Skip to content
Regulatory · Dubai

Independent testing against the VARA Rulebook.

Annual VA/PT, pre-change testing, custody and key reviews, and smart-contract scope where it sits on the VA Activities. Written for VASPs that have to show the Authority what was actually tested. Not legal advice.

VARA, Virtual Assets Regulatory Authority ADGM, Abu Dhabi Global Market
// Scope

The Rulebook is about live systems.

Part I of the Technology & Information Rulebook (current version effective mid-2025) expects qualified, independent vulnerability assessment and penetration testing, at least annually, and before new systems, applications, or products go live, with results available to the Authority on request. Where it matters to the VA Activities, that includes smart contracts.

A public-site scrape and a scanner export do not cover custody UIs, signing workflows, cloud IAM, or the path that moves client assets. If those were out of scope, the brochure was tested, not the VASP.

// What we test

Surfaces that usually decide the outcome.

01

Infrastructure and applications

Internal and external VA/PT across the licence perimeter, admin panels, APIs, cloud accounts, and vendor integrations on Critical or Important Functions.

02

Wallets and cryptographic keys

Quorum, recovery, policy-change paths, and whether a single compromise is enough to move client Virtual Assets. Part I.D is explicit on this.

03

Smart contracts, when they matter

Rule I.E.1 pulls in effectiveness, enforceability, and robustness of contracts tied to the VA Activities, including upgrades and keepers, not only launch-week bytecode.

04

Evidence the Authority can follow

What was tested, when, by whom, against which systems, with what results, plus owners and a remediation trail. A vendor slide deck is not an inspection pack.

// Engagement

Usually two to six weeks.

We start from inventory: systems, apps, cloud accounts, custody stack, contracts, and third parties on Critical or Important Functions. Scope is written against that list, not a generic network range.

ADGM FSRA work uses the same method when the perimeter sits there. This is a security engagement, not licensing advice, and not a claim that AN3 is a VARA-appointed auditor.

Start with the systems that hold assets

Keys, settlement, and Critical Functions first.

Briefs: typically one business day. Active incidents: ir@an3.io, 24/7.

Discuss your scope ↗