← Scale Technology Group Law No. 7545 is in force · Annual audit mandatory

Service Catalog 2026.1

Cyber Security, Audit and GRC Services

13 services, 4 categories, single obligation logic

Each category meets a different stage in the liability lifecycle: installation, consolidation, independent verification, and field testing.

01 · Installation

Compliance, Operation and Support Consultancy

02 · Consolidation

Holistic Service Programs

03 · Verification

Audit Services

04 · Field Test

Penetration Tests

01

Compliance, Operation and Support Consultancy

Establish the obligation

End-to-end consultancy services that establish your legal and standards-based obligations from scratch, make them ready for certification and keep them alive against changing legislation.

KVKK Compliance, Internal Audit, Operation and Support Consultancy

Law No. 6698

Designs the technical and administrative measures within the scope of KVKK No. 6698 by combining law, cyber security and governance disciplines; Integrated service that verifies in the field with independent auditing and keeps it constantly updated.

Typical DurationCompliance: 3–5 months Independent audit: 3–6 weeks Operations and Support: 12 months
Key OutputPersonal Data Processing Inventory and Privacy Risk Analysis Tables
Risk threshold: Administrative fine of 256,357 ₺ – 17,092,242 ₺ for 2026 for violation of data security obligations; The lower limit for non-compliance with the board's decisions is 427,263 ₺.

Information and Communication Security Guide (BİGR) Implementation Process Consultancy

Law No. 7545

A systematic consultancy model that manages the BIGR compliance process end-to-end, from planning to BIGDES reporting, and establishes documentation from scratch for public institutions and critical infrastructure operators.

Typical DurationCompliance program 6–9 months · Annual control and BIGDES cycle is continuous
Key OutputBİGR Asset Groups Inventory and ANNEX-C.1 Criticality Rating Analyzes
Risk threshold: Law No. 7545 art. Administrative fine of 1,000,000 ₺ – 10,000,000 ₺ in accordance with article 16; Three to five times this amount in case of benefit or loss.

ISO/IEC 27001 ISMS Compliance Consultancy and Internal Audit

ISO/IEC 27001

It's not a copy-paste template; A living ISMS architecture designed according to the business processes, organizational structure and risk appetite of the institution, aiming for zero major findings in the certification audit.

Typical Duration4–8 months (depending on scope size) Annual internal audit cycle
Key OutputCurrent Situation (Gap) Analysis Report and Project Roadmap
Risk threshold: Direct administrative fines are not foreseen; However, lack of certification leads to elimination from the tender, contract termination and a "non-operational" decision during supplier audits.

ISO/IEC 27701 KVYS/PIMS Compliance Consultancy and Internal Audit

ISO/IEC 27701

Independent standards compliance consultancy that transforms KVKK and GDPR obligations into an internationally auditable and certifiable privacy management system (PIMS).

Typical Duration4–7 months Shortened to 3–4 months if ISO 27001 is available
Key OutputISO 27701 Current Situation (Gap) Analysis Report and Project Roadmap
Risk threshold: On the KVKK side, 256,357 ₺ – 17,092,242 ₺; Administrative fine of up to 4% of global annual turnover on the part of GDPR.

ISO/IEC 42001 AIMS Compliance and Consultancy Service

ISO/IEC 42001

Systematically manages the operational, legal and ethical risks of machine learning and generative artificial intelligence projects; The world's first AI governance standard compliance program that provides proactive preparation for the EU AI Act.

Typical Duration4–6 months Shortened to 3 months if existing ISO 27001/27701
Key OutputISO 42001 Current Situation (Gap) Analysis Report and Project Roadmap
Risk threshold: Administrative fines of up to 7% of turnover for prohibited applications under the EU AI Act and 3% for high-risk systems. Türkiye-based organizations opening up to the EU market are also included.

ISO 27019 & SGYM Compliance, Operation and Support Consultancy

OT / ICS

Centering on the OT and ICS dynamics of the energy sector; Consultancy that builds industrial cyber resilience architecture by integrating ISO 27019, IEC 62443 and EMRA SGYM requirements into the ISO 27001 framework.

Typical Duration8–12 months · Scales according to the number of sites and facilities
Key OutputISO 27019 & SGYM Compliance Gap Analysis Report
Risk threshold: Administrative fines and license sanctions within the scope of EMRA legislation; Risk of penalty of 1,000,000 ₺ – 10,000,000 ₺ within the scope of Law No. 7545.

Cyber Hygiene Compliance Consultancy

SSB / TRTEST

End-to-end consultancy that prepares companies in the defense industry supply chain and critical sector SMEs for independent audits of the SSB Cyber Hygiene Certification Program carried out under the coordination of TRTEST. Measures the current status in all 13 key control areas (e-mail security, web application security, asset and endpoint security, vulnerability management…); establishes the path to the target maturity level (Awareness · Basic · Intermediate · Advanced) and undertakes post-document operation.

Typical DurationGap analysis 2–4 weeks Preparation program 2–5 months Annual operating and re-inspection cycle
Key OutputCyber Hygiene Gap Analysis Report and Certification Preparation Roadmap
Risk threshold: Exclusion from the market instead of monetary penalties: the company with a major finding in the audit cannot receive orders from main contractors; Poor cyber hygiene directly affects EYDEP classification and position in the pool of qualified suppliers. TSE approved penetration testing is mandatory for certification — due to the principle of independence, the testing is planned separately from the consulting team.
02

Holistic Service Programs

Gather under one roof

Multi-annual programs that combine technical assurance and GRC, consolidating all regulations under a single governance umbrella that would create waste of effort and budget when carried out separately.

Corporate Maturity, GRC and Cyber Resilience Program

12 Months

Combining KVKK, ISO 27001/27701/42001 and Law No. 7545 obligations under a single governance umbrella; 12-month integrated model that brings GRC and technical assurance (penetration testing, threat hunting, SOME support) together in the same program.

Typical Duration12 months · Monthly progress reporting · Renewable
Key OutputCorporate Current Status Report, Risk Analysis and prioritized improvement plan
Risk threshold: The program establishes a comprehensive line of defense at once against all penalty bands of Law No. 7545, which reaches 10,000,000 ₺ and KVKK, which reaches 17,092,242 ₺.

Cyber Security, Institutional Maturity, Operation and Support Program for the Energy Sector

Energy / EMRA

Melting the holding and group companies' obligations of Law No. 7545, EMRA legislation, BİGR, SGYM, ISO 27001, IEC 62443 and ISO 42001 in a single pot; Integrated GRC program that manages IT and OT together.

Typical Duration12 months and above · Scalable according to multi-company structure
Key OutputIntegrated asset inventory, consolidated risk register and holistic security policies
Risk threshold: EMRA sanctions directly affect licensing processes; Penalties within the scope of Law No. 7545 are up to 10,000,000 ₺, and in case of benefit/damage, they may increase by up to three to five times.
03

Audit Services

Prove it with independent eyes

Providing reasonable assurance to official authorities through authorized, impartial and evidence-based audits; Independent audit services in full compliance with the principle of separation of consultancy and audit.

Information and Communication Security Guide (BİGR) Compliance Audit Service

TSE Authorized

An independent audit that is fully compliant with the Cyber Security Presidency's Audit Guide methodology, carried out by a TSE authorized company and BİGR D1/D2 chief auditors, and produces an official audit file ready to be uploaded to BİGDES.

Typical Duration3–8 weeks depending on scope · Repeated at least once a year
Key OutputBIGR Official Audit Report
Risk threshold: Failure to fulfill the annual audit obligation and BIGDES notifications is subject to a penalty of 100,000 ₺ - 1,000,000 ₺, or up to 5% of the gross sales revenue in commercial companies.

Cyber Security Competence Model (SGYM) Independent Audit Service in the Energy Sector

EMRA / EBIS

Within the scope of EMRA SGYM Regulation, carried out by authorized independent auditors; OT/EKS audit that produces an official sectoral audit report ready to be submitted to EMRA via EBİS.

Typical DurationMinimum 2–3 days field inspection + remote inspection · Total 3–6 weeks
Key OutputEMRA SGYM Independent Sectoral Audit Report
Risk threshold: Failure to submit the report within the 12-month legal period following the level notification creates risks in administrative sanctions and licensing processes.

Independent Supplier Cyber Security Audit Service

Supply Chain

Inspects the information security maturity of suppliers and subcontractors with risk-oriented classification; Independent audit with quantitative score as the basis for the "operability decision".

Typical DurationPer supplier Type A: 2–5 days Type B: 3–7 days Type C: 1–3 days
Key OutputTechnical Detail Report and Solution Plan
Risk threshold: Responsibility for violations occurring through the data processor lies with the data controller; KVKK violation carries a penalty risk of 256,357 ₺ - 17,092,242 ₺ for 2026.
04

Penetration Tests

Verify in the field

Technical assurance services carried out by TS 13638 certified staff, verifying the controls on paper by exploiting them at the operational level.

Comprehensive Penetration Test (Penetration Test) Service in TS 13638 Standards

TS 13638 Certificated

Conducted by CEH/OSCP/CISSP certified staff with TSE TS 13638 Penetration Testing Company Certificate; Independent technical assurance covering web, mobile, API, network, wireless and SCADA layers with a formal 8-step methodology.

Typical Duration1–6 weeks depending on scope · Free verification (validation test) included
Key OutputPenetration Test Result Report
Risk threshold: Failure to report vulnerabilities and incidents is subject to an administrative fine of 1,000,000 ₺ - 10,000,000 ₺. Penetration test findings are mandatory evidence items in BİGR and SGYM audits.

Not sure which service is right for you?

Let's clarify your priorities together in a free preliminary meeting.

Contact Us