For years an Estonian crypto licence meant a virtual asset service provider (VASP) permit from the Financial Intelligence Unit, issued under anti-money-laundering law and valid only inside Estonia. That permit no longer exists. Since the EU Markets in Crypto-Assets Regulation took full effect, the only way to provide crypto-asset services from Estonia is a crypto-asset service provider (CASP) authorisation issued by Finantsinspektsioon, the Estonian Financial Supervision Authority (FSA), and recognised across the whole European Economic Area.
This guide explains what that shift in Estonian crypto regulation means in practice: how the VASP licence turned into a MiCA authorisation, how to tell a live authorisation from a lapsed licence, what changed against the old regime and which duties follow once the authorisation is granted. The procedure and costs are covered on our crypto licence in Estonia service page; here the focus is on what an authorised Estonian CASP has to keep doing.
Quick answer
Crypto-asset services in Estonia have a single legal entry point: a CASP authorisation from Finantsinspektsioon under MiCA and the Estonian Market in Crypto-Assets Act. The former FIU virtual currency service provider licence has ceased to be valid, was not converted and cannot be renewed. Once authorised, a CASP must keep meeting MiCA’s governance, prudential, client-asset and conduct requirements, together with Estonian AML rules, for as long as it operates, and may passport its services across the EEA.
Why the Estonian Crypto Licence Is Now a MiCA Authorisation
MiCA is a regulation, not a directive, so it applies directly and identically in every EU and EEA state. For the services within its scope it replaced national crypto licences with one instrument: the CASP authorisation. Estonia implemented the regulation through the Market in Crypto-Assets Act (Krüptovaraturu seadus), which names Finantsinspektsioon as the competent authority that grants, supervises and revokes authorisations, while the Financial Intelligence Unit (FIU, Rahapesu Andmebüroo) keeps its anti-money-laundering role. In practice, MiCA in Estonia means two regulators with two distinct jobs. A “MiCA-compliant Estonian licence” is therefore no longer a claim about how closely Estonian rules resemble European ones: the Estonian authorisation is the MiCA authorisation. How the regulation is built and which assets it covers is explained in our guide to the MiCA regulation.
What Happened to the Estonian VASP Licence
Estonia was one of the first countries in Europe to license crypto businesses, and the VASP licence under the Money Laundering and Terrorist Financing Prevention Act became popular fast: more than six hundred licences were still in force when the FIU began a multi-year clean-up that cut the number to a few dozen before MiCA arrived. Under the Market in Crypto-Assets Act, remaining licence holders could continue only during a transitional period and only until a CASP decision was taken on their file. Nothing was converted automatically.
When the transitional period closed, the FIU cancelled the register data of every remaining virtual currency service provider licence, as the Estonian VASP permit was formally called. Companies without a MiCA authorisation had to stop taking on clients and marketing in the EEA, wind down their services and tell existing clients how to withdraw or transfer their assets, as the regulators set out in their joint statement on the end of the transitional period. The background to the handover of supervision from the FIU to Finantsinspektsioon is in our news piece on the changes in Estonian crypto market supervision.
How to Check Whether a Crypto Company Is Licensed in Estonia
Websites and directories still quote FIU licence numbers as evidence that a crypto exchange, custodian or payment processor is licensed in Estonia. They are not. Two public sources, one national and one European, settle the question in minutes. The first is the register of market participants kept by Finantsinspektsioon, which lists every CASP it has authorised and every foreign CASP notified to operate in Estonia. The second is the EU-wide register maintained by ESMA, which consolidates MiCA-authorised CASPs from all member states and also lists entities that supervisors have flagged as non-compliant. A provider that appears in neither may not lawfully serve clients in Estonia, whatever its website says.
Banks, payment institutions and corporate counterparties doing due diligence on a crypto partner should go one step further and ask for the authorisation decision, the list of authorised services, the notifications for the countries actually served and a description of how client assets are safeguarded. A legacy registration offered instead is a red flag, not a credential.
VASP Licence vs CASP Authorisation: What Changed in Estonia
The old VASP licence was, in substance, an anti-money-laundering registration with capital and background checks attached; a CASP authorisation is a financial-sector licence with EU-wide reach built in.
| Area | Former FIU VASP licence | MiCA CASP authorisation |
|---|---|---|
| Legal basis | Estonian Money Laundering and Terrorist Financing Prevention Act | MiCA (Regulation (EU) 2023/1114) and the Estonian Market in Crypto-Assets Act |
| Supervisor | Financial Intelligence Unit, an AML authority | Finantsinspektsioon, the financial supervisor; the FIU keeps AML oversight |
| Focus of supervision | AML/CFT procedures, ownership and management background | Governance, prudential position, safekeeping of client assets, conduct of business, market abuse and AML |
| Services covered | Exchange, wallet, transfer and token-offering services in broad terms | Ten defined crypto-asset services, each authorised and passported separately |
| Capital | Fixed share capital paid in once | Own funds that must be maintained and recalculated for as long as the licence is held |
| Client assets | General AML and IT controls | Mandatory segregation, safekeeping rules, client money held at a credit institution |
| Geographic reach | Estonia only; other states required their own registration | Entire EEA through a passport notification |
| IT resilience | National IT and data-security requirements | The EU DORA regime for ICT risk, incidents and third-party providers |
Crypto regulation in Estonia has moved from a national permit to an EU licence: the FIU permit had no effect outside Estonia, while the CASP authorisation opens a market of thirty countries. The ten services and what each covers are listed on our page about the crypto-asset service provider status.
MiCA Obligations an Estonian CASP Must Keep Meeting
A CASP authorisation is a snapshot; post-authorisation crypto compliance in Estonia is a continuous obligation. Everything demonstrated in the application has to be kept alive in daily operations under the supervision of Finantsinspektsioon, a regulator that expects headroom above the minimum rather than compliance at the floor. The checklist at the end of this section summarises the duties.
Governance and Substance in Estonia
The substance shown at authorisation has to be kept up for the life of the licence: effective management stays in Estonia, the management body stays fit and proper, and every change of director, senior manager or qualifying shareholder is notified to Finantsinspektsioon before or as it happens. Policies, internal audit, business continuity and record keeping must grow with the business rather than remain the documents filed with the application. The nominee director abroad and the rented desk that once satisfied the FIU no longer pass.
Prudential Safeguards
Own funds are not a one-off deposit. The required level is recalculated every year from the audited accounts and rises with the cost base, so a CASP that grows must add capital or insurance cover before the shortfall appears, and a CASP that loses money must report it and restore the position. Every CASP also keeps an orderly wind-down plan showing how client assets would be returned if the business had to close, and updates it after any material change.
Safekeeping of Client Crypto-Assets and Funds
This is the area the old VASP regime barely touched and the new one treats as central. Whether the CASP runs an exchange, a custodial wallet or a payment service, client crypto-assets must be held separately from its own assets and may never be used for its own account. Client money must be placed with a credit institution or a central bank by the end of the following business day, in identifiable client accounts. A custodian signs a written agreement with each client, keeps a register of positions, maintains a documented custody and key-management policy and is liable for losses caused by its own failures, including ICT incidents.
Conduct of Business
A CASP must act with honesty, fairness and professionalism in the best interests of its clients. In practice that means marketing that is clear, fair and not misleading; published prices, costs and fees; risk warnings; a free complaints-handling procedure; a conflicts of interest policy; and full responsibility for any outsourced function. Service-specific rules sit on top: operating rules for a trading platform, a non-discriminatory commercial policy for exchange services, best execution for orders and a suitability assessment before advice or portfolio management.
Market Abuse
MiCA extends market-abuse prohibitions to crypto-assets admitted to trading: insider dealing, unlawful disclosure of inside information and market manipulation are all offences. A CASP that operates a trading platform or arranges and executes transactions must have systems to detect suspicious orders and report them to Finantsinspektsioon.
AML and DORA: Rules That Sit Alongside MiCA
MiCA is the backbone of the regime, not the whole of it. Two other frameworks apply to every CASP in Estonia at the same time.
- Anti-money laundering. A CASP is an obliged entity under the Estonian Money Laundering and Terrorist Financing Prevention Act: customer due diligence (KYC), a documented risk assessment, a compliance officer and suspicious transaction reports to the FIU, which lost the licensing role but not the AML one. The EU regulation on transfers of crypto-assets adds the Travel Rule: originator and beneficiary details must accompany every transfer between service providers.
- DORA. As a financial entity, a CASP falls under the Digital Operational Resilience Act: an ICT risk-management framework, incident reporting, resilience testing and contractual controls over ICT third-party providers, covered in our guide to the DORA regulation.
Ongoing Obligations of an Estonian CASP at a Glance
The table condenses everything above into a form a board or compliance officer can work with: what must be true at all times, and what evidence a supervisor will ask for.
| Obligation | What must be true at all times | Evidence Finantsinspektsioon expects |
|---|---|---|
| Governance | Effective management remains in Estonia; management body remains fit and proper; changes notified in time | Board minutes, staffing, notified changes of managers and qualifying shareholders |
| Own funds | Capital kept above the required level, recalculated every year | Audited accounts, annual recalculation, cover documents where used |
| Client assets | Segregated crypto-assets; client money at a credit institution; custody agreements in place | Reconciliations between internal records, wallets and bank balances |
| Conduct | Fair marketing, published fees, complaints handling, conflicts policy, outsourcing under control | Complaints log, conflicts register, outsourcing agreements and exit plans |
| Market abuse | Systems to detect and report suspicious orders and transactions | Surveillance records, suspicious transaction reports, staff training logs |
| Wind-down | A plan for returning client assets if the business stops | Current wind-down plan reviewed after any material change |
| AML and transfers | Due diligence, risk assessment, compliance officer, transfer data travelling with every transaction | Internal rules, risk assessment, reports to the FIU, Travel Rule test records |
| DORA | ICT risk framework, incident reporting, third-party controls | Register of ICT providers, incident log, testing results |
MiCA Passporting: Serving the EEA from an Estonian CASP Licence
A MiCA authorisation granted in Estonia carries passporting rights across the single market: the Estonian CASP may provide the same services in every other EU and EEA state without a local licence or a local company. The mechanism is a notification: the CASP tells Finantsinspektsioon which states it intends to serve and with which services, Finantsinspektsioon forwards the notification to the host authorities, and the CASP may begin shortly after submitting it.
Three limits apply. The passport covers only the services listed in the authorisation, so adding a service later means extending the authorisation first. Host states keep their consumer-protection and marketing rules. And “reverse solicitation”, where a client approaches an unauthorised provider entirely on their own initiative, is a narrow exception, not a passport. If the Estonian CASP licence is one of several options under consideration, our crypto licence in Europe page compares the CASP route across EU states.
Options for Former Estonian VASP Licence Holders
Many Estonian companies still exist whose only regulated status was a legacy VASP licence that has now lapsed. Their owners face a real decision, and four routes are open.
- Seek a CASP authorisation in Estonia. The company, its history and its Estonian infrastructure can be reused, but nothing from the FIU file carries any weight and the old AML manual is a starting point at best.
- Obtain a MiCA authorisation elsewhere in the EEA and passport into Estonia. This fits groups whose real management sits in another member state; the Estonian company then becomes a branch or a service entity rather than the licensee.
- Keep the company for activity outside MiCA. Software development, mining, pure NFT projects, dealing on own account and consultancy do not require a CASP authorisation. The company may continue, but every crypto-asset service to third parties must stop.
- Wind down in an orderly way. Clients must be told how to withdraw or transfer assets, positions must be closed and the FIU’s final reporting obligations met before the company is repurposed or liquidated.
The Cost of Doing Nothing
Serving clients on the strength of a lapsed licence is unauthorised provision of financial services. MiCA requires member states to back its rules with administrative fines running into millions of euro or a share of annual turnover, and Estonian law adds its own penalties for operating without an authorisation, reaching the individuals who run the business. Finantsinspektsioon publishes warnings about unauthorised providers, and a listing in the non-compliant section of the ESMA register follows a company across the whole EU.
Conclusion
The Estonian crypto licence is a key to MiCA compliance in a literal sense: the authorisation granted by Finantsinspektsioon is the MiCA CASP authorisation. The VASP permit that once carried the same name is gone, and what replaces it is a demanding but portable licence, with obligations that run from governance and own funds to client-asset safekeeping, conduct of business, AML, the Travel Rule and DORA. Eesti Firma supports crypto businesses through the compliance framework a licensed CASP has to run; the practical route is on our Estonian crypto licence service page.
Frequently Asked Questions
No. Virtual currency service provider licences issued by the Financial Intelligence Unit ceased to be valid when the transitional period under the Market in Crypto-Assets Act ended. The only valid Estonian licence today is a CASP authorisation from Finantsinspektsioon.
No. Existing licence holders had to file a full CASP application with Finantsinspektsioon during the transitional period; those that did not receive an authorisation had to wind down.
Finantsinspektsioon, the Estonian Financial Supervision Authority (FSA), grants and supervises CASP authorisations under MiCA and the Market in Crypto-Assets Act. The Financial Intelligence Unit remains the AML authority to which a CASP reports suspicious transactions.
Ongoing compliance with the governance and substance rules, own funds above the required level, safekeeping and segregation of client assets, conduct-of-business rules, market-abuse controls and reporting to Finantsinspektsioon, plus Estonian AML obligations, the Travel Rule and DORA.
Yes. After a passport notification through Finantsinspektsioon, a CASP authorised in Estonia may provide its authorised services in every EU and EEA state without a local licence or local company.
Search the register of market participants on the Finantsinspektsioon website, which lists authorised Estonian CASPs and foreign CASPs operating in Estonia, and cross-check the EU-wide register kept by ESMA. An FIU licence number is not evidence of authorisation.
Apply for a CASP authorisation in Estonia, obtain authorisation in another EEA state and passport into Estonia, keep the company for activity outside MiCA such as software or own-account trading, or wind it down in an orderly way. Providing crypto-asset services on the old licence is no longer an option.
Administrative fines under the MiCA sanctions regime, penalties under Estonian law for operating without an authorisation that can reach the individuals running the company, public warnings by Finantsinspektsioon and an entry among non-compliant entities on the ESMA list.