Tightened Rules for Crypto Businesses/VASPs

VASP

As of 27 August 2026, the rules for crypto businesses in Georgia have changed. Until now, such companies were mainly required to register with the National Bank of Georgia (NBG) and comply with anti-money laundering rules. Under the NBG’s new Order No. 207/04, they are now, for the first time, required to hold minimum capital and maintain a full-fledged risk management system. The changes affect both companies already on the register and anyone currently planning to register.

Who is affected?

The changes apply to virtual asset service providers (VASPs), also known as crypto companies. These are companies that offer others the exchange of virtual assets, including through self-service kiosks, as well as transfers, custody, portfolio management, trading platforms, lending, or the initial offering of new assets.

The change did not come out of the blue. In December 2025, an amendment to the Organic Law on the National Bank of Georgia empowered the NBG to set capital, risk management and liquidation rules for VASPs, and the law required the NBG to adopt these rules by 1 September 2026. The August orders deliver on that mandate. As a result, the VASP sector is now subject not only to anti-money laundering oversight, but also to supervision of its financial soundness.

What has changed: 5 key updates

  1. Minimum capital - There was no such requirement before. A company must now maintain, at all times, own capital of GEL 150,000 to GEL 350,000, depending on the services it offers to customers.
  2. Risk management system - Written policies, cyber protection, regular testing of systems and an independent auditor’s report are required.
  3. Automated monitoring - A company must have software that automatically detects suspicious and interconnected transactions based on blockchain data.
  4. Tighter control over owners - Anyone holding exactly 10% is now also treated as a holder of a “significant share”. Previously, the threshold was more than 10%.
  5. A clear list of services - The rules list eight types of services. No new type of service may be launched before the NBG gives its consent. The NBG responds within 1 month of receiving the complete documentation.

What does this mean for your business?

How much capital will you need?

Supervisory capital is a company’s own funds, which act as a “safety cushion” in case of losses. The amount depends on the type of service (Minimum capital):

  • Exchange of crypto assets (including via kiosks) or transfers - GEL 150,000
  • Operating a trading platform (exchange) - GEL 350,000
  • Other services, e.g. custody, portfolio management, lending - GEL 250,000

If a company provides several services, the amounts are not added up: the highest one applies. For example, exchange and a trading platform together require GEL 350,000, not GEL 500,000. The issuance of stablecoins (crypto assets pegged to a currency) is governed by a separate rule, under which the minimum is GEL 500,000 plus a variable component.

Capital is not the same as money held in a bank account. Under the law, minimum supervisory capital is the sum of primary (Tier 1) and secondary (Tier 2) capital elements: at least 75% must consist of primary capital elements, and secondary capital elements must not exceed one third of the primary capital elements.

Capital must be maintained at all times. If it falls below the minimum, the company must notify the NBG immediately and submit a recovery plan within 5 business days.

What does risk management mean in practice?

  • Written policies on operational risk, cybersecurity, fraud and technological resilience.
  • Penetration testing, a controlled “hacker attack” carried out by specialists to uncover vulnerabilities. It is performed annually on critical systems, at least once every 3 years on other systems, and after every significant change to critical infrastructure.
  • Vulnerability scanning at least twice a year.
  • Business continuity plan: how the company will keep operating during an outage or a cyberattack, including the recovery of IT systems. Testing it at least once a year is recommended.
  • Record keeping: all versions of risk management documents must be kept for 8 years after the company stops providing its services.
  • An independent auditor’s report confirming compliance with these requirements.

If the audit or a penetration test reveals a critical or high-risk vulnerability, the NBG may revoke the company’s registration or its consent for a specific service.

By when must crypto companies/VASPs that are already registered comply with the law?

Deadlines and action list

Transition periods apply only to capital and risk management. All other changes have been in force since 27 August 2026.

Right now:

  • Check whether your monitoring software automatically detects both suspicious and interconnected transactions. Not having such a system is a ground for revoking registration, followed by a 3-year ban on re-registration. The fine for the same violation is GEL 20,000.
  • Review your ownership structure: is there anyone holding exactly 10% who now counts as a holder of a “significant share”?
  • Do not launch any new type of service before the NBG gives its consent.
  • Use the new forms when submitting documents to the NBG.
  • Select an auditor.

By 1 July 2027: One must have in place a full risk management system.

By 1 September 2027: One must meet the minimum capital requirement.

By 1 January 2028: The NBG will update your registration act and list your services in it. Check that they are reflected correctly.

Planning to register? What you will need

  • Capital, before you apply. Your application must be accompanied by a bank statement confirming that the minimum capital has been paid in.
  • Monitoring software, before you start operating.
  • A risk management system and an auditor’s report, within 12 months of registration.
  • New forms, including the updated list of services.
  • For issuing stablecoins, in addition, already at the registration stage: corporate governance, capital and audit documents, and an offering document.

The NBG normally decides within 60 calendar days, although this period may be suspended or extended.

What else is changing?

  • Fines. Since 25 August 2026, the NBG’s rules on fines also cover breaches of VASP regulations. For example, breaching a service scheme agreed with the NBG is punishable by a fine of GEL 20,000.
  • Customer complaints, from 1 January 2027. You must accept complaints orally, in writing and electronically, handle them within 1 month, and submit statistics to the NBG every month, by the 10th.
  • Travel Rule, by 31 December 2027. This is the rule on transmitting sender and recipient data with transfers. From that date, each breach carries a fine of GEL 500.
  • Liquidation rules, from 1 September 2028. Liquidation begins as soon as registration is revoked, and the liquidator is appointed by the NBG.

How we can help

The JUSTICE LEAGUE team can help you assess compliance with the new requirements, structure your capital, prepare your business plan and risk management documentation, put together your registration package and communicate with the NBG. The sooner you start working on compliance, the more smoothly you will get through these changes.

Apply Now

This article is for information purposes only, reflects the situation as of 30 September 2026 and does not constitute legal advice.

Related Articles:

  1. VASP Registration in Georgia: A Complete Guide 2026

  2. VASP: Registration Documentation Checklist

Irakli Tsankashvili

IRAKLI TSANKASHVILI

September 30, 2026

Justice League All rights reserved
Loading
Georgia VASP Rules 2026: New Capital and Risk Requirements