Legislation · Türkiye · Law (No. 7545)

Cybersecurity Law (No. 7545)

Cybersecurity Law No. 7545 (Siber Güvenlik Kanunu) has been in force since 19.03.2025 and its scope is not confined to critical infrastructure: it covers every real and legal person that exists, operates or provides services in cyberspace. The implementing secondary legislation had not been published as of July 2026, but the Article 7 duties and the administrative fines attached to them are enforceable now.

In forceIn force · 19.03.2025Source · Official Gazette 19.03.2025, No. 32846Threshold · Anyone operating or providing services in cyberspace
In summary

The Law gives the Cybersecurity Directorate powers to demand information, documents, data and log records, to conduct incident response on site or remotely, and to audit. Entities in scope must meet those requests as a priority, report vulnerabilities and incidents without delay, and, in critical infrastructure, procure only from authorised suppliers. Under Article 18, transactions conferring control on foreign parties require approval, and a transaction carried out without approval has no legal validity. (As of July 2026)

Who does it affect?

Every company in cyberspace

Scope is not limited to critical infrastructure; Article 2 reaches real and legal persons and unincorporated entities alike.

Critical infrastructure sectors

In the fifteen sectors determined on 05.05.2026, procurement is limited to authorised and certified suppliers.

Investors and acquirers

Share transfers giving foreign parties control of a cybersecurity product manufacturer have no legal validity without approval.

Key Obligations
  • 01Supply information and assistance promptly and as a priority whenever the Directorate requests it (Article 7(1)(a)).
  • 02Report vulnerabilities and incidents without delay; the Law sets no numeric deadline, leaving that to secondary legislation (Article 7(1)(b)).
  • 03Procure from authorised suppliers if you are a public institution or a critical infrastructure (Article 7(1)(c)).
  • 04Obtain approval for transfers and exports where foreign control arises; a transaction without approval has no legal validity (Article 18).

Overview

Cybersecurity Law No. 7545 (Siber Güvenlik Kanunu) was adopted on 12.03.2025, published in the Official Gazette of 19.03.2025 (No. 32846) and in force the same day (Article 20). It sets out the framework, powers and sanctions for cybersecurity in Türkiye. The implementing secondary legislation has not appeared: the one-year period in Provisional Article 1(6) expired on 19.03.2026 and, as of July 2026, nothing substantive has been published; what appeared that day concerned internal staffing.

Scope and institutions

Article 2 draws the scope unusually widely: public institutions, professional organisations with public-institution status, and real and legal persons and unincorporated entities that exist, operate or provide services in cyberspace. The scope is not limited to critical infrastructure. Intelligence activities under Laws 2559, 2692, 2803, 2937 and 211 are excluded.

Operational authority rests with the Cybersecurity Directorate (Siber Güvenlik Başkanlığı); the Cybersecurity Board, chaired by the President of the Republic, sets policy and determines the critical infrastructure sectors (Article 9). On 05.05.2026 it determined fifteen: digital infrastructure, digital services, electronic communications, energy, finance, food and agriculture, manufacturing industry, public services, media and crisis communication, post and courier services, health, defence industry, water management, transport and space.

The Article 6 powers are intrusive: the Directorate may demand product-generated data and log records, conduct incident response on site or remotely, and access archives, data centres and communication infrastructure — which no entity may refuse by invoking its own sectoral legislation.

Key obligations

Article 7(1) sets five private-sector duties: supply any requested data, document, hardware or software promptly and as a priority; take the measures prescribed by legislation and report detected vulnerabilities or cyber incidents to the Directorate without delay, the Law fixing no numeric deadline; in public institutions and critical infrastructures, procure cybersecurity products and services only from suppliers it has authorised and certified; cybersecurity companies subject to certification must obtain approval before commencing operations; and the policies and action plans of the Directorate must be implemented.

Audit, transfers and export approval

Under Article 8 the Directorate may audit on site with its own staff or authorised independent auditors; the audited entity must keep systems open and provide access (Article 8(4)). Article 8(5) also permits search, copying and seizure at non-public premises on a judicial order.

Article 18 is the provision most often overlooked. Export of cybersecurity products, software, hardware and services follows procedures set by the Directorate, and listed products require approval. Mergers, demergers, share transfers and sales of companies producing them must be notified; where the transaction confers direct or indirect control on foreign persons, approval is required and a transaction without it has no legal validity (Article 18(3)). This bears on deal structuring today.

What this means for Turkish companies

The absence of implementing regulations is no reason to wait. The first step is a written procedure setting out who reports, at what threshold and through which channel (Article 7(1)(b)); with no numeric standard, the records evidencing timely escalation decide the case.

The critical point for Turkish exporters

The missing secondary legislation does not suspend the Article 7 duties. They are binding today, and breaches of Articles 7(1)(b) and 7(1)(c) carry administrative fines of TRY 1,000,000 to TRY 10,000,000 — nominal 2025 figures, revalued each year at the statutory revaluation rate.

Companies in one of the fifteen sectors should review the supply chain now. Article 7(1)(c) requires authorised and certified suppliers, and because that regime does not yet exist the correct posture is contractual: supplier warranties as to credentials, compliance undertakings, audit rights and a repapering trigger for when the regime arrives. Producers of cybersecurity products should also map which activities need prior approval (Article 7(1)(ç)).

Provisional Article 1(4) gives cybersecurity associations, federations, foundations and commercial companies one year to complete certification and authorisation — but that year runs from the entry into force of the Provisional Article 1(6) regulations, not from the Law. Because those had not been published as of July 2026, the period has not begun, and any commentary quoting a fixed end date is an assumption. Audit readiness is meanwhile the largest financial exposure, and it turns on process, not a breach.

Enforcement and penalties

Article 16 carries criminal sanctions alongside fines. Imprisonment ranges from one to three years for withholding or obstructing requested information, through two to four years for operating without a required approval and four to eight years for breach of the Article 13 confidentiality duty, up to eight to twelve years for cyber attacks on the elements of national power in cyberspace. Article 16(7) raises these by one third, one half or up to double for public officials, multiple offenders and organised activity respectively.

The administrative fines (Article 16(10)–(11)) are nominal 2025 figures, revalued each year at the statutory revaluation rate: TRY 1,000,000 to 10,000,000 for Articles 7(1)(b) and 7(1)(c); TRY 10,000,000 to 100,000,000 for Article 18; and TRY 100,000 to 1,000,000 for the Article 8(4) audit duties, rising for commercial companies to as much as 5% of gross sales revenue in the audited annual financial statements. Article 17 adds a 30-day written defence, one-month payment and appeal to the administrative courts.

Related content

Read it with the KVKK record for the personal data dimension and NIS2 for the EU counterpart; foreign investment approvals sit in the Foreign Direct Investment Law No. 4875 record and incident response in our Cybersecurity focus area.

Entry into force & amendment history

  • 01.06.2026

    Notifications moved to API

    The Directorate began delivering security notifications by API through siberguvenlik.gov.tr.

  • 05.05.2026

    Fifteen critical sectors determined

    The Cybersecurity Board identified the sectors treated as critical infrastructure.

  • 19.03.2026

    Deadline for regulations missed

    The one-year period in Provisional Article 1(6) expired with no substantive implementing regulation.

  • 19.03.2025

    Law entered into force

    Published in the Official Gazette (No. 32846) and effective the same day.

This record is provided for general information and monitoring only; it does not constitute legal advice or create an attorney–client relationship. The official text in force is authoritative. Contact our team for a scope and compliance assessment specific to your company.
02

Focus & Sector Links

This regulation creates a cross-disciplinary focus with a greater impact on certain sectors.

DC
Related Desk · Regional

Data & Cybersecurity Desk

Integrated advice spanning multiple jurisdictions in KVKK and GDPR compliance, cross-border data transfer, and cyber incident response.

Explore the regional desk
03

How We Help on This Matter

We structure compliance with this instrument across both the Türkiye and DACH sides of your business.

Scope and Status Analysis

Determining the position of the company under Article 2 and its relationship to the fifteen critical infrastructure sectors.

Reporting Process Design

Internal procedure, authority matrix and records enabling vulnerabilities and incidents to be reported without delay.

Supplier Contracts

Contractual undertakings, audit rights and repapering triggers for the period until the authorisation regime is published.

Audit Readiness

Preparing for the access, documentation and process duties that apply during an Article 8 audit.

Transfers and Shareholding

Building the Article 18 notification and approval requirements into transaction structures.

All our services
Legislation · Türkiye

Cybersecurity Law (No. 7545) — obtain the right legal support.

Let us assess the impact of this regulation on your business and establish a practical compliance framework.