Follow us :
Data Security

Turkey's Cybersecurity Law No. 7545: What SMEs Must Know

Cybersecurity monitoring on computer screens with network traffic visuals — Xen Bilişim Data Security

If your company detected a cyberattack tomorrow, would you know who to officially notify, and how fast? Since March 19, 2025, when Turkey’s Law No. 7545 on Cybersecurity came into force, the answer changed for a much wider group of companies than most business owners assume. Plenty of SMEs still tell themselves “this doesn’t apply to us, we’re not critical infrastructure” without ever reading the scope article.

What the law does, and who it covers

Law No. 7545 passed the Turkish parliament on March 12, 2025, and was published in the Official Gazette (No. 32846) on March 19, 2025, taking effect that same day. It also created a new authority reporting directly to the Presidency: the Cyber Security Presidency (Siber Güvenlik Başkanlığı). USOM, Turkey’s long-running national cyber incident response center, and its threat-feed operations were folded into this new body.

The part that catches most SMEs off guard is the scope clause (Article 2). Outside of intelligence and military services, it covers public institutions, professional bodies with public-institution status, and — critically — any natural or legal person operating in cyberspace or providing services through it. In plain terms: any company that runs a system to deliver a service or process data falls inside that definition, whether it’s a 10-person accounting office or a 200-person manufacturing plant.

Three obligations that apply to SMEs

Article 7 puts direct responsibilities on every entity within scope. In practice, they group into three:

ObligationArticleWhat it means
ReportingArt. 7(1)(b)(c)Report any detected vulnerability or cyber incident to the Presidency without delay
Cooperating with auditsArt. 8Allow the Presidency to inspect systems and processes, and respond to information requests
Keeping infrastructure audit-readyArt. 8Maintain the technical setup needed for that inspection to actually happen

The law doesn’t set a fixed reporting window; it uses the phrase “without delay.” That’s a separate duty from the 72-hour data-breach notification under Turkey’s data protection law (KVKK) — the two run in parallel, not as substitutes for each other.

The fines are not symbolic

Article 16 provides for both administrative fines and, for the more serious violations, prison terms. Failing to meet the reporting and cooperation duties under Article 7(1)(b)(c) can bring a fine of 1 million to 10 million lira. Failing to maintain audit-ready infrastructure carries 100,000 to 1 million lira, and in some cases up to 5% of a commercial company’s gross sales revenue. More severe breaches — like violating confidentiality obligations or operating without required authorization — carry prison sentences as well. For a 20-person business, a 1-million-lira fine is several times an annual IT budget. Assuming “they’ll never come after us” is a real gamble.

Is your USOM feed still working?

One technical change slipped in alongside the legal one. As of June 1, 2026, USOM’s malicious-link list stopped being distributed as a plain .txt file; it’s API-only now. If your firewall or security product used to pull that list the old way, the integration has likely stopped quietly, with no error message telling you protection has gone stale. Checking this on Sophos, FortiGate, or similar gear takes a few minutes, but it’s an easy thing to overlook.

What to do now

You don’t need a large compliance project to start. Three steps cover the basics:

  • Put your incident-reporting process in writing — who reports what, to whom, and how. That knowledge shouldn’t live in one person’s head.
  • Ask your security vendor whether your USOM / Cyber Security Presidency feed integration runs over the API or the discontinued method.
  • Review in advance which logs and records you could produce on request. Scrambling to organize them mid-audit makes everything harder.

Frequently asked questions

Does Law No. 7545 replace KVKK? No. KVKK governs personal data processing; Law No. 7545 governs the cybersecurity of information systems. A single breach can trigger notification duties under both laws — they’re independent obligations.

Does a company running only cloud-based systems fall under this law? Yes. The scope hinges on providing a service or processing data through an information system, regardless of whether the servers sit in your office or in the cloud.

Do I get fined the moment I miss a report? No — an inspection process runs first, and fines aren’t automatic. But not knowing the obligation exists makes it much harder to defend your position once an inspection starts.

Should my MSP handle this, or is it on me? Your provider can manage the technical side — feed integration, log collection, incident detection. But approving the reporting procedure and naming who’s accountable for it should stay a decision your company makes itself.

If you’re not sure whether your firewall’s USOM feed has moved to the API, or you want your incident-reporting process written down properly, get in touch — we’ll walk through your current security setup against Law No. 7545 together.

Share this post
Türkçe oku

Related Posts