[codicts-css-switcher id=”346″]

Global Law Experts Logo
crypto custody licence estonia

How to Obtain an Estonian Crypto Custody Licence (CASP) in 2026: Requirements, Safeguarding & Timeline

By Global Law Experts
– posted 1 hour ago

A crypto custody licence estonia application is now one of the most consequential regulatory decisions a digital-asset business can make in the European Union, and the clock is running toward the 1 July 2026 transition deadline under the Markets in Crypto-Assets Regulation (MiCA). From that date, firms that safekeep or administer crypto-assets for third parties must hold authorisation as a Crypto-Asset Service Provider (CASP) to continue operating lawfully. This guide sets out, in practical and sequential terms, what a custody applicant in Estonia must prepare, the eligibility and capital thresholds, the safeguarding models regulators expect, the anti-money-laundering (AML) and DAC8 tax-reporting obligations, and a realistic application timeline.

It is written for founders, chief operating officers, heads of compliance and in-house counsel who are comparing EU bases and building a submission-ready file.

  • What you’ll learn. How custody sits within CASP scope under MiCA and when a licence is genuinely required.
  • How to prepare. The corporate, capital, safeguarding and AML documentation a regulator expects before you apply.
  • How long it takes. A realistic 2026 timeline covering preparation, review and post-licence supervision.

This article is general information, not legal advice. Regulatory requirements evolve; verify current provisions against the primary sources cited before acting.

What is a CASP custody licence and why choose Estonia?

Definition: CASP and custody services

Under MiCA (Regulation (EU) 2023/1114), a Crypto-Asset Service Provider is a legal person or undertaking authorised to provide one or more crypto-asset services on a professional basis. Custody sits within that framework as the “custody and administration of crypto-assets on behalf of clients”, meaning the safekeeping or controlling of crypto-assets, or the means of access to them (typically private keys), for a third party. In practice this covers hosted wallet services, institutional safekeeping, and the administration functions that accompany holding assets for clients, such as recording positions, processing transfers and enabling clients to exercise rights attached to their assets.

A CASP custody licence is therefore distinct from mere technology provision: the defining feature is that the provider holds or controls client assets, and consequently bears liability for their loss.

Why Estonia?

Estonia built an early reputation as a fintech-forward jurisdiction, with a fully digital company registry, e-residency infrastructure and a supervisory authority, the Financial Supervision and Resolution Authority (Finantsinspektsioon), that engages substantively with applicants. Filings and correspondence can, in practice, often be conducted in English, which shortens the practical distance for international teams. The Ministry of Finance has driven a structured national implementation of MiCA, and the regulator has published guidance on supervisory expectations for financial-service providers. For a business seeking a crypto custody licence estonia offers, the attractions are a mature digital state, comparatively efficient processing where an application is genuinely complete, and a legal environment that has hosted virtual-asset service providers for years.

The trade-off is rigour: Estonia tightened its AML regime substantially after earlier enforcement experience, so applicants should expect close scrutiny of substance, governance and safeguarding rather than a light-touch pathway.

CASP transition and key dates for 2026

1 July 2026 transition, what changes in practice

MiCA’s provisions on crypto-asset services became applicable across the EU from 30 December 2024, but the regulation permits member states to grant a transitional period allowing existing providers to continue operating under prior national regimes while they seek CASP authorisation. Estonia has set its transitional window to end on 1 July 2026. From that date, a firm providing custody must hold a CASP licence, or be validly relying on the transitional provisions with an authorisation in progress, to continue serving clients. After the deadline, continuing to safekeep client crypto-assets without authorisation exposes the business to enforcement, the winding-down of client-facing activity, and potential exposure for directors.

The practical effect, industry observers expect, is a compression of applications into the first half of 2026 and a corresponding lengthening of regulator review times for those who file late. Confirm the precise wording and end date of the transitional provisions with the regulator, as national arrangements can be adjusted.

Pre-transition milestones, what to file and when

Because a custody application is document-heavy, working backwards from 1 July 2026 is essential. A realistic sequence is: finalise corporate structuring and capital injection well before submission; complete fit-and-proper documentation and safeguarding evidence in parallel; and lodge a complete application with enough lead time for the regulator’s assessment period and any request for further information. Firms that already operate under Estonia’s prior virtual-asset regime should confirm precisely how the transitional provisions apply to them and whether their existing registration allows continuity while the CASP file is assessed. Those relocating from other jurisdictions should not assume the deadline leaves ample runway, a partial or deficient file does not stop the clock.

Do you need a CASP licence to offer custody in Estonia? Scope and exemptions

Which activities require a crypto custody licence estonia authorisation

The test is control. If your business holds crypto-assets belonging to clients, or holds the means of access to those assets, most commonly the private keys, on their behalf, you are almost certainly providing custody and administration within CASP scope and require authorisation. This captures:

  • Hosted (custodial) wallets. Where you generate, store or control keys for users and can move assets on their instruction.
  • Institutional safekeeping. Cold-storage services for funds, exchanges or corporates where you hold assets as custodian.
  • Exchange-integrated custody. Where a trading venue also holds client balances between trades.
  • Administration functions. Position-keeping, transfer processing and enabling clients to exercise asset rights, performed alongside safekeeping.

Common exemptions and borderline activities

Not every wallet or key-related service is custody. The clearest distinction is between custodial provision, where you hold client assets, and purely technical or non-custodial provision, where the user retains sole control of their keys. A genuinely non-custodial (self-custody) wallet, where the software never gives the provider the ability to access or move client assets, falls outside custody as a service, because there is no safekeeping on behalf of the client. Similarly, providing infrastructure, node access or software licences without ever holding client assets is generally technology provision rather than a regulated crypto-asset service. Borderline cases include multi-signature arrangements where the provider holds one of several keys, and “MPC” (multi-party computation) set-ups where key shares are distributed.

Whether these amount to custody depends on whether the provider, alone or in combination, can control the movement of client assets.

  • Can we, technically, move or block a client’s assets without the client’s cooperation?
  • Do we hold, generate or store any key material that grants access to client assets?
  • Do we owe the client a return or restitution obligation for their specific assets?

An affirmative answer to any of these points strongly toward custody and the need for a CASP licence. Classification is fact-specific and should be documented and, where marginal, taken with legal advice.

Eligibility, corporate and ownership requirements

Legal form and local presence

A CASP must be a legal person or other undertaking with a registered office in the member state where it seeks authorisation, and must have its place of effective management in the EU. For Estonia, this ordinarily means an Estonian company (typically an osaühing, a private limited company) with genuine local substance, a registered office, resident or accessible management, and operational decision-making conducted from Estonia rather than a nameplate. Regulators across the EU, and Finantsinspektsioon in particular, scrutinise “letterbox” structures. Applicants should expect to demonstrate that key functions, risk, compliance, AML, are performed by people with real presence and authority, not outsourced away to the point that Estonia is merely a flag of convenience.

At least one director should be resident in the EU.

Fit and proper requirements for management and beneficial owners

Members of the management body and beneficial owners holding qualifying stakes must satisfy fit-and-proper standards: good repute, absence of relevant criminal convictions, sufficient knowledge and experience, and adequate time to perform their functions. The regulator assesses both individual competence and the collective suitability of the board to run a custody business safely. Expect to provide, for each relevant individual:

  • Detailed curricula vitae evidencing crypto, financial-services or custody experience;
  • Criminal-record extracts (police clearance) from relevant jurisdictions;
  • Declarations of interests, other directorships and any past regulatory or insolvency history;
  • Evidence of beneficial ownership and the group structure up to the ultimate owners.

Minimum capital and prudential thresholds

MiCA sets prudential requirements for CASPs calibrated to the services provided, expressed as a minimum capital floor and an alternative measure based on a proportion of fixed overheads, with own funds being at least the higher of the two. Custody and administration falls within a defined minimum-capital tier under MiCA’s prudential schedule (Annex IV), and firms must also hold own funds at least equal to one quarter of the prior year’s fixed overheads. Applicants should model both measures, evidence the capital with bank statements or an auditor’s confirmation, and present financial projections showing the firm can maintain own funds through its early trading period.

Confirm the applicable figures against the current MiCA text, as the tiers are set at EU level. Because custody carries direct liability for client-asset loss, regulators pay particular attention to the adequacy of capital relative to the value of assets under custody and the firm’s insurance and reserve arrangements.

Safeguarding client assets: models, controls and minimum standards

Safeguarding is the heart of a custody authorisation: the entire licence exists to protect client assets, and the regulator’s central question is whether client crypto-assets are held so that they can always be identified, segregated and returned.

Custody models: segregated wallets, multi-sig, cold/hot split and qualified custodian

MiCA requires custodians to hold client crypto-assets segregated from their own and to maintain a register of positions per client. In practice, custodians combine several models. Segregated wallet architectures assign identifiable holdings to clients, either through dedicated on-chain addresses or through robust internal ledgering reconciled to on-chain balances. A cold/hot split keeps the bulk of assets in offline “cold” storage disconnected from the internet, with a limited “hot” tranche online to service withdrawals. Multi-signature schemes require several independent keys to authorise a movement, removing single points of failure. Some firms adopt a qualified sub-custodian model, placing assets with a specialist custodian while retaining the client relationship, which shifts, but does not eliminate, safeguarding responsibility.

Technical measures: key management, HSMs, MPC, backup and recovery

Key management is the technical core. Regulators expect documented policies covering key generation, storage, use and destruction. Hardware Security Modules (HSMs), tamper-resistant devices that generate and hold keys, and MPC (multi-party computation, where a key is split into shares so no single party ever holds the whole key) are both widely accepted approaches. Whatever the design, the applicant must evidence secure backup and disaster-recovery procedures so that client assets can be reconstituted after loss of a facility, device or individual, and must ensure that no single employee can unilaterally access client assets.

Operational controls: segregation of duties, reconciliation and incident response

Technical strength must be matched by operational discipline. Expect the regulator to test for segregation of duties (so that initiation, approval and settlement of transfers involve different people), regular and independent reconciliation of internal records to on-chain balances, and a documented incident-response plan covering key compromise, theft, and outage. Audit logs, change-management records and evidence of periodic penetration testing are the kind of assurance material regulators ask to see.

Legal and contractual measures: custody agreements, sub-custodians and insurance

Custody agreements should clearly define the custodian’s obligations, the client’s rights of restitution, the treatment of assets on insolvency, and the terms on which any sub-custodian is used. Where sub-custodians are engaged, the firm should conduct and document due diligence and retain oversight. Insurance covering theft and loss of keys, while not always mandatory, is strong supporting evidence of a credible safeguarding posture. Note that under MiCA a custodian is liable to its clients for the loss of crypto-assets or the means of access resulting from an incident attributable to it.

Safeguarding model Pros Cons Typical documentation required
Segregated cold storage Strong protection against remote theft; clear client segregation Slower withdrawals; operational overhead Key-management policy, cold-storage procedures, reconciliation logs
Multi-signature No single point of failure; distributed control Complex key ceremony; recovery risk if signers lost Signer register, quorum policy, key-recovery plan
MPC / HSM-based No single whole key exists; hardware-grade protection Vendor dependency; technical assurance burden HSM certifications, MPC design docs, penetration-test summaries
Qualified sub-custodian Leverages specialist infrastructure; faster to market Residual liability; counterparty and oversight risk Sub-custody agreement, due-diligence file, oversight procedures

AML, KYC and compliance programme for Estonian CASPs

Customer due diligence and onboarding

Estonian CASPs are obliged entities under the national Money Laundering and Terrorist Financing Prevention Act, which transposes the EU AML framework. Onboarding must apply risk-based customer due diligence (CDD): identifying and verifying the customer and any beneficial owner, understanding the purpose and intended nature of the relationship, and screening against sanctions and politically-exposed-person (PEP) lists. Enhanced due diligence applies to higher-risk relationships. For custody clients, the firm should also understand the source of the assets it will safekeep.

Ongoing transaction monitoring and suspicious reporting

The compliance obligation does not end at onboarding. Custodians must monitor activity on an ongoing basis, calibrating alerts to the customer’s risk profile and expected behaviour, and applying blockchain-analytics tooling appropriate to crypto flows. Where a transaction or pattern gives rise to a suspicion of money laundering or terrorist financing, the firm must file a suspicious-transaction report with Estonia’s Financial Intelligence Unit without undue delay, and must not tip off the customer. Sanctions screening must be continuous, not merely at onboarding, so that newly listed parties are caught. FATF’s recommendations and virtual-asset guidance are the international benchmark against which these controls are assessed.

Internal AML policies, officer appointment and training

A CASP must maintain written AML/CFT policies and procedures, appoint a designated compliance officer (often referred to as an MLRO) of sufficient seniority and independence, and deliver regular staff training. The board bears ultimate responsibility for the AML programme’s effectiveness. Regulators expect the AML function to have real authority, the ability to block onboarding, freeze activity and escalate, rather than a nominal appointment.

Record keeping and regulator reporting

Firms must retain CDD records, transaction data and reporting evidence for the statutory retention period and produce them to the regulator or FIU on request. Periodic regulatory returns and ad-hoc notifications form part of the ongoing relationship with Finantsinspektsioon.

DAC8 and tax reporting obligations for custodians in Estonia

What DAC8 requires from crypto custodians

DAC8 (Council Directive (EU) 2023/2226) is the eighth amendment to the EU Directive on Administrative Cooperation. It extends the automatic exchange of information between member states’ tax authorities to crypto-assets, obliging reporting crypto-asset service providers, a category that captures custodians serving EU-resident clients, to collect and report information on reportable users and their crypto-asset transactions. In substance, custody providers become tax-reporting intermediaries: they must identify the tax residence of their users, collect taxpayer identification numbers, and report defined transaction data so that it can be exchanged cross-border. Most of DAC8’s crypto-asset reporting rules are due to apply from 1 January 2026. DAC8 aligns with the OECD’s Crypto-Asset Reporting Framework, meaning the data model is broadly consistent internationally.

Practical implementation: data collection, systems and timelines

The operational overlap between AML onboarding and DAC8 is significant, which is why the two should be designed together. Practical steps include extending onboarding to capture tax-residence self-certifications and taxpayer identification numbers; building systems that record reportable transactions with the required fields; validating self-certifications against onboarding data; and establishing an annual reporting workflow to the Estonian Tax and Customs Board. Sample data fields to capture from the outset include user identity and residence, TIN, wallet identifiers, and the type, value and counterparty category of reportable transactions. Building this into onboarding before launch is far cheaper than retrofitting it, and early indications suggest regulators will expect reporting readiness rather than remediation after the fact.

Application process and realistic timeline

Pre-application checklist and documentation pack

A CASP custody application is only as fast as its weakest document. Assemble, before submission:

  1. Corporate documents: registration, articles, group structure and beneficial-ownership evidence;
  2. A programme of operations describing the custody services and business model;
  3. Fit-and-proper files for management and qualifying owners (CVs, police clearances, declarations);
  4. Proof of capital and financial projections demonstrating ongoing own-funds compliance;
  5. The safeguarding package: custody model, key-management policy, technical assurance and reconciliation procedures;
  6. The AML/CFT policy suite, compliance-officer appointment and training plan;
  7. Governance, risk, business-continuity and complaints-handling policies;
  8. DAC8 and tax-reporting readiness documentation.

Submission, review, on-site checks and expected decision timeline

After a complete submission, the regulator assesses completeness, then substantively reviews the file, typically issuing requests for further information. Under MiCA, the competent authority assesses completeness within a set number of working days and then has a defined period (of the order of a few months) to reach a reasoned decision once the application is complete; verify the exact statutory periods in the MiCA text. Custody applications frequently attract questions on safeguarding architecture and AML calibration. On-site or remote readiness checks may follow.

A realistic total, where the applicant arrives with a genuinely complete and coherent file, is broadly in the region of several months from lodgement to decision, with preparation of the pack itself commonly taking a number of weeks beforehand. The most common causes of delay are incomplete fit-and-proper files, thin safeguarding evidence, weak local substance, and AML policies that read as templates rather than as controls tailored to the specific business. Filing close to the 1 July 2026 deadline compounds these risks, because review capacity is finite.

Post-licence obligations and inspections

Ongoing capital, reporting, audits and supervisory contact

Authorisation is the beginning of supervision, not the end of the process. A licensed custodian must maintain its own-funds and prudential position continuously, submit periodic regulatory returns, undergo external audit where required, and notify the regulator promptly of material changes, to ownership, management, business model, safeguarding arrangements or serious incidents such as a security breach or loss of client assets. Finantsinspektsioon may conduct thematic or targeted inspections, and custody, given its client-asset exposure, is a natural focus. Firms should maintain audit-ready evidence of segregation, reconciliation and key management at all times, on the assumption that they may be asked to demonstrate it without notice.

Practical risks and mitigation when choosing Estonia

Operational risk, regulatory enforcement and bank access

Three risks deserve candid attention. First, operational and security risk: custody businesses are theft targets, and a single key-management failure can be existential, mitigate with defence-in-depth, insurance and rehearsed incident response. Second, regulatory-enforcement risk: Estonia’s post-tightening stance means substance and AML rigour are non-negotiable, mitigate with genuine local presence and a well-resourced compliance function. Third, banking access: securing crypto-friendly banking remains selective across the EU, Estonia included, mitigate by engaging banking partners early and presenting a mature compliance story. For guidance on this last point, see the GLE resource on opening a crypto bank account in Estonia, which addresses the practicalities that custodians commonly encounter.

Comparison: crypto custody licence estonia vs alternative EU bases

MiCA harmonises the substantive requirements across the EU, so the licence itself is portable via passporting once granted. The meaningful differences between bases lie in processing efficiency, supervisory posture, banking access and cost. The table below summarises the practical contrasts; verify current specifics against each national regulator before deciding.

Feature Estonia (CASP custody) Malta Lithuania
Typical licence timeframe Several months if fully prepared Several months Several months
AML rigour High, aligned with EU AML and national AML Act High High
Banking access (crypto-friendly) Selective but possible Historically more accessible Improving
Capital and prudential Per MiCA tier for custody (harmonised at EU level) Per MiCA tier (harmonised at EU level) Per MiCA tier (harmonised at EU level)
2026 MiCA transition readiness Clear national guidance; active regulator Active regulator engagement Active regulator engagement

Because prudential capital and the core authorisation conditions derive from MiCA itself, the substantive requirements are broadly equivalent across EU member states; the differences are largely practical rather than legal. For a business weighing exchange versus custody scope, or comparing Estonian pathways directly, the related Global Law Experts resources on Estonian crypto licensing provide adjacent context. The right base depends on where your substance, banking relationships and passporting priorities align.

Next steps: how to prepare your application pack

Founders and compliance teams should treat the run-up to 1 July 2026 as a project with a fixed deadline. Prioritise the items most likely to cause delay:

  • Confirm your service classification and document why custody applies (or does not);
  • Incorporate or restructure the Estonian entity and establish genuine local substance;
  • Inject and evidence capital; model ongoing own-funds compliance;
  • Complete fit-and-proper files, including police clearances, early, they take time;
  • Finalise the safeguarding architecture and gather technical assurance (audit logs, penetration tests, key-management statements);
  • Tailor the AML/CFT policy suite and appoint a credible compliance officer;
  • Build DAC8 and tax-reporting into onboarding from day one;
  • Engage banking partners in parallel, not after authorisation.

Conclusion

Securing a crypto custody licence estonia authorisation in 2026 is achievable, but it rewards early, disciplined preparation over last-minute filing. The 1 July 2026 transition deadline is a firm milestone, custody sits squarely within CASP scope under MiCA, and the areas regulators probe hardest, safeguarding of client assets, AML rigour, genuine local substance and DAC8 readiness, are precisely those that cannot be assembled overnight. Businesses that classify their services correctly, build a coherent documentation pack, and design safeguarding and reporting into their operations from the outset will move through authorisation fastest and supervise well thereafter.

For tailored support on structuring, safeguarding design and a submission-ready application, consult a specialist adviser and review the related Global Law Experts resources on Estonian crypto licensing and banking.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Yuliya Barabash at SBSB Fintech Lawyers, a member of the Global Law Experts network.

Sources

  1. Estonian Financial Supervision and Resolution Authority (Finantsinspektsioon)
  2. Estonian Ministry of Finance
  3. Riigi Teataja, Estonian State Gazette
  4. European Commission, Markets in Crypto-Assets (MiCA) overview
  5. EUR-Lex, MiCA Regulation (EU) 2023/1114 official text
  6. EUR-Lex, DAC8 (Council Directive (EU) 2023/2226)
  7. Financial Action Task Force (FATF), Recommendations and guidance
  8. European Banking Authority (EBA)
  9. European Securities and Markets Authority (ESMA)
  10. Estonian Tax and Customs Board

FAQs

What is the CASP transition deadline in Estonia in 2026?
Estonia has set its transitional window for existing crypto-asset service providers to end on 1 July 2026. By that date, custody providers must hold CASP authorisation, or be validly relying on the transitional provisions with an application in progress, to continue serving clients. Verify the exact wording of the transitional provisions in the MiCA text and Estonian regulator guidance for your specific situation.
If you provide custody or administration of crypto-assets for third parties, holding client assets or the keys that control them, you require a CASP licence. Narrow technical or genuinely non-custodial services, where the user retains sole control of their keys, may fall outside custody scope, but classification is fact-specific and should be documented.
MiCA requires segregation of client assets from the firm’s own, per-client position records, and secure key management. In practice regulators expect a documented custody model (often cold/hot split with multi-signature or MPC/HSM key management), independent reconciliation, incident response, clear custody agreements protecting client restitution rights, and appropriate insurance where available.
DAC8 extends automatic exchange of tax information to crypto-assets, with the crypto-asset reporting rules generally applying from 1 January 2026. As a reporting crypto-asset service provider, a custodian must identify users’ tax residence, collect taxpayer identification numbers, and report defined transaction data for cross-border exchange. Build these fields into onboarding alongside AML data to avoid costly retrofitting.
Preparing the documentation pack typically takes a number of weeks. Regulator review varies, but a realistic total from complete submission to decision is broadly in the region of several months where the file is coherent and the firm has genuine local substance. Late filing near the July 2026 deadline can extend timelines.
Outsourcing of certain functions is permitted, but responsibility remains with the licensed firm. Regulators expect documented oversight, due diligence on providers, and retention of core risk and compliance decision-making in-house. Over-outsourcing that hollows out local substance is a red flag.
The most common are incomplete fit-and-proper files, thin safeguarding evidence, weak local substance, and template-style AML policies not tailored to the business. Filing close to the deadline compounds delay because supervisory capacity is finite.
Yes. Because MiCA harmonises CASP authorisation, a licence granted in Estonia can be passported to provide services in other EU member states, subject to the applicable notification procedures. This is a core reason to select a base with efficient processing and workable banking access.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Obtain an Estonian Crypto Custody Licence (CASP) in 2026: Requirements, Safeguarding & Timeline

Send welcome message

Custom Message