The wave after KVKK: why DORA and NIS2 concern Turkish companies
2026-07-10 · 8 min read
"We are in Türkiye, DORA doesn't bind us." We have heard this sentence many times over the past year. Technically true, practically wrong. EU regulations may stop at the border legally, but contracts do not.
DORA: finance's operational resilience exam
The Digital Operational Resilience Act regulates the digital resilience of institutions operating in the EU financial sector and of their critical IT suppliers. The key word is supplier: a Turkish company providing software, hosting, data or operations services to an EU bank finds that bank's DORA obligations flowing down to it by contract. Threat-led penetration testing (TLPT), incident notification deadlines and third-party risk registers now travel inside tender documents.
NIS2: scope far beyond "critical infrastructure"
NIS2 moved past energy and transport to cover food, manufacturing, digital services and public administration. For medium and large companies operating in or serving the EU it brings board-level accountability, early-warning notification within 24 hours, and supply chain security obligations. This is why the security questionnaires Turkish exporters receive from EU customers keep getting thicker.
No slowdown on the KVKK side either
Meanwhile Turkish data protection law continues converging with GDPR practice; expectations around breach notification and cross-border transfer keep rising. What Turkish companies face in the near term is not a single regulation but an intersection set of similar obligations.
A practical roadmap
The common denominator of all three regimes demands the same core capabilities:
- Asset and supplier inventory. No compliance work can start without knowing what you run, where, and with whom.
- An exercised incident response process. 24 or 72-hour notification windows require a plan that works in drills, not on paper.
- Evidence-based security testing. DORA's TLPT is institutionalized Red Teaming at its core; NIS2's security testing expectation maps to regular penetration testing.
- Board-level reporting. All three frameworks tie accountability to executive management; reporting security in management language is now mandatory.
If you don't know where to start, the five-minute Security Maturity Check shows which of these four areas is your weakest. For comprehensive support, see our ISO 27001 & Compliance advisory.