---
title: "Turkey TİTCK - Cybersecurity Submission Playbook"
description: "How to submit a medical device to TİTCK in Turkey: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FDA &amp;"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Turkey - Medical Devices Regulation (mirrors EU MDR) + KVKK overlay",
      "description": "How to submit a medical device to TİTCK in Turkey: step-by-step route, evidence checklist, common rejections, and typical review timeline. Compared with FDA &",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "2024",
      "about": "Turkish Medicines and Medical Devices Agency",
      "dateModified": "2026-07-16",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/standards/tr"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is SBOM required for medical devices in Turkey?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Recommended. Mirrors EU expectations; will follow CRA timeline through equivalence."
          }
        },
        {
          "@type": "Question",
          "name": "What does TİTCK require for pre-market cybersecurity?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "EU MDR-equivalent technical documentation, ÜTS registration, Notified Body conformity assessment for higher classes."
          }
        },
        {
          "@type": "Question",
          "name": "What are the post-market cybersecurity obligations under TİTCK?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Vigilance via TÜFAM; ÜTS UDI tracking; KVKK breach notifications."
          }
        },
        {
          "@type": "Question",
          "name": "What is the penalty for non-compliance with TİTCK cybersecurity rules?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Market removal; KVKK fines; criminal liability under cybercrime statutes."
          }
        },
        {
          "@type": "Question",
          "name": "How much of my FDA cybersecurity package is reusable in Turkey?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Roughly 55% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report)."
          }
        },
        {
          "@type": "Question",
          "name": "Why do TİTCK submissions get rejected for \"uts listing not completed\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Ensure UDI and UTS registration are complete before market placement."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "How to submit a medical device to TİTCK",
      "description": "Turkey aligns with EU MDR content requirements. Cybersecurity is reviewed as part of the technical file for connected devices.",
      "totalTime": "3-6 months post-CE",
      "step": [
        {
          "@type": "HowToStep",
          "position": 1,
          "name": "Appoint local representation",
          "text": "Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission."
        },
        {
          "@type": "HowToStep",
          "position": 2,
          "name": "Reuse FDA or CE package as baseline",
          "text": "Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions."
        },
        {
          "@type": "HowToStep",
          "position": 3,
          "name": "Translate and localise",
          "text": "Local-language technical summary and labeling are usually mandatory; certified translation is safest."
        },
        {
          "@type": "HowToStep",
          "position": 4,
          "name": "Submit + track queries",
          "text": "Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock."
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Standards"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Turkey"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Standards 
3.  Turkey 

TİTCK

# ![Flag of Turkey](/flags/tr.svg)Turkey - TİTCK 

Mandatory Last updated · 2024 Verified · 2026-07-16 

Medical Devices Regulation (mirrors EU MDR) + KVKK overlay

Share Copy link X LinkedIn Email

Sources verified · 2026-07-16

TİTCK device rules + KVKK confirmed; standalone cyber instrument awaiting SME review.

Authority

Turkish Medicines and Medical Devices Agency

Enforced

Jun 2021

Legal framework

TİTCK MDR Regulation + KVKK + ÜTS device tracking system

FDA package reuse

~55%

[Editorial estimate · how →](/methodology#fda-reuse)

## Scope

All medical devices marketed in Türkiye; rules mirror EU MDR with national overlays.

Pre-market

EU MDR-equivalent technical documentation, ÜTS registration, Notified Body conformity assessment for higher classes.

Post-market

Vigilance via TÜFAM; ÜTS UDI tracking; KVKK breach notifications.

SBOM

Recommended 

Mirrors EU expectations; will follow CRA timeline through equivalence.

Vulnerability disclosure

USOM (National Cyber Incident Response Center) coordination encouraged.

Penalty

Market removal; KVKK fines; criminal liability under cybercrime statutes.

## Unique requirements

-   01 Turkish Authorised Representative 
-   02 Turkish-language IFU and labelling 
-   03 ÜTS UDI registration 

## Highlights

-   De-facto EU MDR equivalence 
-   ÜTS national device tracking mandatory 
-   KVKK aligns closely with GDPR 

## Aligns with

EU MDR  IEC 81001-5-1  ISO 14971 

## Timeline

1.  Jun 2021
    
    MDR regulation enters force
    
2.  2024
    
    ÜTS tightening for software devices
    

## Key documents

[

TİTCK Medical Devices

https://www.titck.gov.tr/



](https://www.titck.gov.tr/)[

ÜTS, Product Tracking System

https://utsuygulama.saglik.gov.tr/



](https://utsuygulama.saglik.gov.tr/)

## How to submit in Turkey

Playbook reviewed · 2026-07-16

Submission route

TITCK registration via ÜTS portal with cybersecurity for connected devices

Turkey aligns with EU MDR content requirements. Cybersecurity is reviewed as part of the technical file for connected devices.

[Authority portal](https://titck.gov.tr/)

### Step-by-step

1.  Step 01
    
    Appoint local representation
    
    Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
    
2.  Step 02
    
    Reuse FDA or CE package as baseline
    
    Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
    
3.  Step 03
    
    Translate and localise
    
    Local-language technical summary and labeling are usually mandatory; certified translation is safest.
    
4.  Step 04
    
    Submit + track queries
    
    Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
    

### Evidence checklist

Item

Level

FDA equivalent

Notes

Cybersecurity documentation (baseline FDA or CE)

Required 

SPDF

Local authorised representative agreement

Required 

—

Local-language labeling and IFU

Required 

—

SBOM

Recommended 

—

Not mandatory but reduces clarification rounds.

### Common TİTCK rejections

UTS listing not completed

Common 

Fix ·  Ensure UDI and UTS registration are complete before market placement.

### Typical timeline

End-to-end window: 3-6 months post-CE 

Phase 01

Local rep + dossier prep

2-4 months

Phase 02

Regulatory review

3-6 months post-CE

Phase 03

Approval + market entry

1-3 months

[Previous ![Flag of New Zealand](/flags/nz.svg)New Zealand ](/standards/nz)[Next  ![Flag of Norway](/flags/no.svg)Norway ](/standards/no)

## Related markets

[![Flag of Switzerland](/flags/ch.svg)

Switzerland

~55% FDA reuse

](/standards/ch)[![Flag of European Union](/flags/eu.svg)

European Union

~60% FDA reuse

](/standards/eu)[![Flag of Brazil](/flags/br.svg)

Brazil

~60% FDA reuse

](/standards/br)[![Flag of Norway](/flags/no.svg)

Norway

~60% FDA reuse

](/standards/no)

## Frequently asked about Turkey

### Is SBOM required for medical devices in Turkey?

Recommended. Mirrors EU expectations; will follow CRA timeline through equivalence.

### What does TİTCK require for pre-market cybersecurity?

EU MDR-equivalent technical documentation, ÜTS registration, Notified Body conformity assessment for higher classes.

### What are the post-market cybersecurity obligations under TİTCK?

Vigilance via TÜFAM; ÜTS UDI tracking; KVKK breach notifications.

### What is the penalty for non-compliance with TİTCK cybersecurity rules?

Market removal; KVKK fines; criminal liability under cybercrime statutes.

### How much of my FDA cybersecurity package is reusable in Turkey?

Roughly 55% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).

Sponsored note · Blue Goat Cyber

Submitting to TİTCK? Get a second pair of eyes before you file. Blue Goat Cyber has packaged cybersecurity evidence for Turkey alongside 37 other markets. We'll tell you what to keep, what to rework, and what's missing, in 30 minutes.  [Talk through your TİTCK submission](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.