The Law gives the Cybersecurity Directorate powers to demand information, documents, data and log records, to conduct incident response on site or remotely, and to audit. Entities in scope must meet those requests as a priority, report vulnerabilities and incidents without delay, and, in critical infrastructure, procure only from authorised suppliers. Under Article 18, transactions conferring control on foreign parties require approval, and a transaction carried out without approval has no legal validity. (As of July 2026)
Every company in cyberspace
Scope is not limited to critical infrastructure; Article 2 reaches real and legal persons and unincorporated entities alike.
Critical infrastructure sectors
In the fifteen sectors determined on 05.05.2026, procurement is limited to authorised and certified suppliers.
Investors and acquirers
Share transfers giving foreign parties control of a cybersecurity product manufacturer have no legal validity without approval.
- 01Supply information and assistance promptly and as a priority whenever the Directorate requests it (Article 7(1)(a)).
- 02Report vulnerabilities and incidents without delay; the Law sets no numeric deadline, leaving that to secondary legislation (Article 7(1)(b)).
- 03Procure from authorised suppliers if you are a public institution or a critical infrastructure (Article 7(1)(c)).
- 04Obtain approval for transfers and exports where foreign control arises; a transaction without approval has no legal validity (Article 18).
Overview
Cybersecurity Law No. 7545 (Siber Güvenlik Kanunu) was adopted on 12.03.2025, published in the Official Gazette of 19.03.2025 (No. 32846) and in force the same day (Article 20). It sets out the framework, powers and sanctions for cybersecurity in Türkiye. The implementing secondary legislation has not appeared: the one-year period in Provisional Article 1(6) expired on 19.03.2026 and, as of July 2026, nothing substantive has been published; what appeared that day concerned internal staffing.
Scope and institutions
Article 2 draws the scope unusually widely: public institutions, professional organisations with public-institution status, and real and legal persons and unincorporated entities that exist, operate or provide services in cyberspace. The scope is not limited to critical infrastructure. Intelligence activities under Laws 2559, 2692, 2803, 2937 and 211 are excluded.
Operational authority rests with the Cybersecurity Directorate (Siber Güvenlik Başkanlığı); the Cybersecurity Board, chaired by the President of the Republic, sets policy and determines the critical infrastructure sectors (Article 9). On 05.05.2026 it determined fifteen: digital infrastructure, digital services, electronic communications, energy, finance, food and agriculture, manufacturing industry, public services, media and crisis communication, post and courier services, health, defence industry, water management, transport and space.
The Article 6 powers are intrusive: the Directorate may demand product-generated data and log records, conduct incident response on site or remotely, and access archives, data centres and communication infrastructure — which no entity may refuse by invoking its own sectoral legislation.
Key obligations
Article 7(1) sets five private-sector duties: supply any requested data, document, hardware or software promptly and as a priority; take the measures prescribed by legislation and report detected vulnerabilities or cyber incidents to the Directorate without delay, the Law fixing no numeric deadline; in public institutions and critical infrastructures, procure cybersecurity products and services only from suppliers it has authorised and certified; cybersecurity companies subject to certification must obtain approval before commencing operations; and the policies and action plans of the Directorate must be implemented.
Audit, transfers and export approval
Under Article 8 the Directorate may audit on site with its own staff or authorised independent auditors; the audited entity must keep systems open and provide access (Article 8(4)). Article 8(5) also permits search, copying and seizure at non-public premises on a judicial order.
Article 18 is the provision most often overlooked. Export of cybersecurity products, software, hardware and services follows procedures set by the Directorate, and listed products require approval. Mergers, demergers, share transfers and sales of companies producing them must be notified; where the transaction confers direct or indirect control on foreign persons, approval is required and a transaction without it has no legal validity (Article 18(3)). This bears on deal structuring today.
What this means for Turkish companies
The absence of implementing regulations is no reason to wait. The first step is a written procedure setting out who reports, at what threshold and through which channel (Article 7(1)(b)); with no numeric standard, the records evidencing timely escalation decide the case.
The critical point for Turkish exporters
The missing secondary legislation does not suspend the Article 7 duties. They are binding today, and breaches of Articles 7(1)(b) and 7(1)(c) carry administrative fines of TRY 1,000,000 to TRY 10,000,000 — nominal 2025 figures, revalued each year at the statutory revaluation rate.
Companies in one of the fifteen sectors should review the supply chain now. Article 7(1)(c) requires authorised and certified suppliers, and because that regime does not yet exist the correct posture is contractual: supplier warranties as to credentials, compliance undertakings, audit rights and a repapering trigger for when the regime arrives. Producers of cybersecurity products should also map which activities need prior approval (Article 7(1)(ç)).
Provisional Article 1(4) gives cybersecurity associations, federations, foundations and commercial companies one year to complete certification and authorisation — but that year runs from the entry into force of the Provisional Article 1(6) regulations, not from the Law. Because those had not been published as of July 2026, the period has not begun, and any commentary quoting a fixed end date is an assumption. Audit readiness is meanwhile the largest financial exposure, and it turns on process, not a breach.
Enforcement and penalties
Article 16 carries criminal sanctions alongside fines. Imprisonment ranges from one to three years for withholding or obstructing requested information, through two to four years for operating without a required approval and four to eight years for breach of the Article 13 confidentiality duty, up to eight to twelve years for cyber attacks on the elements of national power in cyberspace. Article 16(7) raises these by one third, one half or up to double for public officials, multiple offenders and organised activity respectively.
The administrative fines (Article 16(10)–(11)) are nominal 2025 figures, revalued each year at the statutory revaluation rate: TRY 1,000,000 to 10,000,000 for Articles 7(1)(b) and 7(1)(c); TRY 10,000,000 to 100,000,000 for Article 18; and TRY 100,000 to 1,000,000 for the Article 8(4) audit duties, rising for commercial companies to as much as 5% of gross sales revenue in the audited annual financial statements. Article 17 adds a 30-day written defence, one-month payment and appeal to the administrative courts.
Related content
Read it with the KVKK record for the personal data dimension and NIS2 for the EU counterpart; foreign investment approvals sit in the Foreign Direct Investment Law No. 4875 record and incident response in our Cybersecurity focus area.
Entry into force & amendment history
- 01.06.2026
Notifications moved to API
The Directorate began delivering security notifications by API through siberguvenlik.gov.tr.
- 05.05.2026
Fifteen critical sectors determined
The Cybersecurity Board identified the sectors treated as critical infrastructure.
- 19.03.2026
Deadline for regulations missed
The one-year period in Provisional Article 1(6) expired with no substantive implementing regulation.
- 19.03.2025
Law entered into force
Published in the Official Gazette (No. 32846) and effective the same day.
Official Sources
Consolidated text · mevzuat.gov.tr mevzuat.gov.trOfficial Gazette 19.03.2025 · resmigazete.gov.tr resmigazete.gov.tr


