Access to the crypto market: the Bank of Russia approves requirements for digital depositories, crypto exchanges and DFA issuance operators

28 September 2026

Bank of Russia Regulation No. 890-P of 27 August 2026 adopted under Federal Law No. 282-FZ of 4 August 2026 “On Digital Currencies and Digital Rights”

On 23 September 2026 the Ministry of Justice registered Bank of Russia Regulation No. 890-P — one of the central pieces of secondary legislation under the Law on Digital Currencies and Digital Rights, the core provisions of which took effect on 1 September 2026. The Regulation answers three practical questions faced by anyone planning to operate within the Russian perimeter of the crypto market: who may head a digital currency exchange operator (crypto exchange), a digital depository or an operator of an information system in which DFAs are issued; what level of information security and operational resilience a prospective digital depository must ensure; and which documents, in what order and within what deadlines the Bank of Russia reviews before entering an applicant in the relevant register.

The Regulation enters into force ten days after its official publication — on 5 October 2026. Given that the key restrictions on residents, including the requirement to carry out transactions with digital currencies only through persons organising their circulation (part 1 of article 30 of the Law), will apply from 1 July 2027, the window for preparing and completing the registration procedure is in fact less than a year.

  • 30 business days — for a decision on a digital currency exchange operator
  • 60 business days — for a decision on a digital depository or an information system operator
  • 1 business day — under the fast-track procedure for entities covered by article 55 of the Law
  • 2 years of experience — minimum for the head of a digital depository or an operator

01. Who the Regulation applies to

Law No. 282-FZ admits to professional activity on the crypto market as digital depositories, crypto exchanges and DFA issuance operators only those entities entered in the registers maintained by the Bank of Russia. The Regulation establishes a single procedure for three categories of applicant and, separately, a fast-track procedure for the entities expressly named in the transitional provisions of the Law.

Applicant — Bank of Russia register — decision deadline — documents:

  • Digital currency exchange operator — Register of digital currency exchange operators — no later than 30 business days — Annex 1 to Regulation No. 890-P
  • Digital depository — Register of digital depositories — no later than 60 business days — Annex 2
  • Operator of an information system in which DFAs are issued (including one holding the status of an electronic platform operator) — Register of information system operators — no later than 60 business days — Annex 3
  • Existing operator acquiring the status of an electronic platform operator (settlements between beneficiaries through a nominal account) — Register of information system operators — no later than 30 business days — Annex 3
  • Entities covered by parts 3, 5, 7, 9 and 11 of article 55 of the Law (digital currency exchange, digital depository) — the relevant register — no later than the business day following the day the documents are received — Annex 4

The deadlines run from the date on which the last document is submitted — including documents requested by the Bank of Russia in the course of verification measures. In practice this means that an incomplete or poorly prepared package automatically pushes back the decision date.

02. Requirements for executives and key officers

Higher education is mandatory for every officer covered by the Regulation. The remaining requirements are differentiated by type of activity and by function, and the regulator deliberately allows for different entry paths: experience at financial institutions, at supervisory authorities, at foreign licensed crypto platforms and, for some positions, in the IT industry.

Sole executive body

The head of a digital depository or of an operator of DFA issuance must have at least two years of experience in one or more of the following roles: heading (or serving as deputy head of) a credit or non-credit financial institution, a professional securities market participant, an entity of the national payment system, a foreign bank or its branch; heading a foreign entity that services the circulation of digital instruments under a licence; heading a specialised division of a financial institution; or holding a senior position at the Bank of Russia, federal government bodies, government bodies of the EAEU member states, the Accounts Chamber, state corporations or public law companies — provided that the work related to the financial market or to financial technology.

For the head of a digital currency exchange operator the bar is lower — one year — and the experience counted includes acting as the sole executive body of the applicant itself as at the filing date, as well as heading an IT company or a specialised division within one. This allows the incumbent management of exchange services to pass the qualification filter without changing the team.

Collegial executive body

Members of the management board of a digital depository or an operator must either meet the requirements applicable to the head of the entity, or have at least two years of managerial experience at an entity active in information technology, software development or IT consulting, or experience heading a human resources division. These requirements do not apply to the deputy head of a digital depository responsible for information security.

Compliance officer, internal auditor, risk manager

A tiered scale applies to control functions: one year for persons who have headed a financial institution, an internal control, audit or risk management function, or a foreign licensed platform; two years for heads of specialised divisions (financial markets, accounting for digital assets, internal accounting, legal support) and for staff of control and audit functions; three years for ordinary staff of specialised divisions. Alternatively, experience at the Bank of Russia and at other financial regulators is counted and, for the compliance officer and the internal auditor, so is participation in the audit of financial institutions’ reporting during the two years preceding the filing.

Points to watch

Experience at the entities named in parts 3 and 5 of article 55 of the Law counts only if those entities retain that status as at the filing date. A foreign education requires a certificate of its recognition in the Russian Federation (save for the exceptions established by law), while foreign nationals and persons holding dual citizenship or a residence permit must produce certificates of no criminal record and no disqualification issued by the foreign state. The questionnaire of each officer must be signed with that officer’s own enhanced qualified electronic signature.

03. Information security and operational resilience of a digital depository

The requirements of Chapter 2 of the Regulation are the most resource-intensive for an applicant. A prospective digital depository must ensure information protection under GOST R 57580.1-2017 at no lower than the standard level and confirm compliance at no lower than the fourth level under GOST R 57580.2-2018, with the assessment carried out by an organisation holding an FSTEC licence for the technical protection of confidential information.

Access keys to identifier addresses may be generated and operated only with the use of hardware security modules that have passed conformity assessment against the requirements of the FSB. Application software and the applications that the depository distributes to its clients must be certified by FSTEC or carry an assurance level of no lower than EAL 4; in-house development need not be certified if the secure development process itself is certified under GOST R 56939-2024 (except for software that interacts with cryptographic protection tools).

In addition, the depository must log the actions of its employees and clients across every technological stage — from identification and authentication through to the storage of transaction data (recording identifiers, timestamps, transaction results and device data) — conduct regular penetration testing and vulnerability analysis, maintain protection against DDoS attacks, and build an organisational structure for operational resilience that excludes conflicts of interest and is subject to internal control.

04. The document package and the filing procedure

Documents are filed exclusively in electronic form through the interaction procedure established by the Bank of Russia and are signed with the enhanced qualified electronic signature of the applicant’s head or of a person authorised by them. Documents submitted by any other means are returned without review within seven business days. Foreign documents must be legalised or apostilled and accompanied by a notarised translation. Documents previously filed with the Bank of Russia that have not changed need not be refiled — it is enough to refer to the details of the covering letter.

  • Corporate block — application; constitutional document; information on shareholders (participants) holding more than 10%, on groups of persons and on controlling persons — under the rules of Bank of Russia Ordinance No. 7278-U
  • Personnel block — questionnaires of the head, the compliance officer, the risk manager and the special AML/CFT officer; documents on education, appointment and employment history for the past five years
  • Financial block — calculation of own funds as at a date no earlier than five business days before filing; financial statements and accounting registers (for non-credit institutions); for an operator — documents confirming payment of the charter capital
  • Technological block — confirmation of rights to the primary and backup software and hardware complexes, to the backup system and to the domain name; for an operator — rights to an information system that conforms to its rules
  • Rules and policies — exchange: information on the approval of internal AML/CFT control rules; depository: the terms of its activity and related internal documents, together with confirmation of compliance with Chapter 2 of the Regulation; operator: the information system rules and related documents

05. Verification measures

The Bank of Russia may conduct an on-site inspection of the applicant within the review period (save for an operator acquiring only electronic platform operator rights). Notice is given no later than one business day in advance and the inspection lasts up to five business days. The regulator’s staff request documents and explanations and also attend a demonstration of the functionality of the information infrastructure of the applicant. The applicant’s absence from its place of business, or a failure to take measures allowing the inspection to proceed unimpeded, is recorded in a report on obstruction, which is in itself a ground for refusal.

The Bank of Russia notifies the applicant of its decision in electronic form within three business days.

06. Additional grounds for refusal

Alongside the grounds named in part 8 of article 52 of the Law, the Regulation introduces a broad list of additional grounds for refusing entry in the register. They fall into three groups.

Quality of the application. Inaccurate information in the documents; failure of the applicant, its officers or its owners to meet statutory requirements, including qualification and information security requirements; the absence of primary and backup software and hardware complexes and of a backup system; a report on obstruction of an inspection.

Supervisory history. Bankruptcy or a liquidation decision; provisional administration; revocation of a banking licence; annulment of a licence or exclusion of a non-credit financial institution from a register less than three years ago; suspension of a licence during the past twelve months; for banks — classification in a group below the level set by Ordinance No. 4336-U; unfulfilled Bank of Russia orders concerning the non-compliance of officers or of owners of 10% or more of the shares (participatory interests); a repeat filing by a participant previously struck off the register before expiry of the period established by the Law.

Cyber and anti-fraud profile. The presence of information about the applicant’s head in the database of cases of, and attempts at, money transfers made without the client’s voluntary consent; unfulfilled orders concerning breaches of information protection, operational resilience and anti-fraud requirements.

07. Fast-track procedure for entities covered by article 55 of the Law

Entities named in parts 3, 5, 9 and 11 (digital currency exchange) and parts 3 and 7 (digital depository) of article 55 of the Law file a reduced package under Annex 4 — separately for each type of activity. A decision is taken no later than the business day following the day the documents are received; an incomplete package is left without review within the same period. The application contains the head’s representations that no disqualifying circumstances exist, including that the entity’s status as a participant in an experimental legal regime has not been suspended or terminated. Under this procedure a digital depository submits not evidence of compliance with Chapter 2 of the Regulation but an action plan for bringing its activities into line with information protection and operational resilience requirements.

Practical takeaway

The speed of the fast-track procedure is offset by its rigidity: one missing document and the application is left without review the very next day. For entities seeking to use it, it is critical to confirm in advance that they genuinely fall within the relevant part of article 55 and to assemble a package with no gaps.

08. What to do now

Completing the admission procedure is not a matter of filing an application but a project that involves shareholders, HR, finance, IT and information security at the same time. The longest path belongs to prospective digital depositories: conformity assessment under GOST R 57580, certification of software or of development processes and the procurement of hardware security modules all take considerable time. For exchange services the main risk lies in confirming the team’s qualifications and the ownership structure; for operators, in the information system rules and the confirmation of capital.

We recommend starting with a diagnostic review: determine the target status and whether the transitional provisions apply, check the candidates for key positions against Chapter 1 of the Regulation, disclose the ownership structure down to the ultimate beneficiaries, and draw up a roadmap that accounts for the review periods and a possible on-site inspection.

09. How Lidings can help

We support digital currency and digital rights market admission projects on a turnkey basis — from the choice of model through to entry in the register — and can join at any stage.

  • Diagnostic review and strategy — analysis of the business model and choice of status; assessment of whether the fast-track procedure under article 55 of the Law is available; gap analysis against the requirements of Regulation No. 890-P; roadmap and budget
  • Corporate preparation — disclosure and, where necessary, restructuring of ownership; preparation of information on shareholders and controlling persons; corporate resolutions of the governing bodies; calculation and confirmation of own funds together with the finance team
  • Personnel compliance — screening candidates against the qualification and business reputation requirements; preparation of questionnaires and supporting documents; legalisation, apostilling and translation of foreign documents, recognition of foreign education
  • Internal documents — internal AML/CFT control rules; terms of activity of a digital depository; information system rules of an operator; policies on internal control, audit and risk management
  • Information security and data — legal support for achieving compliance with Chapter 2 of the Regulation: contracts with FSTEC licensees, suppliers of hardware security modules and software developers; the action plan for the fast-track procedure; personal data compliance (Law No. 152-FZ)
  • Filing and inspection — assembly and filing of the document package under the established procedure for interaction with the Bank of Russia; preparation for the on-site inspection and for the demonstration of the infrastructure; responses to the regulator’s requests
  • After entry in the register — ongoing regulatory support, reporting, changes in officers and owners, and liaison with the Bank of Russia

Let’s discuss your project

We will run an initial diagnostic review and propose a roadmap for entry in the register tailored to your business model. Get in touch:

Dmitry Kirillov, Head of Tax and Digital Law practice, Lidings
DKirillov@lidings.com · +7 926 532 5680

This material has been prepared for information purposes only and does not constitute legal advice. The review is based on the text of Bank of Russia Regulation No. 890-P of 27 August 2026; before relying on it, we recommend checking against the officially published version.