The Crosswalk

    NewPer-page social previews and this changelog

    TİTCK

    Flag of TurkeyTurkey - TİTCK

    MandatoryLast updated · 2024Verified · 2026-07-16

    Medical Devices Regulation (mirrors EU MDR) + KVKK overlay

    Share

    Authority

    Turkish Medicines and Medical Devices Agency

    Enforced

    Jun 2021

    Legal framework

    TİTCK MDR Regulation + KVKK + ÜTS device tracking system

    FDA package reuse

    ~55%

    Scope

    All medical devices marketed in Türkiye; rules mirror EU MDR with national overlays.

    Pre-market

    EU MDR-equivalent technical documentation, ÜTS registration, Notified Body conformity assessment for higher classes.

    Post-market

    Vigilance via TÜFAM; ÜTS UDI tracking; KVKK breach notifications.

    SBOM

    Recommended

    Mirrors EU expectations; will follow CRA timeline through equivalence.

    Vulnerability disclosure

    USOM (National Cyber Incident Response Center) coordination encouraged.

    Penalty

    Market removal; KVKK fines; criminal liability under cybercrime statutes.

    Unique requirements

    • 01Turkish Authorised Representative
    • 02Turkish-language IFU and labelling
    • 03ÜTS UDI registration

    Highlights

    • De-facto EU MDR equivalence
    • ÜTS national device tracking mandatory
    • KVKK aligns closely with GDPR

    Aligns with

    EU MDR IEC 81001-5-1 ISO 14971

    Timeline

    1. Jun 2021

      MDR regulation enters force

    2. 2024

      ÜTS tightening for software devices

    Key documents

    How to submit in Turkey

    Playbook reviewed · 2026-07-16

    Submission route

    TITCK registration via ÜTS portal with cybersecurity for connected devices

    Turkey aligns with EU MDR content requirements. Cybersecurity is reviewed as part of the technical file for connected devices.

    Authority portal

    Step-by-step

    1. Step 01

      Appoint local representation

      Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.

    2. Step 02

      Reuse FDA or CE package as baseline

      Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.

    3. Step 03

      Translate and localise

      Local-language technical summary and labeling are usually mandatory; certified translation is safest.

    4. Step 04

      Submit + track queries

      Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.

    Evidence checklist

    Item Level FDA equivalent Notes
    Cybersecurity documentation (baseline FDA or CE) Required SPDF
    Local authorised representative agreement Required
    Local-language labeling and IFU Required
    SBOM Recommended Not mandatory but reduces clarification rounds.

    Common TİTCK rejections

    UTS listing not completed

    Common

    Fix · Ensure UDI and UTS registration are complete before market placement.

    Typical timeline

    End-to-end window: 3-6 months post-CE

    Phase 01

    Local rep + dossier prep

    2-4 months

    Phase 02

    Regulatory review

    3-6 months post-CE

    Phase 03

    Approval + market entry

    1-3 months

    Related markets

    Frequently asked about Turkey

    Is SBOM required for medical devices in Turkey?

    Recommended. Mirrors EU expectations; will follow CRA timeline through equivalence.

    What does TİTCK require for pre-market cybersecurity?

    EU MDR-equivalent technical documentation, ÜTS registration, Notified Body conformity assessment for higher classes.

    What are the post-market cybersecurity obligations under TİTCK?

    Vigilance via TÜFAM; ÜTS UDI tracking; KVKK breach notifications.

    What is the penalty for non-compliance with TİTCK cybersecurity rules?

    Market removal; KVKK fines; criminal liability under cybercrime statutes.

    How much of my FDA cybersecurity package is reusable in Turkey?

    Roughly 55% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).