EST · MMXXVI
Home/Jurisdictions/Lithuania/VASP licensing in Lithuania: Legal Requirements for Businesses
Licensing & Registration

VASP licensing in Lithuania: Legal Requirements for Businesses

Vasp licensing in Lithuania. Independent digital-asset law for exchanges, issuers and funds. Fixed-fee scope, end-to-end. Contact OBOLUS counsel today.

Operating a virtual asset service provider without a compliant licence in Lithuania – a jurisdiction that has moved from one of Europe's most accessible VASP (virtual asset service provider) registration regimes to full alignment with MiCA (the EU Markets in Crypto-Assets Regulation) – carries consequences that arrive fast: enforcement notices, suspended payment rails, and banking relationships withdrawn with little notice. The Bank of Lithuania supervises the transition directly, and the European Securities and Markets Authority (ESMA) sets the overarching standard that every EU operator must now meet. This page maps the regulated perimeter, the current application path, the cross-border interactions that most inbound businesses underestimate, and the moment at which outside counsel becomes necessary rather than optional.

What Activities Require a VASP Licence in Lithuania?

Any business offering exchange between virtual assets and fiat currency, exchange between virtual assets, custody of virtual assets on behalf of clients, or the transfer of virtual assets requires authorisation under the applicable Lithuanian legal provisions, now converging with the MiCA CASP (Crypto-Asset Service Provider) framework. Operating without that authorisation is not a grey area. The Bank of Lithuania has taken an active posture on unapproved operators, and the regulator receives disclosures from payment institutions and credit institutions that flag unlicensed counterparties. If your business onboards Lithuanian-resident clients, processes transactions through Lithuanian payment rails, or markets to EU users from a Lithuanian-registered entity, the licensing obligation applies.

The scope extends beyond the obvious exchange and custody activities. Transfer services, portfolio management of crypto assets, and the placement of crypto assets also fall within the regulated perimeter under the MiCA CASP construct. Businesses that began under the prior lighter-touch registration model must assess whether their current activity profile requires upgraded authorisation. In our practice, the most common gap we identify is a business that registered early – before the MiCA transition tightened requirements – and has since added services without revisiting its regulatory status.

Token issuers face a parallel analysis. Issuing an asset-referenced token (ART) or an e-money token (EMT) in or from Lithuania triggers distinct MiCA obligations, including whitepaper requirements and, for EMTs, a connection to an e-money authorisation. Issuing what MiCA calls "other crypto-assets" – utility tokens and similar instruments – requires a whitepaper notification without full CASP authorisation, though the distribution of those tokens may still engage a CASP if it is done through a platform. The substance of what the token confers governs its classification, not the label the issuer applies.

The Bank of Lithuania and ESMA represent the two levels of oversight every operator must factor into its structure from day one. National supervision handles day-to-day licensing and ongoing compliance; the ESMA layer sets the standards that cannot be varied at member-state level.

Related at OBOLUS

If your entity is already operating and you are uncertain whether your current registration covers your live activity, an urgent scoping review is the right first step. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options.

How Is MiCA Changing the Lithuanian VASP Regime?

Lithuania's historic appeal as a VASP registration hub rested on a relatively streamlined national registration process under the prior anti-money-laundering framework, which placed a lower burden on applicants than the full MiCA CASP authorisation now coming into force across the EU. That gap has closed. The MiCA regulation applies directly in Lithuania without the need for national transposition; the Bank of Lithuania is the designated national competent authority responsible for accepting CASP applications and enforcing the regime on a day-to-day basis, with ESMA coordinating consistency across member states.

For businesses that registered under the old model, the transition period is not indefinite. MiCA provides for a grandfathering window during which existing registered operators may continue to provide services, but that window is finite and the Bank of Lithuania is authorised to set shorter national transition limits. Operators that delay their CASP application risk finding that their grandfathering cover has expired before their new authorisation is granted. In our cross-border practice, we regularly advise businesses that treated the transition period as a planning pause rather than an execution window – and then had to rebuild under enforcement pressure.

The practical shift is significant. Where the prior registration required primarily AML/KYC procedures and a local presence, the CASP authorisation under MiCA demands a detailed programme of operations, governance documentation, prudential own-funds calculations (which vary by class of service provided), a fit-and-proper assessment of management and shareholders, cybersecurity and operational resilience policies, and a client-asset safeguarding framework. The regulator expects the application to demonstrate that the business has the substance to perform the regulated activities, not merely the intention.

One structural consequence matters enormously for businesses that built their EU strategy around a Lithuanian registration: the CASP passport. A CASP authorised in Lithuania may passport its services across the EU and EEA, providing services to clients in other member states without requiring a separate national authorisation in each. This is a material commercial advantage. It also means that the quality of the Lithuanian authorisation is scrutinised by host-state regulators across the bloc – a weakly documented licence becomes a liability rather than an asset when the business tries to activate the passport in Germany, France, or the Netherlands.

What Does the CASP Application Process in Lithuania Involve?

The CASP application to the Bank of Lithuania follows a structured dossier model: the regulator expects a complete submission before the review clock starts, and an incomplete submission restarts the timeline. The core elements of the application are consistent with the MiCA framework requirements and include the programme of operations, governance arrangements, the identity and fitness of key persons, financial resources documentation, operational and security policies, and the safeguarding model for client assets.

The programme of operations is not a high-level business plan. The Bank of Lithuania expects it to specify each service the applicant intends to provide, the technical systems that will support delivery, the markets and client types targeted, and the marketing approach. An application that describes services generically – "we will operate an exchange" – will not satisfy the requirements. The regulator reads the programme as the primary indicator of whether the applicant has genuinely stress-tested its own business model against the regulatory obligations.

Fit-and-proper assessments apply to directors, members of the management body, and qualifying shareholders. Each individual must supply a package of identity, professional background, and conduct documentation. Where shareholders are legal entities rather than individuals, the chain of ownership must be traced to the natural-person beneficial owners and those individuals must also satisfy the assessment. For businesses with complex structures – holding companies, VC investors, multi-jurisdictional ownership – this element alone can extend the preparation timeline materially.

The timeline from complete submission to decision varies by the complexity of the application and the regulator's workload. MiCA sets a maximum review period for competent authorities, but the practical experience across EU jurisdictions is that well-prepared, complete submissions with no follow-up queries from the regulator reach a decision faster than applications that require clarification rounds. A business that submits a dossier requiring two or three rounds of supplementary information should expect a materially longer path. In our practice, preparation quality is the single largest determinant of timeline.

Local presence in Lithuania is required. The regulator expects the management body to include persons with genuine decision-making authority located in or accessible to the jurisdiction. A letter-box entity with all management outside Lithuania does not satisfy the substance requirements of the MiCA regime. The precise form of the local presence – a branch, a subsidiary, a registered office with resident management – depends on the business model and the ownership structure.

What AML and Travel Rule Obligations Apply to CASPs in Lithuania?

Every CASP authorised in Lithuania operates within the EU's AML/CFT regime and is subject to the Travel Rule – the obligation, derived from the FATF Recommendations and implemented in EU law, to pass originator and beneficiary information with every qualifying virtual asset transfer. This is not optional and it is not limited to large transfers: the applicable threshold and de-minimis treatment are set by EU regulation and the Bank of Lithuania's supervisory expectations, and both the sending and receiving VASP must maintain compliant processes for every transfer that meets the threshold criteria.

In practice, Travel Rule compliance requires a technical solution. The CASP must be able to collect originator information before a transfer is sent, transmit that information to the receiving VASP in a format the receiving VASP can process, and receive and screen incoming information. Where the counterpart is an unhosted wallet – a wallet not held by a regulated VASP – additional due diligence obligations apply. Operators we advise frequently underestimate the integration cost and the policy complexity that unhosted wallet interaction introduces, particularly for businesses that serve both institutional clients and retail-adjacent users.

FATF Recommendation 15 and the EU's implementation of the Travel Rule apply regardless of the size of the business. A startup exchange with a small user base is subject to exactly the same obligations as an established platform. The Bank of Lithuania's AML supervision is active, and examination findings related to Travel Rule deficiencies are among the most common enforcement triggers we see across EU jurisdictions.

Beyond the Travel Rule, the AML programme requires customer due diligence, enhanced due diligence for higher-risk clients and transactions, transaction monitoring, suspicious activity reporting, and governance procedures that demonstrate management oversight. The CASP authorisation dossier must include the AML/CFT policies, and the Bank of Lithuania expects those policies to be operational – not draft – at the time of authorisation, not implemented only after approval.

How Do Tax and Banking Interact for a Lithuanian-Licensed VASP?

Licensing in Lithuania does not resolve the full compliance stack for an internationally active VASP. The entity's tax position, banking relationships, and the treatment of its user base across multiple EU and non-EU jurisdictions require a separate layer of analysis that often determines whether the Lithuanian structure is viable at all.

Lithuania offers a standard corporate tax regime. The tax treatment of digital-asset income – whether token-related revenues are recognized as trading income, whether crypto-to-crypto exchanges create taxable events at entity level, and whether VAT applies to exchange fees – depends on the specific facts of the business and the applicable Lithuanian and EU tax rules. Tax characterization of staking rewards, lending income, and token issuance proceeds each follows its own logic. Operators who assume that crypto revenues are taxed identically to traditional financial services revenues frequently encounter unexpected liability. We map this analysis alongside the licensing work.

Banking access is, in practical terms, a more acute constraint than the licence itself for many businesses. Lithuanian banks and payment institutions operate within the EU regulatory perimeter and are subject to their own AML obligations. A VASP, even a licensed one, is treated as a higher-risk customer by most credit institutions. The account opening process requires the business to demonstrate that its own AML programme is sound – in effect, the bank conducts a parallel due diligence on the same policies that the Bank of Lithuania has reviewed. We have seen licensed businesses lose their primary banking relationship because the bank's internal risk appetite changed after the licence was granted.

The cross-border dimension adds further complexity. A Lithuanian-authorised CASP passporting into other EU member states must consider whether host-state tax obligations arise – for example, whether a permanent establishment is created by the business activity in another member state, and whether local VAT registration is required. Outside the EU, where the CASP serves non-EU users or holds assets in non-EU custodians, the regulatory and tax interaction with those jurisdictions runs in parallel. In our cross-border practice, we regularly advise businesses on building the licence, banking, and tax stack as an integrated structure rather than addressing each layer in isolation.

If your structure spans multiple jurisdictions and you are working through the banking and tax implications alongside the licensing process, an integrated advisory mandate is the most efficient path. If a prior application stalled or an account was closed, a second review can surface the structural reason and the route back. Map your options.

Which Operator Profile Should Choose Lithuania, and When?

Lithuania remains a rational first EU licensing choice for specific business profiles, but it is not the right choice for every operator – and the decision requires a clear-eyed assessment of where the business sits today and where it intends to operate within three to five years.

Profile A – the EU-first exchange or custody business. A business whose primary market is EU retail or institutional clients, which requires the CASP passport to operate cross-border within the bloc, and which has the operational substance to support a MiCA-compliant authorisation, is well positioned to use Lithuania as its primary EU licensing hub. The Bank of Lithuania has developed genuine familiarity with crypto-business models through years of VASP registrations, and that institutional knowledge is a practical advantage in the application process. The key risk: the business must be prepared to invest in local substance and governance documentation that satisfies MiCA's higher bar.

Profile B – the non-EU operator establishing an EU presence. A business domiciled outside the EU – in Singapore, in the UAE, in the United States – that wants to passport EU services often considers Lithuania as a cost-effective entry point. This is a sound approach, provided the parent structure is compatible with the Bank of Lithuania's fit-and-proper expectations. Complex ownership chains, jurisdictions that carry higher FATF risk, or parent entities that are themselves unlicensed can create friction in the application. In our practice, the preparation phase for these structures is longer but the underlying thesis is sound: Lithuania offers a credible EU licensing base for non-EU groups with the right structure.

Profile C – the operator whose user base is primarily outside the EU. A business that already holds a strong non-EU licence – under VARA in Dubai, under the MAS Payment Services Act in Singapore, or under the SFC regime in Hong Kong – and whose active user base sits predominantly outside Europe may find that a Lithuanian CASP adds compliance cost without proportionate commercial return. The passport value is only realized if the passported activity generates EU revenue. For this profile, the decision turns on projected EU user growth and whether the cost of maintaining a MiCA-compliant Lithuanian entity is justified by the EU revenue opportunity.

Profile D – the token issuer. An issuer of ARTs or EMTs requires CASP authorisation in addition to the token-specific obligations; for utility tokens and similar instruments, only the whitepaper notification path is required unless the issuer is also providing a CASP service. Lithuanian counsel – and, where the distribution reaches other EU member states, allied counsel in those jurisdictions – should be engaged before the token structure is finalized, because the MiCA classification determines the full compliance obligation set.

A Worked Example: Restructuring Under MiCA Transition Pressure

In a recent licensing matter, a European payments group had operated under a Lithuanian VASP registration obtained in an earlier period when requirements were lighter. The business had since added a custody service and begun offering structured crypto-lending products. When MiCA implementation dates moved closer, the group's existing registration no longer covered its actual activity profile. We conducted an activity-mapping review, identified the gap between the registered scope and the live services, and structured a CASP application that correctly characterised each service and addressed the own-funds requirement for the combined activity set. The application was submitted in a single complete dossier; there was one round of clarification from the Bank of Lithuania and the authorisation was granted. The group then activated its EU passport into two additional member states without a separate application in either.

A Common Assumption About Lithuania Licensing

A common assumption among operators evaluating Lithuania is that the prior registration they obtained – or that a predecessor entity obtained – provides a sufficient basis to continue operating while MiCA is implemented. This assumption is wrong in the majority of cases. Grandfathering under MiCA is conditional: it applies only to operators who were legally providing services under the prior national regime before the MiCA application date, it does not automatically extend to services added after registration, and it does not survive if the operator fails to submit a CASP application within the applicable transition window. Treating the grandfathering period as an indefinite grace period is one of the most consistent errors we see in this jurisdiction.

A related assumption is that a single offshore registration is sufficient to serve EU clients. It is not. MiCA explicitly addresses reverse solicitation narrowly; a business that actively markets to EU residents, regardless of where the entity is incorporated, is operating within the EU regulatory perimeter. The Bank of Lithuania and other national competent authorities are authorised to take enforcement action against operators that rely on reverse-solicitation arguments to avoid authorisation while actively acquiring EU clients.

FAQ

How long does a crypto licence take to obtain?

Timeline varies materially by jurisdiction, application complexity, and the completeness of the submission. Under MiCA, competent authorities including the Bank of Lithuania operate within a maximum review period set by the regulation, but practical timelines depend on how many clarification rounds the regulator requires. A complete, well-prepared CASP application in Lithuania that generates no supplementary queries will reach a decision faster than an incomplete dossier. In our experience, preparation quality is the primary determinant. We advise clients to plan for the process as a multi-month exercise and to begin substance and governance documentation well before the filing date.

Which jurisdiction is best for licensing my crypto business?

There is no universally correct answer. The optimal jurisdiction depends on where your users are, which services you intend to provide, your ownership structure, your banking relationships, and your projected regulatory budget. Lithuania offers an EU passport under MiCA and an experienced regulator, which makes it a rational choice for EU-facing businesses. VARA in Dubai, MAS in Singapore, and the SFC regime in Hong Kong address different market profiles. A decision made without mapping the licence, tax, and banking stack in parallel frequently requires expensive restructuring later. We map that stack before you commit.

Do I need a separate custody licence?

Custody of virtual assets on behalf of clients is a regulated CASP activity under MiCA and requires explicit coverage in the CASP authorisation. It is not automatically included if the authorisation covers exchange or transfer services. Whether your current or planned authorisation covers custody depends on the specific services listed in your application and the authorisation decision. In some models – where a group entity provides custody for affiliates rather than for third-party clients – the regulatory analysis is more nuanced. We assess the custody perimeter as part of any full licensing review.

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, and funds on licensing across 70+ jurisdictions, including Lithuania and the full EU CASP perimeter under MiCA. We map the licence stack across operating, custody, and payment layers before you commit – and we identify gaps in existing structures before regulators do. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in EU CASP authorisations, MiCA transition planning, and inbound licensing structuring for non-EU operators entering European markets.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours