Turkey's comprehensive cybersecurity law, which came into effect on March 19, 2025, significantly consolidates power within the Presidency concerning digital governance and cybersecurity. This legislation, established by Presidential Decree No. 177 and later codified into law, designates the Presidency as the primary regulatory body for the cybersecurity sector. Its mandate includes setting standards, acting as a certification agency for cybersecurity services, and identifying critical infrastructure sectors that require special protection under the new framework. The law also tasks the Presidency with developing and implementing national cybersecurity plans, aiming to enhance Turkey's digital security infrastructure and manage responses to cyberattacks.

A key amendment, further reinforced by Law No. 7590 adopted in July 2026, transfers the authority to determine strategies, formulate policies, and regulate internet domain names directly to the Presidency. This responsibility previously belonged to the Information and Communication Technologies Authority (ICTA), whose relevant assets, infrastructure, and duties are being transferred to the Presidency over a three-month period. The Presidency also gains the power to issue regulations for cybersecurity-related products and services used in public entities and critical infrastructure, and to collect and store data from information systems after cyber incidents, sharing it with prosecutors if criminal activity is suspected.

Beyond its regulatory functions, the law grants the Presidency broad enforcement powers, including the ability to order measures upon request from security or intelligence agencies, or on its own initiative. Telecommunications operators, access providers, data centers, content providers, and hosting providers are required to implement these decisions within two hours. These decisions must be submitted to a criminal judgeship of peace for approval within 24 hours and will lapse if no decision is made within 48 hours. The Presidency can also impose administrative fines ranging from TRY 20,000 to TRY 100,000 for violations. Furthermore, the law introduces severe criminal sanctions for cyberattacks on national force elements, with penalties of eight to 12 years in prison for committing such attacks and 10 to 15 years for selling or spreading related data. Knowingly distributing misleading information about data breaches to cause public panic carries a penalty of three to five years imprisonment.

On December 25, 2025, Presidential Decree No. 192 further expanded the Cyber Security Presidency's duties beyond traditional cybersecurity. These new responsibilities include establishing the legal and institutional framework for the digital state and regulating artificial intelligence use in the public sector. This expansion underscores a comprehensive approach to digital policy, integrating cybersecurity with broader digital transformation goals. The Cybersecurity Council, composed of officials from various government agencies, will continue to play a role in identifying critical infrastructure and coordinating cybersecurity policies, helping to resolve conflicts between public entities and the Presidency.