Critical Infrastructures · Law No. 7545 · BIG Guide
Cyber Security and Compliance in Critical Infrastructures
Cybersecurity is now a scheduled obligation for 15 critical infrastructure sectors
With the transfer of all powers of the former Digital Transformation Office (DDO) to To the Cyber Security Presidency (SGB) , which has legislative and administrative enforcement powers, Information and Communication Security Guide audits have moved from awareness raising to mandatory legal compliance. In line with the EU NIS2 Directive, coverage of critical infrastructure sectors has increased from 6 to 15 ; boards of directors now bear direct legal and financial responsibility for non-compliance.
Horizontal Legislation
Common obligations binding all 15 sectors
All sectors that qualify as critical infrastructure — and suppliers that provide software/hardware to these infrastructures — are subject to the following common framework, regardless of sector.
7545 · Corporate SOME
It is mandatory to establish a Cyber Incident Response Team and to report violations to the SGB immediately, without hiding them. The notification obligation is also valid for Category B sectors as of today.
7545 · Approved Supplier
Only reliable hardware and software certified by the SGB can be used in critical infrastructures. transition process March 19, 2027It is completed in ; Purchasing specifications should be revised today.
6698 · KVKK
In accordance with the principle of data sovereignty, critical data must be hosted domestically and in case of a breach 72 hours in notification rule. The level of precaution becomes more severe in sectors that process special data, such as health.
5651 · Log Management
Storing internal and external network traffic logs with timestamp in an unchangeable format (2 years in general application). Log integrity is one of the basic control items of BİG audits.
Audit Status
Category A and Category B: two different legal calendars
BIG Guide compliance audit obligation is divided into two according to the status of the sector in the legislation. This distinction is the most critical detail that directly affects the legal responsibilities and compliance schedules of institutions.
Category A · Previous 6 Sectors
Strict legal obligation — compliance margin filled
For 6 sectors that have been considered critical infrastructure from the very beginning in the National Cyber Security Strategy Independent compliance audit at least once a year It is a legal obligation that cannot be postponed.
- Certified chief auditors Annual independent audit through
- Your findings and Closing the Difference action plans BIGDES Uploading to the portal
- Direct sanction by SGB in case of disruption
Category B · Newly Added 9 Sectors
Adaptation and transition process — timetable at SGB
Mandatory annual independent audits for the 9 sectors newly included in the list have not yet been officially scheduled; SGB will publish a transition schedule covering mandatory data entry into BIGDES.
- of 7545 penalty and SOME notification clauses valid as of today
- Before the transition period expires asset groups needs to be determined
- Internal audit and Gap Analysis a legal requirement
Sector × Regulation Matrix
Liability map of 15 critical infrastructure sectors
A summary view of the horizontal and vertical regulations that each sector is subject to. Under the sector name, there are relevant authorities and basic sectoral legislation.
| Sector | 7545 | BIG Audit | KVKK | Sectoral | OT / ICS |
|---|---|---|---|---|---|
| Category A — Annual independent BIG audit is mandatoryPrevious 6 sectors · compliance margin is full | |||||
| Electronic CommunicationsBTK · SGB — 5809 p. Law, Network and Information Security Regulation | |||||
| EnergyEMRA · ETKB · SGB — EMRA Cyber Security Competency Model, BIG Energy Annex | |||||
| FinanceBRSA · CBRT · CMB · MASAK · SGB - BRSA Information Systems Regulation, CMB Communiqué | |||||
| Water ManagementMinistry of Agriculture and Forestry · DSI · SGB — BİG Water Management Sectoral Guide | |||||
| transportationMinistry of Transport and Infrastructure · DGCA · SGB — SHY-BİLGİ Instruction, ISPS Code | |||||
| Critical Public ServicesDirect SGB — KamuNet Guidelines, e-Government Information Security Standards | |||||
| Category B — 9 sectors in adaptation and transitionPenalty and SOME notification articles are valid as of today. | |||||
| Digital InfrastructuresSGB · BTK — Data centers, IXP; Tier certifications, ban on physical intervention | |||||
| Digital ServicesMinistry of Commerce · SGB · BTK — Cloud, e-commerce infrastructures; PCI-DSS, SLA protection | |||||
| healthMinistry of Health · KVKK · SGB — HBYS, e-Pulse, IoMT micro-segmentation | |||||
| Defense IndustryMSB · SSB · SGB - Facility Security Certificate, Air-Gap, TEMPEST | |||||
| Manufacturing IndustryMinistry of Industry and Technology · SGB — Industry 4.0, IIoT, IEC 62443 | |||||
| Food and AgricultureMinistry of Agriculture and Forestry · SGB — Smart agriculture, cold chain, security of supply | |||||
| Media and Crisis CommunicationsRTÜK · Directorate of Communications · SGB — Broadcast signal security, combating disinformation | |||||
| Mail and CargoBTK · Ministry of Transport and Infrastructure · SGB — Logistics databases, ISO 22301 | |||||
| spaceTUA · BTK · SGB — Telemetry security, jamming/spoofing, national cryptography | |||||
Column 7545 describes the Law's SOME establishment, violation notification and approved supplier obligations; BİG Audit column indicates annual independent compliance audit status; The sectoral column includes vertical authority regulations; The OT / EKS column expresses the aggravated security expectation for SCADA and industrial control systems. The table is for informational purposes only; It does not replace legal opinion.
Service × Regulation Matrix
Which of our services covers which obligation?
Scope map of the Scale service catalog against the above set of obligations. Indicates which family of regulations or standards each service serves.
For Category A sectors, our audit services produce official reports that can be uploaded to BIGDES; For Category B sectors, the same methodology is applied as Gap Analysis and readiness audit.
For Boards of Directors
High Level strategic action plan
The establishment of the SGB as the main supervisory authority and the heavy penalties of 7545 took cyber security out of the field of responsibility of IT and turned it into the financial and legal responsibility of the Board of Directors. Immediate steps for businesses operating in these 15 sectors — or providing software/hardware to these infrastructures:
If you are in Category A: complete the audit
Complete the BIG Guide independent audit process without wasting time; Upload your detected findings and Gap Closing risk analyzes to the BIGDES portal.
If you are in Category B: don't wait for the calendar
Inventory all IT and OT assets, classify them according to BIG Guide criticality (Level 1-2-3) and allocate a budget for internal Gap Analysis studies today.
Prepare the supply chain for SGB approval
Revise the purchasing specifications today to gradually remove products and services that do not have a SGB approved/certified supplier license from the system.
Set up SOME and notification network
The penalty for not reporting the violation within the legal period has been increased to upper limits. Increase internal SOME competency and integrate the team into the USOM/SGB notification network.
Let's create the liability map of your industry together
From Category A inspection schedule to Category B preparation plan; Let's clarify the scope, duration and budget.