Sandbox

PVARA Sandbox 2026: Eligibility, Application and Exit

How the PVARA sandbox works: eligibility, Form I, the 60-working-day assessment, testing obligations, no-action relief and how participation ends.

Pakistan’s virtual asset framework gives the regulator two very different doors. One is the full licensing route — incorporate, capitalise, get authorised, operate. The other is the sandbox: a controlled environment in which a firm tests a genuinely new product on a limited basis, under supervision, before it is licensed at all.

The Pakistan Virtual Asset Regulatory Authority (PVARA) has published Sandbox Guidelines 2026 setting out how that second door works — eligibility, the application form, the assessment clock, the reporting burden during testing, and what happens on exit.

This article walks through the Guidelines end to end, together with the sandbox provision in the Virtual Assets Act, 2026. It is written for founders and compliance leads deciding whether the sandbox is the right entry route, or a costly detour.

What is the PVARA sandbox?

The PVARA sandbox is a controlled testing environment operated by the Authority in which approved participants may run innovative virtual asset products and services live, for an approved period, under a supervisory arrangement with PVARA, before holding a full licence. The Sandbox Guidelines 2026 define it as:

“the controlled environment established and operated by the Authority under Section 42 of the Ordinance for the purpose of fostering responsible innovation in Virtual Asset products and services.”

The stated objectives include enabling responsible testing, promoting innovation while protecting investors and market integrity, identifying risks in innovative products “in local and global context”, and defining clear procedures for intake, assessment, onboarding, supervision, monitoring and exit.

Two words in that definition do real work. Controlled means PVARA sets the parameters — and under the Key Evaluation Criteria in the Guidelines, “The Authority may impose limits on transaction volumes, user numbers, or exposure on a case-to-case basis.” Testing means it is not a commercial licence. The Guidelines are explicit that if the product succeeds, “its rollout shall be subject to license/approval by the Authority”.

Section 35 of the Virtual Assets Act, 2026 empowers the Authority to establish a regulatory sandbox. Section 35(1) provides that the Authority “may establish a regulatory sandbox to facilitate controlled testing of innovative Virtual Asset products or services, in the manner prescribed by Regulations”, and section 35(2) leaves eligibility, application procedures, supervisory arrangements, risk limits, duration and exit requirements to Regulations.

Section 35(3) adds that the Authority “may issue guidance, no-objection statements or no-action communications in accordance with Regulations”. Section 9(2)(k) separately lists operating regulatory sandboxes “in a transparent and accountable manner” among the Authority’s powers, and section 14(2)(j) allows the Authority’s Fund to receive charges for services including sandbox participation.

One drafting point matters for anyone reading the two instruments side by side. The Sandbox Guidelines 2026 are drafted against the Virtual Assets Ordinance, 2025 and cite its sections 42 to 45. The Act, as passed by the National Assembly, carries the sandbox provision at section 35. Section 74 of the Act is a savings provision, preserving anything done, action taken, or notification or order issued under the lapsed Ordinance as if done under “the corresponding provisions of this Act”. Our reading is that the Guidelines survive on that basis and that the section references should be read across to the Act, but the cross-references have not yet been renumbered in the published Guidelines. Confirm the current position with the Authority before relying on a specific section number. Our PVARA licence guide tracks these instruments as they are reissued.

Who qualifies to enter the sandbox?

An applicant must be fit and proper, operationally ready to test, and able to show a completed regulatory and risk assessment. The Guidelines set out four eligibility limbs, and the last one is the filter most applicants underestimate: the applicant must confirm that the product or service “is not designed for speculation, anonymity, or illicit activity”.

The eligibility criteria in full:

  • Fit and proper standing — no directors, sponsor shareholders, controllers or key management found liable for fraud, financial crime or misconduct; no prior regulatory or licensing breaches, including proscribed and designated persons; no bankruptcy or insolvency proceedings unless adequately resolved. The same integrity themes run through PVARA’s licensing paperwork, and the Form A3 fit and proper questionnaire is a useful proxy for the depth of disclosure expected.
  • Operational readiness — a defined testing plan with objectives, duration, KPIs and target users; risk management and consumer protection measures covering data security, dispute resolution and safeguarding consumer assets; a complete governance structure with a clearly identifiable ultimate beneficial owner; a sandbox exit plan; and readiness for technical, financial and human scalability.
  • A comprehensive regulatory and risk assessment addressing cybersecurity, data privacy, operational risk, market risk and systemic risk.
  • Compliance with the applicable legal framework, plus the confirmation described above.

The internal control expectations bundled into the readiness limb are extensive: enterprise risk assessment, identity verification with detailed KYC and screening for both originator and beneficiary, complaint handling, segregation of client money and virtual assets, liability management to protect clients from fraud, flagging and reporting of suspicious transactions, technology risk including private key protection, full risk disclosure to clients, and compliance with cross-border supervision and information sharing protocols where applicable. Much of this overlaps with the AML architecture required elsewhere in the framework — see our note on FMU goAML registration for how the reporting side is built.

How do you apply, and what does Form I require?

Applications are made on Form I of the Sandbox Guidelines, accompanied by the Annexure-A self-assessment checklist, and may be submitted at any time during the year. The Guidelines describe this as an “Agile Approach”, meaning applicants “may submit applications at any time during the year for consideration by the Authority” — there are no fixed cohort windows.

The Authority “may prescribe application fee, as it may deem appropriate”. Applications are reviewed for completeness, and the Guidelines state that “Incomplete applications will be returned with a request for revisions, with up to two resubmissions permitted”. That cap is the single most important procedural fact in the document: three bites, then nothing.

Form I is organised into six parts:

Part Covers
A Innovation proposition — service summary, blockchain/technology stack, cybersecurity strategy, regulatory and legal environment, risk management
B Readiness for testing — technical readiness, integrations and partnerships, operational and financial readiness, consumer safety, virtual asset product details
C Exit strategy and scaling — termination strategy, transition to full deployment, communication plan
D Applicant background — team, operational history, funding and support
E Applicant particulars — entity information, contacts, application category per Schedule I
F Evaluation criteria and submission checklist

Form E carries a structural requirement for offshore applicants: “In case if the applicant is not a local company, it will be required to have the company incorporated and evidence tax registration with local tax authorities as and when sandbox approval is granted.” Sandbox approval therefore triggers the same company registration and tax registration workstreams a licensing applicant faces. Our section-by-section Form I walkthrough covers the drafting in detail.

How does PVARA assess a sandbox application?

Applications that clear initial screening move to an evaluation phase, and the Guidelines require the comprehensive evaluation to be completed “within sixty (60) working days from the conclusion of the initial screening unless the Authority determines that there is reasonable cause to extend timeline”. Where the applicant is already regulated, “the input from relevant regulator may be sought”.

Assessment is conducted on the application submission plus any further information the Authority requests, to test both the suitability of the applicant and the viability of the product. The key evaluation criteria are grouped as follows:

  • Innovation and market impact — novelty of the model, harnessing of technology, differentiation from existing offerings, and inclusion, described as innovation that helps transition “a largely informal and high-risk market into a formalized, regulated safe ecosystem”.
  • Risk management and compliance — systemic, operational and ML/TF/PF risk; cybersecurity, data protection and consumer protection frameworks; and “Consultation with Shariah advisors where applicable”.
  • Feasibility and exit strategy — technical and operational readiness including team expertise, clear testing parameters, and exit plans for both failure and success.
  • Financial strength — demonstrated capacity to undertake the proposed business model.
  • Tax law compliance — the applicant must demonstrate compliance with applicable Pakistani tax law if based in Pakistan.

Successful applicants receive a Letter of Approval (LoA) subject to terms and conditions approved by the Authority, and must then submit the Annexure-B undertaking. If you are still weighing entry routes, our comparison of sandbox, NOC, no-action and full licence sets the options against each other, and the regulatory and licensing service page explains how we run these applications.

What obligations apply once you are in the sandbox?

Participants operate for the approved period, report to PVARA on a mutually agreed format and frequency fixed before testing begins, and are bound by the Annexure-B undertaking. The undertaking’s incident clock is unusually tight: notification to the Authority within one hour of any material incident, risk event or compliance breach, followed by a detailed incident report within 48 hours.

Other obligations in the undertaking include:

  • Allowing the Authority “complete access” to core reporting, accounting and significant software, and permitting it to validate transactions and trace the flow of funds.
  • Retaining all transaction records and books of account for seven years.
  • Obtaining insurance coverage to indemnify clients against losses from fraud or gross negligence.
  • Indemnifying the Authority against claims arising from participation.
  • Accepting termination on 15 days’ written notice, or immediately for breach of the testing plan, expected negative consequences for consumers or financial stability, failure to provide requested information, or public interest.
  • Ensuring test users can access, correct or request deletion of their personal data at any time.

Where an unexpected technical or business difficulty beyond the participant’s control arises, the Guidelines allow a request for extension of time for commencement of the testing period, submitted “at least two weeks prior to the expiry of the time”. Participants must also notify the Authority promptly if unforeseen circumstances have impaired their ability to commence or complete testing.

Separately, PVARA may temporarily suspend testing and approval until a matter is clarified, or “completely withdraw the approval with a public notice in case a serious discrepancy has been observed related to consumer detriment or any other serious matter”. A public withdrawal notice is a reputational event, not merely a regulatory one — a theme we develop in our piece on protecting reputation on market entry.

What is no-action relief, and does it protect you?

No-action relief is a letter from the Authority stating that it does not intend to take enforcement action in respect of specified conduct for the duration of the test period. It is not immunity. The Guidelines are unambiguous:

“the issuance of a no-action letter shall not constitute a legal immunity, and the Authority reserves the right to withdraw such a letter at any time by providing written notice.”

The Guidelines define No-Action Relief by reference to section 45 of the Ordinance; the corresponding power in the Act appears at section 35(3), which permits the Authority to issue “guidance, no-objection statements or no-action communications in accordance with Regulations”. In practice, a no-action letter manages regulatory risk with PVARA for a defined test. It does not displace the prohibitions in Chapter 9 of the Act, obligations under the Anti-Money Laundering Act, 2010, or the duties of any other regulator. Treat it as narrow and revocable.

How does sandbox participation end?

Testing ends with a completion report, submitted within two weeks of the close of the testing period, followed by an exit stage at which the Authority analyses the results and determines the future course of action — full authorisation, discontinuation, or other steps as directed.

The completion report must include:

  • the overall results and statistics of the testing;
  • an objective assessment of the potential impact of the solution if scaled out, comparing results against the objectives defined at inception;
  • the scope for scaling out to a larger audience in the event of success; and
  • how the participant will fully comply with relevant legal and regulatory requirements.
Stage Timing in the Guidelines
Application Any time during the year (agile)
Resubmission if incomplete Up to two resubmissions
Comprehensive evaluation 60 working days from conclusion of initial screening, extendable for reasonable cause
Extension request before testing starts At least two weeks before expiry
Completion report Within two weeks of close of testing
Incident notification / report 1 hour / 48 hours
Record retention 7 years

The undertaking also commits participants to seek a licence or authorisation to operate commercially after a successful conclusion, to cease all sandbox activities on expiry if testing is unsuccessful or as required by the Authority, and to accept that the Authority “is under no obligation to amend regulatory framework or introduce new regulatory provisions to accommodate the product or service”.

About this analysis

This analysis was prepared by the CoinConnect research desk from the Virtual Assets Act, 2026, the PVARA No Objection Certificate Regulations and the PVARA Sandbox Guidelines 2026, read as published. Where practice is not yet settled or guidance has not been issued, that is stated in the text above.

Regulatory positions change and specific requirements should be verified against the current position published by the relevant authority before you act on them. This is information and analysis, not legal advice, and it does not create an advisory relationship. Take professional advice on your own circumstances.

Entering Pakistan's crypto market?

CoinConnect handles market entry, partnerships, PR and launch for exchanges and Web3 companies moving into Pakistan and South Asia.

Visit CoinConnect