Trackers
Trackers

Crypto Regulation in Estonia: 2026 Update

Crypto regulation in Estonia has undergone a fundamental transformation over the past several years, moving from one of the most permissive regimes in the EU to a tightly supervised framework aligned with the bloc';s Markets in Crypto-Assets Regulation (MiCA). Operators who obtained licences under the old system must now meet substantially higher standards or cease activity. This guide explains the current legal framework, the competent authorities, licensing requirements, ongoing compliance obligations, and the practical implications for foreign founders and established businesses operating in Estonia';s digital asset sector.

What the current legal framework looks like for crypto regulation Estonia

Estonia';s primary legislative instrument governing virtual asset service providers is the Money Laundering and Terrorist Financing Prevention Act (MLTFPA), which was amended several times to tighten the original licensing regime. The MLTFPA defines virtual currency service providers and sets out the conditions under which they may operate. Alongside it, the Financial Supervision Authority Act establishes the powers of the Finantsinspektsioon (FI), Estonia';s financial regulator, which has taken on a central role in supervising crypto businesses.

The EU';s MiCA regulation applies directly in Estonia as in all member states, without the need for national transposition. MiCA introduces a single authorisation framework for crypto-asset service providers (CASPs) and issuers of asset-referenced tokens and e-money tokens. For Estonian-registered entities, this means that the national licensing regime under the MLTFPA is being phased out and replaced by MiCA authorisation supervised by the FI.

The transition period under MiCA allows firms that held a valid national licence before the regulation';s application date to continue operating for a defined period while applying for a MiCA CASP authorisation. In practice, the FI has communicated that it will not extend this window indefinitely, and firms that delay their MiCA applications risk losing the right to operate.

A non-obvious requirement is that even firms operating under the transitional arrangement must already comply with MiCA';s substantive conduct-of-business rules, not merely its authorisation procedure. Many operators underestimate this distinction and assume that holding a legacy licence is sufficient to defer full compliance.

How the Financial Intelligence Unit and Finantsinspektsioon divide supervisory responsibility

Until recent reforms, the Financial Intelligence Unit (FIU, or Rahapesu Andmebüroo in Estonian) was the sole licensing authority for virtual currency service providers. The FIU issued licences for virtual currency exchange services and wallet services under the MLTFPA. At its peak, Estonia had issued thousands of such licences, making it one of the most active crypto licensing jurisdictions in the EU.

Following legislative amendments, the FIU';s role has been significantly curtailed. The FIU retains responsibility for anti-money laundering (AML) and counter-terrorist financing (CTF) supervision, including on-site inspections, transaction monitoring oversight, and enforcement of suspicious transaction reporting obligations. However, the FIU no longer issues new virtual currency licences. That function has transferred to the FI under the MiCA framework.

The FI now acts as the competent authority for MiCA authorisation. It reviews applications, assesses the fitness and propriety of management, evaluates governance and internal control frameworks, and grants or refuses CASP authorisation. The FI also supervises ongoing compliance with MiCA';s conduct rules, including client asset protection, conflict-of-interest management, and disclosure obligations.

In practice, an Estonian crypto business must maintain a relationship with both authorities simultaneously. The FIU will continue to examine AML/CTF compliance, while the FI oversees prudential and conduct matters. Founders who are unfamiliar with Estonia';s dual-authority structure often direct all correspondence to one body and neglect the other, which creates compliance gaps.

Licensing requirements under MiCA for crypto businesses in Estonia

A CASP authorisation under MiCA is required for any entity providing crypto-asset services on a professional basis in Estonia or to Estonian clients from an Estonian-registered entity. The services covered include exchange of crypto-assets for fiat or other crypto-assets, operation of a trading platform, execution of orders, placing of crypto-assets, reception and transmission of orders, portfolio management, and custody and administration of crypto-assets on behalf of clients.

To obtain authorisation, an applicant must submit a comprehensive application to the FI. The core requirements include:

  • A registered office and genuine operational presence in Estonia.
  • A detailed business plan describing the services to be provided and the target client base.
  • Governance documentation, including internal policies on AML/CTF, conflicts of interest, and client asset segregation.
  • Evidence of adequate own funds, which vary by service type and are set out in MiCA';s prudential requirements.
  • Fit-and-proper assessments for all members of the management body and qualifying shareholders.

The FI has up to 40 working days to assess a complete application, with the possibility of extension if additional information is requested. In practice, the review process for complex applications often takes longer, particularly where the applicant';s governance arrangements or own-funds calculations require clarification.

A common mistake among foreign founders is submitting an application with a nominal Estonian address and no substantive local presence. The FI scrutinises whether the applicant genuinely manages its operations from Estonia, including whether key decision-makers are accessible and whether the entity has local staff capable of engaging with the regulator.

If you are preparing a MiCA application or assessing whether your current structure meets the FI';s expectations, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.

AML and CTF compliance obligations for virtual asset operators

Estonia';s AML/CTF framework for virtual asset businesses is among the most demanding in the EU, reflecting the country';s experience with high-volume licence issuance and subsequent enforcement actions. The MLTFPA requires all virtual currency service providers to implement a risk-based AML/CTF programme covering customer due diligence (CDD), enhanced due diligence (EDD) for higher-risk clients, transaction monitoring, and suspicious activity reporting to the FIU.

Customer due diligence must be performed before establishing a business relationship and on a risk-sensitive ongoing basis. For crypto businesses, this includes verifying the identity of beneficial owners, understanding the source of funds and source of wealth for higher-risk clients, and screening against sanctions and politically exposed persons (PEP) lists. The MLTFPA sets out specific thresholds above which enhanced measures are mandatory.

Transaction monitoring is a particular area of FIU focus. Crypto businesses must implement systems capable of detecting unusual patterns, including structuring, rapid movement of funds across wallets, and use of mixing or privacy-enhancing services. The FIU has issued guidance on red-flag indicators specific to virtual asset transactions, and firms are expected to incorporate these into their monitoring logic.

Suspicious transaction reports (STRs) must be filed with the FIU without delay once suspicion arises. A non-obvious requirement is that the obligation to report is triggered by suspicion, not by certainty of wrongdoing. Many operators delay reporting while conducting internal investigations, which creates regulatory exposure.

Penalties for AML/CTF non-compliance are substantial. The FIU may issue precept orders, impose fines, and ultimately revoke a licence or recommend revocation of a MiCA authorisation. The FI may also take supervisory measures under MiCA, including public warnings, temporary prohibitions on activity, and withdrawal of authorisation.

Practical scenarios: how the framework applies to different business models

Scenario one: a foreign-owned exchange seeking EU market access through Estonia. A non-EU group wishes to establish an EU-regulated entity to serve European retail clients. It incorporates a subsidiary in Estonia and applies to the FI for MiCA CASP authorisation covering exchange services and custody. The subsidiary must have a genuine Estonian presence, including a local management body with sufficient authority to make operational decisions. The group';s existing compliance policies must be adapted to meet MiCA';s specific requirements, including the obligation to publish a white paper for each crypto-asset listed on the platform. Once authorised, the Estonian entity can passport its services across the EU under MiCA';s single-licence mechanism, making Estonia an efficient gateway for EU-wide operations.

Scenario two: an existing Estonian VASP transitioning from a legacy FIU licence. A company that obtained a virtual currency exchange licence from the FIU under the old MLTFPA regime must now transition to MiCA authorisation. During the transitional period, it may continue operating but must already comply with MiCA';s conduct rules. It must submit a MiCA application to the FI before the transitional window closes. The application requires a full governance overhaul, including the appointment of a compliance officer with demonstrable crypto-sector experience, updated AML/CTF policies, and a revised own-funds calculation. Firms that treat the transition as a simple administrative renewal typically encounter significant delays and requests for supplementary information.

Ongoing compliance obligations and reporting requirements

Once authorised under MiCA, an Estonian CASP faces a continuous set of compliance obligations that extend well beyond the initial licensing process. These obligations are designed to ensure that the firm remains fit to operate and that clients are adequately protected throughout the relationship.

Capital adequacy must be maintained on an ongoing basis. MiCA sets minimum own-funds requirements that vary by service type, and firms must monitor their capital position and report to the FI if they fall below the required threshold. A common mistake is treating the initial capitalisation as a one-time exercise rather than a dynamic obligation.

Client asset protection rules require that crypto-assets held on behalf of clients are segregated from the firm';s own assets and are not used for proprietary purposes without explicit client consent. Firms must maintain records sufficient to identify each client';s holdings at any time.

Annual and periodic reporting to the FI includes financial statements, compliance reports, and notifications of material changes to governance, ownership, or business model. Any change in qualifying shareholders or management body members requires prior FI approval or notification, depending on the nature of the change.

Under the EU';s Transfer of Funds Regulation as extended to crypto-assets (the "travel rule"), Estonian CASPs must collect and transmit originator and beneficiary information for crypto-asset transfers above specified thresholds. Implementing the travel rule requires technical integration with counterparty VASPs and a policy for handling transfers from or to unhosted wallets.

Many operators underestimate the operational burden of the travel rule, particularly when dealing with counterparties in non-EU jurisdictions that have not yet implemented equivalent requirements. The FIU has indicated that it will scrutinise travel rule compliance closely during supervisory examinations.

For assistance with ongoing compliance programme design or regulatory reporting, contact info@vlolawfirm.com. We can assist with documents and filings across both the FIU and FI frameworks.

FAQ

What is the main practical risk for a crypto business operating in Estonia without a MiCA authorisation?

Operating without a valid MiCA authorisation after the transitional period expires constitutes a breach of directly applicable EU law. The FI has the power to issue public warnings, order cessation of activity, and refer matters to other EU competent authorities. Because MiCA authorisation is required across the EU, an unauthorised Estonian entity cannot rely on any other member state';s licence to serve clients. In addition, operating without authorisation may trigger criminal liability under Estonian law for the individuals responsible for managing the entity. The reputational consequences of a public FI enforcement action are also significant for any firm seeking to attract institutional clients or banking relationships.

How long does it take and how much does it cost to obtain MiCA CASP authorisation in Estonia?

The statutory review period is up to 40 working days from receipt of a complete application, but complex cases routinely take longer due to requests for supplementary information. Applicants should budget for a total process of several months from the start of preparation to receipt of authorisation. Costs include state fees payable to the FI, legal and compliance advisory fees for preparing the application, and the cost of establishing the required governance infrastructure. Professional fees for a well-prepared MiCA application typically start from the low tens of thousands of euros, depending on the complexity of the business model and the extent of existing compliance infrastructure. Own-funds requirements add a further capital commitment that varies by service type.

Should a crypto business choose Estonia over other EU jurisdictions for MiCA authorisation?

Estonia remains a credible choice for MiCA authorisation, particularly for firms that already have an Estonian entity or that value the country';s established digital infrastructure and familiarity with virtual asset businesses. The FI has developed sector-specific expertise and has engaged constructively with the industry during the MiCA transition. However, Estonia';s historically strict enforcement approach means that the FI will scrutinise applications carefully and will not grant authorisation to firms with weak governance or AML/CTF frameworks. Firms with complex structures or high-risk business models may find that other EU jurisdictions offer a more accommodating supervisory dialogue. The choice of jurisdiction should be driven by the firm';s specific business model, client base, and existing infrastructure rather than by a general perception of regulatory ease.

Conclusion

Estonia';s crypto regulatory landscape has matured significantly, with MiCA now setting the standard for authorisation and conduct across the EU. Firms operating in or through Estonia must engage seriously with both the FI and the FIU, maintain robust governance and AML/CTF frameworks, and treat the MiCA transition as a substantive compliance exercise rather than an administrative formality. The passporting benefits of a MiCA authorisation make Estonia a strategically attractive base for EU-wide crypto operations, provided the regulatory requirements are met in full.

VLO Law Firms advises international clients on crypto regulation in Estonia. We can assist with MiCA authorisation applications, AML/CTF compliance programme design, FIU and FI correspondence, governance structuring, and ongoing regulatory reporting. To request a consultation, contact: info@vlolawfirm.com