EST · MMXXVI
Home/Jurisdictions/Estonia/Vara licence application in Estonia: Legal Requirements for Businesses
Licensing & Registration

Vara licence application in Estonia: Legal Requirements for Businesses

Vara licence application in Estonia. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

A payments company preparing to serve European retail clients faces an immediate question: which regulated base gives it both EU passporting rights and a credible AML posture from day one? Estonia has long been the answer many operators reach for first. Its VASP registration (virtual asset service provider registration under the Estonian crypto licence regime) was, for nearly a decade, among the fastest and lightest entry points in the EU. That environment has changed. Enforcement tightened, the Financial Intelligence Unit – Rahapesu Andmebüroo, or RAB – became materially more demanding, and MiCA (the EU Markets in Crypto-Assets Regulation, administered at European level by ESMA and by national competent authorities) now sits above the domestic regime. What follows is a precise account of what the Estonia licensing process requires today, how it interacts with MiCA's CASP authorisation path, and where a cross-border operator should place this jurisdiction in its licensing stack.

The Estonian Regulatory Regime for Crypto Businesses

Estonia regulates virtual asset service providers through the Financial Intelligence Unit – RAB – which acts as the supervisory authority for both virtual currency service providers (VCSPs, the Estonian-law category) and conventional AML-supervised entities. The regime sits within the Estonian Money Laundering and Terrorist Financing Prevention Act, known generically as the MLTFPA. Under the applicable provisions, any business providing exchange services between virtual currencies and fiat currencies, exchange services between virtual currencies, transfer services, or custody and administration of virtual assets for clients must hold a valid Estonian VCSP licence before operating.

RAB does not merely register applicants – it assesses substantive compliance. Since a significant tightening of requirements, the authority expects a physical management presence, a resident compliance officer with verifiable AML expertise, a full AML/CFT programme, and IT and cybersecurity documentation that meets the standards the European Banking Authority has articulated for payment institutions. An application that treats Estonia as a rubber-stamp jurisdiction will fail at the due-diligence stage. We have seen that pattern repeatedly in our licensing practice, and it is the single most common cause of refused or protracted applications.

The CTA bridge: If you are evaluating Estonia as your EU entry point for the first time, the analysis below maps the standard process. Your specific entity structure, the nationalities of your beneficial owners, and your planned user base will each affect the assessment.

For a scoped analysis of whether Estonia fits your structure, contact OBOLUS at info@oboluslaw.com.

Who Needs a VCSP Licence in Estonia?

Any business providing virtual asset exchange, transfer, or custody services to clients – regardless of where those clients are located – must hold an Estonian VCSP licence if it operates from an Estonian legal entity or offers those services into Estonia. The obligation attaches to the activity, not the label the operator gives itself.

The four activity categories that trigger the licensing requirement are: (1) exchange between virtual currencies and fiat currency; (2) exchange between different virtual currencies; (3) transfer of virtual currency on behalf of a client; and (4) custody and wallet services. A business conducting any one of these activities without a licence exposes itself to administrative sanctions, criminal referral, and – critically – the banking consequences that flow from an unlicensed status. European correspondent banks and payment processors routinely screen for VCSP registration status before opening or maintaining accounts. Operating without the right licence does not merely risk enforcement; it severs the payment rails that make the business viable.

The activity perimeter has expanded in parallel with enforcement activity. RAB has pursued enforcement actions against entities that claimed to fall outside the definition by calling their services "software" or "infrastructure." Token issuers that also provide wallet services, and DeFi front-ends that intermediate transfers, should assume they are within scope and seek a formal analysis before operating.

What Does the Application Process Involve?

The Estonian VCSP application is a structured documentation exercise submitted to RAB, covering corporate fitness, management suitability, and the operational AML/CFT programme. The application package has grown substantially since the 2020–2022 licence cull, when RAB cancelled several thousand registrations and began requiring genuine substance.

The core submission components are:

  • A completed application form with corporate documentation – incorporation documents, share register, ownership chart to ultimate beneficial owners (UBOs).
  • A detailed business plan describing the services, target markets, anticipated transaction volumes, and the technology stack.
  • AML/CFT policies and procedures: a full written programme covering customer due diligence (CDD), enhanced due diligence (EDD) for high-risk relationships, transaction monitoring, sanctions screening, and suspicious activity reporting.
  • A risk assessment, including the business's own analysis of its exposure to money laundering and terrorist financing risk.
  • Management background documentation: CVs, identity documents, and certificates of no prior criminal conviction for each director and beneficial owner holding a qualifying stake.
  • Evidence of the compliance officer's appointment, qualifications, and practical AML experience.
  • IT and cybersecurity documentation, including data security policies and, where relevant, evidence of penetration testing or external audit.
  • Evidence of a physical registered address in Estonia with genuine operational substance – a virtual office is not sufficient.

RAB may request supplementary information at any stage. The review period varies by application quality and current RAB workload. Well-prepared submissions from entities with clean beneficial ownership and experienced management have received decisions in a matter of weeks; more complex structures, or applications requiring multiple rounds of supplementary queries, can extend to several months. RAB has the statutory authority to reject an application where it is not satisfied on any of the substantive criteria.

MiCA Transition: How Estonia Fits the EU CASP Regime

From mid-2025, MiCA's CASP authorisation requirements apply directly across the EU, including Estonia, superseding the prior national-only VCSP registration as the primary regulated status for crypto-asset service providers. An Estonian VCSP registration obtained before MiCA's application date benefits from a transitional period under the applicable MiCA provisions, but that period is finite and the business must progress to full CASP authorisation before the transition window closes.

The practical implication for inbound operators is significant. A business that registers in Estonia today is not simply obtaining a national licence; it is entering the beginning of a process that leads to EU CASP authorisation. ESMA and RAB will both be relevant supervisory actors. The CASP regime imposes requirements that go beyond the current VCSP framework in several respects: own-funds requirements calibrated by service category, a formal whitepaper or disclosure regime for certain services, conduct rules on order execution and client classification, and a custody segregation standard. Operators that plan only to the VCSP stage without modelling the CASP upgrade are making a structural planning error.

The passporting mechanism is the principal advantage. A CASP authorised by an EU national competent authority – including RAB acting in its MiCA capacity – may passport its services across all EU and EEA member states without re-authorisation in each. For a business with a pan-European client base, that single authorisation is materially more efficient than maintaining multiple national registrations. The cross-border question is therefore not whether to use Estonia, but whether Estonia is the right national gateway to that EU passport, relative to alternatives such as Lithuania, Malta, or a larger financial-centre member state.

Cross-Border Interaction: Banking and Tax

Banking access for an Estonian VCSP is not automatic. Estonian-domiciled crypto businesses have experienced material difficulty obtaining and maintaining euro accounts with domestic and correspondent banks. Several Lithuanian and Latvian payment institutions have served as the primary banking layer for Estonian-registered VCSPs, but those relationships are increasingly subject to their own KYC scrutiny of the crypto business's end customers. A realistic banking plan must be modelled before the licence application is filed, not after.

The structural question for many operators is whether the Estonian entity is the operating company, the licensed entity, or simply the regulated holding point, with operational flows routed through a related entity in a different jurisdiction. That structure has tax consequences. Estonia's corporate income tax regime is deferred – distributed profits are taxed at the point of distribution, not on accrual. That feature is attractive for reinvestment-heavy businesses, but it interacts with the EU's anti-avoidance directives and with the domestic rules of the jurisdictions where the group's customers, employees, and economic substance actually sit. A structure that puts the licence in Tallinn and the operations in a different EU member state may trigger permanent establishment risk in the operations jurisdiction.

The Travel Rule (the FATF obligation requiring originator and beneficiary information to accompany virtual asset transfers above the applicable threshold) applies in Estonia under the MLTFPA and will continue under MiCA's applicable provisions. Cross-border transfers from Estonian-licensed entities to counterparty VASPs in other jurisdictions require Travel Rule-compliant messaging. Operators whose back-end infrastructure is not Travel Rule-ready before the application is filed will face a condition precedent from RAB during the review process.

A Common Assumption Worth Examining

A common assumption among operators entering the EU market is that a single offshore licence – in the BVI, Cayman Islands, or another non-EU common-law jurisdiction – is sufficient to serve EU clients. That assumption is incorrect in the MiCA environment. MiCA applies to crypto-asset service providers that offer services to clients located in the EU, regardless of where the provider is incorporated. A non-EU CASP that markets services to EU residents without authorisation is operating unlawfully under the applicable MiCA provisions, exposing itself to enforcement action by any of the 27 member-state NCAs. The offshore structure may remain relevant for other parts of the business – for example, for serving non-EU clients, or as a fund vehicle – but it does not replace EU regulatory authorisation for EU-facing activities.

The correct framing is a layered licence stack: the EU CASP authorisation for EU-facing services, potentially combined with a non-EU VASP registration (BVI, Cayman, or AIFC/AFSA in Kazakhstan, for example) for other market segments. We map that stack before a client commits to any single jurisdiction, precisely because the interaction between EU rules and offshore structures is the area where cross-border operators most commonly expose themselves to double-regulation or enforcement gaps.

Illustrative Matter: Exchange Operator Restructuring for MiCA

In a recent licensing matter, a mid-size exchange operating under an early-vintage Estonian VCSP registration sought to assess its position ahead of the MiCA transitional deadline. The entity had been registered before the 2022 enforcement wave and its AML programme had not been updated to reflect RAB's current expectations or the CASP conduct requirements. We conducted a gap analysis across the AML/CFT programme, the beneficial ownership structure, and the own-funds position. The analysis identified two structural issues: a nominee arrangement in the ownership chain that would not satisfy RAB's UBO transparency requirement, and a custody practice that commingled client assets in a way inconsistent with the CASP segregation standard. The client restructured both before filing the CASP upgrade application. The matter resolved without an enforcement referral and the application proceeded on a clean evidentiary record.

Which Operator Profiles Benefit from an Estonian Base?

Estonia works best as a licensing base for a specific set of operator profiles. A pan-European exchange or payment business that needs an EU CASP passport, has the operational resources to staff a compliant Estonian entity, and is prepared to invest in the full AML/CFT infrastructure is a natural fit. The jurisdiction has an established tech-sector ecosystem, English-language government interfaces, and digital public infrastructure that genuinely reduces administrative friction relative to some other member states.

It is less well-suited to an operator that wants a minimal-presence vehicle, that has a complex or opaque ownership structure, or that is primarily serving non-EU markets and does not need the EU passport. For that operator profile, a non-EU VASP jurisdiction – BVI, Cayman, AIFC – may be more efficient, with the EU licensing question addressed later when EU market entry becomes a priority.

A business sitting between the EU market and a non-EU client base should model both licensing layers explicitly. The EU CASP authorisation governs EU-facing activity. The non-EU VASP registration governs the rest. The tax and banking structure must accommodate both – which is where allied counsel in the relevant jurisdictions becomes part of the engagement.

If a prior Estonian application stalled, or a banking relationship closed after a RAB query, a structured second read can identify the gap and the path forward. Write to OBOLUS at info@oboluslaw.com.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

The timeline varies materially by jurisdiction and application quality. In Estonia, a well-prepared VCSP application – with clean beneficial ownership, an experienced compliance officer, and a complete AML/CFT programme – has historically been decided within weeks. More complex structures, or applications requiring supplementary information rounds, extend that period to several months. Under MiCA, CASP authorisation timelines are set by the applicable regime; they are generally measured in months, not days. RAB's current review capacity and caseload also affect the practical timeline at any given point.

Which jurisdiction is best for licensing my crypto business?

There is no single best jurisdiction. The right answer depends on your client base, your service type, your beneficial ownership structure, your banking relationships, and your growth plan. An EU CASP passport makes Estonia or another EU member state the logical base for EU-facing services. A non-EU VASP registration in BVI, Cayman, or AIFC suits operators primarily serving non-EU markets. Many businesses need both layers. We map the licence, banking, and tax stack across all relevant jurisdictions before a client commits to any one path, because the interactions between layers are where the material risks concentrate.

Do I need a separate custody licence?

In most leading regimes, custody of client virtual assets is a separately regulated activity. Under the Estonian VCSP regime and under MiCA's CASP framework, custody and wallet services require specific authorisation – they are not automatically covered by an exchange or transfer licence. The same principle applies in Singapore under the Payment Services Act, in Hong Kong under the VASP licensing regime, and in the UAE under VARA's activity-based licence structure. Whether your planned custody activity triggers a separate authorisation, or is captured within a combined service-category licence, depends on the applicable regime and the precise scope of your service. We assess that question as part of every licensing mandate.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking, and compliance structures that sit around them. We map the licence stack across operating, custody, and payment layers before you commit – so the structure works from the first application, not after the first enforcement query. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in EU and cross-border VASP licensing, MiCA transition structuring, and multi-layer licence stack design for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours