[codicts-css-switcher id=”346″]

Global Law Experts Logo
crypto business structure estonia

Our Expert in Estonia

  • GOLD

How to Structure a Multi‑service Crypto Business in Estonia (2026), Licensing Roadmap for Exchanges, Custody & Payments

By Global Law Experts
– posted 1 hour ago

Crypto business structure Estonia decisions have never carried more weight than they do in 2026, as the EU Markets in Crypto‑Assets Regulation (MiCA) and Estonia’s national implementation converge on a hard licensing transition. Founders, general counsel and compliance leads who want to run an exchange, provide custody and process crypto payments from a single Estonian base must now choose a defensible licensing route or risk being unable to operate lawfully in the EU. This roadmap sets out the operational pathway, entity formation, licence selection, document checklists, timelines, costs and the pitfalls that most frequently sink applications. It is written for decision‑stage readers who need concrete steps, not high‑level commentary.

Read it as a regulator‑style guide: sequential, specific and grounded in the primary sources that govern the regime.

This is general information and not legal advice; consult qualified counsel for tailored advice on your specific structure.

1. Overview: Regulatory Framework (MiCA + Estonian CASP Rules)

A viable crypto business structure Estonia today sits on two legal pillars: the directly applicable MiCA Regulation (EU Regulation 2023/1114) at EU level, and Estonia’s national crypto‑asset market legislation that designates the Estonian Financial Supervision Authority (Finantsinspektsioon) as the competent authority for Crypto‑Asset Service Providers (CASPs). MiCA harmonises authorisation, conduct, governance, custody and passporting rules across the Union. Estonian law layers on supervisory and anti‑money‑laundering touchpoints administered nationally.

1.1 What changed in 2026

The defining change is the shift from Estonia’s older virtual‑asset‑service‑provider (VASP) registration model, previously administered in connection with the Financial Intelligence Unit, to full MiCA‑based authorisation supervised by Finantsinspektsioon. Under the transition, operators must hold a CASP authorisation from Finantsinspektsioon by the applicable deadline or cease the regulated activity. MiCA imposes stricter capital, asset‑segregation, custody, governance and disclosure obligations than the prior regime. The practical effect, as industry observers expect, is a consolidation of the market around better‑capitalised, compliance‑mature operators. For a multi‑service player, this means the days of a light‑touch registration covering exchange and wallet services are over, the 2026 framework demands a structured, auditable licensing project.

1.2 Who this roadmap is for

This guide is written for founders, CEOs, general counsel and heads of compliance who are either entering the Estonian market or consolidating an existing multi‑service offering (exchange + custody + crypto payments) under one coherent, EU‑passportable structure.

1.3 Quick summary checklist

  • Define the business model. Decide whether a single CASP authorisation or a split CASP + EMI structure fits your services.
  • Form the entity and fund capital. Incorporate an Estonian company and evidence the applicable minimum capital.
  • Build the compliance core. Draft AML/KYC, governance, risk and custody policies to MiCA and FATF standards.
  • Prepare the technical dossier. IT/security architecture, penetration testing and asset‑segregation design.
  • Apply to Finantsinspektsioon. Submit a complete CASP (and, where relevant, EMI) application.
  • Onboard banking and AML arrangements. Run these in parallel to protect time‑to‑market.
  • Prepare MiCA passporting. Assemble notification documents for EU‑wide market access post‑authorisation.

2. Eligibility: Who Can Apply

Eligibility for an Estonian crypto authorisation turns on corporate form, management substance, capital and the integrity of controlling persons. Finantsinspektsioon assesses these holistically; a weakness in any one area can delay or defeat an otherwise sound application.

2.1 Legal entity & management substance

Applicants must operate through an Estonian legal entity, typically a private limited company (osaühing, OÜ) or public limited company (aktsiaselts, AS). MiCA requires CASPs to have at least one director resident in the EU and genuine substance in the authorising Member State, including effective management and decision‑making in Estonia. Shell structures with purely nominal local presence will not satisfy the substance test. Expect scrutiny of where directors are resident and where day‑to‑day operational control actually sits.

2.2 Fit & proper criteria

Directors, senior managers and significant shareholders (qualifying holdings) must meet fit‑and‑proper standards: relevant competence, sound financial standing and a clean regulatory and criminal record. Finantsinspektsioon reviews CVs, criminal‑record certificates and declarations of interests. Any history of regulatory sanction, insolvency or financial crime must be disclosed and will be weighed against the application.

2.3 AML/CTF preconditions

Anti‑money‑laundering and counter‑terrorist‑financing readiness is a precondition, not an afterthought. Applicants must demonstrate an AML/CTF framework aligned with FATF Recommendations and Estonian law, with reporting lines to the Estonian Financial Intelligence Unit. A nominated money laundering reporting officer (MLRO) and a documented, risk‑based KYC program must be in place before authorisation is granted.

3. Step‑by‑Step Licensing Roadmap for Your Crypto Business Structure Estonia Project

The following eight steps form the operational heart of any crypto business structure Estonia project. They apply whether you pursue Route A, a single CASP authorisation covering exchange and custody (and permitted ancillary payment flows), or Route B, a split structure combining an Electronic Money Institution (EMI) or payment institution for fiat/crypto payments with a CASP or third‑party custodian for exchange and custody.

3.1 Step 1: Decide business model & licence mix (CASP vs EMI + third‑party custody)

Begin by mapping each service you intend to offer to its regulatory category:

  1. List every product line, spot exchange, order‑book trading, custodial wallets, fiat on/off‑ramps, crypto payment processing.
  2. Classify each against MiCA’s list of crypto‑asset services and against payments/e‑money definitions.
  3. Choose Route A (single CASP) where custody and exchange dominate and fiat payment volumes are incidental, or Route B (EMI + CASP/third‑party custody) where fiat payment rails are a core product.
  4. Document the decision and rationale, this becomes the spine of your application narrative.

This decision drives capital, governance and banking strategy, so resolve it with counsel before any filing. Our supporting guide, Choosing Between Estonian CASP vs EMI + Third‑party Custody, explores the trade‑offs in detail.

3.2 Step 2: Entity formation & capital plan

With the model fixed, incorporate and capitalise:

  1. Incorporate the Estonian OÜ or AS and register the shareholder structure.
  2. Establish the governance bodies (management board; supervisory board where required).
  3. Build a capital plan that meets the applicable minimum for the chosen licence(s) plus an operating buffer.
  4. Arrange evidenced funding, bank statements or escrow confirming the initial capital is paid in.

Setting up a crypto company in Estonia is procedurally straightforward; the regulatory capital and substance requirements are the demanding part.

3.3 Step 3: Draft governance, AML/KYC program & policies

Assemble the compliance core that Finantsinspektsioon will interrogate:

  1. Draft the AML/CTF policy, risk assessment and transaction‑monitoring methodology to FATF and Estonian FIU standards.
  2. Appoint the MLRO and compliance officer and document their authority.
  3. Write governance, conflicts‑of‑interest, outsourcing, complaints and business‑continuity policies.
  4. Define client‑asset segregation and custody governance aligned to MiCA.

3.4 Step 4: Prepare financial projections & IT/security architecture

Regulators expect evidence that the business is both viable and secure:

  1. Produce multi‑year financial projections with a revenue model per product and stress scenarios.
  2. Document the IT and security architecture, including key‑management, cold/hot wallet design and data protection mapping.
  3. Commission a penetration‑testing plan and controls documentation.
  4. Map the asset‑flow and settlement processes end to end.

3.5 Step 5: Apply to Finantsinspektsioon / submit the CASP application

Submission is a single, consolidated event, fragmented filings invite delay:

  1. Compile the full application pack against the Finantsinspektsioon requirements (see the Required Documents section below).
  2. Ensure every policy, projection and CV is internally consistent, reviewers cross‑check narrative against evidence.
  3. Submit the application and formally log the acknowledgement of receipt.
  4. Manage the regulator’s request‑for‑information cycle promptly; slow or incomplete responses are the single biggest cause of extended timelines.
  5. Where pursuing Route B, coordinate the CASP and EMI applications so capital and governance narratives align.

A CASP authorisation in Estonia is granted only once Finantsinspektsioon is satisfied on substance, capital, governance and security. Under MiCA, the authority assesses completeness and then conducts its substantive review within the statutory periods set out in the Regulation, treat the review as an iterative dialogue.

3.6 Step 6: Concurrent AML arrangements & bank/EMI onboarding

Run these workstreams in parallel with the licence review to compress time‑to‑market:

  1. Finalise AML processes and establish reporting channels with the Estonian FIU.
  2. Open banking relationships and payment rails; prepare for enhanced due diligence on a crypto applicant.
  3. For Route B, progress EMI onboarding and safeguarding‑account arrangements for client funds.

3.7 Step 7: Pre‑licence testing, audits & go‑live compliance traps

Before go‑live, validate that controls work in practice, not just on paper:

  1. Execute penetration tests and remediate findings.
  2. Run an external audit or independent review of AML and custody controls.
  3. Test the client‑onboarding, transaction‑monitoring and segregation flows with live‑like data.
  4. Confirm insurance (cyber and professional indemnity) is bound before accepting client assets.

3.8 Step 8: MiCA passporting & EU market access

Once authorised, prepare for EU‑wide reach:

  1. Identify target Member States for passported services.
  2. Assemble the MiCA passporting notification pack for Finantsinspektsioon to transmit to host authorities.
  3. Confirm compliance with any host‑state conduct requirements that overlay the MiCA passport.

Step / Who / Duration timeline

Step (number & name) Who (owner / responsible) Typical duration
3.1 Decide model & licence mix Founders + external counsel + Head of Compliance 1–2 weeks
3.2 Entity formation & capital plan Company secretary / corporate counsel 2–4 weeks
3.3 Governance & AML policies drafting Head of Compliance + external AML counsel 3–6 weeks
3.4 Financials & IT/security design CFO + CTO + external auditors 4–8 weeks
3.5 Submit licence application (Finantsinspektsioon) CEO/Legal + external counsel Subject to MiCA statutory review periods
3.6 AML arrangements & bank onboarding Compliance + banking partner 8–16 weeks (parallel)
3.7 Pre‑licence testing & audits External auditors / security testers 4–8 weeks
3.8 MiCA passporting prep Legal + compliance 6–12 weeks (post‑licence)

Note: under MiCA, the competent authority generally assesses whether an application is complete within a short initial window and then takes a substantive decision within a fixed statutory period. Confirm the exact current timelines with Finantsinspektsioon, as processing in practice can be longer depending on completeness and information requests.

4. Required Documents

A complete, well‑formatted document pack is the difference between a smooth review and months of remediation. Prepare a single master checklist mapped to each licence type (CASP, custody, EMI/payments), with documents translated into English or Estonian and notarised or apostilled where they originate outside the EU. Where capital evidence is required, use recent dated bank statements or escrow confirmations.

4.1 Documents for the CASP application

The CASP pack is built around the business plan, governance and AML framework, management fit‑and‑proper evidence, IT/security documentation and proof of capital, all cross‑referenced to the service list you intend to offer.

4.2 Documents for custody activities

Custody and administration of crypto‑assets demand additional emphasis on asset‑segregation design, sub‑custodian and outsourcing agreements, penetration‑test reports and insurance covering custodial risk.

4.3 Documents for EMI / crypto payments

Where pursuing an EMI or payment route, add safeguarding arrangements for client funds, settlement flowcharts and the governance specific to e‑money issuance and payment processing.

4.4 Tips for evidence of capital and bank statements

Ensure capital evidence is recent, in the entity’s name, and clearly traceable. Mismatches between the capital shown in projections and the capital evidenced in bank documents are a common trigger for regulator queries.

Document Applies to Notes / formatting
Company certificate (commercial register extract) All Certified electronic extract; recent
Memorandum & Articles / shareholder register All Translated to EN/EE; notarised copies if outside EU
Business plan & financial projections All Revenue model per product; stress tests
AML/KYC policy & transaction‑monitoring description CASP / Custody / EMI Must meet FATF + Estonian FIU expectations
Management CVs & fit‑and‑proper statements All Apostilled copies; criminal‑record checks
Proof of initial capital (bank statements/escrow) CASP / EMI Evidence of required minimum capital
IT/security architecture & pen‑test reports CASP / Custody Include penetration test plan and data‑protection map
Outsourcing & custody agreements Custody / EMI Include SLA, sub‑custodian terms
Insurance certificates (cyber & PI) All Include limits & underwriter info
Internal controls & audit plan All Board minutes approving controls
Client T&Cs, custody agreements, settlement flowcharts CASP / Custody Clear onboarding & asset‑flow diagrams
Proof of address & ID for directors/owners All For AML & fit‑and‑proper checks

For a deeper breakdown, see Checklist: Documents & Capital Requirements for Each Estonian Crypto Licence.

5. Timeline & Deadlines

MiCA’s rules for CASPs became applicable across the EU from 30 December 2024. The Regulation permits Member States to grant entities that lawfully provided crypto‑asset services before that date a transitional (“grandfathering”) period during which they may continue operating while seeking authorisation. Estonia has set a national transitional window that ends in 2026; operators requiring CASP authorisation must be licensed by the close of that window or stop providing the regulated service. Because the exact end date and scope of transitional measures are set by national law and may be subject to change, confirm the current deadline directly with Finantsinspektsioon.

5.1 Key regulatory deadlines (MiCA + Estonia timeline)

Unlicensed operators should treat the deadline as immediate: begin entity, capital and compliance preparation now, because the application review runs under MiCA’s statutory periods, and parallel banking and AML onboarding can extend total time‑to‑market to several months. Where transitional measures apply under national law, confirm their exact scope with Finantsinspektsioon rather than assuming a grace period.

5.2 Recommended project plan with milestones

Build backwards from the deadline. Allow 2–4 weeks for incorporation, 3–6 weeks for policy drafting, 4–8 weeks for financials and security design, and a realistic contingency for regulator interaction within the statutory review framework. Running AML and bank onboarding in parallel from week one is the single most effective schedule compression available.

6. Costs / Fees

Budgeting for a crypto business structure Estonia project requires separating one‑off setup costs from recurring operational obligations. Application and supervision fees are modest relative to the dominant cost drivers: regulatory capital, legal and compliance build, and IT/security engineering. The ranges below are indicative planning estimates only; confirm the applicable statutory minimum capital and the current fee schedule with Finantsinspektsioon before finalising budgets.

Cost item Indicative range (EUR) Notes
Regulator application / processing fee Per current FI schedule Confirm with Finantsinspektsioon
Required minimum capital (MiCA) Set by MiCA per service class Depends on crypto‑asset services provided
Legal & consultancy (application prep) 15,000 – 80,000 Drafting, submission, remediation, responses
AML/compliance set‑up 10,000 – 60,000 Systems, KYC provider integration
IT/security (development & pen tests) 20,000 – 200,000 Depends on exchange scale & custody security
Bank onboarding / payment rails 5,000 – 50,000 Banking fees, due diligence costs
Annual regulatory & audit costs 10,000 – 100,000 External audit, regulatory reporting
Insurance (cyber / PI) 5,000 – 100,000/year Depends on risk exposure & limits

On capital: MiCA sets minimum own‑funds requirements for CASPs by reference to the category of services provided (with higher thresholds for custody and for operating a trading platform than for reception/transmission of orders or advice), measured as the higher of the fixed minimum or a proportion of fixed overheads. Verify the exact figure for your service class against the text of MiCA and current guidance.

7. What Changes in 2026 (MiCA / CASP Transition)

The 2026 transition moves Estonia from its national VASP‑registration model to full MiCA authorisation administered by Finantsinspektsioon. The practical consequences for a multi‑service operator are substantial: mandatory CASP licensing by the applicable national deadline; clearer own‑funds requirements; prescriptive conduct, disclosure and governance obligations; and reinforced client‑asset segregation and custody standards. In return, authorised CASPs gain a MiCA passport enabling cross‑border provision of services across the EU.

7.1 CASP transition checklist for operators

  • Confirm your service classification. Map each product to a MiCA crypto‑asset service.
  • Assess your capital gap. Compare current capital against the MiCA own‑funds requirement for your service mix.
  • Upgrade custody controls. Implement segregation, key‑management and insurance to MiCA standards.
  • Refresh governance and AML. Align policies with MiCA conduct rules and FATF standards.

7.2 Immediate tasks for incumbents & new entrants

Incumbents operating under the former registration should begin their CASP application immediately, treating continuity of service as contingent on timely authorisation within the transitional window. New entrants should design the structure MiCA‑native from day one, avoiding the cost of retrofitting controls. Estonian crypto compliance under the new regime is materially more demanding than the pre‑MiCA baseline, and early movers will secure banking and passporting advantages ahead of the deadline crush.

8. Common Pitfalls & Risk Mitigation

Most application failures are avoidable. They cluster around documentation gaps, weak AML design and operational separation issues that only surface under regulator scrutiny.

8.1 Application pitfalls

  • Incomplete or inconsistent packs. Narrative that contradicts the evidence triggers repeated information requests.
  • Weak AML frameworks. Generic policies not tailored to the actual risk profile are routinely rejected.
  • Thin substance. Nominal management presence fails MiCA’s substance expectations.

8.2 Operational pitfalls

  • Banking failure. Underestimating the difficulty of securing crypto‑friendly banking can stall go‑live.
  • Custody separation. Blurred client‑asset segregation breaches MiCA custody obligations.
  • Insurance gaps. Accepting client assets before cyber and professional‑indemnity cover is bound creates acute exposure.

8.3 Enforcement risks & remediation plans

  • Operating unlicensed past the deadline. Continuing regulated activity without authorisation invites enforcement and reputational damage.
  • Reporting failures. Missed FIU reporting obligations attract supervisory attention, maintain a documented remediation and escalation plan.

The Post‑licence Compliance Calendar for Estonian CASPs sets out the recurring obligations that keep an authorised business in good standing.

Comparison: Single CASP vs EMI + Third‑party Custody

Feature Single CASP licence (exchange + custody) EMI + third‑party custody (split route)
Regulatory scope Single authorisation under MiCA for crypto services EMI covers fiat payments; custody via licensed CASP or third‑party custodian
Time to market Potentially faster if CASP covers all activities Faster for payments (EMI) but requires custody partner
Capital required Higher single own‑funds requirement Split capital, EMI + custodian capital
Control over custody Full control (requires strong security & insurance) Less control; reliance on custodian SLAs
Passporting CASP passport under MiCA for crypto services EMI and CASP passporting separate; coordination needed
Bank relationships May be easier with unified compliance May ease banking for fiat via EMI relationships

Conclusion

Building a sound crypto business structure Estonia in 2026 is a disciplined, sequential exercise: classify your services, choose between a single CASP authorisation and a split EMI‑plus‑custody route, incorporate with genuine substance, build an AML and custody framework that meets MiCA and FATF standards, and submit a complete, consistent application to Finantsinspektsioon well ahead of the national transitional deadline. The operators who treat this as a structured project, with parallel banking and AML workstreams and a realistic multi‑month runway, will emerge authorised, passportable and positioned to consolidate a multi‑service offering across the EU. For a bespoke structuring assessment tailored to your product mix, speak with a qualified Estonian crypto specialist before you file.

For related guidance, see Cryptocurrency & Blockchain, Estonia (practice area overview) and Find Estonian crypto lawyers, GLE directory.

This article is general information and not legal advice. Regulatory requirements change; confirm current rules with the named sources and obtain tailored counsel before acting.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Yuliya Barabash at SBSB Fintech Lawyers, a member of the Global Law Experts network.

Sources

  1. Markets in Crypto‑Assets (MiCA), EU Regulation 2023/1114 (EUR‑Lex)
  2. Estonian Financial Supervision Authority (Finantsinspektsioon)
  3. Riigi Teataja (Estonian State Gazette)
  4. Estonian Financial Intelligence Unit (Rahapesu Andmebüroo)
  5. Estonian Tax and Customs Board (EMTA)
  6. FATF, Recommendations & Guidance on Virtual Assets
  7. European Banking Authority (EBA)
  8. European Securities and Markets Authority (ESMA), MiCA
  9. Eesti Pank (Bank of Estonia), Payments Oversight

FAQs

What licences do I need to run an exchange, custody and crypto payments service in Estonia?
Either a comprehensive CASP authorisation covering exchange and custody where those activities fall within MiCA’s crypto‑asset service definitions, and possibly an EMI or payment‑institution licence for fiat payments; or a split route combining an EMI for payments with a CASP (or outsourced custody) for exchange and custody. The right mix depends on which services are core versus incidental, resolve this at Step 1.
MiCA’s CASP rules have applied across the EU since 30 December 2024, with a national transitional period in Estonia running into 2026 for firms that operated lawfully before MiCA applied. Operators must hold authorisation from Finantsinspektsioon by the close of that transitional window or cease services that require licensing. Confirm the precise end date and scope of national transitional measures directly with the regulator.
MiCA sets statutory periods for the competent authority to assess completeness and then take a substantive decision. In practice, realistic time‑to‑market, including concurrent AML and bank onboarding, is often several months, so start early. Confirm current processing times with Finantsinspektsioon.
MiCA sets minimum own‑funds requirements by reference to the category of crypto‑asset services provided, with higher thresholds for custody and trading‑platform operation than for simpler services. Always verify the exact figure for your specific service mix against the text of MiCA and hold an operating buffer above the minimum.
MiCA requires segregation of client crypto‑assets from the provider’s own assets and imposes elevated custody standards, including governance, IT/security and liability expectations. Custody providers must evidence robust key‑management and asset‑protection controls before accepting client assets.
Estonia applies its distinctive corporate income tax model, under which retained and reinvested company profits are generally not taxed until distributed. Crypto transactions are treated per Estonian Tax and Customs Board (Maksu‑ ja Tolliamet, EMTA) guidance, and individual tax treatment follows national rules. Consult EMTA guidance and tax counsel for your specific facts.
Yes. Under MiCA, an authorised CASP can provide services across the EU subject to notification through Finantsinspektsioon and compliance with applicable host‑state rules. Prepare the passporting notification pack after authorisation is granted.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Structure a Multi‑service Crypto Business in Estonia (2026), Licensing Roadmap for Exchanges, Custody & Payments

Send welcome message

Custom Message