Most people who read the Virtual Assets Act 2026 stop at the licensing chapter and assume that is the whole of PVARA’s toolkit. It is not. Section 9 sets out what the Pakistan Virtual Assets Regulatory Authority (PVARA) is for, and then lists, power by power, what it is actually entitled to do to get there.
Section 9(1) states the Authority’s functions in general terms — licensing, protecting customers, attracting investment, promoting innovation, classifying assets, cooperating with other agencies, and advising government. Section 9(2) is the operative list: fourteen specific powers, lettered (a) through (n), that give those functions teeth. If you are dealing with PVARA — as an applicant, a licensee, or a customer with a complaint — this is the list that tells you what is actually within its authority to do.
What are PVARA’s fourteen powers under section 9(2)?
Section 9(2) of the Act gives PVARA fourteen specific powers “for the purposes of sub-section (1), and without prejudice to the generality of the foregoing.” They range from making binding rules to running a regulatory sandbox to simply running public education campaigns. Together they cover rule-making, licensing, supervision, enforcement, cooperation and outreach.
| Ref | Power |
|---|---|
| 9(2)(a) | Make Regulations, standards, directives, guidelines, handbooks and circulars |
| 9(2)(b) | Set prudential, conduct, operational-resilience, risk-management, cybersecurity, data-protection and technical standards |
| 9(2)(c) | Issue, vary, suspend or revoke licences, approvals or directives, and prescribe conditions for such actions |
| 9(2)(d) | Prescribe licensing conditions, eligibility criteria, renewal requirements and additional obligations for licensees |
| 9(2)(e) | Conduct on-site inspections and off-site monitoring of licensees and other entities |
| 9(2)(f) | Require licensees to furnish information, documents and data within a prescribed timeframe |
| 9(2)(g) | Ensure compliance with data-protection, data-governance and cybersecurity obligations, subject to supervisory follow-up |
| 9(2)(h) | Impose administrative sanctions in accordance with the Act, Rules or Regulations |
| 9(2)(i) | Apply to court for civil or criminal remedies as provided under any applicable law |
| 9(2)(j) | Levy fees, charges and penalties as prescribed by Rules |
| 9(2)(k) | Operate regulatory sandboxes in a transparent and accountable manner |
| 9(2)(l) | Enter into cooperation or mutual-assistance arrangements with domestic and foreign regulators and law-enforcement agencies |
| 9(2)(m) | Conduct public education and awareness initiatives |
| 9(2)(n) | Constitute as many committees as deemed necessary |
Nothing in this list requires a court order first. Every one of these powers sits with the Authority itself, which is a deliberate design choice: PVARA is built to act quickly, not to wait on litigation.
What are PVARA’s objectives before we get to the powers?
Under section 9(1), PVARA’s functions are to licence, regulate and supervise virtual asset service providers (VASPs) and issuers; protect customers and market integrity; attract investment; promote responsible innovation and financial inclusion; promote blockchain and distributed ledger technology (DLT) adoption; classify assets and activities; coordinate with other agencies against money laundering and terrorist financing; and advise the Federal Government on emerging risks.
The powers in section 9(2) exist to serve those functions — the Act is explicit that the list is “without prejudice to the generality” of section 9(1), meaning the fourteen powers are examples of how the objectives get carried out, not an exhaustive ceiling on what PVARA may do in pursuit of them. In practice, this gives the Authority considerable interpretive latitude: a power not spelled out but reasonably connected to an objective in 9(1) is still likely to be within scope, subject to section 9(1)(i)’s catch-all — “do all such acts as may be necessary or incidental to the discharge of its functions.”
Which powers let PVARA write its own rules?
Two powers, 9(2)(a) and 9(2)(b), give PVARA the ability to generate binding regulatory instruments without going back to Parliament each time. Section 9(2)(a) lets it “make Regulations, standards, directives, guidelines, handbooks and circulars, or any other instrument, consistent with the objectives of this Act and other applicable laws.” Section 9(2)(b) lets it “set prudential, conduct, operational resilience, risk-management, cybersecurity, data protection & technical standards.”
This is the mechanism behind almost everything a VASP actually has to comply with day to day. The Act itself is a framework; the Regulations, standards and circulars issued under 9(2)(a) and (b) are where the detailed obligations — capital thresholds, custody standards, reporting formats — actually get written. Under section 68, the Authority makes these Regulations in consultation with the Division concerned, but the power to originate them sits with PVARA, not the legislature.
What licensing powers does PVARA hold?
Sections 9(2)(c) and 9(2)(d) cover the licensing lifecycle end to end. Paragraph (c) lets the Authority “issue, vary, suspend or revoke licenses, approvals or directives under this Act and prescribe conditions for such actions.” Paragraph (d) lets it “prescribe licensing conditions, eligibility criteria, renewal requirements and any additional obligations for Licensees.”
Read together with Chapter 3 of the Act — the licensing framework proper — these two powers are what allow PVARA to move the goalposts on eligibility and renewal without new legislation. An applicant going through the no objection certificate process or a licensee approaching renewal should treat these conditions as capable of change between application cycles.
How does PVARA supervise licensees on an ongoing basis?
Three powers form the supervisory core: on-site and off-site monitoring under 9(2)(e), information demands under 9(2)(f), and data-protection follow-up under 9(2)(g).
- 9(2)(e) lets PVARA “conduct on-site inspections and off-site monitoring of Licensees and other entities to ensure compliance with this Act and relevant Rules and Regulations.” Note the phrase “other entities” — inspection power is not limited to licensees.
- 9(2)(f) lets PVARA “require Licensees to furnish information, documents and data in the manner and timeframe reasonably Prescribed by Regulations.” The word “reasonably” qualifies the timeframe, not the obligation itself.
- 9(2)(g) lets PVARA “ensure compliance of data-protection, data-governance and cyber security obligations by Virtual Asset Service Providers subject to supervisory follow-up.”
These three powers underpin the ongoing compliance obligations a licensee carries after the licence is granted — this is not a one-time gate. Refusal to provide information demanded under 9(2)(f) also has criminal consequences: section 57(3) of the Act punishes wilful refusal to provide information to an authorised officer with imprisonment up to one year or a fine up to one million Rupees.
What enforcement powers does PVARA hold, and does it need a court?
Three powers give PVARA teeth: administrative sanctions under 9(2)(h), the ability to go to court under 9(2)(i), and fee and penalty levies under 9(2)(j).
- 9(2)(h) — “impose administrative sanctions in accordance with the provisions of this Act and any Rules or Regulations made thereunder.” This is the power exercised through section 59, and it does not require a court order. PVARA can reprimand, direct, fine, suspend, revoke or disqualify on its own initiative.
- 9(2)(i) — “apply to court for civil or criminal remedies as provided under any applicable law.” This is the route for outcomes PVARA cannot deliver itself, such as a criminal conviction under section 54.
- 9(2)(j) — “levy such fees, charges and penalties as may be Prescribed by Rules.” Note this power is exercised through Rules, made by the Federal Government under section 67, rather than through Regulations made by PVARA under section 68.
Our reading is that this three-part structure — administrative sanction, court application, and fee-levy — gives PVARA a graduated response: it can act unilaterally for most contraventions, and reserve the court route for matters requiring criminal process or civil remedies beyond its own administrative reach.
Can PVARA run test environments and work with foreign regulators?
Yes, and these two powers matter most to anyone entering the market from outside Pakistan. Section 9(2)(k) allows PVARA to “operate regulatory sandboxes in a transparent and accountable manner.” Section 9(2)(l) allows it to “enter into cooperation or mutual assistance arrangements with domestic and foreign regulators and law enforcement agencies to facilitate information sharing and coordinated action, including mutual recognition of Regulations and licenses.”
The regulatory sandbox power is the statutory root of the controlled-testing environment that lets a novel product operate under supervision before full licensing. The mutual-recognition language in 9(2)(l) is notable: it opens the door, in principle, to PVARA recognising a licence or approval already held in another jurisdiction, though the Act does not itself specify which jurisdictions or under what conditions — that detail would need to come through a bilateral arrangement and, presumably, Regulations. A foreign exchange operating into Pakistan should not assume mutual recognition exists in practice merely because the Act permits it in principle — no such arrangement had been publicly announced as at the date of this analysis.
What are the softer powers — education and committees?
The final two powers are less dramatic but still load-bearing. Section 9(2)(m) lets PVARA “conduct public education and awareness initiatives to promote informed participation in the Virtual Asset ecosystem.” Section 9(2)(n) lets it “constitute as many committees as deemed necessary to conduct its functions under this Act.”
The committee power in 9(2)(n) is open-ended by design — it does not name any specific committee (the Act separately names a Shariah Advisory Committee under section 3(1)(xxvii) and permits a regulatory coordination committee under section 17(3)), leaving PVARA free to stand up whatever internal or cross-agency working group a given issue requires.
What does this mean in practice for a VASP or applicant?
The practical takeaway is that section 9(2) is not a menu PVARA picks from occasionally — it is the operating manual for how the Authority interacts with the market at every stage: rule-making before you apply, licensing conditions when you apply, inspection and information demands once you are licensed, sanctions or court action if something goes wrong, and sandbox or cooperation arrangements if your product or your jurisdiction is unusual.
Anyone building a corporate structure for a Pakistan VASP should read section 9(2) alongside the licensing chapter, not instead of it — the powers listed here determine how much the rules can move under your feet between the day you apply and the day you are fully licensed. If a specific instrument — a Regulation, a directive, a circular — has not yet been published under 9(2)(a) or (b), the underlying power still exists; only the detail is missing.
About this analysis
This analysis was prepared by the CoinConnect research desk from the Virtual Assets Act 2026 as passed by the National Assembly — principally section 9 and its cross-references to sections 17, 54, 57, 59, 67 and 68 — read as published. Where practice is not yet settled or guidance has not been issued, that is stated in the text above.
Regulatory positions change and specific requirements should be verified against the current position published by the relevant authority before you act on them. This is information and analysis, not legal advice, and it does not create an advisory relationship. Take professional advice on your own circumstances.
Entering Pakistan's crypto market?
CoinConnect handles market entry, partnerships, PR and launch for exchanges and Web3 companies moving into Pakistan and South Asia.
Visit CoinConnect