Turkey Cybersecurity Law (Law No. 7545)
Duties of organisations: cooperation, security measures, reporting, procurement, certification, cyber maturity, asset inventory and audit – Turkey Cybersecurity Law (Law No. 7545)

Turkey Cybersecurity Law (Law No. 7545) 7.1.a: Article 7(1)(a): supply the Presidency with the data, information, documents, hardware and software it requests, with priority and on time

Everyone within the Law's scope that provides services, collects or processes data or carries out similar activities using information systems must deliver to the Cybersecurity Presidency, as a priority and on time, any data, information, document, hardware, software or other contribution the Presidency requests within its tasks and activities. Under Article 6(1)(ç) the Presidency may obtain information, documents, data and records limited to its activities, use archives, data processing centres and communication infrastructure, keeps what it obtains for at most two years and then destroys it, and those asked may not refuse by relying on provisions of their own legislation. Failing this duty carries an administrative fine of 1 million to 10 million Turkish lira (Article 16(10), which Law No. 7590 extended to point (a) from 31 July 2026); refusing or obstructing information, documents, software, data or hardware demanded by the authorised bodies or auditors is also a crime punishable by one to three years' imprisonment and 500 to 1,500 days' judicial fine for anyone other than public institutions (Article 16(1)).

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27001:2022 · 1 control

  • 5.5 Contact with authorities

NIS2 Directive · 1 control

  • Art.32 Cooperate with supervision: inspections, security audits, scans and requests for information and evidence

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Duties of organisations: cooperation, security measures, reporting, procurement, certification, cyber maturity, asset inventory and audit – Turkey Cybersecurity Law (Law No. 7545)

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.