[codicts-css-switcher id=”346″]

Global Law Experts Logo
crypto payment license estonia

Can an Estonian Payment Institution (EMI/PI) Offer Crypto Payments in 2026?

By Global Law Experts
– posted 48 minutes ago

Crypto payment license estonia questions have become urgent for founders and finance leaders as 2026 arrives with the Markets in Crypto-Assets Regulation (MiCA) fully operational, DAC8 tax-reporting obligations approaching, and the Estonian supervisor sharpening its expectations of anti-money-laundering (AML) controls. The core question this guide answers is deceptively simple but commercially decisive: can a business holding an Estonian Payment Institution (PI) or Electronic Money Institution (EMI) authorisation lawfully process crypto payments, and, if so, under what conditions? This article is written for decision-makers evaluating licence structure, bank access and compliance design in Estonia, and it stays focused on that question rather than token design or tax mechanics.

Below you will find the legal framework, a licence comparison, AML and prudential hooks, practical bank-onboarding tactics and a step-by-step checklist for 2026 applications.

Who this is for: founders, CEOs, compliance heads and CFOs weighing whether to use an Estonian PI/EMI licence to run crypto payment rails in the EU in 2026.

What you will learn: whether a PI/EMI can lawfully process crypto payments, the trade-offs between a payment-services licence and a MiCA CASP authorisation, AML, capital and custody requirements, bank-onboarding tactics, and a practical compliance checklist.

Quick answer (TL;DR). The answer is a conditional yes. An Estonian PI or EMI can support certain crypto-adjacent payment flows, but where the activity involves custody, exchange, or the operation of a crypto-asset service, a separate MiCA Crypto-Asset Service Provider (CASP) authorisation is generally required. Classification depends on the asset type and the exact service. Read the Cryptocurrency Lawyer Estonia, checklist alongside this guide, and see the licence comparison table below.

For a jurisdiction-specific view of the licensing landscape, our author profile sets out the practitioner background behind this analysis. The remainder of this article walks through the 2026 legal baseline, the operational tests that determine which licence you need, and the compliance and banking work that separates a viable application from a rejected one.

Legal framework in 2026, Estonia plus the EU baseline for a crypto payment license estonia strategy

Any assessment of whether a payment institution estonia entity can process crypto payments must sit on two layers: the national Estonian supervisory regime and the overarching EU rulebook. In 2026 these two layers interlock more tightly than at any previous point, and the interaction determines both what is permitted and what triggers additional authorisation.

Estonian supervision and key national rules

Estonia’s principal financial regulator is the Financial Supervision Authority, the Finantsinspektsioon. It authorises and supervises payment institutions and electronic money institutions, sets application standards, reviews permitted-activity scopes, and monitors ongoing prudential and conduct compliance. Under MiCA, the Finantsinspektsioon is also the competent authority for CASP authorisation in Estonia. If your business wants to hold or extend a PI/EMI licence to touch crypto payment flows, the Finantsinspektsioon is the body that assesses whether your model fits within the payment-services perimeter or crosses into crypto-asset services requiring separate authorisation.

National AML supervision runs alongside financial supervision. The Estonian Financial Intelligence Unit (Rahapesu Andmebüroo) receives suspicious transaction reports and enforces the country’s AML obligations; the Estonian Police and Border Guard Board is the wider law-enforcement authority. Estonia’s core statute is the Money Laundering and Terrorist Financing Prevention Act, published on the official legislation portal Riigi Teataja. This Act sets out customer due diligence, risk-assessment, monitoring and reporting duties that apply to obliged entities, including payment firms whose activity touches crypto.

The EU layer, MiCA, PSD2/PSR and DAC8

The EU baseline for a crypto payment license estonia decision starts with MiCA, the Markets in Crypto-Assets Regulation (Regulation (EU) 2023/1114). The full text is available on EUR-Lex, and the European Commission provides an accessible overview of its scope and objectives. MiCA defines the categories of crypto-assets and the list of crypto-asset services that require CASP authorisation, including custody, operation of a trading platform, exchange of crypto for funds or other crypto-assets, and the execution of orders on behalf of clients.

The payment-services layer, the second Payment Services Directive (PSD2) and the evolving successor framework proposed by the EU (a Payment Services Directive and Payment Services Regulation package), governs what a PI or EMI may do when handling funds and issuing electronic money. Where a service qualifies as a payment service or e-money issuance, the PI/EMI regime applies; where it qualifies as a crypto-asset service under MiCA, the CASP regime applies. The two frameworks are complementary but distinct, and a firm can hold both authorisations.

The third strand is reporting. DAC8 (Council Directive (EU) 2023/2226) extends automatic exchange-of-information rules to crypto-asset service providers, imposing tax-reporting and customer-identification obligations on in-scope operators, with reporting generally applying from 2026 onward. The European Banking Authority (EBA) supplements this with AML/CTF guidance that shapes how both crypto firms and their banks are expected to manage financial-crime risk.

Where national practice and MiCA meet

MiCA is a directly applicable EU regulation, so its definitions and authorisation triggers apply uniformly across Estonia. Estonian national law continues to govern AML detail, prudential supervision of PIs/EMIs and the practical application procedures administered by the Finantsinspektsioon. The practical implications for a decision-maker are:

  • Classification is service-driven. Whether you need a CASP authorisation depends on the specific crypto-asset service, not merely on the fact that crypto is involved.
  • A PI/EMI licence is not a crypto licence. Holding one does not by itself permit MiCA-regulated crypto-asset services.
  • Dual authorisation is common. Many crypto-payment models require both a payment-services licence and a CASP authorisation.
  • AML duties bite regardless of licence. The Estonian AML Act applies to obliged entities across both regimes.
  • Reporting obligations are expanding. DAC8 adds tax-reporting exposure for CASPs.

Licence options, Payment Institution/EMI vs CASP/MiCA

The central operational question is when a PI/EMI can lawfully support crypto payments and when a MiCA CASP authorisation becomes mandatory. The distinction turns on functional tests: what precisely does your platform do with the crypto-asset, and does it involve custody, exchange or the operation of a service that MiCA reserves to authorised CASPs?

When a PI/EMI might lawfully support crypto payments

A payment institution or EMI operates within the payment-services perimeter, executing payment transactions, issuing electronic money, and safeguarding client funds. There are models where a PI/EMI can sit alongside crypto flows without itself performing a MiCA-regulated crypto-asset service. Examples include:

  • Fiat rails feeding a separately authorised CASP. The PI/EMI handles the euro leg, collections, settlement, IBANs and e-money, while a distinct CASP entity performs custody or exchange.
  • E-money issuance where an e-money token is involved. MiCA treats e-money tokens in close relationship with the e-money framework, so an EMI’s activity may align with its existing authorisation, though careful classification is essential.
  • Pure payment processing at the merchant boundary. Where the PI/EMI processes the fiat conversion of a completed crypto transaction without taking custody of the crypto-asset itself.

The functional test is straightforward to state but demanding to apply: if your entity holds, controls, exchanges or administers the crypto-asset, you are likely inside the CASP perimeter. If your entity only ever touches funds and electronic money, the payment-services regime may suffice.

When CASP/MiCA authorisation is required

A CASP authorisation becomes mandatory where the activity is a crypto-asset service as defined in MiCA. The clearest triggers are:

  • Custody and administration of crypto-assets on behalf of clients, holding private keys or controlling client crypto.
  • Exchange of crypto-assets for funds or for other crypto-assets, whether operated as a dealer or through matching.
  • Operation of a trading platform or the execution and placement of orders for clients.

Common borderline scenarios include stablecoin payment rails and fiat rails that integrate tokenised assets. A stablecoin classified as an e-money token under MiCA sits close to the e-money framework, whereas an asset-referenced token or an unbacked crypto-asset generally pulls the model firmly into CASP territory. These are precisely the cases where early legal classification prevents a costly restructuring later.

Feature Payment Institution / EMI CASP (MiCA) Hybrid (PI/EMI + CASP)
Regulator / licence Finantsinspektsioon, PI or EMI authorisation under the payment-services regime Finantsinspektsioon, CASP authorisation under MiCA Both authorisations held by one or affiliated entities
Permitted activities Payment services; e-money issuance; safeguarding of funds Custody, exchange, trading-platform operation, order execution, transfer of crypto-assets Full fiat + crypto payment stack under combined scope
Use for crypto payments Conditional, fiat leg only; no custody/exchange of crypto Yes, for the crypto-asset services in scope Yes, end-to-end, subject to both rulebooks
AML reporting (national + DAC8) Estonian AML Act obligations; STRs to the FIU Estonian AML Act plus DAC8 crypto reporting Combined AML and DAC8 obligations across both perimeters
Capital / safeguarding Minimum own funds and safeguarding of client funds under the payment-services regime MiCA prudential and custody requirements calibrated to services offered Highest of the applicable requirements; parallel controls
Typical bank acceptance risk Moderate, crypto exposure raises scrutiny Elevated, banks apply enhanced due diligence to CASPs Elevated, but transparent structure can improve confidence
Time and cost to obtain in Estonia (estimate) Several months of preparation and review; costs driven by policy build-out and capital Comparable-to-longer timeline given custody and prudential detail Longest, two authorisation tracks and integrated controls

AML, custody and capital requirements for PIs supporting crypto payments

Once you have settled the licence question, the compliance architecture determines whether the Finantsinspektsioon will accept your application and whether banks will onboard you. Three pillars matter: AML, custody/safeguarding, and capital.

AML requirements for crypto in Estonia

Aml requirements crypto estonia obligations flow from the Money Laundering and Terrorist Financing Prevention Act on Riigi Teataja, reinforced by EBA AML/CTF guidance at EU level. Any obliged entity processing crypto-linked payments must build and evidence:

  • Customer due diligence (CDD). Identification and verification of customers and beneficial owners before establishing a business relationship.
  • Risk-based assessment. A documented business-wide risk assessment and customer risk-rating that accounts for crypto-specific exposure.
  • Transaction monitoring. Ongoing screening of flows against typologies, sanctions lists and behavioural red flags.
  • Enhanced due diligence (EDD). Deeper scrutiny for higher-risk customers, jurisdictions and product types, including certain crypto counterparties.
  • Suspicious transaction reporting. Prompt reporting to the Estonian Financial Intelligence Unit through its designated channels.

DAC8 layers additional obligations for CASPs, customer identification and tax-relevant reporting, so a firm operating a hybrid model should map both AML and DAC8 data requirements into a single onboarding and record-keeping design rather than bolting them on separately.

Custody and safeguarding, are tokens “funds”?

A frequent classification error is treating crypto-assets as “funds.” Under the payment-services framework, safeguarding rules apply to client funds and e-money, not to crypto-assets generally. Where a firm actually holds crypto-assets on behalf of clients, that is custody within the meaning of MiCA and requires CASP authorisation with the associated custody obligations, including segregation, liability standards and secure key management.

The practical consequence: an EMI safeguarding euro balances is operating within its regime, but the moment it controls client crypto it has stepped into MiCA custody. Designing the model so that fiat safeguarding and crypto custody are cleanly delineated, often across separate authorised entities, is one of the most important structural decisions in a crypto payment services estonia build.

Capital and prudential requirements

PIs and EMIs must hold minimum own funds set under the payment-services regime, with EMIs subject to their own thresholds reflecting e-money issuance, and must maintain ongoing prudential adequacy proportionate to the volume and risk of their activity. MiCA imposes its own prudential and safeguarding standards on CASPs, calibrated to the services provided, custody and trading-platform operation attract more demanding requirements than narrower services. Because the precise figures depend on the exact activities authorised, applicants should confirm current thresholds directly with the Finantsinspektsioon before finalising capital plans. Where a supervisor identifies gaps, remediation and enhanced controls, including EDD triggers tied to DAC8 identification duties, will typically be required before authorisation or continued operation.

Expert tip. In our practice, we advise clients to model the AML, custody and capital pillars together from day one. Treating them as separate workstreams is a common reason applications stall, supervisors want to see one coherent risk architecture, not three disconnected policy binders.

Bank access and onboarding, how Estonian banks treat PIs that support crypto rails

A licence is only half the battle. Securing a bank account for crypto estonia operations is frequently the harder task, because banks apply their own risk appetite over and above the regulatory minimum. The central bank, Eesti Pank, oversees payment systems and comments on the risks that inform how commercial banks approach crypto-linked business.

Typical bank risk questions and red flags

When a bank assesses a PI that touches crypto payment rails, it probes:

  • Service description clarity. Vague or shifting descriptions of what the firm does with crypto are an immediate red flag.
  • Counterparty and flow transparency. Banks want to understand who is on both sides of transactions and how funds move.
  • Jurisdictional exposure. Concentrations in high-risk jurisdictions attract enhanced scrutiny.
  • Source of funds and wealth. Especially for higher-value flows and institutional customers.
  • Control maturity. Evidence that AML, monitoring and sanctions controls are operational, not aspirational.

Practical bank-onboarding tactics for PIs handling crypto payments

In our experience supporting onboarding, the firms that succeed treat the bank as a second supervisor and prepare accordingly. Effective tactics include:

  • Structure legal documentation to match the flows. Ensure your corporate structure, licence scope and payment flows tell one consistent story.
  • Demonstrate segregation. Show clean separation of client funds, e-money and any crypto custody handled by an affiliated CASP.
  • Present enhanced compliance policies. Provide AML, sanctions and monitoring policies with named responsible officers and evidence of testing.
  • Offer transactional limits and staged growth. Proposing initial volume and value limits reassures a cautious onboarding team.
  • Show your KYC and monitoring technology. Concrete tooling for identity verification and transaction screening carries more weight than narrative alone.

Alternative banking and correspondent providers

Where a traditional bank declines, firms often layer relationships across specialist payment and correspondent providers with a defined crypto risk appetite, while continuing to pursue mainstream banking as their compliance track record matures. A staged approach, proving controls at low volume before requesting expanded limits, frequently converts an initial “no” into a later “yes.”

How to structure crypto payment services and a step-by-step compliance checklist for 2026

Bringing the analysis together, the structuring decision follows a clear decision tree, and the application must embed the operational controls the Finantsinspektsioon expects to see.

Decision tree, what to apply for

  • Fiat only, no crypto custody or exchange? A PI or EMI authorisation may suffice.
  • Custody, exchange or trading of crypto-assets? A CASP authorisation under MiCA is required.
  • End-to-end fiat and crypto payment stack? A hybrid model holding both authorisations is the likely route.

Operational requirements to embed in the application

Whichever route you choose, the application should evidence governance, AML/KYC systems, custody arrangements (or clear confirmation that no crypto custody occurs), capital adequacy and outsourced-provider oversight. See the Estonia, Cryptocurrency & Blockchain practice area resources for the wider regime.

12-point 2026 compliance checklist

  1. Confirm the precise MiCA classification of every asset and service.
  2. Decide the licence route: PI/EMI, CASP, or hybrid.
  3. Map fiat safeguarding separately from any crypto custody.
  4. Draft a business-wide AML risk assessment.
  5. Build CDD, EDD and beneficial-ownership procedures.
  6. Implement transaction monitoring and sanctions screening.
  7. Define suspicious-transaction reporting to the FIU.
  8. Integrate DAC8 identification and reporting data flows.
  9. Confirm minimum own funds and ongoing prudential coverage with the Finantsinspektsioon.
  10. Document custody, key management and segregation (if a CASP).
  11. Prepare the bank due-diligence pack with clear flows and limits.
  12. Assign named compliance officers and evidence control testing.

Timeline and estimated costs

Realistic planning should assume several months from serious preparation to authorisation, with additional lead time for bank onboarding and any remediation the supervisor requests. Hybrid models running two authorisation tracks take longest. Cost is driven less by fees and more by the depth of policy build-out, technology, capital and professional support, under-investing early almost always extends the timeline.

Enforcement, supervisory attention and remediation lessons

Estonian supervision of financial-crime risk has been consistently robust, and the Finantsinspektsioon publishes guidance and, where appropriate, supervisory measures that signal its expectations. The practical lesson for a PI whose activity is flagged as touching crypto is to respond quickly and constructively. Where a regulator raises concerns, the remediation playbook is consistent:

  • Assess and contain. Establish exactly which activities are in question and whether they cross into CASP territory.
  • Self-report where required. Proactive engagement is viewed more favourably than defensiveness.
  • Produce a remediation plan. Time-bound, resourced and owned by named senior staff.
  • Strengthen controls. Close AML, custody and reporting gaps and evidence the fix.

Firms that treat supervisory contact as an opportunity to demonstrate control maturity, rather than a threat to be minimised, routinely emerge with a stronger licence position and better banking relationships.

Conclusion and recommended next steps

A crypto payment license estonia strategy in 2026 rests on one disciplined act of classification followed by rigorous execution. An Estonian PI or EMI can lawfully support crypto payment flows where its activity remains within the payment-services perimeter, but custody, exchange and trading of crypto-assets require a MiCA CASP authorisation, and many real-world models need both. For decision-makers, the sequence is clear: obtain a jurisdiction-specific legal review, classify every asset and service against MiCA, choose the licence route, engage the Finantsinspektsioon early, design one coherent AML, custody and capital architecture, and prepare a transparent bank due-diligence pack.

Get those steps in the right order and a crypto payment license estonia project becomes a manageable, well-evidenced application rather than a stalled one.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Yuliya Barabash at SBSB Fintech Lawyers, a member of the Global Law Experts network.

Sources

  1. Estonian Financial Supervision Authority (Finantsinspektsioon)
  2. European Commission, Markets in Crypto-Assets (MiCA)
  3. EUR-Lex, Regulation (EU) 2023/1114 (MiCA)
  4. Riigi Teataja, Estonian legislation portal
  5. Eesti Pank (Estonian Central Bank)
  6. European Banking Authority (EBA)
  7. Estonian Police and Border Guard Board

FAQs

Can a payment institution (EMI/PI) in Estonia legally process crypto payments?
Conditionally, yes. A PI/EMI can support fiat legs of crypto payment flows, but custody or exchange of crypto-assets requires a MiCA CASP authorisation. See the MiCA text and Finantsinspektsioon.
You need CASP authorisation when you provide crypto-asset services, custody, exchange for funds or other crypto, or operating a trading platform. Pure fiat payment processing may stay within the PI/EMI regime under MiCA.
Customer due diligence, risk assessment, transaction monitoring, enhanced due diligence and suspicious-transaction reporting to the FIU, per the Estonian AML Act on Riigi Teataja and EBA guidance.
Conditionally. Banks require enhanced controls, transparent flows and clear service descriptions, informed by payment-system risk views from Eesti Pank. Staged limits and mature compliance evidence improve acceptance odds.
Plan for several months of preparation and review, plus additional time for bank onboarding and any remediation the Finantsinspektsioon requests. Hybrid PI/EMI-plus-CASP structures take longest.
Yes for in-scope CASP activity. DAC8 adds customer-identification and tax-reporting duties, so hybrid models should integrate DAC8 data flows with their AML onboarding from the outset.
residency by investment panama
By Global Law Experts

posted 26 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Can an Estonian Payment Institution (EMI/PI) Offer Crypto Payments in 2026?

Send welcome message

Custom Message