A Programme That Keeps Compounding
Estonia's e-Residency programme is having its best year on record by the metrics that matter most: real companies and real tax receipts. E-residents founded more than 4,200 companies in the first seven months of 2026 — a 36% increase over the same period in 2025 and a 47% increase over 2024 — generating €57.6 million in direct state income, including €35.3 million in labour taxes and €19.5 million in dividend tax (Biometric Update, Sept. 17, 2026). Minister of Economic Affairs and Industry Erkki Keldo put it plainly: "e-Residency allows entrepreneurs from around the world to choose Estonia as their home for business and brings companies and income to our economy that would otherwise go elsewhere." Since the scheme launched in 2014, more than 144,000 people from 187 countries have become e-residents, founding or co-founding over 43,600 companies.
Those numbers matter because e-Residency was always a test case: could a state issue a legal digital identity to non-citizens, let them incorporate and run an EU company entirely online, and treat that as ordinary economic policy rather than a security exception? A decade in, the growth curve says yes. The programme's next phase, announced alongside these figures, pushes that logic further — eliminating the one step in the process that still isn't digital.
Removing the Last Friction Point
Today, a prospective e-resident still has to travel to an Estonian embassy or a Police and Border Guard Board office to have fingerprints and a photo taken before receiving a physical smart card. Estonia's IT and Development Centre has awarded a €3 million, 48-month framework contract to identity-technology firm X Infotech to build a smartphone application that captures facial images and fingerprints remotely while simultaneously verifying document authenticity, targeted for launch in 2027 (Biometric Update, Jan. 2026). SMIT's Kaija Kirch has said the challenge is that document checks, photo capture, and fingerprint collection "must work together within one service" at a security level existing commercial biometric apps don't meet.
The government's own estimate is that going fully remote could lift company-formation activity by roughly 20% and add €3–9 million a year in tax revenue, mainly by removing the embassy visit as a bottleneck for applicants far from Estonian diplomatic presence (e-Residency blog). Physical cards aren't disappearing immediately — the two paths are expected to run in parallel at least through 2027 — but the direction is unambiguous: compress the programme's one remaining analog step to zero.
The Case for Caution
E-Residency has never been free of scrutiny over financial-crime risk. Reuters reporting once raised alarms serious enough that Estonia's own e-Residency team published a public rebuttal, noting Estonia's ranking as the second-lowest jurisdiction globally (after Finland) for money-laundering risk on the Basel AML Index, and detailing that every applicant already undergoes a police background check before a digital ID is issued (e-Residency blog). That rebuttal is worth remembering here, because it frames what's genuinely at stake in going remote. The in-person appointment isn't just paperwork — it's one of the few moments a trained official can examine an applicant and a document together, in the same room. Regulators who worry that swapping an embassy visit for a phone-based capture removes a real fraud checkpoint aren't being reflexively anti-technology; they're naming the exact failure mode KYC regimes exist to catch, in a programme that has an obvious institutional incentive to keep processing volume climbing.
Why Remote Beats In-Person, If Done Right
The steelman only holds if the remote process is actually weaker than the current one, and Estonia's design choices point the other way. The X Infotech app must meet the EU eIDAS regulation's "high" assurance level — the tier reserved for the most sensitive government digital-identity transactions — and must run document-authenticity verification, live facial capture, and fingerprinting as one integrated, auditable flow rather than three separate steps a human reviewer stitches together afterward. A phone that cross-checks a passport's security features against a database in real time, tied to a liveness-checked biometric capture, is not obviously less rigorous than a five-minute embassy appointment; it may be more consistent, because it can't get tired, rushed, or fooled by a forgery a machine-readable check would flag instantly. Critically, Estonia isn't removing the background-check and transparency layers that already answer the money-laundering critique — company ownership stays publicly searchable, and service providers still need licensing to spot and report risk. It's replacing only the physical-presence requirement, and replacing it with something built to a stricter technical bar.
Standards Are the Real Story
The more important signal from mid-September is what surrounded the growth numbers. ETSI and the EU Agency for Cybersecurity convened Estonia's 12th Trust Services and eID Forum in Tallinn on September 15–16, working through the rollout status of the European Digital Identity Wallet, the proposed European Business Wallet, and — notably — the effects of post-quantum cryptography on digital-identity systems (ENISA event page). That last item isn't academic. Identity credentials are long-lived, and a trust certificate issued today under classical cryptography could be harvested now and broken once quantum computing matures. Estonia expanding e-Residency's biometric pipeline at the same moment European standards bodies are hashing out post-quantum trust-service rules is the right sequencing — building the volume business on infrastructure being hardened in parallel, not bolting security on after the fact.
The lesson for other jurisdictions eyeing digital-identity expansion isn't "move fast." It's that Estonia can move fast on user-facing friction precisely because it has spent a decade investing in the unglamorous layer underneath — eIDAS-grade assurance levels, public beneficial-ownership registers, and now active participation in setting the EU's next-generation and post-quantum identity standards. Removing an embassy visit is safe to do only because the credential it produces still has to survive a security bar regulators, not marketers, wrote.