Reverse solicitation is a market access concept that limits how foreign firms can actively market services into a jurisdiction. In Turkey’s crypto rules, it restricts non-resident CASPs from using active promotion or local presence to serve Turkish users, which helps regulators control cross-border exposure and enforcement scope.
How Reverse Solicitation Works in Market Access
Reverse solicitation is a jurisdictional boundary concept, not a marketing tactic. It draws a line between a firm actively soliciting users in a market and a user or counterparty initiating the relationship without that active push. In cross-border financial services and crypto contexts, that distinction can determine whether a foreign provider is treated as serving a local market or simply responding to an unsolicited request.
In practice, the rule is used to narrow the circumstances in which a non-resident firm can rely on an exception to local licensing or registration expectations. That makes the concept important in regimes where regulators want to prevent firms from entering a market through informal promotion, indirect channels, or a nominally offshore setup that still targets local users.
Because the doctrine depends on conduct and evidence, organisations should think about what their website, ads, referrals, local language materials, and business development activity communicate. The issue is not only whether a local customer can technically click through, but whether the firm is behaving as if it is actively seeking that market.
Why It Matters for Cross-Border Compliance
Reverse solicitation matters because it affects enforcement scope, regulatory perimeter, and whether a foreign provider can argue that its activities were user-led rather than market-led. In Turkey’s crypto context, it helps regulators limit exposure to non-resident CASPs that use active promotion or local presence to reach Turkish users.
For firms, the practical consequence is that market-entry behaviour can become a compliance issue even before a local licence discussion begins. A weak boundary between passive availability and active solicitation can create supervisory scrutiny, especially when the firm’s conduct suggests it is building a customer base in the jurisdiction rather than merely responding to inbound demand.
This is also why evidence preservation matters. If a provider intends to rely on reverse solicitation, it should be able to show how the relationship started, what was said publicly, and whether any local targeting took place. Compliance often turns on facts, not labels.
Where the Boundary Usually Gets Tested
Reverse solicitation is most often tested where digital distribution blurs geography. A website, app, or social channel can be globally reachable while still being clearly aimed at a specific country through language, pricing, onboarding flows, local representatives, or region-specific campaigns.
That boundary is also strained when firms use intermediaries, affiliates, or influencers. Even if the ultimate onboarding appears customer-initiated, upstream promotion can still look like active solicitation. Regulators usually care about the substance of the go-to-market behaviour, not the formal story attached to it.
For teams working across jurisdictions, the key question is whether the firm is passively accessible or actively pursuing the local market. Reverse solicitation is easier to defend when the local user truly originates the contact and the provider has not created a tailored path that invites that user in.
What Practitioners Should Watch For
Common misunderstanding: reverse solicitation is often treated as a blanket exemption for any cross-border digital service. It is not. The concept is narrow, fact-sensitive, and vulnerable to being undermined by ordinary marketing activity that looks harmless in one market but targeted in another.
Why practitioners should care: if the solicitation story is weak, firms may find that licensing, consumer protection, conduct, or local presence obligations still attach. That can turn a commercial growth decision into a regulatory exposure issue, especially when the service is financial, crypto-related, or otherwise closely supervised.
Practitioner takeaway: if a business intends to rely on reverse solicitation, align marketing, onboarding, and evidentiary recordkeeping so the channel by which the customer arrived matches the legal theory being claimed.
Risk and Threat Considerations
Reverse solicitation creates regulatory exposure when firms blur passive availability and active targeting. The main risk is not technical compromise, but perimeter drift, where a cross-border service starts looking like an unlicensed local offering because its own conduct created the jurisdictional hook.
Failure mechanism: active promotion, localised messaging, intermediaries, or a de facto local presence can undermine the reverse-solicitation position and expose the firm to enforcement, market-access restrictions, or customer remediation obligations.
Impact: the organisation may lose the ability to rely on a narrow cross-border exception, face supervisory action, and create compliance uncertainty for onboarding, contract validity, and future expansion.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the technical controls, while GDPR define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.SC — Cyber Supply Chain Risk Management | Governs third-party and cross-border exposure created by external service relationships. |
| Recommendation — Assess jurisdictional and third-party exposure before allowing market-facing cross-border service delivery. | ||
| CIS Controls v8 | 15 — Service Provider Management | Applies because outsourced, affiliate, or third-party channels can create solicitation and compliance risk. |
| Recommendation — Review third-party and affiliate channels for conduct that could create local market solicitation risk. | ||
| GDPR | Art. 5 — Principles Relating to Processing of Personal Data | Applies where cross-border market activity also involves personal-data collection or targeted processing. |
| Art. 25 — Data Protection by Design and by Default | Applies when jurisdictional targeting depends on app, website, or onboarding design choices. | |
| Recommendation — Limit targeting and data collection to what is transparently justified by the established market relationship. Build onboarding and targeting flows to avoid unnecessary localised data collection or regional overreach. | ||
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 17, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org