Integration guides · 2026-08-13
Public IT and software authorization certificates: which document does an AI tender in Turkey require?
Which authorization certificate does a contractor need to bid on Turkish public IT procurements, which one is asked for in artificial intelligence software tenders, and how is the ISO 27001 prerequisite met? A source-verified guide for supplier firms.
Where does the public IT authorization requirement come from?
The authorization certificate requirement for firms bidding on Turkish public IT procurements was introduced by the Kamu Bilişim Hizmet Alımı Kapsamında Katılımcıların Yetkilendirilmesi Hakkında Yönetmelik (Regulation on the Authorization of Participants in Public IT Service Procurement), published in the Resmî Gazete (Official Gazette) of 29 June 2022, issue 31881. It was issued by the Sanayi ve Teknoloji Bakanlığı (Ministry of Industry and Technology) and rests on Article 385 of Presidential Decree No. 1 on the Presidential Organization. Its commencement article reads: "Bu Yönetmelik yayımı tarihinden 3 ay sonra yürürlüğe girer" — the regulation enters into force three months after publication. It therefore took effect on 29 September 2022 and applies as of 13 August 2026.
The scope is not limited to a narrow list of bodies. The regulation defines kamu idaresi (public administration) as all institutions and entities subject to Sayıştay (Turkish Court of Accounts) audit, which covers municipalities, ministries, universities, state economic enterprises and their subsidiaries. The definition of an IT service procurement covers service procurements, including consultancy services, under Law No. 4734 (Kamu İhale Kanunu, the Public Procurement Law) of 4 January 2002, as well as IT line items inside public-private partnership projects for goods, services, consultancy and works.
The obligation does not stop at the prime contractor. The regulation's definition of katılımcı (participant) expressly includes subcontractors who will perform part of the contracted work under a contract with the prime contractor and who request authorization. A firm building an AI module as a subcontractor may therefore need to hold its own certificate, depending on the nature of the work it takes on.
- Regulation: Kamu Bilişim Hizmet Alımı Kapsamında Katılımcıların Yetkilendirilmesi Hakkında Yönetmelik
- Official Gazette: 29 June 2022, issue 31881
- In force since 29 September 2022, three months after publication
- Issuing body: Sanayi ve Teknoloji Bakanlığı (Ministry of Industry and Technology)
- Certificate status is reported by the Ministry to the Kamu İhale Kurumu (Public Procurement Authority) under Article 7
Which authorization certificate does each type of work require?
The regulation defines three separate certificates and ties each to a different scope of work. Article 4 splits them as follows: a Kamu Bilişim Yetki Belgesi (Public IT Authorization Certificate) for participants carrying out public IT projects, a Yazılım Yetki Belgesi (Software Authorization Certificate) for software work, and a Sızma Testi Yetki Belgesi (Penetration Testing Authorization Certificate) for penetration testing services. The software provision reads verbatim: "Yazılım geliştirme, yazılım entegrasyon ve yazılım bakım hizmetlerini tedarik edecek katılımcılar için Yazılım Yetki Belgesi düzenlenir" — a Software Authorization Certificate is issued for participants supplying software development, software integration and software maintenance services.
The certificate follows the nature of the tendered work, not the firm's job title. One firm may need more than one certificate: a company that takes on both infrastructure setup and application software for an institution is performing two distinct types of work falling under two distinct certificates. The first step in bid preparation is therefore to map the scope of work in the administrative specification against the categories in Article 4.
The regulation contains no monetary threshold and no exemption clause. It consists of nine articles, and none of them is headed as an exception or exemption. In practice what determines the requirement is whether the contracting authority lists the certificate as a qualification criterion in the tender documents, so the qualification clauses of each administrative specification must be read individually.
| Type of work | Required authorization certificate | Prerequisite certificates |
|---|---|---|
| Carrying out a public IT project: IT system setup and maintenance, IT consultancy, IT security services | Kamu Bilişim Yetki Belgesi (Public IT Authorization Certificate) | TS EN ISO/IEC 27001 certificate covering at least one of the IT service procurement categories |
| Software development, software integration, software maintenance; developing or integrating AI software falls here | Yazılım Yetki Belgesi (Software Authorization Certificate) | TS EN ISO/IEC 27001 certificate covering those services, plus either TS ISO/IEC 15504 Level 2 or higher, or CMMI Level 3 or higher |
| Providing penetration testing services | Sızma Testi Yetki Belgesi (Penetration Testing Authorization Certificate) | TS EN ISO/IEC 27001 certificate covering penetration testing, plus a type A or B TSE penetration testing firm certificate |
| Taking on part of the work as a subcontractor | Whichever of the above matches the nature of the work | The same prerequisites; the regulation includes subcontractors requesting authorization in its definition of participant |
| Providing data centre services | No separate certificate exists under the regulation currently in force | A draft regulation released for public comment proposes a separate data centre certificate; that draft is not yet in force |
What does the ISO 27001 prerequisite mean in practice?
The TS EN ISO/IEC 27001 certificate is the shared prerequisite for all three authorization certificates, and a certificate from just any certification body will not do. The definitions article describes an accredited body as "Türk Akreditasyon Kurumu (TÜRKAK) tarafından akredite edilmiş test ve/veya belgelendirme kuruluşlarını" — testing and/or certification bodies accredited by TÜRKAK, the Turkish Accreditation Agency. The TS EN ISO/IEC 27001 certificate itself is defined as the information security management system certificate issued by bodies holding ISO/IEC 17021-1 accreditation. A certificate from a non-accredited body will not support an application.
The decisive detail in an ISO 27001 certificate is its scope. Article 5 requires that the ISO 27001 certificate submitted for a Software Authorization Certificate cover software development, software integration and software maintenance services. A certificate whose scope is written to cover only corporate IT operations may be technically valid yet still fail to support a software authorization application. The scope wording should be aligned with the regulation's service definitions before the certification contract is signed.
The regulation caps only the Ministry's assessment time, not the contractor's preparation time. Article 6 states: "Bakanlığa yapılan müracaatlar 5 inci maddede istenilen bilgi ve belgelerin eksiksiz olması halinde değerlendirilir ve en geç iki ay içerisinde sonuçlandırılır" — complete applications are assessed and concluded within two months at the latest. By contrast, the regulation says nothing about how long it takes to obtain ISO 27001 and CMMI or TS ISO/IEC 15504 certification; that depends on the certification body and the firm's existing maturity. Plan backwards from the tender date and treat the prerequisite certificates as the longest lead item.
Certificate validity is not expressed as a fixed number of years. The regulation sets the authorization certificate's term by reference to whichever of the supporting certificates listed in Article 5 expires first. If your ISO 27001 certificate expires before your CMMI certificate, your authorization certificate expires on the ISO 27001 date.
- The ISO 27001 certificate must come from a TÜRKAK-accredited body
- The certificate scope must cover the services named by the authorization certificate sought
- ISO 27001 alone is not enough for the Software Authorization Certificate; CMMI Level 3 or TS ISO/IEC 15504 Level 2 is also required
- The Ministry concludes complete applications within two months at the latest (Article 6)
- Authorization certificate validity tracks the earliest-expiring supporting certificate
- Current document requirements should be confirmed from the Ministry's latest announcements before applying
Which qualification certificate do AI tenders ask for?
A firm that develops or integrates artificial intelligence software falls within the regulation's software category. The regulation does not treat artificial intelligence as a separate service type; what matters is whether the work constitutes software development, software integration or software maintenance. Connecting a language model to an institution's application, writing the interface and workflow around it, and sustaining that under a maintenance contract all fall within those three activities. In practice, the certificate sought is therefore the Yazılım Yetki Belgesi.
This is not a theoretical inference; there is a verified tender example. The Başakşehir Municipality IT Department tender registered as İKN 2026/1455679, "Görev Takip ve Yapay Zeka Yazılımları Hizmet Alımı" (task tracking and artificial intelligence software services procurement), is scheduled for 2 September 2026, and its tender documents list the Yazılım Yetki Belgesi among the certificates to be submitted under applicable legislation. The same tender also requires evidence of similar work completed and accepted within the last five years.
The language used in tender documents rarely matches the contractor's technical vocabulary. Contracting authorities describe the work as "yapay zeka yazılımı hizmet alımı" (AI software service procurement) or as leasing AI software, while the contractor's side discusses the same work in terms of model APIs, token consumption and an integration layer. Carrying both vocabularies in the bid file matters for demonstrating that every clause of the technical specification is met.
A change to this framework is on the agenda. The draft Kamu Bilişim Hizmet Alımı Kapsamında Yetkilendirme Yönetmeliği (Regulation on Authorization in Public IT Service Procurement), released by the Ministry for public comment, would expand the current three-certificate structure to five, split the Software Authorization Certificate into Level 1 and Level 2, add the YTE Model maturity measure developed by TÜBİTAK, and create a separate data centre authorization certificate. This draft is not yet in force. If enacted, it provides that it would repeal the 2022 regulation and that certificates issued under the repealed text would remain usable for the remainder of their validity.
- AI software work is assessed under the regulation's software development and integration category
- Verified example: İKN 2026/1455679, Başakşehir Municipality, tender date 2 September 2026, Software Authorization Certificate required
- The draft regulation would require a data centre to be located within Turkey's borders; the draft is not yet in force
- As drafted, the new regulation would apply six months after its publication
- The certificate list must be read from the administrative specification of each individual tender
Why does the contractor's inherited data responsibility drive provider selection?
An authorization certificate opens the qualification gate but does not end the contractor's responsibility once the contract is signed. For the personal data it processes, the public institution is the veri sorumlusu (data controller) under Law No. 6698 (KVKK, the Turkish Personal Data Protection Law). To the extent the contractor processes personal data on the institution's behalf under its authority, the contractor is a veri işleyen (data processor); Article 3 of the law defines this as the natural or legal person who processes personal data on the controller's behalf under the authority granted by the controller.
That position carries the security obligation across to the contractor. Article 12(2) of the KVKK reads: "Veri sorumlusu, kişisel verilerin kendi adına başka bir gerçek veya tüzel kişi tarafından işlenmesi hâlinde, birinci fıkrada belirtilen tedbirlerin alınması hususunda bu kişilerle birlikte müştereken sorumludur" — where personal data is processed on the controller's behalf by another party, the controller is jointly responsible with that party for taking the measures set out in the first paragraph. Article 12(4) further provides that controllers and processors may not disclose personal data they learn contrary to the law or use it outside the processing purpose, and that this obligation continues after they leave their post.
On AI projects this chain reaches as far as the model provider the contractor selects. Where the institution's technical specification requires data to be processed inside Turkey, where the model layer in the contractor's solution architecture is hosted becomes a direct question of contract compliance. If personal data is transferred abroad, the cross-border transfer regime in Article 9 of the KVKK applies, and that assessment must be made together with the institution's legal and compliance units.
The practical consequence is that provider selection belongs in the bid phase, not after signature. If the technical specification contains clauses on data locality, logging, usage reporting or access segregation, the model layer chosen must already answer them architecturally. Otherwise the contractor faces an obligation at acceptance that it cannot meet.
- The institution is the data controller; the contractor is a data processor in most scenarios
- KVKK Article 12(2) creates joint responsibility for security measures
- The confidentiality obligation survives the end of the engagement (Article 12(4))
- If data is transferred abroad, the KVKK Article 9 transfer regime must be assessed separately
- Where the model provider hosts its models is part of technical specification compliance
What does LLMTR provide a contractor at the model layer?
LLMTR is a gateway platform that lets a contractor serving public institutions consolidate the model layer of its delivered solution behind a single OpenAI-compatible API. When different institutions call for different model choices, the firm changes the base URL and the model identifier rather than rewriting the integration. Models hosted in Turkey and models from global providers are called from the same catalogue, so an institution that requires data to be processed domestically and one that has no such constraint can be served from the same codebase.
Two features matter directly for reporting back to the institution. First, a separate API key can be created for each institution or business unit, each with its own rate limit, spending ceiling and usage report. Second, that separation lets the contractor present consumption per contract to the institution's acceptance committee in disaggregated form. Keys are stored as SHA-256 hashes and never in plain text; provider keys live only in environment variables.
On data handling the boundary is explicit: user prompts and model response bodies are not written to the usage and billing database. Commercially, an 8% platform margin applies to credit top-ups; no margin is added to model prices, where the provider's list price applies. That distinction keeps the cost line the contractor presents to the institution predictable.
One point deserves to be stated plainly: LLMTR is not a certification body and does not substitute for any authorization certificate. The Public IT, Software and Penetration Testing Authorization Certificates are issued to the participating firm, and obtaining them depends on that firm's own certification process. LLMTR is only a technical component of the model layer in the solution being delivered.
- One OpenAI-compatible /v1 surface; migration is a base URL and model identifier change
- Turkey-hosted and global models sit in the same catalogue
- A separate API key, rate limit, ceiling and usage report per institution or unit
- Prompts and model response bodies are not written to the usage and billing database
- An 8% platform margin applies to credit top-ups; no margin is added to model prices
- LLMTR does not substitute for an authorization certificate; certificates are issued to the participating firm
Per-institution keys and model selection through one integration
import os
from openai import OpenAI
# A separate key per institution keeps usage reports and ceilings separate.
client = OpenAI(
api_key=os.environ["LLMTR_API_KEY_INSTITUTION_A"],
base_url="https://llmtr.com/v1",
)
# Where the contract requires data locality, pick a Turkey-hosted model.
response = client.chat.completions.create(
model="llmtr/gemma-4",
messages=[
{"role": "system", "content": "Summarise internal correspondence."},
{"role": "user", "content": document_text},
],
)
print(response.choices[0].message.content)
Sources
The regulatory references in this article were verified against the primary sources listed below. Last checked: 13 August 2026.
This content is informational and does not constitute legal advice.
- Kamu Bilişim Hizmet Alımı Kapsamında Katılımcıların Yetkilendirilmesi Hakkında Yönetmelik, Official Gazette of 29 June 2022, issue 31881 — resmigazete.gov.tr
- Draft Kamu Bilişim Hizmet Alımı Kapsamında Yetkilendirme Yönetmeliği, text released for public comment, not yet in force — iso.org.tr
- Law No. 6698 (KVKK), Articles 3, 9 and 12 — mevzuat.gov.tr
- Law No. 4734 (Kamu İhale Kanunu, Public Procurement Law), referenced in the regulation's definition of IT service procurement — mevzuat.gov.tr
- Başakşehir Municipality tender notice, İKN 2026/1455679, tender date 2 September 2026 — milliyet.com.tr official notices
- Kamu Bilişim Alımları Firma Yetkilendirme Portalı, the application channel — kamubilisim.sanayi.gov.tr
Obtaining a Turkish public IT authorization certificate
Steps for a contractor to obtain the authorization certificate needed to bid on public IT service procurements. The total time shown is a planning horizon; the regulation caps only the Ministry's assessment at two months and does not regulate how long the prerequisite certificates take to obtain.
- Map the scope of work to a certificate type. Collect the scope-of-work definitions from the administrative specifications of the tenders you intend to bid on and map each one against the three categories in Article 4: public IT project, software development and integration, and penetration testing. If you fall into more than one category, you need more than one certificate.
- Get the ISO 27001 scope right. Work with a certification body accredited by TÜRKAK and have the scope statement written so that it covers the services named by the authorization certificate you are applying for. For the Software Authorization Certificate, the scope must include software development, software integration and software maintenance services.
- Complete the maturity certificate for software work. If you are targeting the Software Authorization Certificate, obtain either TS ISO/IEC 15504 Level 2 or higher, or CMMI Level 3 or higher, alongside ISO 27001. These two certification processes are usually the longest lead item, so plan backwards from the tender calendar.
- Obtain the TSE certificate for penetration testing work. If you will provide penetration testing services, obtain a type A or B TSE penetration testing firm certificate in addition to an ISO 27001 certificate covering penetration testing. The type you need depends on the scope of the service you will deliver.
- Apply through the Ministry portal. Applications are made to the Sanayi ve Teknoloji Bakanlığı (Ministry of Industry and Technology), which operates the Kamu Bilişim Alımları Firma Yetkilendirme Portalı for this purpose. Because the portal address, sign-in method, document list and screen flow can change over time, all of these should be confirmed from the Ministry's current announcements before applying. This article deliberately does not give a step-by-step walkthrough of the portal screens.
- Track assessment, validity and suspension risk. Complete applications are concluded within two months at the latest. Once the certificate is issued, calendar the expiry dates of the supporting certificates; if one of them lapses, the authorization certificate can be suspended. Where a non-conformity is found, the regulation provides for up to six months to remedy it, with the certificate suspended during that period.
Frequently asked questions
Which document do I need to bid on a Turkish public tender?
For IT service procurements, one or more of three certificates is needed depending on the nature of the work: the Kamu Bilişim Yetki Belgesi (Public IT Authorization Certificate) for participants carrying out public IT projects, the Yazılım Yetki Belgesi (Software Authorization Certificate) for software development, integration and maintenance, and the Sızma Testi Yetki Belgesi (Penetration Testing Authorization Certificate) for penetration testing. The certificates are defined in Article 4 of the regulation published in the Official Gazette of 29 June 2022, issue 31881. Which one a specific tender requires is read from the qualification clauses of that tender's administrative specification.
Which authorization certificate is required in an AI software tender?
The regulation does not treat artificial intelligence as a separate service type; what matters is whether the work is software development, software integration or software maintenance. In practice a firm developing or integrating AI software is asked for the Yazılım Yetki Belgesi (Software Authorization Certificate). As a verified example, Başakşehir Municipality's AI software services tender, registered as İKN 2026/1455679 and scheduled for 2 September 2026, requires the Software Authorization Certificate.
Is ISO 27001 alone enough for the Software Authorization Certificate?
No. Article 5 of the regulation requires a TS EN ISO/IEC 27001 certificate covering software development, software integration and software maintenance services, together with either TS ISO/IEC 15504 Level 2 or higher, or CMMI Level 3 or higher. The ISO 27001 certificate must also come from a body accredited by TÜRKAK, the Turkish Accreditation Agency.
How many years is an authorization certificate valid?
The regulation sets no fixed number of years. The authorization certificate's term is determined by whichever of the supporting certificates submitted with the application expires first. If your ISO 27001 certificate expires before your CMMI certificate, the authorization certificate ends on that date. Extending the term requires renewing the supporting certificates; the current application timetable should be confirmed from the Ministry's latest announcements before applying.
Is there an exemption below a certain contract value?
The regulation contains no monetary threshold and no exemption clause. It consists of nine articles, and none is headed as an exception or exemption. What determines the requirement in practice is whether the contracting authority lists the certificate as a qualification criterion in the tender documents. Each tender's administrative specification should therefore be reviewed individually, and where there is doubt, a clarification question should be put to the contracting authority.
Do subcontractors also need an authorization certificate?
The regulation's definition of participant includes subcontractors who will perform part of the contracted work under a contract with the prime contractor and who request authorization. A firm developing an AI module as a subcontractor may therefore need to hold its own certificate, depending on the nature of the work it takes on. Conditions on the use of subcontractors are additionally set in the tender documents, so the regulation and the administrative specification must be read together.