Operating a digital-asset business without the right licence is not a calculated risk. It is an open invitation to enforcement action, frozen payment rails and banking relationships that disappear overnight. When a business expanding into Europe considers where to plant its regulatory flag, two names appear on almost every shortlist: Lithuania and the United Kingdom. They sit at opposite ends of the EU-versus-third-country divide, they differ sharply in regulator posture, application depth and ongoing compliance cost, and choosing between them can define a company's operational runway for years.
This analysis maps Lithuania and the United Kingdom across the axes that matter to an operator, a custodian, a token issuer and a fund: regulatory regime, authorisation process, substance requirements, AML/CFT (anti-money-laundering and counter-terrorist-financing) expectations, the cross-border reality, and tax and banking interaction. No verdict is declared. The right answer depends entirely on your entity, your user base, your product and where you intend to grow.
The Regulatory Divide: EU Passport vs. Domestic Register
Lithuania operates inside the European Union's regulatory perimeter, which means it is now governed by MiCA (the Markets in Crypto-Assets Regulation), the EU-wide regime administered at the supranational level by ESMA and at the member-state level by the Bank of Lithuania. Under MiCA, a business authorised as a CASP (crypto-asset service provider) in Lithuania can passport that authorisation across the entire EU and EEA without filing a fresh application in each member state. That single-authorisation, multi-market right is the structural centrepiece of the Lithuanian case.
The United Kingdom is no longer part of that regime. Post-Brexit, the FCA (Financial Conduct Authority) operates its own cryptoasset register under the Money Laundering Regulations, a domestic regime that confers no EU market access. A business registered with the FCA cannot rely on that registration to serve MiCA-regulated markets. The two systems are parallel, not linked. For a business that needs both the UK market and EU market access, that means two separate regulatory processes.
This divide shapes every downstream decision. An exchange targeting EU retail users cannot resolve the question with a UK registration alone. A fund managed from London that distributes to European investors faces a gap the FCA register does not fill. We regularly advise operators who discover this incompatibility after committing to a structure, at which point correcting it costs significantly more than designing for it from the outset.
Who Regulates What: Bank of Lithuania vs. FCA
The Bank of Lithuania is a central bank acting as both monetary authority and VASP supervisor, and its posture under MiCA reflects the expectations of a continental European prudential regulator. Application review is substantive. The regulator scrutinises business models, governance arrangements, AML programme depth and capital adequacy. Historically, Lithuania was regarded as an accessible EU entry point for crypto businesses; under MiCA, the standard has risen materially, and operators who approach the Bank of Lithuania with a light-touch application encounter delays and information requests that extend timelines considerably.
The FCA's cryptoasset register is a registration, not a full authorisation in the prudential sense. It was designed primarily around AML compliance, and the FCA has been transparent about its high rejection rate for applications that do not demonstrate adequate systems and controls. The regulator's published data indicates that a significant proportion of cryptoasset registration applications have been refused or withdrawn. The FCA also enforces financial-promotion rules that apply directly to crypto marketing directed at UK persons, adding a second compliance layer that is operationally demanding for any business running retail-facing communications.
A common pattern in our practice: a business applies for FCA registration assuming the process is administrative, encounters a detailed information-gathering exercise, and submits materials that are insufficiently granular on AML controls. The application stalls. A scoped pre-submission review of the AML programme, the governance framework and the financial-crime risk assessment routinely identifies the gaps before they become rejection grounds.
For a scoped pre-submission assessment of your AML programme and governance framework, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your entity structure, user base and product mix change the analysis materially. Map your options.
What Each Regime Covers: Licence Categories and Scope
Under MiCA, the CASP authorisation in Lithuania covers a defined list of crypto-asset services: custody and administration, operating a trading platform, exchange of crypto-assets for fiat or for other crypto-assets, execution of orders, placing of crypto-assets, reception and transmission of orders, providing transfer services, and portfolio management and advice. A business applies for the specific services it intends to provide; the licence scope is activity-defined, not entity-defined.
Token-specific obligations under MiCA apply separately to issuers of ARTs (asset-referenced tokens) and EMTs (e-money tokens). ART and EMT issuers face authorisation requirements, whitepaper obligations and reserve rules that sit on top of, not in place of, any CASP authorisation. A business that both issues a stablecoin and operates an exchange in Lithuania must therefore satisfy both the issuer and the service-provider tracks.
In the United Kingdom, the FCA's MLR registration covers a defined set of cryptoasset exchange and custodian wallet provider activities. It does not cover investment management of crypto funds (which may engage FCA authorisation under the financial-services regime more broadly) or activities involving crypto-assets that qualify as specified investments under UK law, which trigger a separate authorisation track. A business issuing a token that looks like a security needs a different FCA permission entirely, and that permission is not the cryptoasset registration.
The practical implication: the Lithuanian/MiCA CASP framework is, in scope, more comprehensive for a multi-service operator than the UK MLR registration. But comprehensiveness cuts both ways — wider scope means wider compliance obligations.
How Long Does the Process Take and How Deep Is the Review?
Both jurisdictions involve a substantive review; neither is a rubber stamp. Under MiCA, the Bank of Lithuania must complete its assessment within a defined review period after receiving a complete application. Timelines depend heavily on application quality and on the regulator's current workflow. Where a business submits a complete, well-prepared file with granular AML documentation, governance manuals, technology-risk descriptions and financial projections, the process moves faster. Incomplete submissions restart the clock. In our cross-border practice, we see the preparation phase – building the application file before submission – take as long as the regulator's own review period for first-time applicants.
The FCA's cryptoasset registration timeline is similarly tied to application quality. The FCA has been candid that its AML-focused review is thorough. Businesses that engage the process without a detailed financial-crime risk assessment, a documented transaction-monitoring programme and evidence of genuine substance tend to receive information requests that extend the timeline by months. Where a prior application was withdrawn or refused, a fresh application requires demonstrating that the issues identified have been structurally resolved, not merely acknowledged.
Neither jurisdiction publishes a hard guaranteed timeline in the registry. Both regulators reserve discretion to extend review periods. Qualitatively: operators we advise budget for a process measured in months in both cases, with the variation driven almost entirely by application quality, business-model complexity and regulator bandwidth at the time of submission.
If a prior UK or Lithuanian application stalled or was withdrawn, a structured second-look review can surface the underlying reason and the remediation path. To discuss a second-attempt strategy, write to OBOLUS at info@oboluslaw.com. Map your options.
Substance Requirements: How Much Local Presence Do You Actually Need?
Substance is one of the most misunderstood axes in this comparison. Both regulators expect genuine economic and operational substance; neither accepts a brass-plate arrangement.
Under MiCA as applied by the Bank of Lithuania, a CASP applicant must demonstrate a real presence in Lithuania. That means a registered office, senior management with decision-making authority who are genuinely based in or accessible to the jurisdiction, and governance arrangements that are not simply replicated from a parent structure elsewhere. The Bank of Lithuania has been explicit that it expects substance proportionate to the complexity and risk of the business. A large exchange applicant faces a higher substance bar than a niche advisory business.
The FCA applies a similar substance discipline. UK-registered cryptoasset businesses are expected to have a UK presence, UK-resident senior management who can engage with the regulator, and AML/CFT governance that is genuinely run from the UK rather than delegated wholesale to an offshore parent. Where the business is a branch or subsidiary of a non-UK group, the FCA scrutinises the degree to which the UK entity exercises independent control of its compliance function.
A common assumption is that a thin local office satisfies the substance test. In our practice, that assumption consistently underestimates regulator expectations in both jurisdictions. The Bank of Lithuania and the FCA both conduct substance assessments that look through the corporate structure to the actual locus of decision-making. A business that genuinely operates from another country but files in Lithuania or the UK for regulatory convenience is structurally exposed.
AML, the Travel Rule and Ongoing Compliance Obligations
Both jurisdictions align to the FATF Recommendations, including Recommendation 15 on virtual assets and the Travel Rule (the obligation to pass originator and beneficiary data with each qualifying transfer). Compliance with the Travel Rule is a baseline expectation in both the Lithuanian/MiCA regime and the UK MLR framework. The specific data threshold and de-minimis treatment vary by jurisdiction and by the technical implementation chosen, and both are subject to ongoing regulatory clarification.
Under MiCA, the CASP regime integrates with the EU's Transfer of Funds Regulation, which sets the Travel Rule framework for EU-licensed operators. A Lithuanian CASP passporting into other EU member states operates under a single, harmonised AML framework. That harmonisation is operationally valuable: one AML programme, applied across the EU, rather than a patchwork of national rules.
The UK, post-Brexit, has developed its own cryptoasset Travel Rule framework under the FCA and HM Treasury. UK operators must apply the Travel Rule to transfers meeting the relevant threshold but do so under UK-specific guidance that may diverge from the EU position over time. For a business operating in both markets, that means maintaining two parallel Travel Rule implementations – one for UK activity, one for EU activity – with the associated technology and compliance overhead.
In our cross-border practice, we have seen operators underestimate the cost of maintaining dual AML frameworks. For a business serving both EU and UK users, the question of whether to hold two licences or to route EU users through a separate EU-licensed entity is not purely a regulatory question – it is a cost and operational-efficiency question that needs to be modelled before the structure is set.
Tax and Banking: Where the Licensing Decision Has Downstream Consequences
The licensing decision does not exist in isolation. It sits inside a tax and banking stack, and the interactions are material.
Lithuania is an EU member state with a corporate tax environment that has historically been regarded as competitive within the EU. More importantly for an operator, EU membership means access to EU banking relationships and payment-infrastructure providers that require EU-licensed counterparties. A Lithuanian CASP can, in principle, access EU banking and payment rails on the basis of its MiCA authorisation. In practice, banking access for crypto businesses remains operationally difficult across the EU regardless of licence status – regulators and banks are distinct, and a CASP licence does not guarantee a bank account. It does, however, provide a stronger foundation for the banking conversation than an unlicensed or offshore structure.
The United Kingdom's post-Brexit position means a UK-registered cryptoasset business operates outside the EU banking and payment infrastructure. A UK business serving EU users still needs EU banking access – and may find that EU correspondent banks or payment-service providers require an EU-licensed entity as counterparty. The UK's own banking environment for crypto businesses has improved in recent years, with some UK-regulated banks and e-money institutions providing services to FCA-registered cryptoasset businesses, but availability remains selective.
On tax: both jurisdictions tax corporate profits on income and capital gains; the specific rate, the treatment of staking rewards, the VAT/GST characterisation of crypto services and the withholding-tax treatment of payments to non-residents all vary and should be assessed by reference to current legislation and specialist advice. Neither jurisdiction is universally superior on tax for a crypto business; the outcome depends on the entity's activity profile, its holding structure and its investor base.
Decision Matrix by Operator Profile
No jurisdiction is universally correct for every operator. The following profiles illustrate how the decision axes align across different business types. These are structural orientations, not recommendations; the right answer requires a facts-specific analysis.
Profile A – Exchange seeking EU market access. A business operating a crypto-to-fiat or crypto-to-crypto exchange and targeting EU retail or institutional users is, under MiCA, required to hold a CASP authorisation in an EU member state. Lithuania is a credible first-application jurisdiction for a mid-sized exchange: the Bank of Lithuania is experienced with crypto applications, the CASP framework is now operative, and passporting provides the EU reach. Key risk: substance requirements have risen and the application is genuinely substantive. Timeline: measured in months, quality-dependent. The FCA registration alone does not resolve EU access; a parallel EU structure is required.
Profile B – Custodian serving a mixed EU/UK institutional client base. A custody business with EU and UK clients needs, in principle, both EU authorisation and UK FCA registration. Operating from a single jurisdiction and treating the other as incidental carries regulatory risk in the uncovered market. The structurally cleaner approach is a holding structure with separate operating entities in each jurisdiction, each carrying its own authorisation. This is more expensive to establish and maintain but provides the cleanest regulatory footing. Timeline: two parallel processes, both measured in months.
Profile C – Token issuer (ART or EMT under MiCA). An issuer of a stablecoin or an asset-referenced token that intends to distribute within the EU has no practical alternative to MiCA authorisation. The issuer track sits outside the CASP framework and requires its own application, whitepaper approval and ongoing reserve and redemption obligations. Lithuania is a viable authorisation jurisdiction for an ART or EMT issuer. The UK does not have an equivalent MiCA-equivalent regime for stablecoin issuers as of this writing; UK stablecoin regulation is developing separately. An issuer targeting only the UK market may engage a different track; one targeting the EU must engage MiCA.
Profile D – Fund or asset-management vehicle. A digital-asset fund managed from the UK that distributes to EU investors faces a distinct set of questions that extend beyond the cryptoasset registration into fund-management regulation and the EU's AIFMD regime. Neither the FCA registration nor the MiCA CASP authorisation alone resolves the fund-management question. A Lithuania-domiciled fund may engage the Bank of Lithuania under applicable fund-management rules; UK-managed funds distributed to EU investors require separate consideration of the relevant national private-placement rules in each target member state. This profile is the most structurally complex and requires early engagement with counsel in both jurisdictions.
Common Mistakes Operators Make in This Comparison
A common assumption is that a single licence – whether Lithuanian or UK – covers global operations. It does not. The Lithuanian CASP authorisation provides EU/EEA access but does not authorise activity in the UK, the US, Singapore, Hong Kong or any other jurisdiction outside the EU. The FCA registration covers UK activity only. Operating in any other market without the relevant local licence is a separate compliance failure, regardless of what EU or UK authorisation the business holds. In our practice, we regularly see operators who planned for one jurisdiction and discovered – sometimes via an enforcement query – that they were also operating in three others.
A second recurring mistake is conflating the regulatory authorisation with banking access. Obtaining a CASP authorisation or FCA registration opens the door to the banking conversation; it does not guarantee a bank account. The banking and licensing workstreams must run in parallel, not sequentially.
A third mistake is treating the two jurisdictions as mutually exclusive options in a context where both are required. For a business with genuine EU and UK operations, the correct structure often involves entities in both jurisdictions. The cost of dual licensing is real but substantially lower than the cost of enforcement, reputational damage or forced restructuring after the business is operating at scale.
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – how we map the full licence stack across operating, custody and payment layers
- VARA Licence Application in Germany: BaFin – BaFin's crypto authorisation regime for operators targeting the German market
- Crypto Fraud and Asset Recovery in Georgia – enforcement and recovery options in an emerging digital-asset jurisdiction
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, custody and payment stack before you commit – so operators understand the full compliance cost before it becomes a remediation cost. To discuss your situation, contact info@oboluslaw.com.
To pressure-test your structure before you commit, message OBOLUS via t.me/oboluslaw or write to info@oboluslaw.com. Map your options.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in EU and UK regulatory authorisation pathways for digital-asset operators, with a focus on MiCA CASP structuring and FCA registration strategy.
FAQ
How long does a crypto licence take to obtain?
In both Lithuania and the United Kingdom, the authorisation or registration process is measured in months rather than weeks. The specific timeline depends on application quality, business-model complexity and regulator bandwidth at the time of submission. A complete, well-prepared file with granular AML documentation and governance materials moves materially faster than an incomplete submission. Neither regulator publishes a hard guaranteed deadline, and both reserve discretion to extend review periods where additional information is required.
Which jurisdiction is best for licensing my crypto business?
There is no universally correct answer. Lithuania, operating under the EU's MiCA regime, provides EU-wide passporting rights via a CASP authorisation – essential for businesses targeting EU/EEA markets. The UK's FCA registration covers UK activity only and provides no EU access. For a business needing both markets, both may be required. The right jurisdiction depends on your user base, product, entity structure and growth plan. A facts-specific analysis of the licence, banking and tax stack is the necessary starting point.
Do I need a separate custody licence?
Under MiCA, custody and administration of crypto-assets on behalf of clients is a defined CASP service requiring specific authorisation. An operator authorised only for exchange services cannot provide custody without extending its authorisation to cover that activity. In the UK, custodian wallet providers are a separately defined category under the MLR. Whether your activity constitutes regulated custody depends on the structure of the service – particularly whether you hold private keys or control over client assets. This is a product-characterisation question that should be resolved before the application, not after.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.