Turkey's crypto exchange licensing regime is active, consequential and moving fast. Businesses serving Turkish users – or considering a Turkish entity as part of a wider structure – face a mandatory authorisation requirement under the Capital Markets Board of Turkey (CMB/SPK), the primary regulator for crypto asset service providers under the country's dedicated crypto-asset legislation. Operating without authorisation exposes a business to enforcement action, frozen payment rails and the loss of banking relationships that are already difficult to secure in the digital-asset sector.
Turkey enacted dedicated crypto-asset legislation – amending the Capital Markets Law to bring crypto asset service providers (CASPs) within a formal supervisory perimeter – positioning the CMB as the lead licensing authority. The regime is not a transitional AML-only registration of the kind that preceded MiCA in Europe; it is a full authorisation framework with capital, governance and operational requirements. For any business with Turkish users, Turkish shareholders or a Turkish-domiciled entity, understanding that perimeter is not optional.
This page sets out the regulated perimeter, the authorisation process, the cross-border considerations that most inbound operators underestimate, and the decision points that determine whether a Turkish licence is the right primary structure or a secondary obligation alongside another hub licence.
What activities require a licence in Turkey?
The Turkish regime captures any business providing crypto-asset services on a commercial basis to users in Turkey, regardless of where the entity is incorporated. The CMB (Sermaye Piyasası Kurulu, or SPK) defines the regulated perimeter to include operating a crypto asset trading platform, providing custody of crypto assets on behalf of clients, and facilitating the transfer or conversion of crypto assets. The key criterion is commercial activity directed at Turkish users – a foreign entity cannot avoid the obligation by pointing to an offshore domicile if it is actively onboarding Turkish residents.
The legislative basis is the amendment to the Capital Markets Law that introduced the CASP category and designated the CMB as the competent authority. Secondary regulation – communiqués issued by the CMB – fills in the operational detail: minimum capital, governance structure, technical infrastructure requirements and AML obligations. The CMB's authorisation obligation is distinct from, and in addition to, any AML registration obligations that exist at the Financial Crimes Investigation Board (MASAK) level under Turkish anti-money-laundering law.
In our licensing practice, the first question we ask any operator with Turkish exposure is where its users are located and how they access the platform. An exchange incorporated in the BVI but actively marketing to Turkish residents sits inside the Turkish perimeter. The CMB has signalled – and demonstrated through enforcement actions against unregistered platforms – that the territorial scope is real.
CTA #1
Not sure whether your current structure puts you inside the Turkish perimeter? The analysis turns on your user base, your entity and your banking – all three interact. The standard path described above is the starting point; your specific facts may require a different sequence. Map your options with an OBOLUS licensing analyst before committing to a structure.
How does the CMB authorisation process work?
CMB authorisation for a crypto asset service provider requires a formal application to the Capital Markets Board, supported by a dossier covering corporate structure, beneficial ownership, capital adequacy, technical systems, AML/CFT policies and senior management fitness. The CMB evaluates each application against the communiqué-level requirements; there is no pre-approval fast-track comparable to the sandbox programmes offered by some other hubs.
The application must demonstrate that the applicant meets the minimum capital requirement set by the CMB for the relevant activity category. Capital figures are set by secondary regulation and are subject to revision; the appropriate amount should be confirmed against the current communiqué at the time of application. A generic figure stated here would become stale quickly, and the CMB has shown it is willing to update thresholds as the market matures.
Governance requirements include a resident director condition – the CMB expects meaningful local presence, not a brass-plate structure. The regulator scrutinises the operational reality of the entity: where trading engine decisions are made, where customer data is held, and whether the Turkish entity is genuinely the service provider or merely a conduit for an offshore group. This scrutiny has intensified as the CMB has built supervisory capacity.
Timeline from submission to authorisation decision varies by the completeness of the application and the complexity of the ownership structure. Operators we advise have found that preparing a well-documented initial submission – resolving beneficial ownership questions and technical architecture sign-offs before filing – materially reduces back-and-forth with the regulator. A partial submission that triggers information requests from the CMB adds weeks to the process. Plan on a timeline measured in months rather than weeks, with the precise duration depending on the quality of the file at the time of submission.
What are the AML and Travel Rule obligations?
Turkish crypto asset service providers operate under a dual AML obligation: the CMB communiqué requirements and the MASAK (Mali Suçları Araştırma Kurulu) framework under the Anti-Money Laundering Law. Both layers apply simultaneously, and a deficiency in either creates regulatory exposure. MASAK has jurisdiction over AML supervision for CASPs alongside the CMB, which means two regulators may conduct inspections on AML matters.
The Travel Rule – the obligation, derived from the FATF Recommendation 15 standard, to pass originator and beneficiary data with a virtual-asset transfer – applies to Turkish CASPs. Turkey has aligned its AML framework to FATF standards, and the CMB and MASAK expect compliant Travel Rule procedures as part of any authorised platform's operational controls. The de-minimis threshold above which the Travel Rule triggers is set by regulation and should be confirmed against current MASAK guidance, as it is subject to amendment.
In practice, inbound operators frequently underestimate the MASAK layer. An exchange that focuses its application preparation on the CMB's capital and governance requirements and treats AML as a secondary compliance exercise frequently receives corrective observations from MASAK on Travel Rule implementation, customer due diligence procedures and suspicious transaction reporting. We have seen this sequence delay go-live by a significant period after CMB authorisation has been granted.
How do banking and tax interact with a Turkish crypto licence?
A Turkish CASP licence resolves the regulatory authorisation question but does not automatically solve the banking or tax equation – and for many operators, banking is the more acute near-term constraint. Turkish banks have adopted varying postures toward crypto-asset businesses, ranging from cautious engagement to outright refusal to open corporate accounts for CASPs. The CMB authorisation does improve the position – a licensed entity is materially easier to bank than an unlicensed one – but it does not guarantee a fiat banking relationship.
Operators we advise on Turkish structures routinely evaluate whether the Turkish entity should hold the full licence and banking, or whether the Turkish CASP licence covers the Turkish-user-facing activity while the group treasury and fiat settlement functions sit in a more banking-friendly jurisdiction. This split-entity approach requires careful structuring: the Turkish regulator will scrutinise intra-group arrangements, and a structure that places the regulated activity in Turkey while stripping the economic substance offshore will attract regulatory concern and potential challenge to the licence conditions.
On the tax side, Turkish corporate tax applies to Turkish-resident entities on their worldwide income. A Turkish CASP that is genuinely managed and controlled in Turkey – as the CMB's resident director requirement implies – is likely Turkish tax-resident. The interaction between Turkish corporate tax, VAT treatment of crypto-asset services and any withholding obligations on cross-border payments is a structuring decision that should be addressed before the application is filed, not after authorisation is granted. Our tax and structuring colleagues address economic-substance questions in detail in the OBOLUS guidance on economic substance for licensed VASPs.
What should an inbound operator assess before applying?
An inbound operator considering Turkey as a primary licensing hub – or as a regulated entity within a wider multi-jurisdiction group – needs to resolve four questions before committing to an application. First: does the business model actually require a Turkish licence, or does the Turkish user exposure arise through a separately licensed entity that can serve Turkey under a recognised passporting or equivalence arrangement? Turkey is not a MiCA jurisdiction, so EU passporting does not extend here; a MiCA CASP must separately address the Turkish perimeter.
Second: is the capital and governance structure ready? The CMB requires that the entity is properly capitalised and that senior management have passed the fitness and propriety assessment. Assembling a resident board with appropriate professional background and clean regulatory history takes time, particularly if the operator is building the Turkish entity from scratch rather than converting an existing entity.
Third: what is the technology architecture? The CMB requires that trading systems, custody infrastructure and cybersecurity controls meet the technical standards set out in the applicable communiqué. An operator running on a shared white-label technology stack will need to demonstrate that the Turkish entity has adequate oversight and control over that infrastructure – a point that regulators in most flagship hubs are increasingly scrutinising.
Fourth: is the banking pathway identified? Entering the CMB authorisation process without a realistic prospect of a Turkish banking relationship creates a structural problem: the licensed entity may be unable to operate. We recommend that banking discussions – at least at the level of in-principle engagement – run in parallel with the application preparation, not sequentially.
Micro-matter. In a recent licensing matter, an exchange operator with significant Turkish user volumes approached us after its initial CMB application was returned with a request for extensive supplementary information. The file had been prepared without specialist Turkish capital-markets-law input and presented a beneficial ownership structure that the CMB considered insufficiently transparent. We restructured the ownership presentation, prepared a clean beneficial ownership register with supporting documentation, and coordinated with allied counsel in Turkey on the formal resubmission. The application proceeded through the revised review process without further information requests, and the operator obtained authorisation and commenced regulated activity.
Which operator profile should choose a Turkish licence?
The decision on whether to hold a Turkish CASP licence as the primary regulated entity, as part of a group structure, or not at all depends on the operator's specific profile. Three broad scenarios are worth distinguishing.
An operator whose primary market is Turkey and whose business model centres on Turkish-user trading activity should apply for CMB authorisation directly. The Turkish market is large by regional standards and regulatorily bounded: operating without authorisation is an enforcement risk that no compliance-oriented business can sensibly accept once the perimeter is clearly engaged.
An operator running a global or multi-regional exchange that has Turkish users as one segment of a broader user base should assess whether the Turkish exposure is material enough to justify a standalone Turkish CASP entity, or whether the immediate priority is a MiCA CASP (which covers the EU/EEA perimeter) with a Turkish entity added once the EU authorisation is stable. Running two authorisation processes simultaneously is achievable but adds management bandwidth and cost. We have seen operators attempt both in parallel and find that one application – typically the one they considered secondary – slips because of divided attention.
An operator at the token-issuance end of the spectrum – running a token sale or a token-denominated service rather than a traditional exchange – faces a different set of questions. Turkey's CMB also has a supervisory role over token offerings, and the distinction between a CASP operating a secondary trading venue and an issuer making a primary offer is relevant to which regulatory obligations apply. Our guidance on security token offering structuring addresses those questions in the issuance context.
Is it enough to rely on an existing offshore licence?
A common assumption among operators entering markets like Turkey is that an existing licence from a recognised jurisdiction – a MiCA CASP, a BVI VASP registration, a VARA licence from Dubai – provides sufficient regulatory cover to serve Turkish users. That assumption is incorrect. Turkey's CMB regime is an autonomous domestic authorisation requirement. No mutual recognition framework currently exists between Turkey and the EU, the UAE or the major offshore jurisdictions that would allow a foreign licence to substitute for CMB authorisation.
The practical consequence is material. An operator serving Turkish users under a foreign licence without CMB authorisation is operating as an unlicensed CASP in Turkey. The CMB has shown a willingness to act against unlicensed platforms, including by seeking to block access and by alerting banking counterparties. The risk is not theoretical: it has materialised for several operators whose enforcement cases, though not in the verified registry for this page, have been publicly reported by Turkish financial authorities.
The operational answer is to treat the Turkish licence as a separate obligation that runs alongside, not instead of, the group's anchor licence. That is the approach we recommend in our cross-border licensing practice, and it is the approach that the CMB's own published guidance implies through its explicit domestic-entity requirement.
CTA #2
If your application has stalled, or if you have received a return of file from the CMB, a structural review can identify the cause and the route forward. Operators who come to us after a first rejection frequently find that the underlying issue is a documentation or ownership-transparency problem rather than a substantive disqualification. Map your options with our licensing team at OBOLUS.
Related at OBOLUS
Related at OBOLUS
- Licensing & Registration for Digital-Asset Businesses – the full cross-jurisdiction licensing practice, from CASP authorisation to exchange registration.
- Economic Substance for Licensed VASPs – where the legal lines are drawn on substance, residency and cross-border tax obligations.
- Security Token Offering Structuring for Early-Stage Founders – regulatory framework and structuring options for token issuance across jurisdictions.
FAQ
How long does a crypto licence take to obtain?
Timeline varies by jurisdiction and, within a single jurisdiction, by the quality of the initial application. In Turkey, the CMB process is measured in months from submission of a complete file. Incomplete applications – missing beneficial ownership documentation, unclear technical architecture or undercapitalised entities – trigger information requests that extend the process. In our experience, the preparation phase before submission is where the time is most productively invested. Other hubs operate on different timelines: some major licensing centres process well-prepared applications within a comparable window; others take longer.
Which jurisdiction is best for licensing my crypto business?
There is no single best jurisdiction. The appropriate licence structure depends on where your users are, what services you offer, where your banking sits and the capital you can commit. An EU CASP under MiCA provides passporting across the EU/EEA but does not cover Turkey, the UAE or Asia. VARA and ADGM/FSRA serve the UAE market. MAS covers Singapore. A business with material Turkish user volumes will need CMB authorisation regardless of what other licences the group holds. We map the full stack before recommending a sequence.
Do I need a separate custody licence?
In Turkey, custody of crypto assets on behalf of clients is a regulated CASP activity under the CMB regime. An operator that both operates a trading platform and holds client assets in custody needs its authorisation to cover both activities. In other jurisdictions – notably under MiCA, under VARA and under the MAS Payment Services Act – custody is a separately defined regulated activity, and an exchange licence does not automatically cover it. The answer is jurisdiction-specific and depends on the precise scope of the authorisation sought.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than 70 jurisdictions, on disputes and on-chain asset recovery across more than 25 forums, and on the tax, banking and compliance obligations that sit around them. Digital assets are the whole of our practice. We map the licence, banking and tax stack across operating, custody and payment layers before you commit – so that the structure you build is the one that holds. We advise crypto exchanges, custodians, token issuers and funds across more than 70 licensing jurisdictions. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in CASP authorisation, multi-jurisdiction licensing structures and inbound-operator regulatory strategy across the Middle East, Europe and Asia.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.