What Are the CGA’s 2026 Compliance Deadlines?

24 July, 2026

by Cindy Drommond, Regulatory and Compliance Advisor at EM Group  

CGA Policy Deadlines_EM Group Website

Curaçao Gaming Authority (CGA) licensees face several active compliance deadlines between now and October 2026. Operators licensed under the Landsverordening op de Kansspelen (LOK) should treat 2026 as a compliance checkpoint, not a routine renewal.

EM Group has been continuously focused on iGaming corporate services since 2005 and supports operators with corporate, compliance, and licensing services from offices in Curaçao, Malta, and the Netherlands, alongside licensing support in the United Kingdom, the Isle of Man, and other key iGaming jurisdictions on request. We track every CGA policy update as it lands, so operators do not have to.

When is the AML Policy due for review?

The Anti-Money Laundering (AML) Policy is currently due for review. Because AML frameworks vary by operator, a single template does not work; some operators need only a targeted update, others require a full revision aligned with current CGA expectations, which our iGaming compliance services team assesses case by case.

What does the CGA require in a Player Complaint Policy?

The Player Complaint Policy is subject to an annual review, due in July 2026. This year's review car-ries one specific requirement: the policy must clearly reference the Alternative Dispute Resolution (ADR) mechanism available to players. Operators that have already appointed an ADR provider should confirm this is reflected in the policy text; operators that have not yet appointed one should treat this as the priority item.

What happens if a licensed domain becomes inactive?

If an operator plans to remove an active domain from the CGA Portal, or expects a period of inac-tivity, this should be communicated to the CGA in advance, including when activities will cease, the expected duration, and when operations are expected to resume.

All operators with a CGA license need to ensure that the domain is launched within six months of the date of licensing. Under the LOK, the CGA can revoke or decline to extend a license if the operator has not operated its licensed gambling activities for six consecutive calendar months. Therefore it is of utmost importance that operators in this position proactively inform the CGA of the reason for the delay so it can be evaluated and a revocation can be avoided.

Furthermore, it is important that before the end of July 2026 all operators ensure that in the CGA portal the division between main and subdomain is clearly indicated. This is a strict deadline from the CGA and EM Group can assist operators regarding this matter if needed.

What is the deadline for the CGA Operational Manual?

All B2C operators are required to have an Operational Manual in place. Following recent discus-sions with the CGA, the deadline has been extended to August 31, 2026. Operators who have not yet finalized their manual should start now. EM Group can assist with reviewing, updating, or draft-ing it to align with current CGA requirements.

What does the CGA's Crypto Policy require, and when is it due?

The CGA's Crypto Policy guideline changes how B2C licensees handle digital-asset deposits, wagering, withdrawals, and treasury management. Several restrictions took effect immediately: operators cannot accept funds from sanctioned wallets or mixers, cannot use personal or ultimate beneficial owner (UBO) linked wallets, and cannot act as an exchange, custodian, or virtual asset service provider (VASP) beyond accepting crypto as payment for gambling.

The policy separates what is prohibited from what requires closer scrutiny. Fiat-backed stablecoins are the CGA's preferred asset. Privacy coins, meme coins, and wrapped tokens are not banned outright, but each requires a documented risk assessment, and wrapped assets whose backing cannot be verified are off-limits. Operators must also vet any external crypto provider they use, such as an exchange, custodian, or payment processor — known as a virtual asset service provider (VASP). That provider must be regulated and registered, and must show it has adequate controls against money laundering and terrorist financing. Pooled or unhosted wallets remain usable, provided operators verify ownership and monitor transactions to trace where funds originate and end up.

Compliance follows a four-part timeline. By September 2026, operators must submit a compliant Crypto Policy with the CGA. By December 2026, operators must complete risk assessments, VASP due diligence, wallet controls, and staff training. By June 2027, operators must reach full technical compliance, including wallet segregation, blockchain analytics, and audit-ready records.

For the full wallet controls and asset-by-asset requirements, see our Crypto Policy Guide.

What is required in the Responsible Gaming Policy?

The Responsible Gaming Policy has been rolling out in phases since 2025. Most requirements are already in force, including policy submission to the CGA, staff training, and player-facing tools such as self-exclusion and deposit limits. The final phase, due by September 2026, requires operators to have functional operator-initiated exclusion and additional risk-based tools, such as reality checks and time limits, in place. The first periodic review is expected in September 2027.

What is the deadline for updated Terms and Conditions?

The CGA requires updated Terms and Conditions submitted before October 8, 2026, incorporating the minimum requirements published earlier this year. We cover the specifics in our dedicated Curaçao T&C compliance guide; this deadline is document-heavy, so early drafting pays off.

How often must the Information Security Policy be reviewed?

The Information Security Policy is subject to annual review. Operators whose latest version took effect in November 2025 should complete their next review in November 2026.

How EM Group can help

Every deadline above is manageable with enough lead time, and unmanageable without it. Our Curaçao iGaming compliance services team supports operators across drafting, reviewing, and submitting each policy, and we are happy to discuss which approach fits your documentation.

FAQ:
Frequently asked questions about CGA compliance deadlines 2026

Operators must submit a compliant Crypto Policy with the CGA by September 2026, with full technical compliance due by June 2027.

No. They require a documented risk assessment before continued use. Fiat-backed stablecoins are the CGA's preferred asset, and only sanctioned wallets, mixers, and personal or UBO-linked wallets are banned outright.

The CGA expects the manual to be available by August 31, 2026. Operators approaching the deadline without a finalized manual should contact their compliance advisor immediately.

Yes. The CGA expects the policy to clearly reference the ADR mechanism available to players, including the specific provider once one is appointed.

It applies to every CGA B2C licensee that accepts or intends to accept cryptocurrency, and to every group entity that supports a licensed operation, not only the license holder itself.

Written by Cindy Drommond

SHARE THIS INFO

TOP