Securing MiCA CASP authorisation Finland has become the defining regulatory milestone for any business intending to offer crypto‑asset services to customers in Finland and across the European Union. Since the Markets in Crypto‑Assets Regulation (MiCA) became fully applicable, the Finnish Financial Supervisory Authority (FIN‑FSA) is the national competent authority responsible for authorising and supervising crypto‑asset service providers (CASPs). This landing page explains who needs authorisation, the eligibility and capital requirements, a step‑by‑step application process, how Finland compares with other EU routes, and the pressing 2026 tax reporting obligations that now sit alongside licensing.
Is cryptocurrency legal in Finland? Yes. Crypto‑assets and crypto‑asset services are legal but regulated in Finland. Offering those services commercially is not free, it requires authorisation from the FIN‑FSA under the MiCA framework, and firms operating without the correct authorisation face supervisory and enforcement consequences. In short, the asset class is lawful, but the activity is licensable. Anyone considering a Finnish market entry should treat the FIN‑FSA crypto‑asset guidance as the authoritative starting point and build their business plan around it from day one.
The regulatory environment for crypto in Finland changed decisively over 2024 and 2025. MiCA created a single, harmonised authorisation regime across the EU/EEA, replacing the patchwork of national virtual asset service provider (VASP) registrations. For founders and existing operators, understanding the transitional mechanics and the new tax‑reporting overlay is essential to sequencing an application correctly.
Finland applied a transitional arrangement allowing previously registered virtual currency providers to continue operating for a limited grandfathering window while they sought full CASP authorisation. That transitional period ended on 30 June 2025. Firms that did not obtain, or were not actively progressing, their CASP authorisation by that point can no longer rely on the earlier registration regime to continue offering services. The practical consequence is that a firm approaching the Finnish market today must apply directly under MiCA and cannot assume any legacy protection. The FIN‑FSA has published detailed guidance on the transition and on how it treats applications filed after the window closed, and prospective applicants should confirm their status against the official FIN‑FSA CASP pages.
Layered on top of licensing, the Finnish Tax Administration (Vero) has introduced a new obligation for crypto‑asset service providers to collect and report customer and transaction information beginning in 2026. This reflects the EU’s DAC8 tax‑transparency framework and means that a CASP is not only a supervised financial entity but also an information‑reporting intermediary for tax purposes. Firms must design their onboarding, data‑collection and record‑keeping systems to capture the required customer identifiers and transaction data from the outset. The interaction between licensing and tax reporting is one of the most under‑appreciated aspects of achieving durable MiCA CASP authorisation Finland, and the operative requirements are set out in Vero’s crypto‑asset reporting guidance.
Because the transitional window has closed and the 2026 Vero reporting obligations are now in force, delay carries real cost. An unauthorised firm cannot lawfully continue offering in‑scope services, and building compliant reporting infrastructure after go‑live is far more expensive than designing it into the initial architecture. Industry observers expect the FIN‑FSA to maintain an active supervisory posture toward unauthorised activity, so founders should treat authorisation as a prerequisite to market entry rather than a formality to be completed later.
Finland offers a compelling home base for a crypto‑asset business. The FIN‑FSA is a respected Nordic regulator with a reputation for predictable, principles‑based supervision, and Finnish authorisation carries strong reputational weight with banking partners, institutional counterparties and investors who value regulatory credibility. For firms weighing where to obtain a crypto licence Finland gives access to a stable legal system, transparent administrative processes and English‑friendly regulatory correspondence.
The decisive commercial advantage, however, is passporting. Once a firm holds MiCA CASP authorisation Finland from the FIN‑FSA, it can passport its services throughout the EU and EEA by way of notification, without needing a separate licence in each Member State. This “single licence” effect transforms a Finnish authorisation into a gateway to a market of hundreds of millions of consumers. The mechanics of passporting are governed by the MiCA Regulation and explained at EU level by the European Commission’s digital finance pages. Timeline expectations in Finland are competitive, and applicants who submit complete, well‑evidenced files tend to progress efficiently through review.
For firms planning cross‑border growth, our guide to MiCA passporting and EU expansion strategy sets out the notification steps in detail.
The path to MiCA CASP authorisation Finland follows a structured sequence. While every application is fact‑specific, the following eight steps map the process from initial readiness to post‑authorisation supervision. Applicants who treat each step as a discrete workstream, rather than compressing everything into a final drafting sprint, consistently achieve smoother reviews. Our FIN‑FSA application checklist and timeline resource expands each step into a working document set.
Before drafting anything, establish the foundations. Choose your corporate vehicle, identify precisely which crypto‑asset services you will offer, and commission an internal legal review of scope. Readiness at this stage determines the entire timeline. Key preparatory items include:
Not every token or service falls within MiCA. This step distinguishes between asset‑referenced tokens, e‑money tokens and other crypto‑assets, and identifies activities that are excluded or covered by other EU law. Certain instruments that qualify as transferable securities, deposits, or products already regulated under existing financial‑services legislation sit outside MiCA’s CASP regime. Getting classification wrong at the outset can invalidate an entire application, so map each product against the scope and exclusion provisions of the MiCA Regulation on EUR‑Lex. Where a token may qualify as a financial instrument, a separate authorisation regime may apply instead.
MiCA sets tiered minimum capital requirements depending on the services offered. As a general framework, the lowest tier applies to advice and reception/transmission of orders, a middle tier to exchange and execution services, and the highest tier to custody and operation of a trading platform. Typical thresholds begin at €50,000 and rise to €125,000 and €150,000 depending on the service classification, with an alternative measure based on a proportion of fixed overheads also applying. Plan not only to meet the minimum but to evidence it with audited or independently verifiable capital proof. Our dedicated resource on the minimum capital for CASPs in Finland works through modelling examples.
Always confirm the applicable tier for your service set against the FIN‑FSA and the MiCA Regulation, because the higher of the fixed minimum and the overheads‑based figure governs.
The application package is substantial. The FIN‑FSA expects a coherent, internally consistent set of documents that together demonstrate the firm is capable of operating soundly. Core documentation includes:
Applications are filed with the FIN‑FSA registry (kirjaamo). Documents are submitted to the FIN‑FSA registry channel, historically kirjaamo@finanssivalvonta.fi, or through the authority’s electronic filing arrangements, with formal attachments in the required format. Practical points to observe: prepare documents in the accepted language(s), provide certified translations where source documents are in another language, and ensure all attachments are correctly labelled and cross‑referenced to the application index. Electronic filing is generally preferred; confirm current submission channels on the FIN‑FSA CASP pages before you file, as channels and templates are periodically updated.
After submission, the FIN‑FSA reviews the file for completeness and substance. It will typically raise written questions and request additional information or clarifications. This iterative phase is where most timeline variation occurs, a well‑prepared file with anticipated answers moves quickly, while gaps trigger multiple rounds of correspondence. Common deficiency areas include underdeveloped AML risk assessments, insufficient capital evidence, vague outsourcing arrangements and thin ICT resilience documentation. Respond comprehensively and promptly to each request, and keep a running log of the regulator’s questions and your answers to maintain consistency across the review.
Once the FIN‑FSA is satisfied that the applicant meets the requirements, it grants authorisation. The authorisation specifies which crypto‑asset services the firm may provide and may attach conditions or limitations. Authorised CASPs are entered into the relevant register, giving counterparties and customers a means to verify the firm’s regulated status. Achieving this decision is the moment the firm gains its fin‑fsa crypto licence, but it is a beginning, not an endpoint, because authorisation triggers a continuous supervisory relationship.
Immediately after authorisation, several obligations activate. The firm must operate in line with its approved policies, submit periodic supervisory returns to the FIN‑FSA, and maintain its capital and governance standards on an ongoing basis. If the firm intends to serve other Member States, it files passporting notifications through the FIN‑FSA to unlock cross‑border activity. Critically, the 2026 Vero reporting obligations must be operational from launch, meaning customer and transaction data collection is not optional. Post‑authorisation compliance is therefore an integrated programme spanning supervision, tax reporting and cross‑border notification.
Because MiCA harmonises authorisation across the EU, a firm can, in principle, seek its licence from any Member State’s competent authority and passport across the bloc. The practical differences lie in timelines, supervisory culture, cost and market profile. The comparison below sets out how Finland measures against two frequently considered alternatives.
| Feature | Finland (FIN‑FSA) | Estonia (Example) | Germany (BaFin) |
|---|---|---|---|
| Typical review timeline (first decision) | 3–9 months (varies by completeness; FIN‑FSA processing accelerating post‑2025) | 2–6 months | 6–12 months |
| Minimum capital (typical CASP tiers) | €50k / €125k / higher depending on services, must be evidenced | Similar tiers; may require local capital proof | Higher governance scrutiny; higher effective capital needs |
| Filing channel | FIN‑FSA registry (official email/portal), formal attachments required | e‑registry | Formal BaFin submission, German language preferred |
| Passporting ease | Full EU/EEA passporting under MiCA after authorisation | Supports passporting; smaller market profile | Strong passporting; strict supervisory expectations |
| Practical cost (legal + setup) | Moderate, competitive Nordic rates; professional fees €40k–€150k+ depending on complexity | Typically lower set‑up fees | Higher compliance/legal fees |
When should a founder choose the FIN‑FSA? Finland is well suited to firms that prioritise regulatory credibility, predictable processing and a smooth passporting path, and that value operating in an English‑friendly, digitally mature administrative environment. Estonia may appeal where speed and lower initial cost dominate, though the smaller domestic market profile matters less once passporting is used. Germany offers deep market access and strong supervisory prestige but demands a heavier compliance investment and German‑language engagement. For many Nordic and international founders, MiCA CASP authorisation Finland strikes the strongest balance between reputation, cost and cross‑border reach.
Meeting the eligibility criteria is the substantive core of any application. The FIN‑FSA assesses each requirement against the MiCA Regulation and its own supervisory expectations. The headline requirements for casp authorisation Finland fall into five areas.
An applicant must be a legal person established in the EU/EEA with a registered office in a Member State where it carries out at least part of its business, and its place of effective management must be in the EU. Non‑EU firms cannot obtain direct authorisation without an EU establishment. Confirm the current establishment expectations on the FIN‑FSA CASP guidance.
Members of the management body must be of sufficiently good repute and possess appropriate knowledge, skills and experience. The FIN‑FSA reviews CVs, criminal‑record and integrity evidence, and assesses whether the collective management body is competent to run the proposed business. Documented governance arrangements, clear reporting lines, segregation of duties and effective oversight, are essential.
As covered above, the firm must hold prudential safeguards equal to the higher of the applicable minimum capital tier or a proportion of fixed overheads. Acceptable instruments generally comprise paid‑up capital and reserves that qualify as own funds. The firm must be able to demonstrate that capital is genuinely available and maintained, not merely committed on paper.
CASPs must maintain robust ICT systems and security protocols, including safeguards for client assets, secure custody arrangements, incident detection and response, and business continuity plans. The EU’s operational resilience expectations mean applicants should document their systems architecture and demonstrate testing. Weak ICT documentation is a frequent cause of extended review.
Applicants must operate a comprehensive anti‑money‑laundering and counter‑terrorist‑financing programme aligned with Finland’s AML framework and EU rules. This includes a documented risk assessment, customer due diligence procedures, ongoing monitoring, a nominated compliance officer, and clear reporting lines to the Financial Intelligence Unit. Our guide to AML/KYC and transaction reporting under MiCA details the required policy set.
Achieving mica compliance Finland means integrating three reporting and control regimes: AML/KYC obligations, FIN‑FSA supervisory reporting, and Vero’s 2026 tax‑information reporting. Treating these as one connected data architecture, rather than three siloed projects, is the hallmark of a well‑run CASP.
CASPs are obliged entities under AML law. Required procedures include risk‑based customer due diligence at onboarding, enhanced due diligence for higher‑risk relationships, ongoing transaction monitoring, and prompt suspicious‑activity reporting to the FIU. Customer identification and verification must be robust, with defined thresholds triggering additional scrutiny. Because the same customer data underpins both AML and tax reporting, firms should design a single “golden record” per customer to avoid duplicate and inconsistent data capture.
From 2026, crypto‑asset service providers in Finland must collect and report specified customer and transaction information to Vero, implementing the EU’s crypto‑asset tax‑transparency framework. In scope are the identity details of reportable users and the value and nature of relevant crypto‑asset transactions, reported on the timing Vero prescribes. Implementing this requires onboarding fields, transaction tagging and a reporting pipeline built early. The authoritative requirements are published by Vero, and our dedicated guide covers Vero tax reporting for crypto in Finland in practical detail.
The FIN‑FSA’s supervisory returns and Vero’s tax reporting serve different purposes but draw on overlapping data. The recommended approach is to build a unified data model that feeds both channels from a single, validated source, with mapping layers that transform the base data into each authority’s required format. This reduces reconciliation errors, lowers ongoing compliance cost and gives management a single, trustworthy view of the business, a material advantage for firms scaling toward multi‑jurisdiction operations under their MiCA CASP authorisation Finland.
Realistic budgeting and document preparation determine whether an application moves smoothly or stalls. The figures below are indicative ranges; actual outcomes depend on service complexity and file quality.
Applicants should budget for both regulatory processing fees and professional advisory costs. In Finland, combined legal and setup fees commonly fall in the €40,000–€150,000+ range depending on complexity, a firm offering only advice will sit at the lower end, while a custody and trading‑platform operator with bespoke technology and multi‑service scope will be at the higher end. Cost drivers include the number of services, the sophistication of the ICT stack, the volume of translation required, and the number of regulator information rounds.
A structured application index, cross‑referencing each requirement to its supporting document, materially improves review speed. A downloadable checklist and sample application template package help teams track completeness. Content operations should attach the checklist PDF, sample application document package and capital modelling spreadsheet to this page as supporting assets.
Firms previously registered as virtual asset service providers must migrate to full CASP authorisation. Because the transitional period ended on 30 June 2025, legacy registrations no longer support continued in‑scope activity, and affected firms must ensure they have applied for or obtained CASP authorisation. Common pitfalls include underestimating the depth of documentation now required, failing to uplift AML and ICT frameworks to MiCA standards, and neglecting the new Vero reporting build. Immediate compliance actions are to confirm current authorisation status with the FIN‑FSA, close any documentation gaps, and stand up the 2026 reporting pipeline. Our resource on the transitional rules for VASPs sets out the migration steps and remediation checklist.
Obtaining MiCA CASP authorisation Finland is now the essential gateway for any firm seeking to offer crypto‑asset services in Finland and passport across the EU/EEA. With the transitional period closed and the 2026 Vero reporting obligations live, the compliance bar is both higher and more integrated than ever, spanning prudential capital, governance, ICT resilience, AML/KYC and tax‑information reporting. Firms that plan early, map their services accurately against MiCA’s scope, evidence their capital robustly and build a unified data architecture for both supervisory and tax reporting will move through the FIN‑FSA process most efficiently.
Finland’s credible regulator, competitive costs and full passporting reach make it a strong home for a European crypto business, provided applicants treat MiCA CASP authorisation Finland as the strategic foundation of their market entry rather than a box to be ticked after launch.
Last reviewed: 28 August 2026.
posted 15 minutes ago
posted 36 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
posted 4 hours ago
posted 5 hours ago
posted 5 hours ago
posted 5 hours ago
posted 6 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message