Cybersecurity: Türkiye pays for the certifications that win deals
Cybersecurity is named in the eligibility article. Certifications, the thing that gates every enterprise sale, are covered at 50%, and so is the sales team you hire to close them.
Most guidance on Türkiye's IT export incentives is written for companies that sell to consumers, where the big number is advertising spend and the game is user acquisition. A cybersecurity company sells nothing that way. It sells through certifications, references, analyst coverage and a small expensive sales team.
The programme handles that. The items are the same, but the ones that matter are different, and two of them line up closely with how enterprise security software gets sold.
Eligibility is not in question. Article 5 of the implementing circular lists cybersecurity directly among the IT sub-sectors the Standard Programme supports, alongside blockchain, artificial intelligence, big data, smart city and other commercial software.
Certification, which gates every deal
Article 7 covers certificates, accreditations and the audits behind them, obtained for overseas markets, at 50% and up to 4,000,000 TL a year, about $84,000 at roughly 47.7 TRY to the dollar.
For most software companies this is a minor item. For a security company it is close to the centre of the business. Attestations are what get you onto a procurement shortlist, they have to be maintained rather than obtained once, and different markets and buyer types want different ones. A company selling into financial services in three countries can be carrying several concurrently, each with an annual renewal and an audit behind it.
Recovering half of that cost, every year, against spending that is a precondition of selling at all, is the closest thing in the programme to a direct subsidy on revenue.
The sales team
Article 19 covers the gross salary of staff hired for international promotion and marketing work: business development, sales and marketing roles.
- Up to five people in Türkiye, at 50% of gross salary and up to 90,000 TL of support per person per month, which is about $1,890 a month each
- Up to five more in an overseas office, at up to 250,000 TL per person per month, about $5,240
Both run for five years. Filled to the cap, the Türkiye-based five are worth around $113,000 a year and the overseas five around $314,000.
For a company whose go-to-market is people rather than media spend, this is the item that changes the economics. Enterprise security sales is expensive precisely because it needs experienced individuals working long cycles, and half of what you pay them comes back.
Two conditions shape how you use it. The people have to be employed in the company for the first time, and the first claim has to come within six months of them starting. So the item rewards hiring from here on rather than transferring an existing team across.
The rest of the stack
Hosting, at 50% up to 5,000,000 TL a year, covers the cloud and server costs of delivering the service to customers abroad. Where one account mixes customer-facing infrastructure with internal research environments, only the first part counts, so the split has to be evidenced rather than asserted.
Reports and database subscriptions, at 50% up to 2,500,000 TL a year, cover analyst research and the market intelligence a security company buys as a matter of course. Database memberships qualify where the provider is on the Ministry's approved list, and commissioned reports need approval before you pay for them.
International memberships, at 50% up to 2,500,000 TL a year, cover subscriptions to the industry bodies that carry weight with enterprise buyers.
Trade fairs and events, at 50% up to 1,500,000 TL per event and doubled for events the Ministry classes as prestigious, cover the conference circuit that this sector runs on. Stand construction, space, registration, freight and travel for two representatives are all inside the item.
Advertising, where you do it, works the same way it does for anyone else: 50% for overseas campaigns, rising to 70% in the Ministry's target countries.
What a year looks like
Take a company selling security software into Europe and North America, with fifteen people and a small commercial team:
- $150,000 on certifications, audits and renewals across three frameworks
- $340,000 on three commercial hires in Istanbul
- $120,000 on hosting for the customer-facing platform
- $95,000 on two industry conferences with stands
- $45,000 on analyst subscriptions and memberships
Certifications return $75,000. The three commercial hires return roughly $68,000, since the per-person monthly cap binds before half the salary does at senior levels. Hosting returns $60,000. The conferences return about $63,000 once the per-event cap is applied. Subscriptions and memberships return $22,500.
That is roughly $288,000 back on $750,000 of spending, against a cost base that was going to exist anyway.
The certification item in practice
Because this is the item that carries the most weight here, here is precisely how it behaves.
The cap is annual rather than lifetime, so it refreshes every January along with every other figure in the Decision, which are revalued each year in line with the official revaluation rate. A company carrying several frameworks with staggered renewal dates is therefore claiming against a fresh cap each year rather than exhausting a one-time allowance.
What the file needs is ordinary: the invoice from the certification body or auditor, payment from the company's own account, and the certificate or report itself showing what was obtained and for which markets. The last part is what connects the spending to overseas market entry, which is the condition the item turns on.
Where companies get this wrong is scope rather than evidence. An attestation obtained purely for a domestic requirement is not an overseas market entry cost. One obtained because buyers in Germany or the United States will not sign without it plainly is. Most security certifications sit clearly on the right side of that line, and the ones that do not are usually obvious.
Each payment then carries its own six-month filing window, so an audit paid for in March needs to be filed before September rather than waiting for a year-end exercise.
For companies that eventually pass the revenue threshold, the Branding Programme raises or removes several of these caps, including removing the fixed annual limit on certification entirely. That becomes relevant somewhere above $1.5 million a year in earnings from customers abroad.
Why the fit is good
The programme is built around the idea of a Turkish company selling software and services to organisations abroad, and it pays for the things that make that possible: getting certified for other markets, hiring people to sell into them, running the infrastructure customers use, and showing up where buyers are.
That is an unusually accurate description of how a cybersecurity business grows. The advertising items that dominate the arithmetic for a consumer app barely feature, and the items that do the work are ones a B2B company was going to spend on regardless.
The calculator covers each of the items above against your own numbers, and what changed in the 2026 framework sets out the rules the figures come from.
Frequently asked
Are SOC 2, ISO 27001 and similar certifications claimable?
Certificates, accreditations and the audits behind them, obtained for overseas markets, are supported at 50% up to 4 million TL a year. For a company whose sales cycle depends on holding the right attestations in the right jurisdictions, this is usually the item with the most direct connection to revenue.
We sell through enterprise sales rather than advertising. Is the programme still worth it?
The salary item is the one to look at. It reimburses half the gross pay of new business development, sales and marketing hires, which for a company selling seven-figure contracts through a small team is a large number attached to your main go-to-market cost.
Does penetration testing or research infrastructure count as hosting?
The hosting item covers server and cloud costs incurred to deliver your product to users abroad. Infrastructure that runs the service customers use fits that description. Internal research or lab environments are a different thing, so a mixed account is worth splitting in a way you can evidence.
What about industry memberships and analyst subscriptions?
Membership of international industry bodies is a separate item at 50%, and analyst research and database subscriptions fall under the reports and databases item, subject to the provider appearing on the Ministry's approved list. Both are modest but they cover spending most companies in this sector already have.
Do we need to sell to consumers for any of this?
No. The programme is about exporting software and services, and it makes no distinction between selling to enterprises and selling to consumers. The items simply weight differently, with certification and staff mattering more than advertising for a B2B company.
Sources
https://cyberscope.solutions/blog/incentives-for-cybersecurity-companies/ · Updated March 17, 2026 · CyberScope Solutions