- Job title
- Technical service technician
- Sector
- Packaging
- Organization type
- a company within a holding
- Joined
- Jul 2025
- Message
- 263
We are a 40-person B2B logistics and warehousing software company. We've been operating independently for four years and have never commissioned an official penetration test. Last week, during vendor onboarding discussions with a major retail chain, they requested a certified pentest report from the past twelve months as part of their vendor security questionnaire.
We got quotes from two different cybersecurity firms. For our web app and external network perimeter, they quoted between 65,000 TL and 90.000 TL. Our budget is tight, so we're trying to figure out whether this expense is an actual legal requirement or just corporate risk policy on the client's side.
Under KVKK and current Turkish regulations, is penetration testing a strict legal requirement for a mid-sized tech vendor like us? Under what circumstances does it become mandatory, and when is it merely considered a best-practice risk reduction measure?