- Sep 29, 2026
- 6 min read
How MiCA Regulation Reshapes Crypto Licensing in the Baltics and Poland
MiCA Regulation is reshaping crypto licensing across Lithuania, Latvia, Estonia, and Poland. Read on for CASP deadlines, requirements, and risks.

MiCA has replaced Europe’s patchwork of national crypto regimes with a common authorization framework, but that does not mean every market is identical. Although the MiCA Regulation establishes one EU rulebook, national implementation, supervisory expectations, application costs, and processing practices continue to vary.
This contrast is especially clear in the Baltics and Poland. Lithuania, Latvia, and Estonia are processing applications and granting CASP authorizations. Poland still lacks the national legislation and fully empowered authority needed to authorize domestic CASPs.
The divide widened on September 4, 2026, when Poland’s parliament failed to overturn the president’s third veto of its Crypto-Assets Market Act. With Poland’s transitional period already over, the deadlock affects whether domestic providers can operate legally, obtain authorization, and compete with EU-licensed firms passporting into the country.
What is MiCA Regulation and why does it matter?
The Markets in Crypto-Assets (MiCA) Regulation establishes EU-wide rules for crypto-assets and related services not already governed by other EU financial-services legislation. Its provisions for asset-referenced tokens and e-money tokens, which are MiCA’s two regulated stablecoin categories, took effect on June 30, 2024. The remaining provisions, including CASP authorization, applied from December 30, 2024.
Under MiCA, CASP applicants must meet common standards covering capital, governance, operational resilience, conduct, and client-asset protection. Once authorized, they can notify their home regulator and passport their approved services across the EU.
Under Article 59, providers require standalone CASP authorization (granted under Article 63), but Article 60 allows certain already-regulated financial institutions, such as banks and investment firms, to provide specified crypto-asset services through a notification procedure.
Suggested read: MiCA Regulation and EU Crypto Rules: What Changes in 2026
Crypto regulation before MiCA: National CASP rules
Under the former CASP Lithuania framework, exchange and custodial-wallet operators entered a national register and were supervised primarily for AML/CFT compliance. Latvia likewise placed crypto providers under the State Revenue Service’s AML/CFT supervision. In Poland, entry in the virtual-currency business register was not a license and did not subject operators to prudential supervision. Estonia had a stricter system, with providers needing a Financial Intelligence Unit license.
MiCA replaces these divergent arrangements with the EU legal category of crypto-asset service provider (CASP). A virtual asset service provider (VASP) is the term used in FATF’s global AML/CFT standards, whereas CASP is the official term under MiCA.
Suggested challenge: Crypto Crossword Challenge – Decrypt & Win!
MiCA CASP licensing in Lithuania
Businesses seeking a crypto license in Lithuania now apply to the Bank of Lithuania for CASP authorization. Lithuania’s transitional period ended on December 31, 2025. After that date, accepting new clients, providing custody, or delivering other covered crypto-asset services without authorization became illegal. The application fee for issuing a CASP license is €2,425.
The assessment for a CASP license in Lithuania covers prudential safeguards, the suitability of managers and qualifying shareholders, effective management, operational presence in Lithuania, and functioning AML and client-asset controls.
As of September 2026, the public register lists four Lithuania-based holders of standalone CASP licenses. Separate Bank of Lithuania records list BLUE EMI LT and Newrails as providing crypto-asset services through Article 60, bringing the total number of Lithuania-based entities permitted to provide such services under MiCA to six.
MiCA CASP licensing in Latvia
Latvijas Banka accepts CASP license applications and offers free pre-licensing consultations.
In July 2026, Nodu Digital became the tenth Latvian entity authorized to provide crypto-asset services under MiCA. The current entities appear in Latvijas Banka’s crypto-asset market register. Nine hold standalone CASP licenses, while AS TWINO Investments provides specified services through the Article 60 route based on its existing investment-firm license.
As former CASP status is not converted automatically through CASP license adaptation, applicants must complete the applicable MiCA process and pay a €2,500 review fee.
MiCA CASP licensing in Estonia
Businesses seeking a crypto license in Estonia must apply to Finantsinspektsioon. Applications are filed through its online portal, must be submitted in Estonian, and carry a €3,000 processing fee.
Estonia’s transition ended on July 1, 2026, after which legacy Financial Intelligence Unit licenses no longer authorized firms to provide crypto-asset services. So, providers needed standalone CASP authorization, eligibility under Article 60, or authorization passported from another EU member state.
Finantsinspektsioon’s CASP register lists Lightspark Payments Europe as Estonia’s only standalone CASP license holder. The regulator has also confirmed that AS LHV Pank and Lightyear Europe may provide specified crypto-asset services through Article 60 based on their existing bank and investment-firm authorizations.
Poland’s legislative deadlock on CASP licensing
For CASP applicants in Poland, the route to domestic authorization remains blocked. President Karol Nawrocki vetoed three versions of the Crypto-Assets Market Act, which would have designated the KNF (Polish Financial Supervision Authority) as Poland’s national competent authority. The Sejm’s September 4, 2026, attempt to override the latest veto received 241 votes, which was 25 short of the 266 required.
With no Polish authority designated to process CASP applications and the transitional period having expired on July 1, Polish firms must either seek authorization in another member state or stop providing MiCA-covered services. CASPs already authorized elsewhere in the EU may still passport their services into Poland.
On September 8, the president submitted his second draft act, presented as a compromise and based largely on the vetoed government text. It had not become law at the time of writing.
Key CASP authorization requirements
Applicants for aCASP license must have a registered office in a member state where they conduct at least part of their crypto business, effective management within the EU, and at least one EU-resident director. Their application must describe their operations, governance, qualifying shareholders, AML controls, ICT security, business continuity, outsourcing, complaints handling, and segregation of client assets.
Minimum capital for a MiCA crypto license depends on the services offered: €50,000 for Class 1 services such as advice; €125,000 for Class 2 services including custody or exchange; and €150,000 for Class 3 trading-platform operators. Every authorized crypto-asset service provider must maintain prudential safeguards equal to at least the higher of the applicable capital floor or one-quarter of its previous year’s fixed overheads.
Suggested read: Guide for EU CASPs: Legal Requirements and Sumsub Functionalities
Baltic states compared: Costs and timelines
The core MiCA crypto requirements and statutory review timetable are harmonized across the EU. Regulators have 25 working days to determine whether an application is complete, followed by 40 working days to assess a complete application. A request for further information can suspend the latter period for up to 20 working days.
National fees, supervisory practices, and progress with authorization differ:
| Market | Application fee | Statutory review period | Position in September 2026 |
| Lithuania | €2,425 | 25 + 40 working days | Six entities permitted under MiCA, including four standalone CASP licenses |
| Latvia | €2,500 | 25 + 40 working days | Ten MiCA-permitted entities, including nine standalone CASP licenses from Latvijas Banka |
| Estonia | €3,000 | 25 + 40 working days | Three entities permitted under MiCA, including one standalone CASP authorization |
As part of CASP license adaptation, applicants may also need to fund local staffing, professional advice, governance, audits, regulatory capital, and compliant ICT and control systems to transform their businesses for MiCA compliance.
MiCA transitional periods and deadlines
The latest possible EU MiCA transitional period end date was July 1, 2026. Lithuania shortened its window to December 31, 2025. Latvia applied a six-month transitional regime that ended on June 30, 2025, and Estonia used the EU backstop.
Under the MiCA regulation, providers that have not obtained authorization have had to stop taking on new business and conduct an orderly wind-down that protects clients and their assets.
Cross-border MiCA passporting explained
Under the MiCA EU passporting system, an authorized CASP notifies its home regulator of the member states and services it intends to cover. The home authority has 10 working days to transmit the information. The CASP may begin operating when it receives confirmation that the notification has been communicated or, at the latest, 15 calendar days after submitting it.
To determine which crypto exchanges have a MiCA license, consult ESMA’s interim MiCA register and the relevant national register. A national CASP registration or pending application is not MiCA authorization.
AML, Travel Rule, and consumer duties for CASPs
The MiCA crypto regulation requires CASPs to act honestly, fairly, professionally, and in their clients’ best interests. They must safeguard client assets, handle complaints, manage conflicts of interest, and maintain an orderly wind-down plan.
Operational AML duties arise separately under EU and national AML/CFT legislation. These include customer due diligence, ongoing monitoring, record-keeping, and suspicious-transaction reporting. However, the MiCA authorization process still examines an applicant’s AML controls and exposure to money-laundering and terrorist-financing risks. A MiCA crypto license does not replace these obligations.
The Travel Rule under the TFR
The Travel Rule is a FATF standard implemented in the EU through the Transfer of Funds Regulation (TFR). Whereas MiCA regulates who may provide crypto-asset services and establishes requirements covering governance, capital, custody, conduct, disclosures, and client protection, the TFR regulates the information accompanying crypto-asset transfers.
CASPs must collect and transmit originator and beneficiary information, verify relevant customer information, and maintain procedures for identifying and handling transfers with missing or incomplete data. These requirements apply to covered crypto transfers regardless of value. For a transfer exceeding €1,000 to or from a self-hosted address, the relevant CASP must also assess whether its customer owns or controls that address.
Suggested read: Crypto Travel Rule Explained: FATF Requirements for VASPs
Penalties for non-compliant CASPs
Breaches of the MiCA crypto regulation can lead to cease-and-desist orders, management bans, loss of authorization, and criminal penalties where provided under national law. For infringements of CASP rules, national penalty regimes must allow maximum corporate fines of at least €5 million or 5% of annual turnover. The maximum must also be at least twice the profit gained or loss avoided.
MiCA has made authorization a condition of market access across the region. Lithuania, for example, warns that operating without the required crypto license in Lithuania may constitute illegal financial activity punishable by up to four years’ imprisonment.
In Lithuania, Latvia, and Estonia, you can pay it at home. In Poland, for now, you can't, and the only way in is a license from another member state.
Suggested read: One Rulebook for Europe: Inside the EU’s New AML Regulation
Relevant articles
- Article
- 1 week ago
- 7 min read
Learn how biometric authentication works, its pros and cons, and best practices for using it securely in identity verification and compliance.

- Article
- 6 days ago
- 26 min read
Dive into the world of fraud with the ‘What The Fraud?’ Podcast! 🚀 In this special episode, recorded at Seamless Africa, we sit down with leaders ac…

What is Sumsub anyway?
Not everyone loves compliance—but we do. Sumsub helps businesses verify users, prevent fraud, and meet regulatory requirements anywhere in the world, without compromises. From neobanks to mobility apps, we make sure honest users get in, and bad actors stay out.

