[codicts-css-switcher id=”346″]

Global Law Experts Logo
substance requirements estonia

Estonia Fintech Licensing 2026: Substance Requirements, Local Presence & Compliance for Emis, Pis and Crypto Firms

By Global Law Experts
– posted 1 hour ago

Substance requirements Estonia has become one of the most consequential compliance questions for fintech founders as three regulatory forces converge in 2026: the sunset of the legacy virtual asset service provider (VASP) regime, the phased application of the Markets in Crypto-Assets Regulation (MiCA), and the rollout of the EU’s DAC8 crypto-asset reporting framework. For electronic money institutions (EMIs), payment institutions (PIs) and crypto-asset service providers preparing new applications or remediating existing licences, the days of a nominal Estonian company with an offshore management team are firmly over. The Estonian Financial Supervision and Resolution Authority (Finantsinspektsioon) now expects demonstrable local presence, genuine management, and operational readiness before it grants or maintains authorisation.

This guide sets out, in practical and regulator-cited terms, what those expectations mean and how to evidence them.

Last updated: 1 September 2026

Key takeaways on substance requirements in Estonia for 2026

  • Genuine local presence is non-negotiable. A registered entity alone does not satisfy the substance requirements Estonia applicants must meet; regulators look for real management, staff, premises and operational systems.
  • The VASP sunset reshapes crypto licensing. Legacy virtual currency authorisations give way to the MiCA regime, and transitional firms face heightened scrutiny of their substance and AML frameworks.
  • DAC8 adds reporting obligations. Crypto firms operating from Estonia must build the data and compliance capacity to meet new EU-wide crypto-asset reporting rules.
  • MiCA passporting does not dilute home-state substance. Passporting extends market access; it does not relieve Estonian-authorised firms of their obligation to maintain real substance in Estonia.
  • Evidence is everything. Lease agreements, employment contracts, payroll records, board minutes and policy manuals are the currency of a successful application.
  • Governance must be real, not decorative. Independent oversight, an accountable AML officer and functioning internal controls are central to regulator expectations.

Quick overview, Estonian licensing landscape for EMIs, PIs and crypto firms in 2026

Estonia’s financial sector is supervised by the Estonian Financial Supervision and Resolution Authority (Finantsinspektsioon), which authorises and supervises payment institutions, electronic money institutions and, under the new European framework, crypto-asset service providers. The statutory basis for payment and e-money authorisation sits in Estonian legislation consolidated on Riigi Teataja, the Estonian State Gazette, alongside the Money Laundering and Terrorist Financing Prevention Act that governs anti-money-laundering obligations for licensed firms.

For EMIs and PIs, the licensing framework has long required credible governance, adequate capital and effective risk management. What has intensified in the run-up to 2026 is the practical weight regulators place on the economic substance applicants can prove, the difference between a paper structure and a genuine operating business. For crypto firms, the picture has changed more dramatically. The legacy virtual asset regime, under which many Estonian companies once held virtual currency service authorisations, is being wound down as the EU-wide MiCA framework, set out in Regulation (EU) 2023/1114, takes over. MiCA introduces a harmonised authorisation and passporting regime for crypto-asset service providers, but it also raises the bar on organisational and governance requirements, and, by extension, on substance.

The strategic implication is straightforward: whether you are pursuing an EMI licence in Estonia, a payment institution authorisation, or transitioning a crypto business from the legacy regime into MiCA, you must plan your local presence and evidence base from day one. Retrofitting substance after an application has stalled is far more expensive and far less persuasive.

What substance requirements do fintech licence applicants need in Estonia?

“Substance,” in the Estonian licensing context, means that the licensed activity is genuinely directed, managed and carried out in Estonia, not merely booked through an Estonian shell. Finantsinspektsioon assesses whether the applicant has the human, physical and systemic resources to run the regulated business responsibly and to be effectively supervised from within the jurisdiction. This is where the substance requirements Estonia expects diverge sharply from the minimal formalities some applicants assume are sufficient.

In practice, the regulator looks for a cluster of interlocking elements. There must be a genuine Estonian legal entity, properly registered and with a real registered address. There must be management physically present and accountable in Estonia, not just a resident director whose role is nominal. There must be an appropriate number of qualified local staff to perform the core functions, compliance, risk, operations and finance, proportionate to the scale and complexity of the business. There must be office premises capable of housing that team. And there must be operational systems, internal controls and an anti-money-laundering function that actually function.

Crucially, none of these requirements is satisfied by a single document. The regulator evaluates the whole picture and tests whether the pieces cohere, whether the business plan matches the staffing, whether the staffing matches the premises, and whether the governance structure reflects genuine decision-making in Estonia. Where those elements are inconsistent, applications are delayed or rejected, and existing licences can come under supervisory pressure.

Minimum corporate and operational elements: entity, office, IP and bank accounts

The foundation of any Estonian licence is a properly incorporated company. Registration and registered-address evidence should come from the Estonian Business Register (RIK), whose extracts serve as the primary proof of legal existence and registered office. Beyond incorporation, applicants should assemble:

  • Lease agreement. A genuine, arm’s-length lease for physical premises in Estonia, supported by utility bills and evidence of actual use rather than a virtual-office mailbox.
  • Local bank or payment account. An operational account through which the business genuinely transacts, receiving revenue, paying salaries and settling supplier invoices.
  • Invoicing and accounting. Live accounting records, invoices issued and received, and books maintained in Estonia, ideally by or with local bookkeeping resource.
  • Intellectual property and systems. Where the business relies on proprietary technology, evidence of ownership or valid licences to the software and platforms used to deliver the service.
  • Business plan linking local operations. A plan that explicitly maps the Estonian operation to the revenue model, so the regulator can see the local activity is where value is genuinely created.

Minimum staff and senior management: roles and time commitments

There is no single statutory headcount that satisfies substance for every business. Finantsinspektsioon assesses staffing proportionately, a small PI with a narrow product set will reasonably have fewer people than a multi-product EMI or a crypto-asset service provider handling custody. What matters is that the core control functions are genuinely staffed in Estonia by qualified people who devote real time to the business.

Applicants should prepare evidence for each key role: employment contracts, detailed CVs demonstrating relevant experience, and where the regulator expects to see it, time-allocation evidence such as timesheets or calendar records showing the individual is actually engaged with the Estonian operation. Senior management, the persons who direct the business day to day, should be present in Estonia and demonstrably in control. Where a role is filled by someone with commitments elsewhere, be prepared to explain how sufficient time and attention are allocated, because a management team that exists only on paper is one of the most common reasons the substance requirements Estonia imposes are found to be unmet.

Governance, internal controls and the compliance function

The compliance and AML architecture is where substance and regulatory expectation meet most directly. Every EMI, PI and crypto firm must have a designated anti-money-laundering officer with the seniority, resources and independence to do the job. This is not a box-ticking appointment: the AML officer must be able to demonstrate active oversight, and the regulator will expect to see a compliance manual, documented know-your-customer procedures, a business-wide money-laundering and terrorist-financing risk assessment, and clear reporting lines to the board. FATF’s guidance on a risk-based approach to virtual assets and VASP supervision, published by the FATF, sets the international benchmark that Estonian supervision reflects, particularly for crypto businesses.

Internal controls should cover IT security, business continuity, outsourcing oversight and conflict-of-interest management, and each should be documented in a policy that the local team can actually operate.

VASP sunset, DAC8 and AML updates, effects on crypto firms

The most acute change for crypto businesses is the transition away from the legacy virtual asset service provider regime toward MiCA authorisation. The VASP sunset that Estonian crypto operators now face means that authorisations granted under the old national framework cease to be a viable long-term basis for operating, and firms must either obtain authorisation as a crypto-asset service provider under MiCA or wind down their regulated activity. Regulation (EU) 2023/1114 governs the scope, the transitional arrangements and the passporting mechanics; the precise end date of any national transitional period is set by the applicable Estonian implementing provisions, and firms should confirm their own deadline against the current legislation and Finantsinspektsioon guidance.

What this means in substance terms is heightened scrutiny. During the transition, Finantsinspektsioon and its European counterparts are re-examining crypto firms’ governance, capital, custody arrangements and AML controls to a MiCA standard that is materially higher than the old regime demanded. Firms that treated their legacy authorisation as a light-touch formality will find the MiCA authorisation process exposes exactly the substance gaps this guide describes: absent local management, thin staffing, inadequate compliance functions and weak evidence of genuine Estonian operations.

Layered on top is DAC8. The European Commission’s Digital Asset Reporting (DAC8) framework, adopted as Council Directive (EU) 2023/2226 amending the Directive on Administrative Cooperation, introduces new crypto-asset reporting obligations across EU member states, requiring reporting crypto-asset service providers to collect, verify and report user and transaction data to tax authorities. For firms operating from Estonia, this means building the data infrastructure and compliance processes to identify reportable users, apply due-diligence procedures and file with the competent authority. The Estonian Tax and Customs Board is the domestic authority whose administrative guidance and reporting channels will apply.

DAC8 readiness is now inseparable from substance: a firm cannot credibly claim to be operationally ready if it lacks the local compliance and data capacity to meet these reporting duties.

The practical takeaway for crypto firms is that AML, MiCA authorisation and DAC8 reporting form a single, integrated compliance burden. Preparing for one without the others invites supervisory intervention. Industry observers expect the transition period to expose a number of under-resourced firms, and early indications suggest regulators across the EU are prioritising substance and AML adequacy in their reviews.

Governance, board and management, what satisfies Estonian regulator expectations

Governance is the connective tissue of substance. Finantsinspektsioon expects a board and executive management that genuinely direct the business and are fit and proper for their roles. For EMIs and PIs, that means a board with appropriate collective experience, clarity over who holds executive responsibility, and, depending on scale, independent oversight capable of challenging management. Executive management should be present in Estonia, accountable, and able to demonstrate that strategic and operational decisions are taken locally.

Delegation is permitted, but it must be real and controlled. Where certain functions are delegated within the group or to third parties, the licensed entity must retain genuine oversight and the ultimate decision-making authority. The regulator distinguishes sharply between legitimate delegation with robust controls and the outsourcing of core management to a location where the business is actually run, the latter defeats the purpose of an Estonian licence and is treated as a substance failure.

Certain shortcuts are consistently rejected. A resident director who holds numerous directorships and contributes nothing operationally is a red flag, not a solution. A management structure where the persons named in the application are not the persons making decisions is a misrepresentation risk. And an AML officer who lacks the authority or resources to act independently undermines the entire compliance framework. Applicants should assume the regulator will test whether the governance described on paper matches the reality, and should build a structure that survives that test.

Acceptable use of remote and outsourced teams, limits and evidence

Outsourcing and remote working are permitted within limits, and many legitimate fintechs use group service providers or specialist vendors for functions such as IT, customer support or aspects of transaction monitoring. What matters is that outsourcing does not hollow out the licensed entity. Core control functions, particularly compliance, risk management and senior decision-making, should remain genuinely within the Estonian operation. Where functions are outsourced, the firm should maintain:

  • Written outsourcing agreements. Clear contracts defining the scope, responsibilities and service levels of each provider.
  • Service-level agreements (SLAs). Measurable performance standards and remedies, so the licensed entity retains effective control over quality.
  • Ongoing oversight and audit rights. Documented monitoring, reporting from providers, and the contractual right to conduct on-site audits.
  • A retained accountable owner. A named person in Estonia responsible for each outsourced function, ensuring the regulator always has a local point of accountability.

How to document and evidence economic substance and operational readiness

Substance that cannot be evidenced does not exist as far as a regulator is concerned. The strength of an application often comes down to the quality, coherence and organisation of the documentation package. Applicants should assemble a comprehensive evidence file and index it clearly so the case officer can trace each claim to a supporting document. The following checklist reflects the categories of evidence that align with Finantsinspektsioon’s supervisory expectations:

  • Formation documents. Business Register extract, articles of association and shareholder register.
  • Premises evidence. Signed lease agreement, utility bills and photographs or floor plans demonstrating genuine occupation.
  • Employment records. Signed contracts for all key staff, CVs and qualification evidence, and organisational chart showing reporting lines.
  • Payroll and social contributions. Payroll records and proof of social tax payments, demonstrating that staff are genuinely employed and remunerated locally.
  • Accounting and financial records. Books of account, sample invoices issued and received, bank statements and management accounts.
  • Governance records. Board and management meeting minutes showing that decisions are genuinely taken in Estonia, with agendas and attendance records.
  • Policy suite. AML/CTF policy and procedures, KYC manual, business-wide risk assessment, IT security policy, business continuity plan and outsourcing policy.
  • Systems evidence. Software licences, screenshots or specifications of core operating and monitoring systems, and DAC8 reporting-capability documentation for crypto firms.
  • Risk registers. Key risk indicator (KRI) registers and evidence of ongoing monitoring.

Regulators evaluate this material for consistency and authenticity. They cross-check the number of staff against the premises and the business plan; they test whether the payroll matches the named individuals; they read board minutes to see whether decisions are genuinely local. A tidy, well-indexed package with consistent internal logic signals a genuine operation. A disjointed collection of standalone documents signals a constructed façade. Recommended practice is to build a master index that maps each substance element to its supporting files, using consistent file naming, for example, grouping documents by category and dating each version, so the application reads as a coherent narrative rather than a document dump.

Comparison table, substance expectations: EMI vs PI vs crypto (CASP) in Estonia (2026)

Dimension EMI (E-money Institution) PI (Payment Institution) Crypto (CASP under MiCA)
Licensing authority Finantsinspektsioon Finantsinspektsioon Finantsinspektsioon (MiCA authorisation as legacy VASP regime sunsets)
Local staff expectation Proportionate team covering compliance, risk, operations and finance Proportionate team; may be smaller for narrow product sets Proportionate team with custody, security and monitoring capacity where applicable
Compliance function Dedicated AML officer, full policy suite, board oversight Dedicated AML officer, full policy suite, board oversight Dedicated AML officer to MiCA/FATF standard, enhanced monitoring
AML / DAC8 obligations Full AML Act obligations; no DAC8 crypto reporting Full AML Act obligations; no DAC8 crypto reporting Full AML obligations plus DAC8 crypto-asset reporting
MiCA relevance Limited unless issuing crypto-linked products Limited unless offering crypto services Central, MiCA is the governing framework
Passporting readiness EU passporting under payment services framework EU passporting under payment services framework MiCA passporting once authorised
Common substance evidence Lease, payroll, board minutes, capital, policies Lease, payroll, board minutes, capital, policies Lease, payroll, board minutes, custody controls, DAC8 systems

MiCA passporting and cross-border implications, what applicants must anticipate

One of the most attractive features of MiCA is passporting: once authorised as a crypto-asset service provider in one member state, a firm can provide services across the EU without seeking separate authorisation in each country. The mechanism is set out in Regulation (EU) 2023/1114 and operates through notification between the home-state and host-state supervisors. For firms authorised in Estonia, this makes an Estonian MiCA authorisation a gateway to the wider European market.

However, a persistent misconception must be addressed directly: passporting does not relieve a firm of its home-state substance obligations. If Estonia is your home state, Estonia remains responsible for your prudential and conduct supervision wherever you operate, and Finantsinspektsioon must be able to supervise a genuine business located in Estonia. Passporting extends where you can sell; it does not move where you must be substantively established. Firms that obtain an Estonian authorisation intending to run the actual business elsewhere will find that supervisory cooperation between authorities, and the ongoing reporting obligations that passporting entails, quickly expose the mismatch.

Maintaining real Estonian substance is therefore a continuing obligation, not a one-off application hurdle, and it must be sustained throughout the life of the licence.

Practical remediation steps for existing licence holders

Existing EMI, PI and crypto licence holders that recognise substance gaps should act on a prioritised timeline rather than attempting everything at once. The following roadmap reflects a sensible sequencing of priorities:

  1. Immediate (within 30 days). Conduct a substance gap assessment mapping current staff, premises, governance and systems against regulator expectations. Confirm the AML officer’s authority and resourcing. Identify the most exposed weaknesses, typically absent local management or an inactive compliance function.
  2. Short term (within 90 days). Regularise employment contracts and ensure key staff are genuinely engaged locally; hire to close critical gaps. Formalise or renegotiate the lease and premises arrangements. Bring board and management meetings into a documented, Estonia-based cadence with proper minutes.
  3. Medium term (within 6 months). Upgrade AML and transaction-monitoring systems to current standards, complete DAC8 readiness for crypto firms, refresh the full policy suite, and, for crypto operators, advance the MiCA authorisation or transition process in line with the applicable timeline.

Throughout remediation, document every step. A firm that can show a credible, dated remediation plan and evidence of execution is in a far stronger position with the regulator than one that waits to be told its substance is inadequate.

Conclusion

Meeting the substance requirements Estonia now enforces is the central challenge for any EMI, PI or crypto firm seeking or maintaining a licence in 2026. The convergence of the VASP sunset, MiCA authorisation and DAC8 reporting has permanently raised the bar: genuine local management, proportionate qualified staff, real premises, functioning governance and a credible AML framework are no longer optional refinements but the price of entry. The firms that succeed will be those that build substance into their structure from the outset and evidence it meticulously, rather than treating it as a compliance afterthought. Whether you are preparing a new application or remediating an existing licence, a jurisdiction-specific assessment against these expectations is a valuable first step.

For tailored guidance, consult the Licensing lawyers, Estonia directory. This guide is general information and not a substitute for advice from qualified local counsel on your specific circumstances.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Mark Gofaizen at Gofaizen & Sherle Fintech Lawyers, a member of the Global Law Experts network.

Sources

  1. Estonian Financial Supervision and Resolution Authority (Finantsinspektsioon)
  2. Riigi Teataja (Estonian State Gazette)
  3. EUR-Lex, Markets in Crypto-Assets (MiCA) Regulation (EU) 2023/1114
  4. European Commission, Taxation and Customs Union (DAC8 / Council Directive (EU) 2023/2226)
  5. FATF, Guidance on a Risk-Based Approach to Virtual Assets and VASPs
  6. Estonian Tax and Customs Board (Maksu- ja Tolliamet)
  7. Estonian Centre of Registers and Information Systems, Business Register (RIK)
  8. Estonian Bar Association (Advokatuur)

FAQs

What substance does the Estonian regulator expect for a fintech licence?
Finantsinspektsioon expects a genuine Estonian entity with local management, proportionate qualified staff, real office premises, functioning operational systems and an effective AML and compliance function. The activity must be genuinely directed and carried out in Estonia so the firm can be effectively supervised there. Statutory obligations, including AML duties, are set out in legislation consolidated on Riigi Teataja, and supervisory expectations are published by Finantsinspektsioon.
No. Nominal resident directors and offshore management that actually runs the business are among the most common reasons the substance requirements Estonia imposes are found unmet. Decision-making and senior management must be genuinely present and accountable in Estonia. Legitimate delegation and outsourcing are permitted with written contracts, SLAs, oversight and audit rights, but core control functions and ultimate authority must remain within the Estonian entity.
There is no fixed statutory headcount. Finantsinspektsioon assesses staffing proportionately to the scale and complexity of the business. A narrow-scope PI may reasonably operate with fewer people than a multi-product EMI or a crypto custodian. What matters is that core functions, compliance, risk, operations and finance, are genuinely staffed by qualified people in Estonia, evidenced by contracts, CVs, payroll and time-allocation records.
The legacy virtual asset service provider regime is being wound down as MiCA takes over. Crypto firms must obtain MiCA authorisation as crypto-asset service providers or cease regulated activity. The transition brings materially higher governance, capital, custody and AML standards under Regulation (EU) 2023/1114, plus DAC8 reporting obligations. Firms that treated legacy authorisation as light-touch will face heightened scrutiny of their substance during re-licensing. Confirm your applicable transitional deadline against current Estonian legislation and Finantsinspektsioon guidance.
No. Passporting under MiCA extends where you can offer services across the EU, but it does not relieve you of home-state obligations. If Estonia is your home state, Finantsinspektsioon retains supervisory responsibility and must be able to supervise a genuine business located in Estonia. Maintaining real Estonian substance is a continuing obligation for the life of the licence, not a one-time application step.
Include Business Register extracts, articles of association, a signed lease with utility bills, employment contracts and CVs for key staff, payroll and social-tax records, accounting books and sample invoices, board and management minutes, and a full policy suite covering AML, KYC, IT security, business continuity and outsourcing. Crypto firms should add custody controls and DAC8 reporting-capability documentation. Index everything so each claim traces to evidence.
By Awatif Al Khouri

posted 2 hours ago

By Awatif Al Khouri

posted 2 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Estonia Fintech Licensing 2026: Substance Requirements, Local Presence & Compliance for Emis, Pis and Crypto Firms

Send welcome message

Custom Message