Lithuania became one of the most accessible EU entry points for virtual asset service providers (VASPs) during the years when the prior national registration regime allowed rapid, low-barrier market access. That window has materially changed. Under MiCA – the EU's Markets in Crypto-Assets Regulation, supervised at the European level by ESMA and nationally by the Bank of Lithuania – the country now operates within a single EU-wide authorisation standard. A business that secured a Lithuanian VASP registration under the old regime must transition to a CASP authorisation (Crypto-Asset Service Provider) to continue operating lawfully. Operators entering Lithuania for the first time face the full MiCA process from the outset.
The practical consequence is straightforward. A CASP authorised by the Bank of Lithuania can passport its services across the EU and EEA without a separate application in each member state. That passporting right is the primary commercial reason to choose Lithuania today. The legal requirement is no longer a registration tick-box; it is a full regulatory authorisation with substance expectations, capital requirements (which vary by licence class), and ongoing AML/CFT obligations anchored to the FATF Travel Rule.
This page sets out the regulated basis, the application process, the cross-border interactions that most inbound operators underestimate, and the decision point at which external counsel typically adds the most value.
Who Needs a CASP Authorisation in Lithuania?
Any business providing crypto-asset services to EU-based clients must hold a CASP authorisation under MiCA – or rely on a valid passported authorisation from another EU member state. The MiCA regime covers a defined list of regulated activities: operation of a trading platform, exchange of crypto-assets for fiat or for other crypto-assets, execution of orders, portfolio management, advice, transfer services, and custody and administration of crypto-assets on behalf of clients. If your business touches any of those activities and your clients are in the EU, Lithuanian authorisation is not optional.
The Bank of Lithuania is the competent authority for entities incorporated in Lithuania. It supervises CASP applications, monitors ongoing compliance and coordinates with ESMA on cross-border notifications. Operators that previously registered under Lithuania's pre-MiCA VASP regime were not automatically authorised under MiCA; a formal transition application was required. In our practice, we see operators who assumed their legacy registration carried forward – it does not, and the enforcement exposure from that assumption is real.
One structural note for inbound businesses: the entity that holds the authorisation must be genuinely incorporated in Lithuania, with a registered office, an effective place of management, and personnel capable of running the regulated activities. A letterbox entity will not satisfy the Bank of Lithuania's substance expectations. That substance requirement drives many of the cost and timeline decisions an operator must make before filing.
What Activities Does the MiCA CASP Regime Cover?
MiCA defines the regulated perimeter by reference to specific activities, not by reference to the type of asset in isolation. The key activities – exchange services, transfer services, custody, portfolio management, advice, and platform operation – each carry their own capital, organisational and conduct requirements. A business that operates a trading platform and also provides custody sits in a higher-capital bracket than one providing advice alone. The Bank of Lithuania will assess the application against the precise scope of activities declared, so over-scoping or under-scoping a licence application has direct consequences on capital, fees and ongoing reporting.
The token-side of MiCA matters here too. If your business issues or plans to issue crypto-assets that qualify as asset-referenced tokens (ARTs) – instruments that reference a basket of assets – or e-money tokens (EMTs) – tokens referencing a single fiat currency – a distinct authorisation track applies, separate from general CASP authorisation. Stablecoin issuers in particular need to map their instrument against ESMA's and the Bank of Lithuania's guidance before choosing a structure. Publishing a regulatory-compliant whitepaper is mandatory for most token offerings under MiCA, and the whitepaper notification period must be factored into your launch timeline.
For the operator whose business spans token issuance and exchange services, the two tracks must run in parallel – a sequencing challenge that is better anticipated before the project is structured, not after the first regulatory query arrives.
How Does the CASP Application Process Work?
The CASP authorisation process in Lithuania begins with incorporation and substance establishment, followed by a formal application to the Bank of Lithuania with a defined file of documentation. The Bank of Lithuania reviews the application for completeness, then enters a substantive assessment phase. MiCA sets an outer assessment window, though the practical timeline depends on the completeness of the application file, the complexity of the business model, and the regulator's current caseload. Incomplete files – missing AML policies, insufficient capital evidence, or underdeveloped governance documentation – reset the clock.
The required documentation typically includes the following categories:
- A programme of operations and business plan covering the first three years.
- A description of the governance arrangements, internal controls and risk management framework.
- AML/CFT policies, including Travel Rule implementation procedures and a business-wide risk assessment.
- Proof of initial capital, with the capital level corresponding to the declared activities.
- Information on qualifying shareholders (fit and proper assessment) and on key function holders.
- A description of the IT and security arrangements, including custody and segregation mechanisms where relevant.
- Complaints-handling procedures and, where applicable, a client asset protection policy.
The Bank of Lithuania may request additional information during the review. Each information request effectively pauses the clock. Operators who have worked through a prior authorisation in another EU member state often underestimate how specifically the Bank of Lithuania frames its queries; responses need to be legally precise, not commercially general.
The MiCA-mandated assessment period begins from the date the application is deemed complete, not from the date of initial submission. Building a complete file before submission is not a formality – it is the primary variable an operator controls. In our practice, we advise clients to treat the pre-submission review as the most time-efficient investment in the process.
Once authorised, the CASP may notify other EU/EEA member states and commence passported services in those markets without a separate local authorisation. The notification process runs through the Bank of Lithuania and is managed by counsel as part of the post-authorisation phase.
What Are the AML and Travel Rule Obligations for Lithuanian CASPs?
AML/CFT compliance is non-negotiable for any CASP in Lithuania. The Bank of Lithuania enforces Lithuania's anti-money laundering legislation, which incorporates the EU's Anti-Money Laundering Directives and aligns with the FATF Recommendations, including Recommendation 15 on virtual assets. The practical effect is that a Lithuanian CASP must implement a full AML programme: customer due diligence (standard and enhanced), ongoing monitoring, suspicious transaction reporting, and sanctions screening.
The Travel Rule – the obligation to transmit originator and beneficiary data alongside a virtual asset transfer – applies to Lithuanian CASPs in line with the EU's Transfer of Funds Regulation as extended to crypto-assets. A CASP sending or receiving virtual asset transfers must collect, verify and pass the prescribed data fields. The threshold below which the Travel Rule applies and the precise data fields required are set by the applicable EU regulation; CASPs should confirm current thresholds against the regulation and the Bank of Lithuania's supervisory guidance at the time of application, as these parameters are subject to ongoing supervisory clarification.
One operational point that operators consistently underestimate: the Travel Rule requires a counterparty VASP to receive the data, which means your compliance solution depends on your counterparties having compatible infrastructure. If you are operating in a corridor where counterparty VASPs are outside the EU or in jurisdictions with less developed Travel Rule implementation, you need a documented policy for the unhosted-wallet and non-compliant-counterparty scenarios. The Bank of Lithuania will examine this policy during the authorisation review.
How Does Banking Interact with Lithuanian CASP Authorisation?
Securing a CASP authorisation from the Bank of Lithuania does not automatically resolve the banking question, and this is the operational reality that catches the most inbound operators by surprise. EU payment institutions and banks are not obliged to provide accounts to CASPs simply because they are regulated. A number have residual appetite for crypto-client risk; most have not. The practical result is that many Lithuanian-licensed CASPs bank through electronic money institutions, specialised fintech payment service providers, or institutions in other EU member states that have developed crypto-specific onboarding policies.
The cross-border banking interaction creates a secondary compliance layer. Where a CASP holds client funds through a payment institution in a second EU member state, the client money protections of both regimes potentially apply. The CASP's AML and governance documentation must be consistent across jurisdictions. A client receiving services through a Lithuanian entity but whose funds flow through a payment account in a different country needs an operating model that withstands scrutiny by the Bank of Lithuania, the payment institution's compliance team, and, where passporting is active, the NCA in the user's home state.
In our cross-border practice, we routinely work through this three-layer analysis – licence, banking and user-jurisdiction – before a client submits its application. The banking relationship shapes the application's description of payment flows, which in turn shapes the AML programme. Getting that sequencing wrong produces expensive re-submissions.
For a scoped assessment of your licence, banking and structural stack before submission, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base geography, the banking counterparties – change the analysis significantly.
What Is the Cross-Border Reality for a Lithuanian CASP Operating Across the EU?
The passporting right under MiCA is real and commercially valuable, but it is not frictionless. A CASP authorised in Lithuania that wishes to serve clients in, say, France, Germany, the Netherlands and Spain must notify the Bank of Lithuania, which forwards the notification to each relevant NCA. Those NCAs may impose local conduct-of-business requirements. Operator marketing must comply with the financial-promotion standards of each host state. Localised terms of service, language obligations and consumer-facing disclosure requirements in host jurisdictions are outside the scope of the Lithuanian authorisation itself.
The EU's AML supervisory architecture is also evolving. ESMA's convergence work means that supervisory expectations from the Bank of Lithuania are increasingly influenced by ESMA guidelines, not just national implementation. An operator that structures its application around the minimum requirements under the prior Lithuanian VASP regime will find that the Bank of Lithuania's current expectations – on governance, on ICT risk management, and on AML policy depth – have risen materially. The regime has not just been relabelled; it has been substantively upgraded.
For businesses with a global user base – an operator serving EU clients from a structure that also holds a licence in Singapore under the Payment Services Act, or in the UAE under the VARA regime, or in Hong Kong under the SFC VASP licensing regime – the Lithuanian CASP authorisation is one node in a multi-jurisdictional stack. The governance and AML policies must be coherent across all licences, because any NCA in any jurisdiction can examine the group's compliance posture. Operators we advise frequently discover that the weakest link in their compliance chain sits not in the licensing jurisdiction but in a market they passported into without local counsel review.
A Practical Illustration: Transition from Legacy Registration
In a recent licensing matter, a payments-oriented digital-asset operator with an existing Lithuanian VASP registration sought to continue EU operations as MiCA's transitional provisions approached their end. The operator had assumed its legacy registration provided a temporary safe harbour without further action. It did not. We reviewed the operator's existing governance documentation, identified the gaps against the MiCA CASP standard – primarily in the AML programme's Travel Rule procedures and in the capital allocation between regulated activities – and prepared a revised application file. The Bank of Lithuania accepted the completed file within the remaining transitional window, and the operator continued operations without a licensing gap. Timing was the decisive factor; a delay of one further quarter would have required a full cessation of EU-facing services while the application was pending.
What Should an Inbound Operator Assess Before Choosing Lithuania?
Lithuania's primary advantage for an inbound operator is its position as a credible, well-connected EU member state with a functioning CASP authorisation pathway and an active fintech community. The Bank of Lithuania has processed a significant volume of digital-asset applications and its staff are familiar with the business models. The jurisdiction is not the cheapest in the EU – substance requirements mean real cost – but it is not the most demanding for operational build-out either.
The relevant decision axes for an operator choosing a CASP jurisdiction in the EU are broadly as follows:
Profile A – Exchange or transfer service with EU-wide user base: Lithuania is a viable choice. The Bank of Lithuania's familiarity with exchange-model applications, combined with the passporting right, suits a business that needs to move quickly to serve the full EU market. The key constraint is banking; allow meaningful additional time and budget to secure payment infrastructure before or immediately after authorisation.
Profile B – Custody-only or asset management operator with institutional clients: Lithuania can accommodate this profile, but the capital expectations for custody and management activities are at the higher end of the CASP capital scale. An operator with a predominantly institutional, non-retail user base may find that the ADGM/FSRA regime in Abu Dhabi or the AFSA regime in the AIFC offers a comparably rigorous but more actively business-development-oriented supervisory posture.
Profile C – Token issuer seeking EU whitepaper clearance and subsequent service authorisation: A dual-track approach – whitepaper notification and CASP application running in parallel – is possible in Lithuania but requires careful sequencing of the Bank of Lithuania's workload management. Operators with complex token structures should obtain a pre-filing regulatory meeting before committing to Lithuania as the primary authorisation hub.
A common assumption operators bring to this analysis is that a single offshore licence – a BVI FSC registration, or a Cayman CIMA registration, or a legacy Lithuanian VASP certificate – is sufficient to serve EU clients commercially. It is not. MiCA applies on the basis of where the client is located, not where the operator is incorporated. An operator serving EU clients from an offshore structure without a CASP authorisation is operating unlawfully within the EU's regulated perimeter. The enforcement consequences – including withdrawal of access to EU payment rails – are not theoretical.
If a prior application stalled, a banking relationship was closed, or a legacy registration is approaching its transitional deadline, write to OBOLUS at info@oboluslaw.com for a direct structural assessment. We have seen the patterns that produce those outcomes and the routes that resolve them.
Related at OBOLUS
- Licensing and registration for digital-asset businesses – the full OBOLUS licensing practice across 70+ jurisdictions and licence types.
- Digital-asset custody licensing in Gibraltar – how Gibraltar's DLT framework applies to custody operators and how it compares to EU CASP custody authorisation.
- Token legal classification for established operators – determining whether a token is a financial instrument, ART, EMT or utility asset under MiCA and parallel regimes.
FAQ
How long does a crypto licence take to obtain?
Under MiCA, the Bank of Lithuania's formal assessment period begins when the application is deemed complete – not on the date of initial submission. The overall timeline from incorporation through to CASP authorisation varies by the complexity of the business model, the completeness of the application file, and the regulator's current workload. In our practice, operators who submit complete, well-prepared files typically move through the process materially faster than those who submit provisionally and respond reactively to information requests. Allow for a multi-month process; plan your operational launch timeline around the authorisation date, not the submission date.
Which jurisdiction is best for licensing my crypto business?
There is no single answer. The best jurisdiction for a given operator turns on the target user base, the activity scope, the banking infrastructure available, the capital the business can deploy, and the speed-to-market requirements. For EU-facing businesses, Lithuania offers a credible CASP path with passporting rights. For businesses targeting the Gulf, VARA in Dubai or the ADGM/FSRA in Abu Dhabi are the primary options. Singapore's MAS Payment Services Act applies to businesses targeting Southeast Asia or seeking a globally recognised licence. We assess these axes systematically before recommending a jurisdiction stack.
Do I need a separate custody licence?
Under MiCA, custody and administration of crypto-assets on behalf of clients is a distinct regulated activity. If your business model includes holding client assets – even as an ancillary service to an exchange or transfer function – you must declare that activity in your CASP application scope. The capital and organisational requirements for custody are set at a higher level than for some other CASP activities. Operating an exchange without the custody authorisation and then holding client assets creates a specific regulatory breach. The scope of your licence application must match the full perimeter of your actual business operations.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit alongside them. Digital assets are the entirety of our practice. We map the licence stack across operating, custody and payment layers before you commit – so your application reflects your actual business, not a version of it. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in EU and multi-hub CASP authorisation strategy, MiCA transition planning and cross-border licence stack design for digital-asset operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.