Compliance and Audit
We take the obligation out of uncertainty and tie it to the calendar
7545, KVKK, EPDK SGYM and SSB Cyber Hygiene — we map which regulation and schedule you are subject to, and turn compliance into an auditable program.
Compliance · Audit · Technical Assurance
The Cyber Security Presidency is in the field with direct supervision and sanction authority. BIGR audit at least once a year in Category A sectors; Within 12 months after the SGYM report level notification; KVKK checks are periodic. These calendars operate independently of each other — any missed date cannot be restored.
Free online tool · five steps · Report and PDF on screen · Not a sales presentation
Compatibility References
Free Online Tool
You don't need to know service names or regulatory numbers. Describe your organization in five steps; See the legislation you are subject to, your calendar obligations, items with criminal risk and the services that meet them in a single report.
What does he ask?
Sector and establishment type, size, regulatory statuses (EPDK, BTK, BDDK, DGCA, SSB), data and activity characteristics, your existing documents and structures.
What produces
For each liability, the source legislation, the moment or period in which it arises, the criminal risk and the service that meets it. Criticality is separated by color code.
How to review
Filtering by regulation type, source, criticality, criminal risk and period; line details and PDF output.
How long does it take
Only corporate email verification is required to open the report. It is free; The output is a document that you can use within the organization.
Sanctions Board
The amounts below are not recommendations, but administrative fine bands stipulated by the current legislation. In most organizations, the total cost of a compliance program remains below the lower limit penalty for a single violation.
Costs Beyond Punishment
Amounts are for informational purposes only; It does not replace legal opinion. KVKK amounts are updated at the beginning of each calendar year according to the revaluation rate.
Why Now
In most organizations, the total cost of a compliance program remains below the lower limit penalty for a single violation. The problem isn't the budget, it's the mess.
The same asset inventory is drawn up separately for BIGR, ISO 27001 and KVKK — three teams, three budgets, three inconsistent results.
The policy has been written but it is not implemented in the field. What is measured in audits is operating effectiveness, not design.
BİGR annual audit, SGYM 12-month report period, KVKK periodic control - calendars that operate independently and cannot be compensated retrospectively.
License restriction, elimination from the tender, contract termination, increase in insurance premium and personal liability of board members.
Why Scale Technology
Direct field experience in GRC consultancy, independent audit and TS 13638 penetration testing.
ISO/IEC 27001, 27701, 42001, ISO 27019 & Full compliance with SGYM, KVKK, GDPR and BIGR.
Due to the separation of duties, audit services are not provided to institutions that provide consultancy on the same subject.
We conclude each project with a concrete maturity level, official audit file and a workable roadmap.
Service Catalog 2026.1
01 — Install
KVKK, BIGR, ISO 27001/27701/42001, ISO 27019 & SGYM and SSB Cyber Hygiene consultancy and internal audit.
02 — Consolidate
Consolidated, multi-year GRC and cyber resilience programs for multi-regulated entities.
03 — Prove it
Independent reporting ready to be presented to official authorities in BİGR, SGYM and supplier audits.
04 — Test in the Field
Technical assurance at web, mobile, API, network, wireless and SCADA layers with TS 13638 certified staff.
Featured · Defense Industry · SSB · TRTEST
TRTEST Test and Evaluation Inc., which was established under the coordination of the Presidency of Defense Industries and with the support of the Turkish Cyber Security Cluster. The program carried out by aims to ensure that main contractors and sub-suppliers reach the minimum safety level. With its official name Cyber Hygiene Emergency Measures Criteria Setlooks at the technical configuration and operational resilience in the field rather than documentation on paper.
Level 1
Beginning level where basic security steps are aware and basic policies are written down. It is often the first target for SMEs.
Level 2
The stage where security rules begin to be technically implemented and a cyber defense routine such as antivirus and backup is established.
Level 3
An organized and mature security environment where penetration tests, scans, VPN and multi-factor authentication are conducted proactively and frequently.
Level 4
The highest level using advanced tools such as SIEM, SOC and EDR, proactive threat hunting and continuous monitoring operations.
Free Expert Session
The online tool gives you the starting map; The session grounds it in the real situation of your institution. We discuss the regulations you are subject to, upcoming legal calendars and your current maturity level in a single session. At the end of the session you will have:
This is not a sales call. Your map will be delivered to you as a document that you can use within the institution, even if you do not work with us.