EST · MMXXVI
Home/Jurisdictions/Lithuania/EMI licence for crypto firms in Lithuania
Licensing & Registration

EMI licence for crypto firms in Lithuania

Emi licence for crypto firms in Lithuania. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Operating a crypto business in Lithuania without the correct authorisation is not a calculated risk – it is an enforcement event waiting to happen. Frozen payment rails, closed correspondent accounts and regulatory prohibition notices arrive without warning. The Electronic Money Institution (EMI) licence issued under the supervision of the Bank of Lithuania has become one of the most commercially relevant authorisation routes for crypto firms targeting the European Union, combining a well-defined regulatory path with full MiCA (Markets in Crypto-Assets Regulation) transition eligibility. This page sets out the regulated basis for that licence, the inbound process, the cross-border interactions with tax and banking, and the decision points every operator should work through before committing to Lithuania.

Why an EMI licence matters for a crypto firm in Lithuania

An EMI licence in Lithuania grants authorisation to issue electronic money and provide payment services across the European Economic Area under the EU passporting regime – and it is a foundational layer for crypto businesses that need to hold client fiat, move funds across borders and interface with the banking system. Lithuania has been among the most accessible EU entry points for digital-asset businesses. The Bank of Lithuania supervises EMI applicants with a published, process-oriented review cycle. For a crypto firm, the licence resolves the question every bank asks before opening an account: what is your regulatory status, and in what jurisdiction?

The cross-border dimension is immediate. A Lithuanian EMI passport covers the full EU and EEA without a separate licence in each member state. A firm serving users in Germany, France or Poland from a Vilnius-incorporated entity does so under a single authorisation – provided the host-state notification procedures are followed and the firm's governance genuinely sits in Lithuania. Regulators across the bloc have become increasingly attentive to letter-box structures. Substance requirements matter.

Separately, Lithuania maintains a VASP registration (virtual asset service provider registration) regime that predated MiCA. Many operators hold both an EMI licence and a VASP registration. Under the MiCA transition, the VASP registration track is converging toward the CASP authorisation (Crypto-Asset Service Provider authorisation) framework that ESMA and the Bank of Lithuania are now jointly shaping. The EMI licence, by contrast, addresses the payment and e-money layer – a distinct regulated perimeter that does not disappear under MiCA.

The risk of getting this wrong is concrete. A crypto firm that processes client fiat through an unlicensed entity – even one that holds a VASP registration – is operating a payment business without authorisation. That exposure does not require a hostile regulator to materialise; a single correspondent bank's compliance query can surface it and end the banking relationship overnight.

For a scoped assessment of your Lithuanian licensing position, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options.

What does the EMI licence actually regulate?

The EMI licence in Lithuania authorises the issuance of electronic money and the provision of defined payment services under the transposed EU Payment Services Directive and the E-Money Directive. For a crypto firm, the relevant perimeter is: any activity that involves holding client funds denominated in fiat, executing payment transactions on behalf of clients, or issuing instruments that function as stored value redeemable for fiat. That definition covers a substantial portion of what an exchange, a stablecoin issuer or a crypto payments processor actually does.

The Bank of Lithuania draws a clear line between the EMI perimeter and the securities or investment perimeter. A firm issuing asset-referenced tokens (ARTs) or providing portfolio management over crypto-assets will trigger separate MiCA CASP or financial instruments analysis. The EMI licence does not authorise those activities. Operators running multiple product lines – exchange, custody, stablecoin issuance and payment processing – need each layer assessed independently. In our practice, the first mandate we take on is a full perimeter map, because the most common structural error is assuming one licence covers all revenue streams.

The practical consequence: a crypto exchange that settles trades in EUR and holds client EUR balances pending withdrawal is operating a payment service. That requires either an EMI licence, a payment institution licence, or a credit institution licence – or, in limited circumstances, reliance on a licensed partner under an agency or BaaS arrangement. Each path has a different regulatory profile and different capital expectations. The EMI route offers the broadest EU passporting scope and the greatest operational flexibility for firms with multi-currency, multi-product ambitions.

How does the EMI application process work in Lithuania?

The Bank of Lithuania runs a structured, document-intensive authorisation process for EMI applicants, with defined review stages and a published expectation of completeness before the clock starts. The application is not a form-filling exercise; it is a regulatory examination of the business, its governance, its compliance programme and its risk management arrangements.

The process begins with a pre-application phase. Applicants are expected to engage the Bank of Lithuania before formal submission – to confirm scope, discuss any novel features of the business model, and receive feedback on structural questions. For a crypto firm, this phase is particularly important. The Bank's examiners will want to understand the crypto-asset activities alongside the e-money activities, and any ambiguity in the perimeter should be resolved before the formal dossier is filed.

The core application dossier typically covers: the business plan (including financial projections), the governance structure, the programme of operations (the specific payment services to be provided), the internal controls framework, the AML/CFT programme, the IT and security documentation, the safeguarding arrangements, and the fitness-and-propriety documentation for all qualifying shareholders and senior managers. For crypto-adjacent businesses, the Bank of Lithuania will additionally examine the VASP registration status, the on-chain risk assessment and the transaction monitoring architecture.

Timeline is qualitative by design in this registry – the Bank of Lithuania does not publish a fixed statutory clock that runs unconditionally. In our experience advising inbound applicants, a well-prepared dossier with no material information gaps moves through the review cycle materially faster than a file that requires multiple rounds of supplemental questions. Operators who treat the pre-application phase as optional consistently extend their own timelines. Plan for a process measured in months, not weeks, and structure the corporate build accordingly.

A Lithuanian-incorporated company with substance is the prerequisite. That means a registered office, resident management or a locally present authorised representative, and genuine decision-making authority in Vilnius – not a serviced address with a nominal director. The Bank of Lithuania has tightened its substance assessment materially over recent application cycles.

How does MiCA interact with an existing Lithuanian licence?

MiCA does not render the Lithuanian EMI licence redundant – it adds a layer above the existing payment regime for firms whose crypto-asset activities extend beyond the e-money perimeter. An operator that holds a Lithuanian EMI licence and wishes to provide crypto-asset services as defined under MiCA – exchange services, transfer services, custody, advice – must obtain a CASP authorisation or qualify for the transitional grandfathering provisions that MiCA affords to firms already regulated under national law.

The MiCA transition is a live compliance event, not a future planning item. ESMA and the Bank of Lithuania have published joint guidance on the transition pathway. Firms operating under the prior Lithuanian VASP registration need to assess their MiCA classification urgently: are they issuing ARTs or EMTs, are they providing services listed in the MiCA annex, and do their existing licences cover those activities or leave gaps? In our cross-border practice, we have seen operators make the error of assuming the transition is automatic. It is not. Each service line requires its own classification analysis.

For a firm that already holds a Lithuanian EMI licence, the MiCA transition may actually be a competitive advantage. The Bank of Lithuania will apply the transitional provisions to EMI-licensed firms that can demonstrate their existing governance and compliance infrastructure is MiCA-compatible. That means less incremental work for the well-prepared operator and a faster path to CASP authorisation. The inverse is also true: a firm that let its compliance programme stagnate faces a full rebuild under MiCA standards, with no credit for the prior licence.

Stablecoin issuers face a specific MiCA dynamic. E-money tokens (EMTs) – stablecoins referencing a single fiat currency – must be issued by an authorised EMI or credit institution under MiCA. A Lithuanian EMI licence is therefore a direct prerequisite for lawfully issuing a EUR-denominated EMT into the EU market. That requirement alone makes the Lithuanian EMI route structurally significant for any operator building a euro-denominated stablecoin product.

What are the AML and Travel Rule obligations?

AML and Travel Rule compliance (the obligation to pass originator and beneficiary identifying information with a virtual asset transfer) are non-negotiable conditions of both the EMI licence and the VASP registration in Lithuania. The Bank of Lithuania expects a documented, risk-based AML/CFT programme that covers both the fiat-facing (payment) side and the crypto-asset side of the business.

The Travel Rule, derived from FATF Recommendation 15, applies to virtual asset transfers above the applicable de-minimis threshold. In practice, a Lithuanian-licensed crypto firm must be able to collect, screen and transmit originator and beneficiary data for covered transfers, and must operate a VASP-to-VASP due diligence programme before sending or receiving transfers from counterpart VASPs. The technology infrastructure to meet this obligation – a compliant Travel Rule solution – is part of the IT documentation the Bank of Lithuania reviews at authorisation and in subsequent supervision.

Transaction monitoring is an area of increasing supervisory focus. The Bank of Lithuania has invested in its own digital-asset examination capabilities. On-site and off-site reviews now regularly include a technical review of the firm's blockchain analytics tooling, its alert thresholds, its case escalation procedures and its suspicious activity reporting record. A firm that can demonstrate a mature, data-driven monitoring programme – not a checkbox policy – is materially better positioned in supervision than one that relies on legacy rule sets.

The cross-border AML dimension is also significant. A Lithuanian EMI licence does not insulate a firm from AML expectations in the jurisdictions where it operates through the EU passport. Host-state regulators can and do conduct their own AML examinations of passported firms. A firm operating in Germany under a Lithuanian passport must comply with German AML transposition, including local suspicious activity reporting obligations. The compliance programme must be architected for the whole EU footprint, not just the home state.

How do banking and tax interact with the Lithuanian EMI structure?

Banking access is the practical constraint that determines whether an EMI licence has real commercial value. A Lithuanian EMI licence signals regulated status to correspondent banks and payment networks – but it does not guarantee an account. In our experience, the operators who secure banking most efficiently are those who build the compliance narrative before the first bank conversation, not after the licence is in hand.

Lithuanian banks serve some EMI licence holders, but the correspondent banking environment for crypto-adjacent firms is tight across the EU. A Lithuanian EMI typically banks with a combination of a domestic institution, an EU correspondent and a SEPA-connected PSP. The entity's transaction profile, the jurisdictions it serves, the crypto-asset categories it handles and its AML programme are all scrutinised by prospective banking partners. Firms that process high-volume crypto-to-fiat flows for retail users face a narrower set of banking options than firms running institutional or B2B models.

On the tax side, Lithuania offers a competitive corporate tax environment. The standard corporate income rate and the applicable reliefs are set by domestic legislation and are subject to change; operators should obtain current tax advice rather than rely on published summaries. What is structurally relevant for an inbound crypto operator is the interaction between the Lithuanian tax regime and the jurisdictions where shareholders, customers and counterparties are located. A Lithuanian EMI entity sitting in a group structure that includes a BVI holding company, a UAE operational entity and US-resident founders involves at least four distinct tax analyses – Lithuania, the holding jurisdiction, the UAE and the US – before the structure is tax-efficient rather than tax-exposed.

In a recent matter, an exchange operator sought to consolidate its European payment flows through a newly authorised Lithuanian EMI entity. The group structure had been assembled quickly, with the holding company and the operating entity in different jurisdictions and no formal transfer pricing policy. We advised on restructuring the intercompany arrangements before the Bank of Lithuania's authorisation took effect, ensuring the entity could demonstrate genuine economic substance without triggering adverse tax treatment in the parent jurisdiction. The authorisation proceeded on the revised structure without complication.

If your licensing, banking and tax layers were assembled separately and have never been reviewed as a system, the gaps are almost certainly there. To map the licence, banking and tax stack for your build, write to info@oboluslaw.com or map your options here.

Which operator profile should choose the Lithuanian EMI route?

Not every crypto firm needs a Lithuanian EMI licence, and not every firm that needs EU payment authorisation should start in Lithuania. The decision turns on the firm's operating model, its user base, its product road map and its cross-border structure. The following profiles reflect the analysis we run for inbound operators.

Profile A – The EU-market crypto exchange with fiat settlement. An exchange that holds client EUR/GBP/USD balances, executes fiat-to-crypto and crypto-to-fiat conversions, and serves retail or institutional users across the EU is a direct fit for the Lithuanian EMI route. The licence addresses the payment layer; the VASP registration or MiCA CASP authorisation addresses the crypto-asset service layer. Timeline: measured in months for a well-prepared applicant. Key risk: substance requirements – the Bank of Lithuania expects genuine local governance, not a post-box entity.

Profile B – The stablecoin issuer targeting EU distribution. A firm issuing an EMT (a MiCA-defined e-money token pegged to a fiat currency) must hold an EMI or credit institution authorisation in an EU member state. Lithuania is a credible option for an operator that wants EU passporting without the capital and structural complexity of a German or French credit institution authorisation. Timeline: similar to Profile A for the EMI base; MiCA CASP or specific EMT authorisation adds incremental process. Key risk: the reserve and redemption requirements under MiCA for EMT issuers are operationally demanding – the banking and custody arrangements for reserve assets require careful structuring.

Profile C – The crypto payments processor serving EU merchants. A firm providing crypto-based payment processing services to EU merchants, settling in fiat or stablecoin, needs the payment services authorisation that the EMI licence provides. Lithuania offers a faster path than most comparable EU jurisdictions for a well-prepared applicant. Key risk: the passporting notification process is a precondition for serving merchants outside Lithuania – it is not automatic on licence grant.

Profile D – The operator that does not need an EMI licence. A pure crypto-to-crypto exchange that never holds fiat, never issues stored value instruments and never executes payment transactions does not require an EMI licence. It needs the applicable VASP registration or MiCA CASP authorisation. Conflating the two perimeters is a common and expensive error.

Self-assessment: are you ready to apply?

Before filing an EMI application with the Bank of Lithuania, an operator should be able to answer yes to each of the following questions. A no on any item is a gap that the Bank of Lithuania will identify – better to find it first.

  • Is the Lithuanian entity fully incorporated, with a registered office and local substance (resident management or an authorised representative with genuine authority)?
  • Has the business plan been prepared to EMI standard – including financial projections, capital adequacy analysis and a programme of operations that maps each payment service to the regulatory definition?
  • Is the AML/CFT programme documented, risk-based and capable of covering both the fiat and crypto-asset activities of the business?
  • Has a Travel Rule solution been selected and documented – including the VASP-to-VASP due diligence protocol?
  • Have fitness-and-propriety packs been assembled for all qualifying shareholders (above the applicable thresholds) and all senior managers?
  • Has the safeguarding arrangement been confirmed – either a segregated client fund account at an authorised credit institution or a qualifying insurance arrangement?
  • Has the firm obtained a current VASP registration (or assessed whether it is required alongside the EMI licence)?
  • Has the cross-border tax and group structure been reviewed in light of the Lithuanian entity's substance and transfer pricing obligations?

A common assumption among inbound operators is that holding any offshore licence – a BVI VASP registration, a Cayman VASP certificate – is sufficient to serve EU clients. It is not. MiCA and the Bank of Lithuania's EMI regime apply to the services provided to EU users, regardless of where the entity is incorporated. The offshore licence addresses the home jurisdiction only. EU clients require EU authorisation, and that analysis does not change based on the entity's domicile.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timeline varies by jurisdiction, licence category and the completeness of the application dossier. In Lithuania, a well-prepared EMI application with no material information gaps moves through the Bank of Lithuania's review cycle in a period measured in months. Applications that require multiple rounds of supplemental questions extend materially beyond that. Pre-application engagement with the regulator is the single most effective way to compress the timeline. Under MiCA, CASP authorisation timelines are set at the EU level but remain subject to the national competent authority's processing capacity.

Which jurisdiction is best for licensing my crypto business?

There is no universal answer. The right jurisdiction turns on the firm's operating model, target user base, product mix, banking requirements and group structure. Lithuania works well for EU-market operators who need a passportable payment or e-money licence alongside a crypto-asset authorisation. Other operators may be better served by Ireland, Malta, the ADGM in Abu Dhabi, VARA in Dubai or the MAS regime in Singapore. We assess the full licence stack – operating, custody, payment and tax – before making a recommendation. A single jurisdiction rarely covers all layers of a multi-product business.

Do I need a separate custody licence?

In most flagship regimes, custody of crypto-assets is a regulated activity that requires its own authorisation or forms a discrete permission within a broader licence. Under MiCA, custody and administration of crypto-assets on behalf of clients is a defined CASP service requiring specific authorisation. An EMI licence in Lithuania does not, of itself, authorise crypto-asset custody. Operators running exchange, payment and custody functions within a single entity need each layer assessed – the licences may be held in the same entity or split across a group depending on capital, operational and risk-management considerations.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams – ensuring that no gap between those layers creates the enforcement or banking exposure that ends a business before it scales. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in EU and Gulf digital-asset licensing strategy, with a focus on Lithuanian EMI and MiCA CASP authorisation for inbound operators.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours