EST · MMXXVI
Home/Jurisdictions/Czech Republic/Crypto exchange setup in Czech Republic: Legal Requirements for Businesses
Licensing & Registration

Crypto exchange setup in Czech Republic: Legal Requirements for Businesses

Crypto exchange setup in Czech Republic. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Crypto Exchange Setup in Czech Republic: Legal Requirements for Businesses

Operating a crypto exchange (a platform facilitating the buying, selling or exchange of digital assets against fiat or other crypto-assets) in the Czech Republic without the correct regulatory authorisation exposes a business to enforcement action, frozen payment rails and the loss of every banking relationship it has built. The Czech Republic sits inside the European Union, which means the MiCA (Markets in Crypto-Assets Regulation) regime, supervised by the Czech National Bank as the national competent authority, now governs the regulated perimeter for crypto-asset service providers. This page maps what an inbound operator needs, how the process works, and where cross-border complexity bites hardest.

What does Czech Republic crypto law actually require of an exchange?

An exchange operating in or from the Czech Republic must hold a CASP authorisation (Crypto-Asset Service Provider authorisation) under the MiCA regime, issued or recognised by the Czech National Bank. Before MiCA's full CASP provisions came into force, Czech law required registration of a virtual asset service provider under the Anti-Money Laundering Act administered by the Financial Analytical Unit. That earlier VASP registration regime is now transitioning, and operators who relied on a legacy registration must map their path to full CASP authorisation. The two regimes run in parallel during the transition period; the practical question for a new entrant is which track applies to its timeline.

MiCA draws the regulated perimeter around specific services: operation of a trading platform for crypto-assets, exchange of crypto-assets for fiat currency, exchange of crypto-assets for other crypto-assets, execution of orders, placement and reception of orders, transfer of crypto-assets, and advice. A business offering any one of those services to clients in the Czech Republic – whether it is incorporated there or elsewhere in the EU – is within scope. The label a business uses for itself is irrelevant. What matters is the economic substance of what it does.

This is the first point where inbound operators miscalculate. A Cayman-registered exchange with a Czech customer base is not outside MiCA's reach simply because the legal entity sits offshore. Regulatory authorisation follows the activity, not just the address of the server.

How does the MiCA CASP authorisation process work in the Czech Republic?

A CASP authorisation in the Czech Republic requires submission of a structured application to the Czech National Bank, covering the business model, governance arrangements, AML/CFT programme, safeguarding and custody policies, IT security documentation, and the key persons fit-and-proper assessment. The Czech National Bank, as national competent authority under MiCA, reviews the application and coordinates with ESMA on any cross-border or passporting dimension. ESMA's role is supervisory convergence, not direct authorisation for most applicants.

The application package is detailed. Regulators across the EU – and the Czech National Bank is no exception – increasingly expect a complete file on first submission. Incomplete files restart the assessment clock. In our practice, the single most common reason for delay is an AML/CFT programme that describes policies at a general level without the transaction-monitoring logic, customer risk-rating methodology or Travel Rule workflow that the regime demands.

The Travel Rule (the obligation under FATF Recommendation 15 to pass originator and beneficiary data with each virtual asset transfer above the applicable threshold) applies to CASPs under MiCA. Compliance infrastructure for the Travel Rule must be in place before the authorisation is granted, not after. Operators that treat this as a post-licensing task discover it during examination and lose significant time.

Timeline is a function of file quality. The statutory assessment period under MiCA is defined in the regulation; extensions are possible where the authority requests additional information. In our cross-border practice, a well-prepared file for a straightforward exchange service typically moves through assessment in a matter of months. Complex multi-service applications take longer. Stating a specific number of weeks without knowing the file's condition would be misleading.

To map your CASP application timeline and file requirements accurately, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the banking arrangements – change the analysis materially.

What happens to businesses that already hold a Czech VASP registration?

Businesses that registered under the legacy Czech AML-based VASP regime have a defined transition window to upgrade to full MiCA CASP authorisation, but that window is not indefinite. The Czech Republic, like all EU member states, implements MiCA's transitional provisions, which allow competent authorities to permit continued operation under national law for a period while the full authorisation is sought. The Czech National Bank has discretion over how that transitional period is administered in practice.

The critical risk for legacy-registered operators is assuming the transition period is automatic and unconditioned. It is not. A business that continues to operate after the transition period closes without a CASP authorisation – or without having applied in good time – is operating without regulatory authorisation. That carries the same enforcement exposure as never having registered at all.

In a recent matter, we advised a payments company that had registered under the prior Czech AML regime and expanded its services while assuming its registration covered the expanded scope. It did not. The mismatch between the registered activities and the actual service offering was identified during a banking review, not a regulatory inspection. We restructured the entity's application before the transition window closed, and the business maintained uninterrupted operation. This outcome depends entirely on early identification – the same situation discovered late carries a materially higher cost and risk profile.

Does a Czech CASP authorisation allow passporting across the EU?

Yes: a CASP authorisation granted by the Czech National Bank under MiCA gives the holder the right to passport its regulated services into other EU/EEA member states without a separate national authorisation in each host jurisdiction. This is one of MiCA's most commercially significant features for an inbound operator choosing a licensing base. The Czech Republic's position as an EU member state makes it a legitimate entry point to the entire single market.

Passporting is not a blanket permission, however. The passport covers the specific services listed in the authorisation. An operator that adds a service after authorisation – for example, a trading platform that later wants to offer custody or transfer services – must notify the Czech National Bank and obtain an extension before offering the new service in host jurisdictions. ESMA's supervisory convergence programme means that national competent authorities are increasingly aligned on what constitutes a material change to an authorisation.

For a business with users across Germany, France, the Netherlands and the Nordics, holding a single Czech CASP authorisation and passporting is almost always structurally cleaner than seeking separate national licences. The analysis changes if the business's primary commercial presence – management, staff, substantial clients – is concentrated in another member state. MiCA expects the authorisation to reflect genuine establishment, not regulatory arbitrage. The Czech National Bank will ask where the business is actually managed from.

What AML and KYC obligations apply to a Czech-authorised crypto exchange?

A CASP authorised in the Czech Republic is subject to the full MiCA AML/CFT framework, reinforced by the EU's AML Directives as transposed into Czech law, and supervised for AML compliance by the Financial Analytical Unit alongside the Czech National Bank's prudential oversight. These two authorities operate on parallel tracks, and a business must satisfy both.

The practical obligations include: a documented customer risk-rating model, enhanced due diligence for high-risk customers and jurisdictions, transaction monitoring calibrated to the exchange's product risk profile, Suspicious Activity Reporting to the Financial Analytical Unit, and Travel Rule compliance for outgoing and incoming virtual asset transfers. The Travel Rule data threshold and the specific technical standards for interoperability with counterparty CASPs vary by the applicable EU implementation; operators should verify current requirements before going live.

One structural point that operators sometimes overlook: MiCA's AML obligations apply to the CASP entity, not merely to an outsourced compliance provider. Boards and senior managers carry personal responsibility for the adequacy of the programme. Regulators in the leading EU hubs increasingly expect senior management to demonstrate they understand the AML/CFT framework, not merely that they have contracted someone to run it.

How does the Czech banking and tax environment interact with a crypto exchange?

Banking access for crypto exchanges remains the most operationally sensitive element of a Czech setup, as it does in most EU jurisdictions. Czech domestic banks apply their own risk appetite to CASP clients; some are receptive to well-regulated, MiCA-authorised operators, while others maintain sector-wide restrictions. Obtaining a CASP authorisation is a necessary condition for banking access, but it is not sufficient. Banks conduct their own due diligence on governance, ownership, source of funds, and the quality of the AML programme – often at a level of detail comparable to the regulatory review itself.

EMI (e-money institution) partnerships and payment service provider arrangements provide an alternative settlement rail where direct banking is unavailable or slow to establish. Operators we advise routinely build a diversified banking and settlement stack before going live, rather than depending on a single counterparty. A single bank rejection at launch is a common and avoidable operational failure.

On the tax side, Czech corporate tax applies to profits of a Czech-established entity in the ordinary way. The tax treatment of crypto-asset transactions – whether gains are characterised as trading income, capital gains, or something else – depends on the legal nature of the entity and the character of the activities. Czech tax law on digital assets has evolved, and the interaction with transfer pricing rules (relevant where a Czech CASP is part of a group with an offshore holding entity) requires specific analysis. We regularly advise on the licence, banking and tax stack together, because the interdependencies are significant and sequential optimisation produces worse outcomes than integrated planning.

If your build is at the banking or tax structuring stage, write to OBOLUS at info@oboluslaw.com. If a prior application stalled or an account was closed, a second review can identify the structural reason and the route forward.

Which operator profile should license in the Czech Republic?

The right licensing base depends on the operator's specific profile. The Czech Republic is well-suited to certain builds and less optimal for others. The following decision framework reflects what we see in practice.

Profile A – EU-focused exchange, limited operations outside Europe. A business targeting EU retail and institutional clients, with management and technical operations based in Central or Eastern Europe, is a strong fit for a Czech CASP authorisation. The jurisdiction's EU membership provides full passporting access; the Czech National Bank is a functioning and accessible competent authority; and operational costs are generally competitive relative to Western European licensing hubs. The key risk is the banking stack – it requires early work.

Profile B – Global exchange with EU as one of several jurisdictions. A business serving users across the EU, the UAE, Singapore and the US simultaneously needs a multi-jurisdictional licence stack. A Czech CASP authorisation covers the EU layer. It does not cover VARA-regulated services in Dubai, MAS-licensed operations in Singapore, or US state money-transmitter requirements. For this profile, the Czech licence is one component of a broader architecture, and the holding structure matters significantly for regulatory and tax efficiency.

Profile C – Offshore operator testing EU market access. A BVI or Cayman-incorporated business looking to access EU clients cannot rely on its offshore registration for EU services. The options are: establish a Czech (or other EU member state) subsidiary and seek CASP authorisation; or appoint a MiCA-authorised entity to distribute services on its behalf. The second option is structurally complex and carries its own regulatory risks. The first is the cleaner path if EU market access is a genuine strategic priority.

Profile D – Legacy Czech VASP registrant seeking continuity. As described above, the transition to CASP authorisation is mandatory. The decision for this profile is the timing and structure of the upgrade application – specifically whether the existing entity structure and governance model is MiCA-compliant, or whether restructuring is required before the application is filed.

What are the most common mistakes in a Czech crypto exchange setup?

In our licensing practice, the same errors appear repeatedly in Czech crypto exchange setups. Identifying them early saves months and, in some cases, the business itself.

The first is treating the AML/CFT programme as a documentation exercise rather than an operational system. Regulators review the programme as if it will be tested in practice – because it will be. A policy manual that was written to satisfy the application and never operationalised will fail examination.

The second is assuming that a general corporate lawyer can manage the CASP application. MiCA is a specialised regime with its own vocabulary, its own technical standards for areas like the Travel Rule, and its own interface with ESMA guidance. The application process requires practitioners who understand the regime in depth, not generalists who are learning it alongside the client.

The third is separating the licence question from the banking question. Both have lead times. Starting the banking relationship in parallel with the regulatory application is standard practice for well-advised operators. Starting it after the authorisation is received – which happens more often than it should – creates a gap that is commercially damaging.

A common assumption among new entrants is that a single offshore registration is a permissible substitute for EU licensing when serving EU clients. It is not. MiCA's territorial scope covers services provided to clients located in the EU regardless of where the provider is incorporated. An offshore operator serving Czech or other EU clients from a Cayman entity, without a CASP authorisation, is outside the law in every EU member state where those clients are located. The enforcement consequences of that position have become progressively more serious as MiCA supervision has strengthened.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timeline depends on the jurisdiction, the service category and the quality of the application file. Under MiCA, the Czech National Bank's assessment period is defined by the regulation, with possible extensions where further information is required. A well-prepared file for a straightforward exchange service typically takes a matter of months from submission to decision. Complex multi-service applications or incomplete files extend that materially. Preparatory work – governance, AML programme, Travel Rule infrastructure – typically adds further lead time before submission.

Which jurisdiction is best for licensing my crypto business?

There is no single best jurisdiction. The right licensing base depends on where your clients are, where your management sits, what services you offer, and how your banking and tax stack needs to function. An EU-focused exchange with European management is often well-served by a Czech or other EU member state CASP authorisation. A globally active business needs a multi-jurisdictional stack. We map the licence, banking and tax architecture before recommending a structure, because the interdependencies determine the answer as much as the jurisdiction itself does.

Do I need a separate custody licence?

Under MiCA, custody and administration of crypto-assets on behalf of clients is a regulated CASP service, listed separately from exchange or trading platform activities. If your exchange holds client assets – which most exchanges do at some stage in the transaction flow – custody is within scope. Whether that requires a separate authorisation or an extension of an existing one depends on how the service is structured and which activities appear in your CASP authorisation. In our practice, the custody question is one of the first we resolve when mapping an exchange's regulated perimeter.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialises in CASP and VASP authorisation strategies for inbound operators entering EU and cross-border digital-asset markets.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours