

VARA in Practice: From Getting Licensed to Staying Compliant
Discover the VARA rulebook for the three stages of the licensing process from three firms at different stages of the VARA lifecycle
📅 September 16 | 14:00 UTC
Join executives, compliance and operations leaders from three businesses at different stages of the VARA lifecycle for a practical discussion of how the Technology & Information Rulebook translates into day-to-day security work.
One firm is currently in its conditional licensing period, unable to begin regulated operations.
One licensed this year, discovering what the licence started.
One two years in, running the annual cycle.
VARA's technology requirements extend beyond smart-contract security. They cover key management, access controls, infrastructure, personnel, logging, testing and incident response — controls that have to operate continuously and be evidenced when required.
During panel, you’ll learn about three actions required for acquiring and maintaining VARA license:
Build — What controls are required before licensing, and who must own them.
Evidence — What organisations need to demonstrate during assessment.
Operate — What continues after licensing: testing, incident response, key management and security controls for new products.
Hacken's GRC and security team will bring the audit perspective: what organisations need to implement, what evidence matters and where gaps typically appear.
Use the discussion to benchmark your own VARA technology and security readiness.
What You’ll Learn
→ Starting the security programme. Which technology and security controls need to be established early, who should own them, and where teams commonly underestimate the work involved.
→ What VARA expects to see. How to document key management, access controls, infrastructure security and other requirements so they can be demonstrated during assessment.
→ Where implementation gets difficult. What happens when requirements move from policies and documentation into real systems, people and operational processes.
→ Operating after licensing. Incident reporting, recurring testing, key-compromise exercises and security requirements triggered by new products or changes to the business.
→ How to build for the assessment from the start
What companies can do early in the process to avoid rebuilding controls, documentation and processes later.
Our Guests:
▫️ Edwin Cheung — CEO, Gate Dubai
▫️ Kashif Abbas — Head of Compliance, Chainberg
▫️ Guido Rocco — COO, RIV Capital
▫️ Dmytro Yasmanovych — Head of GRC & Security Operations, Hacken
Moderated by Katina Messinis — MENA Security & Compliance Partner, Hacken
Why join:
If your company is preparing for VARA licensing, going through the process or already operating under a licence, this discussion will give you a practical view of what the Technology & Information requirements mean for the business.
You’ll leave with a clearer view of what your technology and security programme needs to cover before and after VARA licensing.
About Hacken
Hacken is an end-to-end blockchain security and compliance partner for digital assets. Born on blockchain in 2017, Hacken combines deep DLT expertise with enterprise-grade quality, AI-powered offensive security, and globally recognized standards. Trusted by 1,500+ adopters — including the European Commission, ADGM, MetaMask, Ethereum Foundation, and Binance — Hacken delivers provable assurance for digital-asset systems across security, transparency, and regulatory readiness.