Estonia was one of the first EU member states to establish a dedicated registration framework for virtual‑asset service providers, and the country remains a strategic base for crypto businesses serving European markets. However, the regulatory landscape has changed materially. Obtaining a VASP licence in Estonia now means navigating the transition from legacy registrations administered by the Financial Intelligence Unit (Rahapesu Andmebüroo, or FIU) to full Markets in Crypto‑Assets Regulation (MiCA) authorisations supervised by Finantsinspektsioon, Estonia’s financial supervisory authority. This guide distils the current requirements, step‑by‑step filing process, capital thresholds, timeline expectations, and MiCA transition actions into a single, regulator‑sourced reference built for founders, compliance leads, and the advisors supporting them.
Who should read this: Anyone preparing a new virtual‑asset or crypto‑asset service provider application in Estonia, as well as operators holding legacy FIU authorisations who must migrate to MiCA CASP authorisation before the transitional deadline of 1 July 2026. The page consolidates regulator citations, internal checklists, and practical commentary so you can begin the process with confidence.
Before diving into the detailed process, here are the essential eligibility criteria and fast facts every applicant should know:
| Fast Facts VASP Licence Estonia | |
|---|---|
| MiCA transitional deadline | 1 July 2026 |
| Finantsinspektsioon portal opens | 18 March 2026 |
| Regulatory application fee | €3,000 (indicative confirm with Finantsinspektsioon) |
| Typical total timeline | 3–6 months (preparation through decision) |
Identify exactly which MiCA service categories your platform will offer custody and administration of crypto‑assets, operation of a trading platform, exchange services (crypto‑to‑fiat or crypto‑to‑crypto), execution of orders, placement, transfer, or advisory services. Each category triggers specific capital, governance, and disclosure obligations. Mapping services early avoids scope creep and regulatory queries later.
Prepare documentary evidence that beneficial owners and senior managers are not subject to international sanctions and have no adverse AML/CFT findings. Screen all relevant persons against EU, UN, and OFAC lists. Compile screening results and retain audit trails the regulator expects to see the methodology as well as the output.
Assemble CVs, diplomas, and professional references for every proposed board member, compliance officer, and MLRO. The regulator looks for demonstrated experience in banking, financial services, or information technology. Where managers are foreign nationals, obtain certificates of clean criminal record from their home jurisdictions, apostilled or legalised as appropriate.
Securing a corporate bank account with an Estonian or EEA bank remains one of the most time‑consuming steps. Begin the banking relationship process early and have confirmation of fiat on‑ramp and off‑ramp rails before filing. The regulator will ask how client funds flow through the business.
Document your custody model (self‑custody vs third‑party custodian), wallet architecture (cold, warm, hot), key‑management procedures, and the results of any security audits or penetration tests. If you intend to rely on a third‑party technology vendor, prepare due‑diligence files and draft outsourcing agreements.
A downloadable regulator checklist summarising all preparation items is available see the closing section for access details.
The standard vehicle is an osaühing (OÜ), Estonia’s private limited company, with a minimum share capital of €2,500 (general corporate law minimum; the VASP/CASP‑specific capital layer sits above this). An aktsiaselts (AS, public limited company) may be appropriate for larger operations but carries higher formation and governance costs. Share capital must be fully paid in before the licence application is filed.
Finantsinspektsioon expects genuine Estonian substance not a shell structure. At a minimum, this means a physical office address (not merely a registered agent), at least one management board member resident in Estonia, local employment of compliance and operational staff, and Estonian or EEA bank accounts. Decision‑making should demonstrably take place within Estonia.
Non‑residents may establish and own an Estonian VASP entity, but the regulator scrutinises nominee or proxy arrangements closely. A local authorised representative or director can satisfy substance requirements; however, nominee directors who lack genuine involvement raise red flags. Industry observers expect Finantsinspektsioon to intensify substance reviews through 2026 as part of MiCA onboarding. Founders outside the EEA should plan for at least one credible local management appointment and budget for relocation or frequent in‑country presence. For detailed guidance on Estonia company formation for crypto businesses, see the related resource.
The board of directors bears ultimate responsibility for regulatory compliance. Applicants must present a clear organisational chart showing reporting lines, a designated compliance officer independent from revenue‑generating functions, an MLRO with direct escalation authority, and for larger operations an internal audit function. Board meeting minutes, a delegation of authority matrix, and written terms of reference for each governance body should be prepared before filing.
Under the Money Laundering and Terrorist Financing Prevention Act (MLTFPA), every VASP must maintain written policies covering customer due diligence (KYC/KYB), risk classification of clients and transactions, enhanced due diligence for high‑risk categories, ongoing transaction monitoring, and suspicious transaction reporting (STR) workflows to the FIU. Include a sample document list in your application pack:
Integrate real‑time sanctions screening at onboarding and on an ongoing basis against EU consolidated sanctions lists, UN lists, and where commercially relevant OFAC SDN lists. Document the technology vendor, screening frequency, false‑positive handling process, and escalation procedures.
If your services involve holding clients’ crypto‑assets, the regulator expects a detailed custody policy covering key‑generation ceremonies, multi‑signature or multi‑party computation (MPC) architecture, segregation of client assets from proprietary holdings, reconciliation schedules, and insurance or reserve arrangements. MiCA introduces explicit custodial obligations applicants should design their custody model to meet both the current Estonian requirements and MiCA Article 75 standards.
Finantsinspektsioon expects applicants to demonstrate robust information‑security controls. Relevant evidence includes SOC 2 Type II or ISO 27001 certification (or a credible roadmap), recent penetration‑test reports, an incident‑response plan with defined notification timelines (to the regulator, to clients, and to CERT‑EE), and a business‑continuity/disaster‑recovery plan with tested recovery‑time objectives.
Compile all governance and compliance documentation into a structured evidence pack. Typical contents include a policy index, full organisational chart, board and committee terms of reference, security‑test results, outsourcing and third‑party agreements, and a data‑protection impact assessment. A well‑indexed evidence pack significantly reduces regulator queries and accelerates processing. For templates and worked examples, see the AML compliance checklist resource.
Under the MiCA framework as transposed into Estonian law, minimum own‑funds requirements vary by service category. The following illustrative thresholds are drawn from MiCA Article 67 and the corresponding Estonian legislative provisions:
Applicants offering multiple service categories must meet the highest applicable threshold. Capital must be genuinely available not encumbered, borrowed on a short‑term basis, or subject to call‑back arrangements.
Submit recent bank statements (typically no older than 30 days), shareholder declarations on the origin of funds, and if capital is provided via equity injection evidence of the shareholder’s own source of wealth. Escrow arrangements are acceptable in some circumstances but must be documented with the escrow agent’s confirmation letter.
Finantsinspektsioon expects a three‑year business plan including profit‑and‑loss projections, cash‑flow forecasts, and at least two stress‑test scenarios (e.g., sharp decline in trading volumes, major cyber‑incident). The financial model should demonstrate that the entity can sustain operations and meet regulatory capital at all times, including during adverse conditions.
The Finantsinspektsioon application processing fee is approximately €3,000. Applicants should also budget for notarisation and apostille fees, external audit costs (if required for capital verification), and legal and advisory fees, which vary depending on the complexity of the application but typically range from €15,000 to €50,000 in aggregate for a well‑prepared submission.
Licensed entities must file periodic financial returns with Finantsinspektsioon and maintain AML reporting obligations to the FIU. Annual accounts must be audited by an approved auditor, and any material change in the financial position of the entity must be notified to the regulator without delay.
The following numbered steps outline how to get a VASP licence (or, from 18 March 2026, a CASP authorisation) through the Finantsinspektsioon filing process:
The Finantsinspektsioon portal provides standard application forms. Accompanying documents typically include: completed application form, articles of association, Commercial Register extract, fit‑and‑proper questionnaires for each key person, AML/CFT policy suite, custody policy, business plan with financial projections, capital‑proof documentation, technology and security documentation, and an organisational chart.
Regulator feedback consistently highlights the same deficiency categories: incomplete or outdated criminal‑record certificates, AML policies that are generic templates rather than tailored to the applicant’s business model, missing stress‑test scenarios in financial projections, and unclear custody segregation arrangements. Assign a senior compliance reviewer to perform a final quality‑assurance pass before submission.
Processing timelines vary based on the completeness and quality of the application, the complexity of the proposed business model, and the regulator’s current workload. The table below summarises typical durations observed in practice:
| Milestone | Typical Duration |
|---|---|
| Internal preparation & document assembly | 4–8 weeks |
| Entity incorporation (if new) | 1–2 weeks |
| Submission to first regulator response | 6–12 weeks |
| Supplementary information rounds | 2–6 weeks (1–3 rounds typical) |
| Full decision (from submission) | 3–6 months |
Expect at least one round of supplementary questions. Well‑prepared applications with a complete evidence pack typically receive fewer queries and reach a decision more quickly. If the application is refused, the regulator will provide written reasons. Re‑application is possible but will require all identified deficiencies to be remedied; industry observers note that a poorly handled first submission can materially delay subsequent attempts.
Receiving the licence is the beginning not the end of regulatory engagement. Key ongoing obligations include:
The Markets in Crypto‑Assets Regulation (MiCA) entered into application for crypto‑asset service providers on 30 December 2024. Article 143(3) provides a transitional period allowing member states to permit existing nationally authorised providers to continue operating. In Estonia, this transitional period expires on 1 July 2026. After that date, all legacy FIU VASP registrations cease to be valid.
Legacy FIU holders must file a CASP authorisation application with Finantsinspektsioon before the deadline, upgrade their AML/CFT and governance policies to MiCA standards, and prepare for supervision by Finantsinspektsioon rather than the FIU. ESMA has issued guidance emphasising orderly wind‑down obligations for providers that fail to obtain authorisation by the deadline.
New applicants should apply directly to Finantsinspektsioon for a MiCA CASP authorisation via the portal that opened on 18 March 2026. There is no longer a pathway to obtain a standalone FIU VASP registration.
Passporting: A significant advantage of the MiCA CASP authorisation is the ability to passport services across all EEA member states through a notification procedure. Operators planning cross‑border activity should factor passporting notifications into their launch timeline.
| Feature | FIU VASP (Legacy) | MiCA CASP (Finantsinspektsioon) |
|---|---|---|
| Supervisor | Rahapesu Andmebüroo (FIU) | Finantsinspektsioon |
| Type of permission | Registration / authorisation under MLTFPA | Full licence (authorisation) under MiCA |
| Capital minima | €100,000 (flat legacy requirement) | €50,000–€150,000 (tiered by service category) |
| Passporting across EEA | Not available | Available via notification procedure |
| Portal & filing body | FIU application (historic) | Finantsinspektsioon e‑portal (from 18 March 2026) |
| Ongoing supervision scope | AML/CFT focused | Comprehensive: prudential, conduct, AML/CFT, governance |
| Key dates / transition status | Registrations expire 1 July 2026 | Applications accepted from 18 March 2026; sole regime from 1 July 2026 |
A comprehensive application‑preparation checklist covering entity setup, documentation, capital, and AML/CFT readiness is available for download. For further authoritative reading, consult the regulator and legislative sources referenced throughout this guide, including the Finantsinspektsioon portal, the FIU guidance pages, Riigi Teataja (Estonian legislation), and EUR‑Lex (MiCA full text). For related advisory resources, see licensing support from Global Law Experts.
posted 5 hours ago
posted 6 hours ago
posted 6 hours ago
posted 6 hours ago
posted 6 hours ago
posted 7 hours ago
posted 7 hours ago
posted 8 hours ago
posted 8 hours ago
posted 12 hours ago
posted 12 hours ago
posted 12 hours ago
No results available
Find the right Legal Expert for your business
Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.
Naturally you can unsubscribe at any time.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Send welcome message