Bultenler
An Overview of The Secondary Regulations Concerning Crypto Asset Service Providers in Türkiye
Turkish Capital Markets Board Publishes the Long-Awaited Secondary Regulations for Crypto Asset Service Providers
The following communiqués prepared by the Turkish Capital Markets Board (“Board”) have been published in the Official Gazette dated 13 March 2025 and numbered 32840: (i) Communiqué on the Establishment and Operating Principles of Crypto Asset Service Providers (Communiqué No. III-35/B.1), (ii) Communiqué on the Operating Procedures and Principles and Capital Adequacy of Crypto Asset Service Providers (Communiqué No. III-35/B.2), (iii) Communiqué Amending the Communiqué on the Independent Audit of Information Systems (Communiqué No. III-62.2.b), and (iv) Communiqué on the Principles and Procedures Regarding the Management of Information Systems (Communiqué No. VII-128.10). Thus the long-awaited secondary regulations in the sector have been enacted.
- REGULATIONS INTRODUCED BY THE COMMUNIQUÉ ON THE ESTABLISHMENT AND OPERATING PRINCIPLES OF CRYPTO ASSET SERVICE PROVIDERS (COMMUNIQUÉ NO. III-35/B.1)
The procedures and principles regarding the following matters are regulated under Communiqué No. III-35/B.1:
- The establishment, commencement of operations, ongoing activities, and suspension of activities of crypto asset service providers,
- Their founders and shareholders, including share transfers,
- Their managers, personnel, and organizational structure,
- Internal audit, internal control, and risk management systems, as well as information systems and technological infrastructure,
- Document registration systems, and
- Independent audits and proof-of-reserves audits.
- Establishment Requirements and Operating License of Crypto Asset Service Providers
The establishment requirements for crypto asset service providers are as follows:
- They must be incorporated as joint stock companies.
- All shares must be registered (non-bearer).
- Shares must be issued in exchange for cash.
- The minimum founding capital must exceed the amount determined by the Board.
- Their articles of association must comply with the Board’s regulations.
- Founders must meet the conditions stipulated under the applicable legislation and must be transparent and reliable.
Crypto asset service providers must be authorized by Board in order to commence operations.
Following the approval of establishment by Board, if an application for an operating license is not submitted within six months, the right to obtain such a license is forfeited. Board may extend this period, provided that the total extension does not exceed one year, if deemed necessary.
- Transactions Subject to the Approval of Board
- Any acquisition of shares resulting in a person becoming a shareholder of a crypto asset service provider by directly or indirectly acquiring 10% or more of its capital or voting rights, or any acquisition of shares belonging to an existing shareholder that results in that shareholder’s shareholding exceeding the thresholds of 10%, 20%, 33%, or 50% of the capital or voting rights, as well as any changes in the shareholding structure that result in falling below these thresholds, are subject to the approval of the Board.
- The transfer of privileged shares granting the right to be represented on the board of directors or shares bearing usufruct rights is subject to approval, regardless of the percentage.
- In the case of legal entity shareholders of a crypto asset service provider, if share transfers within such legal entities lead to exceeding the thresholds of 10%, 20%, 33% or 50%, or if they hold managerial privileges, the approval of the Board must be obtained.
- Internal Audit, Control, and Risk Management
- Crypto asset service providers are required to establish internal audit, internal control, and risk management units.
- The internal control function consists of two components: internal control management and information systems internal control management.
- As a minimum requirement, compliance audits with the applicable legislation and business process procedures must be conducted once a year, and the audit results must be submitted to the board of directors.
- The risk management unit must develop procedures aimed at ensuring information security and preventing market manipulation.
- A dedicated unit responsible for the implementation of the risk management system must be established by crypto asset service providers, and a sufficient number of risk management personnel must be assigned to the unit.
- Custody services must be audited to ensure the protection of client assets.
- All transfer and custody processes must be conducted through secure wallet management systems.
- Written procedures must be established regarding the creation of hot and cold wallets
- Recovery Plan
- A recovery plan must be prepared by identifying actions and risks that may result in crypto asset loss, and by determining the actions to be taken in case such risks or actions materialize.
- Crypto asset service providers are obliged to issue risk disclosures to clients, establish framework agreements, and manage transaction processes in a transparent manner.
- Client assets must be segregated and held in secure accounts.
- If the implementation of a recovery plan becomes necessary, information must be provided to clients via the provider’s website regarding how the recovery plan will be implemented and the related business process procedures.
- Prohibited Activities and Transactions for Crypto Asset Service Providers
- No disposition may be made over the client’s crypto assets or cash in favor of themselves or third parties without having the legal rights or authority to do so.
- Crypto asset service providers may not allow their employees or clients to execute transactions on their own behalf and account by taking advantage of opportunities that fall outside the scope of the ordinary client–provider relationship.
- They may not make donations exceeding five per mille (0.5%) of their equity capital within a single fiscal year.
- Advertising Rules
- Crypto asset service providers must use their trade names in all announcements, advertisements, and written communications.
- Advertisements that are misleading or that include guaranteed returns are not permitted.
- Promotional campaigns must be conducted in accordance with specific rules.
- Practices that create unfair competition for the purpose of customer acquisition are not allowed.
- Outsourcing of Services
Outsourcing is not permitted for the following activities:
- Activities that must be carried out exclusively by the board of directors of the crypto asset service provider.
b) The provision and marketing of services and activities that require authorization from Board.
c) The accounting of the transactions of the crypto asset service provider and the preparation of its financial reports.
d) Activities falling within the scope of the internal audit, internal control, and risk management systems.
- Service providers must ensure that security and compliance criteria are met when outsourcing services.
- Outsourced systems must be subject to continuous audit.
The Communiqué entered into force on 13 March 2025.
You can access the full text of the Communiqué (in Turkish) here.
- REGULATIONS INTRODUCED BY THE COMMUNIQUÉ ON THE OPERATING PROCEDURES AND PRINCIPLES AND CAPITAL ADEQUACY OF CRYPTO ASSET SERVICE PROVIDERS (COMMUNIQUÉ NO. III-35/B.2)
The procedures and principles regarding the following matters have been regulated under Communiqué No. III-35/B.2:
- The Services and activities that may be offered by crypto asset service providers,
- The environments for the trading, custody, and transfer of crypto assets,
- The listing of crypto assets on platforms (i.e. entities where one or more of the following activities are carried out: crypto asset trading, ınitial sale or distribution, clearing, transfer, custody required for such activities, and any other transactions to be determined),
- The capital adequacy of crypto asset service providers.
- Services That May Be Offered by Crypto Asset Service Providers
Crypto asset service providers may offer the following services, provided that they obtain authorization from Board:
- Receiving and executing orders for the purchase and sale of crypto assets, clearing, transfer, and custody services,
- Acting as an intermediary in the initial sale or distribution of crypto assets,
- Investment advisory services,
- Other services to be determined by Board.
Transactions involving the purchase, sale, and transfer of crypto assets conducted by crypto asset service providers for their own wallets, without the intention of offering any crypto asset services to parties other than their clients, are not subject to the approval of Board.
The following services may be carried out without the need for a separate authorization certificate, in accordance with the principles determined by the Board:
- Transactions such as purchase and sale, initial sale or distribution, clearing, transfer, and custody of non-fungible and unique digital assets that are used to record representation and ownership of digital assets, as well as assets used solely for the creation or acquisition of various elements in virtual games,
- Services involving financial analysis and the provision of general recommendations regarding crypto assets,
- Other services to be determined by Board.
- Capital
- The minimum founding capital of crypto asset service providers must be TRY 150 million.
- The minimum capital of custody institutions must be TRY 500 million.
- The equity capital of platforms must not be lower than the liquidity reserve requirement.
- Platforms are required to maintain liquid reserves equal to 3% of client assets. In accordance with the liquidity requirement, current assets must at least match short-term liabilities.
- As of June each year, at least 25% of the equity capital of crypto asset service providers must be maintained as paid-in or issued capital.
- 95% of client assets must be held by custody institutions authorized by the Board and only 5% may be held by platforms.
- The borrowing limit of platforms must not exceed three times the capital adequacy threshold.
- Listing and Delisting Criteria
Crypto asset service providers are subject to the Public Disclosure Platform (“Platform”) and must disclose their listing procedures. They must present information about their authorized services and corporate identity on the Platform and their websites.
The following rules apply to the listing and delisting of crypto assets:
- A Listing Committee must be established to evaluate the assets to be listed.
- Listed crypto assets must be evaluated based on the reliability of the project owner, transaction volume, technological infrastructure, and legal status.
- Crypto assets that conceal wallet addresses to enable transfers or are prone to manipulation may not be listed.
- Platforms must regularly review the crypto assets they list and delist them when necessary.
- The principles determined by the Central Registry Agency (“CRA”) regarding the notification of the listed and delisted crypto assets to the CRA shall be complied with.
- Crypto Asset Custody Service and Transfer Rules
- Custody services include the storage and management of clients' crypto assets or private keys that grant the right to transfer assets from wallets, or other services to be determined by the Board.
- Crypto asset custody services may only be provided by banks authorized by the Banking Regulation and Supervision Agency or institutions approved by the Board.
- The size of the hot wallet held by custody institutions must not exceed 5% of the total client assets.
- Multi-factor authentication must be used in transfer transactions, and security measures must be enhanced.
- A service agreement must be signed between platforms and custody institutions.
- Crypto assets held on a platform are not included in the custody limit unless their total value exceeds USD 100,000. If the total value of these assets exceeds 10% of client assets, the exceeding amount must be included in the custody calculation.
The Communiqué entered into force on 13 March 2025.
You can access the full text of the Communiqué (in Turkish) here.
- REGULATIONS INTRODUCED BY THE COMMUNIQUÉ AMENDING THE COMMUNIQUÉ ON INDEPENDENT AUDIT OF INFORMATION SYSTEMS (COMMUNIQUÉ NO. III-62.2.B)
Crypto asset service providers have been included among the entities subject to audit under this Communiqué. Additionally, banks and insurance companies, as well as financial leasing, factoring, financing, and savings financing companies, which are subject to specific regulations concerning the audit of information systems, are subject to the provisions outlined in this Communiqué, provided that they do not conflict with their own regulations.
- Audit
- Market operators, central clearing and custody institutions, data storage institutions, and crypto asset service providers are required to have an independent audit of their information systems conducted annually.
- Institutions, organizations, and partnerships must have their first independent audit of information systems conducted for the year 2025, and subsequent audits must be carried out for the following year.
- Brokerage firms with limited or extended authority and certain portfolio management companies are required to undergo audits every two years.
- Other specific portfolio management companies and the Capital Markets Licensing, Registry, and Training Corporation must undergo audits every three years.
The Communiqué will enter into force on 30 June 2025.
You can access the full text of the Communiqué (in Turkish) here.
- REGULATIONS INTRODUCED BY THE COMMUNIQUÉ ON THE PRINCIPLES AND PROCEDURES REGARDING INFORMATION SYSTEMS MANAGEMENT (COMMUNIQUÉ NO. VII-128.10)
Crypto asset service providers are required to comply with the provisions regulated under this Communiqué.
- Management of Information Systems
- Institutions are required to establish information security policies, have them approved by senior management, and notify relevant parties of these policies.
- The information security policy must be reviewed at least once a year.
- Risk assessment processes must be carried out regularly, analyzing cyber threats, security vulnerabilities, and risks to business continuity.
- The information systems of institutions, organizations, and partnerships must undergo a penetration test at least once a year, conducted by individuals or legal entities who do not have any responsibilities regarding information security requirements and who possess national or international certification for penetration testing.
- Multi-factor authentication must be used in critical systems.
- Time synchronization must be achieved using atomic clock sources.
- Audit of Information Systems Controls
- An audit trail mechanism must be established, and records must be retained for at least five years.
- Any violations or identified security vulnerabilities must be logged as soon as possible, and necessary actions must be taken.
- Data centers and secure areas hosting critical information systems must be protected with access control systems and continuously monitored with camera surveillance systems.
- Multi-layered security measures must be implemented against internal and external threats to corporate networks.
- Network access must be restricted using whitelisting or blacklisting structures, and untrusted connections must be blocked.
- Remote access must be limited using multi-factor authentication.
- Direct access to sensitive data over the internet must be blocked.
- Information security requirements must be included in contracts with external service providers, and these organizations must be regularly audited. The procurement, use, and management of cloud services will be considered as outsourcing.
- Data sharing with third parties must be conducted within an authorized framework, ensuring that audit trails are maintained.
- Information Security Violations
- Institutions are required to establish controls that ensure the management of all information security violations or identified security vulnerabilities in their information systems.
- The effectiveness and currency of the incident response plan must be tested at least once a year.
- Criteria for evaluating information security incidents must be established, and cybersecurity incident response teams must be formed.
- In the event of critical security breaches, the Capital Markets Board of Türkiye and the relevant regulatory authorities must be notified immediately.
The Communiqué will enter into force on 30 June 2025.
You can access the full text of the Communiqué (in Turkish) here.
- RELEVANT DECISIONS IN THE CAPITAL MARKETS BOARD OF TURKIYE BULLETIN NO. 2025/15
Board published Bulletin No. 2025/15 (“Bulletin”) on its official website on 13 March 2025, announcing it to the public.
With the Bulletin, the following Principle Decisions and the specified articles have been repealed by Board Decision No. 8/313 dated 13 February 2025 (“Desicion”).
Principle Decision No. 42/1259 dated 08.08.2024 (Weekly Bulletin No. 2024/38)
The provisions regulated and repealed in the Decision are as follows:
- Establishment requirements for platforms
- Requirements for founders, shareholders, and managers
- Establishment procedures for platforms
Principle Decision No. 48/1484 dated 19.09.2024, Articles 1, 2, 3, 4, 5, 6, 8, 9, and 12 (Weekly Bulletin No. 2024/48)
The provisions included in the Decision have been repealed, except for the following matters:
- Regarding the transfer of data from platforms to the CRA platforms are required to ensure compliance with the technical infrastructure requirements to be determined by CRA and to perform system integration in accordance with the format and schedule specified by CRA.
- In transactions where platforms act as the counterparty to their clients, the principle is that the sale must be made in an amount equal to the crypto assets available in the platform’s wallets. In transactions where clients’ operations match each other, the responsibility for ensuring that the relevant crypto assets are present in the respective accounts and transferred to the corresponding parties lies with the platforms. Platforms are prohibited from making any disposals of clients' crypto assets or cash in favor of themselves or third parties. Borrowing crypto assets, transactions that result in providing credit to clients, and leveraged transactions cannot be conducted by platforms. Positions and transactions under this provision must be closed within an appropriate transition period in a way that avoids client losses.
a) As is well known, the seventh paragraph of Article 35/B of the Capital Markets Law No. 7518 reserves the duties and powers of institutions and organizations arising from other legislation related to crypto assets. In this regard, the Law on the Amendment of the Capital Markets Law No. 7518 does not introduce any changes to the current legislation concerning any activities related to crypto assets except for those falling under the regulation of the Board. All obligations and sanctions arising from the current legislation remain in effect, and the use of crypto assets as a tool in the activities does not create any difference in terms of the obligations and sanctions prescribed by the legislation. Therefore, activities in areas of authority and regulation of other institutions and organizations in our country such as commodities, real estate, etc., must be conducted in accordance with the regulations of these institutions and organizations regardless of whether the tool used is a crypto asset. Crypto assets that do not comply with this provision may not be listed on platforms.
b) The matters explained in paragraph (a) are also valid in terms of capital markets legislation. Considering that the infrastructure for the custody of crypto assets and the proof-of-reserves mechanisms are not yet operational and in accordance with Article 13 of the Law, no crypto asset may be issued or listed on platforms before regulations are made by the Board regarding the issuance of capital market instruments as crypto assets. Furthermore, according to Article 3 of the Law, capital market instruments, indices determined in connection with capital market instruments, baskets where various asset groups (including crypto assets) are combined, precious metals and assets based on the underlying assets regulated under the Communiqué on Warrants and Investment Firm Certificates No. VII-128.3 may not be used for the issuance of crypto assets and may not be listed on platforms.
c) With regard to the crypto assets that are currently listed under paragraphs (a) and (b), new sales and distributions may not be conducted by platforms. However, the conversion of the assets already sold and distributed into cash or the transfer between clients within the scope of customer requests is allowed.
The Principle Decisions outlined above, along with the specified articles, have been repealed from the regulations covered by Communiqué No. III-35/B.1 on the Establishment and Operating Principles of Crypto Asset Service Providers and Communiqué No. III-35/B.2 on the Operating Procedures and Principles and Capital Adequacy of Crypto Asset Service Providers.
You can access the full text of the CMB Bulletin No. 2025/15 (in Turkish) here.
You can access the full text of the CMB Bulletin No. 2024/48 (in Turkish) here.
You can access the full text of the CMB Bulletin No. 2024/38 (in Turkish) here.
Kind regards,
Zumbul Attorneys-at-Law
All information and documents on our website have been prepared by Zumbul Attorneys at Law for general informational purposes only, in accordance with the Attorneyship Law, other relevant legislation and the Professional Rules of Attorneyship of the Union of Turkish Bar Associations. These publications are not intended for advertising or commercial purposes. The information and documents provided are of a general nature and under no circumstances, do they guarantee or warrant that the content is complete, accurate, up-to-date, or reliable. You should not rely on the information and documents on this website without first consulting a lawyer or expert. The links included in our website’s publications are sourced from publicly available materials and are provided solely for the convenience of visitors in accessing additional information. These links do not constitute any form of recommendation or endorsement of the linked persons, institutions or organizations. The information on this website does not in any way constitute legal advice or establish an attorney-client relationship with visitors to the site. All content on this website is the property of by Zumbul Attorneys at Law, and no content may be copied, reproduced, or used without prior written permission.
Türkçe
English