Lithuania vs Malta: Where to License a Crypto Business
Choosing between Lithuania and Malta for a crypto licence (regulatory authorisation to operate a digital-asset business within the European Union) is one of the most consequential early decisions a founder or general counsel faces. Both jurisdictions sit inside the EU's MiCA (Markets in Crypto-Assets Regulation) perimeter, supervised by ESMA and their respective national competent authorities. Both offer passporting into the single market. Yet their regulatory posture, substance expectations, AML track records and banking ecosystems differ in ways that directly affect how quickly you can launch, how reliably you can bank, and how credible the licence looks to institutional counterparties. This page maps those differences across the axes that matter most to operators, and closes with a decision matrix by business profile.
Operating without the right licence is not an administrative technicality. Enforcement action, frozen payment rails and lost banking relationships are the practical consequences. The analysis below is written for the operator who already understands crypto mechanics and needs the legal answer – not a marketing summary.
The Regulatory Terrain: Two Paths to the Same EU Passport
Both Lithuania and Malta now converge on MiCA's CASP authorisation (Crypto-Asset Service Provider authorisation), yet they arrive from different institutional histories that still shape how each regulator behaves in practice. Lithuania, supervised by the Bank of Lithuania, built a reputation as a fast EU entry point under its prior VASP registration regime. Malta, supervised by the Malta Financial Services Authority (MFSA), developed its own statutory layer – the VFA framework (Virtual Financial Assets framework) – which is now transitioning to MiCA CASP authorisation. Understanding that transition is essential before you commit to either path.
Under MiCA, every EU/EEA member state must authorise CASPs through a common process anchored by ESMA guidelines. The passport that results is genuinely equivalent: a CASP authorised in Vilnius may passport services to Amsterdam exactly as one authorised in Valletta can. What differs is the journey to that authorisation – the regulator's examination style, the substance threshold, the processing culture and the local professional ecosystem you will need to engage.
In our practice, we advise operators not to treat this as a purely administrative choice. The regulator you choose becomes a long-term supervisory relationship. Regulators in the leading EU hubs increasingly expect genuine operational substance, not a brass-plate presence. That expectation is calibrating upward under MiCA, and it applies to both Vilnius and Valletta.
How Each Regulator Approaches Authorisation
The Bank of Lithuania approaches VASP and CASP supervision with a process-oriented, documentation-heavy style that has historically rewarded well-prepared applicants with predictable timelines. It built significant operational experience processing a large volume of fintech and e-money institution applications before the crypto licensing wave, and that institutional muscle shows. Regulators with high application throughput tend to have clearer informal guidance on what a complete file looks like – a practical advantage for first-time applicants.
The MFSA's posture has evolved through the VFA transition period. The authority invested heavily in building a bespoke crypto-specific regime before MiCA was finalised, and it retains institutional knowledge of the sector that is genuinely deep. However, operators we advise have encountered a more exacting pre-application dialogue in Malta, particularly around governance, financial crime risk frameworks and substance. That rigour can be a feature rather than a defect – a harder authorisation is harder to replicate and therefore carries more weight with banking partners and institutional clients.
Both regulators require engagement with local authorised professionals. In Malta, the VFA Agent role (a licensed intermediary who sponsors and co-signs the application) was a feature of the old framework; under MiCA, the direct-application model aligns with the EU standard, though local legal and compliance expertise remains critical. In Lithuania, a local AML compliance officer and a local board presence have historically been baseline expectations, and that has not changed under MiCA.
CTA #1The standard path above describes the general process. Your specific facts – the activity set, the user base geography, the projected transaction volumes and the banking plan – all shift the analysis materially. The process above describes the standard path. Your facts change the analysis. For a scoped assessment of which EU entry point fits your build, contact OBOLUS at Map your options.
What Does 'Substance' Actually Mean in Each Jurisdiction?
Substance is the requirement that an authorised entity maintains genuine operational capacity – staff, management, decision-making – in the licensing jurisdiction, rather than existing only on paper. Under MiCA, ESMA has made clear that substance expectations apply across all member states, and both Lithuania and Malta have aligned their supervisory posture accordingly.
In Lithuania, the minimum substance threshold has historically been interpreted as requiring at least one senior person with decision-making authority resident in the country, a local AML officer, and a registered office that is operationally active. The Bank of Lithuania has signalled that under MiCA it will scrutinise applications for genuine management presence. A Vilnius office with a part-time local director and all real operations run from London or Dubai is increasingly unlikely to pass examination.
Malta's substance expectations have historically been higher, reflecting the MFSA's more relationship-intensive supervisory model. The authority expects the key compliance function, and often the MLRO (Money Laundering Reporting Officer) and senior manager roles, to be substantively located in Malta. Board meetings, risk committee records and internal audit trails are examined as part of ongoing supervision – not merely at initial authorisation.
The practical implication is that substance cost in Malta tends to be higher than in Lithuania, all else equal. For an operator building a lean European entity to access MiCA passporting, Lithuania's traditionally lighter substance floor represents a meaningful cost difference. For an operator who needs the credibility signal of a more demanding regulator – particularly for institutional relationships or a planned regulated fund structure – Malta's higher bar carries genuine commercial value.
MiCA Transition: Where Each Jurisdiction Stands on Timeline
Both Lithuania and Malta are navigating the transition from their prior national regimes to full MiCA CASP authorisation, and that transition creates a period of procedural uncertainty that operators must price into their planning.
Under MiCA, member states may apply transitional provisions that allow existing registered or licensed entities to continue operating for a defined period while seeking full CASP authorisation. The precise duration and conditions of that transitional window vary by member state and are set by national implementation law. Both the Bank of Lithuania and the MFSA have published guidance on their respective transitional arrangements, and current applicants should treat that guidance as the live document – not any prior estimates from the pre-MiCA period.
For new applicants – those without an existing registration in either jurisdiction – the relevant question is how quickly each regulator can process a full MiCA CASP application from scratch. Processing timelines under MiCA are measured in months, not weeks. Both regulators are building their MiCA examination capacity alongside an elevated application load. In our cross-border practice, we advise clients to budget conservatively for the full process, to prepare a complete file before submission rather than engaging in an iterative back-and-forth, and to engage local counsel early enough that the pre-application dialogue with the regulator has time to run its course before the clock matters.
A common mistake we see at this stage is submitting an application timed to a product launch. The authorisation timeline does not compress to fit a commercial deadline. Building the regulatory calendar into the product roadmap – rather than the reverse – is the structural discipline that separates operators who launch on schedule from those who do not.
AML Posture and the Travel Rule: Divergent Enforcement Cultures
AML/CFT compliance – grounded in FATF Recommendation 15 and the applicable EU Anti-Money Laundering directives – is a threshold condition for authorisation and ongoing operation in both jurisdictions. The Travel Rule (the obligation to pass originator and beneficiary data alongside a virtual-asset transfer) applies in both Lithuania and Malta under EU transposition of FATF standards.
The substantive AML obligations are broadly equivalent because both jurisdictions transpose the same EU AML framework. The difference lies in supervisory intensity. Lithuania's Financial Intelligence Unit (FNTT) and the Bank of Lithuania have historically enforced AML rules with increasing severity following a period of criticism that the prior VASP registration regime was insufficiently rigorous. That enforcement upgrade has made Lithuania a more credible AML jurisdiction than its earlier reputation suggested, but it also means that AML file quality is examined more closely than operators who applied five years ago might expect.
Malta has positioned AML compliance as a reputational priority following its removal from and subsequent re-listing by the FATF grey list cycle. The MFSA and the FIAU (Financial Intelligence Analysis Unit) apply detailed scrutiny to AML programme quality, transaction monitoring systems and suspicious transaction reporting. For a CASP seeking to demonstrate AML credibility to banking partners and correspondent institutions, a Malta authorisation backed by a strong FIAU compliance record carries a specific signal value.
In both jurisdictions, the Travel Rule implementation requires technical infrastructure – typically a VASP-to-VASP messaging solution (a system for transmitting originator and beneficiary data between VASPs at the point of transfer) – and must be in place at the time of authorisation, not added later. We regularly advise operators to treat Travel Rule readiness as part of the application package, not a post-authorisation project.
Banking Access and Tax Interaction: The Practical Stack
For a digital-asset business, the licence is only as useful as the banking it unlocks. Both Lithuania and Malta have banking ecosystems that serve licensed CASPs, but neither should be treated as a guaranteed route to frictionless correspondent banking with major EU clearing banks.
Lithuania benefits from a well-developed fintech banking and EMI sector. Operators licensed by the Bank of Lithuania can typically access several Lithuanian-licensed electronic money institutions and neobanks, as well as a growing set of traditional bank relationships that have developed comfort with crypto-adjacent clients. The proximity to the Baltic fintech ecosystem – and to EU payment infrastructure via the SEPA zone – is a material operational advantage.
Malta has a smaller domestic banking sector, and some operators have historically found the transition from MFSA authorisation to a working banking relationship more difficult than anticipated. That said, a well-structured application with strong AML credentials and a credible business model can open banking discussions with EU correspondent banks that look past the jurisdiction label and focus on the regulatory quality of the applicant.
On tax, both Lithuania and Malta offer competitive EU corporate regimes, but the structures differ. Malta's participation exemption and its system of full imputation are well understood in international tax planning. Lithuania offers a low headline corporate tax rate applicable to general corporate income, with specific rules for technology and fintech companies. Neither rate is stated here as a hard figure – the applicable rate depends on the structure, the activity and applicable anti-avoidance provisions, and should be confirmed with a qualified tax adviser in each jurisdiction as part of the structuring analysis.
The interaction between the licensing regime, the corporate structure and the tax stack is an area where operators frequently under-invest at the planning stage. A MiCA CASP structure that is efficient from a licensing perspective may carry unexpected tax cost if the transfer pricing, IP location or dividend flow has not been mapped. In our practice, we map the licence, banking and tax stack together before a client commits to a jurisdiction.
CTA #2If a prior application in Lithuania or Malta stalled, or if banking relationships closed after authorisation, a structural review can surface the underlying reason and identify the route forward. A second read often surfaces the structural reason and the route back. Write to OBOLUS at Map your options.
Decision Matrix: Which Profile Should Choose Which Jurisdiction
No comparison of this kind produces a single correct answer. The right jurisdiction depends on the operator's profile, the activity set, the user geography, the institutional relationships and the timeline. The matrix below addresses the profiles we most regularly advise.
Profile A – Early-stage exchange or brokerage, lean team, EU market access primary objective. Lithuania has historically been the faster, lower-cost EU entry for this profile. The substance requirements are manageable for a team of modest size, the Bank of Lithuania's process is well-charted, and the fintech banking ecosystem provides workable rails. The key risk is that a Lithuania authorisation, if achieved with minimal substance, will face more rigorous examination on an ongoing basis as MiCA supervision matures. Timeline: typically a matter of months from complete file to decision, though MiCA capacity at the regulator is a variable. Key risk: substance challenge at renewal or passporting notification.
Profile B – Custodian or infrastructure provider seeking institutional client relationships. Malta's higher substance threshold and more intensive supervisory relationship carry a credibility premium with institutional counterparties – prime brokers, fund administrators and corporate treasury functions that conduct due diligence on their service providers' regulatory quality. The higher setup cost is offset by reduced friction in institutional onboarding. Timeline: typically longer than Lithuania, reflecting the depth of the MFSA's examination. Key risk: banking access during the post-authorisation setup period.
Profile C – Token issuer planning a public offer under MiCA. Both jurisdictions support whitepaper filing and CASP authorisation for token issuers. Malta's institutional memory from the VFA framework – which was specifically designed with token issuance in mind – gives local advisers and the regulator itself a depth of experience in examining token economics, reserve structures and investor disclosure. For a significant public offer, that institutional depth has practical value. Key risk: higher professional costs and a longer preparation period.
Profile D – Regulated fund or fund manager with crypto exposure. This profile typically needs both a CASP authorisation (for the management entity) and a funds regulatory layer (AIFMD or equivalent). Lithuania and Malta both support AIFMs and AIF structures, but the fund regulatory ecosystem in Malta – developed over decades – tends to offer a more integrated service from a single regulator. Key risk: the interaction between the crypto-specific and fund-specific supervisory expectations, which requires careful mapping before application.
A common assumption we address regularly is that a single offshore registration – outside the EU entirely – is sufficient to serve EU clients without further authorisation. That assumption is incorrect. MiCA imposes requirements on CASPs that actively solicit EU clients regardless of where the entity is domiciled, and member-state regulators are increasingly enforcing that perimeter. An operator relying on an offshore registration to avoid EU licensing requirements is operating on a diminishing foundation.
Common Mistakes and How to Avoid Them
Operators approaching EU licensing for the first time repeat a predictable set of mistakes. Identifying them early is a meaningful part of what counsel does at this stage.
The first and most common mistake is submitting an application before the substance structure is in place. A paper entity with a registered agent and a shared office address no longer passes examination. Both the Bank of Lithuania and the MFSA will require evidence of genuine operational presence before granting authorisation, and a deficient application creates a record that complicates future submissions.
The second mistake is treating the AML programme as a compliance checkbox rather than a substantive business risk system. Both regulators examine whether the AML framework – policies, procedures, transaction monitoring, Travel Rule infrastructure and MLRO capability – is genuinely proportionate to the business model. A generic, off-the-shelf AML manual that does not address the specific risk profile of the applicant's activity is a common reason for application delay or rejection.
The third mistake is planning banking as an afterthought. The licence does not guarantee a bank account. Engaging with potential banking partners in parallel with the licensing process – and structuring the entity in a way that is compatible with the banking due diligence that financial institutions apply – is a discipline that experienced operators treat as foundational. In our practice, we have seen licences obtained and businesses unable to launch for months because banking was not addressed in parallel.
The fourth mistake is selecting a jurisdiction based on cost alone. The cheapest path to a licence is not always the most commercially useful one. A licence with minimal substance, obtained from a regulator with limited supervisory depth, may not pass the due diligence of counterparties, banking partners or institutional clients whose own regulators require them to assess the quality of their service providers' licences.
Self-Assessment Checklist Before You Choose
Before committing to a jurisdiction, an operator should be able to answer the following questions with specificity:
- Which CASP activities does the business actually perform, and do those activities require authorisation in the target jurisdiction as currently structured?
- Where are the end clients located, and does serving them require passporting or local presence beyond a single authorisation?
- What is the realistic substance plan – key personnel, physical presence, governance structure – and does it meet the target regulator's expectations?
- Has the AML/CFT programme been designed for this specific business model, including Travel Rule technical infrastructure?
- Has banking been scoped in parallel, with at least two potential banking partners identified and pre-engaged?
- Has the corporate structure been reviewed for tax efficiency across the licensing, operating and holding layers?
- Is the licensing timeline built into the product or commercial roadmap, rather than the reverse?
An operator who can answer each of these questions with documented specificity is in a materially better position than the majority of applicants either regulator sees. The gap between a prepared and an unprepared application file is one of the most durable observations in our cross-border licensing practice.
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – full-scope EU and global CASP authorisation advisory across seventy-plus jurisdictions.
- CASP Authorisation Under MiCA in Guernsey – an alternative EU-adjacent licensing route for operators evaluating offshore options.
- Crypto Fraud and Asset Recovery: Practical Lessons for Boards – what boards need to know when enforcement or asset loss intersects with a licensed entity.
FAQ
How long does a crypto licence take to obtain?
Processing timelines under MiCA vary by jurisdiction, regulator capacity and the completeness of the application file. A well-prepared, complete application to either the Bank of Lithuania or the MFSA typically takes a matter of months from submission to decision. Incomplete files, additional information requests and pre-application dialogue each extend that window. Building a conservative regulatory timeline into the commercial plan – rather than planning to a best-case scenario – is strongly advisable.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. Lithuania has historically offered a faster, lower-cost EU entry point suited to lean early-stage operators. Malta offers a more intensive regulatory relationship with higher credibility value for institutional counterparties and complex structures. The right choice depends on your activity set, user geography, substance capacity, banking plan and commercial relationships. A structured jurisdiction analysis – mapping all of those variables – is the only reliable basis for a decision.
Do I need a separate custody licence?
Under MiCA, custody and administration of crypto-assets is a regulated CASP activity that requires explicit authorisation. An operator authorised only for exchange or brokerage services cannot provide custody under the same authorisation. If your business model includes holding client assets – even temporarily – the custody activity must be included in the authorisation scope from the outset. Obtaining the right scope at the application stage is significantly more efficient than seeking to extend authorisation later.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than seventy jurisdictions, on disputes and on-chain asset recovery across more than twenty-five forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, banking and tax stack across operating, custody and payment layers before you commit – so that the structure you build is the one that works. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialises in EU CASP authorisation strategy and cross-border digital-asset licensing across the MiCA, VARA and MAS regimes.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.