Upcoming Compliance Deadlines for Operators with a Curaçao Gaming License

Upcoming Compliance Deadlines for Operators with a Curaçao Gaming License

Curaçao Gaming Authority (CGA) licensees face several active compliance deadlines between now and October 2026. Operators licensed under the Landsverordening op de Kansspelen (LOK) should treat 2026 as a compliance checkpoint, not a routine renewal.

AML Policy Under Review

The Anti-Money Laundering (AML) Policy is currently due for review. Because AML frameworks vary by operator, a single template does not work; some operators need only a targeted update, others require a full revision aligned with current CGA expectations.

Player Complaint Policy: The ADR Requirement

The Player Complaint Policy is subject to an annual review. This year's review carries one specific requirement: the policy must clearly reference the Alternative Dispute Resolution (ADR) mechanism available to players. Operators that have already appointed an ADR provider should confirm this is reflected in the policy text; operators that have not yet appointed one should treat this as the priority item.

Domain Activity

If an operator plans to remove an active domain from the CGA Portal, or expects a period of inactivity, this should be communicated to the CGA in advance, including when activities will cease, the expected duration, and when operations are expected to resume.

All operators with a CGA license need to ensure that the domain is launched within six months of the date of licensing. Under the LOK, the CGA can revoke or decline to extend a license if the operator has not operated its licensed gambling activities for six consecutive calendar months. It is therefore of utmost importance that operators in this position proactively inform the CGA of the reason for the delay so it can be evaluated and a revocation can be avoided.

Operational Manual

All B2C operators are required to have an Operational Manual in place before August 31,2026.

The New Crypto Policy: What It Requires, and By When

The CGA's Crypto Policy guideline changes how B2C licensees handle digital-asset deposits, wagering, withdrawals, and treasury management. Several restrictions took effect immediately: operators cannot accept funds from sanctioned wallets or mixers, cannot use personal or ultimate beneficial owner (UBO) linked wallets, and cannot act as an exchange, custodian, or virtual asset service provider (VASP) beyond accepting crypto as payment for gambling.

The policy separates what is prohibited from what requires closer scrutiny. Fiat-backed stablecoins are the CGA's preferred asset. Privacy coins, meme coins, and wrapped tokens are not banned outright, but each requires a documented risk assessment, and wrapped assets whose backing cannot be verified are off-limits. Operators must also vet any external crypto provider they use, such as an exchange, custodian, or payment processor — known as a virtual asset service provider (VASP). That provider must be regulated and registered and must show it has adequate controls against money laundering and terrorist financing. Pooled or unhosted wallets remain usable, provided operators verify ownership and monitor transactions to trace where funds originate and end up.

Compliance follows a four-part timeline. By September 2026, operators must submit a compliant Crypto Policy with the CGA. By December 2026, operators must complete risk assessments, VASP due diligence, wallet controls, and staff training. By June 2027, operators must reach full technical compliance, including wallet segregation, blockchain analytics, and audit-ready records.

Responsible Gaming Policy: The Final Phase

The Responsible Gaming Policy has been rolling out in phases since 2025. Most requirements are already in force, including policy submission to the CGA, staff training, and player-facing tools such as self-exclusion and deposit limits. The final phase, due by September 2026, requires operators to have functional operator-initiated exclusion and additional risk-based tools, such as reality checks and time limits, in place. The first periodic review is expected in September 2027.

Terms and Conditions Due October 8

The CGA requires updated Terms and Conditions submitted before October 8, 2026, incorporating the minimum requirements published earlier this year. This deadline is document-heavy, so early drafting pays off.

Information Security Policy: Annual Review

The Information Security Policy is subject to annual review. Operators whose latest version took effect in November 2025 should complete their next review in November 2026.

Staying Ahead of the Deadlines

Every deadline above is manageable with enough lead time, and unmanageable without it.
EM Group has been continuously focused on iGaming corporate services since 2005 and supports operators with corporate, compliance, and licensing services from offices in Curaçao, Malta, and the Netherlands, alongside licensing support in other key iGaming jurisdictions on request. EM Group tracks every CGA policy update as it lands, so operators do not have to.

EM Group's compliance team supports operators across drafting, reviewing, and submitting each of these policies. Operators who are unsure which deadlines apply to them can get in touch with EM Group's compliance team to find out.

FAQs

What are the main compliance deadlines for Curaçao Gaming Authority licensees in 2026?
Key deadlines include the Operational Manual by 31 August 2026, Crypto Policy by September 2026, Responsible Gaming measures by September 2026 and updated Terms and Conditions by 8 October 2026.

Why is the AML Policy review important?
The AML Policy must reflect current Curaçao Gaming Authority expectations and should be reviewed or revised based on each operator's specific risk profile.

What changes are required for the Player Complaint Policy?
Operators must ensure their policy clearly references the Alternative Dispute Resolution (ADR) mechanism available to players.

What happens if a licensed domain remains inactive?
Operators should notify the Curaçao Gaming Authority before inactivity begins, as prolonged inactivity could affect licence renewal or lead to revocation.

What does the new Crypto Policy require?
It introduces rules on digital asset payments, wallet controls, VASP due diligence, risk assessments and technical compliance over a phased timeline.

When must operators submit their Crypto Policy?
A compliant Crypto Policy must be submitted to the Curaçao Gaming Authority by September 2026.

What are the final Responsible Gaming requirements due in 2026?
Operators must implement operator-initiated exclusions together with additional player protection tools such as reality checks and time limits.

When are updated Terms and Conditions required?
Updated Terms and Conditions must be submitted to the Curaçao Gaming Authority before 8 October 2026.

How often should the Information Security Policy be reviewed?
It should undergo an annual review, with many operators expected to complete theirs in November 2026.

How can operators prepare for multiple compliance deadlines?
Planning ahead, reviewing policies early and working with experienced compliance specialists can help ensure all regulatory requirements are met on time.

Share

I like to keep it short. I am a writer who also knows how to rhyme his lines. I can write articles, edit them and also carve out some poetic lines from my mind. Education B.A. - English, Delhi University, India, Graduated 2017.