Our Expert in Estonia
No results available
Crypto payment license estonia questions have become urgent for founders and finance leaders as 2026 arrives with the Markets in Crypto-Assets Regulation (MiCA) fully operational, DAC8 tax-reporting obligations approaching, and the Estonian supervisor sharpening its expectations of anti-money-laundering (AML) controls. The core question this guide answers is deceptively simple but commercially decisive: can a business holding an Estonian Payment Institution (PI) or Electronic Money Institution (EMI) authorisation lawfully process crypto payments, and, if so, under what conditions? This article is written for decision-makers evaluating licence structure, bank access and compliance design in Estonia, and it stays focused on that question rather than token design or tax mechanics.
Below you will find the legal framework, a licence comparison, AML and prudential hooks, practical bank-onboarding tactics and a step-by-step checklist for 2026 applications.
Who this is for: founders, CEOs, compliance heads and CFOs weighing whether to use an Estonian PI/EMI licence to run crypto payment rails in the EU in 2026.
What you will learn: whether a PI/EMI can lawfully process crypto payments, the trade-offs between a payment-services licence and a MiCA CASP authorisation, AML, capital and custody requirements, bank-onboarding tactics, and a practical compliance checklist.
Quick answer (TL;DR). The answer is a conditional yes. An Estonian PI or EMI can support certain crypto-adjacent payment flows, but where the activity involves custody, exchange, or the operation of a crypto-asset service, a separate MiCA Crypto-Asset Service Provider (CASP) authorisation is generally required. Classification depends on the asset type and the exact service. Read the Cryptocurrency Lawyer Estonia, checklist alongside this guide, and see the licence comparison table below.
For a jurisdiction-specific view of the licensing landscape, our author profile sets out the practitioner background behind this analysis. The remainder of this article walks through the 2026 legal baseline, the operational tests that determine which licence you need, and the compliance and banking work that separates a viable application from a rejected one.
Any assessment of whether a payment institution estonia entity can process crypto payments must sit on two layers: the national Estonian supervisory regime and the overarching EU rulebook. In 2026 these two layers interlock more tightly than at any previous point, and the interaction determines both what is permitted and what triggers additional authorisation.
Estonia’s principal financial regulator is the Financial Supervision Authority, the Finantsinspektsioon. It authorises and supervises payment institutions and electronic money institutions, sets application standards, reviews permitted-activity scopes, and monitors ongoing prudential and conduct compliance. Under MiCA, the Finantsinspektsioon is also the competent authority for CASP authorisation in Estonia. If your business wants to hold or extend a PI/EMI licence to touch crypto payment flows, the Finantsinspektsioon is the body that assesses whether your model fits within the payment-services perimeter or crosses into crypto-asset services requiring separate authorisation.
National AML supervision runs alongside financial supervision. The Estonian Financial Intelligence Unit (Rahapesu Andmebüroo) receives suspicious transaction reports and enforces the country’s AML obligations; the Estonian Police and Border Guard Board is the wider law-enforcement authority. Estonia’s core statute is the Money Laundering and Terrorist Financing Prevention Act, published on the official legislation portal Riigi Teataja. This Act sets out customer due diligence, risk-assessment, monitoring and reporting duties that apply to obliged entities, including payment firms whose activity touches crypto.
The EU baseline for a crypto payment license estonia decision starts with MiCA, the Markets in Crypto-Assets Regulation (Regulation (EU) 2023/1114). The full text is available on EUR-Lex, and the European Commission provides an accessible overview of its scope and objectives. MiCA defines the categories of crypto-assets and the list of crypto-asset services that require CASP authorisation, including custody, operation of a trading platform, exchange of crypto for funds or other crypto-assets, and the execution of orders on behalf of clients.
The payment-services layer, the second Payment Services Directive (PSD2) and the evolving successor framework proposed by the EU (a Payment Services Directive and Payment Services Regulation package), governs what a PI or EMI may do when handling funds and issuing electronic money. Where a service qualifies as a payment service or e-money issuance, the PI/EMI regime applies; where it qualifies as a crypto-asset service under MiCA, the CASP regime applies. The two frameworks are complementary but distinct, and a firm can hold both authorisations.
The third strand is reporting. DAC8 (Council Directive (EU) 2023/2226) extends automatic exchange-of-information rules to crypto-asset service providers, imposing tax-reporting and customer-identification obligations on in-scope operators, with reporting generally applying from 2026 onward. The European Banking Authority (EBA) supplements this with AML/CTF guidance that shapes how both crypto firms and their banks are expected to manage financial-crime risk.
MiCA is a directly applicable EU regulation, so its definitions and authorisation triggers apply uniformly across Estonia. Estonian national law continues to govern AML detail, prudential supervision of PIs/EMIs and the practical application procedures administered by the Finantsinspektsioon. The practical implications for a decision-maker are:
The central operational question is when a PI/EMI can lawfully support crypto payments and when a MiCA CASP authorisation becomes mandatory. The distinction turns on functional tests: what precisely does your platform do with the crypto-asset, and does it involve custody, exchange or the operation of a service that MiCA reserves to authorised CASPs?
A payment institution or EMI operates within the payment-services perimeter, executing payment transactions, issuing electronic money, and safeguarding client funds. There are models where a PI/EMI can sit alongside crypto flows without itself performing a MiCA-regulated crypto-asset service. Examples include:
The functional test is straightforward to state but demanding to apply: if your entity holds, controls, exchanges or administers the crypto-asset, you are likely inside the CASP perimeter. If your entity only ever touches funds and electronic money, the payment-services regime may suffice.
A CASP authorisation becomes mandatory where the activity is a crypto-asset service as defined in MiCA. The clearest triggers are:
Common borderline scenarios include stablecoin payment rails and fiat rails that integrate tokenised assets. A stablecoin classified as an e-money token under MiCA sits close to the e-money framework, whereas an asset-referenced token or an unbacked crypto-asset generally pulls the model firmly into CASP territory. These are precisely the cases where early legal classification prevents a costly restructuring later.
| Feature | Payment Institution / EMI | CASP (MiCA) | Hybrid (PI/EMI + CASP) |
|---|---|---|---|
| Regulator / licence | Finantsinspektsioon, PI or EMI authorisation under the payment-services regime | Finantsinspektsioon, CASP authorisation under MiCA | Both authorisations held by one or affiliated entities |
| Permitted activities | Payment services; e-money issuance; safeguarding of funds | Custody, exchange, trading-platform operation, order execution, transfer of crypto-assets | Full fiat + crypto payment stack under combined scope |
| Use for crypto payments | Conditional, fiat leg only; no custody/exchange of crypto | Yes, for the crypto-asset services in scope | Yes, end-to-end, subject to both rulebooks |
| AML reporting (national + DAC8) | Estonian AML Act obligations; STRs to the FIU | Estonian AML Act plus DAC8 crypto reporting | Combined AML and DAC8 obligations across both perimeters |
| Capital / safeguarding | Minimum own funds and safeguarding of client funds under the payment-services regime | MiCA prudential and custody requirements calibrated to services offered | Highest of the applicable requirements; parallel controls |
| Typical bank acceptance risk | Moderate, crypto exposure raises scrutiny | Elevated, banks apply enhanced due diligence to CASPs | Elevated, but transparent structure can improve confidence |
| Time and cost to obtain in Estonia (estimate) | Several months of preparation and review; costs driven by policy build-out and capital | Comparable-to-longer timeline given custody and prudential detail | Longest, two authorisation tracks and integrated controls |
Once you have settled the licence question, the compliance architecture determines whether the Finantsinspektsioon will accept your application and whether banks will onboard you. Three pillars matter: AML, custody/safeguarding, and capital.
Aml requirements crypto estonia obligations flow from the Money Laundering and Terrorist Financing Prevention Act on Riigi Teataja, reinforced by EBA AML/CTF guidance at EU level. Any obliged entity processing crypto-linked payments must build and evidence:
DAC8 layers additional obligations for CASPs, customer identification and tax-relevant reporting, so a firm operating a hybrid model should map both AML and DAC8 data requirements into a single onboarding and record-keeping design rather than bolting them on separately.
A frequent classification error is treating crypto-assets as “funds.” Under the payment-services framework, safeguarding rules apply to client funds and e-money, not to crypto-assets generally. Where a firm actually holds crypto-assets on behalf of clients, that is custody within the meaning of MiCA and requires CASP authorisation with the associated custody obligations, including segregation, liability standards and secure key management.
The practical consequence: an EMI safeguarding euro balances is operating within its regime, but the moment it controls client crypto it has stepped into MiCA custody. Designing the model so that fiat safeguarding and crypto custody are cleanly delineated, often across separate authorised entities, is one of the most important structural decisions in a crypto payment services estonia build.
PIs and EMIs must hold minimum own funds set under the payment-services regime, with EMIs subject to their own thresholds reflecting e-money issuance, and must maintain ongoing prudential adequacy proportionate to the volume and risk of their activity. MiCA imposes its own prudential and safeguarding standards on CASPs, calibrated to the services provided, custody and trading-platform operation attract more demanding requirements than narrower services. Because the precise figures depend on the exact activities authorised, applicants should confirm current thresholds directly with the Finantsinspektsioon before finalising capital plans. Where a supervisor identifies gaps, remediation and enhanced controls, including EDD triggers tied to DAC8 identification duties, will typically be required before authorisation or continued operation.
Expert tip. In our practice, we advise clients to model the AML, custody and capital pillars together from day one. Treating them as separate workstreams is a common reason applications stall, supervisors want to see one coherent risk architecture, not three disconnected policy binders.
A licence is only half the battle. Securing a bank account for crypto estonia operations is frequently the harder task, because banks apply their own risk appetite over and above the regulatory minimum. The central bank, Eesti Pank, oversees payment systems and comments on the risks that inform how commercial banks approach crypto-linked business.
When a bank assesses a PI that touches crypto payment rails, it probes:
In our experience supporting onboarding, the firms that succeed treat the bank as a second supervisor and prepare accordingly. Effective tactics include:
Where a traditional bank declines, firms often layer relationships across specialist payment and correspondent providers with a defined crypto risk appetite, while continuing to pursue mainstream banking as their compliance track record matures. A staged approach, proving controls at low volume before requesting expanded limits, frequently converts an initial “no” into a later “yes.”
Bringing the analysis together, the structuring decision follows a clear decision tree, and the application must embed the operational controls the Finantsinspektsioon expects to see.
Whichever route you choose, the application should evidence governance, AML/KYC systems, custody arrangements (or clear confirmation that no crypto custody occurs), capital adequacy and outsourced-provider oversight. See the Estonia, Cryptocurrency & Blockchain practice area resources for the wider regime.
12-point 2026 compliance checklist
Realistic planning should assume several months from serious preparation to authorisation, with additional lead time for bank onboarding and any remediation the supervisor requests. Hybrid models running two authorisation tracks take longest. Cost is driven less by fees and more by the depth of policy build-out, technology, capital and professional support, under-investing early almost always extends the timeline.
Estonian supervision of financial-crime risk has been consistently robust, and the Finantsinspektsioon publishes guidance and, where appropriate, supervisory measures that signal its expectations. The practical lesson for a PI whose activity is flagged as touching crypto is to respond quickly and constructively. Where a regulator raises concerns, the remediation playbook is consistent:
Firms that treat supervisory contact as an opportunity to demonstrate control maturity, rather than a threat to be minimised, routinely emerge with a stronger licence position and better banking relationships.
A crypto payment license estonia strategy in 2026 rests on one disciplined act of classification followed by rigorous execution. An Estonian PI or EMI can lawfully support crypto payment flows where its activity remains within the payment-services perimeter, but custody, exchange and trading of crypto-assets require a MiCA CASP authorisation, and many real-world models need both. For decision-makers, the sequence is clear: obtain a jurisdiction-specific legal review, classify every asset and service against MiCA, choose the licence route, engage the Finantsinspektsioon early, design one coherent AML, custody and capital architecture, and prepare a transparent bank due-diligence pack.
Get those steps in the right order and a crypto payment license estonia project becomes a manageable, well-evidenced application rather than a stalled one.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Yuliya Barabash at SBSB Fintech Lawyers, a member of the Global Law Experts network.
posted 4 minutes ago
posted 26 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message