Turkmenportal logo
Today 11:56
27952795
Share on social networktelegram iconOk iconVk iconTwitter (X) icon
The Ministry of Communications of Turkmenistan has updated the technical requirements for websites

On July 23, 2026, the Ministry of Communications of Turkmenistan issued Order No. 116-iş, introducing amendments and additions to the unified technical requirements for the creation and launch of websites, which had been approved in 2021. The document was registered by the Ministry of Justice of Turkmenistan on September 1, 2026, under registration number 1966.

As noted in the order, the amendments were adopted to improve existing requirements in accordance with the laws of Turkmenistan "On Legal Acts" and "On Cybersecurity."

A section defining the terms used has been added to the requirements, along with a new provision requiring websites to include a dedicated service for the automated dissemination of updated information.

The list of website security requirements has been expanded to now include the timely updating of server software and libraries, the regular application of security patches, the closing of unused server ports, restricted access to administrative configuration files, the use of network traffic filtering and additional protection against common cyberattacks, the discontinuation of outdated data transmission protocols in favor of modern secure versions, and the configuration of additional security headers alongside the masking of server software version details.

Requirements for website data backups have been clarified: backups must now be performed according to an established standard, and copies must be stored in encrypted form with restricted access. The requirement to obtain secure connection certificates from trusted organizations has also been specified in greater detail.

A new provision has been added to the requirements regarding the protection of the administrative sections of websites. It mandates the logging of all login attempts and administrative actions, the use of two-factor authentication for accessing the control panel, temporary account lockout following multiple failed login attempts, the use of secure remote connection methods, access restrictions based on network address and location, and the modification of the default login page URL for the control panel.

In addition, detailed requirements have been established regarding the use of temporary access keys for user authentication on websites—specifically concerning their validity periods, renewal procedures, storage, and revocation upon logout or in the event of an incident, as well as the maintenance of logs recording operations involving such keys.

Control over the execution of the order is entrusted to the Deputy Minister of Communications of Turkmenistan Y. Gulmamedov and the head of the State Cyber Security Service under the Ministry of Communications of Turkmenistan.

The full text of the changes can be found on the official website of the Ministry of Adalat of Turkmenistan.