Operating a virtual asset service without proper authorization in Georgia exposes a business to enforcement action, blocked banking relationships and the immediate suspension of payment rails. VASP licensing in Georgia is governed by the National Bank of Georgia (NBG), which extended its regulatory authorisation regime to virtual asset service providers (VASPs) through dedicated amendments to the country's payment services and anti-money laundering legislation. For an inbound exchange, custodian or token platform, the first practical question is not whether a licence is required – it almost certainly is – but which activity category triggers registration and how the Georgian stack interacts with the operator's home-country obligations. This page sets out the regime, the application process and the cross-border decisions that operators consistently get wrong.
What is the regulatory perimeter for VASPs in Georgia?
The National Bank of Georgia is the sole competent authority for virtual asset service provider supervision in the country. Under the applicable VASP provisions embedded in Georgian financial-sector legislation, any legal entity conducting regulated virtual asset activities on a commercial basis – whether exchange, transfer, custody or administration of virtual assets – requires prior authorisation from the NBG before commencing operations. The regime draws its definitional architecture from the FATF Recommendation 15 standard (the global baseline requiring states to regulate and supervise VASPs), meaning Georgia's list of covered activities maps closely to the FATF-defined perimeter: exchange between virtual assets and fiat, exchange between one or more forms of virtual assets, transfer, safekeeping and administration, and participation in token-issuance services.
Two structural points matter immediately for an inbound business. First, the place-of-business requirement: the NBG expects the licensed entity to be registered under Georgian law, with real operational substance rather than a nominal address. Second, the regime is not purely a registration tick-box. The NBG reviews the applicant's governance, AML/CFT programme, technology controls and ultimate beneficial ownership before granting authorisation. Operators who approach the process as a paper exercise routinely stall at the fit-and-proper and programme-adequacy stages.
Georgia's regulatory posture has been broadly welcoming to digital-asset business. The country introduced a VAT exemption on crypto-to-fiat conversion that remains in place and is a material consideration for exchange operators comparing jurisdictions in the region. That said, "welcoming" does not mean undemanding. The NBG has sharpened its supervisory expectations alongside the global tightening driven by FATF's mutual evaluation cycle, and applications that would have sailed through several years ago now attract substantive technical review.
Who needs a VASP licence in Georgia?
Any business providing virtual asset services to Georgian residents or operating from Georgian-registered entities falls within the NBG's supervisory perimeter, regardless of where the beneficial owner is located. The key categories are exchange platforms (fiat-to-crypto and crypto-to-crypto), custody and wallet services, transfer and settlement services, and participation in token offerings. Peer-to-peer facilitators, OTC desks and certain DeFi-adjacent businesses are in a grey zone that the NBG has not formally codified – these require a facts-and-law analysis before an operator commits to a Georgian structure.
A business licensed in another jurisdiction does not automatically enjoy passporting rights into Georgia. Unlike the EU's MiCA passporting mechanism (under which a CASP authorised in one member state may operate across the EEA), Georgian law does not recognise foreign VASP licences as a substitute for local authorisation. An operator who acquires a CASP under MiCA and then onboards Georgian users without separate NBG registration is operating unlicensed in Georgia. We see this oversight frequently among operators who assume that a single EU licence solves all market-access questions.
Mid-page decision point: if your business already holds a VASP or CASP licence elsewhere and is expanding into – or through – Georgia, the analysis turns on where your Georgian users' contracts are formed, where the servers sit and where customer funds are held. These facts determine whether the NBG's regime applies and in what form. The answer is rarely the same for two operators with superficially similar structures.
The process above describes the standard path. Your facts – the entity type, the user base, the banking structure – change the analysis significantly. For a scoped assessment of whether your existing licence stack covers Georgian operations, contact OBOLUS at info@oboluslaw.com.
How does the VASP licence application process work in Georgia?
The NBG application process runs in several sequential phases, and the elapsed time depends almost entirely on preparation quality before submission rather than on the regulator's statutory review clock. Operators who submit a complete, technically coherent package consistently move faster than those who treat the initial submission as a dialogue-opener.
The core submission package includes: a Georgian legal entity (or evidence of an imminent registration), constitutional and ownership documents traced through to the ultimate beneficial owner, audited financials or a credible business plan for new entities, an AML/CFT programme meeting the standards set under the applicable anti-money laundering provisions, a technology and cybersecurity description, and a governance structure demonstrating clear accountability. Fit-and-proper declarations for all directors and senior managers are mandatory, and the NBG conducts its own background review rather than relying solely on the applicant's representations.
The NBG may issue a request for further information (RFI) at any stage. Each RFI resets the practical clock. In our cross-border practice, we find that the most common RFI triggers are: incomplete UBO chains where holding structures cross multiple jurisdictions, AML programmes that are generic rather than calibrated to the specific risk profile of the VASP's activity, and technology descriptions that do not address the custody and key-management architecture in adequate detail. Preparing for these points before initial submission is the single most effective way to compress the timeline.
Once the NBG grants authorisation, the licensed entity must begin activities within a defined period or the licence lapses. Post-authorisation, the entity is subject to ongoing supervisory reporting, periodic AML/CFT programme reviews and change-in-control notification requirements. A change of ultimate beneficial owner, a material change to business model or a new product line that falls within a different activity category may each require a fresh notification or a licence amendment.
What are Georgia's AML and Travel Rule obligations for VASPs?
Georgia has implemented the FATF standard on virtual assets into its national AML/CFT legislation, and licensed VASPs are subject to the full suite of customer due diligence, suspicious transaction reporting and record-keeping obligations that apply to other obliged financial entities. The NBG acts as both licensor and AML supervisor for the VASP sector.
The Travel Rule – the obligation to pass originator and beneficiary data alongside a virtual asset transfer – applies to Georgian-licensed VASPs above the applicable transaction threshold. The specific de-minimis threshold is set in the implementing legislation and should be confirmed against the current text before operational systems are designed around it, as the figure has been subject to regulatory clarification. What is established is the underlying obligation: a Georgian VASP must collect, verify and transmit originator and beneficiary information for covered transactions, and must have technical systems in place to do so at the point of transfer rather than retrospectively.
The cross-border dimension of Travel Rule compliance is where operators most frequently encounter friction. When a Georgian VASP sends to a VASP in a jurisdiction that has not yet implemented the Travel Rule, the Georgian entity still bears the outbound obligation. It must have a counterparty due-diligence process for assessing whether the receiving VASP can handle Travel Rule data. Where the receiving VASP cannot, the Georgian operator faces a choice between declining the transaction or applying enhanced transaction monitoring. Regulators in the leading hubs increasingly expect documented policies on this point rather than ad hoc decisions.
How does Georgian licensing interact with tax and banking?
Georgia's tax treatment of virtual asset businesses is a material competitive consideration. The country operates a territorial tax system: income earned outside Georgia by a Georgian-registered entity is generally not subject to Georgian corporate tax, though the precise treatment depends on the entity's tax residency classification and the substance of its Georgian operations. Exchange operators comparing Georgia against other licensing hubs in the region – such as the AIFC in Kazakhstan or the EU member-state CASP routes – factor this territorial principle into their structuring analysis.
The VAT exemption on virtual asset exchange services, noted above, is operationally significant for exchange-facing businesses. It removes a cost layer that applies in several competing jurisdictions and directly affects the unit economics of a high-volume exchange. Operators should, however, confirm the current scope of the exemption with Georgian tax counsel, because the boundary between exempt exchange services and taxable ancillary services is not always obvious in a vertically integrated business.
Banking access is the variable most frequently underestimated at the structuring stage. Georgian commercial banks have implemented their own due-diligence frameworks for VASP clients that go beyond the regulatory baseline, and the practical openness of a given bank to VASP business is not uniform across the sector. An NBG licence is a necessary but not sufficient condition for banking access. In our cross-border practice, we advise clients to map the banking layer – including correspondent banking relationships and the bank's appetite for the specific activity category – before committing to a Georgian structure, not after.
For operators with a European user base or EU-licensed entities in the group, the interaction between Georgian operations and MiCA obligations requires careful attention. A Georgian VASP that is affiliated with an EU-licensed CASP may be subject to MiCA's third-country provisions depending on how the group's activities are structured. Regulatory authorisation in Georgia does not resolve EU compliance exposure for EU-directed services.
Which operator profile should choose Georgia?
Georgia suits a specific set of operator profiles, and the decision to license there should be driven by business substance rather than by the assumption that it is the easiest or cheapest route to a VASP registration.
Profile A – Regional exchange operator targeting the CIS and Caucasus market. Georgia's geographic position, the territorial tax system and the VAT exemption make it a logical domicile for an exchange whose primary user base is in the region. The NBG regime is established and predictable. The key risk is banking: the operator should stress-test correspondent bank access before committing. Timeline to authorisation, assuming a complete submission, is typically a matter of weeks to a few months depending on the complexity of the application and the NBG's current queue.
Profile B – EU-licensed CASP seeking a non-EU operational hub. A CASP that already holds MiCA authorisation and wants a lower-cost operational base for back-office, technology or non-EU-directed services may find Georgia attractive. The analysis must confirm that the Georgian entity's activities do not constitute EU-directed services triggering MiCA's third-country rules. This is a facts-specific assessment that counsel must perform before structuring, not after.
Profile C – Token issuer seeking a permissive but credible jurisdiction. Georgia is not the obvious primary jurisdiction for a regulated token offering that targets sophisticated investors. Operators in this profile typically look first at regimes with more developed token-specific frameworks – such as the VARA regime in Dubai or the ADGM/FSRA framework in Abu Dhabi. Georgia may serve as a secondary operational hub rather than the primary issuance jurisdiction.
Profile D – Custody-only provider. Custody is a regulated activity in Georgia under the applicable VASP provisions. A standalone custody business can obtain NBG authorisation, but the capital and governance expectations are real. Operators who want to combine custody with exchange or transfer activities must ensure each activity is covered by the authorisation scope; adding an activity post-licence requires a formal amendment process.
A cross-border licensing matter: Georgian VASP with European exposure
In a recent licensing matter, an exchange operator with a Georgian-registered holding company and a growing user base across Eastern Europe sought to formalise its regulatory position before expanding its product set. The entity had been operating under a legacy registration that predated the NBG's current VASP regime and had not mapped the gap between that registration and the updated licensing requirements. We conducted a gap analysis across the Georgian, EU and target-market obligations, identified three activity categories that required explicit NBG authorisation, and rebuilt the AML/CFT programme to address the Travel Rule obligations the operator had not yet implemented. The application was submitted as a complete package; the operator received NBG authorisation without a substantive RFI. Banking relationships, which had been informal, were formalised concurrent with the licence grant on the strength of the documented compliance programme.
What mistakes do operators make when pursuing VASP licensing in Georgia?
The most common structural error is treating Georgian licensing as an isolated step rather than as one layer in a multi-jurisdiction compliance stack. An operator who secures NBG authorisation without addressing the banking layer, the Travel Rule infrastructure and the interaction with its other licensed entities has a licence but not a compliant operating business.
A further mistake is UBO disclosure that stops at the first layer. The NBG traces ownership to the natural person level. Holding structures that were assembled for commercial reasons but that obscure the natural-person UBO – through nominee arrangements, complex trust structures or multi-tier holdings across non-cooperative jurisdictions – create significant friction in the fit-and-proper review and, in some cases, result in refusal.
A common assumption is that a Georgian VASP licence is sufficient to serve clients globally without additional authorisations. It is not. Georgian authorisation addresses the obligation to be licensed in Georgia for activities carried on from Georgia. It does not resolve the licensing position in the jurisdictions where the operator's users are located. An exchange that onboards users in the EU, the UK, Singapore or the US from a Georgian legal entity is subject to each of those jurisdictions' own VASP or equivalent requirements. Georgia is one piece of the compliance picture, not the whole of it.
If a prior application stalled or an existing structure has generated banking or regulatory friction, a structured second read can identify the cause and the path forward. To map the licence, banking and tax stack for your build, write to OBOLUS at info@oboluslaw.com.
Related at OBOLUS
- Licensing & Registration for Digital-Asset Businesses – end-to-end VASP and CASP authorisation across 70+ jurisdictions, from scoping to post-licence compliance.
- CASP under MiCA: A Legal Guide – how the MiCA CASP regime works, who it covers and how it interacts with non-EU licensing structures.
- NFT Project Legal Structuring in Germany under BaFin – a jurisdiction-specific guide to structuring token and NFT projects within a major EU regulatory regime.
FAQ
How long does a crypto licence take to obtain?
In Georgia, the timeline from initial submission to NBG authorisation depends primarily on the completeness and quality of the application package. A well-prepared submission by an entity with clear ownership, a documented AML/CFT programme and a coherent business model will typically move through review within a matter of weeks to a few months. Applications that generate requests for further information reset the practical clock. Across other major licensing hubs – Singapore, the UAE, EU member states – timelines vary considerably by regime and current regulator queue. A realistic timeline assessment requires a jurisdiction-specific scoping exercise before commitment.
Which jurisdiction is best for licensing my crypto business?
There is no single correct answer. The right jurisdiction depends on the operator's activity category, target user base, banking requirements, tax priorities and the group's existing licensed entities. Georgia suits regional exchange operators and businesses seeking a territorial-tax environment with an established VASP regime. EU member-state CASP routes suit operators targeting European users with passporting benefits. Dubai's VARA regime or ADGM suit operators building in the MENA region. A structured jurisdiction analysis – mapping the activity, the user base and the compliance cost – is the only reliable route to the right answer for a specific business.
Do I need a separate custody licence?
In Georgia, custody of virtual assets is a regulated activity under the applicable VASP provisions, and a business providing custody services requires NBG authorisation that explicitly covers that activity. If an operator is licensed for exchange but not custody, holding client assets in a segregated wallet technically falls outside the scope of the existing authorisation and creates an unlicensed-activity exposure. The same principle applies in most leading jurisdictions: custody is treated as a distinct, regulated function. Where an operator intends to combine exchange, transfer and custody in a single entity, each activity must be included within the authorisation scope from the outset.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing requirements and regulatory authorisation across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence stack across operating, custody and payment layers before you commit, so that structural gaps surface before they become enforcement events. To discuss your situation, contact info@oboluslaw.com or reach us via t.me/oboluslaw.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in VASP and CASP authorisation across emerging and established digital-asset licensing regimes, with a focus on cross-border structure and regulatory gap analysis.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.