TrustlexGeorgia business setup

Crypto in Georgia: VASP Registration, What the National Bank Requires, and What It Costs You in Practice

Georgia moved from an unregulated crypto market to a registered VASP regime. What activities are caught, what the National Bank expects from an applicant, the AML programme and travel rule, the banking reality, the tax treatment, and the honest timeline.

Beka Shakulashvili · Founder & Managing Partner August 9, 2026 16 min read

For several years Georgia was known in crypto circles as a jurisdiction where a company could operate with very little regulatory friction. That period is over. Georgia introduced a Virtual Asset Service Provider regime, supervised by the National Bank of Georgia, and the practical position now is that a business providing virtual asset services must be registered before it operates.

Registration is the condition of operating, not an optional upgrade.

Months

Realistic registration timeline

Set by evidence production, not form-filling

NBG

The supervising authority

National Bank of Georgia registers and supervises VASPs

2

Sequential gates

Registration first, then the banking relationship - never assume either

The most common thing we see is a company incorporated a year ago, trading, with no registration and a bank account that has just been closed. Registration is not a formality you add later; it is the condition of operating.

Law of Georgia on Facilitating the Prevention of Money Laundering and the Financing of Terrorism· Virtual asset service providers
Virtual asset service providers are accountable entities subject to registration and supervision by the National Bank of Georgia, and must apply customer due diligence, monitor transactions, comply with the travel rule for virtual asset transfers, and report suspicious activity to the Financial Monitoring Service of Georgia.
Stated in outline; the National Bank's secondary acts set the operative detail.

Which activities are caught

The regime follows the international definition of a virtual asset service provider closely. In outline it captures a person who, as a business, provides:

  • Exchange between virtual assets and fiat currency.
  • Exchange between one virtual asset and another.
  • Transfer of virtual assets.
  • Custody or administration of virtual assets, or of the instruments that control them.
  • Participation in and provision of financial services related to the offer or sale of a virtual asset.
  • Lending, borrowing and comparable services in virtual assets, where offered as a business.

Mining for one's own account and holding one's own assets are treated differently from providing a service to others. The perimeter question is always the same: are you doing this for other people, as a business?

ModelCaught as a VASP?Why
Exchange fiat to crypto for customersYesExchange between virtual assets and fiat
Custodial wallet for usersYesCustody and administration of virtual assets
Non-custodial wallet softwareUsually notThe provider never controls the assets
Mining for own accountUsually notNo service provided to another person
OTC desk arranging trades for clientsYesExchange and transfer as a business
Analytics or data product onlyNoNo virtual asset service is provided
Common crypto business models against the VASP perimeter.

What the National Bank looks at

  • A Georgian legal entity with transparent ownership up to identifiable beneficial owners.
  • Fit and proper assessment of owners, directors and key function holders.
  • Capital and financial standing appropriate to the activity, maintained continuously.
  • Governance: internal controls, risk management, business continuity, and outsourcing arrangements described rather than asserted.
  • Information security and custody arrangements - key management, cold and hot wallet policy, incident response.
  • A full AML/CFT programme, including the travel rule for virtual asset transfers, blockchain analytics, sanctions screening, and reporting to the Financial Monitoring Service of Georgia.
  • Segregation of client assets from the provider's own assets, with the mechanism evidenced.

Custody and key management, examined closely

For any model that holds customer assets, the National Bank pays particular attention to how private keys are controlled, because that is where customer losses actually happen. Expect to describe, and evidence, a concrete key-management policy: the split between cold and hot storage, who can authorise a movement of assets, whether multi-signature or equivalent controls apply, how keys are backed up and recovered, and how a security incident is detected and responded to. Client assets should be segregated from the provider's own, so that customer holdings are identifiable and returnable and do not form part of the provider's estate if it fails. A custody model that cannot be explained in operational detail is not ready to file.

The AML programme, specifically

For a VASP the anti-money-laundering file is the application. It has to work on the day it is inspected.

  1. Business risk assessment covering customers, products, geographies, channels and asset types.
  2. Customer due diligence, with enhanced measures for higher-risk relationships and politically exposed persons.
  3. Wallet screening and transaction monitoring, with the analytics provider named and the escalation path defined.
  4. Travel rule compliance for transfers between providers, including how you handle counterparties that cannot receive the data.
  5. Sanctions screening at onboarding and continuously, with a documented false-positive procedure.
  6. Suspicious transaction reporting, record retention, training and independent testing.

The travel rule, in practice

The travel rule is the part of a VASP AML programme that catches applicants off guard, because it depends on parties you do not control. When virtual assets move between providers, originator and beneficiary information has to travel with the transfer. Your programme has to specify how you collect and transmit that data, how you receive and check it on inbound transfers, and - the hard case - what you do when a counterparty cannot receive or return the required information. The National Bank wants to see a defined, documented policy for that gap, not an aspiration that every counterparty will be compliant.

Banking, which is the real constraint

Registration does not entitle a business to a bank account. Georgian banks apply their own risk appetite to crypto, and it is narrow. Expect a bank to ask for the registration, the AML programme, the analytics arrangements, the source of the company's funds, the flow of funds through the product, and named officers. Budget more time for banking than for the registration itself, and do not sign customer commitments before the account exists.

Tax

  • Corporate income tax follows the general Estonian-model rules: 15% on distributed profit, with reinvested profit generally untaxed until it leaves the company.
  • VAT treatment depends on the service and the customer, and must be assessed for each revenue stream rather than assumed.
  • Personal taxation of crypto gains for individuals has its own treatment and has been the subject of specific guidance; it should be confirmed case by case rather than taken from a forum post.

Timeline, honestly

A VASP registration is a project measured in months, not weeks, and the banking relationship often takes longer than the registration itself. The pace is set by how quickly the applicant can produce evidence rather than intentions: a real AML programme, a described and tested custody model, named and vetted officers, and answers to the National Bank's follow-up questions. The sequencing matters too - registration first, then banking - and neither should be assumed to complete on a fixed date. Do not make customer or investor commitments that depend on a registration or an account that does not yet exist.

Anyone selling you a "Georgian crypto licence in two weeks, no substance required" is selling a problem. Ask them to put the registration number and the supervising authority in writing.

Worked example

Is this a VASP at all? Reasoning through the perimeter

A team builds a non-custodial wallet with a built-in swap feature routed through a third-party exchange, and asks whether it needs Georgian VASP registration.

  1. 1Start from the definition, not the product name: the perimeter turns on the services performed - custody, exchange, transfer - for or on behalf of clients.
  2. 2Non-custodial wallet alone: the users hold their own keys, and the software argument against registration is strong.
  3. 3The swap feature changes the analysis: routing client orders to an exchange may be an exchange service performed for clients, depending on how the flow and the fees are structured.
  4. 4The answer is architectural: restructure the swap as a plain referral to the third party and the perimeter case weakens; take a spread inside the flow and it strengthens.

The registration question was answered by the product's money flow, not its marketing description - and the team chose the architecture knowing the regulatory price of each option, which is the entire point of asking before building.

Illustrative. The VASP perimeter is defined by the current National Bank rules and applied to the specific facts.

How Trustlex approaches crypto files

Worked example

The registration that was granted and the banking that never came

A crypto business completes VASP registration, treats it as the finish line, and begins onboarding customers.

  1. 1Registration confirms the business is supervised. It does not oblige any bank to serve it.
  2. 2Georgian banks apply their own appetite to crypto-facing businesses, and several decline the sector as a matter of policy irrespective of the registration.
  3. 3The business operates through payment intermediaries with higher costs and less stability, which is a materially different model from the one in its plan.
  4. 4The banking question could have been tested with the same institutions before the registration work began.

For crypto businesses the licence is the achievable part and the banking is the binding constraint. Test the constraint first, because a supervised business without a payment route is a supervised business that cannot trade.

Illustrative. Bank appetite for the sector changes and differs by institution.

We begin with a perimeter analysis - what the product does, for whom, with whose assets - and give a written answer on whether registration is required. If it is, we scope the governance, AML and technology work, and we say honestly what the banking prospects look like for that specific model before the engagement starts.

General information, not legal or tax advice. The VASP perimeter, the conditions and the tax treatment turn on your specific model and the current National Bank rules, which should be confirmed before you build.

Related articles