Public sector and enterprise compliance, through implementation

KVKK, ISO 27001 and Information and Communication Security Guide compliance

We put the technical measures of KVKK (Turkish Personal Data Protection Law) Article 12, an ISO 27001 information security management system and the requirements of the Presidential Information and Communication Security Guide (BİGR) into operation by implementing them, not like a consultant who writes a report and walks away. With open-source tools and on the organization's own servers. Your data never leaves your organization; compliance runs on-premise.

Explainer

What is compliance consulting?

For public institutions and enterprises, information security is no longer a choice; it is an obligation imposed by several overlapping legal frameworks. KVKK technical measures, ISO 27001, the Presidential Information and Communication Security Guide (BİGR) and Corporate SOME obligations intertwine. The critical question is usually not "which certificate", but who will actually implement the measures. The consultant who writes the report and the team that puts it into the systems are rarely the same.

C3T closes this gap. It brings the logging, monitoring, access management and hardening infrastructure that compliance requires to life with open-source tools and on the organization's own servers; it works as an implementing partner that complements, rather than competes with, the audit and certification body.

How is KVKK, ISO 27001 and BİGR compliance achieved?

Compliance proceeds in four steps: (1) asset inventory and criticality levelling, (2) a gap analysis of the current state, (3) implementation of the technical measures according to the roadmap — access authorization, logging, encryption, monitoring — and (4) audit readiness. C3T delivers these steps with open-source tools and on the organization's own servers, offline if desired. For the public sector, an open-source (AKKY) migration analysis and implementation is also carried out under Circular No. 2023/13. Logs, personal data and the inventory never leave the organization; data sovereignty is preserved.

What do we do within compliance?

We implement four main compliance areas end to end: BİGR alignment, KVKK Article 12 technical measures, the ISO 27001 management system and Corporate SOME. Each one runs on-premise and is auditable.

BİGR alignment

Brings the requirements of the Information and Communication Security Guide into practice end to end.

  • Asset grouping and inventory
  • Criticality levelling
  • Gap analysis
  • Implementation roadmap
  • Audit readiness

KVKK Article 12 technical measures

Puts the technical safeguards for personal data security into practice as implementation, not as a report.

  • Access authorization and logging
  • Encryption and data masking
  • Vulnerability management integration
  • Breach detection and notification process
  • Personal data processed on-premise

ISO 27001 ISMS setup

Establishes the information security management system and makes it ready for certification.

  • ISMS policies and procedures
  • Risk treatment plan
  • Implementation of the control set
  • Certification readiness
  • Internal audit support

Corporate SOME setup and operation

Deploys and operates the infrastructure of the Corporate Cyber Incident Response Team (SOME).

  • SOME organization and process
  • Coordination with USOM
  • Incident response procedures
  • Link to logging and monitoring infrastructure
  • Continuous operation and support
Highlight for the public sector

Public sector open-source (AKKY) migration analysis report

Presidential Circular No. 2023/13 established the use of open-source software (AKKY) in the public sector as official policy and directed institutions to prepare a migration analysis. C3T assesses the feasibility of the organization's migration from commercial licences to open source; prepares the technical and financial analysis report and then implements the migration. This process runs within the Digital Transformation Office (DDO) framework, independent of the critical-infrastructure restrictions of Law No. 7545. Our open-source position is no longer an alternative; it is an approach aligned with government policy.

Which obligations does it meet?

Our implementations are designed to satisfy several regulatory frameworks at the same time.

BİGR (CBDDO)

The Presidential Information and Communication Security Guide; mandatory for all public institutions and critical infrastructure. Requires asset grouping, criticality levelling and implementation of measures.

KVKK 6698 · Art. 12

Technical and administrative measures for the security of personal data. Includes concrete obligations such as access control, logging, encryption and breach notification (72 hours).

ISO 27001

The information security management system (ISMS) standard. Offers an internationally recognized compliance framework through a risk-based control set and process management.

USOM / Corporate SOME

The Corporate SOME (CSIRT) obligation for public institutions with an independent IT unit. Covers the detection, response and reporting of incidents in coordination with USOM.

About Law No. 7545 (Cybersecurity Law): The law introduced the framework and the concept of an authorized provider; the secondary legislation that will set the application criteria is still maturing. C3T does not claim to be "authorized". It builds architecture aligned with the localization and data-residency principles set out in the law, and is ready to provide compliance and integration support for critical infrastructure as the authorization process becomes clear.

Why C3T?

We approach compliance with three principles: being the implementer, working on-premise and complementing the certifier.

Implementer, not just adviser

We do not write a report and walk away. We build the technical infrastructure compliance requires, integrate it into existing systems and maintain it.

On-premise, with data sovereignty

The compliance infrastructure runs on the organization's own servers, offline if desired. Logs, personal data and the inventory never leave the organization.

Complements the certifier

We do not compete with auditors and certification bodies; we complement them. We implement the security infrastructure the certified organization needs.

Compliance triggers every security layer

A single compliance obligation usually requires several technical measures. C3T also implements the penetration testing, SIEM, identity management and logging infrastructure the certified organization needs.

Policy alignment

An approach aligned with government policy

Our open-source and on-premise approach overlaps with the "use of open-source software (AKKY) in the public sector" policy set out in Presidential Circular No. 2023/13 and with the Information and Communication Security Guide (BİGR). It enables institutions to achieve compliance on a low budget and with domestic/open technologies, keeping their sensitive data within their own boundaries. Within the framework of Law No. 7545 (Cybersecurity Law), we also build architecture aligned with the localization and data-residency principles.

Regulation, obligation and C3T's measure

Summarizes which regulation imposes which obligation and the C3T measure that meets it.

Regulation Obligation imposed C3T's corresponding measure
KVKK Art. 12 Technical/administrative measures for personal data Access control (IAM/PAM), logging/monitoring (SIEM), encryption, DLP — on-premise
BİGR (CBDDO) Asset grouping + criticality + control set Gap analysis + alignment + implementation with open-source tools
Law No. 7545 (Cybersecurity Law) Data residency + (for critical infrastructure) authorized provider 100% data localization in Türkiye, localization-first architecture (ready for authorization)
ISO 27001 ISMS + control implementation ISMS setup + technical controls + certification readiness
Law No. 5651 Retention of access/transaction logs Time-stamped logging infrastructure (open source)
Circular No. 2023/13 Public sector open-source migration + analysis report AKKY migration feasibility + technical/financial report + implementation

Frequently asked questions

Who is required to comply with BİGR?

BİGR (Turkey's Information and Communication Security Guide), issued by the Presidency, is a mandatory compliance framework for all public institutions and critical infrastructure operators. The organization groups its assets, applies measures according to criticality level and becomes audit-ready. C3T delivers the technical side of these steps.

Is C3T a certification body?

No. C3T is not an auditing or certifying body; it is the implementing partner that complements the consultant and the certifier. We deploy and operate the logging, monitoring, access management and server hardening infrastructure that a certified organization, or one preparing for certification, needs, on the organization's own servers.

Do you only report on KVKK technical measures?

No. We are not a consultancy that writes a report and walks away. We actually implement the KVKK Article 12 technical measures (access authorization, logging, encryption, data masking, breach detection), integrate them into existing systems and maintain them. Implementation is done on-premise with open-source tools.

What do you do for the public sector's open-source (AKKY) migration?

Under Presidential Circular No. 2023/13, we assess the feasibility of the organization's migration from commercial licences to open source; prepare the technical and financial analysis report; then implement and operate the migration. This process runs as a DDO (Digital Transformation Office) procedure, independent of the critical-infrastructure restrictions of Law No. 7545.

Does our data leave the organization during the compliance process?

No. We set up the compliance infrastructure and analysis tools on the organization's own servers, fully offline (air-gapped, i.e. never connected to the internet) if desired. Logs, personal data and the asset inventory never leave the organization; this preserves KVKK and data sovereignty requirements.

How does Law No. 7545 (Cybersecurity Law) affect us?

Law No. 7545 introduced the framework and the concept of an authorized provider; the secondary legislation that will set the application criteria is still maturing. C3T does not claim to be "authorized"; it builds architecture aligned with the localization and data-residency principles set out in the law and is ready for the authorization process.

Where do your compliance obligations begin?

Let's assess your current state together and identify which regulations apply to you. Starting from a gap analysis, we'll clarify in a free assessment how compliance can be implemented without your data leaving the organization.