DeFi Security AllianceRequest an audit
Menu

DeFi regulation & security

DeFi regulation in Lithuania

Lietuvos bankas examines whether the applicant has a real, controlled business. Former VASP registration no longer provides the transition route used before 2026.

Sources checked
Published
Prepared by
DeFi Security Alliance

Scope: Lithuanian provider authorization, governance and launch evidence. This guide does not determine individual tax treatment or approve a particular business model.

Start with the current permission

Lietuvos bankas's licensing guidance distinguishes a CASP license from the Article 60 procedure available to specified existing financial institutions for eligible services. Match the actual service to the permission. An electronic money institution, for example, does not receive an unrestricted right to offer every crypto service through notification.

The bank's 31 December 2025 transition notice states that unlicensed VASPs lost the right to continue the relevant active service business from 1 January 2026. Treat the old registration and its transition as historical evidence. For a provider licensed elsewhere in the EU, verify the entity, authorized services and notification covering Lithuania.

Show who runs and funds the business

In its published expectations for prospective CASPs, Lietuvos bankas focuses on ownership, funding transparency, management competence and effective control of operations. It also addresses applicants that lack real activity while outsourcing most core and control functions. This is a supervisory expectation tied to the application assessment, not a separate DeFi certification scheme.

Prepare a factual responsibility map. For each important decision, identify the person who can approve it, the team that implements it and the record that demonstrates oversight. Check whether the people described in the business plan have the access and time needed to perform those duties.

MiCA Article 59 requires the relevant registered-office and effective-management arrangements. An address and an outsourced compliance manual alone do not demonstrate the operational arrangements described in an application.

Test the operating model before submission

The following DeFiSec worksheet tests consistency between the application and the operating business. It does not replace the bank's application documents.

Lithuania: governance and outsourcing readiness
Review areaSuggested evidencePractical check
Ownership and fundingOwnership chain with funding records and explanationsCan each material funding source be traced to the applicant?
Decision-makingDelegations, board records and named control ownersWho can stop an unsafe launch or supplier change?
OutsourcingService contracts, access rights and oversight recordsDoes the applicant retain the ability to challenge and replace suppliers?
ContinuityObserved recovery exercise and unresolved actionsCan the responsible team restore records and reconcile balances?
Permission scopeLicense or eligible notification mapped to product featuresDoes the permission cover every service exposed to customers?

A useful implementation step is to connect outsourced services to their legal contracts and internal owners. Pharos Production's DORA information-register guide for crypto providers describes this technical mapping. The legal duties come from DORA and the applicable supervisory requirements. A completed spreadsheet does not prove that oversight operates effectively.

Control the decision to launch

Separate the Article 63 completeness check from the assessment of a complete application. The EU procedure includes a 25-working-day completeness stage and a 40-working-day assessment stage, with specified requests and suspensions. Do not convert them into a guaranteed total licensing time.

Before activating a service, compare the final permission, onboarding disclosures and actual entity handling customer assets. Record any feature excluded from the initial scope. For a controlled DeFi interface, revisit the service analysis when custody, execution or administrative powers change. Use the EU guide to identify related regimes without assuming they apply to every protocol.

Continue your research

Sources and further reading

Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.

  1. MiCA — Regulation (EU) 2023/1114European Union ·
  2. DORA — Regulation (EU) 2022/2554European Union ·
  3. DORA Register of InformationPharos Production ·
  4. Licensing crypto-asset service providersLietuvos bankas ·
  5. Lithuanian crypto transition endsLietuvos bankas ·
  6. Expectations for prospective crypto-asset service providersLietuvos bankas ·

Publication record

First publication of this guide and its source-backed evidence map.

Report an outdated source