Back to Frameworks

Turkey Cybersecurity Law (Law No. 7545)

Turkey (Turkiye)
vLaw No. 7545 (Resmi Gazete 19 March 2025 No. 32846) as amended by Law No. 7590 of 24 July 2026 (in force 31 July 2026)
2 domains
11 controls

Turkey's Cybersecurity Law No. 7545 (Siber Guvenlik Kanunu, in force 19 March 2025), as amended by Law No. 7590 from 31 July 2026: what organisations using information systems must do (deliver data and systems the Cybersecurity Presidency requests, take the prescribed measures, report vulnerabilities and incidents without delay, carry out the Presidency's cyber maturity policies and action plans, keep systems open for audit), what public bodies and critical infrastructures must do (buy cybersecurity products and services only from authorised providers, keep asset inventories with risk analysis), and what cybersecurity companies must do (obtain approval before operating and certify within the transition period, follow export procedures, notify mergers and obtain approval for changes of control), with the fines of up to 100 million lira and the crimes the Law creates. 11 duty leaves.

Verified

Turkey Cybersecurity Law (Law No. 7545) is a compliance framework from Turkey (Turkiye) with 2 domains and 11 controls that map to 2 other frameworks. The largest domains are Duties of organisations: cooperation, security measures, reporting, procurement, certification, cyber maturity, asset inventory and audit – Turkey Cybersecurity Law (Law No. 7545) (9 controls), Duties of cybersecurity producers: exports and changes of control – Turkey Cybersecurity Law (Law No. 7545) (2 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard Blokdyk

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (2)

Duties of cybersecurity producers: exports and changes of control – Turkey Cybersecurity Law (Law No. 7545)

2 controls
Controls in the Duties of cybersecurity producers: exports and changes of control – Turkey Cybersecurity Law (Law No. 7545) domain of Turkey Cybersecurity Law (Law No. 7545) — 2 controls
CodeTitle
turkey-cybersecurity-law-law-no-7545::18.1Article 18(1): export cybersecurity products under the Presidency's procedures, with approval for listed products
turkey-cybersecurity-law-law-no-7545::18.2Article 18(2) and (3): notify mergers and share transfers of cybersecurity producers; obtain approval for changes of control

Duties of organisations: cooperation, security measures, reporting, procurement, certification, cyber maturity, asset inventory and audit – Turkey Cybersecurity Law (Law No. 7545)

9 controls
Controls in the Duties of organisations: cooperation, security measures, reporting, procurement, certification, cyber maturity, asset inventory and audit – Turkey Cybersecurity Law (Law No. 7545) domain of Turkey Cybersecurity Law (Law No. 7545) — 9 controls
CodeTitle
turkey-cybersecurity-law-law-no-7545::5.1.c-chArticle 5(1)(ç): public institutions and critical infrastructures keep a full asset inventory, including data, and a risk analysis
turkey-cybersecurity-law-law-no-7545::7.1.aArticle 7(1)(a): supply the Presidency with the data, information, documents, hardware and software it requests, with priority and on time
turkey-cybersecurity-law-law-no-7545::7.1.b-measuresArticle 7(1)(b): take the cybersecurity measures the legislation prescribes
turkey-cybersecurity-law-law-no-7545::7.1.b-reportArticle 7(1)(b): report vulnerabilities and cyber incidents to the Presidency without delay
turkey-cybersecurity-law-law-no-7545::7.1.cArticle 7(1)(c): public institutions and critical infrastructures buy cybersecurity products and services only from Presidency-authorised providers
turkey-cybersecurity-law-law-no-7545::7.1.c-chArticle 7(1)(ç) and Article 16(2): cybersecurity companies obtain Presidency approval before starting activity
turkey-cybersecurity-law-law-no-7545::7.1.dArticle 7(1)(d): implement the Presidency's policies, strategies, action plans and regulatory acts on cyber maturity
turkey-cybersecurity-law-law-no-7545::8.4Article 8(4): keep systems open for audit and provide the audit infrastructure
turkey-cybersecurity-law-law-no-7545::P1.4Provisional Article 1(4): complete certification, authorisation and accreditation within one year of the implementing regulations

Maps to 2 other frameworks

11 total controls
NIS2 Directive
6 source controls mapped|6 target controls covered
55%
ISO 27001:2022
6 source controls mapped|5 target controls covered
55%

Coverage is not the same as your position

This page shows what Turkey Cybersecurity Law (Law No. 7545) overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is Turkey Cybersecurity Law (Law No. 7545) and who does it apply to?

Turkey Cybersecurity Law (Law No. 7545) is a compliance framework from Turkey (Turkiye) with 2 domains and 11 controls. Turkey's Cybersecurity Law No. 7545 (Siber Guvenlik Kanunu, in force 19 March 2025), as amended by Law No. 7590 from 31 July 2026: what organisations using information systems must do (deliver data and systems the Cybersecurity Presidency requests, take the prescribed measures, report vulnerabilities and incidents without delay, carry out the Presidency's cyber maturity policies and action plans, keep systems open for audit), what public bodies and critical infrastructures must do (buy cybersecurity products and services only from authorised providers, keep asset inventories with risk analysis), and what cybersecurity companies must do (obtain approval before operating and certify within the transition period, follow export procedures, notify mergers and obtain approval for changes of control), with the fines of up to 100 million lira and the crimes the Law creates. 11 duty leaves. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Turkey Cybersecurity Law (Law No. 7545) actually require?

Turkey Cybersecurity Law (Law No. 7545) has 11 controls organised across 2 domains. The largest domains are Duties of organisations: cooperation, security measures, reporting, procurement, certification, cyber maturity, asset inventory and audit – Turkey Cybersecurity Law (Law No. 7545) (9 controls), Duties of cybersecurity producers: exports and changes of control – Turkey Cybersecurity Law (Law No. 7545) (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Turkey Cybersecurity Law (Law No. 7545) do I already cover?

Turkey Cybersecurity Law (Law No. 7545) maps to 2 other compliance frameworks. The top mapping partners are NIS2 Directive (55% coverage), ISO 27001:2022 (55% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement Turkey Cybersecurity Law (Law No. 7545)?

Start your Turkey Cybersecurity Law (Law No. 7545) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Turkey Cybersecurity Law (Law No. 7545) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 11 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 723 frameworks.

Get Started Free →

Free forever — no credit card required