EST · MMXXVI
Home/Jurisdictions/Estonia/VASP licensing in Estonia: Legal Requirements for Businesses
Licensing & Registration

VASP licensing in Estonia: Legal Requirements for Businesses

Vasp licensing in Estonia. Independent digital-asset law for exchanges, issuers and funds. Fixed-fee scope, end-to-end. Contact OBOLUS counsel today.

Operating a virtual asset business in Estonia without the correct licence is not a calculated risk – it is an accelerating liability. The Estonian Financial Intelligence Unit (Rahapesu Andmebüroo, or RAB) has materially tightened its supervisory stance since the regime's inception, and the consequences of non-compliance now include enforcement action, frozen payment rails and the permanent loss of banking relationships. For any exchange, custodian or token-related service provider considering an Estonian establishment, the first question is no longer whether to licence – it is whether the current Estonian path still fits the business model, given the EU's transition to MiCA (the Markets in Crypto-Assets Regulation) and the CASP authorisation framework that will govern digital-asset businesses across the entire bloc.

Estonia was, for years, the leading European entry point for VASP (virtual asset service provider) registration. The RAB issued licences in volume, and the jurisdiction attracted a significant share of the EU's crypto business community. That era is over. Regulatory reform, sharply higher compliance standards and the phased displacement of national regimes by MiCA have fundamentally changed the calculus. This page sets out what the current regime requires, what an inbound operator must demonstrate, how the cross-border tax and banking interaction works, and where Estonia sits in a rational licence-jurisdiction decision today.

The Current Regulatory Regime in Estonia

Estonia's VASP regime is administered by the Financial Intelligence Unit (RAB), which holds supervisory, licensing and enforcement authority over virtual currency service providers under Estonian law. The regime covers two core activities: providing a virtual currency exchange service (fiat-to-crypto, crypto-to-fiat and crypto-to-crypto exchange) and providing a virtual currency wallet service (custody of private keys on behalf of clients). Both require a licence from the RAB before any activity commences. Operating without a valid licence exposes the business to administrative sanctions, licence refusal and, in serious cases, criminal referral.

The RAB's supervisory posture shifted decisively in the early 2020s. Faced with a registry populated by thousands of entities that held licences but demonstrated no genuine local substance, the authority introduced minimum substance requirements, stricter fit-and-proper assessments and enhanced AML/CFT controls aligned to the FATF Recommendations – including Recommendation 15 on virtual assets and the Travel Rule (the obligation to pass originator and beneficiary data with every qualifying transfer). The effect was substantial: many previously registered entities lost their licences, and the RAB's active licence register contracted sharply. What remains is a regime that demands real organisational presence and a functioning compliance architecture, not a letterbox registration.

The medium-term horizon is equally important. Under MiCA, national VASP regimes across the EU will be superseded by the CASP (crypto-asset service provider) authorisation framework administered by national competent authorities aligned to ESMA. Estonia's transition path means that businesses currently operating under an RAB licence will need to obtain a MiCA CASP authorisation to continue serving EU customers beyond the national transition window. An inbound operator today must therefore evaluate the RAB licence not in isolation but as a step toward, or alongside, a full MiCA CASP authorisation.

Who Needs a Licence in Estonia?

Any legal entity providing virtual currency exchange or wallet services to customers – regardless of where those customers are located – that is incorporated or operating in Estonia requires an RAB licence. The scope is activity-based, not entity-type-based. A company incorporated under Estonian law that routes all transactions through non-Estonian infrastructure still falls within the RAB's jurisdiction if it is conducting regulated activities. Equally, a foreign entity that establishes a branch or otherwise conducts these activities from Estonian territory requires authorisation.

The practical perimeter extends further than many operators initially assume. A platform that enables peer-to-peer crypto trading, even if it does not itself hold client funds, may fall within the exchange service definition. A non-custodial wallet provider that exercises any degree of control over private keys – even temporarily – likely falls within the wallet service definition. In our practice, we regularly advise founders who have self-assessed as outside the licence perimeter, only to discover that a specific feature of their product architecture pulls them inside it. Early perimeter analysis is the lowest-cost intervention in the licensing process.

Mid-page note: The perimeter question is fact-specific. A business model that sits just outside the RAB's current scope may still attract MiCA CASP obligations once the EU transition is complete. Both analyses run in parallel.

If you are assessing whether your business model requires an Estonian VASP licence – or a MiCA CASP authorisation – a scoped perimeter analysis is the right starting point. The process above describes the standard path. Your facts – the entity structure, the user base, the banking relationships – change the analysis. Map your options with our licensing team before committing to an entity or a jurisdiction.

What Does the RAB Application Require?

An Estonian VASP application is a substantive compliance exercise, not an administrative form-fill. The RAB requires a fully developed set of documents demonstrating that the applicant meets the fit-and-proper, substance, and AML/CFT standards before a licence is granted. The core requirements can be grouped across four dimensions.

Entity and ownership. The applicant must be an Estonian company (a private limited company, osaühing, is the standard vehicle). The share ownership structure must be disclosed fully, with ultimate beneficial owners identified and verified to the RAB's satisfaction. All shareholders holding a qualifying interest, and all members of the management board, are subject to fit-and-proper assessment – covering professional background, financial soundness and the absence of relevant criminal convictions.

Local substance. The RAB requires genuine organisational presence. A management board member must be a resident of Estonia or, at minimum, be demonstrably accessible and accountable to the RAB in Estonia. A registered address that is also a real operational address – not a virtual office – is expected. In our practice, we have seen applications rejected or delayed specifically because the substance test was not met at the time of filing.

AML/CFT framework. The applicant must submit a comprehensive anti-money-laundering and counter-terrorist-financing policy package, including a risk assessment, customer due-diligence procedures, transaction monitoring protocols, a Travel Rule compliance methodology and a designated Money Laundering Reporting Officer (MLRO). The MLRO must be identifiable, qualified and resident or demonstrably accessible in Estonia. This is the component that most frequently causes delays for inbound operators: a generic policy copied from another jurisdiction's template will not pass RAB scrutiny.

Capital and financial standing. The RAB requires evidence of adequate financial resources. The specific minimum capital threshold is set by the applicable legislation and should be confirmed against current requirements at the time of application – the figure has been subject to revision and the model writes this qualitatively: operators should treat the capital requirement as a material entry cost that varies by the specific activity licences sought, and confirm the current threshold directly with counsel or the RAB before filing.

How Long Does the Estonian Licensing Process Take?

The RAB's formal review period, from a complete application to a licensing decision, typically runs to several weeks under the statutory clock – but in practice, the total elapsed time from initial preparation to a granted licence is substantially longer. The preparation phase – building the AML/CFT policy suite, establishing the Estonian entity, completing the beneficial-ownership disclosure and conducting the fit-and-proper assessments – typically requires a number of months before a file-ready application can be submitted. We regularly advise clients to build a realistic pre-filing runway into their project plan: rushing the preparation phase is the single most common cause of rejection or drawn-out supplementary-information requests.

The RAB has, in recent years, issued supplementary-information requests in a significant proportion of applications it receives. Each such request resets part of the clock. Applications filed with incomplete AML documentation, unresolved fit-and-proper questions or inadequate substance arrangements generate the highest volume of queries. A well-prepared application – with every document in order at the time of filing – is materially more likely to proceed without interruption. That is the practical value of front-loading the compliance investment.

The timeline also interacts with the MiCA transition. An operator licensing today in Estonia must plan for the subsequent CASP authorisation process under MiCA, which will require a further application to the RAB as the national competent authority under the MiCA regime. Businesses that treat the Estonian VASP licence as a long-term solution without factoring in the MiCA transition risk a gap in their authorisation status at a critical point in the EU's regulatory calendar.

Cross-Border Tax and Banking: The Practical Reality

An Estonian VASP licence opens a European legal presence but does not, by itself, resolve the banking and tax questions that determine whether the business is operationally viable. In our cross-border practice, we regularly see operators who obtained an RAB licence and then discovered that their banking options were more constrained than anticipated.

Banking. Estonian and EU banks have, in general, reduced their appetite for crypto-related clients following the supervisory pressures of recent years. An operator with an RAB licence will not automatically receive a corporate bank account; most Estonian banks will require sight of the full licensing file, the AML/CFT framework, source-of-funds documentation for shareholders, and a clear business model narrative before making a credit decision. Banking relationships for licensed crypto businesses in Estonia are obtainable but require active origination, not passive assumption. Operators who plan the banking origination in parallel with the licensing process – rather than after the licence is granted – consistently achieve faster go-live timelines.

Tax. Estonia operates a distinctive corporate tax regime: retained profits are not taxed; the tax event for corporate income tax arises only on profit distribution. This can be structurally advantageous for reinvestment-heavy digital-asset businesses. However, tax treatment of token transactions, staking rewards and trading income is jurisdiction-specific and evolves with regulatory classification. Estonian VAT treatment of crypto services also requires case-by-case analysis. We advise operators to map the tax stack – corporate, VAT and withholding – before committing to the Estonian structure, particularly where the business serves customers across multiple EU member states and where the entity will also carry the MiCA CASP authorisation.

The cross-border user problem. A licensed Estonian VASP may serve EU customers with the benefit of EU membership – but it does not automatically have the right to serve customers in non-EU jurisdictions. A business that serves US users, for example, faces a separate US regulatory analysis (under the SEC, CFTC and FinCEN frameworks) regardless of its Estonian licence status. We have seen operators build a compliant EU structure and then create liability in a second jurisdiction by assuming the Estonian licence travels. It does not.

A Recent Licensing Matter

In a recent licensing engagement, a payments technology company incorporated outside the EU sought to establish an Estonian entity for a crypto exchange and custody product targeting European retail users. The initial application was refused by the RAB on substance grounds: the proposed management board lacked genuine local presence, and the AML/CFT policy package had been adapted from a non-EU template that did not reflect the RAB's current expectations on Travel Rule compliance. We were engaged at the re-application stage. We restructured the management layer to include a resident board member with demonstrable decision-making authority, rebuilt the AML/CFT framework from scratch using a risk-assessment methodology aligned to the RAB's published guidance, and coordinated the banking origination in parallel. The re-application was approved within the RAB's statutory review period, and the business launched its EU product within the quarter.

Estonia vs. Other EU Licensing Options: Where Does It Fit?

Estonia remains a viable EU licensing jurisdiction for businesses that can meet the substance and AML/CFT requirements – but it is no longer the default choice for EU VASP entry. Operators weighing EU licensing options should consider the following decision logic, based on operator profile.

Profile A: a lean exchange or custody business seeking EU market access, with capacity to meet the RAB's substance requirements. Estonia is a competitive option. The regulatory framework is well-understood, the RAB has published guidance, and – once the substance and AML/CFT thresholds are met – the path to a MiCA CASP authorisation under the Estonian NCA is a known quantity. The timeline, from preparation start to live licence, is best described as a matter of several months for a well-prepared applicant.

Profile B: a business requiring rapid EU market access with minimal local presence. Estonia is not the right choice under the current regime. The RAB's substance requirements make a low-footprint approach non-viable. Lithuania's Bank of Lithuania and the MFSA in Malta are alternative EU starting points, each with distinct postures on substance and capital – though all are converging on the MiCA CASP standard. The practical differences between EU licensing jurisdictions are narrowing as MiCA harmonises the baseline.

Profile C: a business seeking to combine EU licensing with a broader international stack. The Estonian entity can anchor the EU layer, but the full structure will need to address the non-EU markets separately – through, for example, a MAS-licensed Singapore entity for APAC, or a VARA-licensed Dubai entity for MENA and offshore users. The licensing, banking and tax implications of the multi-entity structure require coordinated analysis before the first entity is incorporated. We map the full stack – operating, custody and payment layers – across jurisdictions before clients commit capital and structure.

A common assumption among operators is that a single licence in a well-regarded EU jurisdiction is sufficient to serve clients globally. It is not. The EU VASP or MiCA CASP authorisation covers EU-nexus activity. Every other market – the US, APAC, MENA, Latin America – has its own regulatory analysis. Operators who build on this assumption regularly discover the gap only when a regulator or a bank surfaces it.

If a prior Estonian application stalled, or if your banking relationships were disrupted following a regulatory review, a second read of the structure can surface the reason and the route back. We have supported re-applications and structural remediation across multiple EU jurisdictions. Map your options with our licensing team.

Self-Assessment: Are You Ready to Apply?

Before filing an Estonian VASP application, an operator should be able to answer yes to each of the following questions. These are the criteria the RAB will assess; gaps identified before filing are fixable. Gaps discovered during RAB review create delays and, in some cases, refusals.

  • Is the Estonian entity legally incorporated, with a registered address that constitutes a genuine operational presence?
  • Have all ultimate beneficial owners been identified, and is supporting documentation ready for RAB submission?
  • Has a fit-and-proper assessment been completed for each management board member and qualifying shareholder?
  • Is the AML/CFT policy suite complete – covering risk assessment, CDD, enhanced due diligence, transaction monitoring, Travel Rule methodology and MLRO designation?
  • Does the designated MLRO have the qualifications, authority and accessibility that the RAB expects?
  • Have the capital and financial-standing requirements been confirmed against current RAB thresholds, and is the capital demonstrably available?
  • Has a banking origination strategy been defined, with at least one bank having seen the licensing file?
  • Has the MiCA transition timeline been built into the operational and legal plan?
  • Has the cross-border user perimeter been mapped – identifying which non-EU markets require separate licensing analysis?

In our experience, operators who work through this checklist methodically before filing submit cleaner applications and achieve faster licensing outcomes. The RAB has limited appetite for iterative supplementary-information exchanges; a complete file at first submission is the strongest competitive advantage in the process.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

The elapsed time from preparation start to a granted licence varies by jurisdiction and application quality. In Estonia, a well-prepared applicant working from a complete file can expect a total process measured in several months – covering entity setup, AML/CFT framework development and the RAB's formal review period. Underprepared applications generate supplementary-information requests that extend the timeline materially. In other EU jurisdictions, comparable timelines apply, with variation based on the national competent authority's current caseload and the completeness of the submission.

Which jurisdiction is best for licensing my crypto business?

There is no single best jurisdiction. The right choice depends on your business model, your target user base, your ownership structure, your banking requirements and your appetite for ongoing compliance cost. Estonia suits operators who can meet its substance and AML/CFT requirements and want EU market access with a MiCA transition pathway. Businesses with a broader international footprint typically require a multi-jurisdiction stack – an EU anchor, plus a licensed entity in the APAC or MENA hub that serves users in those regions. We map this analysis before clients commit to any structure.

Do I need a separate custody licence?

In Estonia, wallet services (custody of virtual currency private keys on behalf of clients) are a separately licensed activity from exchange services. An operator providing both exchange and custody requires authorisation covering both activities. Under MiCA's CASP framework, custody and administration of crypto-assets on behalf of clients is a defined service category requiring specific authorisation. Operators building a combined exchange-and-custody product should confirm the licence scope at the outset – structuring an application to cover only the exchange activity and then adding custody later creates regulatory risk during the gap period.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions – including Estonian VASP and MiCA CASP pathways – on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around every structure. Digital assets are the whole of our practice. We map the licence, banking and tax stack across operating, custody and payment layers before you commit capital and entity structure. To discuss your situation, contact info@oboluslaw.com or reach us via t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in EU and APAC VASP licensing strategy, MiCA CASP transition structuring and inbound establishment for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours