Skip to Content

PVARA Sandbox & Reduced Capital: How to Test Pakistan's Market Before Full Licensing (2026)

June 15, 2026 by
Malik Muntazir Abbas

Written by Malik Abbas, CEO of CoinConnect

TL;DR

  • Pakistan's draft 2026 regulations give cautious entrants two lean routes: the regulatory sandbox (test under supervision) and the restricted, limited-scope license under Regulation 7(5) (a real license with reduced minimum paid-up capital).
  • The trade-off is explicit: you accept customer caps, transaction limits and product restrictions in exchange for a lower capital bar and a faster, lighter entry.
  • Reduced capital is set case by case — PVARA has not published a fixed sandbox figure — so the number is negotiated against the size of your capped exposure.
  • Token issuers get their own restricted track under Regulation 34(11), with caps on supply and holders — but the 100% reserve rule still applies.
  • A sandbox or restricted license is a test, not a guarantee: Regulation 7(6) states participation creates no entitlement to a full license.

Table of Contents

  1. What is the PVARA sandbox? (quick answer)
  2. Why a reduced-capital route exists at all
  3. The three entry routes compared
  4. Route 1: The regulatory sandbox
  5. Route 2: The restricted license under Regulation 7(5)
  6. How much capital does the reduced route actually require?
  7. The caps and conditions you accept in return
  8. Token issuers: the restricted issuance track (Reg 34(11))
  9. The graduation path: sandbox → restricted → full license
  10. A worked example: a payments firm entering lean
  11. Who should use the reduced route — and who should not
  12. Mistakes that get a sandbox application rejected
  13. FAQ

What is the PVARA Sandbox? (quick answer)

The PVARA sandbox is a supervised testing environment that lets a virtual asset business operate in Pakistan on a limited, controlled basis — with reduced capital and lighter obligations — before committing to a full license. It is paired with a restricted, limited-scope license under Regulation 7(5) of the draft Virtual Asset Services Regulations, 2026, which allows reduced minimum paid-up capital in exchange for customer caps and product restrictions.

In other words: it is how a global exchange or payments firm proves Pakistani demand is real before injecting PKR 1 billion (~$3.6 million). For most foreign entrants weighing the country, this is the single most important provision in the entire framework — and it is the natural next question after you have read our breakdown of PVARA capital requirements.

Conversions use an indicative rate of PKR 278 = USD 1 (June 2026).

Why a reduced-capital route exists at all

A regulator launching a new regime faces a tension. Set the capital bar high and you signal seriousness, protect consumers, and keep out the under-capitalised — but you also deter serious, well-run firms who are not yet sure the market justifies a multi-million-dollar commitment. Set it low and you invite risk.

PVARA's answer is proportionality. The draft regulations repeatedly tie obligations to the "nature, scale, complexity and risk-profile" of the licensee. The sandbox and the restricted license are the practical expression of that principle: if you cap your risk, the regulator caps your obligations to match.

This matters most for the firms Pakistan most wants to attract — established international operators testing a genuinely new market. The country is an emerging crypto market with a large, under-served user base, and the reduced route is designed so that testing it does not require betting the balance sheet on day one.

The three entry routes compared

Before going deep, here is the landscape. There are three distinct ways to begin, and they are frequently confused with one another.

RouteWhat it isCapitalCan you serve real customers?Best for
NOC / Preliminary Approval (Reg 6)A no-objection certificate to incorporate and proceed — not a licenseNone at this stageNo — it authorizes no serviceSecuring regulatory comfort before you build
Regulatory Sandbox (Reg 7(6), 5A(4))Supervised testing of a product under controlled conditionsReduced / proportionateYes, but tightly limitedNovel models needing regulatory clarity
Restricted License (Reg 7(5))A real, limited-scope license with reduced capitalReduced, set case by caseYes, within capsProven models entering at limited scale
Full License (Reg 7, Schedule I)The complete category licenseFull Schedule I figureYes, at scaleCommitted, at-scale operators

The key mental model: the NOC is a permission to prepare, the sandbox is a permission to test, the restricted licence is a permission to operate small, and the full license is a permission to operate at scale. They form a ladder, and most foreign entrants should expect to climb it rather than jump to the top.

Route 1: The regulatory sandbox

The sandbox is the lightest live-market entry. It already exists in practice — the draft regulations preserve sandbox arrangements created under the earlier Virtual Assets Ordinance. Regulation 5A(4) confirms that any "sandbox arrangement … issued or granted by the Authority under the Virtual Assets Ordinance … shall, to the extent not inconsistent with the Act or these Regulations, continue in full force and effect."

This is why a Form I sandbox pathway is already operational, which we document step by step in our PVARA Sandbox Form I walkthrough.

What the sandbox gives you:

  • A live environment to onboard a limited set of real users and test a real product.
  • Proportionate capital and reporting, calibrated to the capped scope.
  • Direct supervisory engagement — you learn exactly what PVARA expects before scaling.

What it does not give you is certainty of graduation. Regulation 7(6) is unambiguous:

"Participation in a regulatory sandbox does not create an entitlement to a License. The Authority may, however, take into account testing outcomes and compliance history in assessing a subsequent License application, subject to the applicant meeting all applicable requirements."

Read that second sentence carefully — it is the upside. A clean testing record becomes evidence in your favor at the full-license stage. The sandbox is not wasted effort; it is a rehearsal that counts.

Route 2: The restricted license under Regulation 7(5)

Where the sandbox is a test, the restricted license is a real license — just bounded. This is the provision that directly answers "how do we get reduced capital?"

Regulation 7(5) provides:

"The Authority may grant a limited scope License where necessary to advance the primary objectives of the Act. The Authority shall specify the scope, duration, conditions, and exit criteria in such limited License."

And Schedule I — the capital table itself — carries the matching carve-out:

"The Authority may, under regulation 7(5), grant a restricted license with proportionate prudential requirements (including reduced minimum paid-up capital) subject to customer caps, product restrictions, and enhanced safeguards."

Three features make this route powerful:

  1. Reduced minimum paid-up capital. You are no longer pinned to the full Schedule I figure. The amount is proportionate to your capped exposure.
  2. Defined scope, duration and exit criteria. The license states exactly what you may do, for how long, and what you must achieve to progress. This gives a board a finite, modellable commitment.
  3. Lighter governance, where justified. Regulation 20(4) lets PVARA permit a lower proportion of independent directors for limited-scope licenses — a meaningful reduction in the cost and difficulty of standing up a compliant board on day one.

The restricted license is, in effect, a smaller version of the real thing — which makes it the most credible route for an established operator who knows their model works elsewhere and simply needs to prove it in Pakistan.

How much capital does the reduced route actually require?

This is the question every CFO asks, and honesty matters here: the draft does not publish a fixed reduced figure. Regulation 7(5) and the Schedule I note both leave the reduced amount to PVARA's case-by-case determination, calibrated to your caps and safeguards.

That is not evasion — it is how proportional regimes work. What you can do is shape the outcome by shaping your proposal. In practice, the reduced capital you are likely to be granted tracks:

  • The size of your customer cap — fewer users, lower exposure, lower capital.
  • Transaction and volume limits — a capped monthly throughput limits the risk PVARA is underwriting.
  • Whether you hold customer assets — custody of assets raises the bar; a non-custodial or pass-through model lowers it.
  • The strength of your safeguards — robust segregation, reserves and controls let you argue for a lower buffer.

The practical move is to come to PVARA with a specific, self-limiting proposal: "we will serve X capped users, at Y capped volume, with these safeguards, and propose Z capital." That is a far stronger position than asking the regulator to set the number for you. This is precisely the modelling our PVARA licensing service does before you file.

The caps and conditions you accept in return

Reduced capital is not free. Schedule I lists the price in three words — "customer caps, product restrictions, and enhanced safeguards" — and in practice a restricted license will specify some combination of:

  • A ceiling on customer numbers (e.g. a fixed maximum of onboarded users).
  • Transaction-volume and value limits, often monthly or aggregate.
  • Product restrictions — only certain services, assets or use cases permitted.
  • Distribution-channel limits — restrictions on how and to whom you market.
  • Enhanced disclosures — customers told clearly they are using a pilot or limited-scope service.
  • Enhanced reporting — more frequent returns to PVARA so it can watch the test closely.

These caps are the mechanism, not a punishment. They are what lets the capital figure come down. A well-designed restricted license aligns the caps with your genuine test objectives, so the limits never bind before you have learned what you came to learn.

Token issuers: the restricted issuance track (Reg 34(11))

Stablecoin and tokenized-asset issuers — the PKR 1 billion categories — get their own dedicated restricted route. Regulation 34(11) allows PVARA to:

"grant a restricted license under regulation 7(5) for issuance of an FRT or ART for a limited scope including but not limited to: (a) caps on outstanding supply, number/type of holders, and transaction volumes; (b) limitations on distribution channels and use cases; (c) enhanced disclosures to holders regarding pilot status and risks; (d) redemption controls and operational safeguards."

For a stablecoin pilot, this is the difference between a viable test and an impossible one. You can launch a capped supply to a limited holder base rather than capitalizing for a national rollout from day one.

But note the hard floor. Regulation 34(13) preserves the reserve rule absolutely:

"Nothing in this regulation permits the Issuer to maintain reserves below one hundred percent (100%) unless expressly authorised by the Act."

So the capital can flex; the reserve backing cannot. A restricted stablecoin issuer still backs every token in circulation, 100%, in a segregated reserve. What shrinks is the scale of the circulation — and therefore the absolute size of the reserve — not the ratio. Regulation 34(12) does, however, permit "proportionate assurance and reporting arrangements" for limited-scope issuers, easing the audit and attestation burden during the pilot.

The graduation path: sandboxrestrictedfull license

The routes are not isolated; they are rungs. A typical lean entry for a foreign operator looks like this:

Step 1 — NOC (Reg 6). Secure preliminary approval to incorporate and proceed. Valid for three months, extendable once. No service yet.

Step 2 — Incorporate (Reg 5). Stand up the Pakistani company through SECP. Our corporate setup guidance covers this.

Step 3 — Sandbox or restricted license. Enter the live market under caps and reduced capital. Build a compliance and operational track record.

Step 4 — Full license (Reg 7). Apply to convert to a full category license, with your clean testing record now counting in your favor under Regulation 7(6).

On timing: once you reach the full-license application, Regulation 7(3) requires PVARA to decide a complete application within 90 days, extendable by up to 60 days under Regulation 7(4) for complex cases. The sandbox and restricted phases run on their own defined durations, set in the license conditions. Realistically, plan the full ladder in quarters, not weeks — but each rung de-risks the next. The operational reality of life after approval is covered in our post-NOC operational playbook.

A worked example: a payments firm entering lean

Consider an international payments company that wants to offer stablecoin-based remittance into Pakistan. The full path would imply a Transfer & Settlement licence (PKR 200 million / ~$720,000) and possibly a stablecoin issuance license (PKR 1 billion / ~$3.6 million) — a heavy combined commitment for an unproven market.

The lean path instead:

  • Restricted Transfer & Settlement license under Reg 7(5), capped at a defined number of corridor customers and a monthly volume ceiling, on reduced capital proportionate to that exposure.
  • Pilot stablecoin use under Reg 34(11) if needed — capped supply, limited holders, 100% reserve maintained but small in absolute terms.
  • 6–12 month test to prove corridor demand, unit economics and compliance.
  • Conversion to full licenses once the numbers justify the full capital.

The firm enters for a fraction of the day-one capital, learns whether the corridor is real, and only scales commitment to match proven demand. That is the entire commercial logic of the reduced route.

Who should use the reduced route — and who should not

Strong fit:

  • Established operators testing genuine but unproven Pakistani demand.
  • Payments and remittance firms with a specific corridor to validate.
  • Stablecoin or tokenised-asset issuers wanting a controlled pilot.
  • Any firm whose board will approve a bounded commitment but not an open-ended one.

Weak fit:

  • Operators ready to launch at national scale immediately — for them, the restricted caps simply throttle a viable business; go straight to the full licence.
  • Firms hoping the sandbox is a permanent low-capital loophole. It is not. It is time-bound, with defined exit criteria, and it confers no entitlement to anything further.

Mistakes that get a sandbox application rejected

  • Treating the sandbox as a discount, not a test. Applications that read as "we want to pay less capital" fail. Applications that read as "we want to test these specific hypotheses under these specific caps" succeed.
  • Proposing no caps. The reduced capital is earned by the limits you accept. An application with vague or absent caps gives PVARA nothing to calibrate against.
  • Ignoring the reserve floor. Token issuers who model reduced reserves rather than reduced scale misread Regulation 34(13) — the 100% rule does not bend.
  • No exit plan. Regulation 7(5) requires the license to state exit criteria. Come with a credible graduation plan, not an open-ended pilot.
  • Underbuilding compliance "because it's just a test." Your testing-phase compliance record is evidence at the full-license stage. A messy pilot damages the very application it was meant to strengthen.

Avoid these, and the reduced route does exactly what it is designed to do: let you enter Pakistan seriously, at controlled cost, with a clear path to scale. The next step is matching your model to the right route before you file — start with the complete VASP licensing guide or speak to us directly.

Thinking about entering Pakistan lean rather than all at once? CoinConnect designs the caps, capital proposal and exit plan that make a restricted PVARA licence approvable — so you test the market for a fraction of the full commitment. Book a free 30-minute discovery call →

Frequently asked questions


The sandbox is a supervised testing environment for a product, often the first live step. A restricted (limited-scope) licence under Regulation 7(5) is a real licence to operate at limited scale with reduced capital. They are related rungs on the same ladder, and a firm may move from sandbox testing to a restricted licence to a full licence.

The draft regulations do not publish a fixed reduced figure. Under Regulation 7(5) and Schedule I, PVARA sets it case by case, proportionate to your customer caps, transaction limits and safeguards. A tighter, self-limiting proposal generally supports a lower capital requirement.

No. Regulation 7(6) states that sandbox participation "does not create an entitlement to a License." However, your testing outcomes and compliance history are taken into account in a later full-licence assessment, so a clean record helps.

Yes. Regulation 34(11) allows a restricted issuance license with caps on outstanding supply, holders and volumes. But Regulation 34(13) preserves the 100% reserve rule — a restricted issuer reduces the scale of issuance, not the reserve ratio.

No. The NOC (Regulation 6) is a preliminary no-objection certificate that lets you incorporate and proceed — it authorizes no virtual asset service. The sandbox and restricted license let you actually operate, within limits.

The duration is set in the license conditions under Regulation 7(5), which requires the Authority to specify "scope, duration, conditions, and exit criteria." It is time-bound by design, with a defined path to graduate or exit.

Not necessarily. Regulation 20(4) allows PVARA to permit a lower proportion of independent directors for limited-scope licences, provided equivalent oversight is achieved — reducing the day-one governance burden.

Last reviewed: June 2026. Based on the draft Pakistan Virtual Asset Services Regulations, 2026, published for public consultation. Figures and provisions are subject to change pending finalisation.

External sources: PVARA · SECP · State Bank of Pakistan · FATF – Pakistan