EST · MMXXVI
Home/Jurisdictions/Compare/European Union (MiCA) vs Lithuania: Where to License a Crypto Business
Licensing & Registration

European Union (MiCA) vs Lithuania: Where to License a Crypto Business

European Union (MiCA) vs Lithuania: Where to License a Crypto Business. Cross-border digital-asset legal counsel for business – licensing, disputes and structur

For a digital-asset business choosing between a direct MiCA (Markets in Crypto-Assets Regulation) authorisation and a Lithuania-routed EU entry, the legal question is not which jurisdiction looks friendlier on paper. The question is which structure sustains operations, banking and growth across the markets you actually intend to serve. Operating without the right licence exposes the business to enforcement action, frozen payment rails and the loss of institutional banking relationships – risks that compound quickly in a regulatory environment that is tightening across every major hub.

MiCA created a single CASP (Crypto-Asset Service Provider) authorisation that passes across the EU and EEA from the member state that grants it. Lithuania, supervised by the Bank of Lithuania, was for several years the fastest EU entry point for VASP (virtual asset service provider) registration and remains a relevant gateway as the MiCA transition matures. The two paths are not opposites; for many operators they are sequential, with Lithuania serving as the initial EU foothold and a full CASP authorisation following as the business scales. This comparison maps the six decision axes that matter most and identifies which operator profile belongs in which structure.

What the Regulatory Perimeter Covers

MiCA establishes the first comprehensive EU-wide regime for crypto-assets, covering exchanges, custodians, advisers, portfolio managers and transfer services under a unified CASP authorisation issued by a national competent authority and passported across all member states. The regime also creates distinct authorisation tracks for ART (asset-referenced token) and EMT (e-money token) issuers, with whitepaper obligations and issuer-level requirements that sit above the service-provider tier.

Lithuania's framework operated through a lighter-touch VASP registration under the Bank of Lithuania and the country's AML supervisory regime before MiCA. Registered entities could passport AML compliance signals across the EU but could not passport regulated service permissions the way a MiCA CASP can. That distinction is the structural heart of this comparison. As MiCA's transition provisions run their course, Lithuanian-registered VASPs that continue to serve EU clients at scale will need CASP authorisation regardless of where they incorporated.

The practical perimeter question is therefore this: does your current activity require a passportable regulated permission today, or can a well-structured VASP registration carry the business through the transition while the CASP application is prepared? The answer turns on the services you offer, the clients you serve and the banking relationships you depend on.

To map which permissions apply to your specific activity set, contact OBOLUS at info@oboluslaw.com. The service mix – custody, exchange, advice, token issuance – changes the analysis materially, and a misclassified activity is one of the most common structural errors we see at the outset.

How the Licence Categories Compare

Under MiCA, the CASP authorisation is activity-based: an entity applies for the specific services it intends to provide, and the authorisation is scoped accordingly. A business providing only custody holds a narrower permission than one operating an exchange and offering portfolio management. Each activity category carries its own capital, governance and organisational requirements, which the applicable MiCA regime sets at the EU level, leaving limited room for member-state discretion on the substantive thresholds.

Lithuania's legacy VASP registration was a registration rather than a full licence – an important distinction. Registration confirmed AML-compliance status; it did not confer a regulated permission to provide investment services or passportable financial services. The Bank of Lithuania's approach was efficient: registration timelines were typically measured in weeks rather than months, and the substance requirements focused on AML/CFT policy, beneficial-owner transparency and the fitness of management. That efficiency attracted a large volume of crypto operators to the Lithuanian register during the pre-MiCA period.

Under MiCA's transition provisions, entities operating in Lithuania under the prior regime have a defined window to apply for CASP authorisation. The Bank of Lithuania acts as the national competent authority for MiCA purposes, so a Lithuanian-incorporated entity seeks CASP authorisation from the Bank of Lithuania – maintaining the same supervisory relationship while upgrading to the full EU permission. An operator that never registered in Lithuania and is entering the EU for the first time faces the same CASP authorisation process regardless of which member state it chooses; the member-state selection then becomes a question of supervisory culture, substance expectations and the practical depth of local support.

What Do the Timelines and Substance Requirements Look Like?

MiCA sets a statutory target period for CASP authorisation decisions, but the practical timeline at each national competent authority reflects that authority's case load, its maturity with the new regime and the completeness of the application submitted. In our practice, applications that arrive with incomplete AML frameworks, thin governance documentation or unclear beneficial-owner structures are the primary driver of delays – not the statutory calendar. Operators who treat the application as a compliance exercise rather than a business case consistently encounter longer timelines.

Lithuania historically processed VASP registrations faster than most EU jurisdictions. That speed advantage narrows under MiCA because the substantive requirements are now harmonised at the EU level. Where Lithuanian competent authority practice may still offer an advantage is familiarity with crypto-business models and a track record of working through novel structure questions that a less-experienced authority might refer upward. That institutional familiarity is not guaranteed, but it is a legitimate factor in member-state selection for a first-time CASP applicant.

Substance requirements under MiCA – registered office, senior management presence, governance bodies, qualified AML/CFT compliance function – are set at the regime level. No member state can waive them. An operator that builds a genuine operational presence in Lithuania, with a compliance officer employed locally and board members who can credibly represent the entity to the Bank of Lithuania, is in a materially stronger position than one that incorporates a shell and expects the registration to carry the weight.

In a recent licensing matter, a payments company sought CASP authorisation in an EU member state after operating under a transitional VASP registration. The initial application stalled because the AML framework documentation did not reflect the entity's actual transaction flows. We restructured the compliance narrative, aligned the governance evidence to the competent authority's published expectations and resubmitted. The application moved to the next procedural stage within the authority's standard review window. No outcome is guaranteed, but preparation quality is the single largest variable within the applicant's control.

AML, the Travel Rule and Cross-Border Compliance Posture

Both the MiCA regime and the Lithuanian supervisory framework operate within the FATF Recommendations, including Recommendation 15 on virtual assets and the Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer). ESMA and the European Banking Authority provide joint guidance on the AML expectations that apply to CASPs across the EU, and the Bank of Lithuania as national competent authority supervises against those standards.

For operators whose transaction flows cross jurisdictions – an exchange serving users in Asia, the Middle East and Europe from a single EU entity – the Travel Rule creates practical compliance obligations that the licence structure alone does not resolve. A Lithuanian or EU-licensed entity transferring value to a counterpart VASP in Singapore (supervised by MAS under the Payment Services Act) or in Hong Kong (supervised by the SFC under the VATP regime) must manage data-passing obligations under multiple Travel Rule implementations simultaneously.

The cross-border AML posture is therefore not just a licensing question. It is a technology and counterparty-due-diligence question that a well-constructed compliance framework addresses at the architectural level before go-live. Operators who separate the "get licensed" workstream from the "build compliance infrastructure" workstream consistently discover the conflict at the worst moment – after launch, when a banking partner's correspondent triggers a review.

Which Operator Profile Belongs in Which Structure?

The right structure for a specific business turns on four variables: the services offered, the client base by geography, the entity's organisational maturity and the timeline to commercial launch. No single structure is categorically superior; each optimises for a different combination of those variables.

Profile A – Early-stage exchange or custodian targeting EU retail users at launch. An operator at this stage typically benefits from a Lithuanian VASP registration as the immediate EU entry point, used during the MiCA transition period to begin operations, establish banking and build the governance infrastructure while preparing a full CASP application. The risk is that the transition window is not indefinite; any delay in CASP preparation risks a compliance gap. The key risk at this profile is treating the registration as a destination rather than a waypoint.

Profile B – Established exchange seeking EU passportable permission for institutional clients. Institutional counterparties and prime-broker relationships increasingly require a MiCA CASP authorisation as a baseline condition. A VASP registration alone will not satisfy this tier of client. This profile should apply directly for CASP authorisation, selecting the member state where it can build genuine substance and where the national competent authority has the most developed engagement with complex exchange structures. Lithuania is a credible option; so are several other member states depending on the specific activity mix.

Profile C – Token issuer (ART or EMT). Token issuers operating under the ART or EMT regime face requirements that sit above the CASP service-provider layer. Issuer authorisation under MiCA requires whitepaper approval, reserve management frameworks and ongoing disclosure obligations. Lithuania can serve as the member state of incorporation and authorisation for an ART or EMT issuer, but the issuer-level substance expectations are set at the EU level. This profile requires specialist structuring advice before any member state is selected.

Profile D – Fund or investment manager with digital-asset exposure. A fund or discretionary portfolio manager providing crypto-asset services to professional clients may fall within the CASP regime, the existing MiFID framework or both, depending on the nature of the assets and the services provided. Lithuanian fund infrastructure is established, and the CASP regime can be layered onto a Lithuanian-domiciled fund structure in some configurations. This profile requires a careful activity-by-activity analysis before a structure is committed.

If your profile sits between these categories or combines elements of more than one, the structure question is unlikely to have a clean off-the-shelf answer. To pressure-test your structure before you commit, message us via t.me/oboluslaw.

Banking and Tax: The Infrastructure Layer Below the Licence

A licence is a legal permission; banking is the operational reality. In our cross-border practice, we regularly see operators obtain a well-structured licence and then encounter significant friction opening or retaining accounts, because the banking due-diligence process applies its own risk assessment independently of the licence. A Lithuanian-licensed entity benefits from access to Lithuanian and broader EU banking infrastructure, but the quality of that access depends on the entity's AML documentation, its transaction-monitoring architecture and the banking relationship strategy built before the account application is submitted.

Lithuania's EU membership and its euro-zone status mean that a Lithuanian-licensed entity can access SEPA payment infrastructure and engage with EMIs and payment institutions across the EU. That is a genuine operational advantage relative to offshore licensing structures that require correspondent relationships to reach European payment rails. Operators we advise routinely underestimate the banking preparation workload; in practice, the banking timeline frequently exceeds the licensing timeline.

Tax treatment of digital-asset operations in Lithuania and across the EU varies by the nature of the activity, the entity structure and the residency of beneficial owners. Lithuania's corporate tax environment has historically been competitive within the EU, but the tax question for a crypto business is not simply the headline corporate rate. It encompasses the VAT treatment of services, the tax character of token issuance proceeds, the treatment of staking and lending income, and the permanent-establishment risk created by cross-border activity. These are questions the licensing process does not resolve; they require separate structuring analysis.

What Are the Most Common Mistakes in This Comparison?

The most frequent structural error we encounter is selecting a jurisdiction on the basis of registration speed without modelling the compliance cost of the resulting entity at scale. A fast registration that produces a shell with thin governance creates supervisory risk from day one and banking friction from day two. Competent authorities and banking counterparties have both become more sophisticated at identifying entities that registered for convenience rather than operational intent.

A second common mistake is conflating the MiCA transition window with an indefinite grace period. Operators who registered in Lithuania before MiCA and are continuing to operate without a filed CASP application are accumulating supervisory exposure. The transition provisions are time-limited, and the Bank of Lithuania as national competent authority is obligated to enforce compliance with the new regime on its schedule.

A third mistake – and the one that most often appears in the context of this comparison – is the assumption that a single offshore or EU licence is sufficient to serve clients globally. A Lithuanian or MiCA CASP authorisation permits passported operations across the EU and EEA. It does not authorise the entity to provide regulated services to clients in Singapore, Hong Kong, the United States, the UAE or the United Kingdom without additional permissions in those jurisdictions. Operators who build a business model on the assumption that an EU CASP covers their global user base routinely encounter enforcement inquiries from regulators whose users are being served without a local permission.

We map the licence stack across operating, custody and payment layers before a client commits to a structure, precisely because the interaction between the EU permission and the requirements of every other jurisdiction where the business operates is where the most significant structural risks reside.

A Common Assumption: "The EU Licence Covers Everything I Need"

A common assumption among operators entering this analysis is that a MiCA CASP authorisation resolves the compliance question for the whole business. It does not. MiCA passports the permission to provide crypto-asset services across the EU and EEA; it says nothing about the entity's obligations in third-country markets. An EU-licensed exchange with significant trading volumes from US persons, or with a marketing presence in Singapore or Dubai, is operating those non-EU segments under the rules of the relevant local regimes – the SEC, CFTC and FinCEN in the United States; MAS under the Payment Services Act in Singapore; VARA in Dubai.

The EU licence is therefore the foundation of a global licence stack, not the completion of it. Operators who treat it as the latter are exposed to enforcement in every market outside the EU where they have a regulatory footprint. The correct question is not "which EU jurisdiction should we licence in?" but "what is the full permission architecture required to support our business model across every market we serve, and what is the sequencing that gets us there at the least structural risk?"

If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Reach the OBOLUS licensing desk at info@oboluslaw.com.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timelines vary by jurisdiction, activity type and application quality. Under MiCA, national competent authorities have a statutory decision window, but the practical duration depends on the completeness of the AML framework, governance documentation and beneficial-owner evidence submitted. In our practice, well-prepared applications move materially faster than incomplete ones. Lithuania historically offered faster registration under the pre-MiCA VASP regime; CASP authorisation timelines are now harmonised at the EU level. Operators should plan for a process measured in months, not weeks, for a full CASP authorisation.

Which jurisdiction is best for licensing my crypto business?

There is no single best jurisdiction. The right choice depends on the services offered, the client base by geography, the entity's organisational maturity and the banking relationships required. Lithuania is a credible EU entry point with supervisory familiarity with crypto business models. A direct CASP application in another member state may suit an operator with stronger local substance elsewhere. For businesses serving clients outside the EU, the EU licence is one layer of a broader permission architecture. A jurisdiction-selection analysis should model all of these variables before a structure is committed.

Do I need a separate custody licence?

Under MiCA, custody of crypto-assets on behalf of clients is a distinct regulated activity requiring specific CASP authorisation. An entity authorised for exchange services is not automatically authorised to provide custody unless that activity is included in its permission scope. Several other major regimes – including MAS in Singapore and the SFC in Hong Kong – treat custody as a separately regulated function. Operators combining exchange and custody services in a single entity must ensure both activities are covered by the applicable permissions in every jurisdiction where they operate.

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – because the interaction between your EU permission and every other jurisdiction you touch is where the most significant structural risks reside. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in EU regulatory authorisation, VASP registration and cross-border licence architecture for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours