Let's talk about your project
DOKI / Cybersecurity

Cybersecurity · Compliance

When you prepare for a standard or regulation we make clear where to start: we measure the current state, rank the gaps and prepare policies and evidence files with you. Certification decisions belong to accredited bodies; we get you ready for that day.

  • Gap analysis
  • Policy drafts
  • Evidence list
  • Readiness review
01 / What this service includes

Be ready before the auditor arrives.

01

Gap analysis

We compare the controls of your target framework one by one with your current practice. Each control is marked “in place, partial, missing” and noted with its evidence.

02

Policy and procedure drafts

Instead of copying a template we write documents that match how you work and that your team can actually follow. Each document has an owner and a review date.

03

Evidence file and readiness review

We arrange the records an audit will ask for by control number and flag what is missing. As a last step we run a mock audit to see the surprise questions in advance.

02 / How it works

The readiness funnel

From all controls in the framework to those ready for audit, the list gets sharper at every stage.

Controls in scope
Controls implemented
Controls with evidence
Audit-ready
03 / Scope

Let's define the scope together.

We clarify the scope, deliverables and acceptance criteria together in the first meeting. The written quote lists that scope item by item; if the scope changes, the quote is updated as a new version.

Doki provides preparation and consulting. Official certification belongs to an authorized accredited body.

Deliverables

  • 01Gap analysis
  • 02Policy drafts
  • 03Evidence list
  • 04Readiness review
04 / Process

How we move forward, step by step.

Each step ends with something concrete in your hands; we move on with your approval.

  1. 01

    Analysis

    We examine the current state with data and find the real source of the problem.

  2. 02

    Priorities

    We rank findings by impact and effort and make clear what comes first.

  3. 03

    Documentation

    We write down decisions, settings and processes so that someone else can carry them on.

  4. 04

    Review

    We review the output together and work your feedback into the next version.

05 / Decision details

What to know before you ask for a quote.

What is included, what we need from you, timing and payment, all in one place. The exact scope and price are set in the written quote.

Included

  • The security measures of KVKK, GDPR and NIS2; the security side of ISO 27001 and PCI-DSS.
  • A gap analysis, closing the gaps and a readiness report.
  • Policy drafts and an evidence list.

Not included

  • The official certificate and certification audit (carried out by an accredited body).
  • Legal advice.

What we need from you

  • Your current policies and procedures.
  • A contact who knows your processes.

What sets the price

  • The target framework (KVKK, GDPR, NIS2, ISO 27001, PCI-DSS) and the size of your organisation.

Payment and aftercare

  • For work agreed in person, the full fee is paid at the start.
  • For remote work, half is paid at the start and half on delivery.
  • We respond to every request within 12 hours.
  • Meetings are held in Turkish; correspondence and deliverables are handled in the language of your choice with translation support.
  • We work in person in Istanbul and remotely across Türkiye and worldwide.
06 / FAQ

The questions on your mind.

Tell us what you need; we will define the scope together.

Tell us about your project
Do I receive a certificate at the end of this service?

No. Doki is not a certification body and does not issue certificates. This service prepares you for the audit; the certificate decision depends on the independent audit by the accredited body you choose.

Do you also help prepare for GDPR and NIS2?

Yes, on the security side. We run a gap analysis against the technical and organisational measures GDPR and NIS2 expect, prepare policy drafts and the incident notification plan, and help close the gaps. Legal matters such as whether you are in scope and data processing agreements are handled through your lawyer's assessment.

Is permission needed before testing?

Yes. Only systems you are authorised for and have approved in writing are assessed.

Let's begin

Let's talk about your project.

Tell us what you need; we will define the scope together.