TSE TS 13638 Class A Authorised Penetration Testing Company

Regulation-Compliant Penetration Tests

From BDDK, SPK, TCMB and EPDK to CBDDO BIGR and cloud architectures, we have full command of each sector’s specific legislation. With our TSE Class A authorisation certificate and OSCP-certified expert team, we manage end-to-end, under one roof, all the penetration testing and compliance reporting processes mandated by the regulations.

Uygar Y. AYDIN
Uygar Y. AYDIN
Cybersecurity Team
OSCP

Let’s clarify the penetration test scope in a 30-minute online meeting.

Schedule an Online Meeting Download the scoping form (PDF)

Finance, Payments & Banking 5 services

Capital Markets Board

SPK-Compliant Information Systems Penetration Test

We test the information systems of brokerage houses and portfolio management companies according to the annual periodic testing requirements of the SPK Information Systems Communiqué. In tests within the Capital Markets Board scope, we assess network, application, configuration and, where required, social engineering components with the OWASP and NIST methodologies. Findings are reported with risk level, evidence and remediation recommendations in a format that can be submitted to the regulator, and can be verified with a re-test after remediation.

Banking Regulation and Supervision Agency

BDDK BSD-2012/1 Compliant Penetration Tests

We conduct network, application and social engineering tests at banks and payment institutions within the scope of BDDK BSD-2012/1. In this service, we test the network, web/application and external attack surface with manual and automated techniques in line with the requirements of the Banking Regulation and Supervision Agency. At the end of the test, an executive summary and a technical findings report are delivered; on request, a re-test verifies that the weaknesses have been closed.

CBRT Communiqué · TSE TS 13638 T2

CBRT Communiqué-Compliant Pentest Service

We test payment institutions’ systems as an accredited provider within the scope of the CBRT payment system communiqué and TSE TS 13638 T2. Within the CBRT Communiqué · TSE TS 13638 T2 scope, we examine authentication, authorisation, configuration and data security controls end to end. Findings are reported with risk level, evidence and remediation recommendations in a format that can be submitted to the regulator, and can be verified with a re-test after remediation.

Payment Card Industry · PCI-DSS

PCI-DSS Penetration Test & ASV Scanning

We perform the internal/external penetration tests and quarterly ASV scans required by PCI-DSS in payment gateway, e-commerce and bank environments. In tests within the Payment Card Industry · PCI-DSS scope, we assess network, application, configuration and, where required, social engineering components with the OWASP and NIST methodologies. At the end of the test, an executive summary and a technical findings report are delivered; on request, a re-test verifies that the weaknesses have been closed.

SWIFT Customer Security Programme

SWIFT CSP Penetration Test

We perform technical vulnerability assessment and penetration testing for CSP requirements on the SWIFT infrastructure of institutions connected to the SWIFT network. In this service, we test the network, web/application and external attack surface with manual and automated techniques in line with the SWIFT Customer Security Programme requirements. Findings are reported with risk level, evidence and remediation recommendations in a format that can be submitted to the regulator, and can be verified with a re-test after remediation.

Public Sector & Regulators 5 services

DTO · Information and Communication Security Guide

CBDDO BIGR-Compliant Penetration Test

We conduct the regular vulnerability scans and penetration tests prescribed by the BIGR at public institutions and critical infrastructure (energy, water, healthcare, transport). Within the DTO Information and Communication Security Guide scope, we examine authentication, authorisation, configuration and data security controls end to end. At the end of the test, an executive summary and a technical findings report are delivered; on request, a re-test verifies that the weaknesses have been closed.

Information and Communication Technologies Authority

BTK-Compliant Network & Information Security Penetration Test

We perform network and information security penetration tests at electronic communications operators and internet service providers. In tests within the Information and Communication Technologies Authority scope, we assess network, application, configuration and, where required, social engineering components with the OWASP and NIST methodologies. Findings are reported with risk level, evidence and remediation recommendations in a format that can be submitted to the regulator, and can be verified with a re-test after remediation.

Personal Data Protection Authority

KVKK Technical Measures Penetration Test

We provide penetration testing and vulnerability management on IT systems in line with the technical measures in the Personal Data Security Guide. In this service, we test the network, web/application and external attack surface with manual and automated techniques in line with the Personal Data Protection Authority requirements. At the end of the test, an executive summary and a technical findings report are delivered; on request, a re-test verifies that the weaknesses have been closed.

Ministry of Health of the Republic of Türkiye

HIMS & Health Informatics Penetration Test

We perform the required information security tests on health informatics systems working integrated with HIMS and e-Nabız. Within the Ministry of Health scope, we examine authentication, authorisation, configuration and data security controls end to end. Findings are reported with risk level, evidence and remediation recommendations in a format that can be submitted to the regulator, and can be verified with a re-test after remediation.

Defence Industries Presidency · EYDEP

SSB & EYDEP-Compliant Penetration Test

We conduct project-based penetration tests at defence industry contractors and subcontractors, in line with EYDEP processes and institutional directives. In tests within the Defence Industries Presidency · EYDEP scope, we assess network, application, configuration and, where required, social engineering components with the OWASP and NIST methodologies. At the end of the test, an executive summary and a technical findings report are delivered; on request, a re-test verifies that the weaknesses have been closed.

Energy, Transport & Industrial Systems (OT/ICS) 4 services

Energy Market Regulatory Authority

EPDK SCADA & OT/ICS Penetration Test

We perform penetration testing and security audits on the SCADA and OT/ICS infrastructures of electricity, natural gas and petroleum market companies. In this service, we test the network, web/application and external attack surface with manual and automated techniques in line with the Energy Market Regulatory Authority requirements. Findings are reported with risk level, evidence and remediation recommendations in a format that can be submitted to the regulator, and can be verified with a re-test after remediation.

Directorate General of Civil Aviation

SHGM-Compliant Airport & Airline Penetration Test

We conduct critical infrastructure tests at airport operators and airline companies in line with the SHGM Cybersecurity Instruction and ICAO Annex 17. Within the Directorate General of Civil Aviation scope, we examine authentication, authorisation, configuration and data security controls end to end. At the end of the test, an executive summary and a technical findings report are delivered; on request, a re-test verifies that the weaknesses have been closed.

Maritime · ISPS Code (IMO)

ISPS Code Port & Ship OT Penetration Test

We perform IT/OT penetration testing and risk analysis at port operators and on ship systems within the scope of the ISPS Code and IMO resolutions. In tests within the Maritime · ISPS Code (IMO) scope, we assess network, application, configuration and, where required, social engineering components with the OWASP and NIST methodologies. Findings are reported with risk level, evidence and remediation recommendations in a format that can be submitted to the regulator, and can be verified with a re-test after remediation.

Railways · CTC / Signalling

Railway Signalling & OT Penetration Test

We conduct industrial SCADA/OT security tests on Centralised Traffic Control (CTC) and railway communication networks. In this service, we test the network, web/application and external attack surface with manual and automated techniques in line with the Railways · CTC / Signalling requirements. At the end of the test, an executive summary and a technical findings report are delivered; on request, a re-test verifies that the weaknesses have been closed.

Cloud Security 3 services

Amazon Web Services · Cloud & Network

AWS Cloud & Network Penetration Test

We test IAM, S3, VPC and API Gateway configurations on AWS infrastructures in accordance with the AWS penetration testing policy. Within the Amazon Web Services · Cloud & Network scope, we examine authentication, authorisation, configuration and data security controls end to end. Findings are reported with risk level, evidence and remediation recommendations in a format that can be submitted to the regulator, and can be verified with a re-test after remediation.

Google Cloud Platform

GCP Penetration Testing Service

We perform IAM, Cloud Storage, GKE and BigQuery security tests in Google Cloud environments in accordance with GCP rules. In tests within the Google Cloud Platform scope, we assess network, application, configuration and, where required, social engineering components with the OWASP and NIST methodologies. At the end of the test, an executive summary and a technical findings report are delivered; on request, a re-test verifies that the weaknesses have been closed.

Microsoft Azure · Cloud

Microsoft Azure Penetration Test

In Microsoft Azure environments we test identity, storage, network and service configurations in accordance with the ‘Rules of Engagement’. In this service, we test the network, web/application and external attack surface with manual and automated techniques in line with the Microsoft Azure · Cloud requirements. Findings are reported with risk level, evidence and remediation recommendations in a format that can be submitted to the regulator, and can be verified with a re-test after remediation.

E-Commerce, Integrators & Customs 4 services

Ministry of Trade · Trust Stamp

Trust Stamp (TRGO) Penetration Test

As a TSE-authorised company, we perform the annual mandatory penetration test prescribed by the Trust Stamp Communiqué for e-commerce platforms. Within the Ministry of Trade · Trust Stamp scope, we examine authentication, authorisation, configuration and data security controls end to end. At the end of the test, an executive summary and a technical findings report are delivered; on request, a re-test verifies that the weaknesses have been closed.

Revenue Administration · Special Integrator

GIB e-Document Integrator Penetration Test

At e-Invoice, e-Ledger and e-Archive integrators we conduct pre- and post-production penetration tests together with the ISO 27001, 20000-1 and 22301 requirements. In tests within the Revenue Administration · Special Integrator scope, we assess network, application, configuration and, where required, social engineering components with the OWASP and NIST methodologies. Findings are reported with risk level, evidence and remediation recommendations in a format that can be submitted to the regulator, and can be verified with a re-test after remediation.

IYS
Message Management System · Integrator

IYS Integrator Penetration Test

We perform penetration testing and information security verification on the infrastructures of business partners connecting to IYS APIs and consent management (CMP) platforms. In this service, we test the network, web/application and external attack surface with manual and automated techniques in line with the Message Management System · Integrator requirements. At the end of the test, an executive summary and a technical findings report are delivered; on request, a re-test verifies that the weaknesses have been closed.

Ministry of Trade · Authorised Economic Operator

AEO Supply Chain Penetration Test

For AEO status, we conduct technical penetration tests of IT systems and automations within the scope of supply chain security. Within the Ministry of Trade · Authorised Economic Operator scope, we examine authentication, authorisation, configuration and data security controls end to end. Findings are reported with risk level, evidence and remediation recommendations in a format that can be submitted to the regulator, and can be verified with a re-test after remediation.

Our Penetration Testing Process

We conduct all our regulation-compliant penetration tests according to the OWASP Testing Guide and NIST SP 800-115 methodologies. The process consists of six stages:

  1. Scoping and Planning — Test boundaries, target systems and the relevant regulatory requirements are defined.
  2. Reconnaissance — The attack surface is mapped through passive and active information gathering.
  3. Vulnerability Identification — Security weaknesses are identified through automated scanning and manual analysis.
  4. Exploitation — Identified weaknesses are verified in a controlled manner and the real business risk is measured.
  5. Reporting — An executive summary, technical findings, risk levels, evidence and remediation recommendations are prepared in a format that can be submitted to the regulator.
  6. Re-test — It is verified that the remediated weaknesses have been closed.

Sector and Legislation Mapping

SectorRelevant Regulation / StandardTest Focus
Finance, Payments & BankingSPK, BDDK (BSD-2012/1), TCMB, PCI-DSS, SWIFT CSPInformation systems, payment infrastructure, network and application
Public Sector & RegulatorsCBDDO BIGR, BTK, KVKK technical measuresCorporate information systems and personal data security
Energy, Transport & Industry (OT/ICS)EPDK (SCADA), SHGM, ISPS Code, railway signallingOT/ICS, SCADA and critical infrastructure
Cloud SecurityAWS, Microsoft Azure, GCPCloud configuration, identity and network security
E-Commerce, Integrators & CustomsIYS, GIB e-Document, AEO, Trust Stamp (TRGO)Integrator infrastructure and supply chain
Standards & Authorisation CertificatesISO/IEC 27001, TS 13638 (Class A)Periodic testing within the management system

Why Nesil Teknoloji?

  • TSE Class A Authorisation Certificate (TS 13638/T2) — Penetration testing authority at the broadest defined scope.
  • ISO/IEC 27001, 27701, 20000 and 22301 certified information security and process management.
  • CREST membership and an OSCP, CEH, CISSP, CISA certified expert team.
  • 400+ enterprise references — Broad sector experience from finance to the public sector.
  • End-to-end compliance — Testing, reporting and submission to the regulator under one roof.

Official Legislation Sources

Our service scopes are based on the current legislation of the relevant regulators: BDDK, SPK, TCMB, EPDK, KVKK, PCI SSC, TSE.

Let’s clarify together which legislation you are subject to

Let’s assess your scope and compliance obligations in a free 30-minute preliminary meeting.

Get a Quote

Frequently Asked Questions

What is a regulation-compliant penetration test?

A regulation-compliant penetration test is a security test conducted according to the scope, method and reporting requirements mandated by regulators such as BDDK, SPK, TCMB and EPDK and standards such as PCI-DSS and ISO 27001. The aim is both to identify security weaknesses and to document the compliance obligation under the relevant legislation.

How often should penetration testing be performed under PCI-DSS?

Under the PCI DSS v4.0 requirements, penetration tests are repeated at least once a year and after significant changes affecting the scope. ASV (Approved Scanning Vendor) vulnerability scans are performed at least quarterly.

What does the TSE Class A penetration testing authorisation certificate mean?

The Class A authorisation certificate granted under the TS 13638 standard shows that the company is competent to provide penetration testing services at the broadest defined scope. Nesil Teknoloji holds a Class A authorisation certificate under TS 13638/T2.

Which outputs are delivered at the end of the penetration test?

At the end of the test, an executive summary; a technical findings report presenting the vulnerabilities with their risk level, evidence and remediation recommendations; and a compliance report that can be submitted to the regulator are delivered. On request, a post-remediation re-test verification is also provided.

For which sectors and regulations do you provide penetration testing?

We provide regulation-compliant penetration testing in finance, payments and banking (SPK, BDDK, TCMB, PCI-DSS, SWIFT CSP); public sector and regulators (CBDDO BIGR, BTK, KVKK); energy, transport and industrial OT/ICS (EPDK, SHGM, ISPS); cloud (AWS, Azure, GCP); and e-commerce, integrator and customs (IYS, GIB e-Document, AEO).

What is the difference between a penetration test and a vulnerability scan?

A vulnerability scan is the detection of known weaknesses with automated tools. A penetration test is a comprehensive assessment based on the OWASP and NIST methodologies, in which an expert team manually verifies and exploits these weaknesses to reveal the real impact and business risk.