Home About Us Services Awards Team Insights Career Contact Us TÜRKÇEENGLISH Devin Law & IP — Istanbul
← All Insights
CategoryData Protection
Published24 March 2026
Authors
Uğurcan TekinPartner
İnci ÖzçilsalAttorney at Law

Cybersecurity Law No. 7545: Centralised Governance, Audit and Sanctions Regime

In recent years, increasing cyber threats have placed cybersecurity at the heart of national security strategies. For states, it has evolved beyond the notion of “technical compliance” into a field shaped by institutional governance, service continuity, public order and sanction risk. In Türkiye, aligned with this approach, Cybersecurity Law No. 7545 was adopted on 12 March 2025 and entered into force upon its publication in the Official Gazette dated 19 March 2025, No. 32846.

Below, within a comparative framework alongside European Union regulations, the Law’s purpose, scope, institutional structure, obligations and sanctions regime are assessed in a practice-oriented manner.

Cybersecurity has moved from technical compliance to a governance domain linked to national security.

European Union Regulations: The EU Cybersecurity Act and the Cyber Resilience Act

In the European Union, the core framework in the field of cybersecurity has been built around two objectives: first, strengthening the institutional structure through Regulation (EU) 2019/881 and establishing an EU-wide common cybersecurity certification framework; and secondly, ensuring the security of products with digital elements — hardware and software — by design and throughout the product’s entire life cycle through the Cyber Resilience Act (Regulation (EU) 2024/2847).

Regulation (EU) 2019/881 — ENISA and the EU Cybersecurity Certification Framework. Regulation (EU) 2019/881 established ENISA as a permanent body; it provides that the Agency supports Member States in policy development and implementation processes, strengthens coordination in relation to cross-border threats, and monitors and assesses the impact of new technologies on cybersecurity. At the same time, an EU-wide European Cybersecurity Certification Framework was created; assurance levels — classified as “basic”, “substantial” and “high” — were defined for ICT products and services, thereby enabling stricter conformity assessment procedures to be applied for certain product and service categories.

Regulation (EU) 2024/2847 (CRA) — a horizontal regime focused on product security. The CRA centralises the product-security axis and introduces technology-neutral and objective-based minimum cybersecurity requirements for placing products with digital elements on the market; for manufacturers, it mandates that security be addressed from the design, development and production stages and be maintained throughout the product lifecycle. Within this scope, manufacturers are required to determine a support period for vulnerability management reflecting the product’s expected lifetime; as a rule, the support period is at least five years, and where the product’s expected lifetime is shorter than five years, it is limited accordingly. The CRA also provides for a CE marking mechanism for demonstrating conformity.

The CRA further adopts a tiered notification structure for vulnerabilities and security incidents: for vulnerabilities that are actively exploited and for “serious” incidents, the notification flow generally entails an early warning within twenty-four hours, a detailed incident notification within a specified period, and a separate final report within the scope of the relevant reporting obligations. In this process, a central reporting structure to be operated by ENISA comes to the fore.

With respect to the traceability of product components, the SBOM (Software Bill of Materials) approach gains importance under the CRA. In practice, however, the SBOM obligation should not be construed as an unconditional delivery requirement applicable in all cases; rather, it should be assessed together with the traceability and transparency obligations, in the sense that — where an SBOM is to be provided — the access and procurement mechanism for making it available must be clearly established.

As regards audits and sanctions, effective supervision is envisaged to be carried out through market surveillance authorities in the Member States; in the event of non-compliance, stringent sanctions are provided for, including administrative fines of up to EUR 15 million or 2.5% of the company’s worldwide annual turnover, and the principle that sanctions must be “effective, proportionate and dissuasive” is emphasised.

Common Purpose and Direction of the European Regulations

In the European Union, the CRA in particular aims to enhance cybersecurity resilience for products with digital elements across the EU and to establish a uniform legal framework applicable in all Member States. In this context, by eliminating the fragmented structure created by differing national regulations, it seeks to facilitate free movement within the internal market and to increase legal certainty regarding cybersecurity requirements for both manufacturers and users.

The CRA further addresses product security through a lifecycle approach; it envisages that products are placed on the market with fewer vulnerabilities, that manufacturers maintain updates and vulnerability management throughout the product’s lifetime, and that users are informed in a transparent manner about products’ security features and support periods. The overall direction of these regulations is to strengthen security throughout the supply chain, thereby reinforcing the EU’s strategic autonomy in this field and its role as an international standard-setter.

Purpose, Scope, Definitions and Fundamental Principles of Law No. 7545

Purpose. The primary objective of the Law is to prevent cyber threats, ensure an effective response to cyber incidents, protect critical digital infrastructures of the public and private sectors, and establish a comprehensive national cybersecurity strategy. The Law treats cybersecurity not merely as a set of technical measures, but as a governance domain directly linked to national security, public order and service continuity.

Within this framework, the Law is structured around an approach that sets out: the identification and elimination of existing and potential threats; the principles for reducing the possible impacts of cyber incidents; the adoption of regulations aimed at protection against cyberattacks; the determination of strategies and policies to strengthen the country’s cybersecurity; and the principles governing the establishment of the Cybersecurity Board.

Scope. In terms of scope, the Law envisages a broad field of application: it covers public institutions and organisations operating or maintaining a presence in cyberspace, as well as professional organisations having the status of public institutions; moreover, it also encompasses natural and legal persons and entities without legal personality. Accordingly, it expressly recognises that private actors — such as those involved in hosting, data processing, service provision, supply chains and infrastructure operation — form part of the national cybersecurity ecosystem.

On the other hand, the Law establishes a normative distinction between the civil and administrative cybersecurity regime and the domains of intelligence and military activities, by excluding from its scope intelligence activities conducted under specific laws and activities falling within the internal service regime of the Turkish Armed Forces.

Definitions. The definitions set out in the Law clarify the boundaries of the scope of application and the extent of the obligations:

  • “Cyberspace” refers to the environment consisting of information systems connected to the internet or to electronic communications and computer networks, and the networks linking them to one another.
  • “Information systems” are interpreted broadly, covering hardware, software, systems and all components.
  • “Cybersecurity” is a holistic field of activity encompassing safeguarding the confidentiality, integrity and availability of data, detecting attacks and incidents, operating response and alert mechanisms, and restoring systems to their pre-incident state.
  • “Cyber incident” refers to violations of confidentiality, integrity or availability.
  • “Cyberattack” refers to intentional acts aimed at such violations.
  • “Vulnerability” refers to an exploitable security flaw or weakness.
  • “Cyber threat” refers to a potential danger that may lead to a violation.
  • “Critical infrastructure” and “critical public service” refer to areas where a breach may result in loss of life, large-scale economic damage, disruption of public order or severe consequences for national security.

Fundamental principles. The Law underscores that cybersecurity is an integral part of national security and identifies as a core objective the creation of a secure cyberspace by protecting critical infrastructures and information systems. Conducting cybersecurity efforts on the basis of institutionalisation, continuity and sustainability; applying measures throughout the lifecycle of products and services; and prioritising domestic and national products are identified as guiding principles shaping implementation.

This approach, by extending obligations not only to public authorities but also to natural and legal persons, establishes a holistic regime of obligations across prevention and impact-mitigation processes; it is grounded in accountability and aims to keep strategy and policy development activities up to date through a continuous-improvement approach.

The Cybersecurity Directorate: Duties and Scope of Authority

The Cybersecurity Directorate established under the Law is designated as the central authority for determining and implementing Türkiye’s cybersecurity policies. The Directorate conducts activities aimed at increasing the cyber resilience of critical infrastructures and information systems, detecting attacks, preventing potential attacks and mitigating their effects; in this context, it institutionalises risk management by conducting or commissioning vulnerability and penetration tests and risk analyses relating to assets. The Directorate also strengthens operational capacity through its functions of obtaining, producing and sharing threat intelligence, conducting malware analysis activities and combating cyber threats.

The Directorate may identify critical infrastructures and make determinations regarding the relevant institutions and locations; it ensures that asset inventories of public institutions and critical infrastructures are maintained and that security measures are implemented in accordance with the criticality of assets, and it can manage the processes for establishing, causing the establishment of, and supervising Cyber Incident Response Teams. Within this framework, the Directorate’s remit also includes conducting exercises to assess response capabilities, coordinating with incident response teams of other countries, and encouraging the development of national cyber response tools.

In addition, the Directorate may lay down the procedures and principles to be complied with in the field of cybersecurity, assume the function of preparing standards and monitoring their implementation, and carry out certification and authorisation processes — coordinated with the relevant institutions — by establishing and operating testing and certification infrastructures for software, hardware, products, systems and services. As regards the practical implementation of these processes, secondary legislation will be determinative.

Standard-setting, certification, audit and incident response are brought together under a single coordination hub.

The Cybersecurity Board: A Strategic-Level Coordination Mechanism

With the Law, the Cybersecurity Board has been established as the highest-level decision-making mechanism, with the aim of determining cybersecurity-related policies and ensuring coordination.

Pursuant to Article 9 of the Law, the Board consists of the President of the Republic of Türkiye, the Vice President, the Minister of Justice, the Minister of Foreign Affairs, the Minister of Interior, the Minister of National Defence, the Minister of Industry and Technology, the Minister of Transport and Infrastructure, the Secretary General of the National Security Council, the Head of the National Intelligence Organisation, the President of Defence Industries and the Head of the Cybersecurity Directorate.

Where the President is unable to attend, the Vice President chairs the Board. Depending on the nature of the agenda, relevant ministers and individuals may be invited to Board meetings; where deemed necessary, the Board may establish commissions and working groups, and experts in the relevant field may be invited to participate in those groups.

The Board’s remit covers: setting policy and strategy; deciding on the nationwide implementation of the technology roadmap prepared by the Directorate; taking decisions on priority areas to be incentivised and on the development of human resources; determining critical infrastructure sectors; and acting as the decision-making authority in disputes that may arise between the Directorate and public institutions.

Cybersecurity Companies: Overseas Sales, Mergers and Transfers, and the Control Regime

The Law subjects transactions involving companies operating in the field of cybersecurity — such as mergers, demergers, share transfers or other transactions resulting in a change of control — to an approval and notification regime under the Directorate’s supervision. Transactions carried out without obtaining the Directorate’s approval do not acquire legal validity. In addition, the overseas sale of cybersecurity products, systems, software, hardware and services is made subject to procedures and principles to be determined by the Directorate; for products subject to authorisation, the Directorate’s approval is required.

These provisions serve the objectives of monitoring corporate transactions within the cybersecurity ecosystem from a national security perspective, keeping changes of control over critical technologies under administrative oversight, and ensuring supply chain security.

Critical infrastructure sectors are determined by the Board and mapped by the Directorate.

Obligations, Audit and the Critical Infrastructure Regime

Obligations. The Law imposes a range of cybersecurity obligations on persons and entities that provide services by means of information systems and collect and process data. Accordingly, the actors within the scope of the Law are responsible for:

  • Timely submitting to the Directorate the elements it requests, such as data, information, documents, hardware and software
  • Taking the measures prescribed by legislation
  • Reporting, without delay, any vulnerabilities or cyber incidents they detect
  • Procuring cybersecurity products and services to be used in public institutions and critical infrastructures from authorised and certified persons and entities
  • Implementing the necessary measures in line with the policies, strategies and action plans published by the Directorate

In addition, for companies carrying out activities subject to certification or authorisation, the Law provides for a mechanism requiring the Directorate’s approval before commencing operations.

Audit. From an audit perspective, the Directorate may audit acts and transactions falling within the scope of the Law where it deems necessary, and may conduct on-site inspections or have them conducted. Audit powers may be exercised not only by the Directorate’s personnel but also through authorised and certified independent auditors and independent audit firms. Those subject to audit are obliged to keep their devices, systems, software and hardware open to inspection, to provide the necessary infrastructure for the audit, and to take the measures required to keep that infrastructure operational.

Search, copying and seizure. For the purposes of national security, public order and preventing the commission of crimes or cyberattacks, the Law sets out the procedure under which searches, copying and seizure may be carried out in closed premises upon a judge’s decision; in cases where delay would be prejudicial, such measures may be taken pursuant to a written order of the public prosecutor. For these measures to be carried out in the data centres of authorised data centre operators, a judge’s decision is required.

Critical infrastructure regime. The Law defines as critical infrastructure those infrastructures hosting information systems where a breach of information or data security may lead to severe consequences such as loss of life, large-scale economic damage, security vulnerabilities or disruption of public order. It assigns to the Board the task of determining critical infrastructure sectors, and to the Directorate the tasks of identifying the institutions and locations of critical infrastructures, maintaining the asset inventory, and determining and ensuring the implementation of security measures based on criticality. Under existing practice, electronic communications, energy, water management, finance, transport and various public services are considered within the scope of critical infrastructure areas; within the Board’s power of determination, it is possible for these areas to be expanded.

Breaches and Sanctions: Criminal Provisions and Administrative Fines

The sanctions envisaged under the Law aim to ensure the effective fulfilment of obligations and establish a detailed framework covering both criminal sanctions and administrative fines. Under the Law, imprisonment and/or judicial fines are prescribed for: those who fail to provide, or who obstruct access to, information, documents, software, data or hardware requested by the competent authorities or audit officials; those who carry out activities without obtaining the required approvals, authorisations or permits; those who breach confidentiality obligations; those who unlawfully make accessible, disseminate or offer for sale data of a personal nature or data falling within the scope of critical public services; those who aim to create fear or panic in the public through false data-breach content; and those who commit cyberattacks against elements constituting Türkiye’s national power in cyberspace. Notable penalties in this context include:

  • Failure to provide, or obstruction of access to, information, documents, software, data or hardware requested by competent authorities or audit officials: one to three years’ imprisonment and a judicial fine of 500 to 1,500 day-units
  • Carrying out activities without the required approvals, authorisations or permits: two to four years’ imprisonment and a judicial fine of 1,000 to 2,000 day-units
  • Breach of confidentiality obligations: four to eight years’ imprisonment
  • Unlawfully making accessible, disseminating or selling personal data or data falling within the scope of critical public services: three to five years’ imprisonment
  • Aiming to create fear or panic through false data-leak content: two to five years’ imprisonment
  • Carrying out attacks against Türkiye’s national power in cyberspace, or keeping the obtained data in cyberspace: eight to twelve years’ imprisonment; disseminating, transmitting or selling such data: ten to fifteen years’ imprisonment
  • Violations of Article 12: three to five years’ imprisonment
  • Causing a data breach through abuse of duty or failure to take necessary measures: one to three years’ imprisonment

With respect to administrative fines, the Law provides for substantial administrative sanctions particularly in cases such as breaches of notification obligations, failure to comply with the requirement to procure certified and authorised products and services, non-compliance with procedural requirements for transactions subject to the Directorate’s approval or conformity assessment, failure to respond to requests for information, and failure to fulfil the obligation to cooperate during audits. In addition, the sanctions regime is complemented by procedural safeguards through provisions regulating the procedure for obtaining a defence statement, the possibility of escalation in the event of repeated misdemeanours, benefit- and loss-based increases, collection procedures, and recourse to administrative judicial review.

Conclusion and Assessment

The Law marks a clear shift towards eliminating institutional fragmentation in cybersecurity governance and consolidating authority under a central body. It is envisaged that cybersecurity activities previously carried out in a dispersed manner across different institutions will be brought together around the Directorate, and that the lack of coordination will be reduced through the implementation of a transition mechanism concerning the transfer of relevant assets and infrastructures. In this context, cybersecurity should no longer be regarded solely as a technical responsibility of IT units; rather, it should be assessed as a strategic governance domain that must be addressed at board level and is directly linked to corporate risk management, compliance and sustainability processes.

At the same time, the Law institutionalises the highest-level political and administrative coordination through the Board mechanism, so as to address cybersecurity at a strategic level; and it aims to strengthen uniform implementation across the public–private ecosystem and enhance rapid decision-making capacity by bringing standard-setting, certification, auditing and incident response functions together under a single coordination hub.

One of the Law’s most notable features is that it abandons a recommendation-based approach and establishes a sanctions regime with a high deterrent effect. In this framework, the explicit codification of notification and cooperation duties as binding obligations, the establishment and supervision of Cyber Incident Response Teams, and the combined regulation of administrative and criminal sanctions bring cyber risk management to the centre of the senior management agenda for companies.

Nevertheless, for the regulation to be effectively implemented in all its aspects, it will be decisive that the implementing regulations and secondary legislation are brought into force within the prescribed timeframes, so as to clarify the practical application of standardisation, certification and audit processes.

Our Recommendations

The Law introduces numerous obligations that directly address not only public institutions and organisations but also private-sector actors. In this context, in order for companies to avoid exposure to administrative and criminal sanctions and to establish an adequate level of compliance with cybersecurity legislation, it is important to create an institutional archiving and reporting infrastructure that enables information and documents to be duly retained and classified and, upon request, produced without delay; to measure the level of technical security by conducting vulnerability scans and penetration tests at regular intervals; and to minimise human-resource-related risks through periodic training programmes aimed at increasing employees’ cybersecurity awareness.

Likewise, keeping the asset inventory up to date and structuring risk analysis as an ongoing process, operationalising vulnerability and cyber-incident notification mechanisms, and ensuring compliance with certification and authorisation requirements for procured cybersecurity products and services will directly contribute to meeting the standards of the obligations set out under the Law.

In particular, for companies operating within the scope of critical infrastructure or critical public services, the following are decisive for mitigating the risk of sanctions arising from non-compliance: establishing a written procurement and supply policy and contractual framework that takes into account supply chain security and the prioritisation of domestic and national products; putting in place a documentation, record-keeping and traceability framework so as to be prepared for notification and audit processes; incorporating certification and authorisation requirements into supplier contracts through clear and binding provisions; and ultimately transforming all of these elements — under senior management oversight — into a sustainable cyber compliance programme.