A crypto exchange finalizing its European expansion discovers that its offshore payment licence does not satisfy the onboarding requirements of a Polish acquiring bank. The acquiring bank needs to see a regulated payment entity – either a local payment institution (PI) or a passported EU entity – before it will open a merchant account and route card settlements. Without that structure in place, the business cannot collect fiat, cannot pay out to customers and, in practice, cannot operate the European corridor it planned. The legal question is specific: what is required to enter into a payment service provider (PSP) and acquiring agreement in Poland, and how does a digital-asset business satisfy those requirements from a cross-border starting position?
Poland regulates payment services under the national implementation of the EU Payment Services Directive – the second iteration, PSD2 – supervised by the Komisja Nadzoru Finansowego (KNF), Poland's financial supervisory authority. A business seeking a PSP or acquiring relationship in Poland must present either a KNF-issued licence or authorisation, a valid passport notification from another EU member state's competent authority, or registration as a mały instytucja płatnicza (small payment institution, SPI), which carries a volume ceiling. Crypto businesses add a second layer: they must also satisfy KNF's VASP registration requirements under the Polish AML Act, which implements the EU's Fifth and Sixth Anti-Money Laundering Directives. This page sets out the regulated basis, the inbound process, the cross-border interaction with tax and banking, and the practical decision points for an operator choosing Poland as a payment corridor.
What is the regulatory perimeter for payment services in Poland?
The regulated perimeter in Poland covers any business that executes payment transactions, issues payment instruments or acquires payment transactions for merchants – activities that require either authorisation or registration with the KNF under the Payment Services Act. The KNF is the sole competent authority for payment institution licensing in Poland, and it maintains a public register of authorised PIs, SPI registrants and passported EEA entities. A business that processes card payments for a crypto exchange – for example, routing card-funded deposits or merchant settlements – is an acquiring institution and falls squarely within that perimeter.
The perimeter extends to the crypto layer. Under the Polish AML Act, any entity providing exchange services between virtual assets and fiat currency, or custody of virtual assets, must register with the KNF as a dostawca usług w zakresie walut wirtualnych – a virtual asset service provider in the statutory definition. Operating those services without registration is a criminal offence under Polish law. Importantly, VASP registration and payment institution authorisation are two distinct tracks. A business that needs both – for instance, a custodial exchange with integrated card acquiring – must satisfy both regimes. Neither registration alone is sufficient.
The EU's MiCA (Markets in Crypto-Assets Regulation), applied directly in Poland from late 2024 onward under ESMA coordination, overlays a third requirement for certain token-related services. Operators already authorised as MiCA CASPs in another member state benefit from passporting across the EU, including Poland, for the activities covered by the CASP authorisation. The interaction between the MiCA CASP passport, the PSD2 PI passport and the Polish VASP register creates a three-tier compliance picture that operators frequently underestimate.
Who actually needs a PSP or acquiring agreement in Poland?
Any crypto business that intends to accept card payments, process SEPA transfers or route merchant settlements from Polish-resident customers or merchants needs a PSP and, where card schemes are involved, an acquiring relationship. The most common operator profiles are: a centralized exchange wanting to enable PLN or EUR card deposits; a token issuance platform accepting subscription payments from Polish investors; a crypto-payroll or B2B settlement provider routing stablecoin-backed payments to PLN bank accounts; and a marketplace or protocol that wants to offer fiat on-ramp or off-ramp functionality in the Polish market.
In each case, the acquiring bank or PSP counterparty will conduct its own due diligence. That due diligence is not merely KYC formality. Polish acquiring banks – and the international PSPs operating in Poland – apply enhanced scrutiny to crypto-related merchants. They require confirmation of VASP registration status, a clean AML programme audit, proof of regulatory status in the entity's home jurisdiction and, frequently, a legal opinion on the classification of the product being sold. Operators we advise routinely encounter a situation where the commercial terms of an acquiring agreement are agreed but signing stalls because the compliance pack is incomplete. Resolving that stall – assembling the right regulated wrapper around the business – is precisely the work this page addresses.
What is the inbound process for obtaining regulated status in Poland?
The inbound process depends on the operator's starting point: an EU-domiciled entity with an existing PSD2 authorisation in another member state can notify a passport into Poland through the KNF notification procedure, which is the most efficient route. Notification involves the home regulator transmitting a passport notification to the KNF; the KNF then has a statutory period to acknowledge the notification before the entity may commence cross-border services or establish a branch. Timelines vary by member state and the completeness of the notification package, but the process is generally measured in weeks rather than months for a clean notification.
For operators without an existing EU payment licence, there are two primary routes. First, applying for a full instytucja płatnicza (PI) authorisation from the KNF directly – a capital-intensive, document-heavy process with a formal review period that can extend across several months depending on business complexity and the KNF's examination load. Second, registering as a mały instytucja płatnicza (SPI), which is faster and carries lower capital demands but imposes a monthly and annual volume ceiling set by the applicable EU payment services law. For a scaling crypto business, the SPI ceiling is frequently a binding constraint within the first operating year; operators who start on that route often need to convert to a full PI authorisation sooner than projected.
A third route – operating through a third-party licensed PSP as a payment facilitator or sub-merchant – avoids the need to hold a Polish or EU payment licence directly, but shifts the compliance burden to the PSP's own risk appetite for crypto merchants. In practice, most mainstream PSPs apply crypto-merchant policies that restrict or prohibit certain activity categories. Finding a PSP willing to onboard a crypto business and negotiating an acquiring agreement on acceptable commercial and compliance terms is, in our practice, frequently as complex as the licensing process itself.
In parallel with whichever payment route is pursued, the crypto-specific VASP registration with the KNF must be completed before the business commences regulated virtual-asset services in Poland. The registration application requires corporate documentation, details of beneficial ownership, a description of the virtual-asset services, an AML/CFT programme, and evidence that persons responsible for AML compliance meet the statutory fit-and-proper standard. The KNF has broad powers to refuse or revoke registration and will do so where the AML programme is inadequate.
CTA: The process above describes the standard path. Your facts – the entity structure, user base and existing licences – change the analysis materially. Map your options with OBOLUS before committing to a route.
How does the cross-border structure interact with Polish tax and banking?
Structuring a PSP or acquiring agreement in Poland within a cross-border digital-asset group raises corporate tax, VAT and permanent-establishment considerations that must be resolved alongside the regulatory work. A foreign entity that establishes a Polish branch to hold its KNF authorisation or acquiring agreement creates a taxable presence in Poland. Profits attributable to the Polish branch are subject to Polish corporate income tax. The applicable rate and the transfer-pricing rules that govern intragroup payment flows between the branch and the foreign parent entity depend on the group's overall structure – and a structure optimized for speed of licensing is not always optimized for tax efficiency.
VAT is a distinct issue. Under EU law as implemented in Poland, payment transaction services are generally exempt from VAT. But the VAT treatment of crypto exchange services – converting virtual assets to fiat – is not uniformly settled across EU member states and has been the subject of regulatory guidance and national court decisions in several jurisdictions. An operator routing both payment services and crypto exchange services through the same Polish entity needs a clear VAT analysis before going live, because mis-classification affects both the entity's VAT recovery position and its pricing model.
Banking is the third constraint. Polish commercial banks and international banks operating branches in Poland apply enhanced due diligence to crypto-related businesses. Opening a PLN settlement account – necessary for a Polish acquiring relationship – requires satisfying the bank's own risk policies, which typically include a request for regulatory status evidence, a description of transaction flows, identification of all counterparties and an explanation of the stablecoin or digital-asset layer if present. The Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer) compliance posture of the business is increasingly a factor in bank onboarding, even where the immediate transaction being settled is a fiat payment rather than a crypto transfer. We have seen bank onboarding timelines extend significantly where the Travel Rule compliance programme was not documented at the time of the first compliance call with the bank.
What should a PSP and acquiring agreement for a crypto business contain?
A PSP and acquiring agreement for a crypto-related merchant must address several provisions that standard merchant agreements leave silent or handle inadequately. The most important is the scope of permitted activities: the agreement must expressly cover the business model in question – whether that is card-funded crypto purchases, fiat settlement of token sales, or recurring subscription billing for a trading platform. Scope ambiguity in an acquiring agreement is a risk the merchant bears; if the acquiring bank later determines that a class of transactions was not within the agreed permitted scope, it may unilaterally suspend settlement or terminate the agreement.
Reserve and settlement terms are the second critical area. Acquiring agreements for high-risk merchant categories – and crypto is universally classified as high-risk by scheme rules – typically include a rolling reserve, a settlement delay or both. Rolling reserves can represent a material working-capital drag on a crypto business that settles in near-real time on the other side. Negotiating the reserve percentage, the claw-back period and the release mechanism requires an understanding of both the contractual leverage available and the card-scheme rules that constrain what the acquirer can agree to.
Termination and suspension rights are the third area of focus. Standard acquiring agreements grant the PSP or acquirer broad unilateral rights to suspend processing or terminate for cause – including a change in regulatory status, a KNF enforcement action, a scheme-rule violation or reputational concerns. For a crypto business whose operations depend on continuous card processing, a suspension clause that activates on the initiation of a regulatory inquiry – rather than a final adverse finding – is an existential risk. Negotiating a cure period, a notice requirement and a narrower trigger definition is achievable with the right approach, but it requires early engagement with the acquirer's legal team, not a last-minute mark-up of a standard form.
What are the most common mistakes operators make in Poland?
The most consistent mistake is treating VASP registration as the full compliance answer. Registration with the KNF as a VASP is necessary but not sufficient for operating a PSP or acquiring relationship. A business that completes VASP registration but holds no EU payment licence and attempts to process card payments is still operating unlicensed payment services. The two regimes are cumulative, not alternatives, and the KNF supervises both.
The second mistake is launching on a sub-merchant or payment-facilitator arrangement with a third-party PSP before the PSP has completed its own enhanced due diligence on the crypto-business model. Several PSPs in the EU market have standard onboarding processes that do not surface crypto-specific compliance requirements until after go-live. When those requirements emerge mid-operation, the result is a forced suspension of payment processing – exactly the frozen-rail scenario that the operator sought to avoid by using a third-party PSP in the first place.
The third mistake – one we observe with particular frequency in cross-border groups – is assuming that a MiCA CASP authorisation obtained in one EU member state passports the full payment-services activity into Poland. MiCA passporting covers the CASP-regulated activities. It does not passport the acquiring business or the card-processing function, which remains within the PSD2 regime. An operator running both functions needs both passports.
Practice insight: a recent onboarding matter
In a recent cross-border matter, a crypto exchange group holding a MiCA-aligned authorisation in a western European member state sought to establish card acquiring in Poland for its PLN-denominated user base. The group had assumed its CASP authorisation covered the acquiring function. Our review identified that the acquiring activities required a separate PSD2 passport notification to the KNF and that the Polish VASP register entry for the local subsidiary was incomplete. We coordinated the passport notification, remediated the VASP registration pack and negotiated the acquiring agreement's reserve and termination provisions on the group's behalf. The entity was processing card payments within a matter of weeks of the corrected notification being acknowledged by the KNF. The matter illustrated how a single misread of the regulatory perimeter can stall an otherwise compliant structure.
CTA: If a prior application stalled or an account was suspended, a structured review can surface the reason and the route back. Reach the OBOLUS banking desk to start that review.
A common assumption: one offshore licence covers global operations
A common assumption among early-stage operators is that a single offshore licence – a BVI VASP Act registration or a Cayman VASP registration, for example – is sufficient to serve customers and enter into acquiring agreements globally. It is not. Polish law, EU law and the card-scheme rules require regulated status in the relevant EU jurisdiction for any business accessing EU payment infrastructure or serving EU-resident customers at scale. An offshore registration addresses FATF-compliance obligations in the offshore jurisdiction; it does not satisfy the KNF's licensing requirements, the PSD2 acquiring requirements or the MiCA CASP authorisation requirement in Poland or elsewhere in the EU. Operating on the assumption that an offshore wrapper is sufficient exposes the business to KNF enforcement, scheme-level termination and the reputational consequences of a public regulatory action – all of which are harder to resolve after the fact than before.
The practical implication for an inbound operator is a structured assessment of where regulation is required at each layer: the entity layer, the payment layer and the VASP layer. Each layer has its own regulator, its own timeline and its own capital or operational requirement. Mapping all three before committing capital to an EU expansion is the decision that separates a smooth market entry from an enforcement-driven restructuring eighteen months later.
Which operator profile should take which path?
Profile A – an operator already holding a full PI or EMI authorisation in another EU member state: the efficient route is a PSD2 passport notification to the KNF, combined with VASP registration if virtual-asset services are in scope. Timeline is measured in weeks for a complete notification package. The key risk is underestimating the VASP registration requirement and the enhanced KYC demands of Polish acquiring banks on crypto merchants.
Profile B – an operator with no existing EU payment licence, planning to serve the Polish market primarily: the choice is between applying for a KNF PI authorisation directly or incorporating in a faster EU licensing hub (Lithuania or Malta, for example, under their MiCA-transitional regimes) and passporting into Poland. The direct-KNF route may produce a deeper relationship with Polish banks and regulators; the passport route is faster but adds a cross-border management layer. Timeline for direct KNF PI authorisation varies by complexity and is generally measured in months, not weeks.
Profile C – a scaling exchange that needs speed to market and volume above the SPI ceiling: starting on an SPI registration is likely to constrain the business too quickly. That profile should pursue full PI authorisation or a strategic relationship with an existing EU-licensed PSP willing to onboard crypto merchants, while the full licence application proceeds in parallel. Neither path is without risk; the decision turns on the specific volume projections, the acquiring bank's risk appetite and the timeline to first transaction.
Profile D – a business whose product is a stablecoin or payment token with characteristics that bring it within MiCA's ART or EMT category: the payment layer must be preceded by a MiCA issuer authorisation from the relevant NCA, after which the CASP passport and the PSD2 passport can be layered. Poland is the market; the authorisation will typically need to be obtained in a member state with a faster NCA review process, then passported. This profile requires the most lead time of the four and should begin legal structuring well before commercial launch.
Related at OBOLUS
- Banking, payments and EMI onboarding for digital-asset businesses – how we structure the payment and banking layer for exchanges, custodians and token issuers across EU and non-EU jurisdictions.
- EMI onboarding for VASPs in Hong Kong – the regulated onboarding process for virtual-asset service providers seeking fiat rails in Hong Kong under SFC and HKMA oversight.
- Real-world asset tokenization for regulated entities – structuring token issuance, custody and transfer within the applicable regulatory perimeter for institutional issuers.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – so that the acquiring relationship you build on does not need to be rebuilt after a regulatory event. We advise crypto exchanges, custodians, token issuers and funds across more than seventy licensing jurisdictions. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because the business fails their enhanced due diligence review – either the regulatory status is unclear, the AML programme is insufficient, or the transaction flows cannot be satisfactorily explained. Crypto-related businesses are classified as high-risk under the AML frameworks applicable to EU banks. A business that presents complete VASP registration evidence, a documented Travel Rule compliance programme and a clear description of its transaction flows is materially better positioned to retain and open accounts than one that cannot produce those materials on request.
How can a VASP onboard with an EMI?
A VASP (virtual asset service provider) seeking to onboard with an EMI (electronic money institution) must satisfy the EMI's own risk-based due diligence process, which typically requires regulatory status documentation, beneficial ownership disclosure, an AML policy aligned to FATF Recommendation 15 and a description of the virtual-asset services offered. Some EMIs have developed dedicated crypto-business onboarding tracks; others apply standard enhanced-due-diligence criteria. The process is generally measured in weeks for a complete application; incomplete or ambiguous submissions extend the timeline significantly.
What does client-money safeguarding require?
Under PSD2 as implemented in Poland, a payment institution must safeguard client funds – money received from payment service users – by holding them in a segregated account at a credit institution or investing them in secure, liquid, low-risk assets. The safeguarding obligation attaches from the point the PI receives client funds and continues until settlement. For a crypto business operating a PSP relationship, the interaction between the fiat safeguarding requirement and any stablecoin or digital-asset float held in parallel must be structured carefully to ensure each pool meets its own regulatory requirements.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in EU payment services regulation, VASP registration requirements and the cross-border compliance stack for digital-asset businesses entering regulated European markets.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.