Skip to content
Noroxi

KVKK and ISO 27001 complianceWe build controls, not paperwork.

We run your ISO 27001 and KVKK (Turkey’s personal data protection law) program with controls that actually work, not template policies. When the auditor asks for evidence, the file is ready.

Duration
6–16 weeks
Standard
ISO 27001:2022 · KVKK
Deliverables
Evidence file, internal audit report and support throughout the audit

What we test

  1. 01

    Gap analysis

    Where each of the 93 Annex A controls stands today.

  2. 02

    Risk assessment

    Asset inventory and a risk treatment plan.

  3. 03

    Policies and procedures

    Practical documents written for your organization.

  4. 04

    Technical controls

    Access, logging, backups and vulnerability management.

  5. 05

    KVKK

    VERBIS registration, data inventory and breach notification process.

  6. 06

    Audit readiness

    Internal audit and a certification dry run.

Gaps we commonly find

The ones we’ve run into most in recent engagements. You can’t know whether you have them until you test.

  • Outdated asset inventoryHigh
  • Untested business continuity planHigh
  • Logs not retained long enoughMedium
  • Access reviews that never happenMedium
  • Supplier security left unassessedMedium

How it works

  1. 012–3 weeks

    Gap analysis

    Current state, priorities and a roadmap.

  2. 024–10 weeks

    Implementation

    Controls, policies and the evidence file.

  3. 031–2 weeks

    Internal audit

    An independent check before certification.

  4. 04On the certification body’s schedule

    Certification audit

    We’re with you throughout the audit.

Frequently asked questions

Do you issue the certificate?
No. An accredited certification body issues it. We prepare you for the audit and stay with you throughout.
We’re moving from the 2013 version to 2022.
We offer a separate, short gap analysis package for the transition.
Do we also need a lawyer for KVKK?
For legal documents such as privacy notices, we work alongside your legal counsel. We handle the technical and organizational measures.

Often paired with

Let’s take a free look first

Leave us your domain. Within 2 business days, we’ll review your external surface and send the priority risks and a recommended scope on a single page.

  1. 01Leave your email and domain.
  2. 02We review your external surface within two business days.
  3. 03You get a one-page summary and a recommended first step.

We use your details only for this request. Privacy notice

mini assessment1 page
14
Subdomains
6
Exposed services
B
TLS grade
3 / 7
Security headers

Top three risks

  1. 1Admin panel exposed to the internetHigh
  2. 2Outdated TLS version still supportedMedium
  3. 3Content Security Policy missingLow
Delivery: 2 business daysRecommended first step: web and API testing