EST · MMXXVI
Home/Jurisdictions/Lithuania/CASP authorisation under mica in Lithuania
Licensing & Registration

CASP authorisation under mica in Lithuania

Casp authorisation under mica in Lithuania. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

CASP Authorisation Under MiCA in Lithuania

Operating a digital-asset business in the European Union without a valid CASP authorisation (Crypto-Asset Service Provider licence under the Markets in Crypto-Assets Regulation, or MiCA) exposes the business to enforcement, banking exclusion and market exit. Lithuania has historically been among the most accessible EU entry points for inbound crypto operators, and under MiCA that position is evolving: the Bank of Lithuania now supervises the transition from the prior VASP registration regime to full CASP authorisation, giving operators passport rights across the entire EU and EEA single market. This page maps the regulated basis, the application process, the cross-border implications, and the decision points that matter for a business choosing Lithuania as its MiCA foothold.

What Is CASP Authorisation Under MiCA, and Why Does Lithuania Matter?

A CASP authorisation under MiCA is the single EU-wide licence that entitles a legal entity to provide regulated crypto-asset services – exchange, custody, transfer, advisory and portfolio management, among others – to clients across every EU and EEA member state under a single regulatory approval. The Bank of Lithuania acts as the national competent authority (NCA) under MiCA for entities incorporated in Lithuania, meaning it receives applications, conducts fitness-and-propriety reviews, and issues or refuses the authorisation.

Lithuania's relevance for inbound operators is structural. A substantial number of crypto businesses chose Lithuania under the prior VASP framework precisely because the Bank of Lithuania offered a workable pathway into the EU perimeter. That history means local regulatory capacity – legal infrastructure, supervised compliance advisers, experienced banking contacts – is more developed here than in many comparable EU jurisdictions.

The MiCA transition changes the substance, not the geography. MiCA passporting means a CASP authorised in Lithuania may operate across the EU without a second authorisation. For a business that wants EU market access and prefers a regulator with prior crypto-sector experience, Lithuania remains a considered choice.

The risk of delay is real, however. Operators who registered under the prior Lithuanian VASP regime must comply with MiCA's transition timetable. Those who miss that window lose the ability to rely on prior registration and must apply fresh. In our practice, we have seen businesses underestimate that timeline and find themselves holding a legacy registration that no longer supports ongoing operations. Acting early is not a preference – it is a compliance requirement.

Who Needs CASP Authorisation in Lithuania?

Any entity incorporated in Lithuania that provides one or more of MiCA's regulated crypto-asset services to clients – whether in Lithuania or elsewhere in the EU – requires a CASP authorisation from the Bank of Lithuania. The list of regulated services under MiCA covers custody and administration of crypto-assets on behalf of clients, operation of a trading platform, exchange of crypto-assets for fiat or for other crypto-assets, execution and reception and transmission of orders, placement of crypto-assets, and the provision of advisory or portfolio management services in relation to crypto-assets.

A key threshold question is whether the business is already passporting into Lithuania from another EU member state's CASP authorisation. If so, the Lithuanian authorisation is not required for that specific operator. But for any business that wants to be domiciled in Lithuania and to use a Lithuanian entity as the regulated hub, the Bank of Lithuania authorisation is non-negotiable.

The cross-border reality adds a layer of complexity. Many operators run a Lithuanian regulated entity alongside holding companies in the BVI or Cayman Islands, or alongside payment-institution subsidiaries in other EU member states. Each of those layers carries its own regulatory footprint. The Lithuanian CASP authorisation covers the Lithuanian entity's activities. It does not, by itself, authorise the group's global operations.

CTA #1 – The scope of which entity needs which authorisation is not always obvious at formation. The entity structure, the user base's location and the product mix all affect the analysis. For a scoped assessment of your licensing position, contact OBOLUS at info@oboluslaw.com.

What Does the CASP Application Process Involve in Lithuania?

The CASP application to the Bank of Lithuania is a structured regulatory submission, not an administrative filing. Under MiCA, the national competent authority has a defined assessment period once it receives a complete application; the Bank of Lithuania then conducts a substantive fitness-and-propriety review of the applicant entity and its senior persons.

The core application package typically includes the following:

  • A detailed business plan covering the services to be provided, the target market, the revenue model and the projected client base.
  • Governance documentation: articles of association, ownership structure, and identification of all qualifying shareholders and persons who effectively direct the business.
  • Fitness-and-propriety evidence for management and directors, including professional background, absence of relevant regulatory sanctions, and criminal records where required.
  • An AML/CFT framework: policies, procedures, customer due diligence workflows, transaction monitoring systems and a designated AML officer.
  • A description of IT systems, cybersecurity arrangements and operational resilience measures.
  • A prudential capital plan demonstrating compliance with the own-funds requirements applicable to the specific CASP licence class.
  • Client-asset safeguarding arrangements, particularly for custody-related services.
  • A complaints-handling procedure.

The Bank of Lithuania applies MiCA's requirements, supplemented by ESMA technical standards, to assess each element. Where an application is incomplete, the regulator issues a stop-the-clock notice, pausing the assessment window until the applicant provides the missing material. In our cross-border practice, incomplete initial submissions are by far the most common reason for delay.

Once a complete application is received, the assessment period under MiCA runs for a defined period before the Bank of Lithuania must either grant or refuse authorisation. The timeline is set in the regulation and is not within the applicant's control after submission; it is, however, directly affected by the quality and completeness of the materials filed.

How Does Lithuania Handle AML and the Travel Rule for CASPs?

Lithuania's AML/CFT requirements for CASPs are anchored in the FATF framework – specifically FATF Recommendation 15, which covers virtual assets – and in the EU's transfer-of-funds rules implementing the Travel Rule (the obligation to pass originator and beneficiary data with each crypto transfer above the applicable threshold). These obligations apply from the moment a CASP is authorised; the Bank of Lithuania expects a compliant programme in place at launch, not as an after-thought.

The Travel Rule creates a significant operational dependency for Lithuania-authorised CASPs operating cross-border. When transferring crypto-assets to or from a CASP in a non-EU jurisdiction, the Lithuanian operator must have technical capacity to send and receive the required counterparty data. Where the counterpart jurisdiction has not implemented a compatible Travel Rule standard, the CASP must apply a risk-based approach and may need to restrict or refuse the transfer.

Regulators across the leading hubs increasingly expect CASPs to demonstrate Travel Rule compliance not just in policy but in deployed technology: a Travel Rule protocol integrated into the transfer workflow before go-live. The Bank of Lithuania's supervision posture reflects that expectation. Operators we advise routinely find that Travel Rule readiness is assessed as a substantive element of the authorisation review, not merely a condition to satisfy post-authorisation.

What Are the Cross-Border Tax and Banking Interactions for a Lithuania CASP?

A CASP authorisation in Lithuania grants EU regulatory standing. It does not, by itself, resolve banking access, tax structuring or the regulatory position in markets where the operator's clients are located outside the EU.

Banking remains one of the most material operational risks for crypto businesses in the EU. Lithuanian banks have varying appetites for crypto-sector clients, and the authorisation itself does not compel a bank to open or maintain an account. Operators we advise regularly structure their fiat settlement through a combination of a Lithuanian or broader EU payment institution, sometimes alongside an EMI authorised in another EU member state, to create resilience against unilateral account closures. The key is that the banking relationship is consistent with the AML programme: a disconnect between the stated client base and the actual transaction flows is a common trigger for account termination.

On tax, a Lithuanian entity is subject to corporate income tax in Lithuania on its profits. The applicable regime and any treaty benefits depend on where the entity's management and control sits, where its clients are located, and whether any IP or holding structures sit in a different jurisdiction. Token classification – whether tokens held or transacted by the CASP are treated as trading stock, financial instruments or another category – affects the tax base. These questions are jurisdiction-specific and require coordination between Lithuanian tax counsel and any cross-border adviser. We map the licence, banking and tax stack together; treating them as separate workstreams creates gaps.

A second cross-border layer arises from the CASP's client geography. A MiCA CASP authorised in Lithuania may serve EU/EEA clients under the passport. If the operator also wants to serve clients in Singapore, Hong Kong, the UAE or the United States, each of those markets has its own licensing or notification requirement. The Lithuanian authorisation confers no rights outside the EU perimeter. Operators who assume otherwise have, in our experience, been surprised by enforcement enquiries from regulators in those markets.

CTA #2 – If your application has stalled, or if a prior structure is no longer adequate for your user base and product mix, a second structural read often surfaces the reason and the route forward. Write to OBOLUS at info@oboluslaw.com to discuss.

Which Operator Profile Should Choose Lithuania for a MiCA CASP Authorisation?

Lithuania is not the right EU licensing jurisdiction for every operator. The choice depends on the business's scale, product mix, existing infrastructure and time constraints. The following profiles describe the most common situations we encounter.

Profile A – EU market entry by an established non-EU operator: An exchange or custodian incorporated in Singapore, Hong Kong or the UAE that wants a single EU legal entity to passport across the bloc. Lithuania suits this profile well. The Bank of Lithuania has prior experience supervising crypto businesses at scale, local compliance infrastructure is available, and the authorisation pathway is established. The key risk is the substance requirement: the Lithuanian entity must have genuine local substance – a physical presence, a qualified management team and a demonstrable decision-making function – not a letterbox.

Profile B – A fintech startup building its first regulated product: A startup that has not previously operated in a regulated environment may find the MiCA CASP requirements demanding. The governance, own-funds and AML programme expectations reflect an institutional standard. Timeline and cost vary by licence class, but the process is not light-touch for any category. A startup with limited runway should assess whether a simpler authorisation in a less demanding regime – or a phased build under an existing operator's umbrella – is a better first step.

Profile C – A business transitioning from the legacy Lithuanian VASP registration: This is the most time-sensitive situation. Businesses that registered under the prior regime and have been operating on the basis of that registration must apply for CASP authorisation within MiCA's transition window. Operating after that window on a legacy registration that no longer provides legal cover exposes the business to enforcement by the Bank of Lithuania and potentially by other EU national competent authorities in markets where the operator passported. Early application – not the minimum viable filing – is the correct posture here.

A Practical Example: Transition Under Pressure

In a recent licensing matter, a payments company with an existing Lithuanian VASP registration sought to extend its services to include custody and a fiat-on/off-ramp product under MiCA's expanded service categories. The company's existing AML programme had been built for the prior, lighter-touch regime and did not meet the MiCA standard on transaction monitoring architecture or Travel Rule readiness. We advised on restructuring the compliance programme, rebuilding the governance documentation to reflect MiCA's fitness-and-propriety standard for the new management hire, and resequencing the banking setup to align with the expanded product scope. The application was submitted as a complete package on the first filing, avoiding the stop-the-clock delays that had affected a comparable peer operator. The business entered the Bank of Lithuania's formal assessment period without an initial deficiency notice.

A Common Assumption: Does a Single Licence Cover Everything?

A common assumption among inbound operators is that a Lithuanian CASP authorisation, once granted, covers the business globally and resolves its regulatory exposure in every market where it has users. That assumption is incorrect. MiCA passporting extends to the EU and EEA perimeter only. Markets outside that perimeter – including the United States, the United Kingdom, Singapore, Hong Kong, the UAE and many others – maintain independent licensing regimes. Serving clients in those markets from a Lithuanian entity, without the applicable local authorisation or an applicable exemption, may constitute unlicensed activity.

The corollary risk is on the banking side. A bank serving the Lithuanian entity may, as part of its own risk management, restrict accounts if the transaction profile suggests the entity is serving clients in markets it has not declared. The mismatch between the declared regulatory perimeter and the actual user base is one of the most common causes of banking instability for EU-authorised crypto operators.

In our practice, we map the jurisdictions where the operator's users are located – not just where the entity is incorporated – before advising on the licence stack. The Lithuanian authorisation is one layer. The global picture requires more.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Under MiCA, the Bank of Lithuania has a defined assessment period from receipt of a complete application. That window begins only once the regulator confirms the application is complete. In practice, the total elapsed time from initial preparation to authorisation depends heavily on the quality of the initial submission, the complexity of the governance structure and whether the AML programme meets the standard at first review. Well-prepared applications move through the process materially faster than those requiring multiple rounds of supplementary requests.

Which jurisdiction is best for licensing my crypto business?

There is no single correct answer. The right jurisdiction depends on the services offered, the client geography, the group structure, the banking relationships and the operator's timeline. Lithuania suits operators seeking EU passport rights with an established regulatory pathway. Other operators may be better served by VARA in Dubai, MAS in Singapore, the FSRA in Abu Dhabi or another regime. We assess the full operating model before recommending a jurisdiction – the licence is one variable in a wider structural equation.

Do I need a separate custody licence?

Under MiCA, custody and administration of crypto-assets on behalf of clients is a distinct regulated service. If your business model includes holding client assets, that activity must be covered by your CASP authorisation – either as a standalone licence category or as part of a broader authorisation covering multiple service types. Operating a custody function under an authorisation that does not include custody is a regulatory breach. In some group structures, a separate subsidiary holds the custody authorisation; that separation has governance and capital implications that require early planning.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, banking and tax stack across operating, custody and payment layers before you commit to a structure – giving general counsel and founders a clear picture before the board call. To discuss your situation, contact info@oboluslaw.com or reach us via t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in EU and cross-border CASP authorisation processes, MiCA transition structuring and inbound licensing strategy for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours