Quick answer
Crypto subscription compliance starts with classifying what the business does, where it and its customers operate, and whether it merely sells a service or also controls, exchanges or transmits customer funds. Before launch, define KYC or KYB triggers, screen customers and wallets for sanctions risk, restrict unsupported jurisdictions, monitor recurring transactions and retain evidence of every approval, rejection and payment. Non-custodial settlement changes custody risk; it does not cancel merchant obligations.
The crypto subscription compliance decision comes before gateway selection
A merchant is ready for direct-wallet subscriptions only when it can identify the contracting customer, decide where service may be offered, assess the paying wallet and reproduce the transaction history. Choosing a gateway first merely automates an unresolved policy.
Start with the commercial activity, not the token. Selling access to ordinary SaaS is different from operating an exchange, transmitting value for users, holding customer balances or selling a regulated financial product. The latter activities can trigger licensing, AML or reporting duties that a payment integration cannot solve. Industry risk matters too: hosting, creator and adult businesses may face stricter age, content, consumer-protection or local licensing rules even when payment settlement is lawful.
| Merchant model | Minimum pre-launch controls | Escalate before launch when |
|---|---|---|
| SaaS, AI or API access | Customer record, sanctions screening, wallet review, location rules, invoices and refunds policy | The service handles funds, securities, gambling, restricted data or regulated advice |
| Creator or adult platform | Creator KYB/KYC, age and content controls, payer screening, jurisdiction blocks | Local rules prohibit content, anonymity prevents required verification or the platform controls creator funds |
| Hosting or WHMCS reseller | Account identity, abuse controls, wallet screening, service-location records | Customers can resell anonymously or infrastructure supports prohibited activity |
| Web3 or NFT service | Counterparty and wallet review, token classification, transaction records | The product resembles investment, custody, exchange or money transmission |
Write a one-page activity map naming the seller, buyer, service, asset, chain, receiving wallet and countries involved. Have qualified counsel classify the activity in priority jurisdictions. Only then compare a crypto subscription gateway against the controls the business actually needs.

Which identity, sanctions and wallet controls are necessary?
Use risk-based customer due diligence plus transaction controls. Verify identity where law or risk requires it, screen relevant people and businesses against applicable sanctions lists, review wallet exposure before acceptance and rescreen throughout the subscription.
KYC applies to individuals; KYB establishes a company, its controllers and beneficial owners. Whether either is legally mandatory depends on the merchant’s activity and jurisdictions, but anonymity should never be the default where age restrictions, export controls, fraud exposure or regulated services require attribution. Collect only information justified by policy, protect it appropriately and define retention and deletion rules. For self-hosted wallets, a signed message can help demonstrate control of an address, but it does not prove lawful source of funds or the signer’s identity.
- At signup, establish the customer or business identity required by the risk tier.
- Screen the customer, beneficial owners and relevant counterparties against applicable sanctions restrictions.
- Before approval, assess the wallet for direct and indirect exposure to sanctioned or illicit activity.
- At every recurring charge, rescreen the address and transaction context because risk can change.
- Route matches, high-risk exposure and unusual behaviour to documented review; do not let an alert become an automatic accusation.
This continuous approach is central to reliable recurring crypto payments: a clean wallet in January can acquire problematic exposure before June. Define thresholds, reviewers and evidence requirements with counsel and an appropriate analytics provider. The next action is to turn each alert type into an allow, review or reject procedure.
Do not confuse screening with certainty. Blockchain analytics attaches risk signals to transaction history; it cannot always identify the person controlling an address, and indirect exposure needs proportionate interpretation. A merchant selling a low-value productivity tool may set different review thresholds from a platform selling regulated access, but both need consistency. Test the policy with three cases before launch: a clear wallet, a possible sanctions-name match and a wallet with ambiguous indirect exposure. If the operator cannot explain the outcome, the control is not operational.

How should merchants set jurisdiction and customer limits?
Build a written country matrix covering the merchant entity, customer location, service legality, sanctions restrictions, tax treatment and data obligations. If any required basis is unknown, place that market on hold rather than treating global wallet access as global permission.
Blockchains do not respect borders; contracts and enforcement still do. Determine where the business is established, where service is marketed and delivered, and what evidence establishes customer location. An IP address alone is weak evidence, while billing details, declared residence, entity documents and risk signals can support a fuller decision. Define prohibited, restricted and permitted markets, then apply the same rules at signup and renewal. Also document whether consumer cancellation, automatic-renewal notices, tax invoices or age verification differ by market.
- Prohibited: sanctions or law prevents the relationship or service.
- Restricted: service is allowed only after enhanced checks, licences or contractual terms.
- Permitted: documented review supports sales under the defined customer and product conditions.
- Unassessed: no launch until ownership, legal, tax and operational questions have accountable answers.
The comparison between crypto vs fiat subscription payments should include regulatory reach, not just fees and chargebacks. Crypto may widen payment access, but it does not override local consumer, content, export or tax rules. Assign an owner to the matrix and require review whenever the product, entity or target market changes.

What records make recurring billing defensible?
Keep a linked record of the customer, consent, wallet, subscription terms, screening result, each attempted charge, service entitlement and exception decision. On-chain data proves a transfer; it does not explain the contract, reviewer or business purpose.
Create a stable subscription identifier that connects off-chain and on-chain evidence. Store the plan, price, asset, network, billing interval, wallet address, approval transaction, charge transaction hashes, timestamps, invoice status, webhook events and cancellation or revocation. Separately retain the policy version, screening result, alert disposition and reviewer. Restrict access to identity data and define retention with counsel; permanent public transactions are not permission to retain every private document forever.
Finance also needs a consistent valuation source and timestamp, fee treatment, refund policy and reconciliation routine. The detailed crypto subscription accounting treatment depends on jurisdiction and accounting framework, but operations should be able to trace every recognized invoice to settlement or failure. Reconcile chain events against invoices rather than treating wallet balance changes as revenue.
Worked example — assumptions: 120 subscribers owe $49 in USDC for one monthly cycle; all charges succeed; the specified platform fee is 0.5%; network costs and taxes are excluded. Gross billings are 120 × $49 = $5,880. The platform fee is $5,880 × 0.005 = $29.40, leaving $5,850.60 before excluded costs. The operator should preserve the subscriber-level charge list, fee record and reconciliation total, not merely a screenshot of the final wallet balance.

The ordered go-live checklist for direct-wallet subscriptions
Launch only after legal classification, policy design, technical enforcement and evidence retrieval have all passed. A non-custodial gateway can automate collection, but the merchant must own its customer eligibility, compliance decisions and records.
- Classify the product, fund flow, merchant entities and priority jurisdictions with qualified counsel.
- Approve customer tiers defining KYC/KYB, age, sanctions, wallet-risk and enhanced-review triggers.
- Publish supported assets, networks, countries, renewal terms, cancellation rules and refund handling.
- Configure wallet screening before approval and rescreening for recurring charges; document alert ownership.
- Connect subscription approvals, invoices, webhooks, access provisioning and failure handling under one identifier.
- Run test cases for approval, rejection, renewal, cancellation, revoked allowance, insufficient balance and manual review.
- Verify that finance and compliance can retrieve a complete case without relying on one employee’s memory.
- Schedule policy, sanctions-list, vendor, smart-contract and jurisdiction reviews, with material changes triggering reassessment.
Tool selection follows this checklist. Review how smart contract subscriptions authorize charges, where funds settle, which events integrations expose and how exceptions reach operators. For teams comparing architectures, a crypto subscription gateway should fit the documented controls rather than becoming a substitute for them.
This model does not fit a business that requires a custodian, automatic fiat conversion, provider-led compliance decisions or licences it does not hold. It fits best when the merchant can lawfully sell directly, wants self-custody and can operate its own compliance perimeter. The verifiable next action is a sandbox case file showing identity decision, wallet result, approval, charge, invoice and cancellation from end to end.

Turn the approved policy into a working payment flow
Once the merchant model has passed the checklist, the gateway decision becomes concrete: direct settlement, recurring authorization, reliable event data and integration with the merchant’s own controls.
Zyrox is a non-custodial gateway for one-time and recurring crypto payments. Funds settle directly to the merchant wallet, while payment links, webhooks, API access and smart-contract subscriptions support the operating flow. Start at and validate one complete subscription case before opening checkout broadly.
Frequently asked questions
Is KYC always required for crypto subscriptions?
No. The requirement depends on the merchant’s activity, jurisdictions, customer type and risk. Regulated services, age-restricted products and higher-risk relationships may require verification even when an ordinary low-risk SaaS sale does not.
Does non-custodial billing remove AML obligations?
No. Direct settlement can reduce custody and money-flow complexity, but it does not remove sanctions, AML, consumer, tax or sector-specific obligations that apply to the merchant.
Should a merchant screen a wallet only at signup?
No. Wallet risk and sanctions designations can change. Define rescreening at recurring charges and when material risk signals appear.
How can a customer prove control of a self-hosted wallet?
A signed wallet message or controlled verification transaction can demonstrate address control. Neither method alone proves the user’s identity or lawful source of funds.
What should happen when wallet screening raises an alert?
Pause the affected transaction when policy requires it, preserve the evidence and route the case to a trained reviewer. The reviewer should document the reason for approval, rejection or enhanced checks.
Which records should be linked to a crypto subscription?
Link the customer decision, wallet, consent, plan terms, screening results, invoices, transaction hashes, fees, service access, failures, cancellations and reviewer actions under one subscription identifier.
Can a merchant accept crypto subscriptions worldwide?
Technical reach is not legal permission. The merchant should maintain permitted, restricted, prohibited and unassessed country categories based on its entities, product and customer rules.
Does smart-contract billing guarantee every renewal succeeds?
No. A renewal can fail because of insufficient token balance, revoked or inadequate allowance, network conditions, paused contracts or compliance holds. Access and notification workflows must handle failure explicitly.