← Regulations / Cyprus / Operating Models / CEX

Centralized exchange in Cyprus

Order-book exchange that takes custody of user assets and matches trades between users.

Conditional AI-Generated · Unreviewed

CEX is conditionally permitted in Cyprus with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Customer Due Diligence (CDD): Identify and verify natural persons (full name, date/place of birth, nationality, address, ID) and legal entities (name, registration, directors, UBO) under the Prevention and Suppression of Money Laundering Law and CySEC Directive 342/2021.
  • Beneficial Ownership identification: Identify UBOs holding ≥25% shares/voting rights or exercising control.
  • Source of Funds / Source of Wealth (SoF/SoW) measures required for higher-risk clients or significant transactions.
  • Enhanced Due Diligence (EDD) mandatory for PEPs, high-risk third-country customers, non-face-to-face relationships, and unusual/high-value transactions.
  • Ongoing transaction monitoring for suspicious patterns and consistency with customer risk profile.
  • Internal reporting to appointed Money Laundering Reporting Officer (MLRO); MLRO must submit STRs to MOKAS (Cyprus FIU).
  • Record-keeping: All CDD documents, transaction records, and AML policies retained for at least 5 years; accessible to CySEC and MOKAS.
  • Staff training: Regular AML/CFT training for all relevant employees.
  • Appointment of a qualified MLRO at management level; documented AML Manual required.

Key Restrictions

  • Must be registered and authorized as a Crypto-Asset Service Provider (CASP) with CySEC under the current framework (PS-01-2021), transitioning to MiCA authorization by December 30, 2024.
  • Physical presence in Cyprus required — entity must have substance and meet local management/control tests.
  • Minimum initial capital of €125,000 for Class 2 services (custody and administration of crypto-assets).
  • Client crypto-assets must be held separately from the CASP's own assets (Article 67 MiCA); dedicated accounts/mechanisms required to protect client ownership in insolvency.
  • Professional indemnity insurance or own funds required per Article 67(4) MiCA to cover liability risks from custody activities.
  • Robust security measures for cryptographic keys required — strong technological and organisational measures (cold storage implied).
  • Board composition requirements: at least 4 directors (2 executive, 2 non-executive) with fit-and-proper assessment for key personnel.

Key Risks

  • Regulatory transition risk: CASPs currently operating under CySEC PS-01-2021 must adapt to full MiCA authorization by December 30, 2024, requiring potential re-application or notification.
  • Enforcement precedent: CySEC has imposed administrative fines on major operators (eToro Europe Ltd, Bitpanda GmbH) for AML/CFT compliance gaps and organizational requirement breaches.
  • Travel Rule obligations (FATF Recommendation 16 / EU TFR) apply on withdrawals — CASPs must ensure beneficiary VASP information is transmitted; non-compliance carries enforcement exposure.
  • Ambiguity in custody segregation standards under MiCA — while Article 67 requires segregation, practical implementation of 'appropriate technological and organisational measures' for key security may attract regulatory scrutiny.
  • High operating cost from capital requirement (€125k), insurance/own-funds requirement, physical presence mandate, and staffing (MLRO, compliance team).

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 80% confidence

The Prevention and Suppression of Money Laundering and Terrorist Financing Law of 2007 (as amended) remains the foundational law, but CySEC has issued additional strengthened anti-money laundering guidelines beyond the original text, incorporating new risk requirements.

licensing 20% confidence

CySEC Directive for the Prevention and Suppression of Money Laundering and Terrorist Financing (Regulatory Administrative Act 342/2021) for CASPs. This specific directive, issued by CySEC, outlines the detailed AML/CFT obligations for CASPs, including registration, operational requirements, and specific procedures.

licensing 20% confidence

Exchange between crypto assets and fiat currencies.

licensing 20% confidence

Management, transfer, holding, and/or safekeeping of crypto assets or cryptographic keys or means which allow the exercise of control over crypto assets.

licensing 100% confidence

CySEC Policy Statement PS-01-2021 currently outlines practical requirements for Crypto-Asset Service Provider (CASP) registration and ongoing compliance in Cyprus. However, this framework is in the process of being superseded by the EU's Markets in Crypto-Assets (MiCA) regulation, with CySEC mandating that existing CASPs in Cyprus must apply for authorization under MiCA by February 27, 2026.

licensing 90% confidence

Application Process: Submission of a detailed application to CySEC.

licensing 90% confidence

The entity must meet local management and control tests to maintain its status, not strictly be a legal person established in Cyprus.

licensing 90% confidence

Directors and key personnel must be "fit and proper," with adequate knowledge, experience, and integrity. For specific regulated entities, such as Cyprus Investment Firms (CIFs) under CySEC, at least four board members (two executive, two non-executive) must be present, with at least two executive directors managing day-to-day operations and physically residing in Cyprus. However, under general Cyprus company law, a private company requires at least one director, and a public company requires at least two directors.

licensing 90% confidence

Minimum initial capital requirements apply, typically tiered based on the scope of services. For custody and administration of crypto-assets, it falls under Class 2 services, requiring a minimum capital of €125,000.

licensing 90% confidence

Organisational requirements in Cyprus continue to include robust internal controls and compliance with data protection laws, while effective risk management systems, IT systems, security mechanisms, and business continuity plans have been significantly enhanced and made more prescriptive through the Security of Networks and Information Systems Law (N.89 (I)/2020 as amended by N.60 (I)/2025) implementing the NIS2 Directive, which mandates specific technical, operational, and organisational measures for essential and important organisations with compliance by October 2024.

licensing 80% confidence

AML/CFT Compliance: Comprehensive AML/CFT policies, procedures, and internal controls, including customer due diligence (CDD), ongoing monitoring, record-keeping, and suspicious transaction reporting.

licensing 80% confidence

Physical Presence: The CASP must have a physical presence in Cyprus and demonstrate substance.

custody 100% confidence

Article 67: CASPs providing custody services must hold crypto-assets on behalf of clients separately from their own assets. They must ensure that client crypto-assets are not used for their own account and are identifiable from the CASP's own crypto-assets.

custody 100% confidence

Article 67(4): CASPs providing custody services must either have a professional indemnity insurance policy or own funds equivalent to the potential liability risks arising from their activities. The amount of such insurance or own funds must be sufficient to cover losses that may arise from negligence, errors, omissions, fraud, or operational failures. ESMA will develop regulatory technical standards (RTS) to specify the minimum monetary amount of the professional indemnity insurance or own funds.

custody 100% confidence

Article 67: CASPs must establish, implement, and maintain an internal policy on safeguarding client crypto-assets, which shall include appropriate technological and organisational measures to ensure the security of the crypto-assets.

custody 100% confidence

This means dedicated accounts or mechanisms to ensure client ownership is protected, particularly in case of the CASP's insolvency.

aml 20% confidence

Identification and Verification of Customer Identity:

aml 20% confidence

Identification of Beneficial Ownership: For legal entities, identifying and verifying the ultimate beneficial owner (UBO) who directly or indirectly holds 225% or more of the shares or voting rights, or otherwise exercises control.

aml 20% confidence

Source of Funds (SoF) / Source of Wealth (SoW): Especially for higher-risk clients or significant transactions, CASPs must take reasonable measures to establish the source of the funds and/or wealth involved.

aml 20% confidence

Enhanced Due Diligence (EDD): Must be applied in high-risk situations, including:

aml 20% confidence

Ongoing Monitoring: Continuously monitoring the business relationship and transactions to ensure consistency with the CASP's knowledge of the customer, their business, and risk profile. This includes monitoring for suspicious patterns or unusual deviations.

aml 20% confidence

Internal Reporting: Employees must report suspicions to the appointed Money Laundering Reporting Officer (MLRO).

aml 20% confidence

MLRO's Duty: The MLRO must evaluate the internal report and, if a suspicion is formed, submit an STR to the Unit for Combating Money Laundering (MOKAS), which is Cyprus's Financial Intelligence Unit (FIU).

aml 20% confidence

Duration: Records must be kept for at least five (5) years from the completion of the transaction or the termination of the business relationship.

aml 20% confidence

Internal Policies and Procedures: CASPs must establish and maintain robust internal AML/CFT policies, controls, and procedures, including a comprehensive risk assessment. These should be documented in an "AML Manual."

aml 20% confidence

Money Laundering Reporting Officer (MLRO): Appointment of a suitably qualified and experienced MLRO at management level responsible for overseeing AML/CFT compliance.

aml 20% confidence

Staff Training: Regular and ongoing training for all relevant employees on AML/CFT risks, regulations, and internal procedures.

enforcement 70% confidence

Entity Targeted: eToro (Europe) Ltd (a major global trading platform also offering crypto services). Violation Type: Non-compliance with regulatory requirements related to organizational requirements, safeguarding clients' funds, and prevention of money laundering and terrorist financing (AML/CFT). This included deficiencies in operational risk management, internal controls, and measures taken to prevent money laundering and terrorist financing. Outcome: Imposition of an administrative fine. eToro (Europe) Ltd stated it has taken corrective measures.

enforcement 70% confidence

Entity Targeted: Bitpanda GmbH (a well-known European digital investment platform operating as a registered VASP in Cyprus). Violation Type: Non-compliance with the AML/CFT Law, specifically regarding internal controls and measures for the prevention of money laundering and terrorist financing, and deficiencies in customer due diligence procedures. Outcome: Imposition of an administrative fine. Bitpanda GmbH took corrective measures.

custody 100% confidence

Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA):

custody 100% confidence

June 29, 2023: MiCA entered into force.

custody 100% confidence

December 30, 2024: Rules for all other crypto-assets and CASPs (including custody providers) will apply.

custody 100% confidence

CASPs offering "custody and administration of crypto-assets on behalf of clients" will require authorization as a CASP under MiCA. CySEC will be the competent authority for authorizing and supervising CASPs in Cyprus.

custody 100% confidence

Existing CASPs in Cyprus will need to adapt their operations and potentially re-apply or notify for authorization under MiCA.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
high

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a centralized exchange can operate in Cyprus as a CySEC-registered CASP (transitioning to MiCA authorization by December 30, 2024), subject to a high licensing burden, minimum €125k capital, physical-presence requirement, strict client-asset segregation under Article 67 MiCA, comprehensive AML/CFT obligations, and enforcement risks from recent CySEC fines against eToro and Bitpanda.

Questions this verdict aims to answer

  • What exchange / VASP license applies?
  • What custody segregation rules apply to user assets?
  • What market-conduct and listing rules apply?
  • What travel-rule obligations apply on withdrawals?