> cbddo_bi̇g_rehberi_v2026
CBDDO BİG Rehberi v2026
Information and Communication Security Guide (CBDDO Guide v2026)
The Information and Communication Security Guide (issued by the Presidency Digital Transformation Office) is the statutory national cybersecurity mandate across Türkiye's public sector and critical infrastructure (energy, transport, health, banking). It classifies information assets into security levels (Grade 1, 2, 3), enforces domestic data sovereignty, mandates on-premise or sovereign cloud hosting, and establishes 200+ prescriptive technical security controls across 21 domain areas.
Scope & Applicability
All Turkish public agencies, state-owned enterprises, municipal entities, and private critical infrastructure operators in energy, banking, water, and telecom.
Non-Coverage Boundaries
Does not cover military operational tactical networks governed directly by the Ministry of National Defense (MSB/TSK).
Key Clauses & Control Requirements
Asset Grading & Criticality (Varlık Derecelendirme)
Evaluating data, applications, and hardware across Confidentiality, Integrity, and Availability to assign Security Degree 1, 2, or 3.
Data Sovereignty & Domestic Cloud (Veri Egemenliği)
Mandatory requirement that critical public and infrastructure data, telemetry, and institutional emails be stored strictly within sovereign borders.
Mandatory External Audit (CBDDO Denetim Rehberi)
Auditing compliance across 21 technical security control domains using authorized independent audit firms and reporting findings to the Presidency.
Required Regulatory & Audit Evidence Artifacts
- [✓]Institutional Asset Inventory and Asset Grading Matrix (Derecelendirme Tablosu)
- [✓]CBDDO Gap Analysis and Compliance Action Plan submitted to the Presidency
- [✓]Independent Audit Firm (Denetim Firması) Inspection Report and remediation records
“The CBDDO Guide is Türkiye's sovereign cybersecurity law in execution. For critical infrastructure operators, passing the annual CBDDO audit is an essential license to operate.”
Cross-Surface Ecosystem Relationships
- Cumhurbaşkanlığı Dijital Dönüşüm Ofisi Bilgi ve İletişim Güvenliği Rehberi ↗(T.C. Cumhurbaşkanlığı Dijital Dönüşüm Ofisi)
Frequently Asked Questions
Can an institution host Grade 3 critical data on foreign public clouds?
No. The CBDDO Guide strictly mandates that Grade 2 and Grade 3 critical data, public institution email systems, and operational telemetry reside within sovereign Turkish borders.
