[codicts-css-switcher id=”346″]

Global Law Experts Logo
crypto custody license estonia

Mica Crypto Custody Authorisation in Estonia (2026): Requirements, Controls & EU Passporting

By Global Law Experts
– posted 2 hours ago

A crypto custody license estonia application is now the central strategic decision for any firm that safeguards client crypto-assets and wants a compliant footprint inside the European Union. Since the Markets in Crypto-Assets Regulation, Regulation (EU) 2023/1114 (MiCA), established a single, harmonised authorisation regime for crypto-asset service providers, Estonia has re-emerged as a pragmatic gateway into the EU market, combining fast incorporation, English-language dialogue and an experienced supervisor. The 2026 landscape, shaped by high-profile exchange exits and closely watched authorisation cases across the bloc, has pushed custody providers to reassess where and how they seek authorisation.

This guide translates the statutory text into a practical, Estonia-specific roadmap: who needs authorisation, what operational and security controls the regulator expects, how AML/KYC obligations interact with the Estonian framework, and how a MiCA-authorised custodian can passport its services across all EU Member States.

Who this guide is for and what it delivers

This guide is written for compliance officers, founders and CEOs of custody and wallet providers, in-house counsel and fintech compliance consultants who need an Estonia MiCA authorisation and EU passporting roadmap. It sets out the step-by-step authorisation process in Estonia, the required documentation, capital and operational controls, the AML/KYC impacts, practical passporting options, and a checklist for both the application phase and ongoing compliance. Throughout, statutory claims are anchored to primary sources, the MiCA text on EUR-Lex, European Commission policy pages, and guidance from the Estonian Financial Supervision Authority (Finantsinspektsioon), the Estonian Financial Intelligence Unit, the EBA and ESMA.

MiCA authorisation pathway for a crypto custody license estonia

MiCA created a single category of authorisation for crypto-asset service providers (CASPs), and within it defines the specific activity of “providing custody and administration of crypto-assets on behalf of clients.” A firm that holds, controls or safeguards clients’ crypto-assets, or the means of access to them, such as private keys, falls within this activity and must be authorised before it begins providing the service. Understanding where custody sits within the wider CASP framework is the first step toward a successful crypto custody license estonia application.

Legal basis and key MiCA provisions for custody

The governing instrument is Regulation (EU) 2023/1114. MiCA defines the crypto-asset services subject to authorisation, imposes prudential, organisational and conduct-of-business obligations on CASPs, and sets specific duties on custodians relating to the safekeeping of client assets, the maintenance of a register of positions, liability for loss, and the segregation of client holdings from the provider’s own assets. The custody provisions require firms to establish a custody policy, keep records that allow the reconstruction of every client’s holdings at any point in time, and put in place procedures to prevent the use of client crypto-assets except on the client’s instructions. These statutory requirements sit alongside the general CASP obligations on governance, own funds, complaints handling, conflicts of interest and outsourcing.

Competent authority in Estonia and pre-application engagement

In Estonia, the competent authority for MiCA authorisations is the Financial Supervision Authority, Finantsinspektsioon. All applications for a crypto custody license estonia are submitted to, assessed by, and supervised on an ongoing basis by this authority. Experienced applicants treat pre-application engagement as a distinct and valuable phase rather than an optional courtesy. Requesting an introductory meeting allows the applicant to outline its business model, custody architecture and governance structure, and to surface any concerns before formal filing. The regulator will typically want to understand the ownership chain, the identity and suitability of key function holders, the technology stack underpinning custody, and the source of the firm’s capital.

Early dialogue reduces the risk of the application stalling later on requests for information and helps calibrate the completeness of the initial submission.

Who needs authorisation: custody, custodian and wallet provider definitions

Not every business that touches a wallet requires authorisation, and the distinction is one of control. The determining factor under MiCA is whether the firm holds or controls clients’ crypto-assets or the means of access to them on the clients’ behalf.

  • Custody service provider. A firm that safeguards clients’ crypto-assets or the private keys used to access them, and administers those assets. This is the classic hosted-custody model and it requires authorisation.
  • Custodial wallet provider. A wallet operator that holds the private keys on behalf of the user is exercising control and therefore performs a custody service subject to authorisation.
  • Non-custodial (unhosted) wallet provider. Software that generates and stores keys entirely on the user’s device, where the provider never holds or controls the keys, generally falls outside the custody activity, though firms should assess the precise facts, because functionality that gives the provider access can change the analysis.

Because these categories turn on the degree of control, the correct classification is fact-specific. Firms operating hybrid models, for example, multi-party computation arrangements where key shares are distributed, should analyse whether they can, alone or with others, effectively control client assets, as that determines whether authorisation is required.

Minimum documentation and corporate prerequisites

Before filing, the applicant must be a properly constituted legal entity with a registered office and effective management in the EU, and MiCA requires at least one director to be resident in the Union. MiCA also requires that the persons who direct the business and hold key functions are fit and proper, with the necessary knowledge, skills and integrity. Governance arrangements must be documented, with clear reporting lines, an internal control framework, and identified responsibility for compliance, risk and anti-money-laundering functions. The corporate prerequisites include evidence of the required own funds or safeguarding cover, a robust business plan, and a description of the custody technology and controls.

These elements feed directly into the application pack set out later in this guide and should be assembled to the standard the regulator expects before any formal submission for a crypto custody license estonia.

Operational, security and key-management controls required under MiCA

The controls layer is where custody applications most often succeed or fail. MiCA requires CASPs, and custodians in particular, to maintain sound administrative and accounting procedures, effective risk management, and information and communication technology systems that are resilient and secure. For a custody provider, the practical translation is a demonstrable, auditable framework covering how private keys are generated, stored, used and recovered, and how client assets are protected against loss, theft and operational failure. Crypto custody compliance is not a paperwork exercise; the regulator expects evidence that the described controls actually operate.

Key management and custody models

MiCA does not mandate a single key-management technology, but it does require that the chosen model delivers the security, integrity and availability that the safekeeping obligation demands. In practice, custodians deploy a combination of storage tiers, and the regulator will scrutinise the rationale for the mix and the controls around each tier.

  • Cold storage. Keys held entirely offline, typically for the majority of client assets, with strict physical and procedural access controls and multi-person authorisation for any movement.
  • Warm and hot wallets. Connected or semi-connected storage used to service withdrawals and operational liquidity, held to the minimum necessary and protected by layered controls.
  • Hardware security modules (HSMs). Certified devices used to generate and protect keys, providing tamper resistance and controlled signing.
  • Multi-party computation (MPC). Distribution of key shares across parties or environments so that no single point of compromise can move assets.

Whichever architecture is adopted, the applicant must document key generation, backup, rotation, recovery and destruction procedures, and evidence them through independent audit. Regulators expect clear separation of duties so that no single individual can unilaterally move client assets.

IT security, security assurance, encryption and business continuity

MiCA’s ICT resilience expectations require custodians to protect the confidentiality, integrity and availability of data and systems. In practice this means encryption of sensitive data in transit and at rest, hardened infrastructure, formal access management, and continuous monitoring. Independent assurance is central: applicants are expected to commission recognised security assessments, such as control assurance reports and regular penetration testing, and to remediate findings on a defined cadence. Custodians should also be mindful that the EU Digital Operational Resilience Act (Regulation (EU) 2022/2554, DORA) applies to CASPs and imposes detailed ICT risk-management, testing and incident-reporting obligations.

Business continuity and disaster recovery planning must address the specific failure modes of a custodian, including loss of a key-storage facility, compromise of a signing environment, and the incapacity of key personnel. The regulator will look for tested recovery procedures, not merely documented ones, and for evidence that testing is repeated at appropriate intervals. Custodians should also be prepared for incident notification obligations, which require prompt reporting of significant operational or security incidents to the competent authority.

Insurance, internal control and segregation of client assets

Segregation is a core custody obligation under MiCA: client crypto-assets must be held separately from the provider’s own assets and must not be used for the provider’s account. Custodians must maintain records and reconciliations sufficient to identify each client’s holdings at any moment and to demonstrate that segregation is maintained in practice. Beyond segregation, applicants strengthen their position by holding appropriate insurance or an equivalent capital buffer against loss of client assets, insurance cover for crypto custodians is increasingly treated as a marker of operational maturity. Internal control functions, including compliance and risk, must be adequately resourced and independent, with reporting to the management body.

The combination of segregation, reconciliation, insurance and independent controls is what allows a custodian to evidence that client assets are genuinely protected.

Third-party providers, outsourcing and cloud use

Most custodians rely on third parties, cloud infrastructure, HSM vendors, MPC providers and monitoring tools. MiCA permits outsourcing but does not permit a firm to outsource its responsibility. Applicants must perform documented due diligence on providers, put in place written contracts that secure audit and access rights, service levels, data protection and exit arrangements, and retain the ability to oversee and, if necessary, replace the provider. Where outsourcing concerns critical or important functions, firms should expect to notify Finantsinspektsioon and to demonstrate that the arrangement does not impair supervision or the firm’s operational resilience. DORA additionally sets requirements for the management of ICT third-party risk.

Cloud deployment in particular attracts scrutiny of data location, segregation, encryption key ownership and the provider’s own resilience posture. Robust outsourcing governance is a recurring focus of custody assessments and a frequent source of remediation requests.

AML/KYC, prudential and reporting changes under MiCA in Estonia

MiCA sits alongside, rather than replaces, the EU anti-money-laundering framework. A crypto custody provider authorised in Estonia is both a CASP under MiCA and an obliged entity under AML rules, and it must operate a single, integrated compliance framework that satisfies both. Firms that previously held Estonian virtual asset service provider registrations should not assume their existing AML programme is sufficient; MiCA authorisation raises the bar on governance, controls and evidence, and the AML expectations have tightened in parallel.

Interaction with AML rules and the Estonian FIU

In Estonia, anti-money-laundering and counter-terrorist-financing reporting for crypto firms flows to the Financial Intelligence Unit, which is a government agency operating within the area of government of the Ministry of Finance. A custody provider is the reporting entity: it must appoint responsible officers, including a money-laundering reporting officer, and file reports directly with the FIU. The custodian must implement customer due diligence, ongoing monitoring and record-keeping consistent with the Estonian Money Laundering and Terrorist Financing Prevention Act and the applicable EU framework, and cooperate with the FIU’s information requests.

Aligning the MiCA governance structure with the AML reporting structure, so that the compliance function, the money-laundering reporting officer and the management body have clear, non-conflicting responsibilities, is essential to satisfying both regimes at once.

Enhanced due diligence and ongoing monitoring for crypto custody

Crypto custody carries elevated inherent risk, and the regulator expects a risk-based programme calibrated accordingly. Customer due diligence must establish beneficial ownership and the source of funds and wealth where risk factors are present, and enhanced due diligence applies to higher-risk relationships, complex structures and exposure to higher-risk jurisdictions. Ongoing transaction monitoring should be tuned to the specific typologies of crypto, including exposure to mixing services, high-risk counterparties and sanctioned addresses, and supported by blockchain analytics. The European Banking Authority guidance on AML risk factors and supervisory practice is a useful reference point for calibrating these controls, and custodians should document their risk assessment and the reasoning behind their thresholds.

Prudential safeguards, capital and reserve rules

MiCA imposes prudential requirements on CASPs, requiring them to hold minimum own funds set by reference to the class of services provided, and to maintain safeguards over client assets. For custodians, the prudential dimension combines a capital floor with the safeguarding and segregation obligations described above, so that the firm has both a loss-absorbing buffer and structural protection of client holdings. Applicants must evidence the source and adequacy of their capital at authorisation and maintain it on an ongoing basis, reporting to the supervisor as required; the applicable minimum own-funds figures are set out in MiCA and should be checked against the current regulatory text.

ESMA provides supervisory context on capital, safeguarding and cross-authority cooperation under MiCA, and its work is relevant where custody activity interacts with instruments that may fall within the securities regime. Firms should treat capital planning as a live obligation rather than a one-time hurdle.

Incident and suspicious transaction reporting flows

Two distinct reporting channels must operate reliably. Suspicious transaction reports go to the Estonian FIU under the AML framework, following the FIU’s procedures and timelines, and the custodian must have systems that surface reportable activity promptly. Separately, operational and security incident notifications go to Finantsinspektsioon under MiCA and, where applicable, DORA, covering significant events that affect the firm’s systems or client assets. Custodians should map both flows explicitly in their procedures, assign ownership, and rehearse them, so that when an incident or a suspicious pattern arises the correct report reaches the correct authority within the required timeframe. Clear escalation paths and documented decision-making are what supervisors look for when they test these processes.

EU passporting under MiCA, options, timeline and practical steps

The single most compelling reason to pursue a crypto custody license estonia is the passport. Once authorised, a CASP can provide its services throughout the EU without seeking a separate authorisation in each Member State, turning a single Estonian authorisation into access to the entire bloc. MiCA passporting for an Estonian custodian is driven by a home-state notification procedure and structured cooperation between the home and host authorities.

Passporting mechanics under MiCA

Under MiCA, a CASP intending to provide services in another Member State notifies its home competent authority, in this case Finantsinspektsioon, of the Member States in which it intends to operate, the services it will provide, and the intended start date. The home authority communicates that information to the host authorities and to ESMA within the period set by the regulation. The provider may then commence cross-border activity once the notification process is complete, in accordance with the timelines MiCA prescribes. The European Commission’s MiCA pages provide policy context on the passporting framework and implementation. The mechanism is administrative rather than a fresh authorisation, which is what makes Estonia attractive as a launch jurisdiction.

Branch, subsidiary or cross-border service delivery

The passport supports different operating models, each with distinct compliance consequences.

  • Cross-border services. The lightest model: the firm serves clients in other Member States from its Estonian base under the passport notification, with home-state supervision. It carries the lowest establishment cost but requires careful attention to how services are marketed and delivered in host states.
  • Branch. A physical establishment in a host state, notified through the passport process, which brings a local presence and some host-state interaction while remaining part of the authorised Estonian entity.
  • Subsidiary. A separately incorporated and separately authorised entity in another Member State. This is not passporting in the strict sense; it means a fresh authorisation and its own capital, governance and supervision, and is chosen only where local substance or strategic reasons justify the additional burden.

Even under cross-border passporting, AML supervision and certain conduct rules can involve host-state considerations, so firms should confirm the host expectations before launch rather than assume full uniformity.

Practical checklist: passport readiness

Before notifying, a custodian should confirm that its authorisation scope covers the services it intends to passport, that its capital and controls scale to the additional volumes, and that its AML programme addresses the risk profile of the new markets. It should identify any language, marketing or consumer-protection requirements in the host states, prepare the notification documentation, and build a realistic timeline that allows for the statutory notification period before go-live. Treating passporting as a planned project, rather than an afterthought, avoids the operational gaps that draw supervisory attention.

Application checklist and timeline for a crypto custody license estonia

The crypto custody license estonia application is document-intensive, and the quality of the pack materially affects the timeline. A well-prepared submission that anticipates the regulator’s questions moves faster than a thin filing that triggers successive information requests.

Pre-application: corporate readiness and fit and proper checks

Incorporate the Estonian entity, establish governance, and assemble evidence of the suitability of directors and key function holders. Hold pre-application discussions with Finantsinspektsioon to align expectations and confirm the completeness of the intended submission.

Application pack

  • Business plan. Description of the custody services, target clients, volumes and financial projections.
  • Governance and internal control framework. Organisational structure, reporting lines, and compliance, risk and AML functions.
  • Capital evidence. Proof of the required own funds and their source.
  • Key management and custody description. The custody architecture, storage tiers, key lifecycle procedures and access controls.
  • Security assurance. Independent security assessments, penetration test results and remediation status.
  • Business continuity and disaster recovery plans. Tested procedures for custody-specific failure modes.
  • AML/CTF policy. Risk assessment, CDD and monitoring procedures, and appointment of the responsible officer.
  • Insurance evidence. Cover against loss of client assets, or an equivalent buffer.

Typical timeline and fees

Timelines depend on the completeness of the application and the complexity of the business. MiCA sets out the periods within which the competent authority must acknowledge and assess a complete application, and the assessment clock can be paused while information requests are outstanding. Applicants should build in time for pre-application engagement, the regulator’s assessment period and any information requests, and should confirm current processing expectations and fees directly with Finantsinspektsioon, as these are subject to change.

Comparison table: Estonia versus selected EU Member States

The following high-level comparison is intended to support passport-strategy decisions. All timelines are estimates only, reflect general market observation, and should be verified against the relevant competent authority, for Estonia, Finantsinspektsioon, before any decision is taken.

Jurisdiction Typical authorisation timeline (estimate) Key documentation Practical considerations
Estonia Several months, subject to completeness Application form, business plan, governance, key-management description, AML policy, insurance evidence Fast company incorporation; English-language dialogue generally possible; banking relationships can be a binding factor
Lithuania Several months; variable Similar documentation; local translations may be required Active fintech hub but variable regulator timelines
Malta Longer; substance-focused Detailed substance proofs and local presence evidence Higher costs and stricter substance focus
Germany Longer; stringent Stringent prudential scrutiny and local requirements Strong market with heavier regulatory scrutiny

These figures are indicative and non-binding; regulator timelines shift as MiCA implementation matures.

Conclusion and next steps

Securing a crypto custody license estonia is achievable for firms that treat authorisation as an operational programme rather than a form-filling exercise. The strongest applications combine a clear MiCA classification, a documented and independently tested key-management framework, genuine segregation and insurance of client assets, an integrated AML programme aligned to the Estonian FIU, and a deliberate passporting plan. The practical next steps are to open pre-application dialogue with Finantsinspektsioon, close any gaps in governance, capital and security controls before filing, and build a realistic timeline that allows for the assessment and, later, the passport notification period. Grounding every step in the MiCA text and current regulator guidance is what turns Estonia’s structural advantages into a durable EU custody operation.

This article is for general information only and does not constitute legal advice. MiCA implementation, regulator guidance and timelines continue to evolve; obtain jurisdiction-specific advice before acting.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Mark Gofaizen at Gofaizen & Sherle Fintech Lawyers, a member of the Global Law Experts network.

Sources

  1. Regulation (EU) 2023/1114 (MiCA), EUR-Lex
  2. European Commission, Markets in Crypto-Assets (MiCA)
  3. Estonian Financial Supervision Authority (Finantsinspektsioon)
  4. Estonian Financial Intelligence Unit
  5. European Banking Authority (EBA)
  6. European Securities and Markets Authority (ESMA)

FAQs

What authorisation do crypto custody providers need under MiCA in Estonia?
They need authorisation as a crypto-asset service provider performing custody and administration of crypto-assets under MiCA. The application is made to, and supervised by, Finantsinspektsioon, and the firm must meet MiCA’s governance, prudential, safeguarding and operational requirements.
Yes. A CASP authorised in Estonia can provide services in other Member States through MiCA’s home-state notification procedure, without a separate authorisation in each state. The firm chooses between cross-border services, a branch, or, where justified, a separately authorised subsidiary.
MiCA requires CASPs to hold minimum own funds set by reference to the class of services provided and to safeguard client assets through segregation and record-keeping. Custody applicants must evidence adequate capital and its source at authorisation and maintain it on an ongoing basis; the applicable figures are set out in the MiCA text and should be verified against the current regulation.
Custodians must operate a risk-based AML programme with robust customer due diligence, ongoing transaction monitoring, suspicious transaction reporting to the Estonian FIU, and record-keeping, integrated with MiCA’s governance obligations. EBA guidance is a useful reference for calibrating risk factors and controls.
MiCA does not prescribe a single technology. Cold storage, HSMs and MPC are all acceptable provided the model meets the security, integrity, availability, audit and resilience standards MiCA requires, evidenced through independent audits and penetration testing.
A bank account is not always a formal filing prerequisite, but banks’ willingness to service crypto firms materially affects operational readiness, and the regulator may treat banking and safeguarding arrangements as evidence of operational viability.
arbitration clauses ghana
By Global Law Experts

posted 45 minutes ago

By Awatif Al Khouri

posted 1 hour ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Mica Crypto Custody Authorisation in Estonia (2026): Requirements, Controls & EU Passporting

Send welcome message

Custom Message