Qualified Electronic Certificate (NES) and Law No. 5070
A qualified electronic certificate (NES) enables secure electronic signatures that carry the same legal effect as handwritten ones under Law No. 5070.
Stands for: Qualified Electronic Certificate (Nitelikli Elektronik Sertifika)
Electronic Signature Law No. 5070 entered into force in Türkiye in 2004 and set out the legal and technical framework for electronic signatures. Under the law, a secure electronic signature is uniquely linked to the signatory and created with a secure signature creation device under the signatory's sole control. It identifies the signatory on the basis of a qualified electronic certificate and makes any later change to the signed data detectable. A secure electronic signature has the same legal effect as a handwritten signature.
The law contains an important exception. Legal transactions that statutes subject to an official form or special ceremony (for example the sale of real estate, which must be executed at the land registry) and guarantee agreements cannot be concluded with a secure electronic signature. Beyond these, most contracts, petitions, internal approvals and official applications can be signed with an NES.
A qualified electronic certificate contains the signatory's identity details (name and Turkish ID number), public key, validity period and serial number. Certificates are issued by electronic certificate service providers (ESHS) authorised and supervised by BTK, after the applicant's identity has been reliably verified. The private signing key is kept on a secure device and cannot be exported. That device can be a smart card, a USB token, a dedicated SIM card for mobile signature or, where supported, the chip-based Turkish ID card (TCKK). An NES belongs to a natural person. The financial seal (mali mühür) that legal entities use for processes such as e-invoicing is a separate certificate type.
NES is widely used for e-Government services, the UYAP judicial network, public procurement, registered electronic mail (KEP), HR and contract workflows. Depending on the use case, signatures are produced in CAdES, XAdES or, for PDF documents, PAdES format. Validation checks that the certificate was valid and unrevoked at signing time. Adding a trusted timestamp is recommended for documents that must remain verifiable for years. In practice, certificate expiry dates should be tracked, and users should know that a PIN can be blocked after several wrong attempts.
Have a project in mind?
Tell us briefly what you want to set up, or give us a call. We'll pass it to the right team.