Skip to main content

> epdk_siber_güvenlik_modeli:2024

EPDK Siber Güvenlik Modeli:2024

EMRA Cybersecurity Competency Model for the Energy Sector

SPEC // INSPECT: EPDK Siber Güvenlik Modeli:2024REVIEWED: 2026-09-16
CATEGORYIndustrial & OT Cybersecurity
JURISDICTIONTURKIYE
REGULATORY AUTHORITYEnerji Piyasası Düzenleme Kurumu (EPDK)
LIFECYCLE STATUSCURRENT
EXECUTIVE BRIEF SPECIFICATION PDFDISTRIBUTION LOCKED
Fail-Closed Distribution Policy: Download control is visibly disabled until Cloudflare R2 CDN upload and remote SHA-256 verification complete.
[AI // ARCHITECTURAL SUMMARY]

The EMRA (EPDK) Cybersecurity Competency Model establishes a mandatory, audited cybersecurity framework for energy utilities across Türkiye. Mandating compliance with international standards (IEC 62443, ISO/IEC 27019, NIST CSF), it classifies critical industrial control infrastructure, enforces Purdue model segmentation between SCADA and corporate IT, mandates multi-factor authentication for maintenance jumpboxes, and requires annual third-party penetration testing.

Scope & Applicability

Licensed electricity generation, transmission, and distribution companies, natural gas network operators, petroleum pipeline managers, and critical power market participants in Türkiye.

Non-Coverage Boundaries

Does not replace statutory consumer billing regulations or physical security guards; it focuses strictly on IT, OT, SCADA, telecontrol, and AMR cybersecurity resilience.

Key Clauses & Control Requirements

epdk-seviye-belirleme

Utility Categorization & Target Maturity Tier (Seviye Belirleme)

Categorizing energy assets into Level 1, 2, or 3 based on megawatt capacity and customer count, establishing minimum mandatory technical security controls.

epdk-it-ot-ayrimi

Purdue IT/OT Network Segmentation (Ağ İzolasyonu)

Strict prohibition of direct routing between corporate enterprise networks and SCADA/DCS networks; mandatory Industrial DMZ with jumpbox MFA.

epdk-denetim-ve-sızma

Independent Third-Party Auditing (TSE Onaylı Denetim)

Mandatory annual independent penetration testing and gap assessment conducted by certified firms, with results submitted directly to EMRA.

[AUDIT // VERIFIABLE EVIDENCE CHECKLIST]

Required Regulatory & Audit Evidence Artifacts

  • [✓]EPDK Target Maturity Self-Assessment and Gap Analysis Report
  • [✓]Network Architecture Diagram showing physical/logical separation between OT and Corporate IT
  • [✓]Annual TSE-Certified Penetration Testing Report with remediation evidence
  • [✓]SCADA remote access jumpbox MFA authentication logs and session recordings
[LEADERSHIP TAKEAWAY // CTO & VP OF ENGINEERING DIRECTIVE]
In energy utilities, an unsegmented PLC connected to an office PC is not just an IT risk; it is an immediate regulatory violation under EPDK that risks statutory operating license suspension.
PRIMARY SOURCES & AUTHORITY

Frequently Asked Questions

Does the EPDK model apply to privately owned solar or wind plants?

Yes, all licensed grid-connected generation facilities exceeding statutory MW thresholds must implement the model based on their assigned tier.