EST · MMXXVI
Home/Jurisdictions/Turkey/Crypto exchange setup in Turkey: Legal Requirements for Businesses
Licensing & Registration

Crypto exchange setup in Turkey: Legal Requirements for Businesses

Crypto exchange setup in Turkey. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Operating a crypto exchange in Turkey without proper authorisation exposes the business to enforcement action, suspended banking rails and permanent exclusion from the market. Turkey's crypto exchange regulatory regime has tightened materially: the Capital Markets Board of Turkey (SPK – Sermaye Piyasası Kurulu) now requires domestic authorisation for any platform providing crypto asset services to Turkish residents. For an inbound operator, the question is not whether to engage the regime but how – and what the cross-border tax, banking and custody layers add to the structural design. This page maps the legal requirements, the application process and the decision points a business must resolve before committing resources to the Turkish market.

The Turkish Regulatory Regime for Crypto Exchanges

Turkey's primary regulatory authority for crypto asset services is the Capital Markets Board (SPK), which operates under amendments to the Capital Markets Law that extended its perimeter to cover crypto asset service providers (CASPs). The legal basis for crypto exchange authorisation sits within the SPK's published communiqués and the broader Capital Markets Law framework, which was formally amended to bring crypto assets within the SPK's supervisory scope. Separately, the Financial Crimes Investigation Board (MASAK) governs anti-money laundering and counter-financing-of-terrorism obligations for entities that touch Turkish users – including the Travel Rule (the obligation to pass originator and beneficiary data with each transfer). Any platform offering trading, custody or transfer services to Turkish residents falls within both perimeters simultaneously.

The regime is not permissive by design. Turkey's history of high retail crypto adoption – the country has consistently ranked among the highest globally in peer-reviewed survey data published by regulators and supranational bodies – combined with a period of enforcement against unregistered platforms drove the government toward a formal licensing structure. The SPK's communiqués now specify who must apply, what they must demonstrate and what they may do only once authorised.

For an inbound operator, the critical threshold question is whether the entity serves Turkish residents at all. If the answer is yes – regardless of where the legal entity is incorporated – the SPK authorisation requirement applies. Offshore structuring does not remove the obligation. It shifts the question to whether the foreign entity can satisfy SPK requirements or whether a Turkish legal entity must be established as the licensed vehicle.

MASAK's AML/CFT supervision runs in parallel and is not satisfied by SPK authorisation alone. Both obligations must be addressed in the compliance architecture from day one.

Who Needs SPK Authorisation in Turkey?

Any business that regularly provides crypto asset trading, brokerage, transfer or custody services to persons in Turkey requires authorisation under the SPK's crypto asset regime. The perimeter is activity-based, not entity-based. A platform incorporated in Estonia, the British Virgin Islands or the Cayman Islands that actively markets to or accepts Turkish residents is within scope. The SPK has demonstrated willingness to act against offshore platforms that operate in the Turkish market without authorisation – enforcement options include blocking orders and payment processor restrictions.

The categories of regulated activity include, at minimum: operating a crypto asset trading platform; providing order routing or brokerage; custodying crypto assets on behalf of clients; and transferring crypto assets as a service. Staking-as-a-service and yield products are under active regulatory development in Turkey, and the SPK's communiqués should be read at the time of application to assess whether a contemplated product line triggers additional requirements.

A common misconception among inbound operators is that a well-capitalized offshore entity with a clean compliance record automatically satisfies Turkish requirements. In our practice, we see this assumption derail timelines and licensing budgets. The SPK assesses Turkish-nexus factors: where decisions affecting Turkish users are made, where customer funds are held, and whether the entity can respond to regulatory enquiries within Turkey's jurisdiction. These are domestic-presence questions, not merely paperwork questions.

CTA #1

If you are assessing whether your platform's current structure captures or excludes Turkish users, the analysis turns on activity – not where the company is registered. The process above describes the standard regulatory perimeter. Your facts – the entity, the user base, the banking rails – change the analysis materially. Map your options with OBOLUS before you commit to a structure.

What Does the SPK Application Process Involve?

The SPK application for a crypto asset service provider licence requires the applicant to submit a structured dossier covering corporate formation, shareholder and beneficial ownership disclosure, fit-and-proper assessment of key personnel, capital adequacy documentation, an AML/CFT programme, technology and cybersecurity standards, and a client-asset segregation plan. The SPK's communiqués specify the documentary requirements in detail; the standard list runs to several dozen items.

Formation of a Turkish joint-stock company (anonim şirket) is typically a prerequisite for domestic authorisation. A foreign entity cannot generally hold the SPK licence directly; the licensed vehicle must be a Turkish legal entity with a registered office, a compliant board structure and capital meeting the SPK's published minimums. Those minimums are set in the relevant communiqué and are subject to revision; we always confirm the current figure at the point of application rather than relying on figures circulating in the market.

The application process has multiple stages: pre-application engagement with SPK staff, formal submission, completeness review, substantive review and conditional grant. The SPK may issue a list of deficiencies requiring a supplemental response. Realistically, an applicant should plan for a process measured in months – the precise timeline varies with the completeness of the initial submission, the complexity of the applicant's structure and the SPK's current workload. Applications with clear corporate structures, clean beneficial ownership chains and pre-built AML programmes tend to move faster. Applications that arrive with complex offshore holding structures, incomplete UBO disclosure or technology stacks that cannot demonstrate segregated client-asset custody draw extended review.

In a recent matter, an exchange operator with a central European parent structure sought to enter the Turkish market. The initial submission was returned with deficiencies centred on the cross-border data-sharing arrangement between the Turkish entity and the parent's custody system. We restructured the custody and data-processing agreement to create a clean Turkish-entity perimeter, re-submitted with an updated AML programme aligned to MASAK requirements, and the application moved to substantive review without further deficiency notices.

AML, MASAK and the Travel Rule Obligation

MASAK supervision applies to any entity performing crypto asset services in Turkey, and it operates independently of the SPK licensing track. A Turkish-licensed exchange must maintain a MASAK-compliant AML/CFT programme, appoint a designated compliance officer, conduct customer due diligence and enhanced due diligence where required, and implement transaction monitoring.

Turkey is a FATF member and its AML framework reflects FATF Recommendation 15, which requires countries to regulate virtual asset service providers (VASPs) for AML/CFT purposes. The Travel Rule – requiring originators and beneficiaries to be identified and data passed with transfers above the applicable threshold – applies. The threshold and the precise technical standard for Travel Rule data transmission are set in MASAK's operative guidance; operators should confirm the current de minimis figure and the accepted messaging protocol at the time of compliance-programme design.

Cross-border transfers present a structural complexity. When a Turkish-licensed exchange sends funds to a counterpart VASP in a jurisdiction that has not yet implemented the Travel Rule, the gap in the counterpart's compliance capability creates a receiving-end failure that can be attributed back to the Turkish sender in a MASAK review. In our cross-border practice, we address this by building a tiered counterpart due diligence policy that distinguishes Travel-Rule-capable VASPs from those that are not, and routes transactions accordingly.

Banking and Fiat Rails for Turkish Crypto Exchanges

Banking access is the operational bottleneck that regulatory authorisation alone does not solve. Turkish banks have historically been cautious in opening accounts for crypto exchanges, and SPK authorisation – while necessary – is not sufficient to guarantee banking relationships. The SPK licence demonstrates regulatory standing, but each bank conducts its own risk assessment independently.

In practice, licensed exchanges in Turkey have obtained TRY deposit and withdrawal rails through domestic banks that have developed internal frameworks for assessing VASP clients. The key factors those banks assess include: the completeness of the exchange's KYC/AML programme, the identity of beneficial owners, whether the exchange's technology provides transaction-monitoring outputs the bank can rely on, and whether the exchange can demonstrate that client funds are segregated from operational accounts.

For exchanges with international operations, the fiat-banking problem compounds. A Turkish entity that is also licensed in the EU under MiCA – or registered with the FCA in the United Kingdom – faces the interaction between its Turkish compliance architecture and its EU or UK obligations. The two regimes do not conflict in principle, but the reporting, client-asset segregation and AML requirements must be designed cohesively from the start, or the Turkish entity's banking application will surface contradictions that cause delays.

We regularly advise exchanges on the sequencing of banking outreach: applying to domestic Turkish banks after SPK authorisation, building the AML-programme documentation in the format those banks' compliance teams expect, and where a client needs offshore banking for hard-currency settlement, mapping the interaction with the Turkish entity's regulated perimeter.

Cross-Border Tax and Structuring Considerations

Turkey's tax treatment of crypto asset income is an evolving area. The Turkish Revenue Administration has published guidance addressing the taxation of gains from crypto asset trading, and the position has shifted as the SPK regime has taken shape. At the time of structuring, the key questions are: whether exchange income is treated as commercial income subject to corporate tax; how the interaction between the Turkish operating entity and any offshore holding structure is analysed for transfer-pricing purposes; and whether any withholding applies on cross-border payments from the Turkish entity to related parties.

A common structuring pattern for inbound operators involves a foreign holding company that owns the Turkish operating entity. That structure creates permanent-establishment risk if the holding company's key management and decision-making functions are exercised from Turkey. The SPK's fit-and-proper requirements for key personnel reinforce this: if the management team that satisfies SPK criteria is physically and legally resident in Turkey, the holding company's offshore status is potentially nominal for tax purposes.

Turkey has an extensive network of double-taxation treaties, and the interaction between the applicable treaty and the Turkish domestic tax position on crypto income must be assessed before the corporate structure is finalised. This is not a step to defer to after licensing – the structure chosen at the licensing stage is the structure that will govern tax exposure for the life of the business.

VAT treatment of exchange services and transaction fees in Turkey has its own analysis. The applicable position should be confirmed with Turkish tax counsel at the point of business-model design, not after the fee structure has been set.

CTA #2

If your structure involves an offshore holding company above a Turkish operating entity, the tax and regulatory analyses must run together – not sequentially. If a prior application stalled or a banking relationship was closed, a second read of the structural design often surfaces the cause. Map your options with the OBOLUS team.

Which Operator Profiles Should Enter Turkey, and How?

Not every operator is equally positioned to pursue a Turkish licence, and the right structure depends on the business profile.

A large, well-capitalised exchange that already holds a MiCA CASP authorisation in an EU member state and wants to expand into Turkey is the strongest candidate for a direct Turkish entity. The EU authorisation demonstrates regulatory maturity to the SPK and to Turkish banks. The primary task is translating the existing compliance programme into Turkish-specific requirements and establishing the Turkish entity with the capital and personnel the SPK requires. Timeline is a matter of months; the primary risk is the banking phase, not the licensing phase.

A mid-market operator that is at an earlier stage of regulatory development – holding perhaps an FCA cryptoasset registration in the United Kingdom or a VASP registration in a smaller EU jurisdiction – faces a different calculus. The SPK will assess the quality of the existing compliance programme. A thin AML programme or a complex beneficial-ownership structure that was acceptable for an EU registration may not satisfy SPK review. In this profile, the sensible sequence is to strengthen the compliance architecture first, then approach Turkey.

A startup operator that has no prior licensing history faces the highest barrier. The SPK's fit-and-proper requirements apply to directors and senior management, and an unlicensed team applying for a first-ever regulatory authorisation in Turkey will face close scrutiny of individual track records. In this profile, the decision is whether to establish licensing history in a faster jurisdiction first – such as a Baltic state operating under MiCA transition, or a Gulf hub – before committing to Turkey. The Turkish market's size and depth make the eventual investment worthwhile; the question is sequencing.

A business whose users include Turkish residents but whose Turkish revenue is modest relative to other markets faces a proportionality question. The cost and complexity of full Turkish authorisation must be weighed against the strategic value of the Turkish user base. In some cases, geofencing Turkish users while the compliance programme matures is the appropriate interim step; in others, the market opportunity makes early entry compelling despite the cost.

Custody and Safeguarding Requirements

The SPK's communiqués address client-asset custody as a discrete requirement, not merely as part of the general AML programme. A licensed exchange must demonstrate that client crypto assets are segregated from the exchange's own operational assets, that the custody system meets technical security standards the SPK has prescribed, and that the custody arrangement survives an insolvency scenario at the exchange level.

For an exchange that intends to custody client assets itself, the technical infrastructure – cold storage architecture, key management, access controls and audit trail – must be documented to SPK standards before authorisation. Exchanges that rely on a third-party custodian must demonstrate that the custodian arrangement is legally structured to provide client-asset protection, not merely operational convenience.

The custody question interacts with the cross-border structuring question. If the exchange's custody infrastructure is operated by a non-Turkish affiliate, the SPK will scrutinise whether the Turkish entity's client assets are genuinely segregated and recoverable under Turkish law in a stress scenario. The arrangement must withstand that analysis structurally, not just contractually.

FAQ

How long does a crypto licence take to obtain?

In Turkey, the SPK authorisation process is measured in months rather than weeks. The timeline depends on the completeness of the initial submission, the complexity of the applicant's corporate structure and the SPK's current review workload. A well-prepared application with a clean beneficial-ownership chain and a pre-built AML programme moves faster than one requiring multiple deficiency responses. Other jurisdictions vary: some EU member states operating under MiCA transition timelines can move faster; Gulf hubs such as VARA in Dubai operate their own review cycles. We confirm the current timeline at the point of engagement.

Which jurisdiction is best for licensing my crypto business?

There is no single answer. The right jurisdiction depends on where your users are, what activities you perform, your capital position, your team's residency and your banking requirements. Turkey is the right answer if you are building primarily for the Turkish market. For EU reach, a MiCA CASP authorisation in a member state may be more efficient. For Gulf markets, VARA or the ADGM/FSRA regime applies. A common mistake is choosing a jurisdiction for its cost or speed without mapping where the users are – a mismatch creates unlicensed-activity exposure in the user's jurisdiction regardless of where the entity is licensed.

Do I need a separate custody licence?

Under the SPK regime, custody of client crypto assets is a regulated activity that is addressed within the CASP authorisation framework, but the technical and operational requirements for custody are assessed as a distinct element. An exchange that custodies client assets must satisfy the SPK's custody-specific requirements as part of its authorisation. Whether custody requires a formally separate licence, or is covered as a permitted activity within the exchange authorisation, turns on the structure of the application and the SPK's current communiqué. Operators relying on a third-party custodian must structure that arrangement to satisfy the SPK's client-asset protection expectations independently.

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance structures that sit around them. Digital assets are the entirety of our practice – we act only for businesses, and we map the licence, custody and payment-rail stack before you commit, not after. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in inbound VASP and CASP authorisation in emerging and transitional regulatory regimes, with a focus on cross-border licensing sequencing and compliance architecture for exchange operators.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours