Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Neobank compliance: what licences, audits and security certifications does a neobank need?

6 min read

There are 381 neobanks worldwide, but only 25 currently operate with a crypto licence, according to NeobankBeat. The gap reflects how difficult it is to turn a crypto product into a financial service that banks, payment partners and customers are willing to trust.

For a crypto neobank, credibility is part of the product. Crypto services still carry a higher due-diligence burden than conventional banking products, so operators need to show more than a polished app and a list of partners. They need evidence that their controls can withstand external scrutiny.

This article breaks down the main assurance signals and what they prove: licensing, certifications, security audits, bug bounties and custody. We then apply the same criteria to five crypto neobanks: ether.fi Cash, KAST, Plasma One, Tria and Kolo, comparing what each discloses publicly and how far that evidence goes.

What does a crypto neobank need before anyone trusts it with money?

More than one document. A crypto neobank that expects deposits shows six layers of evidence:

  • Licences for the regulated activities it performs
  • Security certifications (ISO 27001, SOC 2) and resilience regulation (DORA)
  • Smart contract audits
  • Penetration testing
  • A bug bounty

1. Which entity holds which license?

A crypto neobank's operations break down into five legal and operational functions:

  • Neobank Ltd provides crypto-asset services. In the EU, these generally require authorisation under MiCA. Other jurisdictions run their own regimes, such as VARA in Dubai and the Monetary Authority of Singapore (MAS) under the Payment Services Act.
  • Neobank Payments Ltd provides fiat and payment services. Depending on the activity and jurisdiction, this needs an Electronic Money Institution (EMI), Payment Institution (PI), bank or other authorisation.
  • Issuer X issues the Visa or Mastercard card. It needs both the regulatory authorisation and the card-scheme approval, and those are separate.
  • Processor Y provides payment-processing infrastructure. A pure technical provider can support a regulated institution without its own licence. A processor that performs regulated services needs one.
  • Custodian Z holds and administers users' crypto-assets. In the EU, that is a regulated service under MiCA and requires CASP authorisation.

One entity can perform several of these functions and outsource the rest. What counterparties check is which legal entity performs each regulated activity, and which authorisation covers it. A neobank can market itself in 40 countries while one entity in its chain is authorised in none of them.

Why does the legal entity matter more than the brand? 

A crypto brand can market the card under its own name while another regulated entity issues it. Look at the Wirex example below:

Wirex Limited holds UK FCA authorisation for its e-money activities, while its crypto services have involved Wirex Digital Services S.r.l., an Italian company registered with OAM. One brand, two regulatory frameworks. 

2. Security certifications and DORA

ISO/IEC 27001 certifies an information security management system (ISMS). It covers how you identify security risks, define controls, manage access, review those controls and respond to incidents. A counterparty's risk team can read your certificate scope instead of auditing you themselves.

SOC 2 is an independent auditor's report on your controls against the Trust Services Criteria, with security as the most common category. A Type I report assesses whether controls are suitably designed at a point in time. A Type II report also tests whether they operated effectively over a period, commonly 3 to 12 months. SOC 2 vs ISO 27001 covers which one your counterparty is likely to accept.

The Digital Operational Resilience Act (DORA) is an EU regulation for financial entities in scope, including CASPs and payment institutions. It sets requirements for ICT risk management, incident reporting, resilience testing and ICT third-party risk. DORA also requires a register of contractual arrangements with ICT third-party service providers, and for a card programme, that register typically includes the processor. What DORA requires walks through the obligations if you're still preparing.

All five neobanks we reviewed point to the same certificate: Rain's SOC 2. That report covers the issuer's controls. It doesn't cover the neobank's app, wallet or backend.

3. Smart contract audits

A smart contract audit finds vulnerabilities in the on-chain code your neobank relies on, and the report doubles as evidence for users, banks and partners. Two limits decide what it's worth:

  • Scope: code outside the audit gets none of its protection.
  • Version: the audit covers the code as the reviewers saw it, and every later deploy can introduce new vulnerabilities.

The August drain hit both. The attackers used deprecated infrastructure that the audit never covered.

A trust benchmark for audits:

  • Audit the contracts your neobank uses, including critical integrations with card infrastructure.
  • Publish the audit scope and the reviewed versions.
  • Publish remediation status for every finding.
  • Re-audit after material code or architecture changes.

Our other article, the smart contract audit process shows how a review runs end to end.

4. Penetration testing

A smart contract audit reviews on-chain code. A penetration test looks for weaknesses in everything around it: the app, APIs, authentication, backend, cloud infrastructure and admin interfaces. Attackers don't need to break a contract they can route around. In Q2 2026, keys, signers and infrastructure accounted for 88.3% of losses, according to Hacken's Q2 2026 security report.

In many setups, pentesting is a formal requirement:

  • DORA requires financial entities in scope to run an ICT security-testing programme.
  • PCI DSS requires it for cardholder-data environments.
  • MAS, APRA and the HKMA require it for the institutions they regulate.
  • ISO 27001 and SOC 2 can use it as control evidence, though neither makes it mandatory.

Certain DORA entities must also undergo threat-led penetration testing (TLPT). During it, you identify your critical functions and the systems behind them, and testers run a realistic attack scenario against them. 

5. Bug bounties

A bug bounty pays independent researchers to report vulnerabilities instead of exploiting them. Two things decide whether it protects you:

  • Scope: which assets researchers are allowed to test.
  • Reward pool: how much you pay, and for which severity.

A large reward means little if the programme excludes the systems handling customer funds. Gnosis Chain's bounty offers up to $2 million, but a protocol-level bounty may not cover Gnosis Pay's card infrastructure, and the card module is what got exploited in June 2026. 

What five crypto neobanks disclose publicly

If a bank, fintech, or institutional counterparty is assessing a crypto card programme, the first step is often desk research: checking the issuer, licences, assurance reports, security testing and vulnerability disclosure programme.

Hacken did research on some popular neobanks across these trust metrics. We reviewed Ether.fi Cash, KAST, Plasma One, Tria, Kolo. Here are the results of our due diligence:

Table comparing security and compliance disclosure for five crypto cards issued through Rain. ether.fi Cash is the only card with a smart contract audit (45+ reports from 9 firms) and a bug bounty specific to the card (Immunefi, $200k). It is self-custodial, but no licence was identified. KAST is custodial via Fireblocks and BitGo. It has offshore entities and a claimed FINTRAC MSB licence, a $50k bug bounty on a third-party repo only, and no audit. Plasma One is self-custodial and licensed through Bridge and Rain partners, with no audit or bug bounty found. Tria is self-custodial with TSS keys and an audit of its Lit Protocol component only. It has no licence or bug bounty identified. Kolo is hybrid, with an MPC wallet and the card balance held on Rain. It holds a Kazakhstan sandbox licence with no MiCA CASP authorisation, and has no audit or bug bounty found. For all five cards, the only certification is Rain's SOC 2.

A few points are worth noting about the research.

Firstly, it was based solely on public sources, and the real result may be quite unpublished, but present. 

Also, all five neobanks use Rain as an card issuer or issuing partner. As a result, Rain's SOC 2 report appears across the products, but that does not make it a certification of the neobanks themselves. 

Three of five do not disclose a bug bounty. For the other products, we did not find public evidence of a neobank-specific audit or bounty programme in our review.

Licensing evidence is not uniform. Some products point to licences or regulated partners, while others provide less direct evidence in their public materials.

So what makes a crypto neobank trustworthy?

A paper trail. Every layer covers a defined part of the business, and counterparties check where each one stops.

Layer

What it covers

Licence

A named entity is authorised for a named activity in a named jurisdiction

ISO 27001

A security management system is in place and reviewed

SOC 2

Controls are suitably designed (Type I) and operated effectively over a period (Type II)

DORA

An obligation: ICT risk, incident reporting, testing and a register of ICT third-party providers

Smart contract audit

Findings reported in the reviewed code, at the reviewed version

Penetration test

The app, APIs, keys and cloud resisted an authorised, simulated attack

Bug bounty

Researchers are paid to report instead of exploit, continuously

Custody model

Who holds user funds, and where they are at the moment of spend

Found a gap?

Send them to us, so a Hacken specialist can reply to you with an offer and roadmap for remediation.

Talk to a specialist
Banner Image

Subscribe to our newsletter

Be the first to receive our latest company updates, Web3 security insights, and exclusive content curated for the blockchain enthusiasts.

Speaker Img