Montenegro: crypto & digital assets regulation

Partially regulated

Montenegro: VASPs regulated under AML law; no specific crypto capital regime yet

Lead regulator
Central Bank of Montenegro (CBN) / Financial Intelligence Unit (FIU)
Also involved
FIU (AML supervision) · CBN (systemic oversight)
Core law
Law on the Prevention of Money Laundering and Terrorist Financing (2023)
Entry capital
Approval timeline
Customer assets
No specific segregation rule defined in source docs
Data protection
Law on Personal Data Protection · Agency for Personal Data Protection
Sandbox
No

Montenegro regulates crypto-asset service providers (VASPs) primarily as reporting entities under its AML framework, supervised by the Financial Intelligence Unit (FIU) with oversight from the Central Bank of Montenegro (CBN). There is no dedicated crypto licensing regime with specific capital requirements for VASPs; instead, entities must comply with general AML/CFT obligations and, if applicable, digital operational resilience standards. The regulatory stance is cautious, focusing on transparency and financial crime prevention rather than fostering a specific crypto industry.

Which licence do you need?

Your activityRequirementCapitalTimelineAuthority
Exchange / trading platformRegistration[1]

Must register as reporting entity under AML law

FIU
Custody of client assetsRegistration[1]

Treated as VASP activity under AML framework

FIU
Token issuance / public offeringUncertainverify with regulator

No specific securities or token issuance law cited

Broker-dealer / OTC deskUncertainverify with regulator

No specific broker-dealer regime for crypto cited

Stablecoin issuanceUncertainverify with regulator

No specific stablecoin regulation identified

Crypto payments acceptanceRegistration[1]

Crypto payment services fall under AML reporting entities

FIU
Mining / staking servicesUnregulated

Mining/staking not explicitly regulated as financial service

Advisory / portfolio managementUncertainverify with regulator

No specific investment advice regime for crypto cited

New — what changed recently

  • 2023-01-01Law on Digital Operational Resilience for the Financial SectorExtended digital resilience requirements to crypto-asset service providers alongside traditional financial entities.
  • 2023-01-01Law on the Prevention of Money Laundering and Terrorist FinancingFormalized VASPs as reporting entities subject to AML/CFT obligations and FIU supervision.

Market-entry checklist

  1. 1Register with FIU as reporting entityComply with AML/CFT obligations under the 2023 Law on Prevention of Money Laundering.
  2. 2Implement DORA compliance measuresAdopt digital operational resilience standards as mandated by the 2023 DORA law.
  3. 3Establish local legal entityRegister a company in Montenegro to operate as a reporting entity.
  4. 4Appoint compliance officerDesignate a responsible person for AML/CFT compliance as required by law.
  5. 5Prepare transaction monitoring systemsImplement systems to detect and report suspicious transactions to the FIU.
This guide is compiled automatically from 1 primary-source documents published by Montenegro's regulators, reviewed by RegAlert, and refreshed monthly (last updated 2026-07-12). It is not legal advice — always confirm requirements with the regulator or local counsel before acting.