On September 26, 2025, Poland’s Sejm (Lower House) approved the draft of the Crypto-Assets Market Act (referred to as “the Act”) with 230 votes in favor and 196 against. Although the Act still requires review by the Senate, signature by the President, and will take effect 14 days after publication (except for Article 70: concerning internet domain blocking, registration directories, and access restrictions, which will only take effect four months after publication), this legislative milestone marks a new phase in the country’s crypto regulation system.
This Act not only serves as Poland’s comprehensive “crypto regulation framework” but also aligns deeply with the European Union’s Markets in Crypto-Assets Regulation (MiCA): during the legislative process, the bill underwent about 3-4 review rounds and 45 amendments (including fine-tuning licensing boundaries and penalty standards), ensuring a smooth transition from the “anti-money laundering registration” era to an “全面牌照监管” (comprehensive licensing regulation) track.
For crypto practitioners intending to operate in Poland—such as trading, token issuance, custody, or payment settlement—this means regulatory transparency is imminent—future operations must be licensed; otherwise, penalties or market exit are likely.
The scope of regulation in the Act is highly consistent with MiCA. Poland’s legislation does not redefine the regulatory boundaries but fully incorporates the entities and business activities established under MiCA into domestic law. Specifically, the regulated entities include:
Token issuers: including “asset-backed token issuers” and “electronic money token issuers.”
Foreign crypto asset service providers: institutions from other EU member states can provide cross-border services in Poland via the MiCA Article 63 “passport mechanism.”
In summary, if you operate or provide any form of crypto asset services within Poland—regardless of where your company is registered—you must either obtain a license or exit the market.
The Act enforces a typical licensing regime for crypto asset businesses. Only institutions authorized by the Polish Financial Supervision Authority (Komisja Nadzoru Finansowego, KNF) and holding a Crypto Asset Service Provider license (CASP License) can operate legally.
Can conduct approved activities within Poland or for Polish users. After licensing, entities must continuously comply with obligations such as regular reporting, internal audits, capital adequacy, and risk management.
Engaging in crypto services without permission will face hefty fines or criminal penalties. The Act explicitly lists various illegal conduct and penalty standards (see below).
This is the core of the entire Act and the most noteworthy part. The regulatory logic is clear: to obtain a license, you need money, systems, and capabilities.
The Act states that CASPs must have “sufficient funds,” which not only sets a minimum registered capital threshold but also encompasses liquidity management, risk reserves, and customer asset segregation to ensure ongoing compliance and solvency amid market fluctuations and risks.
Currently, Poland has not issued specific secondary regulations on minimum registered capital, so MiCA standards remain the primary reference. Below are the minimum registered capital requirements under MiCA for different service types provided by CASPs:
Besides paid-in capital, regulators require CASPs to maintain “continuously sufficient capital,” and if business fluctuations or market losses cause capital shortfalls, timely replenishment is mandatory.
Licensed institutions must implement robust compliance and risk management practices, with multi-layered requirements.
The Act requires CASPs to establish comprehensive governance and compliance systems, including:
Particularly, Article 22 emphasizes: each institution must develop internal rules detailing technical standards for “professional confidentiality and information protection.” These standards cover not only corporate policies but also system security, data access, encryption, and internal communication protocols.
These technical standards will not be fully detailed in the Act itself but will be issued gradually by KNF through “secondary regulations.” These will standardize reporting content, operational procedures, technical compliance, cybersecurity standards, and regulatory interfaces, ensuring consistency across all institutions. Therefore, licensed entities must pay close attention to KNF’s guidance, rules, and implementation standards to avoid “formal compliance but substantive violations.”
CASPs are required to regularly disclose to KNF:
Any events that could impact client asset safety or market stability must be reported immediately with response measures. The regulator may also publish enforcement decisions to ensure transparency and market accountability.
Licensed entities must establish comprehensive risk management covering market, operational, and liquidity risks, including:
The Act imposes higher requirements on licensed entities regarding investor protection and information disclosure:
The goal is to rebuild investor trust and market safety through institutional standards.
Aligned with EU standards, CASPs must implement:
Violations can lead to fines or license revocation.
Licensed institutions must:
Specific templates and deadlines will be detailed in future operational secondary regulations issued by KNF.
Beyond explicit compliance and regulatory requirements, the Polish crypto asset law also strictly limits the conduct of market participants, explicitly listing illegal and non-compliant behaviors to avoid. The law also establishes criminal liability provisions, creating a “high-voltage line” for illegal activities in the crypto sector to ensure market transparency and order.
The law defines key criminal offenses and penalties, including:
To facilitate a smooth transition and avoid operational disruptions, the Act provides a transition period for existing crypto service providers (VASPs). Currently registered under anti-money laundering regulations, VASPs can continue compliant operations until July 1, 2026, but must gradually upgrade to meet the new standards and obtain CASP authorization or comply by the deadline. The following outlines the specific requirements for the transition period, along with the implementation of secondary rules issued by the market regulator.