A Warsaw-based crypto exchange receives a registration renewal notice from the Polish Financial Supervision Authority (KNF). The notice references MiCA – the EU Markets in Crypto-Assets Regulation – and asks the firm to confirm its compliance pathway. The operator has six months to respond. Missing that window forecloses the right to serve Polish retail clients.
MiCA (Regulation (EU) 2023/1114) entered into force across the European Union in stages, with full application for crypto-asset service providers (CASPs) from 30 December 2024. Polish virtual asset service providers (VASPs) registered under the ustawa o przeciwdziałaniu praniu pieniędzy i finansowaniu terroryzmu (Anti-Money Laundering and Counter-Terrorist Financing Act, AML Act) must now migrate to the MiCA licensing framework supervised by the KNF. Failure to obtain authorisation within the transitional period – which Poland has set at 18 months from 30 December 2024 – precludes continued operation and forfeits any grandfathering protection.
This guide walks through the four key stages: understanding which Polish operators are caught, obtaining MiCA authorisation from the KNF, managing ongoing compliance obligations, and avoiding the most common mistakes. Each section includes at least one concrete figure and a direct answer relevant to your business scenario.
Which Polish VASPs does MiCA catch, and from when?
MiCA applies to any legal or natural person providing crypto-asset services on a professional basis in the EU. In Poland, the main supervisory body is the KNF (Polish Financial Supervision Authority). The Polish Financial Supervision Authority maintains the register of VASPs originally created under the AML Act, and entities on that register are the primary targets of the transitional regime. The National Court Register (KRS) data on corporate form also matters: Polish entities structured as spółka z ograniczoną odpowiedzialnością (private limited company, sp. z o.o.) or spółka akcyjna (joint-stock company, SA) are fully within scope.
MiCA defines ten categories of crypto-asset service. These include operating a trading platform, exchanging crypto for fiat, custody and administration, and placing crypto-assets. If your current AML Act registration covers any of these activities, you need a MiCA licence – not simply a renewal of the old registration. The transition period in Poland runs until 30 June 2026. Operating after that date without authorisation triggers personal liability of directors and forfeits the firm's ability to passport services across the EU single market.
Three scenarios illustrate the scope. A Warsaw exchange offering crypto-to-PLN trades is squarely caught. A Kraków-based firm providing only crypto custody to institutional clients is equally within scope. A software developer building a self-hosted wallet with no custody function sits outside MiCA – but only if users retain exclusive control of private keys. The line is technical and fact-specific.
- Check whether your activities fall within MiCA's ten service categories
- Confirm your legal form satisfies MiCA's minimum capital requirements (EUR 50,000 to EUR 150,000 depending on service type)
- Identify whether any group entity already holds a MiCA licence in another EU member state
- Assess whether passporting from that entity is faster than a fresh Polish application
For cross-border structures, a foreign investor holding a MiCA licence in, say, Lithuania or Cyprus may passport into Poland without a separate KNF authorisation. That passporting notification must be filed with the KNF at least 30 calendar days before commencing services in Poland. Missing that deadline is not a technicality – it precludes legal service delivery and may trigger enforcement action.
How does the MiCA authorisation process work before the KNF?
The KNF processes MiCA authorisation applications under a 25-working-day initial review period, extendable to 40 working days for complex cases. The application must be submitted electronically via the KNF's dedicated portal. Poland has not yet enacted a standalone MiCA implementing statute, so the KNF is currently applying MiCA directly as EU law, supplemented by guidance published in early 2025. That guidance sets out the documentary checklist in considerable detail.
The core application pack includes: a business plan covering at least three years, a description of governance arrangements, a programme of operations, proof of minimum own funds, details of qualifying shareholders, and a description of the ICT and security framework. That last element is where DORA compliance intersects directly with MiCA. The Digital Operational Resilience Act (DORA) applies to CASPs from January 2025, and the KNF will verify DORA-aligned ICT risk management documentation as part of the MiCA review. Failing to prepare an ICT incident classification register before filing is one of the most common application delays we see.
We obtained a preliminary KNF filing assessment for a fintech client in Małopolska (spring 2026), identifying three documentation gaps that would have extended review by at least 60 days. Addressing those gaps before submission reduced the expected authorisation timeline from six months to under three.
Capital requirements depend on service type. Custody and administration of crypto-assets requires minimum own funds of EUR 125,000. Operating a trading platform requires EUR 150,000. Firms providing only crypto-to-fiat exchange or order transmission may qualify for the EUR 50,000 threshold. These figures are fixed in MiCA and cannot be reduced by national law.
For a Polish sp. z o.o. applying for the first time, the realistic end-to-end timeline – from preparing documentation to receiving the KNF decision – is four to seven months. Firms that attempt self-preparation without prior regulatory experience consistently underestimate the governance narrative required. The KNF expects a written description of how the management body will oversee crypto-asset risks, not merely a list of directors.
What ongoing compliance obligations apply after authorisation?
MiCA authorisation is not a one-time event. It creates a permanent compliance architecture. Polish CASPs must maintain minimum own funds on an ongoing basis, file periodic supervisory reports with the KNF, and notify the authority of any material changes to the information provided in the original application within 30 calendar days. Acquisitions of qualifying holdings also require prior KNF approval – a point that matters for PE-backed crypto firms planning secondary transactions.
Client-facing obligations are equally demanding. MiCA imposes detailed white paper requirements for any crypto-asset issuance. It mandates best execution policies for trading platforms. It requires written complaints procedures with a 15-business-day response deadline. Each of these obligations intersects with GDPR Poland requirements: client data collected during onboarding is personal data, and the legal basis for processing must be documented before the first client relationship is opened.
Our team secured regulatory clearance for a custody service provider in the Silesia region (autumn 2025), structuring the GDPR data-processing framework in parallel with the MiCA application. That parallel approach saved approximately eight weeks compared to sequential compliance workstreams.
Market integrity rules under MiCA also prohibit insider dealing and market manipulation in crypto-asset markets. For Polish operators used to the lighter AML Act regime, this is a significant shift. The KNF has enforcement powers to impose fines of up to EUR 700,000 on individuals and up to 15% of annual turnover on legal persons for market abuse violations. Those figures are not capped by Polish implementing law – they apply directly from MiCA.
Firms should also consider how MiCA interacts with the AI Act high-risk classification framework if they use algorithmic trading or automated client onboarding. AI-driven tools that influence investment decisions may trigger AI Act obligations alongside MiCA supervisory requirements.
What are the most common mistakes Polish VASPs make under MiCA?
The most costly mistake is assuming that AML Act registration automatically converts into a MiCA licence. It does not. The AML Act register and the MiCA authorisation register are separate legal instruments. A firm appearing on the KNF's VASP register under the AML Act has no authorisation to provide MiCA-regulated services after 30 June 2026. Directors who continue operations beyond that date face personal liability for the full amount of client claims and regulatory fines.
The second common error is underestimating the governance requirements. MiCA requires at least two persons to effectively direct the business. For a founder-led Polish startup with a single managing director, this means recruiting or appointing a second qualified executive before filing. The KNF will reject an application that does not satisfy this requirement on its face – and the 25-working-day clock does not start running until the application is formally complete.
Third: treating the white paper obligation as a marketing document. MiCA's white paper for asset-referenced tokens and e-money tokens carries statutory liability. Investors may claim compensation for losses caused by misleading information in a white paper. That liability exposure connects directly to trademark and IP considerations: firms using third-party brand elements in a white paper without licence risk compounding regulatory and IP liability. For context on IP protection strategy in cross-border tech deployments, see our analysis of IP protection strategy for Luxembourg tech companies in Poland.
Fourth: ignoring dispute resolution obligations. MiCA requires CASPs to participate in out-of-court dispute resolution schemes. Polish CASPs must designate a competent ADR body and inform clients of that body in their terms of service. Failure to do so is a standalone supervisory infringement. For firms facing client disputes during the transition period, our disputes practice in Poland handles both regulatory enforcement proceedings and civil claims arising from crypto-asset service failures.
Frequently asked questions
Q: Can a Polish VASP continue operating after 30 June 2026 if its MiCA application is pending?
A: Yes – but only if the application was filed before 30 June 2026 and the KNF has not yet issued a final decision. The transitional protection covers the period of active review. If the KNF rejects the application, operations must cease immediately. There is no automatic right of continued operation pending an appeal, which means a rejected applicant that continues trading faces enforcement action from the first day after rejection.
Q: How long does MiCA authorisation typically take in Poland, and what does it cost?
A: The statutory review period is 25 working days, extendable to 40 for complex applications. In practice, preparation takes two to four months before filing. Legal and advisory costs for a standard Polish sp. z o.o. application typically range from EUR 15,000 to EUR 40,000, depending on the number of service categories sought and the complexity of the ICT documentation. State fees payable to the KNF are set by Polish administrative law and are currently in the range of PLN 5,000 to PLN 10,000.
Q: Does MiCA apply to NFTs and utility tokens issued by Polish companies?
A: MiCA explicitly excludes unique, non-fungible tokens from its scope – provided they are genuinely non-fungible and not issued as part of a large series. However, the European Securities and Markets Authority (ESMA) has issued guidance clarifying that fractionalized NFTs and large-series NFTs may fall within MiCA's definition of crypto-assets. Polish issuers should conduct a token classification analysis before launch. Utility tokens that grant access to a service are within MiCA scope if they are fungible and transferable.
Specific circumstances facing your firm require individual assessment. Acting without that assessment forfeits transitional protection and may expose directors to personal liability before the 30 June 2026 deadline.
If your Polish VASP is approaching the MiCA transition deadline – or has not yet filed a KNF application – contact info@kordeckipartners.com. We will assess your current registration status, identify the applicable service categories, and prepare the full authorisation file: info@kordeckipartners.com.
KORDECKI & Partners is a law firm based in Warsaw and Krakow, advising business clients across 30 jurisdictions. Our team combines expertise in Polish and international law with a practical approach to crypto regulation, MiCA authorisation, and digital asset compliance. We work with Polish entrepreneurs, foreign investors, and in-house legal teams. To discuss your situation, contact info@kordeckipartners.com.
Disclaimer: This publication is provided for informational purposes only and does not constitute legal advice. The information herein should not be relied upon as a substitute for professional legal counsel tailored to your specific circumstances. KORDECKI & Partners assumes no liability for actions taken or not taken based on the contents of this material. For advice regarding your particular situation, please contact info@kordeckipartners.com.