forumNew topic

Public tender now requires compliance with the penetration testing circular, what do we need at our scale?

AAslı G***ExpertCommunity member
Joined
Jan 2023
Message
1
#1

We are a team of 12 based in Ankara, developing archiving and digital record management software for public institutions. In the specifications for a ministry tender we are entering next month, providing an up-to-date penetration testing report under the Presidential Information and Communication Security Circular has been made mandatory.

Last year, we paid 35,000 TL to a senior freelancer for a private project to get a penetration test done, and we have a technical report for it. However, when we review the circular clauses in the tender dossier, we are very confused about the scope of the test, the credentials of the auditing organization, and the report's official validity.

What exactly does this penetration testing circular referenced in public tenders mandate? What is the minimum service level a mid-sized software vendor like us needs to procure, and what certifications should we look for to satisfy the agency and avoid disqualification?

RRecep Y***Member
Job title
System administrator
Sector
Sports and fitness
Organization type
boutique agency
Joined
Jun 2022
Message
9
Most Helpful#2

Short answer: Pursuant to the penetration testing circular referenced in public tender specifications, test reports obtained from independent individuals or unaccredited IT firms are officially invalid. To avoid disqualification, the test must be performed by a certified firm holding the Penetration Testing Organization credential approved by the Turkish Standards Institution (TSE).

To manage the process properly, follow these steps: 1) Authorization Check: Make sure to request the TSE-approved Penetration Testing Firm certificate (Level A or B) from any firm you solicit quotes from, and verify its validity on the official registry. Individual certificates do not meet the corporate requirement.

2) Defining the Test Scope: Per the circular, not only the web interface, but also the servers hosting the software, the database, the network layer, and any API endpoints must undergo gray box testing. Every component integrating with the agency's systems must be included in the scope.

3) Retest (Validation): If critical and high-severity vulnerabilities are identified during the initial test, the report cannot be submitted in that state. Your developers are typically given 15-30 days to remediate the flaws, after which the firm performs a retest and issues a clean report.

4) Budget and Timeline: For a mid-sized public software application and two associated servers, going market rates for TSE-approved testing range roughly between 60,000 TL and 110,000 TL. Because reporting and verification take at least three weeks, you need to act immediately based on your tender submission deadline.

MMustafa G***Member
Job title
Co-founder
Sector
Machinery manufacturing
Organization type
boutique agency
Joined
May 2022
Message
155
#3

Tender commissions are extremely strict when checking circular compliance. If the TSE-approved firm's stamp and the certified testers' registration numbers are not included in the report, your submission will be eliminated immediately during the technical evaluation. Under no circumstances should you submit that report from the freelancer.

FFurkan A***Veteran
Job title
Supply chain manager
Sector
Education
Organization type
boutique agency
Joined
Oct 2023
Message
1
#4

We gathered quotes from three TSE-approved firms for a similar tender last month. For a scope covering two web apps and a single server, the quotes came in at 55,000 TL, 75,000 TL, and 90,000 TL. If there are fewer than 15 days left before the tender deadline, firms may also charge a rush fee.

MMurat Ç***Expert
Job title
Project manager
Sector
Accounting & advisory
Organization type
medium-sized business
Joined
Oct 2022
Message
246
#5

Copy-paste the penetration testing clause from the specifications directly to at least two TSE-approved firms. They will send you a scoping form. If you exclude non-essential modules while filling it out, you will cut down both the testing duration and your overall costs.

GGökhan G***MemberCommunity member
Joined
Mar 2023
Message
4
#6

Will your software be deployed on local servers inside the public agency's own data center, or will you deliver it as a cloud service? For on-prem installations, source code analysis and application testing are sometimes sufficient, whereas external hosting mandates infrastructure testing as well.

TTülay Y***MemberCommunity member
Joined
Jan 2025
Message
412
#7

There are plenty of players on the market slapping the TSE logo on their websites while subbing out the actual work. Before signing any contract verify for yourself whether the firm is listed on the official TSE directory of active, registered penetration testing organizations and avoid paying cuts to middlemen.

YYasemin K***ExpertCommunity member
Joined
Mar 2023
Message
201
#8

During our first public tender we didn't know the proper procedures and submitted a report from an ordinary cybersecurity agency. The tender commission disqualified our bid due to the lack of document standards. We couldn't even contest it; the 30,000 TL we spent went down the drain, along with 6 months of tender prep. In public procurement, you must follow the rules to the letter.

MMert Ş***Member
Job title
Customer Relations Manager
Sector
Retail
Organization type
regional distributor
Joined
May 2025
Message
195
#9

The TSE-approved firm requirement is non-negotiable; also, make sure the test date on the report falls within the retroactive 6- or 12-month validity window specified in the tender documentation.

HHüsniye D***Member
Job title
Customer Relations Manager
Sector
Law
Organization type
family business
Joined
Jul 2024
Message
384
#10

You're right. Taking measures without an inventory leaves doors you haven't seen open.

If I were you, I'd go this route.

GGamze Ç***ExpertCommunity member
Joined
May 2023
Message
20
#11

My question might sound amateurish, sorry about that. The harder it is to reverse a decision, the slower you should make it.

I'm also curious if anyone does it differently.

MMustafa M***Member
Job title
Quality control inspector
Sector
Food wholesale
Organization type
regional distributor
Joined
Feb 2024
Message
106
#12

Timely topic. Don't rely on a single measure; go layer by layer.

If you post the result here, it will help others too.

TTolga G***Veteran
Job title
Secretary
Sector
Plastic
Organization type
regional distributor
Joined
Jan 2024
Message
138
#13

let me write how its done in practice. like having backups accessible on the same network and with the same identity makes them part of the target.

hope this helps.

HHasan K***Member
Job title
Software developer
Sector
Jewelry
Organization type
workshop
Joined
Sep 2025
Message
212
#14

You're right.

FFerhat A***ExpertCommunity member
Joined
Mar 2026
Message
124
#15

I've been dealing with this for a long time. Trying to do this alone is the most expensive way.

Proven by experience.

BBurcu E***MemberCommunity member
Joined
Feb 2023
Message
94
#16

i agree, and Id like to emphasize that. btw processes without records never improve, because you dont know what to fix.

if the notifciation path is long notifications don't arrive; missing notifications mean delayed incident detection. honestly if I were you I'd go this route.

SSultan G***MemberCommunity member
Joined
Jun 2024
Message
153
#17

I agree.

VVeli A***MemberCommunity member
Joined
Nov 2023
Message
43
#18

I have no experience with penetration testing circular, so Im asking. like the biggest time-waster for us was not knowing who had the final say.

Good luck with that.

MMustafa S***Member
Job title
Human Resources Manager
Sector
Jewelry
Organization type
two-branch business
Joined
May 2024
Message
43
#19

there's a trap here let me mention it then the answer varies greatly by industry; there is no one-size-fits-all rule.

hope this helps.

ÜÜlkü Y***Member
Job title
Logistics planning
Sector
Food wholesale
Organization type
a company within a holding
Joined
Nov 2024
Message
84
#20

Good call starting this thread.

Reply