Cesa Yazılım
TR EN DE

AMP • EN

How to Obtain a Payment Institution License in Turkey (2025/2026)

Step-by-step guide to getting a payment institution license in Turkey: capital requirements, BDDK application, compliance, security, and operational readiness.

How to Obtain a Payment Institution License in Turkey (2025/2026)

This guide covers the BDDK payment institution license process with capital, compliance, security, and operational requirements. Built as a hub page with spoke links to detailed long-tail topics (PCI-DSS, KYC/AML, DR/BCP, capital planning).

Last updated

1) Legal and corporate framework

2) Capital and financial adequacy

3) Technical and security requirements

4) Compliance and operations

5) Application dossier (core docs)

6) Illustrative timeline (may vary)

  1. Preparation (policies, architecture, docs): 6–10 weeks
  2. Filing and pre-discussions: 2–4 weeks
  3. BDDK review & clarifications: 8–16 weeks
  4. License & go-live permit: total 4–8 months depending on readiness

7) Checklist

8) Hub-spoke and internal links

FAQ

What is the minimum paid-in capital?

BDDK sets minimum paid-in capital for payment institutions; EMIs require a higher threshold. Check latest BDDK publications for exact amounts.

Which technical documents are mandatory?

Network/system architecture, access matrix, HA/DR design, security controls (WAF/DDoS/IPS), PCI-DSS/3DS design, logging/audit policies.

Which KYC/AML steps are expected?

Electronic ID verification, watchlist screening, suspicious transaction scenarios, STR filing, data retention aligned with KVKK.

How long does it take?

Typical cycle is 4–8 months depending on dossier completeness and technical readiness.

Is PCI-DSS required?

If you process/handle card data, PCI-DSS is expected. Even with tokenized models, segmentation and controls are reviewed.

Why is DR/BCP important?

Continuous service and regulatory expectations demand proven RPO/RTO targets, redundant infrastructure, and tested drills.

Conclusion

Licensing requires strong compliance, secure architecture, resilient ops, and solid financial planning. A hub-spoke content approach plus a complete technical dossier accelerates approvals.

Need expert help?

Sıkça Sorulan Sorular

What is the minimum paid-in capital? BDDK sets minimum paid-in capital for payment institutions; EMIs require a higher threshold. Check latest BDDK publications for exact amounts.

Which technical documents are mandatory? Network/system architecture, access matrix, HA/DR design, security controls (WAF/DDoS/IPS), PCI-DSS/3DS design, logging/audit policies.

Which KYC/AML steps are expected? Electronic ID verification, watchlist screening, suspicious transaction scenarios, STR filing, data retention aligned with KVKK.

How long does it take? Typical cycle is 4–8 months depending on dossier completeness and technical readiness.

Is PCI-DSS required? If you process/handle card data, PCI-DSS is expected. Even with tokenized models, segmentation and controls are reviewed.

Why is DR/BCP important? Continuous service and regulatory expectations demand proven RPO/RTO targets, redundant infrastructure, and tested drills. Conclusion Licensing requires strong compliance, secure architecture, resilient ops, and solid financial planning. A hub-spoke content approach plus a complete technical dossier accelerates approvals. Need expert help? 📧 iletisim@cesayazilim.com 📞 +90 850 225 53 34 💬 WhatsApp: Payment License Desk