Service Catalog 2026.1
Cyber Security, Audit and GRC Services
13 services, 4 categories, single obligation logic
Each category meets a different stage in the liability lifecycle: installation, consolidation, independent verification, and field testing.
01 · Installation
Compliance, Operation and Support Consultancy
02 · Consolidation
Holistic Service Programs
03 · Verification
Audit Services
04 · Field Test
Penetration Tests
Compliance, Operation and Support Consultancy
Establish the obligation
End-to-end consultancy services that establish your legal and standards-based obligations from scratch, make them ready for certification and keep them alive against changing legislation.
KVKK Compliance, Internal Audit, Operation and Support Consultancy
Law No. 6698Designs the technical and administrative measures within the scope of KVKK No. 6698 by combining law, cyber security and governance disciplines; Integrated service that verifies in the field with independent auditing and keeps it constantly updated.
Information and Communication Security Guide (BİGR) Implementation Process Consultancy
Law No. 7545A systematic consultancy model that manages the BIGR compliance process end-to-end, from planning to BIGDES reporting, and establishes documentation from scratch for public institutions and critical infrastructure operators.
ISO/IEC 27001 ISMS Compliance Consultancy and Internal Audit
ISO/IEC 27001It's not a copy-paste template; A living ISMS architecture designed according to the business processes, organizational structure and risk appetite of the institution, aiming for zero major findings in the certification audit.
ISO/IEC 27701 KVYS/PIMS Compliance Consultancy and Internal Audit
ISO/IEC 27701Independent standards compliance consultancy that transforms KVKK and GDPR obligations into an internationally auditable and certifiable privacy management system (PIMS).
ISO/IEC 42001 AIMS Compliance and Consultancy Service
ISO/IEC 42001Systematically manages the operational, legal and ethical risks of machine learning and generative artificial intelligence projects; The world's first AI governance standard compliance program that provides proactive preparation for the EU AI Act.
ISO 27019 & SGYM Compliance, Operation and Support Consultancy
OT / ICSCentering on the OT and ICS dynamics of the energy sector; Consultancy that builds industrial cyber resilience architecture by integrating ISO 27019, IEC 62443 and EMRA SGYM requirements into the ISO 27001 framework.
Cyber Hygiene Compliance Consultancy
SSB / TRTESTEnd-to-end consultancy that prepares companies in the defense industry supply chain and critical sector SMEs for independent audits of the SSB Cyber Hygiene Certification Program carried out under the coordination of TRTEST. Measures the current status in all 13 key control areas (e-mail security, web application security, asset and endpoint security, vulnerability management…); establishes the path to the target maturity level (Awareness · Basic · Intermediate · Advanced) and undertakes post-document operation.
Holistic Service Programs
Gather under one roof
Multi-annual programs that combine technical assurance and GRC, consolidating all regulations under a single governance umbrella that would create waste of effort and budget when carried out separately.
Corporate Maturity, GRC and Cyber Resilience Program
12 MonthsCombining KVKK, ISO 27001/27701/42001 and Law No. 7545 obligations under a single governance umbrella; 12-month integrated model that brings GRC and technical assurance (penetration testing, threat hunting, SOME support) together in the same program.
Cyber Security, Institutional Maturity, Operation and Support Program for the Energy Sector
Energy / EMRAMelting the holding and group companies' obligations of Law No. 7545, EMRA legislation, BİGR, SGYM, ISO 27001, IEC 62443 and ISO 42001 in a single pot; Integrated GRC program that manages IT and OT together.
Audit Services
Prove it with independent eyes
Providing reasonable assurance to official authorities through authorized, impartial and evidence-based audits; Independent audit services in full compliance with the principle of separation of consultancy and audit.
Information and Communication Security Guide (BİGR) Compliance Audit Service
TSE AuthorizedAn independent audit that is fully compliant with the Cyber Security Presidency's Audit Guide methodology, carried out by a TSE authorized company and BİGR D1/D2 chief auditors, and produces an official audit file ready to be uploaded to BİGDES.
Cyber Security Competence Model (SGYM) Independent Audit Service in the Energy Sector
EMRA / EBISWithin the scope of EMRA SGYM Regulation, carried out by authorized independent auditors; OT/EKS audit that produces an official sectoral audit report ready to be submitted to EMRA via EBİS.
Independent Supplier Cyber Security Audit Service
Supply ChainInspects the information security maturity of suppliers and subcontractors with risk-oriented classification; Independent audit with quantitative score as the basis for the "operability decision".
Penetration Tests
Verify in the field
Technical assurance services carried out by TS 13638 certified staff, verifying the controls on paper by exploiting them at the operational level.
Comprehensive Penetration Test (Penetration Test) Service in TS 13638 Standards
TS 13638 CertificatedConducted by CEH/OSCP/CISSP certified staff with TSE TS 13638 Penetration Testing Company Certificate; Independent technical assurance covering web, mobile, API, network, wireless and SCADA layers with a formal 8-step methodology.
Not sure which service is right for you?
Let's clarify your priorities together in a free preliminary meeting.