Governance · Risk · harmony · MANAGE
Governance, Risk & harmony
We turn the problem of regulation into service on a single road map
Compliance consultancy that brings ISO/IEC standards, cyber security legislation, risk management and supply chain security under one roof. Each heading below links to the corresponding service in our service catalog or our self-liability screening tool.
International Standards
ISO/IEC management systems
Each can be documented on its own; It can also be carried out in a single program under the umbrella of common governance.
ISO/IEC 27001
Information Security Management System (ISMS)
ISMS architecture and internal audit designed according to the organization's business processes and risk appetite, targeting zero major findings in the certification audit.
Service detail →
ISO/IEC 27701
Personal Data Management System (KVYS/PIMS)
Consultancy that transforms KVKK and GDPR obligations into an internationally auditable and certifiable privacy management system.
Service detail →
ISO/IEC 42001
Artificial Intelligence Management System (AIMS)
Systematically manages the operational, legal and ethical risks of machine learning and productive artificial intelligence projects; Management system consultancy preparing the EU AI Act.
Service detail →
National Legislation and Sectoral Obligations
KVKK, BIGR and sectoral audits
Regulations specific to Türkiye; For critical infrastructure operators, public institutions and any institution that processes personal data.
6698 p. KVKK
KVKK Compliance, Internal Audit and Sustainability
Designs the technical and administrative measures within the scope of KVKK No. 6698 by combining law, cyber security and governance disciplines; Service that verifies on-site with independent auditing.
Service detail →
BIGR · 7545 p. law
BİGR Compliance Consultancy and Audit
Compatible with the Cyber Security Presidency's audit guide methodology; End-to-end consultancy and TSE authorized independent audit from planning to BIGDES reporting.
Service detail →
EMRA · ISO 27019
Energy Sector SGYM Compliance and Audit
Centering on the OT and ICS dynamics of the energy sector; Consultancy and independent auditing that integrates ISO 27019, IEC 62443 and EMRA SGYM requirements within the framework of ISO 27001.
Service detail →
Technical Assurance and Corporate Program
Field-verified assurance beyond documentation
The governance framework remains on paper unless it is supported by independent technical testing and supply chain auditing.
GRC Program
Corporate Maturity, GRC and Cyber Resilience Program
Combining KVKK, ISO 27001/27701/42001 and Law No. 7545 obligations under a single governance umbrella; Integrated model that brings GRC and technical assurance (penetration testing, threat hunting, SOME support) together in the same program.
Service detail →
TS 13638
Comprehensive Penetration Testing Service
Conducted by CEH/OSCP/CISSP certified staff with TSE TS 13638 penetration testing company certificate; Independent technical assurance covering web, mobile, API, network, wireless and SCADA layers.
Service detail →
Supply Chain
Independent Supplier Cyber Security Audit
Inspects the information security maturity of suppliers and subcontractors with risk-oriented classification; Independent audit with a quantitative score that forms the basis for the “operability decision”.
Service detail →
Our Working Limit
Diagnosis is free, prescription is in session
On this page we show which standard or legislation meets which need; We create a gap analysis and closure roadmap specific to your institution together in a free pre-evaluation session.
- KVKK No. 6698 — legislature.gov.tr (OG 07.04.2016/29677)
- Cyber Security Law No. 7545 — legislature.gov.tr (OG 19.03.2025/32846)
- Cyber Security Competency Model Regulation in the Energy Sector (EPDK) — epdk.gov.tr (OG 06.06.2023/32213)
- Information and Communication Security Guide (BİGR) — cbddo.gov.tr (Circular No. 2019/12); current editor — siberguvenlik.gov.tr/mevzuat
- ISO/IEC 27001, 27701, 42001 — iso.org/standard/27001, 27701, 42001
- TS 13638 (TSE Penetration Test Certification) — tse.org.tr
Legal note: The above regulatory references are valid as of their date of publication and are subject to change; It does not constitute a final judgment and does not replace a legal opinion. Request a pre-evaluation session for an up-to-date and institution-specific evaluation. Last check: 23.09.2026.
Free Pre-Assessment
Let's map together which standard you need and with which calendar.
We deliver the written road map to you.