Turkey moved from an unregulated digital-asset environment to a fully supervised crypto licence regime when the Capital Markets Board – the Sermaye Piyasası Kurulu, or SPK – assumed supervisory authority over crypto asset service providers under amendments to the Capital Markets Law. Firms that handle trading, custody, transfer or exchange of crypto assets for Turkish-resident clients must now hold an SPK authorisation before operating. The payment layer sits in a separate but equally critical lane: the Banking Regulation and Supervision Agency (BDDK) governs electronic money institutions, and the Central Bank of the Republic of Turkey (TCMB) has historically restricted the use of crypto assets in payment transactions. That combination – SPK for the asset side, BDDK for the payment side, TCMB for the monetary perimeter – defines the regulatory architecture every inbound operator must map before committing capital.
The short answer for any operator asking whether a Turkish EMI licence alone is enough to run a crypto business: it is not. A business that wants to provide crypto-related payment rails, stablecoin settlement or fiat-to-crypto on-ramps in Turkey needs to resolve both the crypto authorisation question under the SPK regime and the payment institution question under the BDDK regime. Getting one without the other leaves a structural gap that Turkish regulators will find. This page maps both tracks, explains where they interact, and identifies the decision points a foreign operator should reach before opening an entity in Turkey.
The Turkish Regulatory Architecture for Crypto and Payments
Turkey's digital-asset regime is built on three separate but overlapping supervisory pillars, and an operator who conflates them will structure the wrong entity. The SPK authorises and supervises crypto asset service providers (CASPs) – the firms that operate trading platforms, provide custody and execute crypto-to-crypto or fiat-to-crypto transactions for clients. The BDDK licences electronic money institutions and payment service providers. The TCMB has issued rules prohibiting the direct use of crypto assets as a payment instrument in goods and services transactions within Turkey.
Each pillar addresses a distinct part of the value chain. A firm that only operates an exchange needs an SPK authorisation. A firm that issues a stored-value product or processes fiat settlement flows needs a BDDK payment institution or EMI licence. A firm that does both – as most scaled platforms do – needs to satisfy both regulators. The TCMB prohibition on crypto-as-payment adds a third constraint: products that route crypto into the domestic payment rails in a way that functions as a substitute for Turkish lira will attract TCMB scrutiny regardless of what the SPK or BDDK has authorised.
The SPK has published detailed authorisation criteria covering minimum capital, shareholding transparency, fit-and-proper requirements for controllers and senior managers, technology and cybersecurity standards, and client asset segregation. The BDDK applies its own capital and operational requirements to EMIs, and those requirements are not the same as the SPK thresholds. An operator planning to run both the trading and payment layers from a single Turkish entity must satisfy the higher of the two capital bars in each category.
Who Needs a Turkish Crypto or EMI Licence?
Any firm providing regulated crypto-asset services to clients resident in Turkey – whether the firm itself is onshore or offshore – falls within the SPK's supervisory perimeter. The regime is effects-based: location of the entity is less relevant than location of the customer. A Maltese or BVI entity that actively markets to Turkish retail or institutional clients and processes Turkish-lira deposits is squarely within scope.
The categories that the SPK has identified as regulated include operating a trading platform, providing custody or wallet services, enabling the transfer or exchange of crypto assets, and offering portfolio management or advisory services in relation to crypto assets. A firm that provides even one of those services to Turkish-resident clients without an SPK authorisation is operating without a licence. The BDDK perimeter is similarly broad: any firm that issues electronic money, operates a payment account or provides payment initiation services in connection with Turkish-lira flows must hold the relevant BDDK licence.
Foreign operators should note that Turkey does not currently offer a passporting mechanism equivalent to the EU's MiCA CASP passport. There is no bilateral recognition arrangement that allows an ESMA-supervised CASP or a VARA-licensed Dubai exchange to serve Turkish clients without a local authorisation. Each jurisdiction stands alone. That is the structural reality that makes a Turkey-specific licence decision a standalone board decision, not a routine extension of an existing EU or Gulf licence.
To assess whether your business model, user base and transaction flows trigger Turkish authorisation requirements, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options.
How Does the SPK Authorisation Process Work?
The SPK authorisation process for a crypto asset service provider proceeds in broadly sequential stages: pre-application engagement, formal submission, technical and financial review, and a decision on authorisation. The timeline from formal submission to decision is not fixed by statute in the same way as some EU regimes, and in practice it has varied considerably depending on the complexity of the business model and the completeness of the application dossier.
The application dossier is substantial. The SPK requires, among other things, a detailed description of the business model and the specific regulated activities sought; evidence of minimum capital at the required level; audited financial statements or equivalent financial standing documentation; a corporate governance structure with identified ultimate beneficial owners and a demonstration of their fitness; fit-and-proper documentation for each proposed director and senior manager; a technology architecture description addressing cybersecurity, wallet infrastructure and system resilience; an AML/CFT policy and compliance framework aligned with Turkish Financial Crimes Investigation Board (MASAK) expectations; and client asset segregation procedures.
MASAK sits alongside the SPK as the primary AML supervisor for the sector. The MASAK (Financial Crimes Investigation Board) designation of crypto asset service providers as obliged entities means that AML registration with MASAK is a prerequisite or parallel condition to SPK authorisation. The Travel Rule – the obligation to pass originator and beneficiary data with a virtual-asset transfer – applies under the MASAK framework, and the SPK expects applicants to demonstrate a credible implementation plan for Travel Rule compliance before authorisation is granted.
In our licensing practice, we have seen applications that were technically complete on submission but were returned for supplementary information on cybersecurity architecture and on the AML policy's coverage of stablecoin transactions. Building those elements to the required standard before submission, rather than in response to a regulator's query, compresses the timeline materially.
What Does the BDDK EMI Licence Track Require?
The BDDK electronic money institution licence is the required authorisation for any firm that intends to issue electronic money, hold client funds in a payment account or provide fiat settlement infrastructure in Turkey. For a crypto business, the BDDK track becomes relevant the moment the product involves fiat-denominated stored value, a lira-denominated user wallet or a payment initiation service that moves lira into or out of a crypto position.
The BDDK applies a set of capital requirements, operational standards and shareholding-transparency rules that are independent of the SPK's crypto-specific regime. The minimum capital for an EMI licence in Turkey is set by regulation and is subject to change; operators should obtain current figures from BDDK-published guidelines or from counsel with current knowledge of the applicable thresholds, as these vary by the scope of payment activities sought.
BDDK authorisation also requires a physical presence: the applicant must be a Turkish-law entity (a joint-stock company), with its headquarters in Turkey and with a board composition that meets the BDDK's governance requirements. A foreign holding company cannot hold a BDDK licence directly. The structure therefore typically involves a Turkish operating subsidiary, capitalised to the BDDK minimum, with the foreign parent as the shareholder subject to BDDK fit-and-proper approval.
The interaction between the BDDK EMI licence and the SPK crypto authorisation creates a dual-track compliance structure. Senior managers who are directors of the Turkish entity will require fit-and-proper approval from both regulators. The AML framework must satisfy both MASAK's crypto-specific expectations and the BDDK's payment-institution AML standards. Compliance teams that are built for one track will frequently need augmentation to satisfy the other.
How Does a Turkish Licence Interact with Cross-Border Operations?
A Turkish-licensed crypto business operating cross-border faces a structural tension that does not resolve itself through good intentions: Turkish authorisation governs the domestic user base, but it does not licence the firm to operate in other jurisdictions. A Turkish CASP that also serves EU-resident clients needs, at minimum, a MiCA CASP authorisation from an EU national competent authority. A Turkish CASP serving Singapore-resident clients falls within the MAS Payment Services Act regime. Each jurisdiction has its own perimeter, and the Turkish licence provides no passport into any of them.
Banking is the practical chokepoint. Turkish banks have become more receptive to providing correspondent and settlement services to SPK-authorised crypto firms than to unlicensed operators, but international banking for a Turkish crypto entity remains a live challenge. Banks in the EU, the UK and the US continue to apply enhanced due diligence to Turkish financial institutions and to Turkish-domiciled crypto businesses. The result is that a Turkish CASP frequently needs a secondary banking relationship in a jurisdiction with more straightforward correspondent access – typically the UAE, Switzerland, or an EU member state where a group entity holds an authorisation.
Tax interaction is a further complexity. Turkey taxes crypto gains under its income tax and corporate tax frameworks, but the treatment of specific transaction types – staking rewards, DeFi returns, cross-chain swaps – is not always settled by clear guidance. A Turkish operating entity that books revenues from international users needs transfer-pricing analysis if it is part of a group, and the group structure itself may trigger controlled-foreign-company rules in the jurisdiction where the holding company sits. We regularly advise on the tax and banking stack alongside the licence application, because the licence in isolation rarely tells the full story.
If a prior application stalled or a banking relationship closed, a second read can surface the structural reason and the route back. Write to OBOLUS at info@oboluslaw.com or reach us at t.me/oboluslaw. Map your options.
A Cross-Border Crypto Licensing Matter: Turkey and the Gulf
In a recent licensing engagement, a payments company incorporated in a Gulf free zone sought to extend its service offering to Turkish-resident users through a newly formed Turkish subsidiary. The business model combined a crypto trading layer with a fiat settlement wallet. We were instructed to map the full regulatory perimeter before the Turkish entity was incorporated.
The analysis identified that the proposed product triggered both the SPK crypto authorisation requirement and the BDDK EMI licence requirement. A single-track approach – SPK only, with the fiat wallet characterised as ancillary – carried a material risk of BDDK non-compliance. We restructured the corporate architecture so that the trading layer and the payment layer were separated at the entity level, allowing each to be authorised by the relevant regulator without one dossier having to satisfy both sets of capital and governance requirements simultaneously. The client proceeded to formal submission on the SPK track in the following quarter, with the BDDK application sequenced to follow the SPK decision. The matter is ongoing, but the structural issue that would have delayed or blocked authorisation was identified and resolved before first submission.
Which Operator Profile Needs Which Turkish Authorisation?
The right authorisation path in Turkey depends on the specific activities, the user base and the transaction flows. Three operator profiles illustrate the decision logic.
A pure trading platform – an operator that matches crypto-to-crypto or crypto-to-fiat orders for Turkish-resident users, holds client crypto in segregated custody and does not issue stored-value instruments – needs an SPK authorisation. The capital, governance and technology standards of the SPK regime apply. The BDDK track is not triggered so long as the fiat leg is handled through a licensed bank on behalf of the user, rather than through an EMI account held by the operator.
A payment-focused operator – a firm that issues a lira-denominated stored-value wallet, enables users to buy and sell crypto from within that wallet and processes the fiat settlement internally – needs both an SPK crypto authorisation and a BDDK EMI or payment institution licence. The capital requirement is higher, the governance structure more complex, and the compliance team needs to satisfy two sets of AML expectations. The indicative timeline to dual authorisation is longer than for the single-track SPK path; operators should plan for a multi-month process with no guarantee of outcome.
An OTC desk or institutional broker – a firm that serves corporate clients, executes large-block crypto transactions and does not hold retail client funds – may qualify for a narrower SPK authorisation that reflects the institutional nature of its activities. The fit-and-proper and capital requirements still apply, but the technology-infrastructure and client-protection standards may be calibrated to the wholesale context. Operators in this profile should confirm the applicable authorisation category with counsel before structuring the entity, as the SPK's category mapping for institutional activity continues to develop.
What Are the Most Common Mistakes in Turkish Crypto Authorisation?
The most consequential mistake we see is assuming that a MASAK AML registration – which was required before the SPK crypto regime was fully enacted – is equivalent to, or a substitute for, the SPK CASP authorisation. It is not. MASAK registration addresses anti-money-laundering obligations. The SPK authorisation addresses the right to carry on regulated crypto-asset service activities. A firm that holds only a MASAK registration and continues to serve Turkish clients is operating without a crypto licence in the SPK's view.
A common assumption in the market is that a single offshore licence is enough to serve Turkish clients globally. That assumption is incorrect for Turkey. The SPK's effects-based perimeter covers services actively directed at Turkish-resident users regardless of where the operator is incorporated. Enforcement actions and account-blocking measures have followed from this position. Operators who have relied on an EU, UAE or BVI authorisation to serve Turkish users without a local SPK authorisation should seek an updated legal opinion on their current exposure.
A further structural error is under-capitalising the Turkish entity relative to the combined SPK and BDDK capital requirements. Operators sometimes size the Turkish subsidiary to the lower of the two capital bars, only to discover during the second authorisation process that the entity needs to be recapitalised. Building the capital structure to the highest applicable bar from the outset avoids a recapitalisation round mid-application.
Finally, underestimating the time and documentation burden of the fit-and-proper process for ultimate beneficial owners and senior managers is a consistent cause of application delay. Turkish regulators have requested extensive background documentation on beneficial owners, including documentation from jurisdictions that do not have straightforward information-exchange arrangements with Turkey. Assembling that documentation proactively, before first submission, is the most effective way to prevent a regulator-driven pause in the authorisation timeline.
Related at OBOLUS
Related at OBOLUS
- Licensing and registration for digital-asset businesses – End-to-end CASP and payment institution authorisation across 70+ jurisdictions.
- Legal counsel for OTC trading desks – Structuring, authorisation and compliance for institutional crypto execution desks.
- Exchange disclosure orders under the VARA regime in Dubai – Recovery and disclosure tools available through the VARA-regulated Dubai exchange environment.
FAQ
How long does a crypto licence take to obtain?
Timeline varies by jurisdiction, application complexity and the completeness of the submission dossier. In Turkey, the SPK authorisation process has, in practice, taken several months from formal submission for well-prepared applicants; incomplete applications take materially longer. A dual-track SPK-plus-BDDK process takes longer still. Operators should build licensing timelines into their go-to-market planning rather than treating authorisation as a post-launch formality. We map realistic timelines during the initial scoping assessment.
Which jurisdiction is best for licensing my crypto business?
There is no single best jurisdiction. The right licensing domicile depends on where your users sit, what activities you carry on, your banking requirements and your tax position. A Turkish CASP authorisation is necessary if you serve Turkish-resident clients; it does not remove the need for other authorisations if you also serve EU, UAE or Singapore clients. We map the full licence stack – operating, custody and payment layers, across all relevant jurisdictions – before recommending a structure.
Do I need a separate custody licence?
In Turkey, custody of crypto assets for third parties is a regulated activity under the SPK regime. Whether a standalone custody authorisation is required, or whether custody is covered under a broader CASP authorisation, depends on the scope of the authorisation sought and the specific custody model. Operators that hold client crypto assets – even incidentally to a trading or payment function – should confirm their custody authorisation position with counsel before launch, as operating outside the authorised scope carries enforcement risk.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – identifying the structural gaps that cause applications to stall or banking relationships to close. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialist in inbound digital-asset authorisation across emerging-market and multi-regulator environments, including Turkey, Central Asia and the Gulf.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.