Cybersecurity & Compliance

Turkey's Cybersecurity Law and manufacturing SMEs: what changes?

Turkey's Law No. 7545 on Cybersecurity, in force since 19 March 2025, covers any legal entity operating an information system. What it means for manufacturing SMEs running ERP, cloud, and IoT, and which precautions are actually proportionate.

Updated: 27 August 2026 The figures and legal references on this page are based on official/primary sources.

Turkey's Cybersecurity Law and manufacturing SMEs: what changes?

Law No. 7545 on Cybersecurity was published in the Official Gazette (Resmî Gazete) on 19 March 2025, issue 32846 — Turkey’s first standalone cybersecurity law. Most manufacturers who skim the text conclude “this isn’t about us, we’re not critical infrastructure.” The scope wording is broader than that: any legal entity operating an information system is a potential addressee.

For a manufacturer that has moved its ERP to the cloud, connected IoT sensors on the shop floor, or shares data with suppliers and customers, that stops being an abstract legal question and becomes a concrete one: which obligation applies in our specific case, and which doesn’t?

What the law introduces, briefly

The framework breaks down into four areas.

AreaContent
ScopePublic institutions, critical infrastructure operators, cybersecurity product/service providers, and — more broadly — legal entities operating information systems
AuthorityThe Cybersecurity Presidency (Siber Güvenlik Başkanlığı), established under the Presidency, with power to issue policy, strategy and guidance, and to conduct oversight and intervention
Core obligationsImplementing security measures published by the Presidency, providing requested information and documentation on time, reporting detected attacks or vulnerabilities without delay
SanctionsAdministrative fines (the law sets a band roughly between 1 million TRY and 100 million TRY) and, for certain violations, imprisonment

Entities designated as critical infrastructure operators carry one more obligation: they must source cybersecurity products and services exclusively from providers authorized by the Presidency. Which sectors and which specific businesses count as “critical infrastructure” will be clarified through secondary regulation the Presidency has yet to publish in full at the time of writing.

Two separate layers of obligation are worth pulling apart here.

The first layer applies to critical infrastructure operators — companies and institutions in sectors such as energy, transport, finance, or healthcare, formally designated as such by the Presidency. For this group the obligations are heavier: authorized-supplier requirements, regular audits, penetration testing.

The second layer is broader and less defined: the law text treats any legal entity running an information system as a potential addressee. A manufacturing SME may not appear on a critical infrastructure list, yet there is no guarantee it falls outside the Presidency’s general information-sharing and precaution-taking requirements — because the secondary regulation hasn’t fully settled yet.

The practical takeaway: concluding “we’re not critical infrastructure, so this doesn’t apply to us” is premature for now. The safer approach is to track the guidance the Presidency publishes, while treating what are already sound digital-hygiene practices as a priority regardless.

The practical risk surface for manufacturers: ERP, cloud, IoT

Independent of how the scope debate settles, a digitalizing production site has one concrete fact to deal with: every new connection point is also a new risk point.

  • ERP and cloud systems — once planning, inventory and financial data sit in one system, weak authentication or access control there creates a single point of large-scale data loss.
  • IoT sensors and machine-to-machine (M2M) communication — once shop-floor sensors go online, unpatched legacy device firmware widens the attack surface.
  • Supplier and customer data sharing — the emissions and production data increasingly exchanged under CBAM and CSRD pressure is, at the same time, a new data-security responsibility.
  • Remote access — field teams or maintenance contractors connecting remotely can become a back door if not configured correctly.

None of this list is created by the law itself — it’s created by digitalization. The law adds a regulatory and notification layer on top of risks that already exist.

Proportionate precautions: you can’t manage what you don’t measure

The same rule that applies to green transition applies here: you cannot manage a risk you haven’t measured. For a manufacturing SME, the steps involved are less about a large-budget transformation project and more about ongoing discipline.

  1. Build an inventory. Which system (ERP, cloud, IoT gateway) has access to which data, and who administers it — if that isn’t clear, this table comes first.
  2. Tighten access. Multi-factor authentication (MFA) and role-based access control are two low-cost, high-impact measures.
  3. Set a patching and update cadence. Especially for legacy shop-floor devices — hardware past vendor support is among the most common open doors.
  4. Define an incident-reporting process. When a vulnerability or attack is detected, who does what should already be settled; the law reinforces this with its without-delay notification requirement.
  5. Review supplier and partner access. Every remote account belonging to a third party is only as secure as your own access controls make it.

These steps line up with the ISO/IEC 27001 framework we work within as part of our Sustain axis: treating cybersecurity as a precondition built into system design, not a layer bolted on afterward.

Not to be confused with data-protection law (KVKK)

Turkey’s Cybersecurity Law doesn’t replace KVKK (the Law on the Protection of Personal Data) — the two sit at different layers. KVKK governs how personal data is processed and protected: VERBİS registration, explicit consent, data-processing agreements. The Cybersecurity Law instead targets the resilience of the system itself and coordination with the state during an incident or vulnerability. In practice the two complement each other: KVKK answers “which data are you processing and why,” while the new law answers “how are you protecting the system that carries it.” For a manufacturing SME, evaluating both together is more efficient than treating them as separate tracks.

Where to start, concretely

Across 550+ customers and 100+ ERP projects in the Qera track record, the pattern behind most security gaps is rarely a sophisticated attack — it’s the absence of basic hygiene: shared passwords, unpatched servers, accounts left active after someone leaves. Building that inventory at the start of a digitalization project is consistently cheaper than patching after the fact.

Companies looking for a corporate assessment can request a discovery conversation through our contact form that covers digitalization and security inventory together, within our Measure–Transform–Sustain methodology; sharing preliminary information carries no commitment.

Frequently Asked Questions

Which businesses does the Cybersecurity Law directly bind?

The definitive answer depends on the critical infrastructure list and secondary regulation the Presidency has yet to publish in full. What’s known today: public institutions, critical infrastructure operators, and cybersecurity product/service providers are directly in scope; the scope and degree of obligation for other legal entities operating information systems depends on forthcoming secondary regulation.

Does a manufacturing SME count as critical infrastructure?

General manufacturing activity alone doesn’t meet the critical infrastructure definition; that designation is typically tied to sectors like energy, transport, finance, or healthcare. However, businesses active in energy production/distribution, water, or food safety, or that supply critical infrastructure operators, may be assessed differently — the final determination rests with the Presidency.

Is the penalty risk real, or just a deterrent ceiling?

The administrative fine band set in the law (1 million to 100 million TRY) and imprisonment for certain violations are actual sanctions written into the text. How severely a given violation is penalized in practice will become clearer through the Presidency’s enforcement pattern.

If a business is already KVKK-compliant, is it ready for this law too?

Partially. KVKK compliance — VERBİS registration, a data-processing inventory, consent processes — builds a solid foundation, but the Cybersecurity Law’s focus is different: system resilience against attacks and the incident-reporting process. The two should be assessed separately.

How much budget should a small production site set aside for this?

A precise figure would be misleading; it depends on scale, existing infrastructure, and risk profile. The general direction favors ongoing, proportionate measures (MFA, access control, a patching cadence) over one large upfront investment. For a framework specific to your situation, consulting a compliance advisor or the Presidency’s forthcoming guidance is recommended.

Sources

Related pages: Digital Transition · Solutions · Services · Glossary

Share on LinkedIn

Related posts

This content is informational; confirm official regulation and incentive terms from primary sources (the relevant authority / Official Gazette).

Looking for where to start your digital or green transformation?

Starting with İkiz Eksen is simple: we first measure where you stand and build your roadmap together. You begin with a single step, not a large programme.