TSE TS 13638 Class A Authorised Penetration Testing Company
Regulation-Compliant Penetration Tests
From BDDK, SPK, TCMB and EPDK to CBDDO BIGR and cloud architectures, we have full command of each sector’s specific legislation. With our TSE Class A authorisation certificate and OSCP-certified expert team, we manage end-to-end, under one roof, all the penetration testing and compliance reporting processes mandated by the regulations.
Related pages: Penetration Testing · DevSecOps
Let’s clarify the penetration test scope in a 30-minute online meeting.
Schedule an Online Meeting Download the scoping form (PDF)Finance, Payments & Banking 5 services
BDDK BSD-2012/1 Compliant Penetration Tests
We conduct network, application and social engineering tests at banks and payment institutions within the scope of BDDK BSD-2012/1. In this service, we test the network, web/application and external attack surface with manual and automated techniques in line with the requirements of the Banking Regulation and Supervision Agency. At the end of the test, an executive summary and a technical findings report are delivered; on request, a re-test verifies that the weaknesses have been closed.
CBRT Communiqué-Compliant Pentest Service
We test payment institutions’ systems as an accredited provider within the scope of the CBRT payment system communiqué and TSE TS 13638 T2. Within the CBRT Communiqué · TSE TS 13638 T2 scope, we examine authentication, authorisation, configuration and data security controls end to end. Findings are reported with risk level, evidence and remediation recommendations in a format that can be submitted to the regulator, and can be verified with a re-test after remediation.
PCI-DSS Penetration Test & ASV Scanning
We perform the internal/external penetration tests and quarterly ASV scans required by PCI-DSS in payment gateway, e-commerce and bank environments. In tests within the Payment Card Industry · PCI-DSS scope, we assess network, application, configuration and, where required, social engineering components with the OWASP and NIST methodologies. At the end of the test, an executive summary and a technical findings report are delivered; on request, a re-test verifies that the weaknesses have been closed.
SWIFT CSP Penetration Test
We perform technical vulnerability assessment and penetration testing for CSP requirements on the SWIFT infrastructure of institutions connected to the SWIFT network. In this service, we test the network, web/application and external attack surface with manual and automated techniques in line with the SWIFT Customer Security Programme requirements. Findings are reported with risk level, evidence and remediation recommendations in a format that can be submitted to the regulator, and can be verified with a re-test after remediation.
Public Sector & Regulators 5 services
CBDDO BIGR-Compliant Penetration Test
We conduct the regular vulnerability scans and penetration tests prescribed by the BIGR at public institutions and critical infrastructure (energy, water, healthcare, transport). Within the DTO Information and Communication Security Guide scope, we examine authentication, authorisation, configuration and data security controls end to end. At the end of the test, an executive summary and a technical findings report are delivered; on request, a re-test verifies that the weaknesses have been closed.
BTK-Compliant Network & Information Security Penetration Test
We perform network and information security penetration tests at electronic communications operators and internet service providers. In tests within the Information and Communication Technologies Authority scope, we assess network, application, configuration and, where required, social engineering components with the OWASP and NIST methodologies. Findings are reported with risk level, evidence and remediation recommendations in a format that can be submitted to the regulator, and can be verified with a re-test after remediation.
KVKK Technical Measures Penetration Test
We provide penetration testing and vulnerability management on IT systems in line with the technical measures in the Personal Data Security Guide. In this service, we test the network, web/application and external attack surface with manual and automated techniques in line with the Personal Data Protection Authority requirements. At the end of the test, an executive summary and a technical findings report are delivered; on request, a re-test verifies that the weaknesses have been closed.
HIMS & Health Informatics Penetration Test
We perform the required information security tests on health informatics systems working integrated with HIMS and e-Nabız. Within the Ministry of Health scope, we examine authentication, authorisation, configuration and data security controls end to end. Findings are reported with risk level, evidence and remediation recommendations in a format that can be submitted to the regulator, and can be verified with a re-test after remediation.
SSB & EYDEP-Compliant Penetration Test
We conduct project-based penetration tests at defence industry contractors and subcontractors, in line with EYDEP processes and institutional directives. In tests within the Defence Industries Presidency · EYDEP scope, we assess network, application, configuration and, where required, social engineering components with the OWASP and NIST methodologies. At the end of the test, an executive summary and a technical findings report are delivered; on request, a re-test verifies that the weaknesses have been closed.
Energy, Transport & Industrial Systems (OT/ICS) 4 services
EPDK SCADA & OT/ICS Penetration Test
We perform penetration testing and security audits on the SCADA and OT/ICS infrastructures of electricity, natural gas and petroleum market companies. In this service, we test the network, web/application and external attack surface with manual and automated techniques in line with the Energy Market Regulatory Authority requirements. Findings are reported with risk level, evidence and remediation recommendations in a format that can be submitted to the regulator, and can be verified with a re-test after remediation.
SHGM-Compliant Airport & Airline Penetration Test
We conduct critical infrastructure tests at airport operators and airline companies in line with the SHGM Cybersecurity Instruction and ICAO Annex 17. Within the Directorate General of Civil Aviation scope, we examine authentication, authorisation, configuration and data security controls end to end. At the end of the test, an executive summary and a technical findings report are delivered; on request, a re-test verifies that the weaknesses have been closed.
ISPS Code Port & Ship OT Penetration Test
We perform IT/OT penetration testing and risk analysis at port operators and on ship systems within the scope of the ISPS Code and IMO resolutions. In tests within the Maritime · ISPS Code (IMO) scope, we assess network, application, configuration and, where required, social engineering components with the OWASP and NIST methodologies. Findings are reported with risk level, evidence and remediation recommendations in a format that can be submitted to the regulator, and can be verified with a re-test after remediation.
Railway Signalling & OT Penetration Test
We conduct industrial SCADA/OT security tests on Centralised Traffic Control (CTC) and railway communication networks. In this service, we test the network, web/application and external attack surface with manual and automated techniques in line with the Railways · CTC / Signalling requirements. At the end of the test, an executive summary and a technical findings report are delivered; on request, a re-test verifies that the weaknesses have been closed.
Cloud Security 3 services
AWS Cloud & Network Penetration Test
We test IAM, S3, VPC and API Gateway configurations on AWS infrastructures in accordance with the AWS penetration testing policy. Within the Amazon Web Services · Cloud & Network scope, we examine authentication, authorisation, configuration and data security controls end to end. Findings are reported with risk level, evidence and remediation recommendations in a format that can be submitted to the regulator, and can be verified with a re-test after remediation.
GCP Penetration Testing Service
We perform IAM, Cloud Storage, GKE and BigQuery security tests in Google Cloud environments in accordance with GCP rules. In tests within the Google Cloud Platform scope, we assess network, application, configuration and, where required, social engineering components with the OWASP and NIST methodologies. At the end of the test, an executive summary and a technical findings report are delivered; on request, a re-test verifies that the weaknesses have been closed.
Microsoft Azure Penetration Test
In Microsoft Azure environments we test identity, storage, network and service configurations in accordance with the ‘Rules of Engagement’. In this service, we test the network, web/application and external attack surface with manual and automated techniques in line with the Microsoft Azure · Cloud requirements. Findings are reported with risk level, evidence and remediation recommendations in a format that can be submitted to the regulator, and can be verified with a re-test after remediation.
E-Commerce, Integrators & Customs 4 services
Trust Stamp (TRGO) Penetration Test
As a TSE-authorised company, we perform the annual mandatory penetration test prescribed by the Trust Stamp Communiqué for e-commerce platforms. Within the Ministry of Trade · Trust Stamp scope, we examine authentication, authorisation, configuration and data security controls end to end. At the end of the test, an executive summary and a technical findings report are delivered; on request, a re-test verifies that the weaknesses have been closed.
GIB e-Document Integrator Penetration Test
At e-Invoice, e-Ledger and e-Archive integrators we conduct pre- and post-production penetration tests together with the ISO 27001, 20000-1 and 22301 requirements. In tests within the Revenue Administration · Special Integrator scope, we assess network, application, configuration and, where required, social engineering components with the OWASP and NIST methodologies. Findings are reported with risk level, evidence and remediation recommendations in a format that can be submitted to the regulator, and can be verified with a re-test after remediation.
IYS Integrator Penetration Test
We perform penetration testing and information security verification on the infrastructures of business partners connecting to IYS APIs and consent management (CMP) platforms. In this service, we test the network, web/application and external attack surface with manual and automated techniques in line with the Message Management System · Integrator requirements. At the end of the test, an executive summary and a technical findings report are delivered; on request, a re-test verifies that the weaknesses have been closed.
AEO Supply Chain Penetration Test
For AEO status, we conduct technical penetration tests of IT systems and automations within the scope of supply chain security. Within the Ministry of Trade · Authorised Economic Operator scope, we examine authentication, authorisation, configuration and data security controls end to end. Findings are reported with risk level, evidence and remediation recommendations in a format that can be submitted to the regulator, and can be verified with a re-test after remediation.
Standards & Authorisation Certificates 2 services
Penetration Testing under ISO/IEC 27001
At customs firms, e-invoice integrators and companies entering public tenders, we carry out the annual penetration test required by ISO/IEC 27001. In tests within the Information Security Management System scope, we assess network, application, configuration and, where required, social engineering components with the OWASP and NIST methodologies. At the end of the test, an executive summary and a technical findings report are delivered; on request, a re-test verifies that the weaknesses have been closed.
TS 13638 Class A Penetration Testing Authorisation
As a TSE TS 13638 Class A authorised company, we provide legislation-compliant penetration testing to public and regulated institutions, including work requiring an official authorisation certificate. In this service, we test the network, web/application and external attack surface with manual and automated techniques in line with the Ministry of Industry and Technology & TSE requirements. Findings are reported with risk level, evidence and remediation recommendations in a format that can be submitted to the regulator, and can be verified with a re-test after remediation.
Our Penetration Testing Process
We conduct all our regulation-compliant penetration tests according to the OWASP Testing Guide and NIST SP 800-115 methodologies. The process consists of six stages:
- Scoping and Planning — Test boundaries, target systems and the relevant regulatory requirements are defined.
- Reconnaissance — The attack surface is mapped through passive and active information gathering.
- Vulnerability Identification — Security weaknesses are identified through automated scanning and manual analysis.
- Exploitation — Identified weaknesses are verified in a controlled manner and the real business risk is measured.
- Reporting — An executive summary, technical findings, risk levels, evidence and remediation recommendations are prepared in a format that can be submitted to the regulator.
- Re-test — It is verified that the remediated weaknesses have been closed.
Sector and Legislation Mapping
| Sector | Relevant Regulation / Standard | Test Focus |
|---|---|---|
| Finance, Payments & Banking | SPK, BDDK (BSD-2012/1), TCMB, PCI-DSS, SWIFT CSP | Information systems, payment infrastructure, network and application |
| Public Sector & Regulators | CBDDO BIGR, BTK, KVKK technical measures | Corporate information systems and personal data security |
| Energy, Transport & Industry (OT/ICS) | EPDK (SCADA), SHGM, ISPS Code, railway signalling | OT/ICS, SCADA and critical infrastructure |
| Cloud Security | AWS, Microsoft Azure, GCP | Cloud configuration, identity and network security |
| E-Commerce, Integrators & Customs | IYS, GIB e-Document, AEO, Trust Stamp (TRGO) | Integrator infrastructure and supply chain |
| Standards & Authorisation Certificates | ISO/IEC 27001, TS 13638 (Class A) | Periodic testing within the management system |
Why Nesil Teknoloji?
- TSE Class A Authorisation Certificate (TS 13638/T2) — Penetration testing authority at the broadest defined scope.
- ISO/IEC 27001, 27701, 20000 and 22301 certified information security and process management.
- CREST membership and an OSCP, CEH, CISSP, CISA certified expert team.
- 400+ enterprise references — Broad sector experience from finance to the public sector.
- End-to-end compliance — Testing, reporting and submission to the regulator under one roof.
Official Legislation Sources
Our service scopes are based on the current legislation of the relevant regulators: BDDK, SPK, TCMB, EPDK, KVKK, PCI SSC, TSE.
Let’s clarify together which legislation you are subject to
Let’s assess your scope and compliance obligations in a free 30-minute preliminary meeting.
Get a QuoteFrequently Asked Questions
What is a regulation-compliant penetration test?
A regulation-compliant penetration test is a security test conducted according to the scope, method and reporting requirements mandated by regulators such as BDDK, SPK, TCMB and EPDK and standards such as PCI-DSS and ISO 27001. The aim is both to identify security weaknesses and to document the compliance obligation under the relevant legislation.
How often should penetration testing be performed under PCI-DSS?
Under the PCI DSS v4.0 requirements, penetration tests are repeated at least once a year and after significant changes affecting the scope. ASV (Approved Scanning Vendor) vulnerability scans are performed at least quarterly.
What does the TSE Class A penetration testing authorisation certificate mean?
The Class A authorisation certificate granted under the TS 13638 standard shows that the company is competent to provide penetration testing services at the broadest defined scope. Nesil Teknoloji holds a Class A authorisation certificate under TS 13638/T2.
Which outputs are delivered at the end of the penetration test?
At the end of the test, an executive summary; a technical findings report presenting the vulnerabilities with their risk level, evidence and remediation recommendations; and a compliance report that can be submitted to the regulator are delivered. On request, a post-remediation re-test verification is also provided.
For which sectors and regulations do you provide penetration testing?
We provide regulation-compliant penetration testing in finance, payments and banking (SPK, BDDK, TCMB, PCI-DSS, SWIFT CSP); public sector and regulators (CBDDO BIGR, BTK, KVKK); energy, transport and industrial OT/ICS (EPDK, SHGM, ISPS); cloud (AWS, Azure, GCP); and e-commerce, integrator and customs (IYS, GIB e-Document, AEO).
What is the difference between a penetration test and a vulnerability scan?
A vulnerability scan is the detection of known weaknesses with automated tools. A penetration test is a comprehensive assessment based on the OWASP and NIST methodologies, in which an expert team manually verifies and exploits these weaknesses to reveal the real impact and business risk.