Operating a crypto exchange in Lithuania requires a formal VASP registration (virtual asset service provider registration) under the supervision of the Bank of Lithuania, with AML/CFT (anti-money laundering and counter-terrorism financing) compliance obligations that have grown materially more demanding as the EU moves toward full MiCA (Markets in Crypto-Assets Regulation) authorisation. The answer for an inbound business is straightforward: you must obtain regulatory authorisation before offering exchange services to customers, and the compliance infrastructure required today is meaningfully heavier than it was two years ago. This page maps the regulated perimeter, the application process, the cross-border banking and tax interaction, and the decision point every operator faces as MiCA's CASP regime takes hold across the EU.
What does the law actually require to run an exchange in Lithuania?
Running a crypto exchange (a platform that exchanges virtual assets for fiat currency, or virtual assets for other virtual assets, on a commercial basis) in Lithuania is a regulated activity under the applicable VASP provisions supervised by the Bank of Lithuania. Any entity providing these services must register as a VASP before it begins operations. Providing the service without registration exposes the business to enforcement action, administrative penalties and, critically, the loss of payment and banking rails that any functioning exchange depends on. The Bank of Lithuania does not treat unregistered operations as a technicality.
The registration requirement applies to the Lithuanian entity itself. Operating through a foreign entity without a local presence, while routing Lithuanian or EU-resident customers through that foreign entity, is the kind of structure regulators in the leading EU hubs increasingly examine with scepticism. Cross-border operations do not dissolve the jurisdictional hook.
The Bank of Lithuania is the competent authority for VASP supervision. It operates within the EU's broader AML supervisory architecture, which means its expectations track the FATF Recommendations, including Recommendation 15 (the virtual-asset-specific standard) and the Travel Rule obligation to pass originator and beneficiary data with each qualifying transfer. Both obligations are live requirements, not aspirational guidance.
There is an important structural overlay. Lithuania was historically one of the faster EU entry points for VASP registration. That positioning is changing. Under MiCA, Lithuania will transition to the CASP authorisation model that applies across the EU, meaning the compliance bar rises and the passporting benefit — a CASP authorised in one member state may passport across the EU and EEA under a single authorisation — becomes the primary strategic reason to pick a member state carefully. Operators building now should design for MiCA from the outset, not for the legacy regime.
To map your specific registration path and MiCA readiness before you commit resources, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts — the entity structure, the user base across EU member states, the banking arrangements — change the analysis materially.
Who needs to register, and who is exempt?
The registration obligation captures any entity that, in the course of business, exchanges virtual assets for fiat or for other virtual assets, or operates a trading platform. The test turns on the commercial nature of the activity and the provision of services to third parties; internal treasury operations and single-token infrastructure for own-account purposes generally fall outside the perimeter, though the line is not always obvious.
Entities that do need to register include: exchange platforms matching buy and sell orders, OTC desks facilitating bilateral transactions, and operators combining exchange functions with wallet or custody features. If your product includes any of these in the Lithuanian market or involves Lithuanian-resident customers, the registration question is live.
The exemption analysis also runs in reverse. A foreign operator with no Lithuanian entity that actively markets to Lithuanian residents is not automatically outside the regime. The Bank of Lithuania, like regulators across the EU, is increasingly attentive to digital-first distribution that relies on the absence of a physical presence to argue against local jurisdiction. In our cross-border practice, we consistently advise operators to assess the jurisdictional position of each operating entity and each user-facing interface, not just the registered office.
How does the VASP registration and MiCA CASP application process work?
The VASP registration process in Lithuania involves submitting a formal application to the Bank of Lithuania, supported by a compliance package that covers the entity's AML/CFT programme, beneficial ownership structure, governance arrangements and key personnel credentials. The application is assessed against the applicable VASP provisions; the Bank of Lithuania may request supplementary information before issuing its decision.
The compliance package is the operative challenge, not the administrative filing. The Bank of Lithuania expects a functioning AML programme — written policies, a designated compliance officer with appropriate credentials, transaction monitoring procedures, customer due diligence and enhanced due diligence protocols, and Travel Rule implementation. A package that looks complete on paper but lacks operational substance will either be rejected or queried extensively, adding time and cost to the process.
For the MiCA transition, the picture is more demanding. CASP authorisation under MiCA adds a whitepaper obligation for many token-related services, own-funds and capital requirements set at the CASP class level (light, standard or significant), and ongoing reporting obligations to the national competent authority. Operators currently registered as VASPs will need to transition to the CASP framework; the transition window is defined under MiCA but varies in implementation detail by member state. Designing the entity and governance structure for CASP authorisation from the start avoids the cost of a material restructure mid-transition.
Timelines for registration under the legacy VASP regime varied by the quality of the submission and the volume of applications at the Bank of Lithuania at any given time. Under MiCA, CASP authorisation timelines are set within the regulation itself, though national implementation may affect how quickly the authority processes a complete application. We advise clients to plan for a process measured in months, not weeks, particularly when the compliance infrastructure is being built from scratch.
What are the AML and Travel Rule requirements for a Lithuanian crypto exchange?
AML and Travel Rule compliance are not checkbox items for a Lithuanian exchange — they are the operational infrastructure the entire licence rests on. The Bank of Lithuania supervises compliance actively, and FATF (the Financial Action Task Force) mutual evaluation cycles mean Lithuanian regulators face external scrutiny of how effectively they enforce these obligations on supervised entities.
The Travel Rule (the obligation to pass originator and beneficiary data with a qualifying virtual-asset transfer) applies to Lithuanian VASPs and will apply to CASPs under MiCA. Implementation requires a technical solution that integrates with counterparty VASPs/CASPs, captures the required data fields at the point of transaction initiation, and stores records for the minimum retention period specified in the applicable provisions. The data threshold below which the obligation does not apply is set in the applicable legislation; because that threshold is subject to change and to national implementation variation, we recommend confirming the current figure against the live legislation rather than relying on any static published summary.
In practice, the Travel Rule creates a network dependency. Your exchange can only satisfy the obligation if the counterparty VASP or CASP at the receiving end is also able to receive and process the data. For transactions to unhosted wallets, a different — and currently unsettled — set of obligations may apply depending on the risk assessment and the applicable provisions in force at the time. Operators we advise routinely underestimate the technical and legal complexity of Travel Rule implementation; it is among the top reasons a completed AML programme still fails in practice.
How does the cross-border banking and tax picture interact with a Lithuanian exchange licence?
Licensing in Lithuania resolves the regulatory authorisation question but does not, by itself, resolve banking or tax. Both require separate structuring, and the interaction between all three layers is where operators most frequently encounter structural failure.
On banking: EU-regulated VASPs and CASPs have faced material de-banking pressure across the bloc. Lithuanian entities are not exempt. Obtaining an account with a Lithuanian credit institution requires demonstrating a functioning AML programme, clear beneficial ownership, and a business model that the bank's compliance team can explain internally. In our practice, we see applications stall not because the exchange lacks a licence but because the banking presentation does not map the regulated compliance infrastructure to the bank's own due diligence expectations. A separate, parallel banking strategy — including the identification of EU and non-EU banking relationships appropriate to the exchange's transaction profile — is a first-order concern, not an afterthought.
On tax: the tax treatment of crypto exchange operations in Lithuania turns on the Lithuanian corporate tax regime and, for cross-border structures, on the interaction with the tax laws of the group holding structure and the jurisdictions of key personnel. Token classification — whether a transaction produces trading income, capital gain, or triggers VAT considerations — is fact-specific and subject to evolving administrative guidance. A Lithuanian exchange that is part of a wider group structure must also assess the transfer pricing implications of intercompany arrangements for technology, IP, and shared services. The Lithuanian tax authority's approach to these questions has tightened as the asset class has matured, and reliance on informal guidance from prior years carries risk.
For any operator with EU users and a holding structure outside Lithuania, the cross-border tax and banking analysis is not optional. It is the part of the structure that determines whether the licensed entity is operationally viable.
How does this play out in practice?
In a recent matter, a payments-adjacent business sought to add a crypto exchange function to an existing EU-regulated entity, believing the existing AML framework would be sufficient for VASP registration in Lithuania. On review, the compliance programme lacked transaction monitoring procedures specific to virtual-asset transfers and had no Travel Rule implementation plan. The banking relationship also predated the crypto component and had not been disclosed to the bank. We advised on the required additions to the compliance infrastructure, restructured the disclosure to the bank, and supported the registration filing with an updated programme. The registration proceeded, and the banking relationship was preserved. The key delay was the time required to build the Travel Rule solution — a point the client had not anticipated at the outset.
What is the right decision framework for operators considering Lithuania?
Lithuania is a credible EU base for a crypto exchange, particularly for operators whose primary objective is EU market access and the passporting benefit that comes with CASP authorisation. It is not the right choice for every operator, and the decision should be tested against a defined set of axes before committing capital to entity formation and compliance infrastructure.
Profile A – an exchange targeting EU retail and institutional clients, with a holding structure capable of supporting EU-compliant capitalisation and governance: Lithuania is a viable and cost-competitive EU entry point. The CASP authorisation under MiCA provides the passporting that makes a single-jurisdiction licence commercially meaningful. The key risk is the transition timeline and the capital requirements at the applicable CASP class.
Profile B – a non-EU operator seeking a licensing anchor to serve a global user base under a single licence: the premise needs testing. A single EU authorisation does not cover the US, UK, Singapore, UAE or other material markets. Operators we advise on multi-market structures typically need a stack of authorisations across two or three hubs, with Lithuania or another EU member state covering the EU-passportable perimeter. The "single offshore licence" assumption is the most common structural error we encounter.
Profile C – an operator with a live exchange in another jurisdiction looking to add EU access: the cleanest approach is usually a purpose-built EU entity with a dedicated compliance function, rather than attempting to extend the existing entity's registration across jurisdictions. The Bank of Lithuania, like other EU competent authorities, expects the regulated entity to have operational substance in the jurisdiction.
A common assumption among operators approaching the EU market for the first time is that the legacy VASP registration was essentially a filing exercise and that MiCA represents a modest incremental step. That assumption understates the change. MiCA CASP authorisation is closer in substance to a financial services licence than to an AML registration. The governance, capital and ongoing reporting obligations are materially more demanding, and the passporting benefit — real and valuable as it is — is available only to operators that meet the full standard.
If your application has stalled or your banking has been challenged after registration, a second structural review can surface the underlying issue. Write to info@oboluslaw.com to scope that work.
Related at OBOLUS
- Licensing and registration for digital-asset businesses – the full cross-jurisdictional licensing practice at OBOLUS, from VASP to CASP and beyond.
- Malta vs Hong Kong: where to licence a crypto business – a comparative analysis of two leading non-EU hubs against the EU passporting model.
- Transaction monitoring setup in Germany under BaFin – AML and transaction monitoring requirements for exchanges operating under BaFin supervision.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, banking and compliance stack across operating, custody and payment layers before you commit — so the structure works from day one, not after the first enforcement query. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums. To discuss your situation, contact info@oboluslaw.com.
FAQ
How long does a crypto licence take to obtain?
Under the legacy VASP regime in Lithuania, timelines varied by submission quality and regulatory volume — typically a matter of months for a complete application. Under MiCA, CASP authorisation timelines are set within the regulation, though national processing adds variability. Operators should plan for a process measured in months, not weeks, particularly when AML infrastructure and Travel Rule implementation are being built from scratch. Early engagement with counsel reduces the risk of information requests that extend the timeline.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. The right jurisdiction turns on your user base, your business model, your holding structure and your banking relationships. Lithuania offers a cost-competitive EU base with MiCA passporting. Singapore, the UAE and Hong Kong offer non-EU hubs with strong banking access. Most operators serving multiple regions need a stack of authorisations across two or more jurisdictions. A single offshore licence is not sufficient to serve a global user base. We advise on the full multi-jurisdiction analysis before any commitment is made.
Do I need a separate custody licence?
In most flagship jurisdictions, custody of client virtual assets is a separately regulated activity or at minimum a separately authorised function within a broader licence. Under MiCA, custody and administration of crypto-assets on behalf of clients is a distinct CASP service category. If your exchange also holds client assets between transactions, the custody perimeter almost certainly applies to you. The answer is fact-specific and depends on the structure of your product; it should be assessed before the exchange goes live, not after the first client complaint.
By Aisha Tan, Licensing & Jurisdictions Analyst — specialising in EU and multi-hub VASP/CASP authorisation, with a particular focus on inbound operators structuring for the MiCA transition.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.