CMS Expert Guide to Crypto Regulation in Sweden
- How is crypto regulated?
- What are the steps taken by the regulator to adopt MiCAR?
- Are the following activities regulated or unregulated in your jurisdiction?—Exchange (buy/sell)—Custody (hold)—Borrowing/lending—Yield/staking services—Staking on proof of stake consensus mechanisms
- Can offshore business provide services to local customers on either active solicitation or reverse solicitation basis?
- How long would establishing a cryptoasset business/obtaining a license in your jurisdiction take?
- What would be the approximate overall cost of obtaining a licence?
- What is the probability (%) of success in obtaining a licence?
- What other limitations are there in your jurisdiction when looking to set up a cryptoasset business?
jurisdiction
Disclaimer: This chapter was last updated on 3 September 2026 and does not reflect any subsequent developments. The information provided is intended for general informational purposes and should not be construed as legal advice.
1. How is crypto regulated?
| Jurisdiction-specific MiCAR implementation and deviations | Any other Regulation |
Crypto-assets in the EU are regulated under Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCAR), which establishes a harmonised framework for the issuance, offering, and trading of crypto-assets across EU Member States. MiCAR applies to crypto-assets that are not covered by existing EU financial services legislation, such as MiFID II and the Prospectus Regulation, and introduces specific regimes for: Asset-referenced tokens (ARTs); E-money tokens (EMTs); and Other crypto-assets, including utility tokens. MiCAR also sets out conduct of business rules, governance standards, asset segregation requirements and prudential requirements for crypto-asset service providers (CASPs), which include services such as custody, trading, exchange, advising, transfer and operation of trading platforms. As of 30 December 2024, CASPs must have a licence issued by the national competent authority to offer their services in the EU. Regulated financial entities such as credit institutions, investment firms, market operators, and electronic money institutions can offer crypto-asset services upon notification. MiCAR entered into force on 29 June 2023, with the main provisions applying from 30 December 2024, while rules relating to ARTs and EMTs applied from 30 June 2024. | AML Regulation Directive (EU) 2018/843, which amends Directive (EU) 2015/849 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing, has been implemented into Swedish legislation through the Swedish Money Laundering and Terrorist Financing Prevention Act (2017:630) (the ”AML Act”). Crypto-asset service providers, as defined in MiCAR, have been obligated to comply with the AML Act since 30 December 2024. Further amendments have been made to the AML Act following the implementation of MiCAR, including specific requirements for crypto-asset service providers. For example, when entering into a correspondent relationship for crypto-asset services with a counterparty entity that is not established in the EEA, providers must verify whether the counterparty is licensed or registered to operate. Furthermore, if a crypto-asset service provider offers its services from another EEA state without establishing a branch or subsidiary in Sweden, the Swedish Financial Supervisory Authority (“SFSA”) has the right to require the provider to appoint a central contact point in Sweden. The CFO Act Prior to the implementation of MiCAR, providers that offer services relating to the safeguarding of private cryptographic keys on behalf of customers, storage, and facilitating the holding and transfer of virtual currencies, and that maintain a physical presence, such as a branch office, in Sweden, were previously obligated to register with SFSA under the Certain Financial Operations Act (1996:1006) (the “CFO Act”). The scope of the CFO Act was amended as of 30 December 2024 to exclude the above-mentioned services as part of the implementation process of MiCAR. Criminal Liability for Unauthorised Financial Activity Since 1 March 2026, it is a criminal offence in Sweden to conduct financial activity without the required authorisation or registration from the SFSA. The new Act on Penalties for Unauthorised Financial Activity (Sw. Lag (2026:56) om straff för olovlig finansiell verksamhet) (the "Criminal Liability Act") applies to anyone who, intentionally or through gross negligence, carries out financial activity — including crypto-asset services — without the necessary authorisation or registration. Criminal liability attaches to the natural persons responsible for the unauthorised activity, such as formal or de facto representatives of the entity conducting the business. The Criminal Liability Act also establishes a duty for the SFSA to report suspected offences to the public prosecutor. For providers of crypto-asset services, this means that offering such services in Sweden without the required MiCAR authorisation now carries a risk of personal criminal liability for those individuals directing or controlling the activity. Please see our answer below for the additional steps taken to adopt MiCAR in Sweden. |
2. What are the steps taken by the regulator to adopt MiCAR?
MiCAR has direct effect in Sweden. Multiple legislative steps have however been taken by the regulator to implement MiCAR.
An act relating to the appointment of the national competent authority was passed on 22 May 2024. The SFSA was appointed as the national competent authority to handle all relevant applications for the authorisation of issuers of e-money tokens and asset-referenced tokens. The act entered into force on 30 June 2024.
On 27 November 2024, the Swedish Parliament passed a new act with supplementary provisions to MiCAR (Sw. Lag (2024:1159) med kompletterande bestämmelser till EU:s förordning om marknader för kryptotillgångar). The new act regulates, inter alia, the SFSA’s (as the national competent authority) supervisory and investigative powers, as well as its rights to take intervening measures. The act entered into force on 30 December 2024.
As stated above, existing laws have been amended as part of the implementation of MiCAR. For example, crypto-asset service providers are now subject to direct regulation under the AML Act, and the scope of the CFO Act has been reduced to exclude administration and the trading of virtual currencies following MiCAR. These legislative changes entered into force on 30 December 2024.
The SFSA applies the EU regulatory framework and takes account of technical standards and guidelines developed by the European Supervisory Authorities, including ESMA and EBA. In relation to MiCAR, the SFSA has stated that it will comply with a number of guidelines issued by ESMA and/or EBA, including guidelines concerning the classification of crypto-assets, the provision of services by third-country firms, crypto-asset transfer services, supervisory practices for the prevention and detection of market abuse, and knowledge and competence requirements. The SFSA considers guidelines issued by the European Supervisory Authorities and addressed to competent authorities or financial market participants to be comparable to Swedish general guidelines (Sw. allmänna råd).
3. Are the following activities regulated or unregulated in your jurisdiction?—Exchange (buy/sell)—Custody (hold)—Borrowing/lending—Yield/staking services—Staking on proof of stake consensus mechanisms
| Jurisdiction-specific MiCAR implementation and deviations | Any other Regulation |
Under MiCAR, the following activities are regulated throughout the EU: Direct sales of tokens by issuers:
Exchange (buy/sell):
Custody (hold):
Borrowing/lending:
Yield/staking services:
Staking on proof of stake consensus mechanisms:
NFTs:
| Generally, it can be stated that Sweden has previously had minimal regulations concerning crypto-asset service-related activities. The introduction of MiCAR has therefore brought a significant change to the legal landscape of crypto regulation. The listed activities are not specifically regulated in the new act of supplementary provisions and are thus subject to MiCAR, with some exceptions In addition to the general MiCAR framework (covered in the new chapter LINK) it can be said in relation to lending or borrowing of crypto-assets, that under Swedish law, borrowing and lending of crypto-assets may technically be considered a transfer of title of the crypto-asset. It remains uncertain whether the SFSA considers services relating to such activities to fall within the scope of MiCAR. |
4. Can offshore business provide services to local customers on either active solicitation or reverse solicitation basis?
| Jurisdiction-specific MiCAR implementation and deviations | Any other Regulation |
Active solicitation by offshore firms into the EU is not permitted under MiCAR unless the firm is authorised as a CASP within the EU. MiCAR permits reliance on reverse solicitation only under strict conditions. Offshore firms may in certain cases provide crypto-asset services to an EU client without a MiCAR licence, but only if the client has initiated the request entirely on their own initiative. Reverse solicitation under MiCAR is only permitted under strict and narrowly interpreted conditions. ESMA emphasises that this exemption is exceptional and applies only when: (i) the EU client initiates the service request on their own exclusive initiative, without prior solicitation or marketing by the offshore firm; (ii) the exemption is limited to the specific crypto-asset service requested; and (iii) it cannot be used to expand into other services. | N/A |
5. How long would establishing a cryptoasset business/obtaining a license in your jurisdiction take?
| Jurisdiction-specific MiCAR implementation and deviations | Any other Regulation |
Please refer to individual chapters in this guide. MiCAR sets out a harmonised process across the EU. Competent authorities are required to assess licence applications within 40 working days of receiving a complete application. During the assessment period and no later than on the 20th working day of that period, competent authorities may request further information. This will suspend the 40 working day period, but the suspension cannot exceed 20 working days. The exact time to prepare an application and address any follow-up queries may vary by jurisdiction. In practice, obtaining a MiCAR licence will take several months. | The processing time with the SFSA for authorisation as a crypto-asset service provider is as follows:
|
6. What would be the approximate overall cost of obtaining a licence?
| Jurisdiction-specific MiCAR implementation and deviations | Any other Regulation |
Please refer to individual chapters in this guide. MiCAR does not fix costs at EU level. Costs vary based on:
| The cost of obtaining licences under MiCAR varies depending on the type of licence and the complexity of both the application and the company. The current fee for obtaining authorisation as a crypto-asset service provider ranges between SEK 135,000 – 690,000, while the processing fee for obtaining a licence to issue asset-referenced tokens or seek the admission of trading of asset-referenced tokens ranges between SEK 525,000 – 13,500,000. All processing fees at the SFSA relating to MiCAR can be found at the link (in Swedish): LINK The processing fees for authorisation to provide services related to virtual currency under the CFO Act were removed following the amendment to the scope of the CFO Act. The SFSA charges an annual supervisory fee based on the balance sheet total, with a minimum of SEK 150,000 per year. |
7. What is the probability (%) of success in obtaining a licence?
| Jurisdiction-specific MiCAR implementation and deviations | Any other Regulation |
| Please refer to individual chapters in this guide. | This cannot be determined, as decisions made by the SFSA are taken on a case-by-case basis. As of 3 September 2026, the SFSA has received seven applications for authorisation to provide crypto-asset services. Only one of these applicants (Safello AB) has been granted a licence, while two applicants had their applications rejected due to deficiencies in their anti-money laundering procedures. |
8. What other limitations are there in your jurisdiction when looking to set up a cryptoasset business?
| Jurisdiction-specific MiCAR implementation and deviations | Any other Regulation |
| Please refer to individual chapters in this guide. | When establishing a crypto-asset business in Sweden as either a private or public limited liability company, certain corporate law restrictions need to be considered. These include, for example, residency requirements for board members and managing directors. |