Poland’s pre-2026 Virtual Asset Service Provider (VASP) registration system attracted over 1,500 crypto businesses to the market with relatively low costs and straightforward entry requirements.
However, as the EU’s Markets in Crypto-Assets (MiCA) Regulation became applicable across all Member States, the old regime was phased out. The transition has created challenges for crypto-asset service providers in Poland, where the practical route to serving Polish clients now involves obtaining authorisation in another EU Member State and using MiCA’s passporting framework.
This guide explains what changed, what the current regulatory position means for crypto businesses, and how companies can approach the Polish market without a domestic CASP licence.
TL;DR
- Poland currently has no domestic CASP authorisation route.
- The former VASP registration no longer provides a basis for continuing MiCA-regulated services after 1 July 2026.
- KNF has not been designated as Poland's competent authority for CASPs.
- Businesses can consider obtaining CASP authorisation in another EU member state and using MiCA passporting rights to serve Polish clients.
- MiCA's capital, governance, compliance, and operational requirements apply regardless of the member state granting authorisation.
What Happened to Poland’s VASP Registration?
Before MiCA, businesses conducting certain virtual currency activities in Poland could register in the national Register of Virtual Currencies. The registration was administered through the tax administration, with the relevant register maintained by the Head of the Second Tax Office in Katowice.
This system was designed around anti-money laundering obligations rather than the broader prudential and organisational requirements introduced by MiCA. At the same time, registration did not represent the same type of authorisation as a MiCA CASP licence represents now.
Instead, MiCA introduced a harmonised framework for crypto-asset services across the EU. Its transitional provisions allowed Member States to determine how long certain existing providers could continue operating under national regimes, subject to the maximum period established by Article 143(3).
Poland’s transitional period ended on 1 July 2026. The former VASP registration system therefore cannot be used as a continuing substitute for CASP authorisation.
Why Is There No Domestic CASP Licence in Poland?
MiCA applies directly across the EU, but Member States must still establish national arrangements, including competent authorities, supervisory procedures, fees and sanctions.
Poland’s Crypto-Asset Market Act was intended to establish this framework and designate the Polish Financial Supervision Authority (Komisja Nadzoru Finansowego, or KNF) as the relevant authority. However, the legislation was vetoed by the president three times already, and the latest attempt to override the President’s veto also failed on 4 September.
As a result, MiCA remains in force, but Poland has not completed the domestic supervisory framework needed to process CASP applications. Businesses therefore cannot currently follow a complete domestic application process to obtain a CASP authorisation in Poland.
What Can Businesses Do in Poland?
Poland currently has no operational domestic route for obtaining a CASP authorisation. The former VASP registration system ended as a pathway for businesses providing services covered by MiCA, and the country has not completed the framework needed to process domestic CASP applications.
Businesses that want to serve Polish clients can instead consider obtaining MiCA authorisation in another EU Member State. Once authorised, they may use MiCA’s passporting framework to provide eligible services in Poland without obtaining a separate Polish CASP licence.
The selected jurisdiction should be assessed based on the company’s planned services, governance structure, substance requirements, compliance resources and long-term operating model. Businesses may consider jurisdictions such as Estonia or Lithuania, alongside other EU Member States with operational MiCA licensing frameworks.
After authorisation, the provider must notify its home competent authority of its intention to offer services in Poland. Passporting does not remove the provider’s ongoing compliance responsibilities. The company must continue operating within the scope of its authorisation and meet applicable requirements for customer onboarding, AML controls, client disclosures, complaints handling, the Travel Rule and operational resilience.
What Does MiCA Require?
MiCA requirements depend on the crypto-asset services a business intends to provide. These may include custody, exchange, order execution, operating a trading platform, placing crypto-assets, advice, portfolio management and transfer services.
A CASP application generally needs to demonstrate that the business has:
- An appropriate EU-based corporate and governance structure.
- Suitable management and effective organisational arrangements.
- The required minimum capital or equivalent safeguards.
- Risk management and internal control procedures.
- AML and counter-terrorist financing controls.
- Cybersecurity, incident management and business continuity measures.
- Procedures for safeguarding client assets and information.
- Documented business plans, policies and descriptions of the proposed services.
The company must also consider operational resilience requirements under the Digital Operational Resilience Act (DORA), where applicable. The exact requirements depend on the service category, the applicant’s structure and the expectations of the selected competent authority.
MiCA authorisation is not a one-time compliance exercise. Providers must maintain their governance, security, risk management and customer protection arrangements throughout their operations. Hacken’s compliance services can support businesses assessing these requirements before and after authorisation.
Compliance Considerations for Polish Customers
Serving Polish clients through a foreign MiCA-authorised entity requires more than submitting a passporting notification.
The provider should review how its operating model addresses:
- Customer onboarding and identification.
- AML and sanctions controls.
- Client communications and disclosures.
- Complaints handling.
- Crypto-asset transfers and the Travel Rule.
- Custody and safeguarding arrangements.
- Incident reporting and operational resilience.
- Marketing and consumer protection requirements.
- Tax and reporting obligations applicable to the business model.
The company should also establish which services it can legally offer under its specific authorisation. A licence covering custody, for example, should not be treated as permission to provide every other crypto-asset service.
Where the business relies on external technology providers, custody partners or other infrastructure vendors, those relationships should be reflected in its risk management and outsourcing documentation.
A structured compliance programme can help businesses prepare for the application process and maintain the controls expected after authorisation. Hacken’s compliance services can be used to assess relevant security and compliance requirements as part of this preparation.
Poland’s Regulatory Position: What Businesses Should Do
Poland’s domestic CASP licensing route remains unavailable following the failed veto override on 4 September 2026. The regulatory gap does not suspend MiCA. Instead, it prevents Polish authorities from completing the domestic authorisation process.
Businesses that intend to serve Polish customers should therefore assess whether obtaining authorisation in another EU Member State is appropriate for their operating model. This requires a review of the planned services, corporate structure, compliance requirements, technical infrastructure and passporting strategy.
The key distinction is between having access to the Polish market and obtaining a Polish licence. Under MiCA, an authorised provider in another EU Member State may be able to serve Polish clients through passporting, while a business seeking domestic authorisation in Poland currently has no completed application route.
The legislative position may change if Poland adopts a new Crypto-Asset Market Act. Until then, businesses should base their plans on the authorisation routes and supervisory arrangements that are actually available.




