Turkey Cybersecurity Law (Law No. 7545)
Turkey's Cybersecurity Law No. 7545 (Siber Guvenlik Kanunu, in force 19 March 2025), as amended by Law No. 7590 from 31 July 2026: what organisations using information systems must do (deliver data and systems the Cybersecurity Presidency requests, take the prescribed measures, report vulnerabilities and incidents without delay, carry out the Presidency's cyber maturity policies and action plans, keep systems open for audit), what public bodies and critical infrastructures must do (buy cybersecurity products and services only from authorised providers, keep asset inventories with risk analysis), and what cybersecurity companies must do (obtain approval before operating and certify within the transition period, follow export procedures, notify mergers and obtain approval for changes of control), with the fines of up to 100 million lira and the crimes the Law creates. 11 duty leaves.
Turkey Cybersecurity Law (Law No. 7545) is a compliance framework from Turkey (Turkiye) with 2 domains and 11 controls that map to 2 other frameworks. The largest domains are Duties of organisations: cooperation, security measures, reporting, procurement, certification, cyber maturity, asset inventory and audit – Turkey Cybersecurity Law (Law No. 7545) (9 controls), Duties of cybersecurity producers: exports and changes of control – Turkey Cybersecurity Law (Law No. 7545) (2 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (2)
Duties of cybersecurity producers: exports and changes of control – Turkey Cybersecurity Law (Law No. 7545)
| Code | Title |
|---|---|
| turkey-cybersecurity-law-law-no-7545::18.1 | Article 18(1): export cybersecurity products under the Presidency's procedures, with approval for listed products |
| turkey-cybersecurity-law-law-no-7545::18.2 | Article 18(2) and (3): notify mergers and share transfers of cybersecurity producers; obtain approval for changes of control |
Duties of organisations: cooperation, security measures, reporting, procurement, certification, cyber maturity, asset inventory and audit – Turkey Cybersecurity Law (Law No. 7545)
| Code | Title |
|---|---|
| turkey-cybersecurity-law-law-no-7545::5.1.c-ch | Article 5(1)(ç): public institutions and critical infrastructures keep a full asset inventory, including data, and a risk analysis |
| turkey-cybersecurity-law-law-no-7545::7.1.a | Article 7(1)(a): supply the Presidency with the data, information, documents, hardware and software it requests, with priority and on time |
| turkey-cybersecurity-law-law-no-7545::7.1.b-measures | Article 7(1)(b): take the cybersecurity measures the legislation prescribes |
| turkey-cybersecurity-law-law-no-7545::7.1.b-report | Article 7(1)(b): report vulnerabilities and cyber incidents to the Presidency without delay |
| turkey-cybersecurity-law-law-no-7545::7.1.c | Article 7(1)(c): public institutions and critical infrastructures buy cybersecurity products and services only from Presidency-authorised providers |
| turkey-cybersecurity-law-law-no-7545::7.1.c-ch | Article 7(1)(ç) and Article 16(2): cybersecurity companies obtain Presidency approval before starting activity |
| turkey-cybersecurity-law-law-no-7545::7.1.d | Article 7(1)(d): implement the Presidency's policies, strategies, action plans and regulatory acts on cyber maturity |
| turkey-cybersecurity-law-law-no-7545::8.4 | Article 8(4): keep systems open for audit and provide the audit infrastructure |
| turkey-cybersecurity-law-law-no-7545::P1.4 | Provisional Article 1(4): complete certification, authorisation and accreditation within one year of the implementing regulations |
Maps to 2 other frameworks
Coverage is not the same as your position
This page shows what Turkey Cybersecurity Law (Law No. 7545) overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is Turkey Cybersecurity Law (Law No. 7545) and who does it apply to?
Turkey Cybersecurity Law (Law No. 7545) is a compliance framework from Turkey (Turkiye) with 2 domains and 11 controls. Turkey's Cybersecurity Law No. 7545 (Siber Guvenlik Kanunu, in force 19 March 2025), as amended by Law No. 7590 from 31 July 2026: what organisations using information systems must do (deliver data and systems the Cybersecurity Presidency requests, take the prescribed measures, report vulnerabilities and incidents without delay, carry out the Presidency's cyber maturity policies and action plans, keep systems open for audit), what public bodies and critical infrastructures must do (buy cybersecurity products and services only from authorised providers, keep asset inventories with risk analysis), and what cybersecurity companies must do (obtain approval before operating and certify within the transition period, follow export procedures, notify mergers and obtain approval for changes of control), with the fines of up to 100 million lira and the crimes the Law creates. 11 duty leaves. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Turkey Cybersecurity Law (Law No. 7545) actually require?
Turkey Cybersecurity Law (Law No. 7545) has 11 controls organised across 2 domains. The largest domains are Duties of organisations: cooperation, security measures, reporting, procurement, certification, cyber maturity, asset inventory and audit – Turkey Cybersecurity Law (Law No. 7545) (9 controls), Duties of cybersecurity producers: exports and changes of control – Turkey Cybersecurity Law (Law No. 7545) (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Turkey Cybersecurity Law (Law No. 7545) do I already cover?
Turkey Cybersecurity Law (Law No. 7545) maps to 2 other compliance frameworks. The top mapping partners are NIS2 Directive (55% coverage), ISO 27001:2022 (55% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement Turkey Cybersecurity Law (Law No. 7545)?
Start your Turkey Cybersecurity Law (Law No. 7545) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Turkey Cybersecurity Law (Law No. 7545) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 11 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 723 frameworks.
Get Started Free →Free forever — no credit card required