Virtual Asset Regulatory Authority (PVARA) has been given licensing, prudential, conduct and anti-money-laundering powers over virtual assets. It has not been given the power to write tax law. So the Act does the only thing it sensibly can: it points every licensee at the Federal Board of Revenue (FBR) and moves on.

For anyone building a licensing budget, that single section has larger consequences than its length suggests. Below is what the primary documents actually say about tax — the Act, the Sandbox Guidelines 2026 and the No Objection Certificate Regulations 2025 — and, just as importantly, where they say nothing.

What does the Virtual Assets Act 2026 actually say about tax?

One provision. Section 66, headed “Tax Compliance”, requires every licensed Virtual Asset Service Provider (VASP) to comply with income tax law and FBR rules. It creates no crypto-specific tax, no rate, no exemption and no filing regime of its own.

The operative wording is short enough to read in full:

“66. Tax Compliance.— Every Virtual Asset Service Provider licensed under this Act shall comply with the obligations imposed under the Income Tax Act, 2001 and any Rules or Regulations issued by the Federal Board of Revenue.”

Three features of that drafting matter in practice.

First, it is addressed to a licensed VASP. A “Licensee” is defined in section 3(1)(xvi) as a person who holds a licence under the Act. Section 66 therefore attaches to the licence, not to the activity. It does not create a new tax obligation for an applicant sitting in the No Objection Certificate (NOC) stage, and it does not create one for an unlicensed operator. General tax law reaches those parties independently — section 66 simply adds a regulatory hook on top of it once a licence exists.

Second, it names Issuers nowhere. Section 66 refers only to Virtual Asset Service Providers. The Act elsewhere treats “Issuer” as a distinct concept — section 3(1)(xiii) defines it separately, and section 42 imposes separate obligations on Issuers. Whether a pure Issuer that holds no VASP licence falls inside section 66 on its own terms is, on the face of the document, open. Our reading is that this is a drafting economy rather than a policy carve-out, because Issuers remain fully within Pakistan’s ordinary tax net regardless. But it is a gap worth noting if you are structuring an issuance vehicle alongside your licensed operating company.

Third, there is no derogation. Section 5(1) provides that the Act is “in addition to, and not in derogation of, any other law for the time being in force”. Where there is inconsistency, the Act prevails — except against the Foreign Exchange Regulation Act, 1947, and except where another law deals with data protection, data governance, cybersecurity, financial secrecy or cross-border personal data transfer, which prevail under section 5(2). Tax law is not carved out either way. In practice, that means the Act creates no tax shelter and no special virtual asset tax regime. Licensing does not change your tax position; it merely makes tax compliance a supervisable condition of holding the licence.

Which tax law applies, and who writes the rules?

Section 66 sends licensees to two places: the income tax statute it names as the “Income Tax Act, 2001”, and any rules or regulations issued by the Federal Board of Revenue. PVARA writes the virtual asset rulebook. The FBR writes the tax rulebook. Nothing in the Act lets PVARA do the latter.

That division is reinforced by the Authority’s own powers. Section 9(2) lists what PVARA may do — make regulations, set prudential and conduct standards, licence, inspect, sanction, and under section 9(2)(j) “levy such fees, charges and penalties as may be Prescribed by Rules”. Fees and penalties are not taxes. Section 14(2) confirms the point by treating “NOC, licensing, supervision, renewal or other fees received by the Authority” as receipts of the PVARA Fund, sitting alongside “penalties, fines, settlements, and other recoveries”. Those are regulatory revenues, and they are a cost line in your licensing model, entirely separate from your tax and banking workstream.

Where the two regimes do meet is information. Under section 17(1) of the Act, PVARA is required to cooperate and share supervisory and enforcement information “in a timely and secure manner” with a named list of bodies that expressly includes the Federal Board of Revenue, alongside the State Bank of Pakistan, the Securities and Exchange Commission of Pakistan, the Financial Monitoring Unit and the Federal Investigation Agency. Section 17(3) allows PVARA to set up inter-agency coordination mechanisms for the same purpose.

Read that with section 48, which requires licensees to establish secure reporting channels and, where required, secure automated interfaces enabling the Authority “and such other agencies as notified” to access prescribed data. The architecture contemplated by the Act is one in which the regulator holds transaction-level supervisory data and is under a statutory duty to share enforcement information with the revenue authority. That is the single most important structural fact about crypto tax in Pakistan for a licensed VASP, and it has nothing to do with rates.

What tax obligations does a sandbox participant sign up to?

More explicit ones than the Act imposes. The PVARA Sandbox Guidelines 2026 make tax compliance an evaluation criterion at entry, and the mandatory undertaking at Annexure-B contains express anti-evasion, record-keeping and traceability commitments.

At the assessment stage, the Guidelines list “Tax Law Compliance” among the Key Evaluation Criteria:

“The applicant must demonstrate compliance with applicable tax laws in Pakistan, if based in Pakistan.”

Form I, Part E goes further for foreign applicants: “In case if the applicant is not a local company, it will be required to have the company incorporated and evidence tax registration with local tax authorities as and when sandbox approval is granted.” Tax registration is therefore a condition of proceeding, not a post-launch tidy-up. If you are mapping the sandbox route, this sits alongside the other onboarding steps covered in our Form I walkthrough.

The Annexure-B undertaking, which an approved participant must execute in favour of the Authority, then binds the participant to a set of commitments with direct tax consequences:

  • It shall “fulfill all tax obligations and maintain complete financial records as required by law, and shall not engage in or facilitate any tax evasion”.
  • It shall “allow the Authority to validate the transaction and trace the flow of funds”.
  • It shall “retain all the transaction record and maintain proper book of account for a period of 7 years”.
  • It shall “allow complete access to the Authority to its core reporting/accounting/significant software”.
  • It shall submit information and progress reports signed by a competent authority designated by the CEO, in the agreed format and timelines.

Note the second and fourth items. A sandbox participant contractually grants PVARA the ability to trace fund flows and to open its accounting systems. Combined with the section 17 duty to share enforcement information with the FBR, a participant should assume its books are visible to the state, not merely auditable on request. Anyone weighing the sandbox against a full application should factor that in alongside the capital considerations we set out on reduced capital and sandbox testing.

Where does tax appear elsewhere in the framework?

In four places beyond section 66, none of which is a tax rule as such — but each of which turns your tax history into a licensing variable.

Provision Source What it requires
s.66 Act Licensed VASPs comply with income tax law and FBR rules
s.17(1) Act PVARA shares supervisory and enforcement information with FBR
s.22(c) and s.27(2) Act Periodic returns and an annual audit by Chartered Accountants approved by the Division concerned, including verification of customer asset segregation
Key Evaluation Criteria; Form I Part E Sandbox Guidelines Demonstrated tax compliance; local tax registration for foreign applicants
Annexure-B Sandbox Guidelines Anti-evasion undertaking; 7-year books; fund-flow traceability
Forms A2 and A3, Financial Soundness NOC Regulations Disclosure of any tax enforcement or penalties
Form A2, Section 4 NOC Regulations Tax filings as evidence of source of wealth and source of funds

The last two deserve emphasis. In Form A2, every Controller — defined in Regulation 7.1 as any person holding 20% or more of voting power or share capital — and every Beneficial Owner must disclose whether they have been “subject to tax enforcement or penalties”, and must document source of wealth and source of funds with evidence that expressly includes tax filings. Form A3 asks each Key Individual the same question under Financial Soundness. Tax residency across all jurisdictions is collected in both forms.

So an unresolved tax dispute involving a shareholder is not a tax problem in the PVARA process. It is a fitness and propriety problem, assessed under section 20 of the Act and Part 2 of the NOC Regulations, and it can sink an application that is otherwise strong. We deal with how that assessment actually runs in our Form A3 fit and proper walkthrough, and it is one of the reasons the regulatory and licensing workstream and the tax workstream cannot be sequenced separately.

How long must a licensed VASP keep records?

Seven years, on the documents available. The Sandbox Annexure-B undertaking specifies seven years for transaction records and books of account. Regulation 13.1 of the NOC Regulations sets a minimum of seven years for all AML/CFT records. The Act itself defers the licensee retention period to regulations.

Section 47(4) of the Act provides that a licensee shall maintain records of transactions, customer due-diligence data and risk assessments “for a period prescribed by Regulations, which shall not be less than the period required under the Anti-Money Laundering Act, 2010”. Section 46(2)(b) is to similar effect. The Act therefore sets a floor by reference to AML law rather than a fixed number, and the two instruments that do specify a number both say seven years.

In practice, a single seven-year retention architecture covering AML records, transaction records and books of account satisfies every retention requirement visible in these documents. Regulation 13.2 adds that records must be “stored securely and must be auditable, retrievable and tamper-evident” — a specification that also happens to describe what a defensible tax position looks like. If you are designing that stack, note that section 39 permits offshore storage subject to data protection and cross-border transfer law, but section 39(2) preserves PVARA’s power to require immediate localisation of specific datasets.

What has the Act deliberately left to the FBR?

Almost everything a taxpayer wants to know. The Act settles which body writes virtual asset tax rules and that licensees must obey them. It settles nothing about characterisation, rates, withholding, thresholds, reporting formats or the treatment of specific virtual asset activities.

Settled by the Act Left to the FBR
Licensed VASPs must comply with income tax law (s.66) How virtual asset gains and revenues are characterised
PVARA shares enforcement information with FBR (s.17) Rates, thresholds and withholding mechanics
Regulatory fees are payable to PVARA, not FBR (s.14, s.9(2)(j)) Reporting formats and filing deadlines
Annual audit by approved Chartered Accountants (s.27(2)) Treatment of staking, mining and lending returns
Tax history feeds fit and proper assessment (NOC Forms A2, A3) Any virtual asset-specific documentation standard

Nothing in these three documents prescribes how a licensed exchange should treat trading fee income, how a custodian should treat customer assets for tax purposes, or how a lending platform should treat interest. Those questions live in tax law and FBR guidance, and they must be verified against the current published position of the FBR rather than inferred from the Act. Our general treatment of the wider Pakistani position sits in our crypto tax guide, and readers modelling individual outcomes can use the Pakistan crypto tax calculator.

One more asymmetry is worth flagging. Section 66 sits in Chapter 12, Miscellaneous, and carries no penalty of its own. But section 59(1) empowers PVARA to sanction a person who contravenes “any provision of this Act” — with reprimand, remedial directive, financial penalty, licence suspension or revocation, or disqualification from office. Because section 66 is a provision of the Act, a tax default is capable of becoming an administrative matter for PVARA in addition to whatever the FBR does. Section 23(1)(a) allows variation, suspension or revocation of a licence where a licensee “has contravened any provisions of this Act or any other applicable laws”. Read literally, that reaches tax law directly.

About this analysis

This analysis was prepared by the CoinConnect research desk from the Virtual Assets Act, 2026, the PVARA No Objection Certificate Regulations and the PVARA Sandbox Guidelines 2026, read as published. Where practice is not yet settled or guidance has not been issued, that is stated in the text above.

Regulatory positions change and specific requirements should be verified against the current position published by the relevant authority before you act on them. This is information and analysis, not legal advice, and it does not create an advisory relationship. Take professional advice on your own circumstances.

Entering Pakistan's crypto market?

CoinConnect handles market entry, partnerships, PR and launch for exchanges and Web3 companies moving into Pakistan and South Asia.

Visit CoinConnect