forumNew topic

What credentials should I ask for when hiring a penetration testing firm — is an accreditation certificate required?

KKübra M***Member
Job title
Accounting Manager
Sector
Consulting
Organization type
early-stage startup
Joined
Oct 2023
Message
140
#1

We run a B2B SaaS platform with an 18-person team, hosting enterprise client and financial data in our cloud infrastructure. Due to upcoming client security audits and our ISO 27001 certification process, we need to bring in a penetration testing service.

Evaluating vendors has been confusing. A boutique consultancy quoted 25.000 TL, mentioning certified engineers but offering no corporate accreditation. Another cybersecurity firm quoted 85.000 TL, emphasizing they are a Türk Standardları Enstitüsü (TSE) approved penetration testing provider and claiming this certification is mandatory for audits.

What credentials are we legally or operationally required to demand from pen testing vendors in the Turkish private sector? Does working with unaccredited firms cause issues during audits?

OOrhan D***New memberCommunity member
Joined
Jul 2026
Message
347
Most Helpful#2

Short answer: For private sector firms outside public institutions, banks, and payment providers, working with a TSE-approved pen test firm is not legally mandatory; however, for the report to hold weight in ISO 27001 or enterprise audits, the testers must hold internationally recognized technical certifications, and the company must provide corporate liability guarantees.

Evaluate vendor credentials across three core pillars: 1) Corporate competency: Having a TSE Penetration Testing Authorized Firm Certificate (Grade A or B) builds confidence, but isn't strictly mandatory for the private sector. Still, having an ISO 27001 certification and solid corporate references is the bare baseline. 2) Staff qualifications: The engineers signing the report must hold hands-on, practical certifications (senior penetration testing credentials, practical network and web security certs). Paper certs earned via multiple-choice quizzes alone won't pass muster. 3) Legal protection: Always require a professional liability insurance policy to cover outages or data leaks during testing, along with a robust NDA.

The biggest risk with uncertified firms or solo freelancers is that they run automated scanners haphazardly and dump raw scanner exports on you labeled as a report. This leaves actual vulnerabilities undetected and leaves you with zero legal recourse if your data gets compromised.

ÜÜlkü A***New memberCommunity member
Joined
Jul 2026
Message
70
#3

Look at the individual tester's hands-on, practical certs rather than just corporate paperwork. Multiple-choice test certs are easily brain-dumped online. Reports delivered by engineers holding credentials earned by breaking live boxes in 24-hour hands-on labs never get questioned in audits.

RRıdvan B***MemberCommunity member
Joined
May 2023
Message
180
#4

Two years ago, we hired an uncertified team on a 20.000 TL budget. The audit-ready report they handed us was literally just server version banners. A major enterprise client rejected it immediately during an audit. We ended up having to shell out 70.000 TL to a TSE-approved vendor to redo the entire test from scratch.

MMeryem A***Member
Job title
Logistics planning
Sector
Electrical-electronics
Organization type
regional distributor
Joined
May 2023
Message
62
#5

When gathering quotes, send companies a standard qualification checklist. Ask for these three documents before signing a contract: 1) Resumes and exam certification numbers of the staff who will actually conduct the test, 2) An anonymized sample test report, 3) A copy of their professional liability insurance policy, if available. Immediately disqualify any vendor that cannot provide these three.

FFatih B***Member
Job title
Quality Assurance Manager
Sector
Education
Organization type
120-person company
Joined
Feb 2025
Message
321
#6

The TSE certificate is issued to the company but they might just let an intern run the actual test. There are plenty of shops out there flaunting corporate TSE banners while just running automated scanners behind the scenes. Instead of relying on the company stamp make sure the contract explicitly names the exact individual who will be launching the attacks against your IP addresses.

DDeniz K***MemberCommunity member
Joined
Nov 2025
Message
21
#7

The ISO 27001 standard requires an independent technical assessment, but it does not mandate a certification from any specific public authority. However, to prove that the technical measures under the KVKK Data Security Guide have been fulfilled, having a legally incorporated and verifiably competent testing provider serves as strong evidence in your company's favor during audit processes.

KKemal G***MemberCommunity member
Joined
Nov 2025
Message
5
#8

an authorization certificate means nothing on its own guys. what mattesr is working with ppl experienced enough not to cause service downtime on live systems... tbh definitely get a professional liability insurance clause into the contract.

NNuri G***Member
Job title
Field sales representative
Sector
Glass
Organization type
300-person organization
Joined
Mar 2025
Message
328
#9

If our senior developer scans the system using open-source security tools and generates a report, would that be accepted if we submit it during an ISO 27001 certification audit?

VVeli S***ExpertCommunity member
Joined
Apr 2026
Message
62
#10

The guy quoting 25,000 TL will run an automated open-source tool for two days and dump an 80-page English printout in front of you. The one asking for 85,000 TL will just swap the logo on that same tool and slap a cover with a TSE logo on it. The only real difference is that the auditor will cringe at the first one.

EEfe Y***Member
Job title
Site Manager
Sector
Leather
Organization type
boutique agency
Joined
Jul 2025
Message
367
#11

Same here.

RRecep N***MemberCommunity member
Joined
Jul 2023
Message
85
#12

I'm a small business, let me explain from my side. Forgotten test environments are more often the entry point than live systems.

If I were you, I'd go this route.

KKader Y***Member
Job title
Front office accounting
Sector
Software
Organization type
300-person organization
Joined
Aug 2025
Message
34
#13

Sorry, but this doesn't apply in every case. Processes without records never improve, because you don't know what to fix.

Just leaving this note, it might be useful.

AAli K***Member
Job title
Finance Manager
Sector
Automotive aftermarket
Organization type
medium-sized business
Joined
Sep 2023
Message
73
#14

I have a question, don't want to go off-topic though. Security isn't absolute; it's about making attacks not worth the effort.

Just leaving this note, it might be useful.

KKader Ö***Member
Job title
Quality control inspector
Sector
Furniture manufacturing
Organization type
300-person organization
Joined
Sep 2024
Message
163

Doki · Incident response support · 2026

#15

Correct.

ZZafer K***MemberCommunity member
Joined
Nov 2024
Message
1
#16

Youre right Ive been down that road too. Security isnt absolute; its about making attacks not worth the effort.

Taking measures without an inventory leaves doors you haven't seen open. btw if you post the result here, it will help others too.

AAycan A***Expert
Job title
Social media manager
Sector
Seafood
Organization type
regional distributor
Joined
May 2023
Message
6
#17

this thrread is archived.

AAleyna B***Member
Job title
Intern
Sector
Accounting & advisory
Organization type
a company within a holding
Joined
Sep 2024
Message
200
#18

the discussion got scattered let me summarize. most time waste accumulates in tasks waiting for approval.

im also curious if anyone does it differently.

EErcan Ç***Member
Job title
Graphic Designer
Sector
Furniture manufacturing
Organization type
sole proprietorship
Joined
Aug 2023
Message
57
#19

My perspective changed after experiencing that... Most time waste accumulates in tasks waiting for approval.

That's all, sorry if I went on too long.

MMerve Ö***MemberCommunity member
Joined
Feb 2026
Message
1
#20

Quick summary for newcomers: Payment information changes are never verified through the channel they came from.

Reply