We are a team of 12 based in Ankara, developing archiving and digital record management software for public institutions. In the specifications for a ministry tender we are entering next month, providing an up-to-date penetration testing report under the Presidential Information and Communication Security Circular has been made mandatory.
Last year, we paid 35,000 TL to a senior freelancer for a private project to get a penetration test done, and we have a technical report for it. However, when we review the circular clauses in the tender dossier, we are very confused about the scope of the test, the credentials of the auditing organization, and the report's official validity.
What exactly does this penetration testing circular referenced in public tenders mandate? What is the minimum service level a mid-sized software vendor like us needs to procure, and what certifications should we look for to satisfy the agency and avoid disqualification?