Cybersecurity Law, Reporting and Cooperation Duties
Law No. 7545 (12 March 2025), Art. 7
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 19 March 2025.
A vulnerability and incident reporting rule binding public and private bodies.
As of 14 September 2026.
What it requires
- This binds any entity that uses information systems to provide services, collect data, or process data within the Cybersecurity Law's own broad scope, with no revenue or user threshold gating this particular duty; a separate, narrower certification and export-approval duty binds only cybersecurity product and service vendors and is not raised here.
- Report a detected vulnerability or cyber incident in the area of service provided to the Cybersecurity Directorate without delay; the Law's own text sets no numeric reporting clock.
- Provide the Cybersecurity Directorate promptly with any data, information, document, hardware, software, or other contribution it requests in connection with its duties.
- Where cybersecurity products, systems, or services are procured for use in a public institution or in critical infrastructure, source them only from a provider the Directorate has certified or authorized.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Article 16(10) enforces the Article 7(1)(a)-(c) duties raised here only by administrative fine. Elsewhere in the same Law, obstructing an authorized inspector's information request is punished by one to three years' imprisonment plus a judicial fine (Art. 16(1)), and a public official or a person who abuses a position of trust in connection with certain other offenses in the Law faces increased penalties; those provisions bind different conduct than the reporting, cooperation, and procurement duties described in this row.
Penalty structure
Art. 16(10) sets an administrative fine of 1,000,000 to 10,000,000 Turkish lira for failing the Art. 7(1)(a), (b), or (c) duties described in this row (cooperation, incident/vulnerability reporting, and certified-vendor procurement). The same subsection sets a separate, higher tier of 10,000,000 to 100,000,000 Turkish lira for failing the Art. 18 cybersecurity-product export and company-certification duties, which are not this row's duty and are not flagged on any declared activity.
- Rule
- Fixed only
- As of
- 14 September 2026
- Currency
- TRY
- Fixed cap
- 10,000,000
Who enforces it
Enforcement body
Siber Güvenlik Başkanlığı (Cybersecurity Directorate), established under the Presidency by this Law
Settledness
- As of
- 14 September 2026
- Open questions
- Have the implementing regulations this Law directs the Presidency to issue within one year of publication (due by 19 March 2026) been issued, and do they set a numeric clock for the Art. 7(1)(b) vulnerability/incident reporting duty?
- Law No. 7590 (24 July 2026) added a new transitional article continuing the transfer of national cybersecurity functions and assets from the Information and Communications Technologies Authority (BTK) and the Telecommunications Communication Presidency to the Cybersecurity Directorate: has any amendment of this kind also changed Article 7's substantive duties?
What it reaches
Obligation class
Security, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 7(1) of Turkey's Cybersecurity Law binds any entity that uses information systems to provide services or to collect and process data within the Law's scope. It must report a detected vulnerability or cyber incident to the Cybersecurity Directorate without delay. It must also supply the Directorate with any data or documentation the Directorate requests.
Where it serves public institutions or critical infrastructure, it must source cybersecurity products only from Directorate-certified providers. Failing the reporting, cooperation, or procurement duties in items (a) through (c) carries an administrative fine of 1,000,000 to 10,000,000 Turkish lira under Article 16(10); the Law's own text sets no numeric clock for the reporting duty itself.
A related item (ç) requires a certified cybersecurity company to obtain the Directorate's approval before beginning operations, a licensing duty that binds the narrower class of cybersecurity-product and service vendors rather than a general software or app developer, and is not itself covered by the Article 16(10) fine named above.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
official statute text, mevzuat.gov.tr consolidated legislation portal
Turkish only, no official English translation was located