Quick Summary: What You Need to Know About Crypto Licensing in Turkey
Turkey’s crypto asset market one of the largest by retail adoption globally now operates under a comprehensive licensing framework administered by the Capital Markets Board (CMB/SPK). If you are a founder, general counsel, compliance lead, or investor planning to launch or regularise crypto asset service provider (CASP) operations in Turkey, this page gives you the complete picture: who needs a licence, core eligibility and fit-and-proper standards, capital and custody requirements, transitional deadlines under the 2025–2026 regime, AML/KYC and Travel Rule obligations, the emerging tax and fee landscape, and a practical eight-step application checklist with realistic timelines. Every claim on this page is sourced directly from the relevant statute, regulator communiqué, or official registry guidance so you can plan with confidence.
For a quick-reference overview, download the one-page Turkey CASP Application Checklist (PDF) a summary of the twelve core documents your application dossier must contain, from incorporation papers and capital proof through to your disaster recovery plan and MASAK compliance officer appointment evidence.
Who Needs a CASP Licence in Turkey?
Activities in Scope
Law No. 7518, which amended the Capital Markets Law No. 6362, defines “crypto asset service providers” (Kripto Varlık Hizmet Sağlayıcılar KVHS) and brings a broad range of activities under SPK supervision. Services that require a CASP licence include:
- Trading platform operation: Operating order books, matching engines, or any marketplace where crypto assets are bought, sold, or exchanged.
- Custody and safekeeping: Holding, storing, or managing crypto assets and private keys on behalf of clients.
- Transfer services: Facilitating the transfer of crypto assets between wallets or accounts.
- Token listing and initial sales/distributions: Listing new crypto assets for trading or organising initial token offerings and distributions to the public.
Who Must Apply
The licensing obligation applies to all domestic platforms already active in the Turkish market and to foreign platforms that target Turkish residents including through Turkish-language interfaces, localised marketing, Turkish lira payment integrations, or partnerships with Turkish payment institutions. The concept of “reverse solicitation” is narrowly interpreted: if a platform is actively directing services toward persons in Turkey, it will generally be treated as requiring SPK authorisation, regardless of where the platform is incorporated.
Enforcement is a live risk. Operating without an SPK licence while serving Turkish residents may constitute unlicensed capital markets activity under Law No. 7518, carrying administrative fines and potential criminal liability. Existing platforms that pre-date the licensing regime must apply within the transitional windows set by the SPK failure to do so risks enforcement action and compulsory cessation of services.
Key Dates and Legal Basis
Primary Statutes and Instruments
The Turkish CASP framework rests on several interlocking instruments:
- Law No. 7518: Enacted to amend the Capital Markets Law (No. 6362), this statute introduced formal definitions of crypto assets and CASPs, granted the SPK regulatory authority over the sector, and established ownership suitability, governance, and sanctions rules. The full law text is published through the TBMM archive.
- SPK Communiqués (Tebliğ) III-35/B.1 and III-35/B.2: Published on 13 March 2025, these communiqués set out the detailed licensing procedures (III-35/B.1) and capital, operational, and custody requirements (III-35/B.2) for CASPs.
- MASAK KVHS Rehberi: The Financial Crimes Investigation Board published an updated guidance document for CASPs covering KYC, transaction monitoring, suspicious transaction reporting, and Travel Rule compliance.
- Official Gazette / Resmî Gazete references: Certain implementing measures and presidential decisions including those published in the 27 February 2026 issue further clarify deadlines and procedural details.
Transitional Deadlines and Enforcement Windows (2025–2026)
The SPK has published transitional timetables through its bulletins and member communications. Existing platforms were given defined windows to submit their licence applications and bring operations into compliance. The regulator has signalled that it will not grant indefinite extensions: platforms that fail to file complete dossiers within published deadlines face enforcement proceedings. Industry observers expect the SPK to take a progressively firmer stance as 2026 enforcement windows narrow, particularly for platforms that have not demonstrated material progress toward compliance. For the latest published deadlines, operators should monitor SPK announcements and tebliğ updates.
Licence Requirements: Entity, Capital, Governance, and Custody
Legal Entity and Ownership
Under Law No. 7518, a CASP must be established as a Turkish joint-stock company (anonim şirket). Branches of foreign entities are not permitted as standalone licensees; foreign operators must incorporate a local legal entity in Turkey. Key structural requirements include:
- Ownership transparency: The identity of all direct and indirect shareholders above specified thresholds must be disclosed to the SPK, and each qualifying shareholder must pass suitability assessments.
- Suitability tests: Shareholders, ultimate beneficial owners, and senior managers are subject to fit-and-proper evaluations covering criminal record checks, financial soundness, and regulatory history.
- Registered capital system: The company must operate under the registered capital system as prescribed by the SPK communiqués.
Minimum Capital and Capital Adequacy
The SPK communiqué III-35/B.2 sets out capital and solvency requirements that vary by the scope of licensed activities. Operators seeking to provide trading, custody, and market-making services face higher capital bands than those offering only transfer or listing services. Key capital-related obligations include:
- Minimum paid-in capital: Amounts are set by activity category in the communiqué tables. Operators should consult the specific tebliğ schedules for their intended service mix.
- Ongoing capital adequacy: CASPs must maintain capital ratios and demonstrate continuous compliance through periodic reporting to the SPK.
- Reserve proof and independent attestation: Platforms must provide reserve proof evidence that customer crypto assets held correspond to on-chain and off-chain records verified by independent auditors meeting SPK criteria.
Corporate Governance and Fit-and-Proper Requirements
The SPK expects a governance structure that mirrors the standards applied to other regulated capital markets intermediaries. Specific requirements under the SPK communiqués include:
- Board composition: The board must include members with relevant financial services, technology, or risk management experience. At least one board member should be resident in Turkey.
- Local representative: A locally resident representative with authority to interact with the SPK and other regulators is required.
- Compliance officer (Uyum Görevlisi): A MASAK-accredited compliance officer must be appointed as part of the AML/CFT programme. This individual is responsible for suspicious transaction reporting, internal AML policy oversight, and regulatory liaison.
- Internal audit and risk management: Separate internal audit and risk management functions staffed by appropriately qualified personnel must be established before the licence application is submitted.
Technology, Security, and Operational Resilience
The SPK communiqués set detailed expectations for IT infrastructure and operational resilience. Applicants must demonstrate:
- Wallet architecture policies: Clear policies governing the use of cold, warm, and hot wallets, including maximum hot-wallet exposure limits and multi-signature controls.
- Information security standards: Security frameworks must align with recognised standards, and the SPK references TÜBİTAK criteria for certain technology assessments.
- Disaster recovery and business continuity: Documented disaster recovery plans, tested at regular intervals, must be in place before go-live.
- Proof-of-reserves infrastructure: On-chain attestation mechanisms and reconciliation tools must be operational to support periodic reserve proof obligations.
Custody Models and MKK/KVMKS Interactions
Turkey has established the Crypto Asset Central Registry System (KVMKS), operated by the Central Securities Depository of Turkey (MKK), as a core infrastructure component for the sector. The MKK’s KVMKS member letters detail the integration, reporting, and fee obligations that apply to licensed CASPs. Key custody models include:
- Segregated custody: Client assets held in individually segregated wallets with clear on-chain attribution to each customer.
- Omnibus custody: Pooled wallet structures with robust internal sub-accounting and reconciliation.
- Dedicated custodian: Engagement of a separately licensed custodian entity for asset safekeeping.
All licensed platforms must register with the KVMKS and comply with its reporting requirements for token types that fall within the system’s scope. KVMKS membership carries its own fee schedule, published in the MKK’s member letters and tariff notices.
Independent Audit and Reserve Proof
Licensed CASPs must engage independent auditors to verify reserve proof statements on a periodic basis. The scope of the audit includes confirming that aggregate client crypto asset balances match the assets held in custody across cold, warm, and hot wallets and that the CASP’s own capital resources meet ongoing adequacy requirements. The SPK expects these attestation reports to be filed according to schedules set in the communiqués and made available to the regulator upon request.
Turkey CASP Licence vs UK and EU Regimes: Comparison
| Feature |
Turkey (CMB/SPK) |
UK (FCA Cryptoasset Regime) |
EU (MiCA Framework) |
| Licensing authority |
SPK (CMB) communiqués III-35/B.1 & III-35/B.2 |
FCA permissions vary by activity |
National competent authorities under MiCA (EU-wide framework) |
| Capital & solvency |
Activity-based bands; reserve proof and independent attestations required |
Varies; PRA/FCA regimes for e-money/custody with separate thresholds |
MiCA includes prudential and organisational rules for CASPs |
| Custody model |
MKK KVMKS reporting & custody integration; SPK reserve/audit expectations |
Custody often bank/custodian-based or segregated models |
Standardised asset-class treatment under MiCA |
| AML / Travel Rule |
MASAK KVHS Rehberi and Travel Rule expectations under Turkish AML law |
FCA enforces AML/CTF with JMLSG guidance |
FATF & EU AMLD / MiCA frameworks |
| Passporting |
No passporting; Turkey-specific licence only |
UK-specific; no EU passport post-Brexit |
MiCA licence passportable across all EU/EEA member states |
AML/KYC and Travel Rule Interactions
MASAK Obligations for CASPs
Turkey’s Financial Crimes Investigation Board (MASAK) imposes direct AML/CFT obligations on all crypto asset service providers. The updated KVHS Rehberi sets out detailed requirements covering:
- Customer due diligence (KYC): Identity verification at onboarding, including document verification, liveness checks, and enhanced due diligence for high-risk customers.
- Ongoing transaction monitoring: Automated and manual monitoring of transactions against risk typologies, with calibrated alert thresholds.
- Suspicious transaction reports (STRs): Mandatory and timely filing of STRs with MASAK when transactions or customer behaviour trigger suspicious activity indicators.
- Record keeping: Retention of all KYC records, transaction data, and monitoring logs for the periods prescribed by Turkish AML legislation.
Travel Rule: Data Elements and Interoperability
MASAK expects CASPs to comply with the FATF Travel Rule (referred to as “Seyahat Kuralı” in Turkish guidance). In practical terms, this means:
- Originator and beneficiary data: For crypto asset transfers above applicable thresholds, CASPs must collect, transmit, and verify sender and recipient identifying information.
- VASP messaging standards: Platforms must implement interoperable messaging protocols to exchange Travel Rule data with counterpart VASPs whether domestic or international.
- Wallet attribution and off-ramp checks: Transfers to unhosted wallets require additional due diligence, including wallet attribution analysis and, where risk-indicated, blocking or escalation procedures.
Integration with SPK Licensing
The AML/KYC programme is not a separate workstream it is a core component of the SPK licence application dossier. Applicants must demonstrate that their MASAK-accredited compliance officer (Uyum Görevlisi) is in place, that internal AML policies are documented and operational, and that technical monitoring and Travel Rule systems have been tested and are producing audit-ready logs.
Tax and Fees Impact
2026 Tax Proposals and Likely Operator Impact
Parliamentary proceedings in early 2026 introduced draft legislation contemplating a quarterly withholding tax (tevkifat) on crypto asset transactions. The committee report documents indicate a proposed rate in the range of 10%, with the Presidency granted authority to adjust the rate. If enacted as drafted, platforms would be required to withhold and remit tax on qualifying transactions on a quarterly basis and maintain detailed reporting records.
Industry observers expect this to materially affect operator economics, product pricing, and the competitiveness of Turkey-based platforms relative to those in jurisdictions with no crypto-specific transaction taxes. Operators should model the cashflow impact of withholding obligations and build reporting infrastructure proactively even before final enactment to avoid scrambling when compliance deadlines crystallise.
Regulator and Registry Fees
Licensing and ongoing regulatory costs include SPK application fees (set out in SPK bulletins) and MKK KVMKS membership and tariff fees. The KVMKS tariff covers custody reporting integration, periodic data submissions, and registry services. Operators should budget for both one-off onboarding fees and recurring annual charges.
Cross-Border Services, VAT/KDV, and Tax Rulings
The treatment of crypto asset services under Turkey’s VAT (KDV) regime remains subject to evolving administrative interpretation. Operators providing cross-border services should seek advance clarity from the Revenue Administration (GİB) and, where necessary, apply for binding tax rulings through official Treasury and Ministry of Finance channels. Tax and withholding guidance for crypto in Turkey is a rapidly developing area operators are strongly advised to integrate tax planning into their compliance roadmap from day one.
Application Checklist and Timeline: How to Get a Crypto Licence in Turkey
If you are a compliance lead or general counsel, here is a practical eight-step process and a realistic timeline for obtaining your CASP licence from the SPK.
-
Pre-Assessment and Gap Analysis (1–3 weeks)
- Map your existing service offering against the SPK activity definitions in communiqué III-35/B.1.
- Identify gaps in capital, governance, custody, and AML compliance.
- Deliverable: gap analysis memo and internal checklist.
- Owner: General counsel / external regulatory adviser.
-
Corporate Formation or Local Entity Decision (2–6 weeks)
- Decide between new Turkish anonim şirket incorporation or restructuring existing entities.
- Prepare articles of association conforming to SPK requirements; resolve nominee vs direct ownership structures.
- Deliverable: incorporation documents, shareholder register, notarised articles.
- Owner: Corporate / M&A counsel.
-
Governance and Personnel Appointments (4–8 weeks, concurrent)
- Recruit locally resident board member(s), compliance officer (MASAK Uyum Görevlisi), and IT/security lead.
- Prepare and submit CVs, criminal background checks, and board appointment resolutions.
- Deliverable: appointment documentation, fit-and-proper evidence packs.
- Owner: HR / compliance team.
-
Technology and Custody Readiness (4–12 weeks)
- Build or adapt cold/warm/hot wallet architecture; implement proof-of-reserves infrastructure.
- Integrate with KVMKS reporting APIs where required for registered token types.
- Deliverable: technology architecture document, audit plan, KVMKS integration test results.
- Owner: CTO / infrastructure team.
-
AML/KYC Programme and Travel Rule Implementation (4–10 weeks)
- Develop KYC onboarding flows, transaction monitoring rule sets, and Travel Rule messaging capability.
- Test Travel Rule data exchange with counterpart VASPs; document test results in line with MASAK KVHS Rehberi expectations.
- Deliverable: AML/CFT manual, monitoring test logs, Travel Rule interoperability evidence.
- Owner: MLRO / compliance officer.
-
Prepare Application Dossier and Independent Audit Statements (2–6 weeks)
- Compile corporate documents, shareholder suitability evidence, capital proof, internal controls documentation, and independent reserve attestation report.
- Deliverable: complete application binder conforming to SPK requirements.
- Owner: Compliance lead / external adviser.
-
SPK Submission and Regulator Interaction (8–24 weeks)
- Submit formal application to the SPK; respond to clarification requests and technical queries.
- Expect iterative rounds of questions, possible on-site inspections, and requests for supplementary evidence.
- Deliverable: SPK questions log, supplementary filings, and any required public notices.
- Owner: Regulatory affairs team / external counsel.
-
Go-Live Conditions and Ongoing Compliance Monitoring (post-licence)
- Satisfy any pre-launch conditions imposed by the SPK.
- Commence periodic reporting to MKK/KVMKS, MASAK filings, and SPK supervisory returns.
- Establish internal audit cycle and continuous monitoring infrastructure.
- Owner: Compliance and operations teams.
Timeline Summary
| Phase |
Estimated Duration |
| Pre-assessment through dossier preparation (Steps 1–6) |
3–6 months |
| SPK review and regulator interaction (Step 7) |
2–6 months |
| Total end-to-end estimate |
4–9 months |
Common delay points include foreign ownership verification, reserve attestation by independent auditors, and MASAK compliance officer accreditation. Operators who begin corporate formation and AML programme development in parallel with the gap analysis can compress the timeline significantly.
Core Application Documents
Your application dossier should contain at least the following twelve documents. Download the Turkey CASP Application Checklist (PDF) for a printable version:
- Company formation documents: Articles of association, trade registry excerpts, shareholder register.
- Shareholder KYC packs: Identity documents, beneficial ownership declarations, suitability questionnaires.
- Capital proof: Bank statements, audited financial statements, capital adequacy calculations.
- Board and management appointments: Resolutions, CVs, criminal background check certificates.
- Compliance officer evidence: MASAK Uyum Görevlisi appointment documentation and accreditation proof.
- AML/CFT compliance manual: KYC policy, transaction monitoring procedures, STR filing protocols.
- IT security policy: Information security framework, penetration test reports, incident response plan.
- Custody contracts and architecture: Wallet policy documents, custodian agreements, KVMKS integration plan.
- Reserve proof and audit plan: Independent auditor engagement letter, reserve attestation methodology.
- Sample customer agreement: Draft terms and conditions for platform users.
- Disaster recovery plan: Business continuity and disaster recovery documentation with test evidence.
- Organisational chart: Reporting lines, committee structures, and key personnel mapping.
Sources