Cybersecurity Law 101
Introduction
With the acceleration of digitalization, companies increasingly rely on information systems, digital infrastructure, and interconnected networks in conducting their business. In parallel, cyber threats have evolved beyond purely technical risks and have become a matter directly affecting companies’ operational continuity, data security, and corporate risk management. The growing scale and impact of cyberattacks require cybersecurity to be addressed not only through companies’ internal policies and measures, but also through a comprehensive legal and institutional framework at the national level.
Within this scope, Cybersecurity Law No. 7545 (the “Law”) was published in the Official Gazette dated March 19, 2025 and numbered 32846 and entered into force on the same date.[1] The Law aims to identify and eliminate existing and potential threats against the elements constituting the national power of the Republic of Türkiye in cyberspace, mitigate the effects of cyber incidents, protect public institutions and organizations as well as natural and legal persons against cyberattacks, and establish strategies and policies aimed at strengthening Türkiye’s cybersecurity.
In addition to its broadly defined scope, the Law has attracted considerable attention since its entry into force due to the obligations it imposes and its stringent sanctions regime. In particular, the introduction of imprisonment for certain violations and administrative fines of up to 5% of companies’ gross sales revenue makes the Law a significant compliance framework that companies should closely monitor.
This Article examines the purpose and scope of the Law and the provisions concerning critical infrastructure sectors and discusses the key obligations as well as the audit and enforcement mechanisms, considering their potential implications for companies.
Scope of the Law and Critical Infrastructure Sectors
The scope of application of the Law is defined very broadly. Pursuant to Article 2 of the Law, public institutions and organizations, professional organizations with public institution status, natural and legal persons, and organizations without legal personality that “have a presence, conduct activities, provide services in cyberspace” fall within its scope. Accordingly, the Law is not a sector-specific regulation applicable only to companies operating in the technology or cybersecurity sectors.
In this context, the concept of “cyberspace” becomes particularly relevant in determining the scope of the Law. The Law defines cyberspace as “the environment consisting of all information systems that are directly or indirectly connected to the internet, electronic communications or computer networks, and the networks connecting such systems”. The concept of “information systems” is also broadly defined to include hardware, software, systems, and other components used in the provision of any services, transactions, and data through information and communication technologies.
Considering these provisions, whether a company falls within the scope of the Law depends not only on the sector in which it operates, but also on the relationship between its activities and services and cyberspace and information systems. In other words, the fact that a company’s core business is not technology or cybersecurity does not mean that it falls outside the scope of the Law. In particular, where services or activities are carried out through information systems, digital infrastructure, network-connected environments, or remote access mechanisms, the applicability of the Law should be assessed separately.
However, the broad wording of the scope provision also raises the question of whether the mere use of any digital tool is sufficient to bring an entity within the scope of the Law. The Law does not expressly draw a distinction in this respect. In our view, a company’s mere use of third-party email or cloud-based office applications in the ordinary course of its business should not be determinative. Rather, the key consideration should be whether the company’s activities or services are carried out in cyberspace or through information systems. That said, considering that the phrase “have a presence” in Article 2 constitutes a connecting factor independent of the activity and service elements, and that Article 7 defines its addressees broadly enough to include those who collect or process data through information systems, it should also be noted that this interpretation is open to debate in light of the wording of the Law. Therefore, until clarity is provided through secondary legislation, companies should in any event take a more cautious approach regarding the scope of the Law.
Another key concept in determining the scope of the Law is “critical infrastructure.” Critical infrastructure is defined as infrastructure containing information systems which, if the confidentiality, integrity, or availability of the information or data they process is compromised, may result in loss of life, large-scale economic damage, security vulnerabilities, or disruption of public order. The Cybersecurity Board is authorized to determine critical infrastructure sectors, while the Presidency is authorized to specifically identify critical infrastructures and the organizations to which they belong.
In this context, pursuant to the decision [2] adopted by the Cybersecurity Board on May 5, 2026, digital infrastructure, digital services, electronic communications, energy, finance, food and agriculture, manufacturing, public services, media and crisis communications, postal and cargo, healthcare, defense industry, water management, transportation, and space were designated as critical infrastructure sectors.
An important distinction should be drawn between falling within the general scope of the Law and qualifying as critical infrastructure. The general scope of the Law is not limited to critical infrastructure. However, critical infrastructure status may trigger additional or more specific obligations under certain provisions of the Law.
Key Obligations of Persons and Organizations within the Scope of the Law
Article 7 of the Law sets out the principal cybersecurity obligations applicable to persons and organizations that fall within the scope of the Law and provide services, collect or process data, or conduct similar activities through information systems. These obligations are not limited to notification and cooperation duties arising after a cyber incident occurs; they also require companies to establish a preventive and ongoing cybersecurity compliance framework.
The key obligations under the Law may be summarized as follows:
- Cooperation with the Cybersecurity Presidency: Any data, information, documents, hardware, software, and other contributions requested by the Cybersecurity Presidency (the “Presidency”) within the scope of its duties and activities must be provided to the Presidency on a priority basis and in a timely manner. This also makes it necessary for companies to establish internal processes and organizational structures that enable them to respond promptly to such requests. Persons and organizations may not refuse to comply with requests for information, documents, and records by invoking provisions of their own legislation.
- Implementation of cybersecurity measures and notification: Cybersecurity measures required under applicable legislation for purposes of national security, public order, or the proper provision of public services must be implemented and identified vulnerabilities or cyber incidents must be reported to the Presidency without delay. The Law does not prescribe a specific notification period in terms of days or hours but instead uses the term “without delay.” Companies should therefore establish internal processes in advance for identifying and assessing cyber incidents and vulnerabilities and escalating them to the Presidency. This notification process must also be managed consistently with data breach notifications under Personal Data Protection Law No. 6698 and sector-specific notification obligations.
- Procurement of certain products, systems, and services from authorized providers: Cybersecurity products, systems, and services to be used by public institutions and organizations and in critical infrastructure must be procured from cybersecurity experts, manufacturers, or companies authorized and certified by the Presidency. It should be emphasized that this does not constitute a general procurement requirement applicable to all companies within the scope of the Law.
- Compliance with regulations issued by the Presidency: Another obligation is to comply with the policies, strategies, and action plans developed by the Presidency to enhance cyber maturity, as well as other regulatory instruments issued by the Presidency, and to implement the necessary measures in this respect. Accordingly, companies will also need to closely monitor the secondary regulatory framework to be developed by the Presidency.
- Approval obligation for cybersecurity companies: Cybersecurity companies subject to certification, authorization, and accreditation must obtain the Presidency’s approval before commencing operations.
From a corporate perspective, these obligations demonstrate that compliance with the Law is not merely a technical process that can be left solely to information technology or information security teams. Companies should review their existing cybersecurity governance structures, allocation of roles and responsibilities, access and authorization mechanisms, logging practices, and cyber incident response and notification procedures in light of the obligations introduced by the Law. In particular, effective compliance with the requirement to notify “without delay” requires companies to determine, before a cyber incident occurs, who will identify the incident, to whom it will be escalated internally, and who will be responsible for making the notification to the Presidency.
Audit and Enforcement Mechanism
In addition to imposing various obligations, the Law grants the Presidency broad audit powers. Where deemed necessary, the Presidency may audit acts and transactions falling within the scope of the Law and may conduct or commission on-site inspections. During an audit, electronic data and documents, as well as devices, systems, software, and hardware, may be examined; copies or samples may be taken; and written or oral explanations may be requested from the relevant persons. Persons and organizations subject to an audit are required to make the relevant systems and infrastructure available for inspection and provide the conditions necessary for the audit.
The Law also allows searches to be conducted at workplaces, residences, and enclosed areas not open to the public and copies to be made and items seized, upon a judge’s decision or where delay would be detrimental, the written order of a public prosecutor, for purposes of national security, public order, preventing the commission of crimes, or preventing cyberattacks.
One of the most notable aspects of the Law is its enforcement regime, which provides for both administrative and criminal sanctions. Certain violations, including failure to provide, or obstruction of access to, information, documents, software, data, or hardware requested by the Presidency or audit officials, as well as conducting activities without obtaining the required approval, authorization, or permission, may result in imprisonment and judicial fines. For instance, failure to provide requested information and documents is punishable by imprisonment of one to three years and a judicial fine of 500 to 1,500 days. Those who cause a data breach by acting contrary to the requirements of their duties in protecting critical infrastructure against cyberattacks face imprisonment of one to three years. The Law also establishes separate offenses for the unauthorized sharing or offering for sale of data obtained through data leaks, and for creating content regarding a non-existent data leak with the intent to cause panic.
For companies, the severity of the administrative fines is particularly noteworthy. Failure to implement cybersecurity measures, notify vulnerabilities and cyber incidents, or comply with certain procurement obligations under the Law may result in administrative fines. Furthermore, where commercial companies fail to comply with certain audit-related obligations, an administrative fine of up to 5% of the gross sales revenue stated in their independently audited annual financial statements may be imposed. Violations of the obligations relating to the sale of cybersecurity products abroad and to mergers, demergers, share transfers, or sales of cybersecurity companies result in administrative fines ranging from TRY 10 million to TRY 100 million.
At this point, Article 18 of the Law warrants particular attention, especially in the context of mergers and acquisitions. Mergers, demergers, share transfers, or sales of companies producing cybersecurity products, systems, software, hardware, and services must be notified to the Presidency, and transactions granting direct or indirect control over the company are subject to the Presidency’s approval. Transactions carried out without such approval have no legal validity.
Conclusion
The Cybersecurity Law, which became part of Türkiye’s legal framework in 2025, particularly considering its sanctions regime, transforms cybersecurity from a purely technical information security matter into an area of legal and corporate compliance for companies. Companies should therefore first determine whether their activities fall within the scope of the Law.
Companies that fall within the scope of the Law should review their existing cybersecurity governance structures, incident response and notification processes, allocation of roles and responsibilities, and relevant policies and procedures considering the applicable obligations. Furthermore, given that the Law establishes a general framework in many respects, companies should closely monitor the secondary legislation and other regulatory instruments to be issued by the Presidency and treat compliance with the Law as an ongoing process.
All rights of this article are reserved. This article may not be used, reproduced, copied, published, distributed, or otherwise disseminated without quotation or Erdem & Erdem Law Firm's written consent. Any content created without citing the resource or Erdem & Erdem Law Firm’s written consent is regularly tracked, and legal action will be taken in case of violation.