← Regulations / Cyprus / Operating Models / Crypto debit card

Crypto-funded debit card in Cyprus

A card program where customer fiat balances are funded from crypto holdings, typically through an off-ramp at point of sale or top-up.

Conditional AI-Generated · Unreviewed

Crypto debit card is conditionally permitted in Cyprus with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • CASP must register with CySEC and comply with CySEC Directive 342/2021 for AML/CFT obligations.
  • Full CDD on all cardholders: full name, date/place of birth, nationality, residential address, unique ID (passport/ID).
  • UBO identification for legal-entity cardholders (≥25% ownership threshold).
  • SoF/SoW verification required for higher-risk clients or significant transactions.
  • EDD required for PEPs, high-risk third-country residents, non-face-to-face relationships, and unusual/high-value transactions.
  • Ongoing transaction monitoring to detect suspicious patterns; internal reporting to appointed MLRO.
  • STRs must be filed with MOKAS (Cyprus FIU) when suspicion arises; tipping-off prohibited.
  • Records must be retained for at least 5 years from transaction completion or relationship termination.
  • Appointment of an MLRO at management level; regular staff AML training required.
  • Comprehensive AML manual and risk assessment policies must be documented and maintained.

Key Restrictions

  • Operator must hold either a CASP registration under CySEC (for the crypto off-ramp) AND either an EMI license (authorised under Directive 2009/110/EC and MiCA for e-money token issuance) or partner with a licensed EMI/bank to issue the fiat component.
  • Crypto-to-fiat conversion at point of sale constitutes an 'exchange between crypto assets and fiat currencies' — a regulated CASP activity in Cyprus.
  • If the card loads e-money tokens (EMTs), the issuer must be authorised as a credit institution or EMI under E-Money Directive II and also authorised under MiCA Title III.
  • Minimum initial capital of €125,000 applies for CASP custody/administration services (Class 2).
  • CASP must have physical presence and substance in Cyprus.
  • Directors and key personnel must be 'fit and proper'; at least 4 board members (2 executive, 2 non-executive) for CIF structures.
  • EMI license under Cyprus law requires separate capital (€350,000 minimum under E-Money Directive) and Central Bank of Cyprus supervision — dual licensing likely needed.
  • Partner-bank/BIN-sponsor arrangements are necessary for card issuance and settlement; Cyprus banks have been cautious with crypto-linked programs following enforcement actions against eToro and Bitpanda.

Key Risks

  • Dual regulatory oversight (CySEC for CASP + Central Bank of Cyprus for EMI/e-money) creates coordination and compliance burden.
  • CySEC has imposed significant fines on crypto operators (eToro, Bitpanda) for AML/CFT deficiencies — enforcement risk is material.
  • Cyprus banks remain conservative regarding crypto-linked fiat accounts; securing a BIN sponsor or banking partner may be difficult.
  • MiCA implementation creates transitional uncertainty — CySEC is mandating alignment, which may shift requirements during the application process.
  • Tax treatment of crypto-to-fiat conversions at point of sale is ambiguous pre-2026; from 2026, new Article 20E applies an 8% regime for certain crypto disposals, but characterisation of each transaction matters.
  • Algorithmic stablecoins cannot satisfy MiCA's 1:1 reserve requirements — any stablecoin used must be fully asset-backed.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 20% confidence

Exchange between crypto assets and fiat currencies.

licensing 20% confidence

Management, transfer, holding, and/or safekeeping of crypto assets or cryptographic keys or means which allow the exercise of control over crypto assets.

licensing 20% confidence

CySEC Directive for the Prevention and Suppression of Money Laundering and Terrorist Financing (Regulatory Administrative Act 342/2021) for CASPs. This specific directive, issued by CySEC, outlines the detailed AML/CFT obligations for CASPs, including registration, operational requirements, and specific procedures.

licensing 100% confidence

CySEC Policy Statement PS-01-2021 currently outlines practical requirements for Crypto-Asset Service Provider (CASP) registration and ongoing compliance in Cyprus. However, this framework is in the process of being superseded by the EU's Markets in Crypto-Assets (MiCA) regulation, with CySEC mandating that existing CASPs in Cyprus must apply for authorization under MiCA by February 27, 2026.

licensing 90% confidence

Minimum initial capital requirements apply, typically tiered based on the scope of services. For custody and administration of crypto-assets, it falls under Class 2 services, requiring a minimum capital of €125,000.

licensing 80% confidence

Physical Presence: The CASP must have a physical presence in Cyprus and demonstrate substance.

licensing 90% confidence

Directors and key personnel must be "fit and proper," with adequate knowledge, experience, and integrity. For specific regulated entities, such as Cyprus Investment Firms (CIFs) under CySEC, at least four board members (two executive, two non-executive) must be present, with at least two executive directors managing day-to-day operations and physically residing in Cyprus. However, under general Cyprus company law, a private company requires at least one director, and a public company requires at least two directors.

licensing 80% confidence

AML/CFT Compliance: Comprehensive AML/CFT policies, procedures, and internal controls, including customer due diligence (CDD), ongoing monitoring, record-keeping, and suspicious transaction reporting.

stablecoin 90% confidence

E-money Tokens (EMTs) are crypto-assets referencing a single fiat currency, but in Cyprus, they are now treated under a transitional regulatory regime that distinguishes them from traditional e-money, with specific guidance from the Central Bank of Cyprus addressing the interplay between MiCA and PSD2.

stablecoin 70% confidence

EMT Issuers: Must be authorized as a credit institution (bank) or an e-money institution (EMI) under Directive 2009/110/EC (E-money Directive II). If an EMI, they also need to be specifically authorized under MiCA.

stablecoin 95% confidence

Competent Authority in Cyprus: The Cyprus Securities and Exchange Commission (CySEC) is the designated competent authority for the supervision of crypto-asset service providers (CASPs) and, under MiCA, will be the primary authority for authorizing and supervising ART issuers and existing EMIs/banks issuing EMTs.

stablecoin 95% confidence

Legal Reference: MiCA Regulation (EU) 2023/1114, Article 3(1)(5) and Title III (Articles 43-58).

aml 20% confidence

Identification and Verification of Customer Identity:

aml 20% confidence

Natural Persons: Full name, date and place of birth, nationality, permanent residential address, unique identification number (e.g., passport or ID number). Verification requires reliable, independent source documents and/or data.

aml 20% confidence

Identification of Beneficial Ownership: For legal entities, identifying and verifying the ultimate beneficial owner (UBO) who directly or indirectly holds 225% or more of the shares or voting rights, or otherwise exercises control.

aml 20% confidence

Source of Funds (SoF) / Source of Wealth (SoW): Especially for higher-risk clients or significant transactions, CASPs must take reasonable measures to establish the source of the funds and/or wealth involved.

aml 20% confidence

Enhanced Due Diligence (EDD): Must be applied in high-risk situations, including:

aml 20% confidence

Ongoing Monitoring: Continuously monitoring the business relationship and transactions to ensure consistency with the CASP's knowledge of the customer, their business, and risk profile. This includes monitoring for suspicious patterns or unusual deviations.

aml 20% confidence

Internal Reporting: Employees must report suspicions to the appointed Money Laundering Reporting Officer (MLRO).

aml 20% confidence

MLRO's Duty: The MLRO must evaluate the internal report and, if a suspicion is formed, submit an STR to the Unit for Combating Money Laundering (MOKAS), which is Cyprus's Financial Intelligence Unit (FIU).

aml 20% confidence

Tipping-off: CASPs and their employees are strictly prohibited from disclosing to the customer or any third party that an STR has been or will be submitted, or that a money laundering investigation is underway.

aml 20% confidence

Duration: Records must be kept for at least five (5) years from the completion of the transaction or the termination of the business relationship.

aml 20% confidence

Internal Policies and Procedures: CASPs must establish and maintain robust internal AML/CFT policies, controls, and procedures, including a comprehensive risk assessment. These should be documented in an "AML Manual."

aml 20% confidence

Money Laundering Reporting Officer (MLRO): Appointment of a suitably qualified and experienced MLRO at management level responsible for overseeing AML/CFT compliance.

aml 20% confidence

Staff Training: Regular and ongoing training for all relevant employees on AML/CFT risks, regulations, and internal procedures.

enforcement 70% confidence

Entity Targeted: eToro (Europe) Ltd (a major global trading platform also offering crypto services). Violation Type: Non-compliance with regulatory requirements related to organizational requirements, safeguarding clients' funds, and prevention of money laundering and terrorist financing (AML/CFT). This included deficiencies in operational risk management, internal controls, and measures taken to prevent money laundering and terrorist financing. Outcome: Imposition of an administrative fine. eToro (Europe) Ltd stated it has taken corrective measures.

enforcement 70% confidence

Entity Targeted: Bitpanda GmbH (a well-known European digital investment platform operating as a registered VASP in Cyprus). Violation Type: Non-compliance with the AML/CFT Law, specifically regarding internal controls and measures for the prevention of money laundering and terrorist financing, and deficiencies in customer due diligence procedures. Outcome: Imposition of an administrative fine. Bitpanda GmbH took corrective measures.

tax 95% confidence

Cyprus introduced a dedicated crypto tax framework via new Article 20E of the Income Tax Law, effective January 1, 2026, replacing the previous application of existing tax laws by analogy.

tax 100% confidence

If a company (resident in Cyprus) engages in cryptocurrency trading as its primary or significant business activity, all profits derived from such activities are subject to the 12.5% corporate income tax rate.

stablecoin 95% confidence

The strict reserve requirements (1:1 backing, segregation, investment in highly liquid/low-risk assets) fundamentally rule out purely algorithmic stablecoins that rely solely on arbitrage mechanisms or burning/minting without direct asset backing. If such a stablecoin cannot demonstrate 1:1 asset backing, it will not be able to obtain authorization under MiCA.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — A crypto-funded debit card program in Cyprus requires dual licensing (CASP registration with CySEC for the crypto off-ramp + EMI authorisation or partnership for the fiat/e-money component), full AML/CFT compliance under CySEC Directive 342/2021, physical substance in Cyprus, and a banking/BIN-sponsor partner; enforcement risk is material following recent fines against eToro and Bitpanda.

Questions this verdict aims to answer

  • What e-money / payment-institution license is required?
  • How is the crypto-to-fiat conversion regulated?
  • What KYC and AML obligations apply to cardholders?
  • What partner-bank or BIN-sponsor arrangements are required?