Worth underlining: notification isn't a general shortcut. It exists only for firms that already hold a different EU financial license and want to bolt crypto activity onto it, not for anyone hoping to skip the CASP file entirely.
What follows maps out CASP (MiCA) licensing in Lithuania as it actually plays out on the ground: which services a given authorization unlocks, what pushes the required capital figure higher or lower, and the practical mechanics behind company setup, management and physical-presence expectations, the application file itself, realistic process timelines, and where the fee and tax obligations land once the license is in hand.
How to Get a Crypto License in Lithuania Under the MiCA Regulation
Everything traces back to one instrument applying the same way in every member state: Regulation (EU) 2023/1114 on Markets in Crypto-Assets, better known as MiCA, and a firm has to demonstrate it clears that bar before it can get a crypto license in Lithuania. A single EU-wide text replacing 27 national regimes is the whole point of the design - a crypto business built once against MiCA doesn't need to be rebuilt country by country. The mechanics of that sit in Title V: how CASP authorization gets granted, what management has to look like, how client assets get kept safe, how large the prudential cushion has to be, and what ongoing supervision looks like once the license is live.
Reading MiCA as a one-off gate to clear rather than a standing operating standard is where a lot of first-time applicants misjudge the workload - the obligations in Title V don't end at approval, they define how the business has to run every day afterward.
National law picks up wherever MiCA hands off a detail for member states to settle themselves, and in Lithuania that's the Law of the Republic of Lithuania on Markets in Crypto-Assets. Regulation of crypto-asset service provider (CASP) activity in Lithuania rests on that statute for naming which bodies hold authority, spelling out how supervision and enforcement actually function, and fixing how liability gets assigned when something goes wrong.
A single rulebook doesn't cover a crypto firm operating in this market. MiCA itself governs corporate governance and how client interests get protected; Regulation (EU) 2022/2554, known as DORA, sets the bar for keeping digital systems resilient and managing ICT risk; and Regulation (EU) 2023/1113 dictates how originator and beneficiary details must travel with every crypto-asset transfer. Because all three regimes apply simultaneously, a MiCA crypto license in Lithuania is never just clearance to exchange or hold tokens - by the time a firm applies, it needs working cybersecurity controls, a functioning record-keeping system, and counterparty-screening already operational, not sketched out for a later phase.
Treating these as three separate compliance projects rather than one integrated program is a common early misstep - the same incident-response plan, for instance, has to satisfy DORA's resilience testing and the transfer-information rules at once, not two disconnected policies filed side by side.
A common assumption trips founders up early: that one regulator handles the whole file. It doesn't work that way in Vilnius. Authorization itself - reviewing the application, vetting the people behind it, deciding who actually gets to operate, and staying in the picture afterward to confirm the firm keeps meeting the bar it was licensed against - sits with Lietuvos bankas, the Bank of Lithuania. Everything to do with laundering risk sits somewhere else entirely, with the Financial Crime Investigation Service, known locally as FNTT, running its own ongoing watch independent of the licensing file. CASP regulation in Lithuania only clicks into place once that division is clear, since a company's internal controls have to satisfy both bodies on their own terms, not just whichever one issued the license in the first place.
A staffing consequence follows from that: sizing a compliance team purely against what the Bank of Lithuania's application checklist asks for is a common miscalculation, since an FNTT inspection later tests a different set of controls than the ones the licensing file was built to satisfy.
Not every crypto business needs full authorization, though. Article 60 of MiCA carves out a notification route for a specific list of existing financial institutions - credit institutions, investment firms, electronic money institutions, fund managers, operators of regulated markets, and a few other categories - none of whom have to go through licensing of crypto companies in Lithuania from scratch. The notification is due at least 40 working days before the activity starts, and what a firm can actually do under it is capped by the scope of its underlying financial license.
The cap tied to the underlying license is the detail firms in this category most often overlook - a payment institution that assumes its notification lets it offer the full CASP service menu usually finds out otherwise only once the regulator flags the mismatch. In practice, the fix is to map notified activities against the existing license scope before filing, not after the review starts; any activity that scope does not cover means abandoning the notification route and applying for full CASP authorization instead.
VASP Licensing in Lithuania After the Transition Period Ends
What used to pass for VASP licensing in Lithuania was, in practical terms, registration - operators exchanging virtual currency or holding crypto wallets on deposit got entered into the national AML monitoring system, and that was the extent of it. It never amounted to a full financial license, and it carried no right to passport services across the EU.
That gap between what a VASP entry looked like from the outside and what it actually verified is the single biggest source of confusion left over from the old regime - clients and counterparties who assumed VASP status meant a prudential check equivalent to a bank license were simply wrong, and that misunderstanding is part of why MiCA replaced the whole model rather than patching it.
Market participants got used to calling that status a VASP license in Lithuania, but the label overstated what it actually confirmed. No prudential, technological, or managerial review under MiCA standards ever happened; the registering authority simply never assessed the business model to anywhere near the depth the Bank of Lithuania applies today.
A surprising number of previously registered operators underestimated exactly this point - having traded legally for years under the old system created no presumption of readiness under the new one, and firms that started their MiCA file late, assuming the transition would be a formality, were the ones most likely to miss the cutoff.
The calendar did the enforcing here: past 1 January 2026, an old VASP registration in Lithuania no longer covers a company that keeps serving clients. Anyone still onboarding users, still holding crypto-assets on their behalf, or still running any regulated operation without a current authorization past that date is, in the Bank of Lithuania's own terms, simply operating unlawfully.
Replacing VASP status with CASP in Lithuania isn't a status upgrade so much as a fresh authorization, granted only after a full review against Title V of MiCA. Whatever paperwork a company held before doesn't shrink the document list this time around, and it certainly doesn't guarantee approval.
Firms that never made it to authorization had to wind operations down in an orderly sequence: cut off new client onboarding, return client funds, transfer or withdraw the crypto-assets held on clients' behalf, close out contracts still in force, and keep client and regulatory records rather than discarding them.
An orderly wind-down doesn't buy quiet time to reapply later, either - the very records it requires keeping are exactly what the Bank of Lithuania will ask to see if that firm resurfaces with a fresh application down the line.
Treating re-registering a crypto license in Lithuania as a paperwork swap in some registry is the wrong mental model entirely. It's a standalone licensing exercise built around the entire operating model, and a company has to prove - not just assert - that it can meet client obligations and keep risk under control on a continuing basis, not just at the moment of filing.
Firms that treated the old registry entry as sufficient evidence of legitimacy for banking and payment partners are finding those partners now ask for the CASP authorization specifically - a VASP history helps the conversation, but it doesn't substitute for the document itself.
Take a project built around exchanging tokens for cash: that puts it squarely in Class 2 territory, meaning a license for a crypto exchange operator in Lithuania is what's actually required. Beyond the authorization itself, the operator needs internal pricing rules, disclosed exchange rates, transaction monitoring, and safeguards protecting client funds - none of which an old exchange-operator registration ever covered.
CASP Licensing in Lithuania: Services and Capital Requirements
Ten distinct activity types fall within the scope of CASP licensing in Lithuania under MiCA, and how a firm's business model maps onto them is what actually decides the authorization category, the size of the prudential safeguard, and the contents the application file needs. A brokerage that only routes and executes client orders sits at one end of that spectrum; a venue that custodies assets or runs its own trading platform sits at the other, and everything gets classified by which functions it actually performs, not by how it markets itself.
Founders drafting the activity program before nailing down the business model in detail tend to describe a broader mix of services than they actually plan to launch with, which pulls the required capital and the review scope up along with it - naming the real starting scope, not the eventual one, keeps the first filing proportionate.
Whichever CASP services in Lithuania a firm chooses to offer ends up shaping its internal procedures, its staffing structure, and how its IT systems get designed. Custody work in particular carries its own weight: private-key protection, asset segregation, and separate position accounting all become mandatory the moment custody is on the menu.
Bolting custody onto a business that was never designed around it tends to cost more in rework than building for it from day one - retrofitting key-management and segregation controls into a live system is a materially bigger lift than specifying them at the architecture stage.
What Capital a CASP Actually Needs, Tier by Tier
CASP license classes in Lithuania build on each other rather than sit side by side as separate options - the second tier absorbs everything the first covers, and the third absorbs both earlier tiers on top of its own scope. Combine services that would normally sit in different tiers and it's the highest applicable capital figure that governs the whole authorization, never an average or a sum.
It's worth separating the marketing label from the legal question here - a firm can call itself an exchange or a broker on its homepage, but the class it actually needs comes from what it does with client assets, not from what it calls itself.
A team that starts on Class 1 and adds custody six months in isn't making a paperwork request so much as opening a second review - the extension gets assessed on largely the same footing as a first-time Class 2 application, capital increase included.
Article 67 of MiCA doesn't let a firm simply pick the lower number: capital for a crypto license in Lithuania is whichever is greater between the fixed minimum for the relevant tier and 25% of the previous year's fixed overhead costs. A brand-new business without a prior year to reference works from projections in its own activity program instead.
Budgeting to the fixed minimum and stopping there is a common miscalculation - run the 25%-of-overhead comparison forward a year or two, and a firm that scales staff and infrastructure quickly can find its real capital floor has moved well past the number it was originally authorized against.
The e-money token change is the kind of detail that gets missed in initial scoping, since it only bites once a firm is already live and starts adding payment-adjacent features that weren't part of the original application.
Getting a License for a Crypto Company in Lithuania: Presence and Management Requirements
A legal entity capable of genuinely running the business inside the country is where getting a license for a crypto company in Lithuania begins. The standard vehicles are a private limited liability company, Uzdaroji akcine bendrove (UAB), or a public limited company, Akcine bendrove (AB); most projects go with a UAB, though incorporating one is a formality that on its own says nothing about whether the company is actually ready to operate.
Picking the corporate form is the easy five minutes of this whole process - everything that follows it, the office, the hires, the paper trail, is where the actual work sits.
A registered office inside the country, and at least part of the stated services genuinely performed there, are baseline expectations under the requirements for a crypto company in Lithuania. Actual management has to be located within the EU, and the regulator will check exactly where decisions get made, where control functions sit, where records are kept, and how oversight of any outsourced contractor actually works.
Outsourcing the bulk of day-to-day operations to a contractor outside the EU while keeping only a token local presence is a structure the Bank of Lithuania has grown used to spotting - it doesn't automatically fail an application, but it invites a much closer look at where control genuinely sits.
Ruling out a nominal-presence setup is a precondition to get a CASP license in Lithuania at all: a registered address with no staff behind it, no real management process, and no technical infrastructure doesn't establish a genuine connection to the jurisdiction, however legitimate the paperwork looks.
Banks doing due diligence on a new client tend to ask the same substance questions the regulator does, which means a company that builds real presence for licensing purposes usually clears account opening faster too - the two checks overlap more than founders expect.
At least one director resident in the EU is a MiCA baseline, but requirements for CASP managers in Lithuania stop short of demanding that any specific director hold Lithuanian residency in particular.
Management-body members get assessed against a fairly broad set of criteria: business reputation, education and professional background, hands-on experience in finance, technology, law, or crypto-assets, whether they can actually give the role enough time, freedom from unresolved conflicts of interest, and how the leadership team functions as a collective, not just as individuals.
That last point about the team functioning as a collective is easy to miss - the regulator isn't just scoring individuals against a checklist, it's asking whether the specific mix of people in the room can actually run this particular business together.
None of those criteria is usually disqualifying on its own - what tends to sink a submission is a weak pattern across two or three of them at once, which is why a strong file addresses the shakier points directly rather than hoping the regulator skips past them.
A flat three-year track-record rule for every director doesn't exist in the legislation. Licensing a crypto company in Lithuania runs on a case-by-case read of each person's actual functions and experience, with the regulator weighing a candidate's qualifications against the scale of the business, the services chosen, and the risk profile involved.
This case-by-case standard cuts both ways - it gives a genuinely experienced but formally junior candidate a real shot, but it also means a polished CV with no crypto-relevant substance behind it convinces the reviewer far less than founders sometimes expect.
AML/CFT, compliance, risk management, information security, complaint-handling, and outsourcing oversight all need to be covered internally, though CASP licensing in Lithuania doesn't force a company into a dedicated headcount line for each function separately.
How many people that takes tracks the volume and complexity of the business itself - a lean Class 1 operation staffs nothing like a trading platform serving clients across several member states.
Registering a crypto company in Lithuania brings scrutiny of anyone holding a qualifying stake of 10% or more into the picture too. The Bank of Lithuania digs into direct and indirect ownership structure, ultimate beneficial owners, shareholder reputation, and financial standing, and a layered ownership chain needs a coherent economic rationale behind it, not just a diagram that technically adds up.
Investor structures built purely for tax efficiency in an unrelated context tend to draw the most questions here, since a chain that made sense for a different deal rarely reads as coherent when the regulator asks why it exists.
Contact our specialists
Documents for Obtaining a Crypto License in Lithuania
Internal policies and procedures get pulled into one coherent operating model in the documents for a crypto license in Lithuania. The application itself goes in on the form set by EU regulatory acts, alongside the specific information Article 62 of MiCA requires.
The corporate block is where a company starts when it moves to file an application for a CASP license in Lithuania: articles of association, founding documents, an extract from the Register of Legal Entities, and both the registered and actual addresses. Disclosure extends further, too, covering the corporate group, related entities, shareholders, ultimate beneficial owners, and any close ties to other persons.
None of this corporate detail is decorative - the same group structure disclosed here gets cross-checked later against the funding-source evidence and the shareholder questionnaires, so an inconsistency introduced at this stage tends to resurface as a question much further into the review.
Groups that grew through several jurisdictions tend to underestimate this part - a clean ownership chart on paper can still take weeks to document once every related entity, historic shareholder, and cross-border transfer has to be traced and evidenced.
An activity program spanning at least three years sits at the core of the document package for CASP in Lithuania, describing every requested service, the crypto-asset types involved, target clients, geography, and how clients will actually be acquired. On the financial side, revenue and expense projections, expected user numbers, transaction volumes, and the size of the prudential safeguard all need to be spelled out.
The three-year horizon forces a discipline most early-stage teams haven't done yet - projecting user numbers and transaction volumes that far out means committing to assumptions about growth that a one-year plan lets a founder leave vague.
A baseline scenario sits alongside an adverse one in the filing, together with the fee and commission model, how cross-border activity will be handled, a clear line between in-house and outsourced functions, planned banking, payment, and custodial relationships, and where the funding for the business is actually coming from.
The adverse scenario is where a lot of first drafts fall flat - reviewers can tell quickly when it's a token pessimistic tweak of the baseline numbers rather than a genuine stress case built around what would actually go wrong.
Separate questionnaires for managers, key staff, and holders of qualifying stakes are unavoidable when applying for a crypto license in Lithuania - each one arrives with a CV, diplomas, evidence of professional experience, a record of other positions held, and a conflict-of-interest declaration.
Gathering these questionnaires early, well before the rest of the file is ready, tends to save the most time overall - chasing a busy board member for a CV and diplomas at the last minute is a recurring bottleneck that has nothing to do with the substance of the application.
Documents for licensing a crypto company in Lithuania have to trace where shareholders' capital and personal wealth actually came from, with banking records, contracts, tax filings, and other supporting material laid out to show the funding is legitimate.
Wealth built up over a career in an unrelated industry is usually the easiest source-of-funds story to document; wealth that moved through several personal holding companies before landing in the applicant is the one that eats the most review time, simply because each hop needs its own paper trail.
On the AML/CFT side, a company puts together a corporate risk assessment, identification rules for clients and beneficial owners, screening for politically exposed persons, sanctions screening, and ongoing transaction monitoring.
A generic template bought off the shelf rarely survives contact with this section - the risk assessment has to actually reflect the firm's real client base and transaction patterns, not a boilerplate list of risks copied from an unrelated business model.
Client protection gets its own block, covering segregation of client funds and crypto-assets, separate accounting for client positions, private-key management, rules governing hot and cold wallets, balance reconciliation, and how assets get returned or handed to a third-party custodian if that becomes necessary.
Reviewers tend to read this block as a single narrative rather than a checklist - a custody policy that reads well on its own but doesn't actually match the wallet architecture described elsewhere in the file is one of the more common reasons a first submission comes back with questions.
Requirements for a crypto company during licensing in Lithuania reach into digital operational resilience too: system architecture, access segregation, logging, backup procedures, and recovery after failures all belong in the application.
Founders building the tech stack often treat this documentation as an afterthought once the systems are running, when in practice it's easier to write a resilience file that matches the architecture if the two get built side by side rather than one after the other.
CASP authorization in Lithuania calls for policies on risk management, conflicts of interest, complaints, outsourcing, and marketing materials as well. Every service needs its own rules for order execution, pricing, and client interaction, and the wind-down plan on file has to address asset return, contract termination, and record retention.
A wind-down plan drafted purely to satisfy the filing checklist, without ever being tested against what an actual closure would look like, is one of the more common weak points reviewers flag - it tends to read as generic rather than built around the firm's real client base.
The Process of Obtaining a Crypto License in Lithuania: Stages, Timelines, and Fees
Long before the official form gets filed, the process of obtaining a crypto license in Lithuania is already underway - a company has to classify its operations correctly, build out corporate infrastructure, and put the necessary systems in place first.
The regulatory perimeter gets defined first: the crypto-asset types involved, what the services actually consist of, and the expected CASP class, alongside a separate check on whether the tokens trigger financial-instruments legislation or whether payment services arise from working with e-money tokens.
Getting this classification wrong at the outset is expensive precisely because it's invisible early on - a token quietly treated as a plain crypto-asset when it actually functions as a financial instrument doesn't surface as a problem until the file is already deep into review.
Corporate infrastructure comes together next - registering a UAB or AB, building a transparent ownership structure, identifying the funding source, appointing management, setting up an office, hiring staff, and getting IT systems running.
Hiring tends to be the long pole in this part of the timeline, not the paperwork - a qualified AML function or compliance hire in Lithuania can take longer to land than the office lease and the IT build combined.
Then comes preparing and filing: the prescribed form gets completed, a three-year business plan gets drafted, and internal policies get built out. A MiCA license for a crypto company in Lithuania is issued against current information, which is exactly why any change to structure, management, or services has to reach the regulator without undue delay, not at the next renewal.
That duty to keep the regulator current outlasts the application itself - a management change made two years after authorization still has to be reported the same way a change discovered mid-review would be, and treating post-approval updates as optional is a recurring source of compliance findings.
A completeness check follows: the Bank of Lithuania confirms receipt within 5 working days, then has 25 working days to verify the information required under Article 62 of MiCA is actually present. Missing documentation gets a deadline for supplementing it; a package that stays incomplete can be handed back without ever reaching a substantive review.
This is the stage where a rushed filing gets punished hardest - a file that looks complete on submission but is missing one supporting schedule loses weeks to a supplementation cycle that a slower, more careful initial build would have avoided entirely.
Once a filing is deemed complete, the substantive review starts - business model, management, shareholders, capital, AML/CFT arrangements, IT systems, and outsourcing all get assessed. Review of a CASP application in Lithuania runs up to 40 working days, and no later than day twenty the Bank of Lithuania can request more information, which pauses the clock for up to 20 working days until a response lands.
A single information request rarely derails a well-prepared file, but a second or third round on the same topic usually signals that the original answer didn't actually address what the reviewer was asking - worth catching internally before the response goes back rather than after.
The resulting decision spells out exactly which services a company may provide. Obtaining a CASP license in Lithuania doesn't come with room to informally add exchange, custody, or platform management later if those weren't part of the original grant; the applicant hears the outcome within 5 working days of the decision.
Reading the decision letter as a formality once it arrives is a mistake worth avoiding - it's the actual scope document a firm has to operate inside, and a service quietly added beyond what it lists is unauthorized activity regardless of how closely related it looks to what was originally granted.
Passporting a CASP license in Lithuania runs through a notification the Bank of Lithuania sends naming the countries, services, and planned start date. Once host-state regulators have that information, the company can serve clients elsewhere in the EU without needing a separate CASP license in each country.
Naming every country a firm might plausibly enter someday, rather than the ones it actually plans to serve in the near term, doesn't buy flexibility - it just adds notification overhead for markets that may never see a client.
Adding 25 and 40 working days together doesn't get you the real timeline for obtaining a crypto license in Lithuania - incorporation, hiring, building systems, and preparing documents all have to happen before filing even starts. Four to seven months is a reasonable planning figure, but it's a guide, not a commitment the Bank of Lithuania has made.
The state fee for a crypto license follows whatever schedule is in force on the date of application. Treating 2,425 euros as a fixed number without checking the current text of Government Resolution No. 1458 on state fees is a mistake worth avoiding.
The fee itself is a rounding error against the total cost of getting authorized, but it's worth double-checking against the current resolution anyway - a stale figure quoted in a budget rarely causes a real problem, whereas a stale figure quoted in the application paperwork can.
Taxation of a Crypto Company Holding a CASP License in Lithuania
Holding a CASP authorization buys a company nothing on the tax side: taxation of a crypto company in Lithuania follows the exact same framework any other Lithuanian legal entity answers to, built on the Law on Corporate Income Tax, the Law on Value Added Tax, and ordinary accounting rules. A license from the Bank of Lithuania and a tax obligation to the state are two entirely separate relationships, and nothing about the first one softens the second.
From 2026, corporate income tax in Lithuania for a crypto company is charged at a standard 17% on taxable profit, with turnover and the size of the licensed capital sitting outside the calculation entirely. Whatever comes in as service fees, spreads earned on exchange activity, custody remuneration, income from transfers, advisory fees, or portfolio-management income all feeds into that same taxable-profit figure.
Founders coming from jurisdictions that tax turnover or gross transaction volume sometimes carry that assumption into Lithuania and misbudget as a result - here it's profit, after allowable costs, that the rate actually bites on.
Main Tax Rates in Lithuania
It's worth treating this as a planning table rather than background reading - which rate a given CASP actually pays depends on choices made well before the tax year closes, not on the licence class alone.
The default for Lithuanian companies and permanent establishments sits at 17% of taxable profit. A company can instead pay 7% if its income for the period stays under 300,000 euros and it clears the related-party exclusions, and a qualifying new small company can owe nothing at all across its first two tax periods. Taxable supplies are subject to a standard 21% VAT unless a specific exemption or a special rate applies - the law carves out 12%, 5%, and 0% for named categories only.
Crypto status itself buys nothing here - taxes for CASP in Lithuania drop only because the general small-business criteria happen to be met. The 7% rate opens up once income stays under 300,000 euros and the company clears the related-organization restrictions; as of 2026, the headcount cap that used to gate this regime has been removed.
Dropping the headcount cap widens who qualifies more than most founders realize - a CASP that scaled its compliance and support staff well past what a small business would typically employ can still land the reduced rate today, provided the income line and the related-organization test are met.
Qualifying for the zero rate takes more than just being new and small, though. Every participant has to be a natural person, and income can't cross 300,000 euros in either of the first two periods; on top of that, the company has to stay put for three straight periods running, with no suspension, no liquidation, no reorganization, and no shares changing hands to someone new. Bring in a corporate shareholder at any point along the way and the whole break disappears.
A funding round that brings in a corporate investor is the single most common way this relief gets lost in practice - founders planning to raise institutional money in year two should treat the zero rate as a temporary window, not a baseline they can count on indefinitely.
One flat rule doesn't cover every service when it comes to VAT on cryptocurrency in Lithuania: 21% is the default, while the 12%, 5%, and 0% special rates apply only where the law specifically names the category. Exchanging crypto-assets, custody, advisory work, technical services, and portfolio management each need their own separate classification rather than one blanket treatment.
Applying one VAT treatment across a firm's entire service mix because the flagship product qualifies for a special rate is a shortcut that doesn't hold up under review - each revenue line needs its own classification, and mixing them tends to surface as an error at audit rather than at filing.
The practical upshot for a growing CASP is that tax planning and licensing strategy end up pulling in the same direction: staying under the 300,000 euro income line to keep the reduced rate can mean deliberately sequencing which services get added and when, rather than launching the full Class 3 scope on day one.
At least one EU-resident director is what MiCA actually requires. To apply for a license for a crypto company in Lithuania, the applicant also has to show that management is accessible and genuinely in control, but no rule explicitly ties that to a specific director's Lithuanian residency.
Taken together, the licensing file, the capital tier, and the tax position aren't three separate decisions - they get made in relation to each other, and changing one late in the process usually means revisiting at least one of the other two.
Once the notification procedure is complete, a CASP can offer the services its authorization covers in other EU states. Passporting doesn't stretch to cover operations outside the Bank of Lithuania's decision, and it's no substitute for related payment or investment authorizations a company might separately need.
It's worth planning the target-market list before filing rather than after - adding a new EU country later is a notification, but adding a service that was never part of the original authorization means going back through a fuller review.