DeFi regulation & security
DeFi regulation in Lithuania
Lietuvos bankas examines whether the applicant has a real, controlled business. Former VASP registration no longer provides the transition route used before 2026.
- Sources checked
- Published
- Prepared by
- DeFi Security Alliance
Scope: Lithuanian provider authorization, governance and launch evidence. This guide does not determine individual tax treatment or approve a particular business model.
Start with the current permission
Lietuvos bankas's licensing guidance distinguishes a CASP license from the Article 60 procedure available to specified existing financial institutions for eligible services. Match the actual service to the permission. An electronic money institution, for example, does not receive an unrestricted right to offer every crypto service through notification.
The bank's 31 December 2025 transition notice states that unlicensed VASPs lost the right to continue the relevant active service business from 1 January 2026. Treat the old registration and its transition as historical evidence. For a provider licensed elsewhere in the EU, verify the entity, authorized services and notification covering Lithuania.
Show who runs and funds the business
In its published expectations for prospective CASPs, Lietuvos bankas focuses on ownership, funding transparency, management competence and effective control of operations. It also addresses applicants that lack real activity while outsourcing most core and control functions. This is a supervisory expectation tied to the application assessment, not a separate DeFi certification scheme.
Prepare a factual responsibility map. For each important decision, identify the person who can approve it, the team that implements it and the record that demonstrates oversight. Check whether the people described in the business plan have the access and time needed to perform those duties.
MiCA Article 59 requires the relevant registered-office and effective-management arrangements. An address and an outsourced compliance manual alone do not demonstrate the operational arrangements described in an application.
Test the operating model before submission
The following DeFiSec worksheet tests consistency between the application and the operating business. It does not replace the bank's application documents.
| Review area | Suggested evidence | Practical check |
|---|---|---|
| Ownership and funding | Ownership chain with funding records and explanations | Can each material funding source be traced to the applicant? |
| Decision-making | Delegations, board records and named control owners | Who can stop an unsafe launch or supplier change? |
| Outsourcing | Service contracts, access rights and oversight records | Does the applicant retain the ability to challenge and replace suppliers? |
| Continuity | Observed recovery exercise and unresolved actions | Can the responsible team restore records and reconcile balances? |
| Permission scope | License or eligible notification mapped to product features | Does the permission cover every service exposed to customers? |
A useful implementation step is to connect outsourced services to their legal contracts and internal owners. Pharos Production's DORA information-register guide for crypto providers describes this technical mapping. The legal duties come from DORA and the applicable supervisory requirements. A completed spreadsheet does not prove that oversight operates effectively.
Control the decision to launch
Separate the Article 63 completeness check from the assessment of a complete application. The EU procedure includes a 25-working-day completeness stage and a 40-working-day assessment stage, with specified requests and suspensions. Do not convert them into a guaranteed total licensing time.
Before activating a service, compare the final permission, onboarding disclosures and actual entity handling customer assets. Record any feature excluded from the initial scope. For a controlled DeFi interface, revisit the service analysis when custody, execution or administrative powers change. Use the EU guide to identify related regimes without assuming they apply to every protocol.
Continue your research
Sources and further reading
Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.
- MiCA — Regulation (EU) 2023/1114European Union ·
- DORA — Regulation (EU) 2022/2554European Union ·
- DORA Register of InformationPharos Production ·
- Licensing crypto-asset service providersLietuvos bankas ·
- Lithuanian crypto transition endsLietuvos bankas ·
- Expectations for prospective crypto-asset service providersLietuvos bankas ·