forumNew topic

We're an SME: is penetration testing legally mandatory for us or purely voluntary?

PPınar B***Member
Job title
Technical service technician
Sector
Packaging
Organization type
a company within a holding
Joined
Jul 2025
Message
263
#1

We are a 40-person B2B logistics and warehousing software company. We've been operating independently for four years and have never commissioned an official penetration test. Last week, during vendor onboarding discussions with a major retail chain, they requested a certified pentest report from the past twelve months as part of their vendor security questionnaire.

We got quotes from two different cybersecurity firms. For our web app and external network perimeter, they quoted between 65,000 TL and 90.000 TL. Our budget is tight, so we're trying to figure out whether this expense is an actual legal requirement or just corporate risk policy on the client's side.

Under KVKK and current Turkish regulations, is penetration testing a strict legal requirement for a mid-sized tech vendor like us? Under what circumstances does it become mandatory, and when is it merely considered a best-practice risk reduction measure?

MMehmet K***Veteran
Job title
Data entry clerk
Sector
Packaging
Organization type
120-person company
Joined
Sep 2025
Message
106

Doki · Interface design · 2026

Most Helpful#2

Short answer: There is no blanket statute ordering every SME to run annual pentests; however, KVKK technical measures guidance and enterprise vendor contracts make it practically mandatory. Unless you operate in a heavily regulated industry like banking, payments, or energy, you won't face ex officio statutory fines just for skipping it, but commercial contracts and data breach liability make it hard to avoid.

The regulatory line is clear: organizations governed by BDDK, SPK, or EPDK (or their tier-one critical vendors) are explicitly required by law to conduct periodic penetration testing through authorized assessors. If you don't fall directly into those regulated spaces, you won't find a statutory clause specifically targeting you. That said, the Personal Data Protection Authority explicitly lists pentesting among the core technical measures in its "Personal Data Security Guide." If you suffer a data breach and the Board audits you, one of their first questions will be, "When were your systems last pentested?" Failing to test is treated as negligence, directly inflating the administrative fine.

Major enterprise accounts, on the other hand, are required to audit their supply chains under ISO 27001. When that retail chain asks for this report, they're protecting their own information security management system. For you, this isn't a regulatory mandate—it's a strictly commercial one. If you can't supply the report, they simply won't sign the contract.

To protect your cash flow right now, narrow the assessment scope: instead of testing the entire internal network, have them test only the web app processing client data and your external attack surface. Also make sure the vendor has TSE-certified penetration testing credentials; otherwise, enterprise clients might reject the final report.

UUğur Ö***Member
Job title
Sales Manager
Sector
IT services
Organization type
regional distributor
Joined
Jan 2024
Message
5

Doki · Brand identity · 2026

#3

When an enterprise deal is on the table regulations don't really matter—you won't close the contract or win the RFP without that report. When getting quotes, ask firms to scope only external IPs and the web application. Leaving the internal network out for now should drop that 65,000 TL quote down to around 35,000-40,000 TL.

ZZafer D***Member
Job title
Operations manager
Sector
Tourism
Organization type
8-person team
Joined
Nov 2024
Message
15
#4

We went through a similar process last year with our 30-person team. We had no choice but to pay 50.000 TL and get it done because of a client specification. During the test, we found out our database port was publicly exposed without authorization and an old API endpoint was running without any authentication. At first we thought it was a useless expense, but the reputational damage those vulnerabilities would have caused would've cost way more than that money.

ZZehra D***Expert
Job title
IT manager
Sector
Food wholesale
Organization type
120-person company
Joined
Feb 2025
Message
44

Doki · Server maintenance contract · 2024

#5

The market is flooded with hundreds of middlemen who just run an automated scanner for 15.000 TL and dump an 80-page report on your desk. If your enterprise client's info-sec team knows anything at all, they'll trash that report immediately and your money will go down the drain. Make sure the service you get definitely includes manual verification and scenario-based exploitation.

KKadir T***MemberCommunity member
Joined
Apr 2026
Message
25
#6

You can evaluate this across four main points: 1) There is no legal obligation unless there is a direct sectoral mandate. 2) Because it is considered a technical measure under KVKK, not having done a test counts as negligence in the event of a data breach. 3) Enterprise clients with ISO 27001 can include it as a contractual requirement. 4) If you ever want to get cyber liability insurance, it will show up as a policy prerequisite.

ZZerrin S***Expert
Job title
Sales Manager
Sector
Software
Organization type
120-person company
Joined
Apr 2023
Message
43
#7

btw don't send the whole report to the client when it's done. ask the security firm for an executive summary. handing the clieent the full technical breakdown with all the vulnerabilities and exploit steps creates other security risks.

PPerihan K***Member
Job title
Front office accounting
Sector
Furniture manufacturing
Organization type
regional distributor
Joined
Nov 2025
Message
45
#8

During vendor audit processes, you are subject to the other party's risk matrix. Signing an NDA prior to the contract and requesting a scope verification document stating that the audit findings will remain strictly limited to the agreed scope will protect your rights.

GGamze K***MemberCommunity member
Joined
Oct 2022
Message
3
#9

Did your client mandate TSE standards or a specific certification for the report? If an independent third-party report is enough on its own, you could keep the scope limited to the web panel and cut down costs; have you read the specifications carefully?

DDilara G***ExpertCommunity member
Joined
Jun 2023
Message
20
#10

Everyone thinks it's a completely pointless expense at first but it's a hurdle every growing B2B software dev has to clear. tbh once you do it once and get the hang of the methodology it goes way faster and with a lot less stress in the following years, don't let it intimidate you.

RRecep B***ExpertCommunity member
Joined
Jun 2024
Message
111
#11

This is exactly what we experienced. Most time waste accumulates in tasks waiting for approval.

Of course, it varies if your situation is different.

İİlknur A***New member
Job title
General coordinator
Sector
Textile
Organization type
early-stage startup
Joined
Jun 2026
Message
59
#12

There's also a measurement aspect to this. Solutions that work at a small scale collapse when you grow; I learned this late.

SSultan U***MemberCommunity member
Joined
Jul 2025
Message
402
#13

Timely topic. If you don't write this down from the start, it leads to arguments later.

If you post the result here, it will help others too.

LLemanNew member
Job title
Healthcare worker
Joined
Oct 2024
Message
30

Doki · Incident response support · 2024

#14

saved. tbh taking notes for two weeks yields better results than a six-month estimate.

if you have questions, write them; I'll answer as best I can.

PPınar A***MemberCommunity member
Joined
Apr 2024
Message
1
#15

Exactly like that. Solutions that work at a small scale collapse when you grow; I learned this late.

I'm also curious if anyone does it differently.

RRecep Y***MemberCommunity member
Joined
Oct 2022
Message
5
#16

I felt relieved reading this answer so it's not just me. Mistakes made on the is pen testing mandatory for smes side are usually reversible but expensive.

Doki destekDoki team
Job title
Technical Support
Sector
Cybersecurity and digital
Organization type
Doki
Joined
Mar 2023
Message
428
#17

My perspective changed after experiencing that. When making decisions, write down the worst-case scenario too, not just the best.

That's all, sorry if I went on too long.

SSultan K***Member
Job title
IT Manager
Sector
Automotive aftermarket
Organization type
cooperative
Joined
Mar 2023
Message
1
#18

There are three things to check when doing this. If you get three different answers on a topic, the question was asked wrong.

If you have questions, write them; I'll answer as best I can.

SSalihNew member
Job title
Hardware store
Organization type
chain store
Joined
Dec 2024
Message
24
#19

I'm curious too.

EEfe A***Member
Job title
System support specialist
Sector
Software
Organization type
8-person team
Joined
Jul 2022
Message
136

Doki · Infrastructure migration · 2025

#20

If I understood correctly, you're saying: Your time to detect an issue directly determines its cost.

Correct me if I'm wrong.

Reply