Operating a crypto exchange in Estonia without the correct regulatory authorisation exposes a business to enforcement action, lost banking relationships and blocked customer onboarding – consequences that arrive faster than most founders expect. Estonia's VASP (virtual asset service provider) regime, supervised by the Financial Intelligence Unit (FIU, or Rahapesu Andmebüroo, RAB), has undergone significant tightening in recent years, moving from a registration model that drew widespread international interest to a full authorisation regime that demands genuine substance in Estonia. For an inbound operator, the question is not simply whether to use Estonia – it is whether your entity, your governance model and your banking stack can meet a regime that now looks closely at physical presence, beneficial ownership and the cross-border reach of your user base.
This page sets out the legal requirements for setting up a crypto exchange in Estonia, the process for obtaining the required authorisation, the cross-border and banking considerations that most applicants overlook, and the point at which the structure should be reviewed by specialist counsel.
What Legal Regime Governs a Crypto Exchange in Estonia?
The Estonian legal basis for crypto-exchange activity sits within the Money Laundering and Terrorist Financing Prevention Act (MLTFPA), which was substantially amended to bring VASP regulation into a single authorisation framework administered by the FIU. Any entity providing virtual currency exchange services – converting cryptocurrency to fiat, fiat to cryptocurrency or one virtual currency to another – requires a virtual currency exchange service authorisation. Wallet service provision (custodial wallet services) requires a separate authorisation, though both are typically pursued together by an exchange operator.
Critically, the regime is activity-based, not entity-based. A foreign company directing exchange services at Estonian users – or routing transactions through an Estonian entity – may trigger the obligation regardless of where it is incorporated. The FIU has made clear that it assesses the economic substance of the applicant: a shell entity with no local management, no local staff and no genuine operational nexus will not receive or retain authorisation.
The EU's MiCA (Markets in Crypto-Assets Regulation) framework, administered by ESMA and the relevant national competent authority, is the overarching EU-level regime. Estonia is a member state, and its national CASP (Crypto-Asset Service Provider) authorisation pathway under MiCA will supersede the existing FIU framework for most exchange activities over the transition period. Operators entering now must plan for MiCA compliance as the primary long-term regime, with the FIU authorisation serving as the bridge to full CASP status.
The process above describes the standard path. Your facts – the entity structure, the user base geography and the banking arrangements – change the analysis materially.
To map the full authorisation requirement for your exchange model, contact OBOLUS at info@oboluslaw.com. We regularly advise inbound operators on the interplay between the current FIU regime and the forward MiCA compliance obligation before a single corporate document is filed.
Who Is Required to Obtain Authorisation in Estonia?
Any business providing virtual currency exchange services to customers – whether retail, institutional or business-to-business – must hold the FIU authorisation if it operates from or through an Estonian legal entity. The obligation extends to companies incorporated in Estonia that conduct activities entirely abroad, to foreign companies with a branch in Estonia, and to platforms that maintain a registered office in Estonia but serve a predominantly non-Estonian user base.
The practical scope of "exchange services" is broad. Peer-to-peer matching platforms, OTC desks, automated market-making services operating under a company umbrella, and hybrid fiat-on/off-ramp services all fall within the regulated perimeter. Payment service wrappers do not displace the VASP authorisation requirement if the underlying activity involves conversion between virtual and fiat currency.
Entities that were registered under the prior lightweight regime must have either transitioned to the new authorisation or ceased activity. The FIU conducted a material review of legacy registrations and withdrew a significant number of them. In our cross-border practice, we have seen operators assume their legacy Estonian registration remained valid for EU market access purposes – an assumption the FIU and, increasingly, EU banking partners do not share.
What Is the Application Process for a Crypto Exchange Authorisation?
The FIU authorisation process is document-intensive and substance-driven; applicants should expect a review that examines the beneficial ownership chain, the AML/CFT compliance programme, the management team's professional fitness, and the technical architecture of the exchange platform.
The application package typically includes: the corporate documents of the Estonian entity (memorandum, articles, registry extract); a detailed description of the services and the technical platform; the AML/CFT risk assessment and internal policies; the compliance officer appointment and evidence of that officer's qualifications; background checks and fit-and-proper documentation for all beneficial owners and board members; the source-of-funds analysis for initial capitalisation; and a business plan demonstrating the genuine Estonian operational nexus.
The FIU reviews the application and may request supplementary information during the process. The timeline from a complete filing to a decision varies by the complexity of the ownership structure and the quality of the initial submission. Incomplete or poorly structured applications routinely extend the process considerably. In our practice, we have seen well-prepared applications for straightforward single-activity authorisations proceed materially faster than multi-activity submissions with complex beneficiary chains – the difference can be measured in months, not weeks.
A compliance officer physically present in Estonia, with demonstrable AML/CFT expertise, is a prerequisite. The FIU has rejected applications where the nominated compliance officer was a nominee or where the officer's relevant experience could not be documented. Fit-and-proper standards for management and beneficial owners (generally those holding a qualifying interest in the entity) are applied rigorously.
What Substance Does Estonia Actually Require?
The Estonian FIU now requires genuine operational substance, and the bar has risen markedly from the pre-2022 environment. An Estonian-authorised exchange must demonstrate that it is managed and directed from Estonia – not simply incorporated there. The compliance function must be local and active. The board, or at minimum a qualifying executive, should be capable of representing the business to the FIU in Estonian or English and of making real business decisions in Estonia.
Physical office premises are expected. A registered-agent address is insufficient. The FIU has revoked authorisations where a post-grant inspection revealed that the premises were shared serviced offices with no dedicated staff, or that the compliance officer's appointment was a paper formality.
Minimum capital requirements apply and are set by the regime; the specific figure varies by the category of activity authorised. Applicants should review the current FIU guidance directly, as these thresholds have changed in line with the regulatory tightening, and the CASP capital requirements under MiCA may differ further. In our cross-border practice, we consistently advise clients to plan for a capital level that reflects genuine operational resilience, not the minimum permitted threshold.
The AML/CFT programme must be proportionate to the risk profile of the business. For an exchange serving international institutional clients, a standard retail-grade AML policy will not satisfy the FIU. Transaction monitoring, Travel Rule compliance (the obligation under FATF Recommendation 15 to pass originator and beneficiary information with virtual asset transfers), and sanctions screening must all be documented and tested.
How Does Cross-Border Banking and Tax Interact With an Estonian Exchange?
Banking for crypto exchanges in Estonia is a known friction point, and it has become a primary commercial risk for inbound operators. Estonian and Baltic banks substantially reduced their exposure to crypto-business clients following the AML enforcement actions of the late 2010s. An authorised exchange does not automatically acquire banking access; the bank makes its own risk assessment, and VASP authorisation is a threshold condition, not a guarantee.
In our practice, we regularly advise clients to engage with the banking question in parallel with, not after, the authorisation process. A business that has obtained FIU authorisation but cannot open a local settlement account is commercially stranded. The practical options typically involve a combination of an Estonian or EU Payment Institution account for fiat settlement, an Electronic Money Institution relationship for customer funds, and potentially a banking correspondent in a jurisdiction with higher VASP appetite. Each layer carries its own regulatory interaction.
The cross-border tax picture matters equally. An Estonian company operating an exchange with users and liquidity providers across the EU faces corporate residency questions (where is management and control?), VAT considerations (Estonia applies EU VAT rules; crypto-to-crypto exchange services are generally VAT-exempt under EU law, but fiat conversion has historically attracted scrutiny), and withholding obligations on payments to non-resident service providers. Estonia's territorial corporate tax model – under which undistributed profits are not taxed at the corporate level, with tax arising only on distribution – is genuinely attractive for a reinvesting exchange, but it requires careful analysis of the PE (permanent establishment) risk created by overseas staff or infrastructure.
MiCA passporting changes the cross-border calculus. An Estonian CASP authorisation, once the MiCA transition is complete, will provide the right to passport exchange services across the EU and EEA without additional per-country authorisation. For operators whose primary target market is the EU, this is a significant structural advantage. For operators whose user base is predominantly non-EU, the CASP authorisation alone does not resolve the regulatory position in third-country jurisdictions – a separate analysis of those markets' requirements is required.
If a prior authorisation application stalled or your banking arrangements have broken down, a second structural read can identify the cause and the route forward. Write to info@oboluslaw.com or message us at t.me/oboluslaw.
How Does MiCA Change the Position for Estonian Exchanges?
MiCA is the governing EU-wide regime for crypto-asset service providers, and it applies directly in Estonia as in all member states. For exchange operators, MiCA creates a harmonised CASP authorisation framework that replaces the national patchwork of VASP regimes – including Estonia's FIU model – for most in-scope activities over the applicable transition period.
Under MiCA, exchange activities (the operation of a trading platform for crypto-assets, the exchange of crypto-assets for fiat and for other crypto-assets) are regulated CASP activities requiring a formal CASP authorisation from the national competent authority – in Estonia, the FIU working in conjunction with the relevant supervisory function. ESMA issues binding technical standards and guidelines that shape how national competent authorities assess CASP applications. Passporting under MiCA requires notification procedures and coordination with the host-state regulator, but it does not require a full licence application in each state.
For operators who entered Estonia under the prior registration model, the MiCA transition is not automatic. A CASP authorisation requires a fresh assessment against MiCA standards. The capital requirements, governance obligations, token-listing rules and market-abuse monitoring obligations under MiCA are materially more demanding than the prior MLTFPA registration. Operators who have not already begun mapping their MiCA compliance posture are behind the curve.
The interaction between the FIU's AML-supervisory function and the CASP authorisation function will also require careful management during the transition period. In our cross-border practice, we have seen operators who focused exclusively on the authorisation track miss parallel AML compliance obligations that triggered FIU scrutiny during the transition.
What AML and Travel Rule Obligations Apply to Estonian Exchanges?
AML/CFT compliance is the operational core of a functioning Estonian exchange authorisation, and the FIU applies a demanding standard. The exchange must maintain a documented AML risk assessment, a compliance programme, a designated compliance officer, an internal audit function proportionate to its size, and the records management infrastructure to respond to FIU information requests promptly.
The Travel Rule – under which an exchange must transmit originator and beneficiary information alongside a virtual asset transfer above the applicable threshold – applies to Estonian-authorised exchanges in line with FATF Recommendation 15 and the EU's Transfer of Funds Regulation (TFR), which extends Travel Rule obligations to virtual asset transfers. The data fields required, the counterparty verification obligations and the handling of unhosted wallet transfers are all points of practical complexity that the compliance programme must address specifically.
Sanctions screening is a live operational requirement. Estonian exchanges must screen against EU consolidated sanctions lists, UN designations and OFAC lists where they have US exposure. The interaction between sanctions obligations and the technical freeze capabilities of stablecoin issuers – Tether (USDT) and Circle (USDC) both hold contract-level freeze authority over their issued tokens – is a compliance consideration that any exchange holding or trading stablecoins must address in its risk framework.
A Cross-Border Restructuring: What Happens When the Entity Does Not Match the Activity
In a recent licensing matter, an exchange operator incorporated in Estonia held a legacy VASP registration but had relocated its actual management, compliance function and technical infrastructure to a third country. The FIU initiated a review; the registration was at risk of revocation. We were engaged to assess the structural position. The analysis identified that the existing Estonian entity could not credibly support an FIU authorisation on its own, but that the group structure included a second EU entity capable of anchoring a MiCA CASP application with genuine substance. We mapped a restructuring path that wound down the Estonian shell responsibly, initiated the CASP application through the qualifying entity and managed the transition in a way that preserved the banking relationships. The business continued operating without a material regulatory gap. No enforcement action was issued.
Which Operator Profile Is Estonia Right For?
Estonia remains a credible EU licensing jurisdiction for the right operator profile, but it is not a low-effort option. The FIU authorisation and MiCA CASP pathway suit a business that can genuinely plant its compliance roots in Estonia: local compliance officer, real premises, management that can engage with the FIU and a capital structure that exceeds the minimum threshold by a meaningful margin.
Profile A – the EU-focused exchange: a business targeting EU retail or institutional clients, committed to passporting across the EEA under MiCA, and willing to build genuine Estonian substance. The FIU/CASP route is well-suited. The timeline to authorisation, when the application is properly prepared, is typically measured in months rather than a year or more. The long-term regulatory dividend – an EU passport with the MiCA brand behind it – is significant.
Profile B – the global exchange with an EU window: a business whose primary market is outside the EU but that needs an EU-regulated entity for institutional counterparty relationships or fiat banking. Estonia can work, but the structure requires careful cross-border tax analysis (PE risk, management-and-control location, transfer pricing for intra-group services) and the banking stack must be planned independently of the authorisation. A single Estonian entity will not resolve the regulatory position in other target jurisdictions.
Profile C – the operator looking for the lightest EU path: the post-2022 Estonian regime is not that path. Operators motivated primarily by cost and speed should consider whether a different EU member state or an offshore VASP regime better fits their near-term profile – and receive honest advice about what that choice means for their EU market access and banking prospects.
In our cross-border practice, we map the licence, banking and tax stack against the operator's actual user base and revenue model before a jurisdiction selection is finalised. A decision made on the basis of the authorisation process alone – without modelling the banking relationships and the forward MiCA compliance cost – routinely produces structural regret.
What Are the Most Common Mistakes in an Estonian Exchange Application?
A common assumption is that the FIU authorisation process mirrors the old registration – that a local lawyer, a standard policy set and a nominee compliance officer will carry the application. This assumption is incorrect and costly.
The mistakes we see most frequently: appointing a compliance officer with no documented AML/VASP experience; submitting an AML risk assessment that is generic and not calibrated to the exchange's specific business model, client base and geography; failing to demonstrate the operational nexus (office, staff, decision-making) before the application is filed rather than promising it as a condition; and ignoring the banking question entirely until after authorisation, then discovering that no Estonian or Baltic bank will onboard the business on its current structure.
The cross-border mistake is equally common: treating the Estonian authorisation as a global licence. It is not. An Estonian CASP authorisation provides EU/EEA market access under MiCA's passporting rules. It does not authorise the business in Singapore, the United Kingdom, the United States, the UAE or any other third-country jurisdiction. Each of those markets – whether MAS under the Payment Services Act, the FCA under the Money Laundering Regulations, VARA in Dubai or the SEC/CFTC/FinCEN nexus in the United States – has its own regulatory perimeter, and the failure to analyse that perimeter is the most expensive oversight in cross-border digital-asset business.
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – our firm-wide approach to VASP and CASP licence advisory across all major jurisdictions.
- Crypto Regulation and Licensing in Kazakhstan (AIFC) – a comparative view of the AFSA regime for operators weighing EU against CIS-region licensing.
- Transfer Pricing for Crypto Groups in the Seychelles – cross-border structuring analysis for groups with a holding or IP layer outside the EU.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence stack across operating, custody and payment layers before you commit – so the authorisation you obtain is one you can actually use. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in VASP and CASP authorisation strategies for inbound operators across EU and non-EU hubs.
FAQ
How long does a crypto licence take to obtain?
The timeline varies by jurisdiction, the complexity of the ownership structure and the completeness of the application. In Estonia, a well-prepared FIU authorisation application for a single activity with a clean beneficial-ownership chain and a credible compliance officer typically proceeds within a matter of months. Multi-activity applications with complex group structures or prior regulatory history take longer. The MiCA CASP transition introduces additional process steps. No responsible adviser can guarantee a specific timeline before reviewing the facts.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. The optimal jurisdiction depends on where your clients are located, what activities you are conducting, where your banking relationships can be established, and the capital and governance resources you can deploy. Estonia suits EU-facing operators who can build genuine local substance. Operators with a global footprint or a non-EU primary market may find that a different jurisdiction – or a multi-licence stack – better matches the regulatory and commercial reality of their business. We map those options before you commit.
Do I need a separate custody licence?
In Estonia, custodial wallet services require their own authorisation, separate from the virtual currency exchange service authorisation. The two are typically applied for together by exchange operators who hold client assets. Under MiCA, custody of crypto-assets on behalf of clients is a distinct regulated CASP activity. Whether you need both depends on whether your exchange model involves the firm holding client private keys or whether it operates on a non-custodial or third-party custody basis. This distinction must be assessed against your technical architecture before the application is filed.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.