Skip to main content

> cbddo_bi̇g_rehberi_v2026

CBDDO BİG Rehberi v2026

Information and Communication Security Guide (CBDDO Guide v2026)

SPEC // INSPECT: CBDDO BİG Rehberi v2026REVIEWED: 2026-09-16
CATEGORYInformation Security (ISMS)
JURISDICTIONTURKIYE
REGULATORY AUTHORITYT.C. Cumhurbaşkanlığı Dijital Dönüşüm Ofisi (CBDDO)
LIFECYCLE STATUSCURRENT
EXECUTIVE BRIEF SPECIFICATION PDFDISTRIBUTION LOCKED
Fail-Closed Distribution Policy: Download control is visibly disabled until Cloudflare R2 CDN upload and remote SHA-256 verification complete.
[AI // ARCHITECTURAL SUMMARY]

The Information and Communication Security Guide (issued by the Presidency Digital Transformation Office) is the statutory national cybersecurity mandate across Türkiye's public sector and critical infrastructure (energy, transport, health, banking). It classifies information assets into security levels (Grade 1, 2, 3), enforces domestic data sovereignty, mandates on-premise or sovereign cloud hosting, and establishes 200+ prescriptive technical security controls across 21 domain areas.

Scope & Applicability

All Turkish public agencies, state-owned enterprises, municipal entities, and private critical infrastructure operators in energy, banking, water, and telecom.

Non-Coverage Boundaries

Does not cover military operational tactical networks governed directly by the Ministry of National Defense (MSB/TSK).

Key Clauses & Control Requirements

cbddo-varlik-derecelendirme

Asset Grading & Criticality (Varlık Derecelendirme)

Evaluating data, applications, and hardware across Confidentiality, Integrity, and Availability to assign Security Degree 1, 2, or 3.

cbddo-veri-egemenligi

Data Sovereignty & Domestic Cloud (Veri Egemenliği)

Mandatory requirement that critical public and infrastructure data, telemetry, and institutional emails be stored strictly within sovereign borders.

cbddo-denetim-rehberi

Mandatory External Audit (CBDDO Denetim Rehberi)

Auditing compliance across 21 technical security control domains using authorized independent audit firms and reporting findings to the Presidency.

[AUDIT // VERIFIABLE EVIDENCE CHECKLIST]

Required Regulatory & Audit Evidence Artifacts

  • [✓]Institutional Asset Inventory and Asset Grading Matrix (Derecelendirme Tablosu)
  • [✓]CBDDO Gap Analysis and Compliance Action Plan submitted to the Presidency
  • [✓]Independent Audit Firm (Denetim Firması) Inspection Report and remediation records
[LEADERSHIP TAKEAWAY // CTO & VP OF ENGINEERING DIRECTIVE]
The CBDDO Guide is Türkiye's sovereign cybersecurity law in execution. For critical infrastructure operators, passing the annual CBDDO audit is an essential license to operate.
PRIMARY SOURCES & AUTHORITY

Frequently Asked Questions

Can an institution host Grade 3 critical data on foreign public clouds?

No. The CBDDO Guide strictly mandates that Grade 2 and Grade 3 critical data, public institution email systems, and operational telemetry reside within sovereign Turkish borders.