Cybersecurity 2026

TÜRKIYE Law and Practice Contributed by: Bora Yazıcıoğlu, Alper Işık, Emre Öntekin and Ferat Gümüş, YAZICIOGLU Legal

Guidance of the MTI The MTI is tasked with identifying critical infrastruc - tures along with the institutions they belong to and their locations (although this duty will be transferred to the Directorate when it is operational). There are six critical infrastructure sectors: • e-communications;

Energy The main regulation on cybersecurity in the energy sector is the By-Law on Cybersecurity Competency Model in the Energy Sector, which aims to define the minimum level of security of industrial control systems used in the energy sector and establish the proce - dures and principles governing their cyber-resilience, proficiency and maturity. The By-Law covers industrial control systems owned by legal entities with the following licences: • electricity transmission; • electricity distribution; • electricity generation facility; • natural gas transmission licence for pipeline trans - mission; • natural gas distribution; • natural gas storage; • crude oil transmission; and • refinery. Banking and Finance The By-Law on Information Systems of Banks and Electronic Banking Services (“By-Law ISBEBS”) aims to manage information systems used by banks, estab - lishing the minimum standards for electronic banking services and the management of risks related thereto. 2.2 Critical Infrastructure Cybersecurity Requirements General According to the Cybersecurity Act, one of the duties of the Directorate is to determine technical criteria for cybersecurity products and services to be used in public institutions and critical infrastructures. How - ever, these criteria have not yet been determined as the Directorate has not yet become fully operational. For information on certification requirements of critical infrastructures, see 5.1 Key Cybersecurity Certifica - tion Legislation . The Presidency Decree provides the following security measures for critical infrastructure security of public entities:

• energy; • finance; • transport;

• water management; and • critical public services.

The Sectoral CERT Guideline published by the MTI defines critical public services as those provided by critical systems with which citizens frequently interact, and mentions the following:

• civil registration; • land registration; • taxation; • commerce; • social security;

• health (emergency services, medical services, blood and organ donation and public health); • food; • security forces; • roads and bridges; • dams; and • services provided via critical systems where salary and judicial transactions are performed and their records are kept. The MTI has also published the “Document for Mini - mum Security Measures for Critical Information Sys - tem Infrastructure” and “Minimum Information Secu - rity Criteria for Public Institutions to Comply”. E-Communications The By-Law on NIS in the E-Communications Sector is the main regulation for the e-communications sec - tor, with the purpose of providing the procedures and principles for operators to apply in order to ensure network and information security. It applies to opera - tors that are subject to the E-Communications Law.

422 CHAMBERS.COM

Powered by