The passage of the draft Polish Crypto-Assets Act marks a new phase in the country's crypto regulatory framework!
On September 26, 2025, the Sejm (Lower House) of Poland passed the draft Crypto-Assets Market Act (hereinafter referred to as the “Act”) by a vote of 230 to 196. Although the Act still requires review by the Senate, signature by the President, and will come into effect 14 days after its publication (except for Article 70, concerning internet domain blocking, registration lists, and access restrictions, which will take effect four months after the Act’s publication), this legislative milestone signifies that the country’s crypto regulatory framework has entered a new stage.
This Act is not only Poland’s domestic “general outline for crypto regulation” but also deeply aligns with the unified framework of the EU’s Markets in Crypto-Assets Regulation (MiCA). During the legislative process, the draft underwent approximately three to four rounds of deliberation and 45 amendments (including fine-tuning of licensing boundaries and penalty standards), ensuring a smooth transition from the loose era of “anti-money laundering registration” to an orderly track of “comprehensive licensing regulation.”
For crypto practitioners intending to engage in crypto trading, token issuance, custody, or payment settlement services in Poland, this means that regulatory clarity is imminent—future operations must be conducted under a license; otherwise, entities will face fines or be forced to exit the market.
Regulatory Subjects and Scope: All “Crypto Players” Are Within Sight
The regulatory subjects defined in the Act remain highly consistent with MiCA. Poland’s legislation did not redefine regulatory boundaries but fully incorporated the regulatory subjects and business scopes established under MiCA into domestic law. The specific regulatory subjects include:
1. Crypto-asset service providers (CASPs), covering the following areas of business:
-
Operation of crypto-asset trading platforms;
-
Wallet custody and asset safekeeping services;
-
Payment and settlement-related services;
-
Other derivative businesses involving crypto assets.
2. Token issuers, including:“Asset-referenced token issuers”and“E-money token issuers”。
3. Foreign crypto-asset service providers: Institutions from other EU Member States may provide cross-border services in Poland through the “passporting mechanism” under Article 63 of MiCA.
In summary, if you operate within Poland or provide any form of crypto-asset services, regardless of where your company is registered, you must either obtain a license or exit the market.
Licensed vs. Unlicensed: Entering the Era of “License Required to Operate”
The Act implements a typical licensing regime for crypto-asset businesses. Only institutions authorized by the Polish Financial Supervision Authority (Komisja Nadzoru Finansowego, KNF) and holding a Crypto-Asset Service Provider (CASP) license may legally operate.
-
Licensed Entities
May conduct approved businesses within Poland or for Polish users. After obtaining a license, institutions must continuously fulfill compliance obligations (including regular reporting, internal audits, capital adequacy, risk control, etc.).
-
Unlicensed Entities
Those engaging in crypto services without permission will face substantial fines or criminal penalties. The Act explicitly lists various violations and penalty standards (see below).
Basic Requirements and Operating Costs for Licensed Entities: Comprehensive Increases in Capital, Compliance Frameworks, and Continuation Costs
This is the core part of the entire Act and the most noteworthy aspect. The regulatory logic is clear: to obtain a license, one must have capital, systems, and capabilities.
(I) Capital Requirements:
The Act states that CASPs must possess “sufficient funds.” This not only sets a minimum threshold for the registered capital of licensed entities but also includes comprehensive considerations of capital strength, such as liquidity management, risk reserve allocation, and segregation of client assets, to ensure compliance and solvency during market fluctuations and risk events.
Poland has not yet issued secondary regulations regarding minimum registered capital; therefore, MiCA standards remain the primary reference. Below are the minimum registered capital requirements under MiCA based on the different types of services provided by CASPs:

In addition to paid-in capital, regulators require CASPs to maintain “ongoing adequate capital.” If funds become insufficient due to business fluctuations or market losses, they must be replenished promptly.
(II) Regulatory Costs and Compliance Expenses: Operational “Compliance” Means Continuous Investment
1. The Act stipulates the cost allocation and fee structure for regulating the crypto-asset market, explaining how Token Issuers and CASPs will finance the regulatory framework:
-
License and assessment fees:Fees vary depending on the type of license or assessment, with a cap of €4,500;
-
Approval of information documents:Approval of documents: €3,000; Amendment of documents: €1,000;
-
Annual license maintenance and regulatory fees for CASPs: Based on the average total revenue over the past three years, ranging from €500 to 0.4% of the average annual revenue.
-
Annual license maintenance and regulatory fees for Token Issuers:Ranging from €500 to the product of the arithmetic mean of the total financial liabilities arising from the issuance of asset-referenced tokens or e-money tokens and an interest rate not exceeding 0.5%.
2. In addition to the costs of regulating the crypto-asset market, licensed entities must incur the following expenses during operations:
-
Regular financial and compliance audit expenditures;
-
External legal counsel and technical compliance costs;
-
Costs for building KYC systems, risk monitoring, and AML technology platforms.
Key Compliance and Risk Management Focus Areas for Licensed Entities
Licensed institutions must continue to manage compliance and risks during operations. To this end, the Act proposes multi-layered risk control and compliance requirements.
(I) Governance Structure and Compliance Architecture: Must Operate “Like a Financial Institution”
The Act requires CASPs to establish comprehensive governance and compliance systems, including:
-
Establishing independent compliance, risk control, and internal audit departments;
-
Management must possess professional qualifications and have no adverse records;
-
Establishing systems for risk identification, internal controls, and anomaly reporting;
-
Formulating professional confidentiality policies with clear technical standards;
-
Strictly enforcing anti-money laundering (AML) and know-your-customer (KYC) requirements.
In particular, Article 22 emphasizes that each institution must formulate internal regulations to refine the technical standards for “professional secrecy and information protection.” These standards are not limited to the corporate level but also include technical details such as system security, data access, information encryption, and internal transmission mechanisms.
The specific details of these technical standards will not be fully included in the main text of the Act but will be promulgated and implemented by the KNF through “secondary regulations.” These secondary regulations will uniformly standardize reporting content, operational details, technical compliance standards, cybersecurity standards, and regulatory interfaces to ensure consistency in execution across all institutions. This means that, in addition to the provisions of the Act itself, licensed institutions must closely monitor the supporting guidelines, detailed rules, and implementation standards issued by the KNF; otherwise, they may face the risk of “formal compliance but substantive violation.”
(II) Information Disclosure and Regulatory Reporting Obligations
CASPs must regularly disclose the following to the KNF:
-
Financial status and risk structure;
-
Reserves, trading volumes, and liquidity indicators;
-
System operation and security status;
-
Compliance controls, governance changes, significant transactions, etc.
Any event that may affect the safety of client assets or market stability must be reported immediately with an explanation of response measures. Regulatory authorities may also publicly disclose penalty decisions to ensure transparency and market accountability.
(III) Risk Management System
Licensed entities must establish a full-process system covering market risk, operational risk, and liquidity risk. Requirements include:
-
Conducting regular stress tests;
-
Establishing abnormal transaction monitoring systems;
-
Implementing customer segmentation and high-risk account identification mechanisms.
(IV) Investor Protection and Information Transparency
Regarding investor protection and information disclosure, the Act imposes higher requirements on licensed entities:
-
Full disclosure of crypto-asset risks;
-
Conducting suitability assessments for retail clients;
-
Establishing mechanisms for the segregation of client assets and compensation;
-
Setting up channels for complaint handling and dispute resolution.
Regulators hope to reshape investor trust and market confidence through institutional construction.
(V) Anti-Money Laundering and Counter-Terrorist Financing (AML/CFT)
Consistent with EU standards, CASPs must implement:
-
End-to-end KYC verification;
-
Monitoring and reporting of suspicious transactions;
-
Enhanced due diligence for high-risk customers;
-
Automated traceability mechanisms within systems.
Violations may not only result in fines but also lead to license revocation.
(VI) Compliance Audit and Reporting Mechanisms
Licensed institutions must:
-
Undergo regular external independent audits;
-
Submit annual compliance and risk reports;
-
Obtain prior approval from the KNF for significant changes in governance, equity, or business structure.
Specific uniform templates and timeline requirements will be prescribed in future operational secondary regulations issued by the KNF.
Prohibited Acts and Criminal Liability
In addition to clarifying compliance requirements and the regulatory framework, the Polish Crypto-Assets Act strictly defines the behavioral boundaries for market participants, explicitly listing illegal and non-compliant acts to be avoided in market operations. Furthermore, by establishing criminal liability provisions, the Act adds a “high-voltage line” for illegal and non-compliant activities in the crypto-asset sector, ensuring market transparency and order through severe punitive measures.
(I) Prohibited Acts and Penalties (Including Unlicensed Entities)
1. Licensed Entities

2. Unlicensed Entities

(II) Criminal Liability
The following are the main criminal offenses and penalties defined in the Act:

Transition Period and Implementation Timeline: Existing Enterprises Must “Migrate” Smoothly
To help the market transition smoothly and avoid operational disruptions, the Act establishes a transition period for existing Virtual Asset Service Providers (VASPs) registered entities: VASPs currently registered under anti-money laundering regulations may continue to operate in compliance with current rules until July 1, 2026, but must gradually upgrade to new standards until they obtain CASP authorization or reach the deadline. Below are the specific requirements for the transition period under the Act. Additionally, market participants should note the effective dates of secondary regulations accompanying the implementation of the Act.


