MiCA Compliance Software · Vilnius · Lithuania
MiCA Compliance
Lighthouse RegTech is a MiCA compliance software firm based in Vilnius, Lithuania, that guides crypto-asset service providers through CASP authorization, licensing readiness and supervisory engagement across the European Union. Founded in 2019, it has guided 14 CASP authorizations to completion across 9 EU jurisdictions with a 118-day median timeline and zero dossiers rejected.
From gap analysis to NCA submission, we build and deliver the complete CASP authorization dossier so your team focuses on the business, not the paperwork.
Full Dossier Build, done for you EUR 74,000 Typical market range: EUR 19,900 fixed fee for licensing paperwork alone (Adam Smith, Lithuania). Ours also covers full dossier construction, NCA submission and supervisory management.
At a Glance
- Who we are: Lighthouse RegTech UAB · Vilnius, Lithuania · founded 2019
- What we do: MiCA Compliance CASP authorization software and licensing readiness for EU crypto-asset service providers
- Track record: 14 CASP authorizations guided · 9 EU jurisdictions · 118-day median timeline · 0 dossiers rejected
- Certifications: ISO 27001 (cert LT-27001-4471, TUV Rheinland) · SOC 2 Type II
- Delivery model: Fixed-scope Readiness Assessment, full Dossier Build or monthly Sustain Retainer
- Price range: EUR 28,000 to EUR 74,000 fixed-scope · EUR 9,500/month ongoing
What We Build
CASP Authorization and MiCA Compliance Capabilities
Lighthouse RegTech builds six MiCA compliance capabilities for EU crypto-asset service providers: readiness gap analysis, dossier assembly and submission, supervisory communication management, ongoing compliance monitoring, EMT and ART issuer support plus AML and Travel Rule implementation. Each is delivered as a fixed scope under Regulation (EU) 2023/1114 (MiCA).
Readiness Gap Analysis
A structured audit of your current legal entity, governance, AML/KYC controls and technical infrastructure against MiCA Compliance authorization requirements. Outputs a prioritized remediation register with owner assignments and deadline milestones.
- Articles 62-76 MiCA requirements mapping
- Governance and management body review
- AML/KYC policy gap scoring
- ICT/DORA readiness check
From EUR 28,000
Request Gap AnalysisDossier Assembly and Submission
We construct the complete CASP authorization dossier - programme of operations, business plan, governance framework, risk management policies and capital adequacy evidence - then manage the NCA submission and respond to supervisory queries on your behalf.
- Programme of operations document
- Governance and internal control framework
- Prudential capital computation
- AML/CFT policies and procedures
From EUR 74,000
Discuss Dossier BuildSupervisory Communication Management
Direct supervisory relationship management with national competent authorities. Our team - led by a former Bank of Lithuania supervisor - handles all NCA correspondence, clarification responses and follow-up meetings so your dossier stays on track.
- NCA query response drafting
- Completeness-check remediation
- Pre-submission NCA meetings
- Post-authorization follow-up
Included in Full Dossier Build
Ask About Supervisory SupportOngoing Compliance Monitoring
Post-authorization, CASPs must maintain continuous MiCA Compliance obligations: supervisory reporting, material change notifications, annual AML review and client-asset segregation attestation. Our Sustain Retainer covers all of these on a monthly basis.
- Periodic supervisory reporting
- Material change notification management
- Annual AML/KYC policy review
- Client-asset segregation audit support
EUR 9,500 per month
Explore Sustain RetainerEMT and ART Issuer Support
For e-money token and asset-referenced token issuers, Lighthouse RegTech handles the specialized MiCA Compliance requirements under Titles II and III: white paper review, reserve attestation workflow setup and Article 17-19 disclosure obligations.
- Crypto-asset white paper review
- Reserve attestation workflow
- Title II/III disclosure mapping
- EMT/ART authorization pathway
From EUR 18,000
Scope EMT/ART SupportAML and Travel Rule Implementation
CASPs must implement robust AML/CFT programs and comply with the EU Transfer of Funds Regulation Travel Rule. We integrate leading blockchain analytics platforms and Travel Rule messaging protocols into your compliance stack.
- Blockchain analytics integration (Chainalysis, Elliptic, TRM Labs)
- Travel Rule protocol setup (TRP, OpenVASP, Notabene)
- Transaction monitoring rule-set configuration
- Suspicious transaction reporting workflows
From EUR 9,000
Configure AML StackIndustries We Serve
What a Gap Analysis Changes
A typical Lighthouse RegTech gap analysis maps four categories, governance, AML/KYC, ICT and DORA readiness and prudential capital adequacy, then tracks each one through to a closed remediation item before the dossier goes to the NCA.
How We Work
The Lighthouse Authorization Pathway
Every CASP authorization at Lighthouse RegTech runs through five phases: scoping and jurisdiction selection, MiCA gap analysis, dossier construction, NCA submission with supervisory engagement, then post-authorization maintenance. The pathway was built from 14 completed dossiers across nine EU jurisdictions, where the median time from submission to decision is 118 days.
Competent authorities shall, within 25 working days of receipt of an application under Article 62(1), assess whether that application is complete
That completeness window is the reason phase 03 below runs to a document-by-document internal review before anything reaches the NCA. A dossier that fails the completeness check restarts the clock rather than continuing it, which is what turns a four-month authorization into a nine-month one.
Scoping and Jurisdiction Selection
We analyse your service scope, corporate structure and target markets to recommend the optimal EU jurisdiction for CASP authorization. Lithuania, Germany, the Netherlands and Malta each offer different NCA timelines and supervisory postures. We match you to the right authority.
MiCA Compliance Gap Analysis
A line-by-line assessment of your current posture against Articles 62-76 MiCA Compliance requirements. We score each requirement (met / partial / gap) and produce a remediation register with named owners and estimated effort, so no requirement surprises you at submission.
Dossier Construction
Our compliance engineers build every document in the dossier: programme of operations, governance framework, risk management policies, AML/CFT procedures, ICT risk assessment and prudential capital computation. Each document is internally reviewed for NCA-readiness before handover.
NCA Submission and Supervisory Engagement
We submit the dossier to the NCA and manage all supervisory correspondence. Dr. Kazlauskaite and our senior compliance team respond to NCA queries within 24 hours, drawing on direct supervisory experience from the Bank of Lithuania to anticipate regulator concerns before they become completeness-check failures.
Post-Authorization Compliance Maintenance
Authorization is not the finish line - it is the starting gate. Your MiCA Compliance obligations continue: supervisory reporting, material change notifications, periodic AML reviews and DORA operational resilience testing. Our Sustain Retainer keeps your obligations current from month one.
Engagement Models
Fixed-Scope Readiness
A defined deliverable: gap analysis report with remediation register. Ideal for CASPs in early planning who need to understand their distance from authorization.
EUR 28,000
Full Dossier Build
End-to-end: gap analysis, full dossier construction, NCA submission and supervisory engagement through to authorization decision. Fixed price, no variable billing.
EUR 74,000
Sustain Retainer
Monthly compliance maintenance after authorization: supervisory reporting, policy updates, NCA correspondence and annual AML review. Cancel with 30 days' notice.
EUR 9,500/month
Compliance Stack
Technology Behind Every Authorization
The Lighthouse RegTech compliance stack pairs a proprietary dossier workflow engine and MiCA rules library with established third-party tooling: Chainalysis, Elliptic and TRM Labs for blockchain analytics, Sumsub and ComplyAdvantage for KYC and KYB, TRP, OpenVASP and Notabene for Travel Rule messaging. Every deliverable stays traceable and NCA-ready.
Rules and Workflow Engines
Blockchain Analytics Integrations
KYC and KYB Providers
Travel Rule Protocols
Reporting and Evidence Formats
Infrastructure
Client Results
MiCA Compliance Authorizations We Have Guided
Lighthouse RegTech has guided 14 CASP authorizations to completion across nine EU jurisdictions with zero dossiers rejected. Three engagements show the range: BalticTrade Exchange authorized in 94 days by the Bank of Lithuania, Nexum Brokers dual-authorized by BaFin in 131 days and NordVault authorized in 107 days from incorporation.
Baltic Exchange · Lithuania
BalticTrade Exchange
- Challenge
- A Vilnius-based spot and derivatives exchange needed to convert its existing VASP registration to a full MiCA CASP authorization within 18 months of the transitional period opening.
- What We Did
- Lighthouse RegTech delivered a complete gap analysis in 12 days, constructed the governance framework and AML/CFT policies, integrated Chainalysis for transaction monitoring and managed the Bank of Lithuania submission.
- Result
- CASP authorization received in 94 days, 24 days inside our median timeline, with zero dossiers rejected and zero NCA completeness-check failures. First Lithuanian crypto exchange to receive MiCA Compliance authorization under the new regime.
OTC Broker · Germany
Nexum Brokers GmbH
- Challenge
- A Frankfurt OTC desk with existing BaFin crypto-custody registration sought a dual MiCA authorization (custody plus execution of orders) under BaFin as their NCA. They had no in-house MiCA Compliance expertise.
- What We Did
- We designed a dual-service authorization structure, constructed the expanded governance framework to cover both custody and execution obligations under Articles 70 and 75 MiCA, and ran all BaFin correspondence in German and English through our bilingual compliance team.
- Result
- Dual authorization received in 131 days. BaFin issued no completeness-check requests. Nexum Brokers GmbH became one of the first dual-authorized CASPs in Germany under MiCA.
Wallet Provider · Nordic Region
NordVault
- Challenge
- A Swedish non-custodial wallet provider expanding into custody services needed to establish an EU legal entity and obtain MiCA CASP authorization before launching custody in six EU markets.
- What We Did
- Lighthouse RegTech advised on entity incorporation in Lithuania (optimal NCA posture and timeline), built the custody-specific MiCA compliance dossier including client-asset segregation policies, integrated Elliptic for transaction screening and set up the Notabene Travel Rule messaging layer.
- Result
- Authorization received in 107 days from incorporation. NordVault launched custody services across six EU markets within 5 months of engagement start. Travel Rule compliance operational from day one of custody launch.
Trust and Security
Security and Regulatory Posture of Lighthouse RegTech
Lighthouse RegTech holds ISO/IEC 27001:2022 certificate LT-27001-4471, issued by TUV Rheinland, alongside a SOC 2 Type II report covering the Security, Availability and Confidentiality criteria. Client authorization materials sit in an EU-hosted document vault, with zero client data incidents recorded since the firm was founded in 2019.
ISO/IEC 27001:2022
LT-27001-4471
Issued by TUV Rheinland ·
Confirms an information security management system covering the MiCA compliance platform and dossier management operations.
SOC 2 Type II
LRT-SOC-2026-Q2
Annual audit · Observation period 2025-Q3 through 2026-Q2
Confirms controls across the Security, Availability and Confidentiality trust service criteria. Full report available on request under NDA.
Other Standards We Hold
- GDPR - All personal data processed under GDPR as a data processor · DPA template provided at engagement start
- DORA-aligned - ICT risk management and operational resilience controls aligned with Regulation (EU) 2022/2554 requirements
Regulatory Frameworks We Cover
- MiCA - Regulation (EU) 2023/1114 - primary CASP authorization framework
- AMLR - EU Anti-Money Laundering Regulation - AML/CFT program requirements for CASPs
- Travel Rule - EU Transfer of Funds Regulation - originator/beneficiary information for crypto transfers
- DORA - Regulation (EU) 2022/2554 - ICT risk and operational resilience for CASPs
- AML/KYC - Know Your Customer and Anti-Money Laundering program design
Security Track Record
Regulatory Capital Context
The figures below are official MiCA, EMD2 and AFM regulatory requirements, not Lighthouse RegTech service prices. They are shown for trust context only.
| Figure | Regulatory requirement | Source |
|---|---|---|
| CASP minimum capital, Class 1 | EUR 50,000 | MiCA Annex IV |
| CASP minimum capital, Class 2 | EUR 125,000 | MiCA Annex IV |
| CASP minimum capital, Class 3 | EUR 150,000 | MiCA Annex IV |
| ART issuer own funds (floor) | EUR 350,000 or more | MiCA Article 35(1) |
| EMT issuer capital (via EMI licence) | EUR 350,000 or more | MiCA Article 48 and EMD2 Article 4 |
| NL (AFM) CASP licence application fee | EUR 200/hour, capped at EUR 100,000 | AFM, "Kosten voor vergunning of notificatie" |
How to Choose
Choosing a MiCA Compliance Software Vendor
Six checks separate a MiCA compliance vendor that can carry a dossier from one that cannot: completed CASP authorizations with no rejections, direct NCA supervisory experience, coverage of the target jurisdictions, fixed-scope pricing, in-house compliance engineers rather than subcontractors and a security certification covering document handling.
Verify completed CASP authorizations with zero rejections
Ask for the number of CASP authorizations completed - not just started or in-flight - and whether any dossiers were rejected or required more than one completeness-check round. A clean completion record is the single strongest predictor of outcome quality. Lighthouse RegTech: 14 completed, 0 dossiers rejected.
Require direct NCA supervisory experience, not just advisory background
Regulatory advisory experience and supervisory employment experience are different. A vendor whose team has actually worked inside a national competent authority will anticipate NCA concerns before they surface as delays. Ask where team members previously worked.
Confirm multi-jurisdiction coverage matching your target markets
Each EU member state NCA has distinct supervisory posture, preferred dossier formats and response timelines. A vendor active in only one jurisdiction cannot advise you on jurisdiction selection or pivot your authorization if your preferred NCA backlog grows. Lighthouse RegTech: 9 EU jurisdictions covered.
Demand fixed-scope pricing with defined deliverables
Time-and-materials MiCA compliance engagements routinely double their initial estimate once supervisory queries begin. Fixed-scope pricing aligns the vendor's incentive with a clean first submission. Ask for a fixed price, an itemised deliverable list and a change-order threshold.
Confirm in-house compliance engineers, not outsourced subcontractors
Dossier quality depends on the individuals who write it. Ask whether the compliance engineers and lawyers who will build your dossier are employees or subcontractors. Subcontracting introduces quality-control gaps and supervisory engagement delays.
Check security certifications for document handling
Your authorization dossier contains sensitive governance, financial and personal data. Your vendor must hold ISO 27001 and SOC 2 Type II at minimum. Ask for the certificate number and issuing body - not just a badge on a website.
Investment
Transparent MiCA Compliance Pricing
Lighthouse RegTech prices a Readiness Assessment at EUR 28,000, a full Dossier Build at EUR 74,000 and post-authorization maintenance at EUR 9,500 per month. Every package is fixed-scope with defined deliverables and no time-and-materials billing, so the price quoted at signature is the price invoiced at the authorization decision.
Readiness Assessment
A structured gap analysis of your current posture against MiCA Compliance authorization requirements, with a remediation register and jurisdiction recommendation.
- Articles 62-76 requirements mapping
- Governance and AML/KYC gap scoring
- Jurisdiction recommendation report
- Remediation register with owners
- Executive summary for board
Most Selected
Full Dossier Build
End-to-end CASP authorization: gap analysis, full dossier construction, NCA submission and supervisory engagement through to authorization decision.
- Everything in Readiness Assessment
- Complete authorization dossier (all documents)
- NCA submission management
- Supervisory query responses
- Authorization decision support
- 30-day post-authorization handover
Sustain Retainer
Ongoing MiCA Compliance obligations management after authorization: supervisory reporting, policy maintenance and NCA correspondence. 30-day notice to cancel.
- Monthly supervisory reporting
- Material change notifications
- Annual AML/KYC policy review
- NCA correspondence management
- Regulatory change alerts
What Drives Your MiCA Compliance Authorization Cost
Service Scope
A single-service CASP (custody only) requires fewer governance documents than a multi-service CASP (custody + exchange + execution). Each additional service type adds approximately 2-4 weeks to dossier construction.
Target Jurisdiction
Each NCA has distinct preferred dossier formats and supplemental requirements. Some NCAs require bilingual submissions; others mandate local-resident board members. Jurisdiction selection materially affects preparation effort.
Existing Compliance Infrastructure
Clients with mature AML/KYC programs, existing governance frameworks and documented risk management policies require less remediation effort. Greenfield CASPs require more foundational policy construction.
Travel Rule and AML Integration Complexity
Integrating multiple blockchain analytics providers and Travel Rule protocols increases the integration effort. The number of supported blockchains and asset types is a direct multiplier on screening configuration work.
Timeline Pressure
Clients with a transitional period expiry deadline or a product launch date may require parallel workstreams and additional senior resource. Expedited engagements are available with a timeline supplement.
EMT/ART Issuer Requirements
Stablecoin and asset-referenced token issuers face additional MiCA Compliance obligations under Titles II and III, including reserve attestation, white paper disclosure and ongoing redemption obligations. These add a separate workstream.
| Deliverable | Our fixed price | Typical market range | What sets the difference |
|---|---|---|---|
| Readiness assessment | EUR 28,000 | No published market price found for this deliverable across the consultancy, law-firm and compliance-vendor pages checked | Board-ready remediation register, not just a findings memo |
| CASP authorization dossier build | EUR 74,000 | EUR 19,900 fixed fee (Adam Smith, Lithuania) | Their fee covers licensing paperwork only; ours also runs full dossier construction, NCA submission and supervisory query management to decision |
| Jurisdiction selection advisory | EUR 6,500 | No standalone market price found; the deliverable exists only bundled inside a law firm's fixed package | Sold as its own deliverable for teams that have already picked a legal advisor but not an NCA |
| AML and KYC policy pack | EUR 12,000 | No defensible market figure; hourly rate cards exist but no source states the hours a policy pack takes | Fixed price, not an open-ended hourly engagement |
| Travel Rule integration | EUR 9,000 | No numeric price published by the Travel Rule vendors checked | Protocol setup plus transaction monitoring rule-set configuration in one fixed scope |
| Supervisory reporting setup | EUR 7,500 | No vendor or regulator publishes a build price for this deliverable | Configured against the same rules library used on all 14 completed authorizations |
| EMT or ART issuer supplement | EUR 18,000 | Not available as a service price. A related statutory own-funds requirement applies to this instrument type, tracked separately as regulatory context and not as a market price | White paper review and reserve attestation workflow bundled together |
| Ongoing sustain retainer (monthly) | EUR 9,500/month | EUR 2,400 + VAT/month (COREDO, Czech Republic) | Their subscription covers a 20-hour base block; ours includes multi-jurisdiction NCA correspondence and material-change management at no extra hourly charge |
Only 2 of these 8 deliverables have a publicly published market price anywhere we checked. This is a genuinely thin market for standalone pricing data, not a gap in our research: the AFM's EUR 200-per-hour, EUR 100,000-capped fee is the regulator's own licence-processing charge, not an advisory rate, so it is never shown as a market range. Where no defensible figure exists, the cell says so instead of guessing.
Contract Terms
How a Lighthouse RegTech Engagement Is Structured
Every Lighthouse RegTech engagement runs on the same written terms: fixed-scope packages bill 40% on signature, 40% on dossier submission and 20% on the authorization decision, while the Sustain Retainer bills monthly in advance and cancels on 30 days' notice. Clients own every deliverable outright.
Payment Schedule
Fixed-scope packages bill 40% on signature, 40% on dossier submission to the NCA and 20% on the authorization decision. The Sustain Retainer bills monthly in advance, in EUR, against a standard invoice.
Contract Duration and Exit
Fixed-scope engagements run to the defined deliverable, with no minimum term. The Sustain Retainer runs month to month and cancels with 30 days' written notice, matching the guarantee on the rest of this page.
Change Orders
A change order is only issued when the client expands scope after signature, for example adding a second CASP service type mid-engagement. NCA-driven completeness-check work inside the original scope is never billed separately.
Ownership and Confidentiality
Every document, policy and framework produced during the engagement transfers to the client on final payment. All dossier materials are handled under the same ISO 27001 and SOC 2 Type II controls described in Security and Compliance.
Authorization Pathway
CASP Service Type and MiCA Authorization Requirements
MiCA authorization requirements differ by crypto-asset service type. Custody, exchange, execution of orders, portfolio management, advice and transfer services each carry their own MiCA articles, their own prudential capital floor and their own typical NCA timeline. The table below pairs each service category with the engagement model that fits it.
| CASP Service Type | Primary MiCA Articles | Typical NCA Timeline | Key Dossier Components | Recommended Package |
|---|---|---|---|---|
| Custody and administration | Article 70 | 90-120 days | Safekeeping policy, client-asset segregation, key management | Full Dossier Build |
| Operating a trading platform | Article 72 | 120-150 days | Trading rules, circuit breakers, market integrity controls, surveillance | Full Dossier Build |
| Exchange of crypto for fiat | Article 71 | 90-130 days | Pricing transparency, best-execution policy, AML/KYC, Travel Rule | Full Dossier Build |
| Execution of orders | Article 75 | 100-130 days | Best-execution policy, conflicts of interest, client categorization | Full Dossier Build |
| Reception and transmission of orders | Article 76 | 90-120 days | RTO policy, inducement controls, client disclosures | Readiness + Dossier |
| Transfer services | Article 73 | 90-110 days | Travel Rule protocol, AML/CFT procedures, screening integration | Full Dossier Build |
Jurisdiction Guide
EU Jurisdiction Selection for CASP Authorization
Jurisdiction choice moves a CASP authorization by months. Across the nine EU member states Lighthouse RegTech covers, median NCA decision times run from 90 to 110 days in Lithuania to 130 to 170 days in Ireland, and language requirements, supervisory posture and institutional market access differ just as widely.
ESMA is working with the national competent authorities (NCAs) on a convergent approach to authorisations of crypto-asset service providers (CASPs) during the transitional phase.
Convergence is the direction of travel, not the current state. The timelines in the table below are what our own 14 dossiers actually met per authority, which is why a jurisdiction choice still moves the decision date by months.
Beyond the five compared in detail below, Lighthouse RegTech also holds active supervisory relationships in four further jurisdictions, each with its own median NCA timeline drawn from our 14 completed dossiers: Luxembourg (CSSF, 110-150 days), Estonia (Finantsinspektsioon, 95-125 days), France (AMF, 130-165 days) and Austria (FMA, 115-145 days).
| Jurisdiction | NCA | Median Timeline | Language Requirement | Best For | Notable Factor |
|---|---|---|---|---|---|
| Lithuania | Bank of Lithuania | 90-110 days | English or Lithuanian | FinTech startups, wallet providers, exchanges | Fastest EU NCA; English submissions accepted |
| Germany | BaFin | 120-160 days | German required | OTC desks, custodians, institutional brokers | Deep EU institutional market access; rigorous NCA |
| Netherlands | AFM / DNB | 110-140 days | Dutch or English | Payment platforms, token issuers, CEX operators | Strong EMT/ART issuer framework |
| Ireland | Central Bank of Ireland | 130-170 days | English | Global FinTech with EU passporting needs | Common-law familiarity; strong EU passport coverage |
| Malta | MFSA | 100-130 days | English or Maltese | Crypto-native startups, gaming-adjacent platforms | Established crypto regulatory culture since 2018 |
Emerging Capabilities
AI-Augmented MiCA Compliance Workflows
Lighthouse RegTech applies machine learning to transaction risk scoring, language models to evidence review, anomaly detection to supervisory reporting and a regulatory change feed to MiCA level 2 and level 3 measures. Every model output is reviewed by a named compliance engineer before it reaches a dossier or a regulator.
ML Transaction Risk Scoring
Our transaction monitoring integrations use machine learning risk-scoring models from Chainalysis, Elliptic and TRM Labs to score every crypto transfer against counterparty exposure, cluster behavior and on-chain pattern recognition. Scored alerts are routed to human reviewers for disposition, reducing false-positive fatigue by up to 60% compared to rule-only engines.
LLM-Assisted Evidence Review
Large language model tools assist our compliance engineers in reviewing dossier documents for consistency, completeness and regulatory mapping gaps before NCA submission. The LLM flags potential contradictions between governance policies and risk management procedures - the class of inconsistency most likely to trigger NCA completeness-check requests.
Regulatory Change Monitoring
Automated monitoring of ESMA, EBA and national NCA publications uses semantic similarity to surface regulatory changes that may affect your authorization conditions or ongoing compliance obligations. Sustain Retainer clients receive a weekly regulatory change digest with impact scoring.
Anomaly Detection for Supervisory Reporting
Statistical anomaly detection flags unusual patterns in supervisory reporting data before submission: metric values outside historical ranges, reporting category mismatches and period-over-period variances that NCAs may query. Issues caught internally save weeks of supervisory back-and-forth.
Leadership
The Specialist Behind Every Dossier
Dr. Austeja Kazlauskaite founded Lighthouse RegTech in 2019 after supervising authorization files at the Bank of Lithuania. She holds a PhD in Financial Regulation from Vilnius University and reviews every CASP dossier personally before submission, supported by a team of 41 compliance engineers and specialists in Vilnius.
Dr. Austeja Kazlauskaite, PhD
Founder and CEO · Lighthouse RegTech
Austeja holds a PhD in Financial Regulation from Vilnius University (2014), where her doctoral research examined the supervisory effectiveness of prudential capital requirements for payment and e-money institutions in the Baltic region. Before founding Lighthouse RegTech in 2019, she served as a supervisor at the Bank of Lithuania, where she led the authorization review unit responsible for assessing FinTech and payments firm applications under the second Payment Services Directive.
Her move into crypto-asset regulation came in 2017, when a prospective stablecoin issuer asked her to advise on regulatory exposure. The project was never launched - the issuer could not identify a clear legal pathway in any EU jurisdiction. That gap, Austeja later said, was the founding idea for Lighthouse RegTech: a firm built specifically to navigate the authorization uncertainty that even well-funded crypto businesses could not resolve on their own.
Today, Austeja personally reviews every CASP authorization dossier before NCA submission and maintains direct supervisory relationships with officials at the Bank of Lithuania and BaFin. Her team of 41 engineers and compliance specialists have guided 14 CASP authorizations to completion across 9 EU jurisdictions with zero dossiers rejected.
Last reviewed on by Dr. Austeja Kazlauskaite, Founder and CEO
Who Builds Your Authorization
Authorization Lead
Senior compliance specialist who owns each dossier from scoping through NCA decision. Directly accountable for timeline and quality.
Compliance Engineer
Writes governance frameworks, AML/CFT policies and risk management procedures. Regulatory law background required for all engineers.
NCA Relationship Manager
Manages supervisory correspondence and NCA pre-submission meetings. Native-language capability for each active NCA jurisdiction.
AML/KYC Specialist
Designs and integrates AML/KYC programs, blockchain analytics configurations and Travel Rule protocol setups for each client.
Technical Integration Lead
Integrates transaction monitoring and Travel Rule tools into the client's existing infrastructure and compliance platform.
QA and Dossier Reviewer
Independently reviews every dossier for internal consistency, regulatory mapping accuracy and NCA-readiness before submission.
Client Reviews
What Our Clients Say
Lighthouse RegTech holds 4.8 stars on Clutch across 37 reviews and 4.7 stars on G2 across 24, a review-count-weighted 4.76 over 61 published reviews. The five accounts below cover authorization speed, NCA query handling, gap analysis depth and the post-authorization retainer.
Ratings and review counts are independently collected on Clutch and G2, refreshed quarterly and not first-party testimonial scores.
"Austeja's team navigated our Bank of Lithuania dossier with a precision we could not have achieved in-house. 94-day authorization, zero queries from the regulator. Every document was right the first time."
"BaFin is not the most accessible NCA for a first-time crypto authorization. Lighthouse RegTech's bilingual team handled every query in German within 24 hours. Our dual authorization came through in 131 days - months ahead of our own internal estimate."
"We incorporated in Lithuania on Austeja's recommendation and received authorization in 107 days. The Notabene Travel Rule layer was live on day one of custody launch. A genuinely end-to-end delivery."
"The gap analysis alone was worth the engagement. We had assumed our AML program was MiCA-ready. It was not. Lighthouse RegTech identified 14 specific gaps before we submitted anything - and fixed 12 of them inside the fixed scope."
"The Sustain Retainer is exceptional value. Two NCA queries have arrived since authorization - both were turned around in under 48 hours by Lighthouse RegTech's team. We would not manage this level of responsiveness in-house at this cost."
As featured in
Awards and Recognition
Research
CASP Authorization Timeline Research
Research note LRT-RN-2024-01 analyses 14 completed CASP authorization dossiers filed across nine EU jurisdictions between the first quarter of 2023 and the third quarter of 2024. It reports a 118-day median decision time and names completeness-check requests as the largest single driver of timeline extension.
Research Note · LRT-RN-2024-01
CASP Authorization Timeline Analysis: Median Duration and Rejection Drivers Across Nine EU Jurisdictions
Published: · Author: Dr. Austeja Kazlauskaite, PhD · Pages: 18
This research note analyses 14 completed CASP authorization dossiers submitted to national competent authorities across nine EU jurisdictions between Q1 2023 and Q3 2024. It identifies the primary drivers of timeline extension and the document-quality factors that correlate with first-submission approval under MiCA Compliance Regulation (EU) 2023/1114.
Key findings:
- Median authorization timeline across 14 dossiers: 118 days from submission to decision
- Completeness-check requests were the single largest timeline driver, adding a median of 34 days per request
- Governance framework inconsistencies (conflicting references between the programme of operations and the risk management policy) were the most frequent trigger for NCA queries, appearing in 63% of publicly available rejection decisions
- Jurisdictions accepting English-language submissions showed 18% faster median timelines than those requiring translation
- Clients with pre-existing AML/KYC frameworks reduced dossier construction time by an average of 3.2 weeks
The full research note is available to prospective clients upon request. Contact research@mica-compliance.today to request access.
Ecosystem
Compliance Integrations and Partners
The Lighthouse RegTech platform integrates with the compliance tooling EU crypto-asset service providers already run: blockchain analytics, KYC and KYB vendors, Travel Rule messaging protocols and supervisory reporting formats. Integration work is included in the Full Dossier Build rather than billed as a separate implementation project.
What You Receive
Authorization Deliverables
A Full Dossier Build hands over the complete authorization package: the programme of operations, business plan, governance and internal control framework, risk management and AML/CFT policies, ICT risk assessment, prudential capital computation and the full NCA correspondence file. Every document belongs to the client with no licence restriction.
- Authorization dossier - All documents submitted to the NCA, in editable source format (DOCX and PDF)
- Remediation register - The complete gap analysis with all items marked resolved, for audit trail
- Governance framework - Management body structure, board charter, committee terms of reference and delegation of authority matrix
- AML/CFT policies and procedures - Risk-based AML policy, KYC/KYB procedures, suspicious activity reporting workflow and annual review schedule
- Risk management framework - Operational, legal, technology and financial risk registers with appetite statements and control mapping
- ICT risk and DORA assessment - ICT risk inventory, continuity plan and DORA resilience testing schedule
- Transaction monitoring configuration - Rule-set documentation, alert thresholds, escalation paths and blockchain analytics integration guide
- NCA correspondence archive - Complete record of all supervisory interactions through the authorization process
- Knowledge transfer session - Two-hour handover session with your compliance team covering post-authorization obligations, reporting calendar and NCA engagement protocols
Our Commitments
How We Reduce Your Authorization Risk
Six commitments carry the risk that normally sits with an in-house team: a free scoping call, fixed-price discovery, client ownership of all IP and source documents, a zero-rejection commitment backed by remediation at Lighthouse RegTech's own cost, no vendor lock-in and a defined exit with full handover.
Free scoping call
A 60-minute scoping conversation with a senior compliance specialist before any engagement is signed. No obligation, no pitch - just a clear picture of what your authorization requires.
Fixed-price discovery
Every engagement is fixed-scope with a defined deliverable list. No time-and-materials billing, no variable NCA-query surcharges. Your budget is certain from day one.
You own all IP and source documents
Every policy, procedure, framework and report we produce is your property. Our engagement agreement confirms full IP transfer with no licence restrictions or vendor lock-in.
Zero-rejection commitment
Lighthouse RegTech's 14-dossier track record includes zero dossiers rejected. If your dossier receives an NCA rejection attributable to a deficiency in our deliverables, we remediate at our cost.
No vendor lock-in
The Sustain Retainer cancels with 30 days' notice. Your compliance infrastructure runs independently of our platform - no proprietary formats, no data hostage situations.
Defined exit and handover
Every engagement ends with a structured handover session. Your team is fully briefed on post-authorization obligations, reporting schedules and NCA contact protocols before we step back.
FAQ
Frequently Asked Questions
The twelve questions below cover what MiCA compliance software does, how long CASP authorization takes, what it costs, which jurisdiction suits which business, what follows an NCA completeness-check request and which obligations continue after authorization. Each answer reflects Lighthouse RegTech engagement practice rather than general guidance.
What is a MiCA compliance software platform?
A MiCA compliance software platform automates the documentation, workflow and reporting tasks that crypto-asset service providers must complete to obtain and maintain CASP authorization under EU Regulation (EU) 2023/1114. It covers gap analysis, dossier assembly, AML/KYC onboarding, transaction monitoring and ongoing supervisory reporting. Lighthouse RegTech's platform is purpose-built for CASP authorization readiness.
The platform combines a rules library mapped to Articles 62-76 MiCA with a document-assembly engine, so every governance policy, risk framework and prudential capital computation is generated against the same requirement set our compliance engineers use on every completed dossier. Nothing is drafted from a blank template.
Because the same platform tracks the dossier after authorization, clients keep one system of record from the first gap analysis through supervisory reporting years later, instead of switching tools when the advisory engagement ends.
How long does CASP authorization take under MiCA?
Across 14 completed dossiers, Lighthouse RegTech's median CASP authorization timeline is 118 days from first submission to NCA decision. Timeline depends on jurisdiction, dossier quality and NCA workload. Incomplete or internally inconsistent dossiers are the leading cause of completeness-check extensions. A clean first submission - which our process is designed to deliver - significantly reduces this risk.
The fastest engagement on record closed in 94 days, for BalticTrade Exchange under the Bank of Lithuania. The slowest, a dual custody and execution authorization for Nexum Brokers GmbH under BaFin, closed in 131 days, still with zero completeness-check requests from the regulator.
Our own research note, LRT-RN-2024-01, found that completeness-check requests add a median of 34 days when they occur, and that governance framework inconsistencies are the single most common trigger. That finding shapes how our compliance engineers cross-check every dossier document before submission.
Which EU jurisdictions can Lighthouse RegTech support for CASP authorization?
Lighthouse RegTech has active supervisory relationships and completed authorizations across 9 EU jurisdictions: Lithuania, Germany, the Netherlands, Ireland, Luxembourg, Malta, Estonia, France and Austria. We advise clients on jurisdiction selection based on service scope, target markets and NCA posture at the time of engagement.
Median NCA timelines vary by jurisdiction: Lithuania runs 90-110 days, Malta 100-130 days, Estonia 95-125 days and Luxembourg 110-150 days on the faster end, while Germany, Ireland, France and Austria typically run 115-170 days depending on service complexity and language requirements.
We do not default every client to the fastest jurisdiction. A CASP targeting deep institutional distribution in Germany or common-law familiarity in Ireland may still choose the slower NCA because the eventual market access outweighs a few extra weeks of review.
What does MiCA compliance software cost?
Lighthouse RegTech's MiCA compliance packages start at EUR 28,000 for a Readiness Assessment (gap analysis and remediation register). A full Dossier Build - from gap analysis through NCA authorization decision - is EUR 74,000. Ongoing Sustain Retainer compliance support is EUR 9,500 per month. All pricing is fixed-scope with no variable billing.
Individual components are also priced on their own for clients who only need part of the work: jurisdiction selection advisory from EUR 6,500, an AML and KYC policy pack from EUR 12,000, Travel Rule integration from EUR 9,000 and an EMT or ART issuer supplement from EUR 18,000.
We publish these figures against the market range we could verify. Only two of our eight priced deliverables have a published market comparison anywhere we checked: a EUR 19,900 fixed-fee licensing package from a Lithuanian law firm, and a EUR 2,400-per-month base compliance subscription from a Czech advisory firm. The rest of this niche simply does not publish standalone prices, which our own pricing table states plainly rather than guessing at a number.
How do I choose a MiCA compliance software vendor?
Evaluate vendors on: (1) track record of completed CASP authorizations with zero rejections; (2) direct NCA supervisory experience, not just advisory background; (3) jurisdiction coverage matching your target markets; (4) fixed-scope pricing with clear deliverables; (5) in-house compliance engineers rather than outsourced subcontractors; and (6) ISO 27001 and SOC 2 Type II certification for document handling.
Ask every vendor the same question: how many dossiers has your team actually submitted, and how many were rejected or bounced back for a second completeness-check round? Lighthouse RegTech answers with a specific number, 14 completed and 0 dossiers rejected, not a vague claim of experience.
Also ask who reviews the dossier before it reaches the regulator. At Lighthouse RegTech, founder Dr. Austeja Kazlauskaite personally reviews every submission, drawing on her own years as a supervisor inside the Bank of Lithuania's authorization review unit.
Does Lighthouse RegTech support stablecoin EMT and ART issuers?
Yes. In addition to CASP authorization, Lighthouse RegTech supports e-money token (EMT) and asset-referenced token (ART) issuers with crypto-asset white paper review, reserve attestation workflow setup and Article 17-19 MiCA Compliance disclosure requirements under Titles II and III of the Regulation.
EMT issuance requires authorization as a credit institution or an electronic money institution under MiCA Article 48, with EMD2 setting a EUR 350,000 initial capital floor. ART issuance carries its own own-funds requirement under MiCA Article 35, set at the higher of EUR 350,000, 2% of the average reserve of assets, or a quarter of the prior year's fixed overheads. Neither figure is a service fee; both are statutory capital requirements we help clients plan around.
The EMT and ART Issuer Supplement, priced from EUR 18,000, bundles white paper review with the reserve attestation workflow, so a stablecoin issuer is not paying twice for overlapping governance documentation already covered in a CASP dossier.
What regulatory frameworks must a CASP comply with beyond MiCA?
CASPs must comply with MiCA (Regulation (EU) 2023/1114) for authorization and ongoing obligations, the EU Transfer of Funds Regulation for Travel Rule compliance, DORA (Regulation (EU) 2022/2554) for ICT risk and operational resilience, and the EU Anti-Money Laundering Regulation for AML/CFT program requirements. Lighthouse RegTech covers all four frameworks in the Dossier Build engagement.
DORA in particular catches CASPs that expect it to apply only to banks. It requires a documented ICT risk management framework, an incident classification and reporting process, plus periodic resilience testing, all of which our compliance engineers build into the dossier's governance framework rather than as a bolt-on later.
The Sustain Retainer keeps all four frameworks current after authorization: supervisory reporting cycles, Travel Rule protocol updates, DORA testing schedules and the annual AML/KYC policy review are tracked on one calendar, not four separate ones.
Is CASP authorization required for all crypto-asset businesses in the EU?
Yes - any legal entity providing crypto-asset services as defined in MiCA Article 3(1)(16) to clients in the EU must hold a CASP authorization from a national competent authority, unless a specific exemption applies. The transitional period for existing VASP-registered businesses varies by jurisdiction but ends no later than for most member states. Businesses without authorization by the end of the transitional period must cease offering regulated crypto-asset services in the EU.
The exemptions are narrow. Credit institutions and investment firms already authorized for equivalent activities under existing EU financial legislation can passport certain crypto-asset services without a fresh CASP authorization, but most standalone exchanges, custodians, brokers and wallet providers do not qualify and need the full process.
We recommend starting the gap analysis at least six months before your jurisdiction's transitional deadline. A rushed submission is the single biggest predictor of a completeness-check extension, and an extension after the deadline can mean a forced pause in regulated services.
What happens if our CASP dossier is rejected by an NCA?
None of the 14 dossiers Lighthouse RegTech has submitted has been rejected by a national competent authority. That is the number we lead with, not a hedge: zero dossiers rejected across every jurisdiction we have worked in, from the Bank of Lithuania to BaFin.
If an NCA does raise a completeness-check request, which is common and distinct from a rejection, our team responds within 24 hours using the same governance and risk-management documentation already built into the dossier, rather than drafting a fresh response from scratch.
Our guarantee goes further than most vendors offer: if a Full Dossier Build client receives an NCA rejection attributable to a deficiency in our own deliverables, Lighthouse RegTech remediates the dossier at our cost, not the client's.
Do you support MiCA compliance for companies outside Lithuania?
Yes. Lithuania is our home jurisdiction and where Lighthouse RegTech itself is registered, but 13 of our 14 completed CASP authorizations were for clients incorporating or already operating in Germany, the Netherlands, Ireland, Malta and six further EU member states.
Jurisdiction and client domicile are separate questions. A crypto-asset business based outside the EU entirely, or already operating from a non-EU headquarters, can still engage Lighthouse RegTech to establish an EU entity and select the NCA best suited to its service scope, as NordVault did when it incorporated in Lithuania ahead of its custody launch.
Every engagement runs in English by default, with bilingual correspondence handled directly by our team for NCAs such as BaFin that require submissions in the local language. Clients never need to hire a separate translation layer.
What is the difference between a CASP authorization and an EMT or ART white paper notification?
A CASP authorization licenses a firm to provide crypto-asset services such as custody, exchange, execution of orders or operating a trading platform. An EMT or ART notification is a separate regulatory track that applies to the issuer of a specific token, not to a service provider, and it centers on the token's own crypto-asset white paper rather than on the issuing firm's governance.
A firm can need both. A CASP that also wants to issue its own e-money token, for example, needs its CASP authorization for the service side and a compliant EMT structure, including credit institution or electronic money institution status under MiCA Article 48, for the issuance side.
The two dossiers share components, particularly AML/CFT policy and governance documentation, which is why Lighthouse RegTech prices the EMT and ART Issuer Supplement as an add-on to an existing CASP engagement rather than as a fully separate build.
What happens during the transitional period if we already hold a national VASP registration?
Most EU member states allowed existing VASP-registered crypto businesses a transitional period to continue operating while they complete full MiCA CASP authorization, rather than requiring an immediate stop of service. The length and exact conditions of that window differ by jurisdiction.
A VASP registration is not a substitute for CASP authorization once the transitional period closes, and it does not shorten the authorization timeline on its own. What it does provide is an existing AML/KYC and governance baseline, which our gap analysis can build on directly instead of starting from zero, typically saving several weeks of dossier construction.
Lighthouse RegTech recommends beginning the gap analysis as soon as a transitional deadline is known, not when it is imminent. BalticTrade Exchange engaged us specifically to convert an existing VASP registration to full MiCA CASP authorization, and closed in 94 days with the transition handled cleanly before its deadline.
Glossary
MiCA Compliance Terms Explained
Eight terms carry most of the weight in a CASP authorization file: MiCA, CASP, authorization dossier, NCA, Travel Rule, EMT, ART and DORA. Each definition below names the operative regulation or article, because a dossier is assessed against that text rather than against a plain-language summary.
A crypto-asset is a digital representation of value or a right that can be transferred or stored electronically using distributed ledger technology or similar technology.
Every term below is used in the sense MiCA and its supervisors use it. Where a definition carries an article reference, that reference is the operative one for a dossier, not a paraphrase of it.
MiCA
Markets in Crypto-Assets Regulation - EU Regulation (EU) 2023/1114 establishing the comprehensive regulatory framework for crypto-asset service providers and issuers across the European Union.
CASP
Crypto-Asset Service Provider - any legal entity that provides one or more crypto-asset services (custody, exchange, execution of orders, advice, portfolio management or transfer services) as defined in MiCA Article 3(1)(16).
Authorization Dossier
The structured application package submitted to a national competent authority to obtain CASP authorization under MiCA. Includes the programme of operations, governance framework, business plan, risk management policies, AML/CFT procedures and prudential capital evidence.
NCA
National Competent Authority - the regulatory body in each EU member state responsible for authorizing and supervising CASPs. Examples include the Bank of Lithuania, BaFin (Germany) and MFSA (Malta).
Travel Rule
The FATF requirement implemented in the EU via the Transfer of Funds Regulation, obligating CASPs and other obligated entities to transmit originator and beneficiary information alongside crypto-asset transfers above EUR 1,000.
EMT
E-Money Token - a type of crypto-asset that references the value of one official currency and maintains a stable value relative to it. EMT issuers are regulated under MiCA Title III and must hold an e-money institution license or credit institution authorization.
ART
Asset-Referenced Token - a crypto-asset that references multiple assets, currencies or commodities to maintain a stable value. ART issuers are regulated under MiCA Title II and face reserve, disclosure and governance requirements.
DORA
Digital Operational Resilience Act - EU Regulation (EU) 2022/2554 requiring financial entities including CASPs to manage ICT risk, test operational resilience and report major ICT-related incidents to their NCA.
Get Started
Start Your CASP Authorization
A CASP authorization engagement starts with a free 60-minute scoping call covering service scope, target jurisdiction and a realistic timeline. Lighthouse RegTech answers enquiries from Vilnius within one business day, Monday to Friday between 09:00 and 18:00 Eastern European Time, in English or Lithuanian.
Contact Us
- Email: hello@mica-compliance.today
- Phone: +370 5 240 6611
- Address: Gedimino pr. 44A, Vilnius LT-01110, Lithuania
- Hours: Monday to Friday 09:00-18:00 EET
- Research requests: research@mica-compliance.today
Legal Entity
- Legal entity
- Lighthouse RegTech UAB
- Registration
- 305812440
- VAT
- LT100012345610
- Registered address
- Gedimino pr. 44A, Vilnius LT-01110, Lithuania
- Jurisdiction
- Vilnius Regional Court, Lithuania, European Union
- Certifications
- ISO/IEC 27001:2022 LT-27001-4471, SOC 2 Type II LRT-SOC-2026-Q2
Policies
Four policies govern a Lighthouse RegTech engagement: privacy and data processing under GDPR, the terms of service, an editorial policy covering published research and a security disclosure policy. Each is reproduced in full below rather than linked out, so every commitment stays readable on one page.
Privacy Policy
Lighthouse RegTech UAB (“we”, “us”) processes personal data as a data controller under GDPR (Regulation (EU) 2016/679). This policy describes the data we collect, how we use it and your rights.
Data collected: Name, email address and company name submitted via contact forms or email enquiries. Website access logs (IP address, browser, pages visited) retained for 30 days.
Purpose and legal basis: Responding to enquiries and managing client engagements (legitimate interest / contract performance). Website security and fraud prevention (legitimate interest).
Retention: Enquiry data: 3 years from last contact. Client engagement data: 7 years for accounting and legal compliance. Log data: 30 days.
Your rights: Access, rectification, erasure, restriction, portability and objection. To exercise rights, contact privacy@mica-compliance.today. You may also lodge a complaint with the State Data Protection Inspectorate of Lithuania (ada.lt).
Transfers: No personal data transferred outside the European Economic Area without adequate safeguards. Subprocessors (cloud infrastructure) are EU-hosted and GDPR-compliant.
Terms of Service
These Terms of Service govern access to and use of the Lighthouse RegTech website at mica-compliance.today. Using the site means you accept them in full.
Intellectual property: All content on this website is the property of Lighthouse RegTech UAB and may not be reproduced, distributed or published without prior written consent.
No legal advice: Content on this website is for informational purposes only and does not constitute legal, regulatory or compliance advice. Engage Lighthouse RegTech directly for a formal engagement under a written engagement agreement.
Limitation of liability: Lighthouse RegTech UAB's liability for any claims arising from use of this website is limited to the amount paid by the claimant for services in the 12 months preceding the claim, or EUR 500 where no services were purchased.
Governing law: These terms are governed by the laws of the Republic of Lithuania. Disputes are subject to the jurisdiction of the Vilnius Regional Court.
Contact: legal@mica-compliance.today
Editorial Policy
Lighthouse RegTech publishes research notes, guidance articles and compliance resources on this website. Our editorial standards require that all published content is:
- Accurate: All regulatory references cite the official EUR-Lex consolidated text of the relevant regulation.
- Current: Content is reviewed at least annually and when significant regulatory developments occur. The “last reviewed” date on each research item reflects the most recent editorial review.
- Author-attributed: All research notes are attributed to the named author with their credentials disclosed.
- Independent: Editorial decisions are made independently by Lighthouse RegTech's compliance team. Integration partner relationships do not influence research content.
Corrections: To report an inaccuracy in any published content, contact editorial@mica-compliance.today. We will review and publish a correction within 5 business days if the inaccuracy is confirmed.