← Scale Technology Group SGB inspection authority active · KVKK upper limit 2026: ₺17.1M
Regulatory compliance, audit and cyber security themed illustration

Compliance and Audit

We take the obligation out of uncertainty and tie it to the calendar

7545, KVKK, EPDK SGYM and SSB Cyber Hygiene — we map which regulation and schedule you are subject to, and turn compliance into an auditable program.

Certificate and shield illustration symbolizing cyber hygiene certification

Defense Industry · SSB · TRTEST

Prove Your Cyber Security, Maintain Your Uninterrupted Business Partnership as a Qualified Supplier.

The Cyber Hygiene Certification Program, carried out by TRTEST under the coordination of SSB, inspects the supply chain at four maturity levels and thirteen control areas. details →

Printed circuit board, technical inspection on laboratory bench

Technical Assurance

We prove the control on paper in the field

Our TS 13638 certified staff conducts penetration testing at the web, mobile, API, network, wireless and SCADA layers; Findings are a mandatory evidence item of BİGR and SGYM audits.

Printed circuit board close-up

Independent Audit

Audit report ready to be submitted to official authorities

We produce official reporting that is fully compliant with the principle of independence in BİGR, SGYM and supplier audits and can be uploaded to BİGDES and EBİS.

    Compliance · Audit · Technical Assurance

    Cyber Security and Information Security Consulting

    The Cyber ​​Security Presidency is in the field with direct supervision and sanction authority. BIGR audit at least once a year in Category A sectors; Within 12 months after the SGYM report level notification; KVKK checks are periodic. These calendars operate independently of each other — any missed date cannot be restored.

    Free online tool · five steps · Report and PDF on screen · Not a sales presentation

    13
    Number of Services
    4
    Category
    1+ per year
    Audit Period
    ₺17.1M
    Penalty Upper Limit

    Compatibility References

    • Information Security MS ISO/IEC 27001
    • Personal Data YS ISO/IEC 27701
    • Artificial Intelligence AI ISO/IEC 42001
    • Energy Sector ISO 27019 · SGYM
    • Data Protection KVKK · GDPR
    • National Regime Law No. 7545 · BIGR
    TSE Authorized Company BIGR D1/D2 Chief Auditor TS 13638 Penetration Test Company Certificate CEH · OSCP · CISSP Certified Staff Full Compliance with the Principle of Independence

    Free Online Tool

    Create your own Liability Map

    You don't need to know service names or regulatory numbers. Describe your organization in five steps; See the legislation you are subject to, your calendar obligations, items with criminal risk and the services that meet them in a single report.

    What does he ask?

    five steps

    Sector and establishment type, size, regulatory statuses (EPDK, BTK, BDDK, DGCA, SSB), data and activity characteristics, your existing documents and structures.

    What produces

    Liability list

    For each liability, the source legislation, the moment or period in which it arises, the criminal risk and the service that meets it. Criticality is separated by color code.

    How to review

    Filterable report

    Filtering by regulation type, source, criticality, criminal risk and period; line details and PDF output.

    How long does it take

    few minutes

    Only corporate email verification is required to open the report. It is free; The output is a document that you can use within the organization.

    The tool is for informational purposes only; It does not constitute a legal opinion, audit opinion or commitment. Situations specific to your institution may not be covered — we recommend verifying the output together in an expert session. For a more detailed maturity survey Quick Assessment You can also look at the page.

    Sanctions Board

    Compliance cost and enforcement cost

    The amounts below are not recommendations, but administrative fine bands stipulated by the current legislation. In most organizations, the total cost of a compliance program remains below the lower limit penalty for a single violation.

    7545 p. Cyber Security LawFailure to take cyber security measures / failure to report vulnerabilities and incidents (Article 16)
    1.000.000 – 10.000.000 ₺Three to five times in case of benefit or loss
    7545 p. Cyber Security LawNon-compliance with audit obligations
    100.000 – 1.000.000 ₺Up to 5% of gross sales revenue in commercial companies
    6698 p. KVKKFailure to fulfill obligations regarding data security
    256.357 – 17.092.242 ₺Amount with 2026 revaluation rate applied
    6698 p. KVKKFailure to comply with board decisions
    427.263 – 17.092.242 ₺2026 amount
    EMRA SGYM RegulationFailure to carry out independent sectoral audit on time
    Risk in licensing processesReport within 12 months of level notification
    SSB Cyber Hygiene (TRTEST)Major finding in certification audit
    Not receiving ordersCondition for doing business in the defense supply chain

    Costs Beyond Punishment

    Risk of license restriction/suspension Elimination in public tenders Corporate contract terminations Cyber insurance premium increase Personal liability of board members loss of reputation

    Amounts are for informational purposes only; It does not replace legal opinion. KVKK amounts are updated at the beginning of each calendar year according to the revaluation rate.

    Why Now

    Harmony no longer works in three separate teams, but on a single road map

    In most organizations, the total cost of a compliance program remains below the lower limit penalty for a single violation. The problem isn't the budget, it's the mess.

    Repeated Effort

    The same asset inventory is drawn up separately for BIGR, ISO 27001 and KVKK — three teams, three budgets, three inconsistent results.

    Paper–Field Space

    The policy has been written but it is not implemented in the field. What is measured in audits is operating effectiveness, not design.

    Calendar Printing

    BİGR annual audit, SGYM 12-month report period, KVKK periodic control - calendars that operate independently and cannot be compensated retrospectively.

    Beyond Punishment

    License restriction, elimination from the tender, contract termination, increase in insurance premium and personal liability of board members.

    Why Scale Technology

    We establish harmony on the field, not on paper

    Field Expertise

    Direct field experience in GRC consultancy, independent audit and TS 13638 penetration testing.

    Mastery of Standards

    ISO/IEC 27001, 27701, 42001, ISO 27019 & Full compliance with SGYM, KVKK, GDPR and BIGR.

    Principle of Independence

    Due to the separation of duties, audit services are not provided to institutions that provide consultancy on the same subject.

    Measurable Result

    We conclude each project with a concrete maturity level, official audit file and a workable roadmap.

    Featured · Defense Industry · SSB · TRTEST

    Cyber Hygiene Certification: the entry ticket to the defense supply chain

    TRTEST Test and Evaluation Inc., which was established under the coordination of the Presidency of Defense Industries and with the support of the Turkish Cyber Security Cluster. The program carried out by aims to ensure that main contractors and sub-suppliers reach the minimum safety level. With its official name Cyber Hygiene Emergency Measures Criteria Setlooks at the technical configuration and operational resilience in the field rather than documentation on paper.

    Level 1

    awareness

    Beginning level where basic security steps are aware and basic policies are written down. It is often the first target for SMEs.

    Level 2

    Basic

    The stage where security rules begin to be technically implemented and a cyber defense routine such as antivirus and backup is established.

    Level 3

    medium

    An organized and mature security environment where penetration tests, scans, VPN and multi-factor authentication are conducted proactively and frequently.

    Level 4

    Advanced

    The highest level using advanced tools such as SIEM, SOC and EDR, proactive threat hunting and continuous monitoring operations.

    Red lines: In the audit, findings are divided into A, B and C classes. RDP/Telnet ports left open to the Internet, missing or incorrect SPF-DKIM-DMARC records, exposed admin panels, untested penetration testing and default passwords immediate class A (major) finding is counted. Documents cannot be obtained until these are closed, therefore SSB tenders cannot be entered.

    Free Expert Session

    Let's verify your map with an expert

    The online tool gives you the starting map; The session grounds it in the real situation of your institution. We discuss the regulations you are subject to, upcoming legal calendars and your current maturity level in a single session. At the end of the session you will have:

    • Which obligation, when: A one-page breakdown of the legal calendars that work for you
    • Which service, in what order: prioritized, reasoned list of steps
    • Estimated effort: written road map with time and resource forecast

    This is not a sales call. Your map will be delivered to you as a document that you can use within the institution, even if you do not work with us.

    Response: within 1 business day · Your data is processed only for this conversation within the scope of KVKK · Clarification Text