[codicts-css-switcher id=”346″]

Global Law Experts Logo
crypto licensing saudi arabia

Talk with Our Expert

Legal professional smiling at desk with a globe and legal-themed decor in modern office setting.

Jonathon Richards

Global Law Experts

Lead Enquiries Qualification
Delete Article

Crypto Licensing in Saudi Arabia: SAMA, CMA, Sandbox & Market-entry (2026)

By Jonathon Richards
– posted 1 hour ago

Introduction, What this guide covers and who it’s for

Crypto licensing Saudi Arabia is now a concrete regulatory pathway rather than a theoretical question, and this guide is written for firms, in-house counsel and advisers preparing to authorise virtual asset activity in the Kingdom during 2026. It consolidates the positions of the Saudi Central Bank (SAMA) and the Capital Market Authority (CMA) into a single, practitioner-led roadmap, covering regulatory boundaries, sandbox admission, AML/CFT obligations, entity structuring and a step-by-step authorisation process. The aim is to replace scattered regulator notices with one dated, actionable reference.

Whether you operate an exchange, a custody platform, a payments-integrated wallet or a tokenisation pilot, understanding crypto licensing Saudi Arabia means understanding which regulator applies to your activity and how to sequence your application. This guide maps that sequence end to end.

Why 2025–26 changes matter

Three developments make this period decisive. First, the CMA’s regulatory sandbox and FinTech experimentation framework have broadened the scope for market-testing novel virtual asset products under controlled conditions. Second, supervisory boundaries between the CMA (securities-type and investment activities) and SAMA (payments, money transmission and prudential oversight of licensed payment entities) have become clearer in published guidance. Third, AML/CFT expectations have tightened in line with FATF standards, raising the compliance bar for applicants.

Is crypto legal in Saudi Arabia? There is no outright prohibition on holding virtual assets, but regulated financial activity involving virtual assets requires authorisation. SAMA has repeatedly cautioned the public that virtual currencies are not recognised as legal tender and are not regulated as official payment instruments, while permitted activity must be conducted within the perimeters set by SAMA and the CMA. In short: participation is possible, but offering regulated services demands a licence or sandbox admission.

Regulatory framework for virtual assets in Saudi Arabia (2026 snapshot)

The architecture of virtual asset regulation Saudi Arabia rests on two pillars, the CMA and SAMA, operating alongside statutory texts published in the Official Gazette and a national AML/CFT framework aligned to FATF. There is no single consolidated “virtual asset act”; instead, activities are regulated according to their economic substance. A trading venue or token that behaves like a security falls toward the CMA; a payment, remittance or e-money function falls toward SAMA. This substance-over-form approach is the single most important concept for anyone planning crypto market entry Saudi Arabia.

Capital Market Authority (CMA), remit and instruments

The CMA regulates securities and investment activities. Where a virtual asset constitutes a security, or where an activity amounts to dealing, arranging, managing, advising on or providing custody of securities-type assets, the CMA is the lead authority. The CMA’s Financial Technology Experimental Permit (FinTech ExPermit) framework allows firms to test innovative products within defined limits. CMA virtual assets supervision in 2025–26 has focused on tokenised securities, distributed-ledger market infrastructure and investor-protection conditions attached to sandbox permits. Applicants should track CMA rule notices and board resolutions, citing circular numbers and dates in their application dossiers.

Saudi Central Bank (SAMA), remit and instruments

SAMA supervises banks, payment service providers and the broader payments ecosystem. SAMA crypto regulations are most relevant where a virtual asset product embeds payment functionality, stored value, remittance, settlement or e-money. SAMA operates its own regulatory sandbox for payment and banking innovation and issues AML/CFT guidance applicable to the entities it licenses. SAMA has also publicly warned against unregulated virtual currency schemes, reinforcing that payment-adjacent crypto services must be conducted through SAMA-authorised structures. Custody models that interact with fiat settlement rails frequently engage SAMA’s expectations in parallel with CMA requirements.

How the two authorities coordinate

Because many virtual asset business models blend investment and payment features, the CMA and SAMA coordinate through supervisory boundaries and referral mechanisms. In practice, an applicant with a hybrid model may engage both regulators, for example, a platform offering tokenised investment products (CMA) that also enables fiat on/off-ramps and stored value (SAMA). Early scoping conversations help determine whether a single-regulator route, a joint sandbox or a dual-authorisation path applies. Resolving this coordination question before filing prevents months of duplicated work. Consult our analysis of SAMA vs CMA roles for worked examples of boundary-setting.

Legislative and policy sources to rely on

  • CMA rule notices and board resolutions: for securities-type classification and sandbox conditions, cited by notice number and date.
  • SAMA circulars and the Payment Services Provider framework: for payment functionality, custody-settlement interaction and AML expectations.
  • Official Gazette (Umm al-Qura): for enacted statutes, royal decrees and formal amendments affecting financial-services regulation.
  • FATF guidance: the international risk-based standard that Saudi AML/CFT requirements transpose domestically.
  • National Cybersecurity Authority (NCA) policies: for data-residency and cyber-resilience obligations.

Grounding every regulatory claim in a dated primary source is not merely good practice, it is the difference between an application that regulators treat as credible and one that invites avoidable queries.

Market-entry: structuring, entity choice and go-to-market priorities

Before any licensing application, applicants must resolve how to establish a presence. Crypto market entry Saudi Arabia begins with an entity decision that interacts directly with foreign-investment rules administered through the Ministry of Commerce and the investment licensing regime. The structuring choice shapes capital, governance, tax posture and the speed at which a licence can follow.

Entity options and commercial pros and cons

  • Saudi limited liability company: the most common vehicle for regulated financial activity, offering a clean local substance footprint and a natural home for a licensed entity, but requiring commercial registration and governance set-up.
  • Branch of a foreign company: can be faster to establish for some activities but may face constraints where the regulated activity requires a locally incorporated, separately capitalised entity.
  • Joint venture with a local partner: useful for distribution, market credibility and navigating sector-specific expectations, while introducing shareholder-governance complexity that must be reconciled with fit-and-proper rules.

Key commercial checks

Whatever the vehicle, several commercial checks run in parallel with licensing. Confirm whether a local partner or local directorship is expected for your activity; decide the licensing route (CMA, SAMA or sandbox); assess tax and employment obligations, including payroll and work-visa planning for inbound teams; and address data localisation and cybersecurity obligations early, because remediating infrastructure late in the process is costly. For jurisdiction selection, our comparative guides: UAE, UK set out where the Kingdom’s framework diverges from neighbouring hubs, and our resource on tax & employment for crypto firms in Saudi covers workforce planning.

How to get authorised: step-by-step process for crypto licensing in Saudi Arabia

The following numbered process reflects a realistic path to authorisation. Treat it as a sequencing framework; exact requirements depend on activity type and whether you pursue a full licence or sandbox admission. For a document-level breakdown, see our step-by-step licensing checklist.

  1. Pre-engagement and regulatory scoping. Map your business model against CMA and SAMA remits to determine the regulatory perimeter. Prepare a concise regulatory analysis memo, a product description and a preliminary compliance overview, then request preliminary meetings. Early, well-documented engagement signals credibility and surfaces classification issues, particularly whether your token or activity is securities-type, before you commit to a filing route.
  2. Choose licence type and lead regulator. Decide whether the CMA, SAMA or a joint pathway applies. Securities-type trading, arranging, management, advice and custody point toward the CMA; payment, remittance, stored-value and e-money functionality point toward SAMA. Hybrid models may require dual engagement. Confirming the lead regulator early prevents duplicated documentation and misaligned capital and governance assumptions later in the process.
  3. Corporate formation and governance set-up. Incorporate the appropriate entity and establish governance: a board with the required composition, senior managers who satisfy fit-and-proper standards, defined shareholding and any local-director expectations. Governance documents, board charter, delegation matrix, conflicts policy, should be ready for regulator review. A credible governance framework is scrutinised closely for financial-services applicants.
  4. Technical and operational readiness. Build the operating backbone: your custody model (hot/cold wallet architecture, key management, segregation of client assets), AML systems, transaction-monitoring tooling and a cybersecurity baseline aligned to National Cybersecurity Authority expectations. Regulators increasingly expect evidence of working systems rather than policy documents alone, so demonstrable readiness strengthens the application materially.
  5. Documentation bundle. Assemble the core dossier: application forms, business plan and financial projections, governance and ownership documents, AML/CFT policy and procedures, risk assessment, custody and safeguarding policy, cybersecurity and business-continuity plans, outsourcing arrangements and consumer-protection disclosures. Completeness here is the single biggest determinant of review speed; gaps generate query rounds.
  6. Sandbox application (if applicable). Where a product is novel or market-testing is appropriate, apply for sandbox admission through the CMA’s experimental permit framework or SAMA’s innovation sandbox. Sandbox filings emphasise proof of concept, a limited and clearly bounded scope, defined customer caps and consumer-protection safeguards. Admission grants a limited-operational authorisation with reporting obligations and an exit plan toward full licensing. This is often the fastest route to live operations for innovative models.
  7. Review, inspections and queries. Expect iterative review. Regulators issue queries, request clarifications and may conduct inspections of systems and controls. Respond promptly with evidence, and treat remediation rounds as an opportunity to demonstrate a maturing control environment. Well-organised applicants who maintain a single source of truth for their dossier move through this phase considerably faster.
  8. Final authorisation and post-licence conditions. On approval, you receive the authorisation subject to conditions: reporting cadence, capital maintenance, periodic audits, AML independent review and consumer-protection obligations. Build operational capacity to meet these from day one, ongoing supervision begins immediately, and early non-compliance undermines regulator confidence in a newly licensed entity.

Typical timelines and where delays occur

Full CMA-route authorisation for trading, exchange or custody activity commonly runs six to twelve months from first engagement to licence, depending on completeness and complexity. Payment-overlay routes engaging SAMA typically range from four to nine months. Sandbox admission is faster, frequently three to six months. Delays concentrate in three areas: incomplete documentation that triggers repeated query rounds; unresolved classification questions (securities vs payment) that should have been settled during scoping; and technical readiness gaps where custody or AML systems are described but not demonstrated. Front-loading these three areas is the most reliable way to protect the timeline for crypto licensing Saudi Arabia.

At-a-glance comparison: CMA licence vs SAMA oversight vs sandbox

Route Regulator Key requirements Typical timeline Best for
Full VASP licence (trading, exchange, custody) CMA Capital, governance, AML program, local entity 6–12 months Exchanges, custody providers
Payment or e-money overlay services SAMA (where payment functionality exists) PSP requirements, client-money segregation, AML 4–9 months Payment-integrated crypto services
Regulatory sandbox admission CMA / SAMA (joint or single) Proof of concept, limited scope, consumer protections 3–6 months New products, pilots, market-testing

Choosing a route depends on your activity’s economic substance and your appetite for a phased launch. Innovative models with uncertain classification often benefit from entering via the sandbox, proving the concept under limited scope, then converting to a full licence with a track record in hand. Payment-integrated services should assume SAMA engagement early. Upfront costs vary widely with complexity, expect material investment in legal scoping, systems build, external audit and ongoing compliance staffing. Rather than relying on speculative figures, obtain current fee schedules directly from the relevant regulator and budget conservatively for the systems and governance infrastructure that underpin any crypto licensing Saudi Arabia application.

Eligibility checklist and statutory requirements

Eligibility turns on corporate substance, credible governance, financial strength and demonstrable local presence. The specifics scale with activity risk, a custody provider faces more demanding prudential and safeguarding expectations than a narrowly scoped sandbox pilot.

Corporate and ownership thresholds

Applicants generally require a properly incorporated Saudi entity with transparent ownership. Ultimate beneficial ownership must be disclosed and verifiable, and ownership structures should withstand fit-and-proper and source-of-funds scrutiny. Opaque or layered holding arrangements are a recurring cause of application friction and should be simplified before filing.

Governance and fit-and-proper

Directors and senior managers must satisfy fit-and-proper standards covering integrity, competence and financial soundness. Expect to evidence relevant experience in financial services, risk and compliance leadership, and a governance framework with clear accountability. A dedicated, suitably senior compliance function, including an identifiable money-laundering reporting officer, is effectively mandatory for VASP-type authorisation.

Minimum capital and prudential expectations

Regulated activities carry capital and prudential expectations proportionate to risk. Custody and trading models attract higher expectations than advisory or limited sandbox activity. Because capital thresholds are set by regulator rule and may be updated, applicants should confirm the current figures against the relevant CMA or SAMA instrument rather than relying on secondary summaries, and should plan for ongoing capital maintenance, not just a one-off minimum at authorisation.

Local presence, data requirements and licensing exclusions

Local substance, staff, management and operational control within the Kingdom, is expected, alongside data-residency and cybersecurity obligations shaped by National Cybersecurity Authority policy. Distinctions between retail and institutional offerings also matter: retail-facing services typically trigger heightened consumer-protection conditions, and some activities may be excluded from certain routes. Clarify any exclusions applicable to your model during pre-engagement.

AML/CFT requirements for VASPs in Saudi Arabia (2026 update)

AML obligations crypto Saudi applicants must meet are among the most heavily scrutinised elements of any file. Saudi Arabia’s framework transposes FATF’s risk-based approach to virtual assets and VASPs, and 2025–26 supervisory practice has reinforced expectations around monitoring, screening and reporting. A robust, risk-calibrated AML/CFT program is not an add-on; it is a precondition for authorisation. Our AML/CFT compliance playbook for VASPs expands each element below into operational detail.

FATF obligations transposed domestically

Core obligations include customer due diligence (KYC) at onboarding, ongoing monitoring of the business relationship, transaction monitoring calibrated to risk, and the filing of suspicious activity reports (SARs) with the national financial intelligence function. VASPs must also implement the FATF “travel rule” approach to originator and beneficiary information for virtual asset transfers, retaining and transmitting the required data to counterparties and authorities on request.

Enhanced due diligence and high-risk indicators

Enhanced due diligence applies to higher-risk relationships, politically exposed persons, high-risk jurisdictions and anonymity-enhancing products. Virtual-asset-specific indicators include use of mixers or privacy coins, structuring across multiple wallets, rapid pass-through of funds, and interactions with sanctioned or dark-market addresses. Firms should document how blockchain analytics feed risk scoring and when EDD or offboarding is triggered.

Reporting lines, record-keeping and sanctions screening

Clear reporting lines run to the money-laundering reporting officer and ultimately the board. Record-keeping obligations require retention of identification, transaction and SAR records for the statutory period. Sanctions screening must cover customers, counterparties and, where feasible, on-chain addresses, with screening repeated on list updates. Governance should evidence board-level oversight of AML risk, not merely delegation to a compliance team.

Practical compliance checklist and technology considerations

  • Documented AML/CFT policy and enterprise-wide risk assessment, reviewed and approved at board level and updated as risk evolves.
  • KYC/KYB onboarding tooling with identity verification, UBO identification and sanctions/PEP screening from a credible vendor.
  • Transaction-monitoring and blockchain-analytics capability to detect high-risk patterns and support travel-rule compliance.
  • SAR workflow and escalation procedures, with defined timelines and a named reporting officer.
  • Training and independent review, including periodic staff training and an independent audit of the AML program.

Because Saudi AML/CFT guidance continues to be refined, applicants should align their program to the latest FATF standards and verify any domestic updates against official AML/CFT committee and regulator publications before finalising policies.

Ongoing supervisory expectations (reporting, audits, consumer protection)

Authorisation is the beginning of a supervised relationship. Licensed entities must maintain the systems, capital and governance that justified their licence and evidence this continuously. Supervisory expectations span prudential reporting, periodic audit, consumer protection and operational resilience.

Data protection, cyber resilience and localisation

VASPs must sustain cybersecurity controls aligned to National Cybersecurity Authority policy, including incident response, access controls and resilience testing, alongside data-residency obligations where applicable. Given custody and transaction-data sensitivity, cyber and data obligations are a standing supervisory focus rather than a point-in-time check.

Prudential reporting, capital maintenance and complaint handling

Expect regular prudential and AML reporting on the cadence set at authorisation, maintenance of required capital, periodic external audit and independent AML review, and a documented complaint-handling and consumer-protection process. Firms that embed these from day one preserve regulator confidence; those that treat them as afterthoughts invite intensified supervision. Sustained compliance is the practical hallmark of a well-run crypto licensing Saudi Arabia operation.

Next steps for applicants and advisory partners

Successful crypto licensing Saudi Arabia hinges on resolving classification, substance and compliance before filing. Begin by scoping your model against CMA and SAMA remits to confirm the lead regulator, then prepare a board-approved AML/CFT program and risk assessment grounded in FATF standards. Request a pre-application meeting with a concise regulatory memo and product description, and decide whether a full licence or sandbox admission best fits your maturity. In parallel, settle your entity structure, governance and cybersecurity baseline so that systems are demonstrable, not merely documented. Approached methodically, crypto licensing Saudi Arabia is a navigable pathway into one of the region’s most strategically significant markets.

Sources

FAQs

Is crypto legal in Saudi Arabia?
Holding virtual assets is not prohibited, but regulated financial activity requires authorisation. SAMA has cautioned that virtual currencies are not legal tender and are not recognised as regulated payment instruments, so permitted services must operate within SAMA and CMA perimeters.
Scope your model against CMA and SAMA remits, choose the lead regulator, incorporate and set up governance, build AML and custody systems, assemble a complete documentation bundle, then apply (or enter the sandbox) and manage review and post-licence conditions. The process section above details each step.
It depends on activity substance. Securities-type trading, arranging, management, advice and custody point toward the CMA; payment, remittance and e-money functionality point toward SAMA. Hybrid models may require engagement with both authorities through their coordination mechanisms.
VASPs must implement KYC, ongoing and transaction monitoring, SAR reporting, sanctions screening and the FATF travel rule, supported by a board-approved risk assessment. Next step: build a documented program and verify current domestic AML guidance before filing.
The sandbox allows controlled market-testing of novel products under a limited-operational authorisation, with defined scope, customer caps, consumer protections, reporting duties and an exit path to full licensing. Admission typically takes around three to six months via CMA or SAMA frameworks.
Core documents include application forms, a business plan and financials, governance and ownership records, AML/CFT policies and risk assessment, custody and safeguarding policies, cybersecurity and continuity plans, and consumer-protection disclosures. See the step-by-step licensing checklist for the full dossier.

Our Expert

Legal professional smiling at desk with a globe and legal-themed decor in modern office setting.

Jonathon Richards

Global Law Experts

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Crypto Licensing in Saudi Arabia: SAMA, CMA, Sandbox & Market-entry (2026)

Send welcome message

Custom Message