Global Law Experts Logo
vasp licence estonia

Talk with Our Expert

Jonathon Richards

Global Law Experts

Lead Enquiries Qualification
Delete Article

How to Apply for a VASP Licence in Estonia Step‑by‑step for Founders & Compliance Leads

By Jonathon Richards
– posted 7 minutes ago

Estonia was one of the first EU member states to establish a dedicated registration framework for virtual‑asset service providers, and the country remains a strategic base for crypto businesses serving European markets. However, the regulatory landscape has changed materially. Obtaining a VASP licence in Estonia now means navigating the transition from legacy registrations administered by the Financial Intelligence Unit (Rahapesu Andmebüroo, or FIU) to full Markets in Crypto‑Assets Regulation (MiCA) authorisations supervised by Finantsinspektsioon, Estonia’s financial supervisory authority. This guide distils the current requirements, step‑by‑step filing process, capital thresholds, timeline expectations, and MiCA transition actions into a single, regulator‑sourced reference built for founders, compliance leads, and the advisors supporting them.

Who should read this: Anyone preparing a new virtual‑asset or crypto‑asset service provider application in Estonia, as well as operators holding legacy FIU authorisations who must migrate to MiCA CASP authorisation before the transitional deadline of 1 July 2026. The page consolidates regulator citations, internal checklists, and practical commentary so you can begin the process with confidence.

Quick Summary & Who Qualifies for an Estonia Crypto License

Before diving into the detailed process, here are the essential eligibility criteria and fast facts every applicant should know:

  • Legal entity requirement: Applicants must be an Estonian legal person (typically an osaühing / OÜ private limited company) or a branch of an EEA‑registered entity.
  • Minimum capital thresholds: Capital minima depend on the specific crypto‑asset services offered. Under MiCA, thresholds range from €50,000 to €150,000, as defined in Estonian legislation transposing EU requirements.
  • Fit & proper management: Directors and beneficial owners must demonstrate relevant professional experience, clean criminal records, and personal integrity.
  • AML/CFT controls: Comprehensive anti‑money‑laundering policies, a designated compliance officer, and a money‑laundering reporting officer (MLRO) are mandatory.
  • Local substance: Decision‑making, compliance functions, and at least one management board member should be based in Estonia.
Fast Facts VASP Licence Estonia
MiCA transitional deadline 1 July 2026
Finantsinspektsioon portal opens 18 March 2026
Regulatory application fee €3,000 (indicative confirm with Finantsinspektsioon)
Typical total timeline 3–6 months (preparation through decision)

Pre‑Application Checklist What to Confirm Before You Start

Business Model & Service Mapping

Identify exactly which MiCA service categories your platform will offer custody and administration of crypto‑assets, operation of a trading platform, exchange services (crypto‑to‑fiat or crypto‑to‑crypto), execution of orders, placement, transfer, or advisory services. Each category triggers specific capital, governance, and disclosure obligations. Mapping services early avoids scope creep and regulatory queries later.

FATF/AML Status & Sanctions Screening

Prepare documentary evidence that beneficial owners and senior managers are not subject to international sanctions and have no adverse AML/CFT findings. Screen all relevant persons against EU, UN, and OFAC lists. Compile screening results and retain audit trails the regulator expects to see the methodology as well as the output.

Management & Key Personnel

Assemble CVs, diplomas, and professional references for every proposed board member, compliance officer, and MLRO. The regulator looks for demonstrated experience in banking, financial services, or information technology. Where managers are foreign nationals, obtain certificates of clean criminal record from their home jurisdictions, apostilled or legalised as appropriate.

Banking and Payment Rails Readiness

Securing a corporate bank account with an Estonian or EEA bank remains one of the most time‑consuming steps. Begin the banking relationship process early and have confirmation of fiat on‑ramp and off‑ramp rails before filing. The regulator will ask how client funds flow through the business.

Technology Readiness Checklist

Document your custody model (self‑custody vs third‑party custodian), wallet architecture (cold, warm, hot), key‑management procedures, and the results of any security audits or penetration tests. If you intend to rely on a third‑party technology vendor, prepare due‑diligence files and draft outsourcing agreements.

A downloadable regulator checklist summarising all preparation items is available see the closing section for access details.

Entity Setup & Local Substance

Choosing the Right Entity Type

The standard vehicle is an osaühing (OÜ), Estonia’s private limited company, with a minimum share capital of €2,500 (general corporate law minimum; the VASP/CASP‑specific capital layer sits above this). An aktsiaselts (AS, public limited company) may be appropriate for larger operations but carries higher formation and governance costs. Share capital must be fully paid in before the licence application is filed.

Local Substance Expectations

Finantsinspektsioon expects genuine Estonian substance not a shell structure. At a minimum, this means a physical office address (not merely a registered agent), at least one management board member resident in Estonia, local employment of compliance and operational staff, and Estonian or EEA bank accounts. Decision‑making should demonstrably take place within Estonia.

Non‑Resident Founders: Options and Risks

Non‑residents may establish and own an Estonian VASP entity, but the regulator scrutinises nominee or proxy arrangements closely. A local authorised representative or director can satisfy substance requirements; however, nominee directors who lack genuine involvement raise red flags. Industry observers expect Finantsinspektsioon to intensify substance reviews through 2026 as part of MiCA onboarding. Founders outside the EEA should plan for at least one credible local management appointment and budget for relocation or frequent in‑country presence. For detailed guidance on Estonia company formation for crypto businesses, see the related resource.

Governance, AML/CFT & Tech/Security

Governance Framework

The board of directors bears ultimate responsibility for regulatory compliance. Applicants must present a clear organisational chart showing reporting lines, a designated compliance officer independent from revenue‑generating functions, an MLRO with direct escalation authority, and for larger operations an internal audit function. Board meeting minutes, a delegation of authority matrix, and written terms of reference for each governance body should be prepared before filing.

AML/CFT Policies

Under the Money Laundering and Terrorist Financing Prevention Act (MLTFPA), every VASP must maintain written policies covering customer due diligence (KYC/KYB), risk classification of clients and transactions, enhanced due diligence for high‑risk categories, ongoing transaction monitoring, and suspicious transaction reporting (STR) workflows to the FIU. Include a sample document list in your application pack:

  • Risk appetite statement: Board‑approved statement defining the firm’s tolerance for money‑laundering, terrorism‑financing, and sanctions risk.
  • Customer onboarding policy: Step‑by‑step KYC/KYB procedures, document collection, and verification timelines.
  • Transaction monitoring rules: Thresholds, scenarios, and alert‑handling procedures.
  • STR filing manual: Internal escalation and filing process, including template forms and FIU contact protocols.
  • Record‑keeping policy: Retention periods (minimum five years under MLTFPA) and secure storage arrangements.

Sanctions Screening

Integrate real‑time sanctions screening at onboarding and on an ongoing basis against EU consolidated sanctions lists, UN lists, and where commercially relevant OFAC SDN lists. Document the technology vendor, screening frequency, false‑positive handling process, and escalation procedures.

Custody & Segregation Model

If your services involve holding clients’ crypto‑assets, the regulator expects a detailed custody policy covering key‑generation ceremonies, multi‑signature or multi‑party computation (MPC) architecture, segregation of client assets from proprietary holdings, reconciliation schedules, and insurance or reserve arrangements. MiCA introduces explicit custodial obligations applicants should design their custody model to meet both the current Estonian requirements and MiCA Article 75 standards.

Cybersecurity & Operational Resilience

Finantsinspektsioon expects applicants to demonstrate robust information‑security controls. Relevant evidence includes SOC 2 Type II or ISO 27001 certification (or a credible roadmap), recent penetration‑test reports, an incident‑response plan with defined notification timelines (to the regulator, to clients, and to CERT‑EE), and a business‑continuity/disaster‑recovery plan with tested recovery‑time objectives.

Evidence Pack: What the Regulator Wants to See

Compile all governance and compliance documentation into a structured evidence pack. Typical contents include a policy index, full organisational chart, board and committee terms of reference, security‑test results, outsourcing and third‑party agreements, and a data‑protection impact assessment. A well‑indexed evidence pack significantly reduces regulator queries and accelerates processing. For templates and worked examples, see the AML compliance checklist resource.

Capital & Financials for a VASP Licence in Estonia

Minimum Capital Requirements by Service Type

Under the MiCA framework as transposed into Estonian law, minimum own‑funds requirements vary by service category. The following illustrative thresholds are drawn from MiCA Article 67 and the corresponding Estonian legislative provisions:

  • Custody and administration / operation of a trading platform: €150,000 minimum permanent capital.
  • Exchange services (crypto‑to‑fiat or crypto‑to‑crypto), execution of orders on behalf of clients, placement, reception and transmission of orders: €125,000.
  • Advisory services, portfolio management, transfer services: €50,000.

Applicants offering multiple service categories must meet the highest applicable threshold. Capital must be genuinely available not encumbered, borrowed on a short‑term basis, or subject to call‑back arrangements.

Sources of Funds & Proof of Capital

Submit recent bank statements (typically no older than 30 days), shareholder declarations on the origin of funds, and if capital is provided via equity injection evidence of the shareholder’s own source of wealth. Escrow arrangements are acceptable in some circumstances but must be documented with the escrow agent’s confirmation letter.

Liquidity Planning & Financial Projections

Finantsinspektsioon expects a three‑year business plan including profit‑and‑loss projections, cash‑flow forecasts, and at least two stress‑test scenarios (e.g., sharp decline in trading volumes, major cyber‑incident). The financial model should demonstrate that the entity can sustain operations and meet regulatory capital at all times, including during adverse conditions.

Fees & Other Charges

The Finantsinspektsioon application processing fee is approximately €3,000. Applicants should also budget for notarisation and apostille fees, external audit costs (if required for capital verification), and legal and advisory fees, which vary depending on the complexity of the application but typically range from €15,000 to €50,000 in aggregate for a well‑prepared submission.

Accounting & Reporting Expectations

Licensed entities must file periodic financial returns with Finantsinspektsioon and maintain AML reporting obligations to the FIU. Annual accounts must be audited by an approved auditor, and any material change in the financial position of the entity must be notified to the regulator without delay.

Process Submitting the Application: Forms, Notary, Portal & What to Include

The following numbered steps outline how to get a VASP licence (or, from 18 March 2026, a CASP authorisation) through the Finantsinspektsioon filing process:

  1. Internal readiness check: Run through the pre‑application checklist above and confirm every item is addressed. Assign a project manager and set internal deadlines.
  2. Incorporate or confirm the Estonian entity: Register the OÜ with the Estonian Commercial Register, prepare articles of association, a shareholder list, and obtain an up‑to‑date registry extract.
  3. Appoint management and compliance officers: Collect identification documents, CVs, professional references, and certificates of clean criminal record for all proposed directors, the compliance officer, and the MLRO.
  4. Prepare AML/CFT, custody, incident‑response, and governance documents: Ensure all policies meet MLTFPA and MiCA standards; index them clearly.
  5. Prepare finance pack: Capital proof (bank confirmations, shareholder source‑of‑funds declarations), three‑year business plan, and stress‑test scenarios.
  6. Notarisation: Certain corporate documents and powers of attorney require notarisation. Foreign‑origin documents typically need apostille or consular legalisation.
  7. Submit via the Finantsinspektsioon application portal: From 18 March 2026, all applications are filed electronically. Include the full document pack and observe submission‑format requirements (PDF, signed digitally where possible).
  8. Pay the application fee: Transfer the €3,000 processing fee as directed and acknowledge the stated processing timelines.
  9. Respond to regulator queries and inspections: Be prepared for requests for supplementary information and, in some cases, on‑site or remote interviews with management and compliance officers.
  10. Receive the decision: If authorised, prepare an onboarding and client‑migration plan particularly if you are transitioning from a legacy FIU VASP registration.

Forms & Templates

The Finantsinspektsioon portal provides standard application forms. Accompanying documents typically include: completed application form, articles of association, Commercial Register extract, fit‑and‑proper questionnaires for each key person, AML/CFT policy suite, custody policy, business plan with financial projections, capital‑proof documentation, technology and security documentation, and an organisational chart.

Common Documentary Deficiencies and How to Avoid Them

Regulator feedback consistently highlights the same deficiency categories: incomplete or outdated criminal‑record certificates, AML policies that are generic templates rather than tailored to the applicant’s business model, missing stress‑test scenarios in financial projections, and unclear custody segregation arrangements. Assign a senior compliance reviewer to perform a final quality‑assurance pass before submission.

Timeline & What to Expect

Processing timelines vary based on the completeness and quality of the application, the complexity of the proposed business model, and the regulator’s current workload. The table below summarises typical durations observed in practice:

Milestone Typical Duration
Internal preparation & document assembly 4–8 weeks
Entity incorporation (if new) 1–2 weeks
Submission to first regulator response 6–12 weeks
Supplementary information rounds 2–6 weeks (1–3 rounds typical)
Full decision (from submission) 3–6 months

Expect at least one round of supplementary questions. Well‑prepared applications with a complete evidence pack typically receive fewer queries and reach a decision more quickly. If the application is refused, the regulator will provide written reasons. Re‑application is possible but will require all identified deficiencies to be remedied; industry observers note that a poorly handled first submission can materially delay subsequent attempts.

Post‑Licence Obligations

Receiving the licence is the beginning not the end of regulatory engagement. Key ongoing obligations include:

  • Periodic financial returns: File regulatory returns with Finantsinspektsioon on the schedule specified in the licence conditions (typically quarterly or annually depending on size and risk profile).
  • AML reporting: Continue filing STRs and other AML reports to the FIU; maintain transaction‑monitoring systems and update risk assessments at least annually.
  • Governance and recordkeeping: Keep board minutes, compliance reports, audit trails, and client records in accordance with statutory retention periods.
  • Material change notifications: Notify Finantsinspektsioon of any change in directors, significant shareholders (10% or more), control structure, business model scope, outsourcing arrangements, or registered address.
  • Supervision activities: Be prepared for on‑site reviews, thematic inspections, and ad‑hoc information requests. Non‑cooperation or late filing can trigger enforcement action, including licence revocation.

MiCA / CASP Transition Dates & Actions

The Markets in Crypto‑Assets Regulation (MiCA) entered into application for crypto‑asset service providers on 30 December 2024. Article 143(3) provides a transitional period allowing member states to permit existing nationally authorised providers to continue operating. In Estonia, this transitional period expires on 1 July 2026. After that date, all legacy FIU VASP registrations cease to be valid.

Legacy FIU holders must file a CASP authorisation application with Finantsinspektsioon before the deadline, upgrade their AML/CFT and governance policies to MiCA standards, and prepare for supervision by Finantsinspektsioon rather than the FIU. ESMA has issued guidance emphasising orderly wind‑down obligations for providers that fail to obtain authorisation by the deadline.

New applicants should apply directly to Finantsinspektsioon for a MiCA CASP authorisation via the portal that opened on 18 March 2026. There is no longer a pathway to obtain a standalone FIU VASP registration.

Passporting: A significant advantage of the MiCA CASP authorisation is the ability to passport services across all EEA member states through a notification procedure. Operators planning cross‑border activity should factor passporting notifications into their launch timeline.

Comparison Table FIU (Legacy VASP) vs MiCA CASP (Finantsinspektsioon)

Feature FIU VASP (Legacy) MiCA CASP (Finantsinspektsioon)
Supervisor Rahapesu Andmebüroo (FIU) Finantsinspektsioon
Type of permission Registration / authorisation under MLTFPA Full licence (authorisation) under MiCA
Capital minima €100,000 (flat legacy requirement) €50,000–€150,000 (tiered by service category)
Passporting across EEA Not available Available via notification procedure
Portal & filing body FIU application (historic) Finantsinspektsioon e‑portal (from 18 March 2026)
Ongoing supervision scope AML/CFT focused Comprehensive: prudential, conduct, AML/CFT, governance
Key dates / transition status Registrations expire 1 July 2026 Applications accepted from 18 March 2026; sole regime from 1 July 2026

Downloadable Checklist & Further Reading

A comprehensive application‑preparation checklist covering entity setup, documentation, capital, and AML/CFT readiness is available for download. For further authoritative reading, consult the regulator and legislative sources referenced throughout this guide, including the Finantsinspektsioon portal, the FIU guidance pages, Riigi Teataja (Estonian legislation), and EUR‑Lex (MiCA full text). For related advisory resources, see licensing support from Global Law Experts.

Sources

FAQs

How do I apply for an Estonian VASP licence?
From 18 March 2026, applications are submitted electronically via the Finantsinspektsioon application portal. You must incorporate an Estonian legal entity, assemble a complete document pack (including AML policies, capital proof, governance documents, and fit‑and‑proper evidence for key personnel), pay the processing fee, and respond to any regulator queries. The step‑by‑step process is detailed in the submission section above.
Key documents include the completed application form, articles of association, Commercial Register extract, fit‑and‑proper questionnaires and criminal‑record certificates for directors and the compliance officer, a tailored AML/CFT policy suite, custody and security documentation, a three‑year business plan with financial projections and stress tests, and proof of regulatory capital (bank statements and shareholder source‑of‑funds declarations).
Including internal preparation, applicants should allow three to six months from initial document assembly to final decision. The regulator typically issues an initial completeness response within six to twelve weeks of submission. Well‑prepared applications with a complete evidence pack tend to reach a decision within three to four months; complex or deficient filings can take longer.
Under MiCA, minimum own‑funds requirements range from €50,000 to €150,000 depending on the service categories offered. Local substance requirements include a physical office in Estonia, at least one management board member resident in the country, local employment of compliance staff, and Estonian or EEA bank accounts. These expectations are drawn from Estonian legislation transposing MiCA and from Finantsinspektsioon supervisory practice.
Yes. Legacy FIU VASP registrations will cease to be valid on 1 July 2026 when the MiCA transitional period expires. All operators must hold a MiCA CASP authorisation issued by Finantsinspektsioon to continue providing crypto‑asset services in Estonia and the broader EEA from that date.
Non‑residents may own an Estonian VASP/CASP entity, but genuine local substance is required. This typically means appointing at least one management board member who is resident in Estonia and establishing a real office and local compliance presence. Nominee arrangements that lack genuine decision‑making involvement are subject to heightened regulator scrutiny and carry material risk of application refusal.

Our Expert

Jonathon Richards

Global Law Experts

By Awatif Al Khouri

posted 4 hours ago

Find the right Advisory Expert for your business

The premier guide to leading advisory professionals throughout the world

Specialism
Country
Practice Area
ADVISORS RECOGNIZED
0
EVALUATIONS OF ADVISORS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Join
who are already getting the benefits
0

Sign up for the latest advisor briefings and news within Global Advisory Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.

Naturally you can unsubscribe at any time.

About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Global Law Experts App

Now Available on the App & Google Play Stores.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Contact Us

Stay Informed

Join Mailing List
About Us

Global Advisory Experts is dedicated to providing exceptional advisory services to clients around the world. With a vast network of highly skilled and experienced advisors, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Global Law Experts App

Now Available on the App & Google Play Stores.

Contact Us

Stay Informed

GAE

Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Apply for a VASP Licence in Estonia Step‑by‑step for Founders & Compliance Leads

Send welcome message

Custom Message