EST · MMXXVI
Home/Jurisdictions/Lithuania/Digital-asset custody authorisation in Lithuania
Licensing & Registration

Digital-asset custody authorisation in Lithuania

Digital-asset custody authorisation in Lithuania. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Digital-asset custody authorisation in Lithuania sits at the intersection of the European Union's tightening MiCA (Markets in Crypto-Assets Regulation) regime and a national supervisory posture that has hardened considerably since the easy-registration era of the early 2020s. For an exchange, fund or custody provider eyeing EU market access, the question is no longer whether Lithuania requires authorisation – it does – but whether the entity's structure, capital and compliance programme are calibrated to what the Bank of Lithuania now actually expects.

Under the MiCA framework, custody of crypto-assets for clients is a regulated service requiring a CASP (Crypto-Asset Service Provider) authorisation. A Lithuanian authorisation confers EU-wide passporting rights, making the jurisdiction a considered entry point for operators who need to serve clients across the EU/EEA from a single regulatory home. The analysis below covers the regulated perimeter, the authorisation process, the cross-border reality for inbound businesses, and the decision point that matters most: whether Lithuania is the right slot in your licence stack.

What Requires Authorisation Under the Lithuanian Regime?

Custody of crypto-assets for third parties is a regulated activity under the applicable MiCA provisions, supervised in Lithuania by the Bank of Lithuania. Any business that holds, stores or controls private keys on behalf of clients – whether described internally as "safekeeping," "wallet management" or "sub-custody" – falls within the regulated perimeter. The label the business uses does not alter the legal characterisation.

Lithuania transitioned from its prior national VASP registration regime to the MiCA CASP authorisation model in line with the EU-wide MiCA timetable. Businesses that were registered under the earlier regime are not automatically authorised under MiCA. They must go through the CASP authorisation process, which carries materially higher requirements on governance, own funds, safeguarding and operational resilience.

The scope extends further than many operators anticipate. Providing custody alongside an exchange function does not mean one licence covers both simply because the activities occur on the same platform. Under the MiCA regime, each regulated activity must be covered by the authorisation scope. The Bank of Lithuania's supervisory practice reflects that expectation. Operators we advise routinely discover mid-build that their proposed structure bundles regulated activities that require distinct coverage within a single CASP authorisation application.

The cross-border dimension sharpens the analysis. A Lithuanian entity serving clients in Germany, France or the Netherlands is providing custody services in those member states. The passporting mechanism under MiCA enables that – but only once the authorisation is in place and the notification procedure has been completed. Operating before that point, even from a licensed entity providing ancillary custody, is an exposure operators cannot afford to ignore.

How Does the CASP Authorisation Process Work in Lithuania?

The CASP authorisation process in Lithuania is managed by the Bank of Lithuania and proceeds through a structured application that covers legal form, governance, own-funds adequacy, operational and security arrangements, and AML/CFT compliance. The Bank of Lithuania has indicated publicly that it will apply the MiCA requirements rigorously; the supervisory tone is substantively different from the pre-MiCA registration environment.

The application requires, at minimum: a Lithuanian or EU-incorporated legal entity; a qualified management body with appropriate fitness-and-propriety assessments; a detailed business plan covering the custody activity; an internal controls framework addressing segregation of client assets, key management and incident response; and an AML/CFT programme aligned with the applicable FATF Recommendations, including the Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer).

The own-funds requirement varies by the scope of authorised activities. MiCA sets a tiered capital structure that increases with the breadth of activities covered. For custody-only authorisations the capital floor is set at a lower tier than for full exchange or lending activity, but the figure is determined by the MiCA own-funds rules and must be verified against current legislation – not estimated from older national thresholds that no longer apply.

Timeline expectations have lengthened under MiCA compared to the prior regime. The review process is measured in months rather than weeks, and the Bank of Lithuania's completeness review – the first gate before substantive assessment begins – can itself take several weeks. Businesses that submit incomplete applications or that cannot evidence the governance and capital requirements face requests for information that extend the timeline further. In our practice, we see applications prepared without specialist legal input losing several months at the completeness stage alone.

A practical note on the business-plan component: the Bank of Lithuania has signalled interest in the commercial viability and the client-protection mechanisms of the proposed custody model, not merely the legal structure. Applications that address only the compliance checklist without explaining the operational model and the client-asset safeguarding approach in substantive terms are consistently returned with questions.

To map your authorisation readiness before you file, contact OBOLUS at info@oboluslaw.com. The standard path described above shifts significantly once the entity structure, the client base and the banking arrangements are factored in. A scoped assessment identifies the gaps before the regulator does.

A Representative Matter: Restructuring Ahead of the MiCA Transition

In a recent authorisation matter, a European payments group with an existing Lithuanian VASP registration sought to expand into institutional custody services as MiCA took effect. The prior registration did not extend to custody under the new regime, and the group's corporate structure – with a holding company in one EU member state and the operating entity in Lithuania – created a governance ambiguity that the Bank of Lithuania's application template required them to resolve. We advised on restructuring the management body, aligning the own-funds position to the MiCA custody tier, and preparing the AML/CFT programme to meet the Travel Rule obligations applicable under the updated supervisory expectations. The authorisation application was submitted in a single complete filing; the completeness gate was cleared without a request for information.

What Does the Cross-Border Reality Look Like for an Inbound Operator?

For a business incorporated outside Lithuania – whether in the UAE, Singapore, BVI or elsewhere – using a Lithuanian CASP authorisation as the EU access point, the cross-border reality involves several layers that must be addressed in sequence. The Lithuanian entity must be genuinely substance-bearing: local management, meaningful decision-making in Lithuania, and day-to-day operations that the Bank of Lithuania can supervise. A brass-plate arrangement does not satisfy the MiCA substance expectations.

Banking is the layer that most frequently derails well-structured licence applications. Lithuanian banks have tightened their onboarding criteria for crypto businesses substantially. The business model, the client AML profile and the source-of-funds position for the entity's own capital are each scrutinised. EMI (electronic money institution) accounts and accounts held at banks in other EU member states are sometimes workable alternatives, but they add complexity to the payment and settlement architecture that needs to be designed into the structure from the outset, not retrofitted after the authorisation is granted.

Tax interaction is a further variable. Lithuania's corporate tax position is competitive within the EU, but the tax treatment of custody fee income, the VAT/GST characterisation of crypto-asset services and the withholding-tax implications of distributions from a Lithuanian entity to a non-EU parent all require analysis specific to the group structure. We regularly advise groups where the tax and banking stack was not aligned to the licence structure, resulting in economic friction that was entirely avoidable.

The passporting mechanism, once the CASP authorisation is live, enables notification to competent authorities in other EU/EEA member states before commencing custody services in those markets. The notification process is administrative, but it is not instantaneous. Operators who build a client pipeline before completing notifications are in a technical breach position in each unsatisfied member state. Timeline discipline on passporting is a straightforward compliance matter that is consistently deprioritised – and then becomes a problem at the point of first client onboarding.

If your licensing timeline is already in motion and the banking or tax stack is unresolved, write to us at info@oboluslaw.com. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams – and that integration is where the most significant practical risks are typically found. Map your options.

How Do AML and the Travel Rule Apply to a Lithuanian Custody Authorisation?

Lithuanian custody providers are subject to the full AML/CFT framework applicable under EU anti-money-laundering directives as transposed into national law, as well as the Travel Rule obligations that apply to virtual-asset transfers under the applicable EU funds-transfer regulation. The Bank of Lithuania supervises compliance with these obligations as part of its ongoing CASP oversight.

The Travel Rule requires that a custodian, when executing a virtual-asset transfer on behalf of a client, passes originator and beneficiary information to the receiving service provider. For custody-specific operations the practical application turns on whether the custodian is the originating VASP, the beneficiary VASP or an intermediary – and each position carries distinct data obligations. Operators that have not mapped their transfer typologies to the Travel Rule data requirements before authorisation typically discover the gap in the Bank of Lithuania's fit-and-proper assessment of their AML programme.

The customer due diligence requirements under the MiCA authorisation framework are aligned with the enhanced due diligence expectations applicable to high-risk financial services. For institutional custody – where the custodian holds assets on behalf of funds, exchanges or treasury operations – the due diligence extends to the beneficial ownership chain of the institutional client, not merely the entity itself. This is a common underestimation in AML programmes submitted by custody applicants without prior financial-services regulatory experience.

Ongoing supervision by the Bank of Lithuania includes the ability to request information, conduct on-site examinations and impose supervisory measures for non-compliance. The Bank of Lithuania has demonstrated a willingness to use its supervisory powers where AML failings are identified. Operating with a deficient AML programme under a CASP authorisation is not a technical breach with low enforcement probability – it is a category of failure that has attracted regulatory action across EU supervisory bodies.

Custody Versus Other Regulated Activities: What Else Is in Scope?

Custody does not exist in isolation for most operators. An exchange that also provides custody for client balances is combining two regulated activities under MiCA, both of which must be within the authorisation scope. A lending platform that takes custody of collateral has the same issue. The MiCA activity definitions are functional: if the economic substance of what the business does matches a regulated activity, it is regulated regardless of what the product documentation calls it.

The five most common miscategorisations we encounter in practice are: treating sub-custody on behalf of another CASP as unregulated intermediary services; characterising wallet infrastructure provided to institutional clients as a technology service rather than custody; treating staking-as-a-service as outside the custody perimeter when the private keys are held by the service provider; assuming that a trading desk operating from a non-EU group entity is not engaged in regulated exchange activity in Lithuania when Lithuanian-entity clients use it; and treating the management of a treasury portfolio on behalf of third-party institutional clients as non-discretionary and therefore unregulated.

Each of these positions is arguable in the abstract and dangerous in practice. The Bank of Lithuania has the authority under MiCA to characterise activities according to their substance. An authorisation application that accurately maps all regulated activities from the outset is far stronger than one that discovers additional activities during supervisory review.

Which Operator Profile Does Lithuania Suit – and Which Does It Not?

Lithuania suits a specific operator profile. The jurisdiction works well for an inbound business that needs EU/EEA market access via a single CASP authorisation, that can build genuine operational substance in Lithuania, and whose client base is predominantly institutional or professional rather than retail. The Bank of Lithuania's supervisory approach under MiCA is structured and process-driven; it rewards well-prepared applications with predictable timelines and penalises incomplete submissions with significant delays.

Profile A – the institutional custody provider entering the EU: a firm holding assets for fund managers, exchanges or treasury operations, with an existing AML programme and capital position, is well placed to use Lithuania as its EU authorisation base. The passporting mechanism then covers the EU/EEA client base from a single regulatory home. The key risk is substance: the Bank of Lithuania expects genuine management presence and decision-making in Lithuania.

Profile B – the retail exchange seeking EU expansion: a business whose primary model is retail spot trading with incidental custody of client balances should consider whether Lithuania is the right jurisdictional home or whether a larger NCA – one with a more developed supervisory infrastructure for retail-facing businesses – better fits the supervisory relationship the business will have over time. Lithuania is not the wrong answer for this profile, but it is not obviously the best one either.

Profile C – the non-EU group using Lithuania as a regulatory arbitrage play: this profile is the highest-risk one. MiCA substance requirements, the Bank of Lithuania's supervisory approach and the EU's anti-regulatory-arbitrage mechanisms under the CASP passporting framework are specifically designed to limit the use of a smaller NCA as a light-touch gateway. Applicants without genuine Lithuanian operations will find the authorisation process more difficult, and the ongoing supervision more demanding, than comparable approaches in the pre-MiCA era.

The decision is ultimately structural. Lithuania may be one slot in a multi-jurisdiction stack – the EU hub alongside a VARA authorisation in Dubai for MENA clients, or a MAS licence in Singapore for APAC distribution. In our cross-border practice, we routinely advise groups that maintain two or three regulatory homes, each serving a defined geographic and product scope. The question is not which single licence to obtain but which combination covers the actual client base and business model without duplication or gap.

A Common Assumption: One Offshore Licence Covers Global Operations

A common assumption among early-stage crypto businesses is that a single registration in a well-regarded offshore jurisdiction – BVI, Cayman, or a pre-MiCA EU jurisdiction – is sufficient to serve clients across the EU, Asia and the Americas. Under the MiCA regime, that assumption is structurally incorrect for EU clients. MiCA applies on the basis of where services are provided and where clients are located, not only where the provider is incorporated.

A custody provider incorporated in the BVI that holds crypto-assets for EU-resident clients is providing a regulated service in the EU. Without a CASP authorisation – either directly or through a passported entity – it is operating outside the regulatory perimeter. The enforcement consequence of that position is not merely a fine; it is the loss of banking relationships, the inability to onboard institutional EU clients, and the reputational exposure that follows a supervisory action in a major market.

The Travel Rule obligation compounds this: even a non-EU VASP receiving a transfer from an EU-based CASP may be required to satisfy Travel Rule data obligations under the EU's regulatory expectations for the sending entity. The cross-border reach of EU regulation extends beyond EU-domiciled businesses in ways that operators frequently underestimate until they encounter a compliance breakdown at the transfer layer.

The practical corrective is a licensing map that treats jurisdiction, client location and product type as three separate variables and identifies the authorisation requirement at each intersection. That map is the starting point of every engagement we take on for a business at the licensing decision stage.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Under the MiCA CASP authorisation process in Lithuania, the timeline is measured in months rather than weeks. The Bank of Lithuania's completeness review is the first gate; once a filing is accepted as complete, the substantive assessment begins. Applications that are fully prepared – with governance, own funds, AML and business-plan components in order – move through the process more predictably than incomplete submissions, which attract information requests that can significantly extend the overall duration.

Which jurisdiction is best for licensing my crypto business?

There is no single best jurisdiction; the right answer depends on where your clients are, what activities you conduct and what your banking and tax structure requires. Lithuania with a CASP authorisation offers EU-wide passporting under MiCA – a significant advantage for businesses serving European institutional clients. Operators serving MENA clients may need a VARA licence in Dubai alongside it. APAC distribution may require engagement with MAS or the SFC in Hong Kong. The optimal structure is a jurisdiction map, not a single licence.

Do I need a separate custody licence?

Under MiCA, custody of crypto-assets for third parties is a discrete regulated activity that must be specifically covered by a CASP authorisation. If an exchange or lending platform holds client assets, custody is part of the regulated scope and must be included in the authorisation. A CASP authorisation granted only for exchange services does not automatically cover custody. The Bank of Lithuania will assess each activity separately; applicants must identify all regulated activities in scope from the outset of the application.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions – including CASP authorisations under MiCA, VARA licences in Dubai and DPT licensing in Singapore – on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around every licence. We map the licence stack across operating, custody and payment layers before you commit, and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in EU and multi-hub CASP authorisations, VASP registration strategy and the cross-border structuring questions that sit at the intersection of licensing, banking and AML compliance.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours