Cybersecurity Law 101

31.08.2026 Sevgi Ünsal Özden

Introduction

With the acceleration of digitalization, companies increasingly rely on information systems, digital infrastructure, and interconnected networks in conducting their business. In parallel, cyber threats have evolved beyond purely technical risks and have become a matter directly affecting companies’ operational continuity, data security, and corporate risk management. The growing scale and impact of cyberattacks require cybersecurity to be addressed not only through companies’ internal policies and measures, but also through a comprehensive legal and institutional framework at the national level.

Within this scope, Cybersecurity Law No. 7545 (the “Law”) was published in the Official Gazette dated March 19, 2025 and numbered 32846 and entered into force on the same date.[1]  The Law aims to identify and eliminate existing and potential threats against the elements constituting the national power of the Republic of Türkiye in cyberspace, mitigate the effects of cyber incidents, protect public institutions and organizations as well as natural and legal persons against cyberattacks, and establish strategies and policies aimed at strengthening Türkiye’s cybersecurity.

In addition to its broadly defined scope, the Law has attracted considerable attention since its entry into force due to the obligations it imposes and its stringent sanctions regime. In particular, the introduction of imprisonment for certain violations and administrative fines of up to 5% of companies’ gross sales revenue makes the Law a significant compliance framework that companies should closely monitor.

This Article examines the purpose and scope of the Law and the provisions concerning critical infrastructure sectors and discusses the key obligations as well as the audit and enforcement mechanisms, considering their potential implications for companies.

Cybersecurity Law 101
% 0

Scope of the Law and Critical Infrastructure Sectors

The scope of application of the Law is defined very broadly. Pursuant to Article 2 of the Law, public institutions and organizations, professional organizations with public institution status, natural and legal persons, and organizations without legal personality that “have a presence, conduct activities, provide services in cyberspace” fall within its scope. Accordingly, the Law is not a sector-specific regulation applicable only to companies operating in the technology or cybersecurity sectors.

In this context, the concept of “cyberspace” becomes particularly relevant in determining the scope of the Law. The Law defines cyberspace as “the environment consisting of all information systems that are directly or indirectly connected to the internet, electronic communications or computer networks, and the networks connecting such systems”. The concept of “information systems” is also broadly defined to include hardware, software, systems, and other components used in the provision of any services, transactions, and data through information and communication technologies.

Considering these provisions, whether a company falls within the scope of the Law depends not only on the sector in which it operates, but also on the relationship between its activities and services and cyberspace and information systems. In other words, the fact that a company’s core business is not technology or cybersecurity does not mean that it falls outside the scope of the Law. In particular, where services or activities are carried out through information systems, digital infrastructure, network-connected environments, or remote access mechanisms, the applicability of the Law should be assessed separately.

However, the broad wording of the scope provision also raises the question of whether the mere use of any digital tool is sufficient to bring an entity within the scope of the Law. The Law does not expressly draw a distinction in this respect. In our view, a company’s mere use of third-party email or cloud-based office applications in the ordinary course of its business should not be determinative. Rather, the key consideration should be whether the company’s activities or services are carried out in cyberspace or through information systems. That said, considering that the phrase “have a presence” in Article 2 constitutes a connecting factor independent of the activity and service elements, and that Article 7 defines its addressees broadly enough to include those who collect or process data through information systems, it should also be noted that this interpretation is open to debate in light of the wording of the Law. Therefore, until clarity is provided through secondary legislation, companies should in any event take a more cautious approach regarding the scope of the Law.

Another key concept in determining the scope of the Law is “critical infrastructure.” Critical infrastructure is defined as infrastructure containing information systems which, if the confidentiality, integrity, or availability of the information or data they process is compromised, may result in loss of life, large-scale economic damage, security vulnerabilities, or disruption of public order. The Cybersecurity Board is authorized to determine critical infrastructure sectors, while the Presidency is authorized to specifically identify critical infrastructures and the organizations to which they belong.

In this context, pursuant to the decision [2] adopted by the Cybersecurity Board on May 5, 2026, digital infrastructure, digital services, electronic communications, energy, finance, food and agriculture, manufacturing, public services, media and crisis communications, postal and cargo, healthcare, defense industry, water management, transportation, and space were designated as critical infrastructure sectors.

An important distinction should be drawn between falling within the general scope of the Law and qualifying as critical infrastructure. The general scope of the Law is not limited to critical infrastructure. However, critical infrastructure status may trigger additional or more specific obligations under certain provisions of the Law.

Key Obligations of Persons and Organizations within the Scope of the Law

Article 7 of the Law sets out the principal cybersecurity obligations applicable to persons and organizations that fall within the scope of the Law and provide services, collect or process data, or conduct similar activities through information systems. These obligations are not limited to notification and cooperation duties arising after a cyber incident occurs; they also require companies to establish a preventive and ongoing cybersecurity compliance framework.

The key obligations under the Law may be summarized as follows:

  • Cooperation with the Cybersecurity Presidency: Any data, information, documents, hardware, software, and other contributions requested by the Cybersecurity Presidency (the “Presidency”) within the scope of its duties and activities must be provided to the Presidency on a priority basis and in a timely manner. This also makes it necessary for companies to establish internal processes and organizational structures that enable them to respond promptly to such requests. Persons and organizations may not refuse to comply with requests for information, documents, and records by invoking provisions of their own legislation.
  • Implementation of cybersecurity measures and notification: Cybersecurity measures required under applicable legislation for purposes of national security, public order, or the proper provision of public services must be implemented and identified vulnerabilities or cyber incidents must be reported to the Presidency without delay. The Law does not prescribe a specific notification period in terms of days or hours but instead uses the term “without delay.” Companies should therefore establish internal processes in advance for identifying and assessing cyber incidents and vulnerabilities and escalating them to the Presidency. This notification process must also be managed consistently with data breach notifications under Personal Data Protection Law No. 6698 and sector-specific notification obligations.
  • Procurement of certain products, systems, and services from authorized providers: Cybersecurity products, systems, and services to be used by public institutions and organizations and in critical infrastructure must be procured from cybersecurity experts, manufacturers, or companies authorized and certified by the Presidency. It should be emphasized that this does not constitute a general procurement requirement applicable to all companies within the scope of the Law.
  • Compliance with regulations issued by the Presidency: Another obligation is to comply with the policies, strategies, and action plans developed by the Presidency to enhance cyber maturity, as well as other regulatory instruments issued by the Presidency, and to implement the necessary measures in this respect. Accordingly, companies will also need to closely monitor the secondary regulatory framework to be developed by the Presidency.
  • Approval obligation for cybersecurity companies: Cybersecurity companies subject to certification, authorization, and accreditation must obtain the Presidency’s approval before commencing operations.

From a corporate perspective, these obligations demonstrate that compliance with the Law is not merely a technical process that can be left solely to information technology or information security teams. Companies should review their existing cybersecurity governance structures, allocation of roles and responsibilities, access and authorization mechanisms, logging practices, and cyber incident response and notification procedures in light of the obligations introduced by the Law. In particular, effective compliance with the requirement to notify “without delay” requires companies to determine, before a cyber incident occurs, who will identify the incident, to whom it will be escalated internally, and who will be responsible for making the notification to the Presidency.

Audit and Enforcement Mechanism

In addition to imposing various obligations, the Law grants the Presidency broad audit powers. Where deemed necessary, the Presidency may audit acts and transactions falling within the scope of the Law and may conduct or commission on-site inspections. During an audit, electronic data and documents, as well as devices, systems, software, and hardware, may be examined; copies or samples may be taken; and written or oral explanations may be requested from the relevant persons. Persons and organizations subject to an audit are required to make the relevant systems and infrastructure available for inspection and provide the conditions necessary for the audit.

The Law also allows searches to be conducted at workplaces, residences, and enclosed areas not open to the public and copies to be made and items seized, upon a judge’s decision or where delay would be detrimental, the written order of a public prosecutor, for purposes of national security, public order, preventing the commission of crimes, or preventing cyberattacks.

One of the most notable aspects of the Law is its enforcement regime, which provides for both administrative and criminal sanctions. Certain violations, including failure to provide, or obstruction of access to, information, documents, software, data, or hardware requested by the Presidency or audit officials, as well as conducting activities without obtaining the required approval, authorization, or permission, may result in imprisonment and judicial fines. For instance, failure to provide requested information and documents is punishable by imprisonment of one to three years and a judicial fine of 500 to 1,500 days. Those who cause a data breach by acting contrary to the requirements of their duties in protecting critical infrastructure against cyberattacks face imprisonment of one to three years. The Law also establishes separate offenses for the unauthorized sharing or offering for sale of data obtained through data leaks, and for creating content regarding a non-existent data leak with the intent to cause panic.

For companies, the severity of the administrative fines is particularly noteworthy. Failure to implement cybersecurity measures, notify vulnerabilities and cyber incidents, or comply with certain procurement obligations under the Law may result in administrative fines. Furthermore, where commercial companies fail to comply with certain audit-related obligations, an administrative fine of up to 5% of the gross sales revenue stated in their independently audited annual financial statements may be imposed. Violations of the obligations relating to the sale of cybersecurity products abroad and to mergers, demergers, share transfers, or sales of cybersecurity companies result in administrative fines ranging from TRY 10 million to TRY 100 million.

At this point, Article 18 of the Law warrants particular attention, especially in the context of mergers and acquisitions. Mergers, demergers, share transfers, or sales of companies producing cybersecurity products, systems, software, hardware, and services must be notified to the Presidency, and transactions granting direct or indirect control over the company are subject to the Presidency’s approval. Transactions carried out without such approval have no legal validity.

Conclusion

The Cybersecurity Law, which became part of Türkiye’s legal framework in 2025, particularly considering its sanctions regime, transforms cybersecurity from a purely technical information security matter into an area of legal and corporate compliance for companies. Companies should therefore first determine whether their activities fall within the scope of the Law.

Companies that fall within the scope of the Law should review their existing cybersecurity governance structures, incident response and notification processes, allocation of roles and responsibilities, and relevant policies and procedures considering the applicable obligations. Furthermore, given that the Law establishes a general framework in many respects, companies should closely monitor the secondary legislation and other regulatory instruments to be issued by the Presidency and treat compliance with the Law as an ongoing process.

Make us your preferred source on Google
See Erdem & Erdem publications featured in your Google Search results.
Add as preferred source More from erdem-erdem.av.tr

All rights of this article are reserved. This article may not be used, reproduced, copied, published, distributed, or otherwise disseminated without quotation or Erdem & Erdem Law Firm's written consent. Any content created without citing the resource or Erdem & Erdem Law Firm’s written consent is regularly tracked, and legal action will be taken in case of violation.

Other Contents

Draft Commission Guidelines on the Classification of High-Risk AI Systems Published
Newsletter Articles
Draft Commission Guidelines on the Classification of High-Risk AI Systems Published

The European Union Artificial Intelligence Act (the AI Act or the Act), which entered into force on 1 August 2024, established a harmonized framework for AI systems across the Union. The Act follows a risk-based approach, with 'high-risk' AI systems at its center…

IT and Artificial Intelligence Law 31.05.2026
New Obligations Imposed on Gaming Companies under Law No. 5651
Newsletter Articles
New Obligations Imposed on Gaming Companies under Law No. 5651

Today, the internet has become an integral part of social life and serves as one of the most widely used means of mass communication. While the internet offers significant opportunities in many areas, such as access to information, communication, and digital services…

IT and Artificial Intelligence Law 31.05.2026
The Use of Generative AI Tools Such as ChatGPT and Google Gemini in the Workplace
Newsletter Articles
The Use of Generative AI Tools Such as ChatGPT and Google Gemini in the Workplace

Generative AI technologies, particularly tools such as ChatGPT, Microsoft Copilot, and Google Gemini, have rapidly created a transformative impact on the business world. By generating original outputs that closely resemble human-produced content, drawing…

IT and Artificial Intelligence Law 28.02.2026
Processing of Personal Data in the Context of Artificial Intelligence Models
Newsletter Articles
Processing of Personal Data in the Context of Artificial Intelligence Models

The European Data Protection Board (“EDPB”) issued Opinion 28/2024 addressing key data protection concerns related to the processing of personal data in the context of artificial intelligence (“AI”) models. This Opinion was prepared in response to the Irish Supervisory Authority’s request under Article 64(2) GDPR...

IT and Artificial Intelligence Law 31.01.2025
Artificial Intelligence in Arbitration
Newsletter Articles
Artificial Intelligence in Arbitration

As technology advances, artificial intelligence (“AI”) is steadily making its way into dispute resolution, promising enhanced efficiency. Practitioners are carefully weighing its capabilities against its limitations...

IT and Artificial Intelligence Law 31.10.2024
Framework Convention on Artificial Intelligence
Newsletter Articles
Framework Convention on Artificial Intelligence

The Framework Convention on Artificial Intelligence (Convention) is an international treaty proposed by the Council of Europe that was recently opened for signature . This is the first legally binding international framework regulating the entire lifecycle of Artificial Intelligence (AI) systems. The Convention ensures...

IT and Artificial Intelligence Law 30.09.2024
Reflections of the European Union Artificial Intelligence Act on Actors in Turkiye
Newsletter Articles
Reflections of the European Union Artificial Intelligence Act on Actors in Turkiye

The "Brussels Effect" refers to the phenomenon where European Union (“EU”) regulations influence or set standards globally. Since the EU is a significant market, global companies often find it practical and economically beneficial to adopt EU standards across all their operations rather than comply with multiple...

IT and Artificial Intelligence Law 31.08.2024
Amendments Introduced to the Law on Regulation of Internet Publications
Newsletter Articles
Amendments Introduced to the Law on Regulation of Internet Publications
IT and Artificial Intelligence Law March 2014
Constitutional Court's Annulment Decision on Certain Provisions of the Internet Law No. 5651
Newsletter Articles
Constitutional Court's Annulment Decision on Certain Provisions of the Internet Law No. 5651

With its decision dated 11.10.2023 and numbered 2020/76 E., 2023/172 K. published in the Official Gazette dated 10 January 2024 and numbered 32425 ("Decision"), the Constitutional Court ("Constitutional Court") evaluated the requests for the annulment of certain articles of the Law No. 7253 on the...

IT and Artificial Intelligence Law 29.02.2024
Latest Development As Regards to the Social Network Providers
Newsletter Articles
Latest Development As Regards to the Social Network Providers

The Information Technologies and Communications Board adopted the Procedures and Principles for Social Network Providers (“Procedures and Principles”) with its decision dated 28.03.2023 and numbered 2023/DK-ID/119. The said decision was published in the Official Gazette dated 01.04.2023, and entered into...

IT and Artificial Intelligence Law 31.07.2023
Artificial Intelligence Act Adopted by the European Parliament
Newsletter Articles
Artificial Intelligence Act Adopted by the European Parliament

The first “Artificial Intelligence Act” of all time, which includes rules and regulations that directly affect tools such as ChatGPT, Bard and Midjourney adopted by the European Parliament with a majority of votes. Thus, the European Parliament has officially taken the steps of a regulation that could be a turning point for...

IT and Artificial Intelligence Law 31.07.2023
ChatGPT: A Grey Zone Between Privacy, Cybersecurity, Human Rights and Innovation
Newsletter Articles
ChatGPT: A Grey Zone Between Privacy, Cybersecurity, Human Rights and Innovation

ChatGPT, a large language model (LLM) developed by OpenAI, is an artificial intelligence (AI) system based on deep learning techniques and neural networks for natural language processing. ChatGPT can process and generate human-like text, chat, analyse and answer follow-up questions, and acknowledge errors...

IT and Artificial Intelligence Law 30.04.2023
Did Social Network Platforms Comply with the New Regulations in Turkey?
Newsletter Articles
Did Social Network Platforms Comply with the New Regulations in Turkey?
IT and Artificial Intelligence Law January 2021
What Has Come About through the Social Media Regulation?
Newsletter Articles
What Has Come About through the Social Media Regulation?
IT and Artificial Intelligence Law June 2020
Internet Actors in Law No. 5651
Newsletter Articles
Internet Actors in Law No. 5651
IT and Artificial Intelligence Law June 2020

For creative legal solutions, please contact us.