Georgia VASP registration & operations See our delivery model
Mon–Fri · 09:00–18:00
ONE BUSINESS, SEVERAL CONNECTED RULES

Georgia VASP Legal Framework: Rules That Apply Together

Entrepreneurs, investors, boards and professional advisers

Georgia’s VASP regime is often reduced to one registration order. In practice, founders need to read the National Bank’s organic-law powers, the VASP registration and regulation rule, the AML/CFT law, transfer-information requirements, sanctions instruments, the 2026 stablecoin framework and any adjacent tax, payment, securities, consumer, data or lending rules together.

1. The Organic Law creates the supervisory perimeter

The Organic Law on the National Bank of Georgia provides the institutional foundation for VASP registration and supervision. It should be read for the NBG’s powers, the statutory concept of virtual-asset services and the limits of what registration permits. Registration is not a general authorisation for payment services, securities activity, deposit taking, consumer lending or every token product.

2. Order No. 94/04 governs entry, cancellation and core operating requirements

NBG Governor Order No. 94/04 is the principal practical route for an ordinary VASP applicant. It addresses the eligible Georgian legal entity, filing information and documents, significant owners and UBOs, administrators, head office, branches and cash activity, websites and applications, service-flow diagrams, electronic systems, providers, three-year business plan, organisation and AML/CFT material. As amended by Order No. 207/04, it also establishes service-based supervisory capital and an operational-risk and cybersecurity framework.

Its annexes and amendments matter. Founders should work from the current consolidated position and current NBG forms, not an outdated checklist or earlier-version summary. The filing is in Georgian and foreign evidence may require apostille or legalisation and certified translation.

3. The AML/CFT law makes the VASP an accountable person

The Law on Facilitating the Prevention of Money Laundering and the Financing of Terrorism provides the wider duties around risk-based controls, customer and beneficial-owner due diligence, monitoring, suspicious-activity handling, records and governance. NBG legal acts and Financial Monitoring Service requirements complete the working framework.

The NBG’s VASP compliance questionnaire and 2024 sector risk update show how those duties translate into an application and operation: organisational risk assessment, internal instructions, customer-risk classification and reassessment, transaction-monitoring technology, unusual-activity detection and evidence that the controls work.

4. Transfer-information rules create a dedicated product workstream

Georgia’s virtual-asset transfer information rules address originator and beneficiary data, counterparty VASPs, self-hosted addresses, secure data transfer and missing or incomplete information. The current NBG implementation date for VASPs is 31 December 2027. That future date does not make the architecture irrelevant today: a transfer product launched without the necessary data model, screens, APIs and case logic may require expensive redesign.

5. Supervision, sanctions and cancellation continue after registration

The NBG can request information, inspect, issue written instructions, impose requirements or restrictions and use the sanctions available under law. Order No. 133/04 sets the VASP fines framework and was most recently amended by Order No. 204/04 on 24 August 2026. The current framework includes breach-specific monetary fines, doubled exposure for repeated violations and non-monetary measures affecting administrators, operations, distributions, control and registration.

Exact financial consequences should be checked against the current consolidated rule when a case arises. In practice, the more useful lesson is to maintain retrievable records, management information, quality assurance and an evidence-based remediation process before supervisory concerns become repeated failures.

6. Stablecoin issuance is a separate 2026 track

Order No. 52/04 applies to the initial offering—including issuance—and subsequent servicing of stable virtual assets. It requires prior written NBG consent and addresses full reserve backing, eligible reserve composition, segregation, redemption, disclosure, reporting, capital and operational and cyber resilience.

Capital regimes must be separated. The stablecoin framework has a GEL 500,000 baseline. Ordinary VASPs now maintain GEL 150,000 for exchange/transfer, GEL 350,000 for a trading platform or GEL 250,000 for other services.

7. Capital, operational risk and cybersecurity are continuing conditions

Order No. 207/04 requires ordinary VASPs to remain above the applicable capital threshold and to maintain a documented risk framework covering operational risk, cybersecurity, outsourcing, business continuity, IT disaster recovery, incidents, testing and management information. At least 75% of minimum capital must consist of primary capital. Critical or high-risk deficiencies may lead to cancellation of registration or of the consent for a particular service.

8. Cash branches and kiosks attract additional operating rules

Exchange through a self-service kiosk is expressly within the VASP perimeter. Cash exchange locations can require premises evidence, video surveillance, functioning-system availability, location records, cash security, reconciliation and stronger monitoring for linked or structured transactions. A registered online model should not add cash locations informally.

9. Tax law follows the actual company and transaction

The Tax Code and Public Decision No. 201 are relevant but should not be turned into a slogan that a Georgian crypto business is tax free. An individual’s disposal of a cryptoasset is different from a company’s exchange spread, custody fee, service income, distributed profit, payroll, VAT/place-of-supply position and related-party transactions.

10. Sandbox and regulatory laboratory are engagement routes, not licences

The NBG regulatory sandbox can permit controlled testing of a genuinely innovative service under defined conditions. The regulatory laboratory supports dialogue on a product or model. Neither should be presented as a temporary VASP registration or as permission for unrestricted commercial operation.

11. Adjacent regimes still require a perimeter check

A VASP model may overlap with payment services, financial instruments or securities, collective investment, lending, consumer protection, advertising, privacy and data transfer, cybersecurity, employment, immigration, sanctions and contract law. A token, fiat rail or yield feature should be classified on its own facts.

How to use this framework in a VASP project

  1. Classify the service and adjacent regimes before incorporation and vendor commitment.
  2. Work from current official texts, annexes and amendments.
  3. Translate legal duties into people, systems, contracts, records and testing.
  4. Separate ordinary VASP requirements from model-specific overlays such as stablecoins or cash locations.
  5. Keep a regulatory-change register after filing and after registration.
  6. Obtain model-specific Georgian legal, tax and technical input where the facts require it.
LEGAL BASIS

Our regulatory assessments and implementation work are based on the Georgian legislation and National Bank of Georgia materials below. Legal texts available in our legislation library open on CryptoLicense.ge; the official Matsne source is linked at the bottom of each legal-text page.

CryptoLicense.ge Legal & Regulatory Team Legal review: 1 September 2026 Model-specific legal review required