Short answer: Penetration testing and intrusion testing are the exact same thing; intrusion testing is simply the direct Turkish equivalent of the English term 'penetration test'. Any consulting firm presenting these to you as two distinct services with separate quotes is either oblivious to basic terminology or assuming you do not know any better and trying to squeeze extra budget out of you.
Here's the reality: the actual distinction in IT security is between a "vulnerability assessment" and a "penetration test." Most likely, their cheaper option is a vulnerability scan that runs automated software to list known vulnerabilities across your systems. Their expensive option is a true penetration test where a specialist actively attempts to exploit those flaws, exfiltrate data, and escalate privileges. Splitting these into two services and calling one "sızma" and the other "penetrasyon" is utterly unprofessional.
If your automotive OEM client is asking for a report for an audit, they definitely aren't asking for an automated scan—they want a comprehensive penetration test compliant with TSE standards or international methodologies. Go back to that firm and demand a written explanation of the methodology differences between both items. Honestly, since trust is already broken, I'd suggest skipping them entirely and getting direct penetration test quotes from other accredited security firms with a clearly defined scope (like the number of external IPs, internal servers, and web interfaces).