Operating a virtual-asset business in Poland without the correct registration exposes the entity to supervisory enforcement, immediate account termination by correspondent banks, and – under the European Union's converging MiCA (Markets in Crypto-Assets Regulation) regime – potential exclusion from the entire EU single market. For exchanges, custodians and token issuers already active or planning a Polish entry, the question is not whether to engage the local regime; it is how quickly and in what sequence.
Poland requires virtual-asset service providers to register with the national supervisory authority before conducting regulated activity. The registration obligation sits under Poland's domestic anti-money-laundering and counter-financing of terrorism (AML/CFT) framework, which transposes the EU's AML directives and incorporates FATF Recommendation 15 on virtual assets. As MiCA's CASP authorisation regime fully matures across the EU, Polish-registered operators will transition to – or simultaneously prepare for – the broader CASP authorisation framework supervised by ESMA and Poland's competent authority. This page sets out the registration basis, the process for an inbound business, the cross-border banking and tax interaction, and the decision criteria that determine whether Poland is the right entry point for a given operator profile.
What Activities Require VASP Registration in Poland?
Any business providing virtual-asset services on a professional or commercial basis in Poland must register as a VASP (virtual asset service provider) before it begins operating. The regulated perimeter covers exchange activity between virtual assets and fiat currencies, exchange between different virtual assets, operating a virtual-asset trading platform, and the transfer of virtual assets – including custody-adjacent transfer services. A business that onboards Polish residents or directs marketing into Poland from a foreign entity may also trigger the domestic registration requirement, regardless of where the legal entity is incorporated.
The substance-over-structure principle applies firmly here. Regulators assess the real economic activity and the location of the customer relationship, not merely the address on a certificate of incorporation. In our practice, we have seen Polish enforcement proceedings initiated against operators who assumed that a non-EU holding structure exempted them from local registration obligations. That assumption was wrong in every instance we reviewed.
Custody services – holding or controlling private keys on behalf of clients – are themselves a regulated activity under the applicable VASP provisions and, at the MiCA layer, will require separate CASP authorisation. An operator offering both exchange and custody services must account for both activity heads in its compliance architecture from day one.
Who Regulates VASPs in Poland?
The Polish Financial Supervision Authority (KNF – Komisja Nadzoru Finansowego) acts as the primary supervisory body for financial-market participants, and it is the authority that handles the registration of virtual-asset service providers. Separately, the General Inspector of Financial Information (GIIF – Generalny Inspektor Informacji Finansowej), operating under the Ministry of Finance, is the AML supervisory authority with jurisdiction over VASPs as obligated entities.
In practice, an inbound operator must satisfy both bodies. KNF registration establishes the right to conduct business. GIIF supervision imposes the ongoing AML/CFT obligations – customer due diligence, transaction monitoring, Suspicious Activity Report (SAR) filing, and the Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer). Under the applicable FATF-aligned provisions, Polish VASPs must implement Travel Rule compliance for transfers above the relevant threshold, which varies by instrument and direction of the transfer.
Under MiCA, Poland's competent authority will also assume CASP authorisation responsibilities alongside ESMA's coordination role. Operators planning a Polish base for EU-wide passporting need to map both the current domestic registration and the forthcoming CASP authorisation timeline into a single project plan.
For a scoped assessment of your Poland entry – covering registration, AML build and the MiCA transition – contact OBOLUS at info@oboluslaw.com.The process above describes the standard path. Your facts – the entity structure, the user base, the banking relationships – change the analysis materially.
How Does the VASP Registration Process Work in Poland?
VASP registration in Poland follows a structured administrative process, but the quality of the application file – not the filing itself – determines the outcome and the timeline. The process moves in three broad phases: pre-filing preparation, submission and review, and post-registration compliance activation.
In the pre-filing phase, the operator must establish a Polish legal entity or a branch of a foreign entity with the required registered presence. The entity must appoint a compliance officer with demonstrable AML expertise, adopt an internal AML/CFT policy, and develop an internal procedure document that addresses customer risk classification, transaction monitoring methodology, SAR escalation, and the Travel Rule. These documents are not formalities; the reviewing authority reads them and may return the application for supplement if they are incomplete.
The submission phase involves filing the registration application with the relevant authority, including the entity documents, the AML policies, identification of beneficial owners, and evidence of the fit-and-proper standing of the management team. Polish VASP registration does not carry the same capital-adequacy requirements as a full MiCA CASP authorisation, but the authority expects management to demonstrate professional competence in financial services or digital-asset markets.
Once registered, the operator must activate its compliance programme immediately. GIIF supervision begins from the date of registration. Ongoing obligations include annual AML risk assessments, staff training records, transaction monitoring logs, and the maintenance of a Travel Rule-capable transfer system. Operators who register but delay implementation of the compliance infrastructure face enforcement risk from the first customer transaction.
Indicative timelines vary by the completeness of the filing. A well-prepared application typically moves through administrative review in a matter of weeks. Incomplete or remediated applications extend that window materially. We advise clients to treat eight to twelve weeks as the conservative working assumption for a clean first filing, while acknowledging that authority workload and application quality are the dominant variables.
How Does MiCA Change the Picture for Polish Operators?
MiCA's CASP authorisation regime changes the compliance calculus for every EU-registered virtual-asset business, and Poland is no exception. Under MiCA, a CASP authorised in one EU member state may passport its services across the EU and EEA – a material commercial advantage for any operator building a European user base. Poland, as an EU member state, is a qualifying jurisdiction for that passport.
The transition from domestic VASP registration to MiCA CASP authorisation is not automatic. Existing registered VASPs must apply for CASP authorisation within the transition window provided under the applicable MiCA provisions. Operators that delay this application risk losing their operating authorisation and their banking relationships simultaneously, since payment institutions and banking partners are tracking MiCA compliance status as a condition of correspondent access.
For operators structured in Poland, the strategic decision is therefore a two-horizon one: register now under the existing domestic regime to maintain operating continuity, and begin the CASP authorisation preparation in parallel. These are not sequential projects; they run concurrently, and the documentation built for domestic registration forms the foundation of the CASP file.
Poland also interacts with the MiCA token regimes. Operators issuing asset-referenced tokens (ARTs) or e-money tokens (EMTs) face a heavier authorisation burden than exchanges or custody providers, including whitepaper obligations, reserve requirements and specific disclosure rules under the applicable MiCA provisions. Token issuers considering Poland as their EU base should build the MiCA token-issuer requirements into the entity structure from the outset.
What Is the Cross-Border Banking and Tax Reality for a Polish VASP?
Registration alone does not solve the banking problem. Polish commercial banks remain cautious about onboarding VASPs, reflecting a pattern consistent across the EU where correspondent banking appetite for digital-asset businesses lags regulatory progress. Operators entering Poland should anticipate a structured banking outreach process that runs in parallel with the regulatory filing.
In our practice, we have seen operators obtain Polish VASP registration within the expected timeline but then spend considerably longer establishing a functional banking relationship. The account-opening process typically requires the operator to present its AML policy, its KYC procedures, its Travel Rule solution, its beneficial ownership structure, and – increasingly – its MiCA transition plan to the prospective banking partner's compliance team. Banks that do onboard VASPs often impose transaction monitoring conditions and periodic reporting requirements at the account level.
EMI (electronic money institution) accounts with regulated EU-based e-money institutions represent an alternative or supplement to traditional banking. Several EU-based EMIs have developed VASP-specific onboarding programmes, though their capacity is finite and their due diligence is equally rigorous. The practical question for an inbound operator is whether its compliance build is credible enough to satisfy both the regulator and the banking partner – and those assessments, while independent, cover substantially the same ground.
On the tax side, Poland applies its domestic corporate income tax rules to virtual-asset activity, with specific provisions addressing exchange gains, mining income and certain token transactions. VAT treatment of crypto-to-crypto exchanges follows the EU pattern established by the Court of Justice of the EU, treating such exchanges as VAT-exempt financial transactions. Staking rewards and token-issuance proceeds carry different characterisations depending on the structure and rights conferred. Cross-border operators with Polish entities must also consider transfer-pricing documentation for intra-group service flows and the interaction of Polish tax rules with the tax regime of any parent or holding jurisdiction. We advise that tax structuring runs alongside the licensing build, not after it.
To map the licence, banking and tax stack for your Polish structure, write to info@oboluslaw.com.
If a prior application stalled or a banking relationship was declined, a second read often surfaces the structural gap and the route to resolution.
How VASP Registration Unblocked a Cross-Border Payments Operator
In a recent licensing matter, a payments company with an existing EU e-money framework sought to add virtual-asset transfer services to its product suite through a Polish entity. The company's initial application had been returned for supplement twice – once for an inadequate Travel Rule procedure and once for insufficient documentation of the beneficial ownership chain through a multi-layer holding structure. We conducted a full compliance-architecture review, rebuilt the AML policy to explicitly address the Travel Rule at the threshold applicable in Poland, and provided a detailed beneficial ownership narrative with supporting corporate documents. The application was approved within the subsequent review cycle. Banking followed within a matter of weeks of registration, with the compliance file serving directly as the bank's KYC pack for the entity.
Which Operator Profiles Should Consider Poland?
Poland suits a specific range of operator profiles, and it is not the optimal entry point for every digital-asset business. Understanding which profile benefits most from a Polish registration – as distinct from a Malta, Lithuanian or other EU CASP filing – is the decision the analysis comes down to.
Profile A – The inbound EU-market builder. An operator with no existing EU regulatory footprint, seeking a cost-effective, credible EU VASP registration as the foundation for a future CASP authorisation and EU passport. Poland offers a structured regime, a functional legal system, and a supervised but proportionate approach to the initial registration. Timeline to registration: weeks, assuming a clean and complete filing. Key risk: banking availability requires a concurrent outreach process.
Profile B – The operator with existing EU coverage seeking a second jurisdiction. A business already registered in Lithuania or Malta that wants a complementary Polish operational entity – for example, to service a specific Central and Eastern European user base or to establish payroll, compliance headcount, and operational substance in Poland. Timeline: aligned to the standard registration process. Key risk: inter-jurisdictional AML coordination across two VASP registrations must be documented, and the group Travel Rule solution must cover both entities.
Profile C – The token issuer building for the EU market. A business intending to issue ARTs or EMTs under MiCA and evaluating which EU member state should host the issuing entity. Poland is a viable option, but the CASP authorisation requirements for token issuers are materially heavier than for exchange-only operators. This profile should weigh the competence and track record of the Polish competent authority in reviewing MiCA token-issuer applications against established alternatives. Key risk: the MiCA ART/EMT review process involves substantive engagement with the competent authority and requires well-developed whitepaper and reserve documentation from day one.
A common assumption in the market is that a single offshore licence – a BVI VASP registration or a Cayman registration – is sufficient to serve EU clients at scale. That assumption understates the reach of MiCA's market-access controls and the practical effect of banking partners' compliance checks. EU-directed activity from an offshore entity, where no EU presence is established, carries growing enforcement and de-banking risk as MiCA supervision intensifies.
What Are the AML and Travel Rule Obligations for Polish VASPs?
Polish VASPs are obligated entities under the applicable AML/CFT provisions, subject to GIIF supervision and full FATF Recommendation 15 compliance expectations. The practical compliance programme has several non-negotiable elements.
Customer due diligence must be risk-based and documented. Enhanced due diligence applies to high-risk customers, politically exposed persons, and transactions above the relevant thresholds. The KYC file must be retained for the period prescribed under the applicable provisions. Transaction monitoring must operate in near-real time for large or unusual transfers; the monitoring system must generate alerts that feed a SAR-filing workflow.
The Travel Rule – the obligation to pass originator and beneficiary data with a virtual-asset transfer – applies to Polish VASPs for transfers above the applicable threshold. The obligation runs both to outbound transfers to other VASPs and to inbound transfers received. Compliance requires a technical integration with a Travel Rule messaging protocol (such as TRISA, TRP or a compliant API layer) and a process for handling transfers from or to unhosted wallets. Poland's AML supervisory authority has indicated an expectation of documented Travel Rule policies as a condition of clean registration; we treat the Travel Rule procedure document as a first-tier deliverable in any Polish VASP filing.
Sanctions screening is a parallel obligation. Polish VASPs must screen counterparties against EU Consolidated Sanctions lists, OFAC designations relevant to their user base, and Polish national lists. An operator with a US-connected user base or a USD-denominated product faces the additional complexity of OFAC compliance running alongside Polish and EU sanctions obligations.
Related at OBOLUS
- Licensing and registration for digital-asset businesses – end-to-end VASP and CASP authorisation across 70+ jurisdictions, structured as a single mandate
- VASP licence application in Japan (FSA/JVCEA) – the registration and self-regulatory process for operators targeting the Japanese market
- Creditor claims in crypto insolvency: the compliance burden in practice – managing regulatory obligations when a counterparty enters insolvency proceedings
FAQ
How long does a crypto licence take to obtain?
For Polish VASP registration, a well-prepared, complete application typically moves through administrative review in a matter of weeks. Applications returned for supplement, or those with complex beneficial ownership structures, can take materially longer. Under MiCA, CASP authorisation timelines are set by the applicable EU regulatory procedure and vary by the competent authority's workload and the complexity of the application. We advise building eight to twelve weeks as a conservative baseline for a clean Polish registration filing, with the MiCA CASP process running on a longer horizon.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. The right jurisdiction turns on where your users are, where you can bank, your product (exchange, custody, token issuance), your governance and substance capacity, and your timeline. Poland suits EU-market builders who need a credible, cost-proportionate registration with a clear MiCA transition path. Other operators may be better served by Lithuania, Malta or a non-EU hub such as Singapore or the ADGM in Abu Dhabi. We map the full jurisdiction matrix against your specific operating profile before recommending a structure.
Do I need a separate custody licence?
Under the current Polish VASP regime, custody – holding or controlling private keys on behalf of clients – is a regulated activity that must be disclosed and accounted for in the registration. Under MiCA, custody and administration of crypto-assets is a defined CASP service requiring explicit authorisation. An operator offering both exchange and custody services cannot cover both under a single registration that discloses only exchange activity; both activity heads must be addressed. We assess the full activity perimeter at the outset to ensure the registration covers everything the business intends to do.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit, and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. Digital assets are the whole of our practice. To discuss your Poland entry or broader EU licensing strategy, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in EU and Central European VASP registration, MiCA CASP authorisation, and multi-jurisdiction licence stack design for inbound digital-asset operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.