Our Expert in Estonia
No results available
Substance requirements Estonia has become one of the most consequential compliance questions for fintech founders as three regulatory forces converge in 2026: the sunset of the legacy virtual asset service provider (VASP) regime, the phased application of the Markets in Crypto-Assets Regulation (MiCA), and the rollout of the EU’s DAC8 crypto-asset reporting framework. For electronic money institutions (EMIs), payment institutions (PIs) and crypto-asset service providers preparing new applications or remediating existing licences, the days of a nominal Estonian company with an offshore management team are firmly over. The Estonian Financial Supervision and Resolution Authority (Finantsinspektsioon) now expects demonstrable local presence, genuine management, and operational readiness before it grants or maintains authorisation.
This guide sets out, in practical and regulator-cited terms, what those expectations mean and how to evidence them.
Last updated: 1 September 2026
Estonia’s financial sector is supervised by the Estonian Financial Supervision and Resolution Authority (Finantsinspektsioon), which authorises and supervises payment institutions, electronic money institutions and, under the new European framework, crypto-asset service providers. The statutory basis for payment and e-money authorisation sits in Estonian legislation consolidated on Riigi Teataja, the Estonian State Gazette, alongside the Money Laundering and Terrorist Financing Prevention Act that governs anti-money-laundering obligations for licensed firms.
For EMIs and PIs, the licensing framework has long required credible governance, adequate capital and effective risk management. What has intensified in the run-up to 2026 is the practical weight regulators place on the economic substance applicants can prove, the difference between a paper structure and a genuine operating business. For crypto firms, the picture has changed more dramatically. The legacy virtual asset regime, under which many Estonian companies once held virtual currency service authorisations, is being wound down as the EU-wide MiCA framework, set out in Regulation (EU) 2023/1114, takes over. MiCA introduces a harmonised authorisation and passporting regime for crypto-asset service providers, but it also raises the bar on organisational and governance requirements, and, by extension, on substance.
The strategic implication is straightforward: whether you are pursuing an EMI licence in Estonia, a payment institution authorisation, or transitioning a crypto business from the legacy regime into MiCA, you must plan your local presence and evidence base from day one. Retrofitting substance after an application has stalled is far more expensive and far less persuasive.
“Substance,” in the Estonian licensing context, means that the licensed activity is genuinely directed, managed and carried out in Estonia, not merely booked through an Estonian shell. Finantsinspektsioon assesses whether the applicant has the human, physical and systemic resources to run the regulated business responsibly and to be effectively supervised from within the jurisdiction. This is where the substance requirements Estonia expects diverge sharply from the minimal formalities some applicants assume are sufficient.
In practice, the regulator looks for a cluster of interlocking elements. There must be a genuine Estonian legal entity, properly registered and with a real registered address. There must be management physically present and accountable in Estonia, not just a resident director whose role is nominal. There must be an appropriate number of qualified local staff to perform the core functions, compliance, risk, operations and finance, proportionate to the scale and complexity of the business. There must be office premises capable of housing that team. And there must be operational systems, internal controls and an anti-money-laundering function that actually function.
Crucially, none of these requirements is satisfied by a single document. The regulator evaluates the whole picture and tests whether the pieces cohere, whether the business plan matches the staffing, whether the staffing matches the premises, and whether the governance structure reflects genuine decision-making in Estonia. Where those elements are inconsistent, applications are delayed or rejected, and existing licences can come under supervisory pressure.
The foundation of any Estonian licence is a properly incorporated company. Registration and registered-address evidence should come from the Estonian Business Register (RIK), whose extracts serve as the primary proof of legal existence and registered office. Beyond incorporation, applicants should assemble:
There is no single statutory headcount that satisfies substance for every business. Finantsinspektsioon assesses staffing proportionately, a small PI with a narrow product set will reasonably have fewer people than a multi-product EMI or a crypto-asset service provider handling custody. What matters is that the core control functions are genuinely staffed in Estonia by qualified people who devote real time to the business.
Applicants should prepare evidence for each key role: employment contracts, detailed CVs demonstrating relevant experience, and where the regulator expects to see it, time-allocation evidence such as timesheets or calendar records showing the individual is actually engaged with the Estonian operation. Senior management, the persons who direct the business day to day, should be present in Estonia and demonstrably in control. Where a role is filled by someone with commitments elsewhere, be prepared to explain how sufficient time and attention are allocated, because a management team that exists only on paper is one of the most common reasons the substance requirements Estonia imposes are found to be unmet.
The compliance and AML architecture is where substance and regulatory expectation meet most directly. Every EMI, PI and crypto firm must have a designated anti-money-laundering officer with the seniority, resources and independence to do the job. This is not a box-ticking appointment: the AML officer must be able to demonstrate active oversight, and the regulator will expect to see a compliance manual, documented know-your-customer procedures, a business-wide money-laundering and terrorist-financing risk assessment, and clear reporting lines to the board. FATF’s guidance on a risk-based approach to virtual assets and VASP supervision, published by the FATF, sets the international benchmark that Estonian supervision reflects, particularly for crypto businesses.
Internal controls should cover IT security, business continuity, outsourcing oversight and conflict-of-interest management, and each should be documented in a policy that the local team can actually operate.
The most acute change for crypto businesses is the transition away from the legacy virtual asset service provider regime toward MiCA authorisation. The VASP sunset that Estonian crypto operators now face means that authorisations granted under the old national framework cease to be a viable long-term basis for operating, and firms must either obtain authorisation as a crypto-asset service provider under MiCA or wind down their regulated activity. Regulation (EU) 2023/1114 governs the scope, the transitional arrangements and the passporting mechanics; the precise end date of any national transitional period is set by the applicable Estonian implementing provisions, and firms should confirm their own deadline against the current legislation and Finantsinspektsioon guidance.
What this means in substance terms is heightened scrutiny. During the transition, Finantsinspektsioon and its European counterparts are re-examining crypto firms’ governance, capital, custody arrangements and AML controls to a MiCA standard that is materially higher than the old regime demanded. Firms that treated their legacy authorisation as a light-touch formality will find the MiCA authorisation process exposes exactly the substance gaps this guide describes: absent local management, thin staffing, inadequate compliance functions and weak evidence of genuine Estonian operations.
Layered on top is DAC8. The European Commission’s Digital Asset Reporting (DAC8) framework, adopted as Council Directive (EU) 2023/2226 amending the Directive on Administrative Cooperation, introduces new crypto-asset reporting obligations across EU member states, requiring reporting crypto-asset service providers to collect, verify and report user and transaction data to tax authorities. For firms operating from Estonia, this means building the data infrastructure and compliance processes to identify reportable users, apply due-diligence procedures and file with the competent authority. The Estonian Tax and Customs Board is the domestic authority whose administrative guidance and reporting channels will apply.
DAC8 readiness is now inseparable from substance: a firm cannot credibly claim to be operationally ready if it lacks the local compliance and data capacity to meet these reporting duties.
The practical takeaway for crypto firms is that AML, MiCA authorisation and DAC8 reporting form a single, integrated compliance burden. Preparing for one without the others invites supervisory intervention. Industry observers expect the transition period to expose a number of under-resourced firms, and early indications suggest regulators across the EU are prioritising substance and AML adequacy in their reviews.
Governance is the connective tissue of substance. Finantsinspektsioon expects a board and executive management that genuinely direct the business and are fit and proper for their roles. For EMIs and PIs, that means a board with appropriate collective experience, clarity over who holds executive responsibility, and, depending on scale, independent oversight capable of challenging management. Executive management should be present in Estonia, accountable, and able to demonstrate that strategic and operational decisions are taken locally.
Delegation is permitted, but it must be real and controlled. Where certain functions are delegated within the group or to third parties, the licensed entity must retain genuine oversight and the ultimate decision-making authority. The regulator distinguishes sharply between legitimate delegation with robust controls and the outsourcing of core management to a location where the business is actually run, the latter defeats the purpose of an Estonian licence and is treated as a substance failure.
Certain shortcuts are consistently rejected. A resident director who holds numerous directorships and contributes nothing operationally is a red flag, not a solution. A management structure where the persons named in the application are not the persons making decisions is a misrepresentation risk. And an AML officer who lacks the authority or resources to act independently undermines the entire compliance framework. Applicants should assume the regulator will test whether the governance described on paper matches the reality, and should build a structure that survives that test.
Outsourcing and remote working are permitted within limits, and many legitimate fintechs use group service providers or specialist vendors for functions such as IT, customer support or aspects of transaction monitoring. What matters is that outsourcing does not hollow out the licensed entity. Core control functions, particularly compliance, risk management and senior decision-making, should remain genuinely within the Estonian operation. Where functions are outsourced, the firm should maintain:
Substance that cannot be evidenced does not exist as far as a regulator is concerned. The strength of an application often comes down to the quality, coherence and organisation of the documentation package. Applicants should assemble a comprehensive evidence file and index it clearly so the case officer can trace each claim to a supporting document. The following checklist reflects the categories of evidence that align with Finantsinspektsioon’s supervisory expectations:
Regulators evaluate this material for consistency and authenticity. They cross-check the number of staff against the premises and the business plan; they test whether the payroll matches the named individuals; they read board minutes to see whether decisions are genuinely local. A tidy, well-indexed package with consistent internal logic signals a genuine operation. A disjointed collection of standalone documents signals a constructed façade. Recommended practice is to build a master index that maps each substance element to its supporting files, using consistent file naming, for example, grouping documents by category and dating each version, so the application reads as a coherent narrative rather than a document dump.
| Dimension | EMI (E-money Institution) | PI (Payment Institution) | Crypto (CASP under MiCA) |
|---|---|---|---|
| Licensing authority | Finantsinspektsioon | Finantsinspektsioon | Finantsinspektsioon (MiCA authorisation as legacy VASP regime sunsets) |
| Local staff expectation | Proportionate team covering compliance, risk, operations and finance | Proportionate team; may be smaller for narrow product sets | Proportionate team with custody, security and monitoring capacity where applicable |
| Compliance function | Dedicated AML officer, full policy suite, board oversight | Dedicated AML officer, full policy suite, board oversight | Dedicated AML officer to MiCA/FATF standard, enhanced monitoring |
| AML / DAC8 obligations | Full AML Act obligations; no DAC8 crypto reporting | Full AML Act obligations; no DAC8 crypto reporting | Full AML obligations plus DAC8 crypto-asset reporting |
| MiCA relevance | Limited unless issuing crypto-linked products | Limited unless offering crypto services | Central, MiCA is the governing framework |
| Passporting readiness | EU passporting under payment services framework | EU passporting under payment services framework | MiCA passporting once authorised |
| Common substance evidence | Lease, payroll, board minutes, capital, policies | Lease, payroll, board minutes, capital, policies | Lease, payroll, board minutes, custody controls, DAC8 systems |
One of the most attractive features of MiCA is passporting: once authorised as a crypto-asset service provider in one member state, a firm can provide services across the EU without seeking separate authorisation in each country. The mechanism is set out in Regulation (EU) 2023/1114 and operates through notification between the home-state and host-state supervisors. For firms authorised in Estonia, this makes an Estonian MiCA authorisation a gateway to the wider European market.
However, a persistent misconception must be addressed directly: passporting does not relieve a firm of its home-state substance obligations. If Estonia is your home state, Estonia remains responsible for your prudential and conduct supervision wherever you operate, and Finantsinspektsioon must be able to supervise a genuine business located in Estonia. Passporting extends where you can sell; it does not move where you must be substantively established. Firms that obtain an Estonian authorisation intending to run the actual business elsewhere will find that supervisory cooperation between authorities, and the ongoing reporting obligations that passporting entails, quickly expose the mismatch.
Maintaining real Estonian substance is therefore a continuing obligation, not a one-off application hurdle, and it must be sustained throughout the life of the licence.
Existing EMI, PI and crypto licence holders that recognise substance gaps should act on a prioritised timeline rather than attempting everything at once. The following roadmap reflects a sensible sequencing of priorities:
Throughout remediation, document every step. A firm that can show a credible, dated remediation plan and evidence of execution is in a far stronger position with the regulator than one that waits to be told its substance is inadequate.
Meeting the substance requirements Estonia now enforces is the central challenge for any EMI, PI or crypto firm seeking or maintaining a licence in 2026. The convergence of the VASP sunset, MiCA authorisation and DAC8 reporting has permanently raised the bar: genuine local management, proportionate qualified staff, real premises, functioning governance and a credible AML framework are no longer optional refinements but the price of entry. The firms that succeed will be those that build substance into their structure from the outset and evidence it meticulously, rather than treating it as a compliance afterthought. Whether you are preparing a new application or remediating an existing licence, a jurisdiction-specific assessment against these expectations is a valuable first step.
For tailored guidance, consult the Licensing lawyers, Estonia directory. This guide is general information and not a substitute for advice from qualified local counsel on your specific circumstances.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Mark Gofaizen at Gofaizen & Sherle Fintech Lawyers, a member of the Global Law Experts network.
posted 16 minutes ago
posted 57 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message