KVKK and ISO 27001 compliance
We run your ISO 27001 and KVKK (Turkey’s personal data protection law) program with controls that actually work, not template policies. When the auditor asks for evidence, the file is ready.
- Duration
- 6–16 weeks
- Standard
- ISO 27001:2022 · KVKK
- Deliverables
- Evidence file, internal audit report and support throughout the audit
What we test
01
Gap analysis
Where each of the 93 Annex A controls stands today.
02
Risk assessment
Asset inventory and a risk treatment plan.
03
Policies and procedures
Practical documents written for your organization.
04
Technical controls
Access, logging, backups and vulnerability management.
05
KVKK
VERBIS registration, data inventory and breach notification process.
06
Audit readiness
Internal audit and a certification dry run.
Gaps we commonly find
The ones we’ve run into most in recent engagements. You can’t know whether you have them until you test.
- Outdated asset inventoryHigh
- Untested business continuity planHigh
- Logs not retained long enoughMedium
- Access reviews that never happenMedium
- Supplier security left unassessedMedium
How it works
- 012–3 weeks
Gap analysis
Current state, priorities and a roadmap.
- 024–10 weeks
Implementation
Controls, policies and the evidence file.
- 031–2 weeks
Internal audit
An independent check before certification.
- 04On the certification body’s schedule
Certification audit
We’re with you throughout the audit.
Frequently asked questions
Do you issue the certificate?
We’re moving from the 2013 version to 2022.
Do we also need a lawyer for KVKK?
Often paired with
- Infrastructure and network penetration testingInternal and external networks, Active Directory, VPN and endpoints.
- Red teamAn objective-driven exercise that measures how well you detect and respond.
- Web and API penetration testingHands-on manual testing focused on the OWASP Top 10 and business logic flaws.
Let’s take a free look first
Leave us your domain. Within 2 business days, we’ll review your external surface and send the priority risks and a recommended scope on a single page.
- 01Leave your email and domain.
- 02We review your external surface within two business days.
- 03You get a one-page summary and a recommended first step.
- 14
- Subdomains
- 6
- Exposed services
- B
- TLS grade
- 3 / 7
- Security headers
Top three risks
- 1Admin panel exposed to the internetHigh
- 2Outdated TLS version still supportedMedium
- 3Content Security Policy missingLow