EST · MMXXVI
Home/Jurisdictions/Turkey/Digital-asset custody licensing in Turkey
Licensing & Registration

Digital-asset custody licensing in Turkey

Digital-asset custody licensing in Turkey. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Digital-asset custody licensing in Turkey

Operating a digital-asset custody business in Turkey without the correct regulatory authorisation now carries direct enforcement exposure. Turkey's capital-markets regulator, the Capital Markets Board (Sermaye Piyasası Kurulu, or CMB), has introduced a licensing regime for crypto-asset service providers that explicitly covers custody as a regulated activity. A business holding client digital assets – whether as a standalone custodian or as part of a broader exchange or wallet service – must obtain the applicable authorisation before conducting operations for Turkish-resident clients. This page maps the regulatory basis, the inbound-operator process, the cross-border interactions with tax and banking, and the practical decision points a business must resolve before committing to the Turkish market.

What is the legal basis for digital-asset custody regulation in Turkey?

Turkey regulates digital assets through its capital-markets legislation, with the CMB designated as the competent authority for licensing and supervision of crypto-asset service providers. The legal basis for this regime was established through amendments to the capital-markets law, and the CMB subsequently issued secondary legislation and communiqués that set out the specific licence categories, capital requirements and operational standards. Custody – the holding, safekeeping and administration of digital assets on behalf of clients – is treated as a discrete regulated activity under those provisions.

This is a meaningful shift from the earlier Turkish posture, which had focused primarily on prohibiting the use of crypto assets as a means of payment rather than building a full licensing architecture. The current regime moves Turkey into the broader group of jurisdictions that require positive authorisation for custody, not merely registration. For an inbound operator, that distinction matters: passive compliance measures are insufficient. The business must go through a formal application, demonstrate fit-and-proper standards and satisfy minimum capital and operational requirements before it may custody client assets.

The CMB's remit covers platforms and firms providing services to Turkish residents, regardless of where the legal entity is incorporated. A Cayman-incorporated entity serving Turkish retail users is within scope. So is a BVI-incorporated holding company whose Turkish subsidiary actually handles the client-facing custody function. Corporate structure does not displace jurisdictional nexus; the test turns on the location of the users and the nature of the service delivered to them.

Who needs a custody licence under the Turkish regime?

Any entity that holds private keys, manages wallets or otherwise controls digital assets on behalf of third-party clients in Turkey requires a licence under the applicable CMB provisions. The obligation is not limited to traditional custodians. It captures exchanges that also hold client assets, lending platforms that take digital assets as collateral, and fund administrators or prime brokers that provide sub-custody to institutional clients.

There are nuances worth examining carefully. A business that provides only software – self-custody wallet infrastructure where the user retains sole control of private keys – is in a materially different position from one that co-manages or fully controls client keys. That said, regulatory perimeters have a way of expanding: the CMB communiqués address not only full custody but also hybrid arrangements where the operator holds one of multiple keys in a multi-signature scheme. Operators in that middle ground should not assume they fall outside the licensing requirement without a specific legal analysis of their key-management model.

The regime also reaches brokers that route orders for execution and then return assets to a custody wallet the broker controls between trade cycles. In our practice, we see operators underestimate this exposure, particularly those whose earlier legal work was done against a jurisdiction that drew the custody perimeter more narrowly.

For a scoped assessment of whether your key-management model requires authorisation under the Turkish regime, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the key architecture – change the analysis. Map your options.

What does the Turkish custody licence application process involve?

The CMB application for a crypto-asset service provider licence covering custody involves a structured documentation and review process that typically runs over a period of several months, with the exact duration varying by the complexity of the applicant's structure and the completeness of its initial submission. Operators who underestimate this timeline frequently miss commercial launch windows or are forced to restructure mid-application.

The core application package includes evidence of legal entity establishment in Turkey (or, for a foreign entity, the recognition of its Turkish branch or subsidiary), fit-and-proper documentation for directors and beneficial owners, a detailed description of the custody technology and key-management model, AML/CFT policies and procedures calibrated to Turkish requirements, and demonstration of the minimum capital prescribed by the CMB for the applicable licence category. The CMB conducts a substantive review – this is not a notification or a tick-box registration.

A common structural question for inbound operators is whether to establish a Turkish limited liability company (limited şirketi) or a joint-stock company (anonim şirketi). For regulated financial services in Turkey, the CMB generally expects the joint-stock form, and its communiqués set out governance requirements – including minimum board composition and shareholder transparency – that align with that corporate structure. Getting the entity form right before filing avoids an early-stage rejection that can delay the entire programme by months.

The AML/CFT component of the application deserves specific attention. Turkey has been subject to FATF scrutiny and its competent authorities are acutely focused on demonstrating credible AML infrastructure. The Travel Rule (the obligation to pass originator and beneficiary data with a digital-asset transfer) is part of the compliance architecture the CMB expects to see embedded in custody operations. Applicants who present a generic AML policy without demonstrating how it integrates with their custody technology are routinely asked to resubmit.

How does Turkish custody licensing interact with cross-border operations?

Turkey does not offer a passporting mechanism equivalent to the one available under MiCA for EU-based CASPs (crypto-asset service providers). A Turkish CMB licence authorises custody operations for Turkish-resident clients; it does not, by itself, provide a route to offer cross-border custody into the EU, the UK, Singapore or other regulated markets. An operator building a globally distributed custody business cannot treat a Turkish licence as the sole regulatory instrument.

The practical implication is that a business with custody clients in multiple jurisdictions needs to map each regulatory obligation separately. A Turkish entity custodying assets for institutional clients that are themselves EU-regulated funds may also need to consider the custody-related requirements those funds' home regulators impose on their service providers. In our cross-border practice, we regularly advise on the interaction between a Turkish operating licence and the concurrent expectations of regulators such as the FCA, MAS and the FSRA (within ADGM) where the custodian's institutional clients are based in those jurisdictions.

Banking is a live constraint. Turkish banks operate under their own CMB and BRSA (Banking Regulation and Supervision Agency) oversight and have been cautious in their approach to crypto-related corporate accounts. A licensed Turkish VASP has a stronger position than an unlicensed one when approaching a correspondent bank, but the licence alone does not guarantee account opening. Operators we advise routinely build the banking relationship into the timeline before the licence application is filed – not after – because banking delays are the most common cause of post-licence operational paralysis.

On the tax side, Turkey treats gains from digital-asset transactions as income subject to the applicable tax provisions; the exact treatment of custody fee income, staking rewards and collateral arrangements requires dedicated analysis under Turkish tax law. Cross-border structures that route custody fee income through a non-Turkish entity also attract transfer-pricing scrutiny if the Turkish subsidiary performs substantive functions. Allied counsel in the relevant jurisdiction should be engaged early where the ownership structure spans multiple tax treaties.

What AML and Travel Rule obligations apply to Turkish custodians?

Turkish-licensed custody providers are designated as obligated entities under the applicable AML legislation, overseen by the Financial Crimes Investigation Board (Mali Suçları Araştırma Kurulu, or MASAK) alongside the CMB. MASAK enforces customer due-diligence, beneficial-ownership identification and transaction-monitoring requirements that apply in full to licensed digital-asset custodians. The FATF Recommendations, including Recommendation 15 on virtual assets, inform the Turkish supervisory posture.

The Travel Rule obligation requires that originator and beneficiary data accompany digital-asset transfers above the applicable de minimis threshold. For a custodian, this means that outbound transfers to third-party wallets or to other VASPs must be accompanied by the required data, and that inbound transfers from other VASPs must be screened against the information received. Turkey has implemented this requirement, and MASAK examinations of licensed custodians have focused on the technical and procedural infrastructure supporting Travel Rule compliance – not simply the written policy.

Operators entering the Turkish market with a technology stack built for a different jurisdiction's AML regime frequently discover gaps at the Travel Rule layer. The thresholds and data-format expectations differ enough from those in, say, the UK or Singapore that a direct transplant of an existing compliance system rarely passes muster without adaptation. We have seen applications stall at this specific point more than once.

If a prior application stalled or your compliance infrastructure needs pressure-testing against Turkish MASAK expectations, write to us at info@oboluslaw.com. A second read can surface the structural reason and the route forward. Map your options.

A cross-border custody matter: navigating dual-regulator expectations

In a recent licensing matter, a digital-asset custodian incorporated in a common-law offshore jurisdiction sought to establish a licensed Turkish subsidiary to serve institutional clients based in both Turkey and the EU. The business had an existing operational licence in a Gulf hub but had not previously engaged with Turkish regulatory requirements. We assessed the entity structure, identified that the intended Turkish subsidiary needed to be reconstituted as a joint-stock company to satisfy CMB governance expectations, and rebuilt the AML/CFT policy suite to reflect MASAK's specific Travel Rule and beneficial-ownership standards. The application was filed with a complete package, and the business was able to initiate banking conversations in parallel with the licence review rather than sequentially. The operator entered the Turkish market within the expected regulatory window without the restructuring delay that an incomplete initial filing would have caused.

Which operator profile should pursue a Turkish custody licence?

Not every custody business should prioritise Turkey as a primary licence jurisdiction. The decision turns on several factors that differ by operator profile.

A large, institutionally-backed custodian with a genuine commercial intent to serve Turkish corporate and institutional clients will generally find the CMB licence path appropriate and proportionate. Turkey's economy is large, its digital-asset adoption rate is among the highest in the region by usage surveys, and a CMB-licensed entity has meaningful market access. The capital and governance requirements are demanding but not prohibitive at institutional scale.

A start-up custody operation looking for a low-friction entry point into EMEA digital-asset markets should consider whether Turkey is the right first jurisdiction or whether an EU-passportable CASP licence under MiCA, combined with a Turkish branch or partnership arrangement later, is the more capital-efficient path. The CMB application process is substantive; the timeline and cost commitment should be modelled against the revenue opportunity before filing.

A foreign custodian serving Turkish institutional clients incidentally – where Turkey represents a small proportion of the asset base – should obtain a specific legal analysis of whether that service level triggers the CMB licensing obligation or whether it falls within an applicable exemption. Operating on the assumption that a small Turkish client base does not require licensing is a risk position, not a legal conclusion.

A DeFi-oriented custody model based on non-custodial or smart-contract-mediated key management occupies genuinely uncertain legal ground in Turkey, as it does in most jurisdictions. The CMB's current regime was designed primarily around centralised custody architectures. Operators in this space should not assume they are outside the perimeter; the analysis must be done.

What are the most common mistakes inbound operators make?

Filing without a Turkish legal entity in place is the most basic – and most common – error. The CMB application requires a local legal presence; a foreign entity cannot simply apply as a remote operator. Operators who begin application preparation without first establishing the Turkish entity waste weeks of preparation work when the structural defect surfaces at submission.

Presenting capital in the form of an intercompany loan rather than paid-up equity is a second recurring problem. CMB capital requirements specify that the minimum capital must be genuine regulatory capital, not debt. Structures that dress up shareholder loans as capital are identified early in the review and require unwinding.

A third pattern is treating the CMB and MASAK as sequential rather than concurrent stakeholders. The CMB will not approve a licence application that does not demonstrate a credible MASAK-ready AML framework, but some applicants address CMB governance requirements thoroughly and leave the AML infrastructure as a post-approval project. That sequencing fails in practice.

Finally, operators routinely underestimate the technology documentation requirement. The CMB expects a detailed technical description of the key-management system, the custody technology and the cybersecurity controls. Vague descriptions of "industry-standard cold storage" without system-level specificity are not accepted. Preparation of the technology annex often takes longer than the legal documentation, particularly for operators whose systems were built for a different regulatory environment.

A common assumption that costs operators time and money

A common assumption among businesses expanding into Turkey is that an existing offshore VASP registration – whether in the BVI, Cayman Islands or another low-friction jurisdiction – is sufficient to serve Turkish clients, provided the offshore entity does not have a physical presence in Turkey. That assumption is incorrect under the current CMB regime. The regulatory nexus test is not territorial in the traditional sense; it is service-based. If the operator's platform, marketing, customer agreements or banking are directed at Turkish residents, the CMB treats the activity as within scope regardless of where the server sits. Enforcement actions against unlicensed operators serving Turkish clients through offshore structures have reinforced this point in practice. The risk is not theoretical.

Equally, some operators assume that because Turkey is outside the EU, MiCA compliance provides a complete substitute for Turkish regulatory engagement. MiCA authorisation in an EU member state does not provide any passporting rights into Turkey. The two regimes are entirely separate. Operators building a combined EU-Turkey custody offering need both a MiCA-compliant CASP authorisation and a Turkish CMB licence.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timelines vary significantly by jurisdiction and by the completeness of the initial application. In Turkey, the CMB application process typically runs over several months from submission of a complete package to authorisation. Preparation – entity formation, capital structuring, AML policy build and technology documentation – adds further time before filing. Operators who plan a twelve-month runway from initial engagement to operational launch are better positioned than those who plan for a shorter window. Qualitatively, no reputable jurisdiction with a substantive review process issues a custody licence in a matter of weeks.

Which jurisdiction is best for licensing my crypto business?

There is no single answer. The right jurisdiction depends on the operator's target client base, the specific regulated activities being conducted, the capital available for licensing and the banking relationships the business can sustain. A Turkish CMB licence is the appropriate instrument for a business genuinely serving Turkish-resident clients. An EU CASP authorisation under MiCA is the right instrument for EU-wide market access. Singapore's Payment Services Act serves APAC-focused operators. The correct approach is to map the licence stack against the commercial footprint, not to select a jurisdiction for ease of application and then stretch it to cover markets it does not reach.

Do I need a separate custody licence?

In Turkey and in a growing number of major jurisdictions, custody is a discrete regulated activity that requires its own authorisation – or at minimum a specific activity endorsement within a broader licence. Exchanges that also hold client assets should not assume their trading-platform licence covers the custody function. Under the Turkish CMB regime, the custody activity is assessed and authorised as part of the CASP licence scope; operators must confirm that custody is specifically included in their authorisation, not merely incidental to it. In our practice, we map every activity in the operating model against the licence scope before the application is filed.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams, and we map the licence stack across operating, custody and payment layers before clients commit to a market. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in VASP and CASP authorisation strategy for custody, exchange and payment businesses across EMEA and APAC jurisdictions.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours