Cybersecurity Perimeter Sharpens: Türkiye Names Its Critical Infrastructure Sectors

Tue 4 Aug, 2026

Türkiye’s Cybersecurity Framework Enters a New Phase

Türkiye’s cybersecurity framework has entered a new phase. The Cybersecurity Board meeting on 5 May 2026 did more than identify critical infrastructure sectors. It signaled the operationalization of a broader national cybersecurity governance model built around resilience, state coordination, data sovereignty, domestic technological capacity and regulatory supervision.

The launch of the Cybersecurity Presidency’s (“Presidency”) institutional website, siberguvenlik.gov.tr, belongs to the same picture, creating a public-facing channel for reporting, applications, guidance and security notices.

Read together, these developments mark a significant step in implementing Cybersecurity Law No. 7545 (“Law”). The 5 May decision operationalizes the Law’s critical infrastructure framework, bringing sectoral operators, vendors and boards directly within regulatory focus.

For organizations falling within scope, the decision represents a recalibration point for compliance programs, third-party risk management, incident response, data governance and audit readiness.

The Cybersecurity Board Designated Critical Infrastructure Sectors

On 5 May 2026, the Cybersecurity Board reviewed current and emerging cyber risks impacting Türkiye’s national cybersecurity posture. It recognized that cybersecurity is an integral component of national security and affirmed the Presidency’s commitment to protecting Türkiye’s digital assets, establishing a proactive threat response and building a strong national cybersecurity architecture.

The meeting’s most significant outcome was the identification of critical infrastructure. The Board designated fifteen sectors as critical infrastructure:

  • Digital Infrastructure
  • Digital Services
  • Electronic Communications
  • Energy
  • Finance
  • Food and Agriculture
  • Manufacturing
  • Public Services
  • Media and Crisis Communication
  • Postal and Courier
  • Health
  • Defense Industry
  • Water Management
  • Transportation
  • Space

This expansion mirrors approaches in comparable jurisdictions, such as the EU’s NIS2 Directive, which covers 18 sectors across two tiers of essential and important entities. This reflects the shared understanding that a cyber incident in a structurally vital sector carries consequences beyond the directly affected company.

This list in the 5 May decision is broader than Türkiye’s earlier critical infrastructure approach. Historically, critical infrastructure encompassed electronic communications, energy, finance, transportation, water management and core public services.

The 5 May 2026 decision clearly broadens this scope to include digital infrastructure, digital services, media and crisis communication, postal and courier services, manufacturing, defense industry, food and agriculture, and space.

The Implementation Path Ahead

The sector list does not close the designation process. It sets the stage for the implementation work to follow.

Through the 5 May decision, the Board has set the sectoral perimeter, while the Presidency, under the Cybersecurity Law, is expected to identify the critical infrastructures, the institutions to which they belong and their locations.

As a priority, the Presidency is expected to determine which systems, platforms, facilities, services and data-processing environments within the fifteen sectors should be treated as critical. It is also expected to establish technical criteria for the software, hardware, products and services used in public institutions and critical infrastructures.

In parallel, the Presidency is expected to develop secondary legislation covering:

  • Vulnerability and incident notification procedures
  • The authorization, certification and accreditation regime for cybersecurity providers
  • Audit expectations and minimum security controls
  • Asset inventory requirements
  • Data inventory requirements
  • Risk analysis requirements for in-scope organizations

For confirmed critical infrastructure operators, the procurement dimension comes to the fore. Cybersecurity products, systems and services used in their environments must be supplied by Presidency-authorized and certified providers.

In practice, this requires:

  • Vendor mapping
  • Contract amendments
  • Replacement of non-compliant suppliers
  • New representations and warranties
  • Audit rights
  • Regulatory cooperation clauses
  • Incident notification timelines
  • Termination or transition mechanisms

Vendor selection ceases to be merely a procurement decision and becomes a regulated activity.

This dynamic extends to suppliers as well. Companies providing services to critical infrastructure operators, or supplying cybersecurity products and services into critical infrastructure environments, will need to continuously monitor their own certification, authorization and ongoing compliance status.

This will be necessary both as a regulatory matter and as a precondition to remaining commercially viable in the sector.

What to Watch Going Forward

Sectoral boundaries: Uncertainty remains regarding the scope of newly added sectors. Digital Services, Digital Infrastructure and Manufacturing are broad categories. How the Presidency defines the boundaries of these newly added sectors will determine the practical impact of the decision.

Narrow functional criteria will result in a manageable scope. Broad sectoral criteria could draw thousands of operators into the regime.

Secondary legislation and technical criteria: Further rules are expected on critical infrastructure designation, SOME establishment requirements, asset and data inventory formats, vulnerability and incident notification procedures, audit methodology, minimum security controls and technical standards, authorized provider requirements, and cybersecurity product and service procurement.

Interaction with existing frameworks and operational readiness: Public institutions and certain critical infrastructure operators already carry cybersecurity obligations under existing frameworks, including, in particular, the Presidential Digital Transformation Office’s Information and Communication Security framework.

Newly designated operators should anticipate overlap and monitor how the Presidency’s evolving rules interact with those existing requirements. They should also review their current cybersecurity posture against the framework already established under the Law.

Procurement and contracting practice: The Law narrows the range of permissible suppliers, and the contractual framework will adjust accordingly.

Authorized-provider clauses, tighter incident notice obligations, audit rights, subcontractor controls, rules on data location and log access, evidence preservation requirements and regulatory cooperation undertakings are likely to become standard.

Procurement and supplier agreements in critical infrastructure environments will need to be reviewed and, in many cases, rewritten against the new compliance architecture.

Sanctions exposure: The Law provides for both administrative fines and criminal penalties. Fines cover notification failures, procurement non-compliance, and breaches of confidentiality or data-sharing duties.

Criminal liability applies to obstruction, operating without required approvals, and unauthorized disclosure. Exposure is not limited to fines.

The website as an operational channel: The Presidency’s official website at siberguvenlik.gov.tr already serves as an active source of guidance and notices. It should be considered part of the compliance architecture and monitored throughout the implementation process.

Final Development

While this note was being finalized, the Presidency updated both the Information and Communication Security Guide and its Audit Guide.

The regime is moving into a more active phase, and further guidance from the Presidency is likely to follow in short order.

Organizations operating within the fifteen designated sectors should keep a close eye on what comes next.