TİTCK
Turkey - TİTCK
Medical Devices Regulation (mirrors EU MDR) + KVKK overlay
Authority
Turkish Medicines and Medical Devices Agency
Enforced
Jun 2021
Legal framework
TİTCK MDR Regulation + KVKK + ÜTS device tracking system
Scope
All medical devices marketed in Türkiye; rules mirror EU MDR with national overlays.
Pre-market
EU MDR-equivalent technical documentation, ÜTS registration, Notified Body conformity assessment for higher classes.
Post-market
Vigilance via TÜFAM; ÜTS UDI tracking; KVKK breach notifications.
SBOM
RecommendedMirrors EU expectations; will follow CRA timeline through equivalence.
Vulnerability disclosure
USOM (National Cyber Incident Response Center) coordination encouraged.
Penalty
Market removal; KVKK fines; criminal liability under cybercrime statutes.
Unique requirements
- 01Turkish Authorised Representative
- 02Turkish-language IFU and labelling
- 03ÜTS UDI registration
Highlights
- De-facto EU MDR equivalence
- ÜTS national device tracking mandatory
- KVKK aligns closely with GDPR
Aligns with
Timeline
-
Jun 2021
MDR regulation enters force
-
2024
ÜTS tightening for software devices
Key documents
How to submit in Turkey
Playbook reviewed · 2026-07-16
Submission route
TITCK registration via ÜTS portal with cybersecurity for connected devices
Turkey aligns with EU MDR content requirements. Cybersecurity is reviewed as part of the technical file for connected devices.
Authority portalStep-by-step
-
Step 01
Appoint local representation
Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
-
Step 02
Reuse FDA or CE package as baseline
Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
-
Step 03
Translate and localise
Local-language technical summary and labeling are usually mandatory; certified translation is safest.
-
Step 04
Submit + track queries
Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
Evidence checklist
| Item | Level | FDA equivalent | Notes |
|---|---|---|---|
| Cybersecurity documentation (baseline FDA or CE) | Required | SPDF | |
| Local authorised representative agreement | Required | — | |
| Local-language labeling and IFU | Required | — | |
| SBOM | Recommended | — | Not mandatory but reduces clarification rounds. |
Common TİTCK rejections
UTS listing not completed
CommonFix · Ensure UDI and UTS registration are complete before market placement.
Typical timeline
End-to-end window: 3-6 months post-CE
Phase 01
Local rep + dossier prep
2-4 months
Phase 02
Regulatory review
3-6 months post-CE
Phase 03
Approval + market entry
1-3 months
Related markets
Frequently asked about Turkey
Is SBOM required for medical devices in Turkey?
Recommended. Mirrors EU expectations; will follow CRA timeline through equivalence.
What does TİTCK require for pre-market cybersecurity?
EU MDR-equivalent technical documentation, ÜTS registration, Notified Body conformity assessment for higher classes.
What are the post-market cybersecurity obligations under TİTCK?
Vigilance via TÜFAM; ÜTS UDI tracking; KVKK breach notifications.
What is the penalty for non-compliance with TİTCK cybersecurity rules?
Market removal; KVKK fines; criminal liability under cybercrime statutes.
How much of my FDA cybersecurity package is reusable in Turkey?
Roughly 55% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).