Key takeaways
- Lithuanian VASP registration ended 31 December 2025 — former registration no longer authorises MiCA-regulated crypto-asset services.
- CASP authorisation requires substantive assessment — not mere registration; governance, capital, compliance and operational resilience are tested.
- Capital requirements depend on service class — €50k–€150k minimum, plus one-quarter of fixed overheads if higher.
- Genuine Lithuanian substance is mandatory — registered office, place of effective management, EU-resident director, and credible governance.
- Timeline extends well beyond statutory periods — preparation, completeness review, substantive assessment, and responsiveness to regulator questions compound realistic duration.
A crypto company in Lithuania still holds evidence of its former VASP registration. Today, a banking partner asks: is it authorised as a CASP under MiCA?
Lithuania's transition period ended 31 December 2025. The former registration regime and current MiCA authorisation are not equivalent. A CASP application requires a credible programme of operations, clear governance, qualifying-holder information, prudential safeguards, ICT controls aligned with DORA, robust AML arrangements, and evidence the business will be genuinely directed and operated from within the EU.
The Bank of Lithuania, now competent authority for MiCA crypto-asset services, conducts substantive assessment before granting authorisation. This guide walks through the key requirements, application roadmap, common pitfalls, and practical project planning for businesses seeking CASP authorisation in Lithuania.
Do Crypto Businesses Need a CASP Licence in Lithuania?
Most businesses providing regulated crypto-asset services in or from Lithuania require MiCA CASP authorisation. A former VASP registration is not a substitute.
Certain already-authorised EU financial entities—credit institutions, investment firms, electronic money institutions, or market operators—may use MiCA Article 60 notification for eligible services instead of seeking CASP authorisation. Most crypto-native platforms and specialists require Article 62 CASP authorisation.
If your business provides custody, exchange, trading-platform operation, or other MiCA-regulated crypto-asset services, you need CASP authorisation. Having a former VASP registration does not answer this question in 2026.
Lithuania VASP Registration vs MiCA CASP Authorisation
| Dimension | Former VASP Framework | MiCA CASP Framework |
|---|---|---|
| Legal Status | Registration under former national virtual-asset framework | Authorisation under MiCA Article 62 |
| Regulatory Focus | Registration, AML/CFT, beneficial ownership | Governance, capital, operational resilience, client protection, passporting |
| Competent Authority | Register of Legal Entities; AML/CFT by FCIS/FNTT | Bank of Lithuania |
| Prudential Safeguards | Registration and AML-focused; no harmonised governance or operational-resilience framework | Mandatory permanent minimum capital, fixed-overheads test, financial controls, ICT resilience |
| Cross-Border Services | Not available | EU passporting available under Article 65 |
After 31 December 2025, former Lithuanian VASP registration no longer authorises provision of MiCA-regulated crypto-asset services. A firm either obtained CASP authorisation, uses Article 60 notification as an already-authorised entity, is winding down, or continues without authorisation—exposing itself to supervisory action.
Lithuania Presence and Substance Requirements
MiCA Article 59 requires:
- Registered office where the CASP carries out at least part of its services
- Place of effective management in the EU
- At least one EU-resident director
The Bank of Lithuania expects credible governance, clear decision-making, appropriate staffing, and operational capacity aligned with proposed service scope. An applicant relying on outsourcing must retain effective control and oversight. A physical Lithuanian office alone does not prove sufficient substance if key decisions are performed elsewhere.
Substance requirements are not a formality. The Bank assesses whether the business is genuinely directed and managed from the EU, decisions are made by competent persons with appropriate governance, and operational capacity matches the proposed service scope.
Article 60 Notification vs Article 62 Authorisation
For most crypto-native businesses, Article 62 CASP authorisation is the relevant route. Certain already-authorised EU financial entities may use Article 60 notification for eligible equivalent services:
- A credit institution might provide certain crypto-asset services within its existing scope
- An investment firm might provide equivalent services
- An electronic money institution might offer certain crypto services
However, permitted services depend on the entity's existing authorisation scope. Article 60 is not a general exemption; it is specific to certain already-regulated entities. Most crypto-specialised startups require Article 62 CASP authorisation.
CASP Application Requirements and Document Checklist
A CASP application covers multiple dimensions. Commission Delegated Regulation (EU) 2025/305 specifies detailed information requirements:
Corporate and Ownership Documents
- Incorporation records and legal entity structure
- Group structure and related-entity relationships
- Shareholder registers and ownership transparency
- Beneficial-ownership verification for all qualifying holders (≥10%)
- Source-of-funds documentation for capital and qualifying holders
Management and Governance Documents
- Management structure with clear roles and responsibilities
- CVs and regulatory history for all management and directors
- Fit-and-proper assessments demonstrating good repute and competence
- Governance policies covering decision-making and oversight
- Conflicts-of-interest procedures and management
Business and Financial Documents
- Programme of operations specifying all services and operational model
- Detailed service descriptions and boundaries
- Business plan and financial forecasts (typically 3-year)
- Capital calculations demonstrating minimum-capital compliance
- Revenue models and business viability
- Outsourcing contracts and service-level agreements
- Banking arrangements and client-fund settlement procedures
Compliance, AML and Operational Documents
- AML/CFT risk assessments and policies
- Customer due diligence and beneficial-ownership verification procedures
- Transaction monitoring and alert procedures
- Sanctions screening and high-risk-jurisdiction procedures
- Travel Rule documentation (Regulation (EU) 2023/1113)
- Complaints procedures and escalation protocols
- Record retention and audit arrangements
ICT, DORA and Outsourcing Documents
- ICT-risk assessments and information-security policies
- Business-continuity and disaster-recovery plans
- Incident-management procedures
- DORA compliance testing and readiness evidence
- Comprehensive outsourcing registers with contractual controls
- Third-party ICT-provider testing and oversight
Bank of Lithuania Assessment Process and Timeline
The Bank of Lithuania's formal assessment follows a structured sequence. Guidance on the assessment and expectations is available on the Bank's Markets in Crypto-Assets page.
- Acknowledgement: Within 5 working days, the Bank acknowledges receipt and assigns a reference number
- Completeness Review: Within 25 working days, the Bank assesses whether all required information is present
- Substantive Assessment: Within 40 working days of a complete application, the Bank conducts detailed assessment
- Information Requests: If gaps are identified, the Bank requests clarification, extending the timeline
- Regulator Questions: Complex applications receive detailed questions requiring substantive responses
- Authorisation or Refusal: The Bank issues a formal decision
- Cross-Border Notification: If authorised for passporting, the Bank notifies other EU Member States
Practical project timeline extends well beyond formal regulatory periods. Variables include business-model complexity, service count, ownership structure, outsourcing extent, ICT architecture, and regulator-question responsiveness. Distinguish preparation time (weeks to months), completeness review, formal assessment, and post-authorisation launch. No fixed approval date should be assumed.
Capital and Prudential Safeguards Under MiCA
Under MiCA Article 67, CASPs must maintain prudential safeguards at least equal to the higher of:
- Applicable permanent minimum capital for the service class (Annex IV), OR
- One quarter of previous year's fixed overheads
Minimum capital by service class:
- Class 1: €50,000 — Execution, placing, transfer, reception and transmission, advice, portfolio management
- Class 2: €125,000 — Adds custody, administration, exchange services
- Class 3: €150,000 — Adds operation of a trading platform
Multi-class applicants must satisfy the highest applicable capital requirement. Depositing minimum capital alone does not prove viability; the financial plan must support the operating model and justify the business case.
Governance, Management and Qualifying Holders
Management must satisfy MiCA fit-and-proper criteria. Qualifying holders (10%+ ownership or voting rights) require particular scrutiny; see our beneficial ownership verification guide for identification and disclosure standards.
Note: While our guide addresses Canadian frameworks, the underlying principles of beneficial-ownership identification, verification, and fit-and-proper assessment align with MiCA qualifying-holder requirements.
Management must satisfy MiCA fit-and-proper criteria:
- Good repute (no criminal conviction, regulatory sanction, or disqualification)
- Relevant knowledge and experience in crypto-asset services and relevant legislation
- Collective suitability—management together covers all necessary competencies
- Sufficient time commitment to the role
- Clear allocation of responsibilities and accountability
Qualifying holders—individuals or entities with 10% or more of capital or voting rights, or significant influence—must also satisfy fit-and-proper criteria. The Bank assesses:
- Good repute and financial soundness
- Source of funds and capital provenance
- Ownership transparency and no hidden control
- Influence and decision-making power
- Any money-laundering or terrorist-financing concerns
No absolute experience requirement is prescribed, but the Bank expects appropriate knowledge and demonstrable competence aligned with service scope.
AML/CFT, Sanctions and the Travel Rule
A CASP must implement robust AML/CFT frameworks aligned with money-laundering prevention obligations. Suspicious activity identification and escalation are critical; see our guide to suspicious transaction reporting for documentation standards and escalation procedures.
Core AML/CFT frameworks include:
- AML risk assessment and policies covering business model, customer types, jurisdictions and products
- Customer due diligence at on-boarding and ongoing monitoring
- Beneficial-ownership verification for corporate clients
- Transaction monitoring and alert procedures identifying suspicious patterns
- Blockchain analytics to trace transaction origins and destinations
- Suspicious-activity escalation and reporting procedures
- Sanctions screening covering OFAC and EU designations
- High-risk-jurisdiction procedures and enhanced measures
Travel Rule compliance is essential. Regulation (EU) 2023/1113 specifies that transfers of crypto-assets must include originator and beneficiary information (name, address, account identifier, transaction reference). Many applications delay due to incomplete Travel Rule documentation or inadequate transaction-monitoring architecture.
The Bank expects credible, operationalised AML procedures—not policies alone. Evidence of testing, staff training, and actual monitoring alerts demonstrates implementation.
DORA and ICT Requirements
CASPs fall within the EU digital-operational-resilience framework. Regulation (EU) 2022/2554 (DORA) requires operational resilience, ICT-risk governance, and incident management. Operational readiness mirrors FINTRAC-style compliance assessment; see our examination readiness checklist for comprehensive operational documentation standards.
DORA specifically requires:
- ICT-risk governance: Board and senior management oversight of ICT risks aligned with overall risk strategy
- Information-security controls: Policies and technical measures protecting confidentiality, integrity and availability
- Incident management: Procedures for detecting, reporting, investigating and remediating ICT incidents
- Business continuity and disaster recovery: Plans ensuring operational continuity in case of disruption
- Third-party ICT provider testing: Assessment and ongoing monitoring of outsourced ICT service providers
- Detailed outsourcing registers: Comprehensive documentation of all ICT outsourcing arrangements with contractual controls
DORA compliance demonstrates that the CASP can operate reliably and securely. Applications with weak or incomplete DORA documentation often face significant regulator questions.
Client Assets, Funds and Safeguarding
MiCA requires custody of clients' crypto-assets be subject to:
- Legal segregation: Clear legal title distinguishing client assets from CASP assets
- Operational segregation: Technical and procedural controls preventing commingling
- Position records: Detailed, accurate records of each client's holdings and transactions
- Access controls: Measures preventing loss or unauthorised access (private key management, multi-signature, vault procedures)
- Reconciliation: Regular reconciliation of recorded positions to actual holdings
A custody platform holding client private keys must have demonstrable security measures, clear operational procedures, and evidence that the CASP retains effective control and knowledge. The Bank expects detailed custody policies, technology architecture documentation, and testing evidence demonstrating security controls.
Electronic Money Tokens and Payment Services
From 2 March 2026, CASPs carrying out certain transactions involving electronic money tokens (EMTs) may require additional payment-services authorisation. This does not automatically apply to every CASP handling an EMT. Analysis depends on:
- Specific service provided (custody vs trading vs exchange)
- Contractual role and flow of funds
- Whether the CASP is acting as principal or agent
- Whether services constitute "payment services" under PSD2
Consult the Bank of Lithuania's current EMT statement before application. EMT/payment-services overlap is complex and jurisdiction-specific.
Common Reasons Applications Are Delayed
- ❌ Unclear service scope—services not clearly mapped to MiCA categories
- ❌ Generic policies copied from other businesses—not tailored to actual operations
- ❌ Weak Lithuanian or EU substance—management or decisions based outside EU
- ❌ Inconsistent ownership—conflicting information about qualifying holders or source of funds
- ❌ Unsupported financial forecasts—no evidence revenue projections are realistic
- ❌ Poor source-of-funds evidence—capital origin not clearly documented
- ❌ Excessive outsourcing without management oversight—control gaps and unclear accountability
- ❌ Incomplete DORA documentation—ICT risks and incident procedures not operationalised
- ❌ Weak custody or client-asset controls—safeguarding procedures not credible
- ❌ Conflicts between programme and technical architecture—written procedures don't match actual systems
- ❌ Management unable to explain business model credibly—inconsistent or vague responses
- ❌ Inconsistent information across documents—conflicting data raises credibility concerns
Lithuania CASP Application Readiness Checklist
- ☐ Services mapped to MiCA categories with clear boundaries
- ☐ Article 60 vs Article 62 pathway assessed and confirmed
- ☐ Lithuania confirmed as appropriate home Member State
- ☐ Legal entity established in Lithuania or another EU jurisdiction
- ☐ Registered office location documented and operational
- ☐ EU-resident director(s) identified with CVs and fit-and-proper evidence
- ☐ Ownership and qualifying holdings transparent with beneficial-owner identification
- ☐ Source of funds documented for all capital and qualifying holders
- ☐ Management suitability assessed with CV, experience and regulatory history
- ☐ Minimum capital identified and available (Class 1/2/3 requirement)
- ☐ Programme of operations complete and consistent with technical systems
- ☐ Financial forecasts supported with realistic revenue models and cost analysis
- ☐ AML/CFT framework operational with risk assessment, CDD, monitoring and reporting
- ☐ Travel Rule documentation specifying originator/beneficiary transfer procedures
- ☐ DORA controls prepared with ICT-risk governance and incident-management procedures
- ☐ Outsourcing arrangements mapped with contracts specifying controls and accountability
- ☐ Client-asset and safeguarding model documented with custody procedures and controls
- ☐ Application documents cross-checked for consistency and completeness
- ☐ Passporting strategy documented if cross-border services are planned
Final Takeaway
Lithuania's former VASP registration framework is no longer the authorisation route for regulated crypto-asset services. CASP authorisation under MiCA Article 62—or Article 60 notification for certain already-regulated entities—is now required. A successful application requires consistency between written policies and actual operating model.
Firms must assess service scope and readiness before submission, engage with the Bank of Lithuania early, and plan for a multi-month project extending beyond formal assessment periods. Capital, governance, AML/CFT, DORA and ICT compliance are assessed substantively. Generic documentation and weak substance are identified and cause delays.
The businesses that succeed are those that invest in genuine substance, operationalise compliance frameworks before application, and provide clear, consistent evidence of capability and control.
Frequently Asked Questions
Is a Lithuanian VASP licence still valid in 2026?
How do I obtain CASP authorisation in Lithuania?
What is the difference between a VASP and a CASP?
Does a CASP need a physical office in Lithuania?
How long does Lithuania CASP authorisation take?
How much capital does a Lithuanian CASP need?
Can a Lithuanian CASP operate across the EU?
Official MiCA Regulations and Guidance
- Bank of Lithuania — Markets in Crypto-Assets — Official CASP authorisation guidance and application portal
- EUR-Lex — Regulation (EU) 2023/1114 (MiCA) — Full text of Markets in Crypto-Assets Regulation
- EUR-Lex — Commission Delegated Regulation (EU) 2025/305 — Application requirements and detailed information specifications
- EUR-Lex — Regulation (EU) 2022/2554 (DORA) — Digital Operational Resilience Act requirements for CASPs
- EUR-Lex — Regulation (EU) 2023/1113 — Travel Rule and transfer of crypto-assets information requirements