A tokenization platform is the software and legal plumbing that lets an issuer represent ownership of a real-world asset, such as a fund share, a bond or an interest in a property company, as a token on a blockchain, while still enforcing who may hold it, who may receive it and what the official register says. The token contract is the smallest part of the job. Identity, compliance, the record of ownership and the movement of cash are where the work is.
What changed between the first STO wave and 2026
The 2018–2020 security token wave promised instant liquidity for illiquid assets and mostly failed to deliver it. Issuers tokenized small private deals, investors could not find buyers, and the regulated trading venues had little volume. The ideas that survived are narrower and more practical.
The growth since then has come from tokenized cash-like instruments: money market funds and short-dated government debt issued on public chains by large asset managers, such as Franklin Templeton's on-chain government money fund and BlackRock's BUIDL fund (launched in 2024 with Securitize as transfer agent). Private credit, tokenized gold and fund share classes followed. What these products have in common is that the asset already had a clear legal wrapper and a regulated manager; the blockchain improved settlement, transferability and use as collateral rather than inventing a new kind of asset.
Policy also moved. The EU's DLT Pilot Regime has applied since March 2023, giving market infrastructures a sandbox for DLT-based trading and settlement. In the US, the GENIUS Act (signed July 2025) created a federal framework for payment stablecoins, which matters to tokenization because the cash leg of a tokenized trade increasingly settles in stablecoins. If you are designing a platform today, assume that institutions, not retail speculators, are your first customers.
The components of a tokenization platform
Whether you build or license one, a credible platform has the following layers. Missing any of them usually means the gap is being filled by spreadsheets and email.
| Layer | What it does | Typical implementation |
|---|---|---|
| Issuer workspace | Set up the instrument, terms, share classes, supply, lockups | Web app over a relational database; terms mirrored into contract parameters |
| Investor onboarding | KYC, AML screening, accreditation or professional-investor checks, tax forms | Third-party KYC provider plus an internal case-management queue |
| Identity registry | Maps wallets to verified investors and their eligibility claims | ONCHAINID claims (with ERC-3643) or an allowlist contract |
| Token and compliance contracts | Block non-compliant transfers, support freezes, forced transfers and recovery | ERC-3643, ERC-1400 family, or ERC-20 with transfer hooks |
| Register of record | The legally authoritative ownership record | Registered transfer agent or registrar, reconciled with on-chain state |
| Custody | Safekeeping of the underlying asset and of investor keys | Qualified custodian for assets; MPC or HSM-based wallets for tokens |
| Cash and settlement | Subscriptions, redemptions, distributions | Bank rails, stablecoins, or both; NAV or price oracle for funds |
| Corporate actions | Dividends, coupons, votes, splits, redemptions at maturity | Snapshot-based distribution contracts plus off-chain reporting |
| Secondary trading | Peer transfers or venue trading within the rules | Bulletin board, ATS or MTF partner, or permissioned AMM |
| Reporting and audit | Regulatory filings, investor statements, auditor access | Indexer over chain events plus a reporting warehouse |
Permissioned token standards
A plain ERC-20 lets anyone send tokens to anyone. Securities cannot work that way, so tokenization platforms use contracts that check a rule set before each transfer. ERC-3643 (originally the T-REX framework) has become the most common open standard for this: every transfer calls an identity registry to confirm the receiver is verified and eligible, then a modular compliance contract checks limits such as maximum holders, country restrictions or holding periods. It also defines agent roles that can freeze balances, pause the token or force a transfer when a court order or lost key requires it.
The older ERC-1400 family split the problem into partitions (for tranches or lockups), document references and transfer restriction codes. It still appears in existing deployments. Some issuers simply use ERC-20 with an allowlist and an owner-controlled transfer hook, which is easier to integrate with wallets and DeFi but pushes more of the policy into custom code that needs a careful smart contract audit.
Whatever you choose, the token is a mirror of the legal register, not a replacement for it, unless your jurisdiction explicitly recognizes ledger-based securities (Switzerland's DLT Act and Germany's electronic securities law are examples). Design reconciliation between the two from day one.
The transfer agent problem
In the US, issuers of registered securities, and many private issuers, rely on a transfer agent to maintain the official shareholder register. Several tokenization firms registered as transfer agents with the SEC precisely so that the on-chain record and the legal record could be the same operation. If you build your own platform, you either become a transfer agent (a regulated activity with books-and-records duties), contract with one that accepts blockchain records, or accept that the token is a convenience copy of a register kept elsewhere.
Custody and key recovery
Two custody questions get confused. The first is who holds the underlying asset: the treasury bills, the building, the painting. That is a traditional custody or trustee arrangement. The second is who holds the keys controlling investor tokens. Institutions will use their own qualified custodian or an MPC wallet provider; retail investors will lose keys, so the platform needs a documented recovery path that uses the forced-transfer function after re-verifying identity. Without it, a lost key is a lost security, which no regulator will accept. Our guide to crypto wallet development covers MPC and HSM trade-offs in more depth.
Which chain?
Most institutional tokenized funds have launched on Ethereum mainnet or on EVM networks such as Polygon, Avalanche, Arbitrum and Base, with Stellar, Solana and purpose-built ledgers like Canton and Provenance also in use. The decision factors are practical:
- Where the buyers and collateral venues are. A tokenized fund that DeFi protocols or exchanges accept as collateral is worth more than one stranded on an isolated chain.
- Privacy. Public chains expose holdings and flows. Some issuers accept that; others need permissioned networks or privacy layers.
- Operational control. Permissioned token contracts on a public chain give you transfer control without running infrastructure. A private network gives you more control and far less composability. See private blockchain development for that trade-off.
- Multi-chain issuance. Issuing on several chains multiplies reconciliation and bridge risk. Start on one, add others only when demand is proven.
Building a tokenization platform, step by step
- Fix the legal structure first. Decide the asset, the wrapper (fund, SPV, note), the offering exemption or license, the investor types and the jurisdictions. Every technical decision below depends on these answers.
- Map the rules into a compliance matrix. List each restriction (eligible investor types, country blocks, holding periods, holder caps, lockups) and decide whether it is enforced on-chain, off-chain, or both.
- Pick the token standard and chain. ERC-3643 or equivalent unless you have a strong reason not to; a chain chosen for distribution, not novelty.
- Design the register and reconciliation. Decide which record is authoritative, how the transfer agent sees on-chain events, and how mismatches are resolved.
- Build onboarding and identity. Integrate KYC/AML, accreditation checks and wallet binding; issue on-chain eligibility claims only after verification.
- Wire up cash. Subscription and redemption flows, bank and stablecoin rails, NAV calculation for funds, distribution logic.
- Audit and test failure modes. External audit, plus drills for lost keys, sanctioned holders, court-ordered transfers, paused tokens and chain reorganizations.
- Launch narrowly. One asset, one chain, one investor class. Expand after the operating model works.
Cost and timeline drivers
There is no honest single price, but you can reason about it. A minimal in-house platform for one asset type, using an audited ERC-3643 implementation and licensed KYC and custody, typically needs a team of roughly two backend engineers, one smart contract engineer, one frontend engineer, a product lead and part-time compliance and legal input. At four to six months for a first production release, that is somewhere around 25 to 35 person-months of engineering before legal fees, audits and vendor licenses. The things that move the number most:
- Number of jurisdictions and investor classes (each adds rules and onboarding variants).
- Whether you need to become, or integrate with, a transfer agent or regulated trading venue.
- Custom compliance logic beyond what the standard's modules already cover.
- Secondary trading, which is a separate regulated business in most places.
- Fiat integration and reconciliation with banks.
Build vs buy
Licensed tokenization platforms and white-label issuance software exist, and for a single issuer they are almost always cheaper than building. Building makes sense when tokenization is your product (you plan to serve many issuers), when you need a regulatory status a vendor cannot give you, or when your asset has mechanics no vendor supports. A sensible middle path is to license the regulated pieces (transfer agency, KYC, custody) and build the investor experience and asset-specific logic yourself. The related DeFi tokenization guide covers the case where you want tokenized assets to plug into lending and AMM protocols.
What to ask a vendor or development team
- Which token standard do you deploy, and has the exact code been audited? Can we see the reports?
- How are freezes, forced transfers and key recovery authorized, and who holds those roles?
- Which record is legally authoritative, and how is it reconciled with the chain?
- Which regulatory licenses do you or your partners hold, in which jurisdictions?
- Can we export the cap table and migrate the tokens if we leave?
- Which tokenized offerings are live on your stack today, and can we talk to those issuers?
When not to tokenize
If your investors are a few dozen people who will never trade, and no counterparty will accept the token as collateral, tokenization adds cost and regulatory surface without much benefit. Tokenization helps most when transfers are frequent, settlement is slow or expensive today, or the token unlocks new distribution or collateral uses. For a deal-level walk-through, see tokenized asset offerings and the legal overview in security token offerings.
Frequently asked questions
Is a tokenization platform the same as an NFT marketplace?
No. An NFT marketplace lets anyone list and buy collectibles with minimal checks. A tokenization platform issues regulated instruments, verifies every holder and blocks non-compliant transfers. Some real-estate projects use NFTs as deed-like records, but the investor-facing product is usually a permissioned fungible token.
Does putting an asset on a blockchain make it legally owned on-chain?
Usually not. In most jurisdictions the token represents a claim recorded elsewhere, such as shares in an SPV or units in a fund. A few legal systems, including Switzerland and Germany, recognize ledger-based securities directly, and even there the issuance must follow specific rules.
Why ERC-3643 rather than ERC-20?
ERC-3643 checks identity and compliance rules on every transfer and defines agent roles for freezing and recovery. You can replicate this on ERC-20 with custom hooks, but you then own the design and audit of that logic, and integrators will not recognize it as a standard.
Can tokenized securities be used in DeFi?
Only where the receiving contract is an eligible holder. Some lending protocols and permissioned pools have whitelisted tokenized treasury funds as collateral. Open, permissionless pools generally cannot hold permissioned tokens because the pool contract itself fails the identity check.
How long does it take to launch a first tokenized product?
On a licensed platform, the legal structuring usually dominates and can take a few months. A custom-built platform adds roughly four to six months of engineering for a narrow first version, plus audit time.
Do we need a stablecoin for settlement?
No, but it helps for 24/7 settlement and on-chain atomic delivery-versus-payment. Many platforms support both bank wires and regulated stablecoins.