Join our Newsletter — 33% off our NHI Course

What is the difference between putting cryptocurrency regulation on the books and actually enforcing it?

Putting regulation on the books means the jurisdiction has adopted formal rules such as AML compliance requirements, licensing, or Travel Rule obligations. Enforcing it means the regulator can identify every supervised VASP, verify compliance, and act on violations. Many jurisdictions can pass rules faster than they can build the supervisory structure, expertise, and information-sharing needed to make those rules effective.

What changes when a rule exists but the state cannot enforce it

cryptocurrency regulation on paper creates a legal obligation, but enforcement determines whether that obligation changes behaviour. A rule set can require licensing, AML checks, or transaction reporting, yet still leave meaningful gaps if supervisors cannot find all covered firms, verify controls, or follow up on violations. The practical difference is the gap between formal compliance and real deterrence.

That gap matters because crypto markets can move quickly across firms, jurisdictions, and service models. If the supervisory body lacks visibility into the full population of virtual asset service providers, regulation becomes uneven: well-run firms comply, while others operate below the regulator’s line of sight.

FATF Recommendations — AML and KYC Framework

Ultimate Guide to NHIs — What are Non-Human Identities

JumpCloud Breach

Why enforcement capacity, not just legislation, determines effectiveness

Enforcement depends on supervisory maturity, not only legislative text. Regulators need clear jurisdiction, technical expertise, reporting channels, audit powers, and often cross-border information sharing to turn rules into action. Without those capabilities, the regime may still exist, but it functions more like a signalling device than an operational control.

In practice, the strongest enforcement systems combine registration, ongoing monitoring, examination, and sanction authority. That lets the state identify who is supervised, compare actual conduct to required conduct, and react when a firm misstates controls or ignores obligations. Where those steps are missing, the legal burden shifts to the market, but the state has little leverage to verify it.

NIST Cybersecurity Framework 2.0

NIST SP 800-53 Rev 5 Security and Privacy Controls

OWASP Non-Human Identity Top 10

What practitioners should look for when judging real-world regulatory strength

The most useful test is not whether a jurisdiction has written rules, but whether it can produce evidence that the rules are being applied. That means asking who is licensed or registered, how the regulator detects unregistered actors, how often compliance is tested, and what happens after a breach, control failure, or false filing.

Decision rule: if a rule cannot be tied to a credible inspection, reporting, or enforcement path, treat it as partial coverage rather than effective control. If the regulator can name the supervised population, verify obligations, and impose consequences, the rule is materially more than legislation on paper.

What to verify: whether the jurisdiction has a current supervised-entity register, routine examination capability, a documented escalation path for violations, and practical information-sharing arrangements for cross-border activity.

Practitioner takeaway: regulation changes market behaviour only when it is paired with supervision, visibility, and consequences, otherwise it remains a policy statement rather than an operating control.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
CIS Controls v8 CIS Control 5 — Account Management Crypto oversight depends on knowing which firms and operators are supervised.
Recommendation — Maintain an accurate register of supervised entities and responsible owners.
NIST CSF 2.0 GV.OV — Oversight The question is about whether formal rules are actually overseen and enforced.
DE.CM — Continuous Monitoring Enforcement requires ongoing visibility into compliance status and violations.
RS.MI — Mitigation Effective enforcement includes acting on violations after they are identified.
Recommendation — Establish monitoring and governance to confirm regulatory obligations are being followed. Monitor regulated activity continuously to detect rule breaches and gaps. Apply timely sanctions and corrective actions when compliance failures are confirmed.
MITRE ATT&CK T1586 — Compromise Accounts Weak supervision can leave regulated actors and their accounts exposed to abuse.
Recommendation — Hunt for account abuse patterns that can exploit weakly supervised crypto services.