Estonia's e-Residency programme, the decade-old digital identity scheme that lets anyone in the world register and run an Estonian company online, has just posted its strongest year on record. E-residents formed more than 4,200 companies in 2026 through the first seven-plus months of the year — an average of 600 a month, up 36% on the same period in 2025 and 47% on 2024. The state collected €57.6 million in direct income from those businesses over that span: €35.3 million in labour taxes, €19.5 million in dividend tax, and €2.8 million in state fees.
That builds on an already record 2025, when e-residents generated €124.9 million in state revenue — an 87% jump on 2024 — and founded 5,556 companies, per the programme's own year-end accounting. One in five new Estonian companies is now founded by someone who has never set foot in the country, and the programme has produced more than 43,600 companies from 144,000+ e-residents across 187 countries since it launched in 2014.
The Next Step Is Bigger Than the Numbers
The programme's next move is more consequential than the growth figures themselves. Estonia is replacing the physical e-Residency card — the plastic chip-ID applicants currently collect in person at an embassy or police station — with a smartphone app that captures facial images and fingerprints remotely. The government has awarded the technical contract to Latvian identity-tech firm X Infotech and confirmed a 2027 rollout alongside a flat €165 state fee, replacing the old pickup-location-dependent pricing. Officials estimate the change could lift company formation by at least 20% and add €3–9 million a year in tax revenue, largely by removing the in-person step that discourages applicants who live far from an Estonian mission.
Steelmanning the Concern
The case for caution here is genuine, not manufactured. Estonian World publisher Silver Tambur has warned that "the physical card was cumbersome, but it baked in a high-confidence identity step," and that "a mobile-first system will live or die by cybersecurity, fraud controls and the credibility of remote biometrics." He's right to flag that e-Residency has already drawn money-laundering and sanctions-evasion risk — a scheme that grants EU company-formation rights to anyone, anywhere, with minimal physical vetting is an obvious target for exactly that kind of abuse, and removing the one mandatory face-to-face touchpoint in the process is not a cosmetic change. Regulators and journalists who ask Estonia to prove the replacement is at least as good as the original are asking the right question.
"A mobile-first system will live or die by cybersecurity, fraud controls and the credibility of remote biometrics." — Silver Tambur, Estonian World
Relocating Verification, Not Removing It
But Estonia's answer isn't to strip out verification — it's to relocate it. The Police and Border Guard Board has said explicitly that all e-Residency applicants will continue to undergo thorough background checks, and it retains the option to require an embassy visit or a live video interview for any applicant who doesn't clear the automated check. The X Infotech contract itself is structured around that standard: the specification requires document-authenticity verification, photo capture, and fingerprinting to work together within the EU's eIDAS framework — a combination that, according to the tender documentation, existing commercial biometric products haven't yet matched. That is arguably a higher bar than the current card process clears today, where a human clerk visually checks a passport once.
This is what proportionate, evidence-based regulation should look like: identify the friction that's suppressing legitimate activity — an embassy visit that particularly disadvantages applicants in Latin America, Southeast Asia, and Africa, where Estonian diplomatic presence is thin — and replace it with a control that is verifiably tighter on the dimension that actually matters (identity assurance) while removing the dimension that doesn't (geography). The €3–9 million revenue projection is a byproduct, not the justification; the real justification is that a government KYC process should be judged on fraud-detection accuracy, not on how many people it forces to travel to prove who they are.
The Real Test Is Enforcement, Not the Announcement
None of this is self-executing. eIDAS compliance on paper doesn't guarantee eIDAS-grade fraud detection in production, and Estonia has given itself a real-world trial period: card issuance won't stop the moment the app ships, but the programme's credibility rests on that app performing at least as well as the process it replaces from day one. If document-spoofing or presentation-attack rates rise even briefly after 2027, the money-laundering critique will look prescient rather than alarmist — and Estonia's broader pitch, that digital government can be both frictionless and secure, takes the hit with it.
Estonia's own instinct so far has been to publish the numbers rather than bury them — the same quarterly transparency that let outside observers calculate the 36% and 87% growth figures cited above should extend to fraud and rejection-rate data once the biometric system is live. A programme that already discloses granular revenue breakdowns every few months has no excuse to go quiet on security metrics the moment they might look less flattering.
Bottom Line
The direction of travel is right. Estonia is scaling a genuinely useful digital-government export without discarding the vetting that keeps it from becoming a shell-company factory — it is swapping a weak, geographically unequal check for a stronger, more consistent one, not cutting a corner. Other governments experimenting with digital residency or remote onboarding should treat this as the template: don't just digitize the friction, replace it with a control that's actually stronger, and publish the results either way, good or bad.