Custodial wallet / SaaS in Cyprus
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Cyprus with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- CDD: Identify and verify natural persons (full name, DOB, nationality, address, ID number) and legal entities (name, form, registration, directors, UBO).
- UBO identification: Identify beneficial owners with ≥25% share/voting rights or control.
- SoF/SoW verification: Required for higher-risk clients or significant transactions.
- EDD: Mandatory for PEPs, high-risk third-country clients, non-face-to-face relationships without safeguards, and unusual/high-value transactions.
- Ongoing monitoring: Continuously monitor business relationships and transactions for consistency with customer risk profile.
- Internal reporting: Employees must report suspicions to the MLRO; MLRO evaluates and submits STRs to MOKAS (Cyprus FIU).
- Record-keeping: Maintain all CDD documents, transaction records, and AML policies for at least 5 years, accessible to CySEC and MOKAS.
- Appoint an MLRO at management level; maintain AML manual and comprehensive risk assessment.
- Conduct regular and ongoing AML/CFT staff training.
- Tipping-off prohibition: Cannot disclose STR submission to customers or third parties.
Key Restrictions
- Must obtain CASP authorization from CySEC under MiCA (applies from December 30, 2024) for custody and administration of crypto-assets.
- Minimum initial capital of €125,000 for custody services (Class 2).
- Must maintain physical presence (substance) in Cyprus.
- Management must be 'fit and proper'; at least 4 board members (2 executive, 2 non-executive) for certain structures.
- Client crypto-assets must be held separately from the CASP's own assets and not used for the CASP's own account (Article 67 MiCA).
- Must hold professional indemnity insurance or own funds sufficient to cover liability risks from custody activities (Article 67(4) MiCA).
- Must establish internal safeguarding policy with appropriate technological/organisational measures, including robust IT systems, secure key storage, access controls, cybersecurity, and business continuity plans (Article 67 MiCA).
- SaaS white-label model: the CASP (custodian) bears direct regulatory obligations under MiCA and AML law; white-label clients likely need their own CASP registration if they exercise control over keys or direct custody services.
Key Risks
- MiCA transition risk: operators registered under CySEC's PS-01-2021 regime must re-apply or notify for authorization under the new MiCA framework by December 30, 2024.
- SaaS/white-label ambiguity: unclear regulatory boundary between the SaaS provider as 'custodian' vs the white-label client; both may need separate CASP authorisation if both hold or access keys.
- Enforcement precedent: CySEC has fined major operators (eToro, Bitpanda) for AML/CFT and organisational compliance failures, indicating active enforcement posture.
- Segregation and insolvency risk: MiCA requires dedicated accounts/mechanisms for client asset protection in insolvency, but practical insolvency-remote structures are not fully prescribed.
- No explicit cold-storage mandate in MiCA — reliance on 'appropriate technological measures' leaves interpretation risk.
- 5AMLD/6AMLD obligations remain in force and are supplemented by CySEC Directive 342/2021, creating a layered compliance burden.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA):
CASPs offering "custody and administration of crypto-assets on behalf of clients" will require authorization as a CASP under MiCA. CySEC will be the competent authority for authorizing and supervising CASPs in Cyprus.
Existing CASPs in Cyprus will need to adapt their operations and potentially re-apply or notify for authorization under MiCA.
Article 67: CASPs providing custody services must hold crypto-assets on behalf of clients separately from their own assets. They must ensure that client crypto-assets are not used for their own account and are identifiable from the CASP's own crypto-assets.
This means dedicated accounts or mechanisms to ensure client ownership is protected, particularly in case of the CASP's insolvency.
Article 67(4): CASPs providing custody services must either have a professional indemnity insurance policy or own funds equivalent to the potential liability risks arising from their activities. The amount of such insurance or own funds must be sufficient to cover losses that may arise from negligence, errors, omissions, fraud, or operational failures. ESMA will develop regulatory technical standards (RTS) to specify the minimum monetary amount of the professional indemnity insurance or own funds.
Article 67: CASPs must establish, implement, and maintain an internal policy on safeguarding client crypto-assets, which shall include appropriate technological and organisational measures to ensure the security of the crypto-assets.
This includes robust IT systems, secure storage of cryptographic keys, access controls, cybersecurity protocols, and business continuity plans. While not explicitly naming "cold storage," the emphasis on "appropriate technological and organisational measures" for safeguarding keys and assets strongly implies that cold storage (or equivalent highly secure offline methods) will be a standard requirement for significant holdings to meet MiCA's security obligations.
Application Process: Submission of a detailed application to CySEC.
Minimum initial capital requirements apply, typically tiered based on the scope of services. For custody and administration of crypto-assets, it falls under Class 2 services, requiring a minimum capital of €125,000.
Physical Presence: The CASP must have a physical presence in Cyprus and demonstrate substance.
Directors and key personnel must be "fit and proper," with adequate knowledge, experience, and integrity. For specific regulated entities, such as Cyprus Investment Firms (CIFs) under CySEC, at least four board members (two executive, two non-executive) must be present, with at least two executive directors managing day-to-day operations and physically residing in Cyprus. However, under general Cyprus company law, a private company requires at least one director, and a public company requires at least two directors.
Directive (EU) 2018/843 (5AMLD): Crucially extended the scope of EU AML rules to include crypto-asset exchanges and custodian wallet providers, requiring them to be regulated and subject to AML/CFT obligations.
CySEC Directive for the Prevention and Suppression of Money Laundering and Terrorist Financing (Regulatory Administrative Act 342/2021) for CASPs. This specific directive, issued by CySEC, outlines the detailed AML/CFT obligations for CASPs, including registration, operational requirements, and specific procedures.
CySEC Policy Statement PS-01-2021 currently outlines practical requirements for Crypto-Asset Service Provider (CASP) registration and ongoing compliance in Cyprus. However, this framework is in the process of being superseded by the EU's Markets in Crypto-Assets (MiCA) regulation, with CySEC mandating that existing CASPs in Cyprus must apply for authorization under MiCA by February 27, 2026.
Identification and Verification of Customer Identity:
Natural Persons: Full name, date and place of birth, nationality, permanent residential address, unique identification number (e.g., passport or ID number). Verification requires reliable, independent source documents and/or data.
Legal Entities: Company name, legal form, registration number, registered address, names of directors and company secretary, articles of association, and proof of legal existence.
Identification of Beneficial Ownership: For legal entities, identifying and verifying the ultimate beneficial owner (UBO) who directly or indirectly holds 225% or more of the shares or voting rights, or otherwise exercises control.
Source of Funds (SoF) / Source of Wealth (SoW): Especially for higher-risk clients or significant transactions, CASPs must take reasonable measures to establish the source of the funds and/or wealth involved.
Enhanced Due Diligence (EDD): Must be applied in high-risk situations, including:
Business relationships with Politically Exposed Persons (PEPs), their family members, or close associates.
Customers residing in or conducting transactions with high-risk third countries (as identified by the EU or FATF).
Non-face-to-face business relationships without adequate safeguards.
Transactions involving unusual patterns, high value, or complex structures.
Ongoing Monitoring: Continuously monitoring the business relationship and transactions to ensure consistency with the CASP's knowledge of the customer, their business, and risk profile. This includes monitoring for suspicious patterns or unusual deviations.
Internal Reporting: Employees must report suspicions to the appointed Money Laundering Reporting Officer (MLRO).
MLRO's Duty: The MLRO must evaluate the internal report and, if a suspicion is formed, submit an STR to the Unit for Combating Money Laundering (MOKAS), which is Cyprus's Financial Intelligence Unit (FIU).
Tipping-off: CASPs and their employees are strictly prohibited from disclosing to the customer or any third party that an STR has been or will be submitted, or that a money laundering investigation is underway.
Duration: Records must be kept for at least five (5) years from the completion of the transaction or the termination of the business relationship.
Internal Policies and Procedures: CASPs must establish and maintain robust internal AML/CFT policies, controls, and procedures, including a comprehensive risk assessment. These should be documented in an "AML Manual."
Money Laundering Reporting Officer (MLRO): Appointment of a suitably qualified and experienced MLRO at management level responsible for overseeing AML/CFT compliance.
Staff Training: Regular and ongoing training for all relevant employees on AML/CFT risks, regulations, and internal procedures.
Entity Targeted: eToro (Europe) Ltd (a major global trading platform also offering crypto services). Violation Type: Non-compliance with regulatory requirements related to organizational requirements, safeguarding clients' funds, and prevention of money laundering and terrorist financing (AML/CFT). This included deficiencies in operational risk management, internal controls, and measures taken to prevent money laundering and terrorist financing. Outcome: Imposition of an administrative fine. eToro (Europe) Ltd stated it has taken corrective measures.
Entity Targeted: Bitpanda GmbH (a well-known European digital investment platform operating as a registered VASP in Cyprus). Violation Type: Non-compliance with the AML/CFT Law, specifically regarding internal controls and measures for the prevention of money laundering and terrorist financing, and deficiencies in customer due diligence procedures. Outcome: Imposition of an administrative fine. Bitpanda GmbH took corrective measures.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS providers can operate in Cyprus as MiCA-authorised CASPs with a local physical presence, minimum €125,000 capital, professional indemnity insurance or own funds, strict asset segregation, and comprehensive AML/CFT obligations under CySEC supervision; the MiCA transition deadline is December 30, 2024, and the SaaS/white-label split of regulatory duties carries ambiguity risk.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?