top of page

Draft Criteria on Information Systems and Technological Infrastructure for Crypto Asset Service Providers Published

  • Writer: Vardar Şanlı
    Vardar Şanlı
  • Apr 14, 2025
  • 2 min read

The Draft Criteria on Information Systems and Technological Infrastructure for Crypto Asset Service Providers (the “TÜBİTAK Criteria”), prepared by the Informatics and Information Security Research Center of the Scientific and Technological Research Council of Turkey (the “TÜBİTAK”), was published on TÜBİTAK’s official website on April 14, 2025.


Within the scope of the TÜBİTAK Criteria, the focus is primarily placed on the security standards for crypto asset wallets, as well as on regulations concerning information security and infrastructure systems. In this context, detailed provisions have been introduced regarding wallet access control procedures and the security of wallet software. The key topics outlined under these criteria are as follows:


1. Security Standards for Wallets


The criteria that private keys stored in cold wallets must meet are specified in detail, and distinct security requirements have been introduced for both custodian entities and platforms with respect to cold and hot wallets. Specific rules have been set forth regarding the generation, storage, encryption, and backup of private keys, including the implementation and use of Hardware Security Modules (HSMs) and secure enclave environments.


Pursuant to the regulations of the Capital Markets Board of Türkiye (the “CMB”) and TÜBİTAK, wallet access control procedures must be completed before any crypto asset transfer is executed; this includes verification that transfer instructions have been authorized by designated personnel and that identity authentication is carried out using mobile devices, smart cards, or similar equipment that are dedicated solely to this purpose and can be remotely managed by the custodian entity.


2. Information Security Standards


The TÜBİTAK Criteria introduce a set of additional information security requirements to be applied alongside the provisions set forth in the CMB’s Communiqué on the Principles and Procedures Regarding the Management of Information Systems. These additional measures include, among others, requirements concerning physical and environmental security such as the obligation to host critical software related to cold wallets within data centers under both primary and secondary systems as well as provisions related to cloud services, data confidentiality, and data protection.


3. Transitional Provisions


The TÜBİTAK Criteria also set forth a number of transitional provisions intended to ensure the practical implementation of requirements concerning cryptographic mechanisms, Hardware Security Modules (HSMs), and software security during the application phase for operational authorization by crypto asset service providers. The draft is expected to be finalized by the end of April following the evaluation of feedback from industry stakeholders and the CMB.


bottom of page