Skip to content
Guide

Does Türkiye's Cybersecurity Law Apply to You? The 15 Critical Infrastructure Sectors

The penalty ceiling is five percent of gross sales revenue, with board liability in play. Who Law No. 7545 applies to, and which fifteen sectors count as critical.

Oğuzhan Gerçek··5 min read
Does Türkiye's Cybersecurity Law Apply to You? The 15 Critical Infrastructure Sectors

Short answer: Türkiye's Cybersecurity Law No. 7545 entered into force on March 19, 2025. Fifteen sectors (including energy, finance, health, manufacturing and transport) are designated critical infrastructure. If you operate in one of them, you are already required to provide information and logs, report vulnerabilities, and report cyber incidents without delay.

Over the past year the question we have heard most from customers is this: "Does this law apply to us?" It sounds innocent, but there is a real budget decision behind it, because if the answer is yes there is work to do and some of the clocks have already started.

This is not a legal text. It is written so you can run the scope check quickly and take the right question to the right person.

The fifteen critical infrastructure sectors

The Cybersecurity Board has designated fifteen critical infrastructure sectors:

Digital Infrastructure, Digital Services, Electronic Communications, Energy, Finance, Food and Agriculture, Manufacturing Industry, Public Services, Media and Crisis Communication, Postal and Cargo, Health, Defense Industry, Water Management, Transport, Space.

The first thing you notice is the breadth. "Critical infrastructure" brings to mind a power station or a dam; yet manufacturing and food are on the list too. A significant share of Türkiye's midsize and large companies fall under one of these fifteen headings.

The second thing is subtler: being in a listed sector does not by itself determine the obligation. The company's role in that sector, how critical the systems it runs are, and the nature of the service it provides all count. So neither "our sector is on the list, therefore we're in scope" nor the reverse is a safe inference: do the scope assessment together with your legal team.

The three obligations in force today

The core obligations that came into force on March 19, 2025 fall under three headings:

Providing information, documents and logs. You are required to deliver records requested by the Cybersecurity Directorate on a priority basis and on time. The practical problem here is usually technical rather than legal: logs are either not centralized, not retained long enough, or not held in a form that can be produced within a reasonable period. When the request arrives, there is no time to build that.

Vulnerability reporting. Identified vulnerabilities must be reported to the Directorate.

Cyber incident reporting. The hardest of the three, because the law says "without delay." Having no fixed number of hours does not make it easier, since in hindsight it becomes arguable whether the notification was made within a reasonable period. In practice this means the notification step has to be written into your incident response process in advance. An incident is no time to work out "who do we call, what do we write, who signs it."

None of the three is solved by buying a new security product. All three are about operational maturity: log infrastructure, detection capability, and written process.

Certification and penalties

Directorate-approved certification is planned for companies that provide cybersecurity services or operate critical systems, with twelve months to complete it once the relevant regulations take effect. Because the timeline depends on secondary legislation being published, confirm the exact dates with your own counsel.

With the administrative fines, the fixed amounts matter less than the fact that the ceiling is calculated from turnover. For breaches such as failing to notify, failing to take preventive measures, or obstructing an inspection, the fine can reach up to five percent of gross sales revenue. A ceiling that high makes it impossible to budget the penalty as an operating cost.

A second point gets less attention: although the fine is imposed on the legal entity, the personal liability of board members may also come into play. That moves the issue off the IT budget and onto the board agenda.

Fixed amounts are updated annually by the revaluation rate; for the current figure, consult the law's text in the Official Gazette.

Outsourcing does not transfer the obligation

BDDK regulation in finance states this principle very clearly, and the same logic carries over to other sectors: buying a service from an outside provider does not transfer the obligation attached to it. In a data leak or an outage, the regulator deals with the organization that receives the service.

This has two practical consequences. First, your vendor's commitments have to be written into the contract, particularly on log access, incident notification and audit rights. Second, when selecting a vendor, the question "can this vendor give me the records I will need in an audit?" carries as much weight as price.

Where to start

We suggest three things, in order:

Scope determination. Which sector you are in, which systems count as critical, and what that means for you. This is the one step legal and IT have to do together.

Log and detection inventory. Which systems you collect logs from, how long you retain them, and how many hours it takes to produce them during an incident. If you do not know the answer, the answer is probably not good.

Written incident response flow. Who detects, who decides, who notifies, using which template. One page is enough, but it has to be in writing.

Once those three are done, the remaining work becomes technical and can be planned. Every security product bought before they are done is an expensive answer to a question nobody has asked yet.


This article is general information, not legal advice. Carry out your scope and obligation assessment with your own legal counsel.