EST · MMXXVI
Home/Jurisdictions/Crypto Regulation and Licensing in Lithuania
Licensing & Registration

Crypto Regulation and Licensing in Lithuania

Crypto Regulation and Licensing in Lithuania. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Lithuania built one of Europe's most accessible entry points for digital-asset businesses in the years before MiCA (the EU Markets in Crypto-Assets Regulation) reshaped the continental regime. Today the country sits at a consequential junction: operators registered under the prior VASP (virtual asset service provider) framework must migrate to full CASP (crypto-asset service provider) authorisation under MiCA, supervised by the Bank of Lithuania. For any business weighing an EU foothold, understanding what Lithuania requires – and what it no longer permits to slide – is an immediate commercial priority.

Lithuania's regulatory posture has tightened materially since its early-entry days. The Bank of Lithuania now applies substance, capital and AML expectations that are broadly consistent with the MiCA standard, meaning a bare-registration play is no longer viable. What remains attractive is the country's single-regulator architecture, EU passporting under MiCA, and a legal environment that serious operators can work through efficiently with properly prepared documentation.

This page covers the regulatory regime, the licence categories that matter, the application process, the AML and Travel Rule (the FATF obligation to pass originator and beneficiary data with a virtual-asset transfer) posture, the tax headline, and how to assess whether Lithuania fits your operator profile.

The Bank of Lithuania is the sole prudential and AML supervisor for virtual-asset businesses operating under the Lithuanian regime, making it the single point of contact for authorisation, ongoing supervision and enforcement. Under MiCA – which is directly applicable EU law – the Bank of Lithuania acts as the national competent authority (NCA) responsible for processing CASP authorisation applications and for passporting decisions that allow an authorised operator to serve clients across the EU and EEA without a separate licence in each member state.

The prior Lithuanian VASP registration regime was deliberately lean: low barriers, light substance requirements and a rapid registration window. That era is closing. MiCA imposes a harmonised authorisation standard across every EU member state, and Lithuania is implementing that standard in full. Operators who registered under the old framework and continue to provide regulated crypto-asset services must obtain CASP authorisation within the MiCA transition periods that apply to their specific service category. Failure to convert is not a procedural oversight – it exposes the business to enforcement by the Bank of Lithuania and, in cross-border scenarios, by other EU NCAs wherever the operator's clients are located.

For inbound operators considering Lithuania as their EU base, the practical question is straightforward: the Bank of Lithuania is a known counterparty, the process is documented, and the passporting benefit is real. The analysis turns on whether your business can satisfy the substance, capital and organisational requirements that the MiCA regime now demands.

For an initial assessment of whether your existing registration or planned structure meets the Bank of Lithuania's current expectations, the facts of your entity, user base and service mix determine the analysis. Contact OBOLUS at info@oboluslaw.com to map your options before the transition window closes.

What Licence Categories Apply Under MiCA?

Under MiCA, Lithuania issues CASP authorisation that covers the full range of crypto-asset services defined in the regulation – and the category of service you provide determines the capital, organisational and insurance requirements that apply. The principal service categories subject to CASP authorisation include: operating a trading platform for crypto-assets, exchanging crypto-assets for funds or other crypto-assets, execution of orders, reception and transmission of orders, placing of crypto-assets, providing advice, and providing portfolio management. Custody and administration of crypto-assets on behalf of clients is a distinct regulated service and is not subsumed under a general exchange authorisation.

The prior Lithuanian VASP framework recognised two broad categories: businesses exchanging virtual currencies for fiat or other virtual currencies, and businesses operating virtual currency depository wallets (custody). Those categories map roughly onto the MiCA service list, but not perfectly – and the mismatch matters for operators whose current registration does not cover all the activities they are actually conducting. We regularly advise businesses that discover a gap between their registration scope and their live service offering only when a banking partner or an institutional counterparty flags the discrepancy during due diligence.

Token issuance is a separate track. If your business issues an ART (asset-referenced token) or an EMT (e-money token), MiCA imposes a distinct authorisation and whitepaper regime that differs from the CASP track. Utility token issuers face whitepaper obligations under MiCA's "other crypto-assets" category but a lighter authorisation burden. The classification of your token – which turns on the rights it confers, not the label your marketing team attaches to it – determines which regime applies.

Who Must Register or Obtain Authorisation in Lithuania?

Any entity established in Lithuania that provides crypto-asset services to clients requires CASP authorisation under MiCA – there is no de-minimis threshold that exempts a small operator from the requirement. Equally, an entity established elsewhere in the EU cannot use a foreign CASP authorisation as a passive cover for a business that is substantively managed and directed from Lithuania; supervisors look through form to substance.

The cross-border dimension is equally important. A business incorporated in Lithuania but serving clients across the EU must assess whether its activities in each member state trigger local notification or passporting obligations. MiCA's passporting mechanism means that a Lithuanian CASP authorisation, once granted, allows the operator to provide its authorised services across every EU and EEA member state under a standardised notification process – without obtaining a separate licence in each country. That passporting benefit is a principal reason why operators choose an EU member state like Lithuania as their single regulatory home rather than maintaining a patchwork of national registrations.

Non-EU operators providing services into Lithuania – and, by extension, into the EU – face a separate question. MiCA applies to CASPs that are established in the EU; third-country operators serving EU clients are subject to the reverse solicitation rules and, increasingly, to active enforcement by national regulators who regard passive-investment carve-outs as narrow. In our cross-border practice, we consistently advise non-EU operators not to rely on the reverse-solicitation exception as a structural solution for an EU user base.

How Does the CASP Application Process Work in Lithuania?

A CASP authorisation application to the Bank of Lithuania requires a complete legal and operational file that demonstrates the applicant's fitness across organisational, financial and compliance dimensions. The Bank of Lithuania reviews applications against the MiCA standard, which specifies minimum content for the application dossier: the applicant's programme of operations, a business plan, the governance framework, the identity and fitness-and-propriety credentials of qualifying shareholders and management, the internal control and risk-management framework, and the AML/CFT policies and procedures.

In practice, the weight of the application sits in four areas. First, substance: the Bank of Lithuania expects genuine operational presence in Lithuania, not a brass-plate structure. This means local management with real authority, staff with relevant competence, and physical premises proportionate to the business. Second, governance: the senior management team and supervisory board (where required) must satisfy the fit-and-proper assessment. Third, capital: the applicable minimum own-funds requirement under MiCA varies by service category and must be maintained on an ongoing basis, not merely at authorisation. The specific thresholds are set in the MiCA regime and should be confirmed against current Bank of Lithuania guidance rather than any approximation in general commentary. Fourth, AML/CFT: a comprehensive AML programme tailored to virtual-asset risk is a non-negotiable element; the Bank of Lithuania has made clear that generic documentation copied from a non-crypto compliance template will not pass scrutiny.

Timeline is a function of preparation quality. MiCA sets a review period within which the NCA must reach a decision, but that period runs from the point at which the application is deemed complete – not from the date of first submission. An incomplete file triggers a deficiency notice and resets the clock. Operators we advise who submit well-prepared dossiers typically proceed through the completeness assessment and into substantive review without material interruption. Those who submit early and iterate tend to extend their total time in process significantly.

If your application previously stalled at the completeness stage or drew a deficiency notice from the Bank of Lithuania, a second read of the file often identifies the structural reason. Write to info@oboluslaw.com to discuss a file review.

AML, the Travel Rule, and Lithuania's Compliance Posture

Lithuania's AML framework applies the FATF Recommendations – including Recommendation 15, which subjects virtual-asset service providers to the same customer due-diligence, record-keeping and suspicious-transaction-reporting obligations as traditional financial institutions. Under the Travel Rule, a Lithuanian CASP that sends or receives a virtual-asset transfer above the applicable threshold must collect and transmit originator and beneficiary information alongside the transaction. The specific threshold applicable in Lithuania under the EU's Transfer of Funds Regulation – which extends Travel Rule obligations to crypto-asset transfers – is set by that regulation and should be verified against current Bank of Lithuania guidance.

The Bank of Lithuania has signalled in its supervisory communications that AML compliance is a primary focus of its post-authorisation examination programme. This is not a formality. Operators that obtained legacy VASP registrations without building genuine compliance infrastructure are exposed: the Bank of Lithuania can revoke or suspend authorisation, impose administrative sanctions, and refer matters to the Financial Intelligence Unit (FIU) of Lithuania where suspicious-transaction indicators are present.

In our practice, the most common AML gap we identify in Lithuanian-registered entities is the absence of a genuine risk-based approach to customer classification. A programme that treats all customers as low-risk, or that relies on automated screening without human review of complex cases, will not withstand a Bank of Lithuania examination. Equally, Travel Rule compliance requires technical infrastructure – a VASP-to-VASP messaging solution – not merely a policy document that acknowledges the obligation.

The cross-border AML dimension matters significantly for businesses operating between Lithuania and non-EU jurisdictions. Where your Lithuanian CASP transacts with counterparties in jurisdictions that FATF has identified as having strategic deficiencies, enhanced due-diligence obligations apply. Operators handling significant volume from high-risk corridors should ensure their compliance framework reflects that exposure explicitly.

Substance, Capital, and Banking for Lithuanian CASPs

Genuine substance in Lithuania is now a hard expectation, not a recommendation. The Bank of Lithuania has moved away from any tolerance for management-from-abroad structures where the Lithuanian entity is a shell coordinated from a parent in another jurisdiction. A CASP must have decision-making authority, qualified personnel and operational systems physically present and active in Lithuania. The depth of substance required scales with the size and complexity of the business: a smaller operator may satisfy requirements with a leaner team, but the senior management responsible for the regulated entity must demonstrably exercise real control.

Capital requirements under MiCA vary by the category of service authorised. The MiCA regime specifies minimum own-funds floors for each service type, with higher floors for businesses operating trading platforms or holding client funds. These figures are set in the regulation itself and in associated technical standards; they must be verified against current published requirements before any business plan is committed to paper. What we can say with confidence is that the capital thresholds under MiCA are materially higher than the nominal figures that applied under Lithuania's prior VASP registration regime – a difference that has caught several operators off-guard during the transition period.

Banking is the operational bottleneck that the licence alone cannot solve. Lithuanian CASPs require euro-denominated banking relationships for operational accounts, client money safeguarding and payment processing. The field of banks willing to onboard digital-asset businesses in Lithuania – or in the EU generally – is narrower than the count of licensed entities might suggest. Operators we advise begin banking due diligence before authorisation is granted, not after, because lead times for account approval at suitable institutions are measured in months and because a rejection at that stage can delay or destabilise the entire build.

In a recent matter, an exchange operator obtained CASP-transitional status in Lithuania but had not secured a banking relationship. By the time supervisory requirements for segregated client-money accounts became active, the operator was in breach of safeguarding rules. We worked with the operator and allied counsel in the relevant jurisdiction to restructure the safeguarding arrangement using an approved electronic money institution, preserving the authorisation while the primary banking search continued.

What Is the Tax Headline for a Lithuanian Crypto Entity?

Lithuania imposes corporate income tax on Lithuanian-resident companies, including those operating as CASPs. The applicable rate should be verified against current Lithuanian tax legislation, as rates and reliefs are subject to legislative amendment; OBOLUS's tax practice maps the current position as part of a full-structure analysis. What the structure of your Lithuanian entity – and whether it holds IP, employs staff or acts as a principal versus a distributor – determines is the taxable profit base, not merely the headline rate.

VAT treatment of crypto-asset services in Lithuania follows the EU position established in EU case law and implemented in Lithuanian domestic law: the exchange of virtual currency for fiat currency is generally treated as a VAT-exempt financial service. However, ancillary services – custody administration, advisory, structured-product wrapping – may attract VAT depending on how they are legally characterised. The characterisation question is live and nuanced; it should not be resolved by analogy with another jurisdiction's ruling without a specific Lithuanian law opinion.

For groups operating across multiple jurisdictions – where the Lithuanian CASP is one entity in a larger structure that includes entities in, say, the AIFC in Kazakhstan, the BVI or the Cayman Islands – transfer pricing becomes a material issue. The Lithuanian tax authority applies OECD transfer pricing principles to intra-group transactions, and intellectual property arrangements, management fee structures and intra-group licensing of technology must be supported by arm's-length documentation. We map the full tax and structuring picture before the entity stack is committed, not as a retrospective correction.

Which Operator Profile Should Consider Lithuania?

Lithuania suits a specific operator profile – and understanding that profile candidly helps a business avoid a costly mismatch between its ambitions and what the jurisdiction can realistically deliver.

The clearest fit is an operator that wants a single EU CASP authorisation with full passporting rights and is prepared to build genuine substance in an EU member state. Lithuania offers a straightforward single-regulator architecture, a Bank of Lithuania that is accessible and processes applications against a documented standard, and an EU legal environment that major institutional counterparties, custody banks and payment providers recognise. For an exchange or custodian that expects EU clients to be its primary user base, the Lithuanian route is credible and efficient when properly executed.

A second profile that fits Lithuania well is a business currently registered under the legacy VASP regime that has the operational infrastructure to upgrade to full CASP authorisation. The transition requires investment in compliance, capital and governance – but the regulatory relationship with the Bank of Lithuania is already established, which reduces some of the uncertainty inherent in approaching a new regulator cold.

Lithuania is a less natural fit for operators whose primary user base is outside the EU, who need activity categories not covered by the MiCA CASP authorisation (for example, certain derivatives or margin products that fall under MiFID II rather than MiCA), or who are unwilling to establish genuine on-the-ground substance. For those profiles, alternative hubs – including VARA in Dubai for a non-EU exchange licence, or the AFSA in the AIFC for a Central Asian or Central-European operator – may better match the commercial reality. No single jurisdiction serves every profile, and the cost of choosing the wrong one is a re-licensing exercise after the entity is already built.

The decision matrix in practice looks like this. An EU-focused exchange or custodian with a willingness to staff locally, sufficient capital under MiCA's service-tier schedule, and a clean beneficial-ownership structure is a strong candidate for a Lithuanian CASP authorisation. A global operator serving clients in the US, Asia and the EU from a single point should assess whether a Lithuanian CASP, a Singapore MAS DPT licence and a US state money-transmitter stack is the right three-layer approach, or whether consolidation around a single hub is preferable. We map those trade-offs explicitly rather than defaulting to a jurisdiction we happen to be familiar with.

A common assumption is that a single offshore registration – whether from a legacy VASP jurisdiction or a light-touch island regime – is sufficient to serve EU clients lawfully. It is not. MiCA's application to businesses targeting EU customers is broad, its enforcement teeth are real, and the Bank of Lithuania is an active supervisor. Building a business on the premise that regulators will not look is a structural risk that surfaces first in banking due diligence and, increasingly, in enforcement actions.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timeline under MiCA depends on preparation quality, not simply regulator speed. The Bank of Lithuania's review period runs from the point at which the application is deemed complete. A well-prepared dossier – covering governance, capital, AML and substance – moves through the completeness assessment without interruption. An incomplete submission triggers deficiency notices that reset the clock. In our experience, total elapsed time from first submission to authorisation varies widely; operators should plan for several months at minimum, and budget more if the file requires iterative remediation.

Which jurisdiction is best for licensing my crypto business?

There is no universally correct answer. The right jurisdiction is determined by where your users are, what services you provide, what capital and substance you can deploy, and where your banking relationships sit. Lithuania under MiCA offers EU passporting and a single-regulator structure. Dubai's VARA regime suits operators targeting MENA and international markets. Singapore's MAS Payment Services Act suits Asia-facing businesses. OBOLUS maps the licence, banking and tax stack across multiple options before you commit to any one structure.

Do I need a separate custody licence?

Under MiCA, custody and administration of crypto-assets on behalf of clients is a distinct regulated service – it is not automatically included in an exchange or trading-platform authorisation. If your business holds client keys or controls client assets in any operational sense, you must ensure that service is explicitly within the scope of your CASP authorisation. Operating custody services outside an authorised scope is a regulatory breach regardless of how the function is described internally. We assess the full service perimeter at the outset to avoid scope gaps that surface only during a supervisory review.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – and where an engagement spans multiple hubs, we coordinate with allied counsel in the relevant jurisdiction to ensure consistency across the full structure. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us via t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in EU and multi-jurisdiction CASP authorisation strategy for exchanges, custodians and token issuers.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours