← Scale Technology Group Law No. 7545 is in force · Critical infrastructure coverage increased to 15 sectors

Critical Infrastructures · Law No. 7545 · BIG Guide

Cyber Security and Compliance in Critical Infrastructures

Cybersecurity is now a scheduled obligation for 15 critical infrastructure sectors

With the transfer of all powers of the former Digital Transformation Office (DDO) to To the Cyber Security Presidency (SGB) , which has legislative and administrative enforcement powers, Information and Communication Security Guide audits have moved from awareness raising to mandatory legal compliance. In line with the EU NIS2 Directive, coverage of critical infrastructure sectors has increased from 6 to 15 ; boards of directors now bear direct legal and financial responsibility for non-compliance.

15
Critical Sector
6
Category A · Annual Audit Mandatory
9
Category B · Transition Process
₺10M
7545 Penalty Upper Limit

Horizontal Legislation

Common obligations binding all 15 sectors

All sectors that qualify as critical infrastructure — and suppliers that provide software/hardware to these infrastructures — are subject to the following common framework, regardless of sector.

7545 · Corporate SOME

It is mandatory to establish a Cyber ​​Incident Response Team and to report violations to the SGB immediately, without hiding them. The notification obligation is also valid for Category B sectors as of today.

7545 · Approved Supplier

Only reliable hardware and software certified by the SGB can be used in critical infrastructures. transition process March 19, 2027It is completed in ; Purchasing specifications should be revised today.

6698 · KVKK

In accordance with the principle of data sovereignty, critical data must be hosted domestically and in case of a breach 72 hours in notification rule. The level of precaution becomes more severe in sectors that process special data, such as health.

5651 · Log Management

Storing internal and external network traffic logs with timestamp in an unchangeable format (2 years in general application). Log integrity is one of the basic control items of BİG audits.

Sanction: In case of avoiding BIG inspections, not reporting violations or opposing SGB decisions From 1 million ₺ to 10 million ₺ An administrative fine (or a certain percentage of the company's annual gross sales revenue) may be imposed. In case of obtaining benefit or causing damage, the penalty may increase by up to three to five times.

Audit Status

Category A and Category B: two different legal calendars

BIG Guide compliance audit obligation is divided into two according to the status of the sector in the legislation. This distinction is the most critical detail that directly affects the legal responsibilities and compliance schedules of institutions.

Category A · Previous 6 Sectors

Strict legal obligation — compliance margin filled

For 6 sectors that have been considered critical infrastructure from the very beginning in the National Cyber Security Strategy Independent compliance audit at least once a year It is a legal obligation that cannot be postponed.

  • Certified chief auditors Annual independent audit through
  • Your findings and Closing the Difference action plans BIGDES Uploading to the portal
  • Direct sanction by SGB in case of disruption

Category B · Newly Added 9 Sectors

Adaptation and transition process — timetable at SGB

Mandatory annual independent audits for the 9 sectors newly included in the list have not yet been officially scheduled; SGB ​​will publish a transition schedule covering mandatory data entry into BIGDES.

  • of 7545 penalty and SOME notification clauses valid as of today
  • Before the transition period expires asset groups needs to be determined
  • Internal audit and Gap Analysis a legal requirement

Sector × Regulation Matrix

Liability map of 15 critical infrastructure sectors

A summary view of the horizontal and vertical regulations that each sector is subject to. Under the sector name, there are relevant authorities and basic sectoral legislation.

Legal obligation in force Adaptation/transition calendar process Directly out of scope
Sector 7545 BIG Audit KVKK Sectoral OT / ICS
Category A — Annual independent BIG audit is mandatoryPrevious 6 sectors · compliance margin is full
Electronic CommunicationsBTK · SGB — 5809 p. Law, Network and Information Security Regulation
EnergyEMRA · ETKB · SGB — EMRA Cyber Security Competency Model, BIG Energy Annex
FinanceBRSA · CBRT · CMB · MASAK · SGB - BRSA Information Systems Regulation, CMB Communiqué
Water ManagementMinistry of Agriculture and Forestry · DSI · SGB — BİG Water Management Sectoral Guide
transportationMinistry of Transport and Infrastructure · DGCA · SGB — SHY-BİLGİ Instruction, ISPS Code
Critical Public ServicesDirect SGB — KamuNet Guidelines, e-Government Information Security Standards
Category B — 9 sectors in adaptation and transitionPenalty and SOME notification articles are valid as of today.
Digital InfrastructuresSGB · BTK — Data centers, IXP; Tier certifications, ban on physical intervention
Digital ServicesMinistry of Commerce · SGB · BTK — Cloud, e-commerce infrastructures; PCI-DSS, SLA protection
healthMinistry of Health · KVKK · SGB — HBYS, e-Pulse, IoMT micro-segmentation
Defense IndustryMSB · SSB · SGB - Facility Security Certificate, Air-Gap, TEMPEST
Manufacturing IndustryMinistry of Industry and Technology · SGB — Industry 4.0, IIoT, IEC 62443
Food and AgricultureMinistry of Agriculture and Forestry · SGB — Smart agriculture, cold chain, security of supply
Media and Crisis CommunicationsRTÜK · Directorate of Communications · SGB — Broadcast signal security, combating disinformation
Mail and CargoBTK · Ministry of Transport and Infrastructure · SGB — Logistics databases, ISO 22301
spaceTUA · BTK · SGB — Telemetry security, jamming/spoofing, national cryptography

Column 7545 describes the Law's SOME establishment, violation notification and approved supplier obligations; BİG Audit column indicates annual independent compliance audit status; The sectoral column includes vertical authority regulations; The OT / EKS column expresses the aggravated security expectation for SCADA and industrial control systems. The table is for informational purposes only; It does not replace legal opinion.

Service × Regulation Matrix

Which of our services covers which obligation?

Scope map of the Scale service catalog against the above set of obligations. Indicates which family of regulations or standards each service serves.

Direct scope of service out of scope

For Category A sectors, our audit services produce official reports that can be uploaded to BIGDES; For Category B sectors, the same methodology is applied as Gap Analysis and readiness audit.

For Boards of Directors

High Level strategic action plan

The establishment of the SGB as the main supervisory authority and the heavy penalties of 7545 took cyber security out of the field of responsibility of IT and turned it into the financial and legal responsibility of the Board of Directors. Immediate steps for businesses operating in these 15 sectors — or providing software/hardware to these infrastructures:

1

If you are in Category A: complete the audit

Complete the BIG Guide independent audit process without wasting time; Upload your detected findings and Gap Closing risk analyzes to the BIGDES portal.

2

If you are in Category B: don't wait for the calendar

Inventory all IT and OT assets, classify them according to BIG Guide criticality (Level 1-2-3) and allocate a budget for internal Gap Analysis studies today.

3

Prepare the supply chain for SGB approval

Revise the purchasing specifications today to gradually remove products and services that do not have a SGB approved/certified supplier license from the system.

4

Set up SOME and notification network

The penalty for not reporting the violation within the legal period has been increased to upper limits. Increase internal SOME competency and integrate the team into the USOM/SGB notification network.

Let's create the liability map of your industry together

From Category A inspection schedule to Category B preparation plan; Let's clarify the scope, duration and budget.

Quick Assessment Contact Us