EST · MMXXVI
Home/Jurisdictions/Turkey/Vara licence application in Turkey: Legal Requirements for Businesses
Licensing & Registration

Vara licence application in Turkey: Legal Requirements for Businesses

Vara licence application in Turkey. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Turkey's VARA (Virtual Asset Service Providers) licensing regime — established under the country's capital-markets legislation and administered by the Capital Markets Board of Turkey (SPK, from the Turkish Sermaye Piyasası Kurulu) — imposes authorisation requirements on any entity providing virtual asset services to users in Turkey. Operating without that authorisation now carries material enforcement risk: the SPK has signalled a zero-tolerance posture toward unlicensed activity, and international operators that assume a foreign licence covers Turkish users are increasingly exposed. This page maps the regulated perimeter, the application process, the cross-border realities and the decision points every inbound business must resolve before committing to the Turkish market.

What Does Turkey's Virtual Asset Regime Actually Regulate?

Turkey's regulatory regime for virtual assets establishes a mandatory authorisation requirement for any business that provides virtual asset exchange, transfer, custody or initial distribution services to Turkish residents. The legal basis sits within amendments to the capital-markets law, with the SPK designated as the primary competent authority. The regime predates MiCA and does not mirror it directly, though both share the FATF-aligned principle that the regulatory trigger follows the user, not the corporate seat of the provider.

The defined activity categories broadly track the FATF virtual asset service provider taxonomy. Exchange services — buying, selling or converting virtual assets — form the core regulated activity. Transfer services (moving virtual assets on behalf of clients), custody of virtual assets, and initial distribution or offering services each attract their own authorisation conditions. A business touching any one of these categories in relation to Turkish users requires SPK authorisation before commencing activity. There is no de-minimis carve-out based on volume for the authorisation requirement itself; the trigger is the activity, not its scale.

Critically, the SPK has confirmed that the registration obligation applies to operators established outside Turkey if they actively solicit or service Turkish residents. An offshore exchange routing Turkish-language marketing, accepting Turkish lira deposits, or onboarding users with Turkish identity documents is squarely within the regulatory perimeter. This cross-border application principle is the single most common blind-spot we see among inbound operators.

The relevant regime is administered by the SPK under its capital-markets authority, implementing FATF Recommendation 15 obligations for virtual asset service providers. The regulated activity categories are exchange, transfer, custody and initial distribution.

To map whether your current structure triggers the Turkish registration requirement, contact OBOLUS at info@oboluslaw.com. The process above describes the standard analytical path. Your facts — the entity, the user base, the currency rails — change the analysis significantly.

Who Is Required to Obtain SPK Authorisation in Turkey?

Any entity offering virtual asset services to users in Turkey must obtain SPK authorisation, regardless of where the operator is incorporated. The Turkish regime, consistent with the FATF approach to virtual asset regulation, applies a conduct-based trigger: it is the activity directed at Turkish residents, not the corporate domicile, that determines whether the obligation bites.

For domestic businesses — companies incorporated in Turkey intending to operate an exchange, custody service or transfer platform — the authorisation requirement is unambiguous. No Turkish legal entity may commence virtual asset service activities without prior SPK approval.

For inbound foreign operators, the analysis is more layered. A foreign entity that passively attracts Turkish users without affirmative marketing — no Turkish-language interface, no lira onramp, no active solicitation — may argue it falls outside the regulated perimeter. In our cross-border practice, we have seen regulators adopt increasingly narrow readings of the passive-service exception. An exchange with a Turkish-language FAQ page, a local customer-support number or a lira deposit option will struggle to maintain that position. The practical advice for any operator with a meaningful Turkish user base is to proceed on the assumption that authorisation is required.

Platform operators that have historically relied on an EU VASP registration or a BVI FSC registration to cover a global user base face a particular transition risk. The SPK does not recognise passporting from foreign regimes — every entity serving the Turkish market must satisfy the Turkish requirements independently. This is a structural point that the "one offshore licence covers everything" assumption consistently fails to account for.

How Does the SPK Authorisation Process Work?

The SPK authorisation process for virtual asset service providers involves a structured pre-application phase, a formal submission, a substantive review and, upon approval, ongoing supervisory obligations. The SPK has published procedural guidance that sets out the document and technical requirements; applicants are expected to engage with that guidance in full before submitting.

The pre-application phase is not optional in practice. The SPK expects applicants to have resolved fundamental structural questions before submission: the Turkish legal entity form, the governance arrangements, the technical infrastructure specifications, the AML/CFT programme, and the beneficial ownership disclosure. Submitting an incomplete application does not pause the regulatory clock — it restarts it. Operators we advise routinely underestimate this phase and then face avoidable delays.

The formal submission requires, at minimum: incorporation documents for the Turkish entity; a detailed business plan covering products, target users and revenue model; a technical architecture submission addressing platform security and business continuity; full KYC files on all beneficial owners, directors and senior managers; a written AML/CFT policy aligned to Turkish legislation and the FATF Travel Rule obligations; and evidence of the minimum capital required by the applicable licence category. Capital thresholds are set by the SPK and vary by the type of activity — exchange licences carry higher minimum capital expectations than transfer-only or custody-only authorisations. The specific figures are set by regulation and should be confirmed directly from current SPK publications, as they are subject to adjustment.

The SPK review timeline, from a complete submission, is typically measured in months rather than weeks. In our cross-border practice, we have observed that applications touching multiple activity categories or involving complex ownership chains — common where a Turkish entity sits beneath an offshore holding structure — attract longer review periods. Applicants should plan their go-to-market timelines accordingly and should not begin soliciting Turkish users during the review period.

The Travel Rule (the obligation to pass originator and beneficiary data alongside a virtual asset transfer) applies to Turkish licensed VASPs. The SPK expects an applicant's AML/CFT documentation to address Travel Rule compliance explicitly, including the technical solution for data transmission and the procedures for transactions involving counterparty VASPs in jurisdictions where a Travel Rule framework has not yet been implemented.

What Corporate Structure Is Required for a Turkish VASP?

Turkish law requires the virtual asset service provider to be a legal entity incorporated in Turkey. Branches of foreign companies are not an accepted vehicle for SPK-licensed activity; the operating entity must be a separately incorporated Turkish company, most commonly an anonim şirket (joint-stock company, commonly abbreviated "A.Ş.") or a limited şirket (limited-liability company, "Ltd. Şti."). For a business of any meaningful scale, the A.Ş. form is strongly preferred given its alignment with governance and capital requirements.

The SPK scrutinises the ownership chain of the Turkish applicant carefully. Beneficial owners above a threshold shareholding percentage — which the SPK aligns to standard AML-supervisory norms — are subject to fitness-and-propriety vetting. Directors and senior managers are individually assessed. Criminal background, financial sanctions exposure and prior regulatory action in any jurisdiction are all material to the vetting outcome.

Where a Turkish operating company sits beneath an offshore parent — a Cayman fund vehicle, a BVI holding company or an ADGM entity — the corporate chain must be fully disclosed and documented. The SPK is particularly attentive to structures where the ultimate beneficial owner is obscured by multiple holding layers. We have seen applications stalled not because of defects in the Turkish entity itself, but because the documentation trail for an overseas parent was incomplete.

For inbound operators considering their group structure, the Turkish licence therefore interacts directly with the offshore holding strategy. A structure that works well for VARA Dubai or the FSRA in Abu Dhabi may require adaptation before it is SPK-ready. The licensing strategy, the holding architecture and the banking access plan need to be designed together, not sequentially.

AML, KYC and the Travel Rule Under the Turkish VASP Regime

The Turkish AML/CFT framework for virtual assets implements the FATF Recommendations, including the FATF Travel Rule under Recommendation 15. Licensed VASPs must maintain a written AML/CFT programme that covers customer due diligence, enhanced due diligence for higher-risk relationships, transaction monitoring, suspicious transaction reporting, and Travel Rule compliance for transfers.

The SPK and the Financial Crimes Investigation Board (MASAK) share supervisory responsibility for AML compliance at licensed VASPs. MASAK is the Turkish financial intelligence unit and functions as the AML supervisor; the SPK oversees the capital-markets and prudential dimensions. An applicant's AML programme must satisfy both bodies' expectations, and in practice the MASAK alignment is the more operationally demanding element.

Customer identification requirements in Turkey are rigorous. Identity verification must occur before any account opening. For retail customers, Turkish national identity documentation is standard; for corporate customers, the beneficial ownership identification requirements mirror international norms. Biometric verification and liveness-check technology are now expected by MASAK as part of a compliant onboarding flow.

The Travel Rule obligation applies to all qualifying transfers above the applicable threshold, and Turkish licensed VASPs must have a technical solution in place at the time of licence activation, not post-authorisation. The SPK has declined to accept applications where the Travel Rule solution is described as "under development." Applicants should retain a compliant Travel Rule messaging solution — there are several interoperable protocols operating in the market — and document it in the AML submission. Operators we advise regularly treat the Travel Rule technical stack as a post-licence implementation item; that sequencing is inconsistent with current SPK expectations.

How Does Turkish Banking Interact With a VASP Licence?

Banking access is the practical bottleneck for most Turkish VASP applicants, and it must be addressed in parallel with the licence application, not after it. Turkish commercial banks have historically applied conservative risk appetites to virtual asset businesses. While the licensing regime creates a regulatory framework that in principle supports banking relationships for licensed entities, the commercial reality is that bank onboarding for a newly licensed VASP can be a protracted process.

The SPK expects applicants to demonstrate that they have made credible arrangements for the custody of client fiat funds. At the application stage this means evidence of engagement with a Turkish bank willing to provide a client-money segregation arrangement. A speculative statement that "banking will be arranged post-licence" is not sufficient. In our practice, we have seen applicants with technically strong applications stall at this point.

The Turkish lira is the domestic currency, and exchange operators handling lira inflows from Turkish users must have a compliant lira settlement account at a Turkish bank. This creates a practical sequencing requirement: the corporate entity must be incorporated first, then banking engagement can commence, then the licence application can proceed with banking evidence attached.

For foreign operators, the cross-border dimension adds a further layer. Where a Turkish operating entity receives fiat from an offshore parent or transmits revenue to an offshore holding company, the Turkish foreign-exchange regulations and capital-account rules apply. These are not primarily a licensing issue, but they interact with the licensing process: the SPK will review the group's fiat-flow model as part of its business-plan assessment. Structuring the intragroup flows correctly from the outset avoids amendments to the approved business plan during the licence term.

The Cross-Border Reality: Turkish Licences and Global Operations

A Turkish VASP licence authorises activity in Turkey; it does not confer any passport right into other jurisdictions. This is the mirror image of the problem that offshore operators face when they try to rely on a foreign licence to serve Turkish users. Each jurisdiction's authorisation stands alone.

For a business that intends to serve Turkish users as part of a wider multi-jurisdiction strategy — common among exchanges that have licensed in the EU under MiCA, in the UAE under VARA, or in Singapore under the MAS Payment Services Act — the Turkish licence sits as an additional operating authorisation, not a replacement for any of the others. The corporate architecture therefore typically involves a Turkish operating subsidiary sitting alongside, not beneath, the primary licensed entity in the operator's home jurisdiction.

Tax interaction is a separate but related consideration. A Turkish operating entity generating revenues from Turkish users is subject to Turkish corporate income tax. Where that entity is part of a group with a holding company in a lower-tax jurisdiction, transfer pricing rules will govern the allocation of profit between the Turkish entity and the parent. Turkey has a developed transfer-pricing regime that applies OECD guidelines; the pricing of intercompany services — technology, compliance, brand — must be at arm's length and documented. The interaction of the Turkish entity's P&L with the group's overall tax position should be modelled before the structure is finalised.

In a recent matter, a payments company seeking to expand its Central Asian and Eastern European user base considered a Turkish entity as the primary operating hub. We assessed the licensing, banking and transfer-pricing stack together and identified that the group's preferred offshore holding structure required amendment before it would satisfy the SPK's beneficial-ownership disclosure requirements. The restructuring was completed before the application was submitted, saving significant time. The entity obtained its authorisation without the ownership-chain queries that have disrupted comparable applications.

If a prior application stalled or a banking relationship closed, a second structural review can surface the cause and the route back. To map the licence, banking and tax stack for your Turkish build, write to info@oboluslaw.com.

Which Operator Profile Should Pursue a Turkish VASP Licence?

Not every operator serving Turkish users needs to establish a Turkish legal entity immediately. The decision turns on the scale and nature of the Turkish user base, the product set, and the operator's tolerance for regulatory risk.

Profile A — the domestic exchange: A Turkish-incorporated exchange targeting the domestic retail market and offering lira trading pairs is unambiguously within the regulated perimeter. The Turkish licence is not optional. The profile should budget for a multi-month authorisation process, the minimum capital requirement for exchange services and an operationally mature AML/CFT and Travel Rule infrastructure. The key risk is underestimating the banking step.

Profile B — the inbound global operator: A foreign exchange with a meaningful Turkish user base — say, several thousand active accounts, Turkish-language support, lira deposits accepted — sits in a higher-risk position than it may appreciate. The SPK's extraterritorial application of the regime is increasingly enforced. The question is not whether authorisation is needed but how quickly the operator can achieve it. A pre-application gap analysis — assessing the current structure against SPK requirements — is the right starting point before a full application commitment.

Profile C — the institutional or B2B service provider: A custody service or a transfer/settlement provider serving other businesses rather than retail users in Turkey faces the same licensing obligation but may be able to structure for a more limited activity authorisation. The product scope, the client base and the transaction flows all affect which activity categories are triggered. A precise activity mapping, conducted before any Turkish entity is established, can avoid over-licensing.

Profile D — the token issuer: A company conducting an initial distribution or token sale with Turkish participants is within the regulated perimeter for that activity. The authorisation requirement for initial distribution is distinct from exchange or custody licensing, though in practice a business that issues and also provides secondary-market liquidity will need to consider whether multiple activity categories apply.

Across all profiles, the cross-border note is the same: a Turkish licence covers Turkey. Adjacent markets — the EU, the UAE, Kazakhstan — each require their own authorisations. A multi-jurisdiction operator should sequence its licensing programme by priority of user concentration and enforcement risk, not by perceived ease of application.

Related at OBOLUS

What Are the Most Common Mistakes in the Turkish VASP Application?

The most common application failure is submitting before the corporate and banking infrastructure is in place. The SPK assesses the application as a whole. A strong legal submission paired with an incomplete banking picture, or a well-drafted AML policy backed by a newly incorporated entity with no operational history, creates gaps that the SPK will surface in queries — and each query cycle adds time.

The second most frequent mistake is the ownership-disclosure gap. Where the beneficial owner of the Turkish applicant is an individual based in a jurisdiction that does not produce readily apostilled corporate documentation — some Central Asian and Eastern European jurisdictions — the evidence trail breaks down at the SPK desk. Applicants should audit their ownership documentation chain at the outset, not after a first information request.

A common assumption among operators entering Turkey from regulated EU jurisdictions is that their existing MiCA CASP authorisation, or their prior national VASP registration under the pre-MiCA regime, carries weight with the SPK. It does not, formally. The SPK conducts its own fit-and-proper assessment. A prior EU authorisation may help demonstrate that the management team and the AML programme meet a recognised standard, but it does not substitute for the Turkish application. Operators that arrive at the SPK expecting a streamlined mutual-recognition process are disappointed.

Finally, the Travel Rule implementation point bears repeating. Treating Travel Rule compliance as a post-licence deliverable is inconsistent with current SPK expectations and has become a recurring obstacle. The technical solution needs to be operational — not merely contracted — at the time the full application is submitted.

FAQ

How long does a crypto licence take to obtain?

In Turkey, the SPK authorisation timeline for a complete application is typically measured in months. The exact duration depends on the number of activity categories applied for, the complexity of the ownership structure and the speed with which the applicant responds to SPK information requests. Incomplete applications do not pause the timeline; they reset it. Operators should allow for a minimum of several months from complete submission to authorisation, and should not begin soliciting Turkish users during the review period.

Which jurisdiction is best for licensing my crypto business?

There is no single best jurisdiction. The right licensing profile depends on where your users are located, which activity categories you operate, your product architecture and your banking strategy. Turkey is the appropriate jurisdiction for operators serving Turkish users — regardless of where the group is headquartered. For operators building a multi-jurisdiction presence, Turkey typically sits alongside, not instead of, a primary licence in the EU under MiCA, in the UAE under VARA, or in Singapore under the MAS Payment Services Act. We map the licence stack across all relevant jurisdictions before any application commitment.

Do I need a separate custody licence?

Under the Turkish VASP regime, custody of virtual assets is a distinct regulated activity category. An operator that provides custody services to Turkish users — whether as a standalone offering or as an ancillary function of an exchange — must ensure that the custody activity is covered by its SPK authorisation. Whether custody requires a fully separate licence or is addressed within a combined authorisation covering multiple activity categories is a matter of current SPK guidance and should be confirmed directly. We regularly advise on scoping the activity categories before submission to avoid gaps in the licence.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, banking and tax stack across operating, custody and payment layers before you commit – so the structure you build is one you can defend. We also work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in VASP authorisation strategy and cross-border regulatory structuring for inbound digital-asset operators across emerging and established markets.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours