TSE-Accredited Penetration Testing
Omniverse is a penetration testing firm accredited by the Turkish Standards Institution (TSE) under TS 13638. TSE accreditation shows that the testing methodology, team competence, and confidentiality and reporting processes have been independently audited, and it is commonly required in audits of regulated organisations in Turkey.
What does a TSE-accredited penetration testing firm mean?
TSE audits and accredits companies that provide penetration testing services against a defined standard. The accreditation reviews the company’s testing methodology, the competence of its penetration testers, the processes that protect customer data, and report quality. Accredited firms are audited by TSE on a regular basis.
TSE also certifies penetration testers individually. For an enterprise penetration test, organisations generally expect both the firm to be TSE accredited and certified testers to be part of the team.
Who needs a TSE-accredited penetration test?
- Banks and financial institutions: organisations regulated by the BDDK (Banking Regulation and Supervision Agency) are expected to work with competent, independent firms for information systems penetration testing, and TSE accreditation is frequently requested in audits.
- Public institutions and critical infrastructure: the Information and Communication Security Guide of the Presidential Digital Transformation Office recommends that penetration tests be performed by competent, accredited firms.
- Payment and e-money institutions, capital markets firms: for tests under the information systems regulations of the Central Bank of the Republic of Turkey (CBRT) and the Capital Markets Board (SPK).
- Any organisation going through audits and compliance: to show in ISO 27001, PCI DSS and customer audits that testing was performed by a competent firm.
Which requirement applies to your organisation depends on your line of business and current legislation. We clarify the requirements you are subject to together during scoping.
How can you verify that a firm is TSE accredited?
TSE publicly publishes the list of accredited penetration testing firms. We recommend checking that the firm you plan to work with is on this list and that its certificate is valid. At the proposal stage we share a copy of our certificate and the qualifications of the testers assigned to your engagement.
What does a TSE-accredited penetration test report contain?
- Test scope, methodology, dates and test team details
- A risk summary for management
- For every finding: risk rating (CVSS), affected asset, exploitation steps and evidence
- Prioritised remediation recommendations
- Retest results after remediation
Why Omniverse?
- TSE TS 13638 accredited penetration testing firm: our methodology, people and reporting processes are independently audited.
- Certified team: TSE senior penetration testers and consultants holding OSCP, OSCE, CRTO and CISSP certifications.
- Manual validation: not automated scan output; every finding is proven through exploitation and false positives are removed.
- Audit-ready reporting: an executive summary and a CVSS-scored technical report that can be used as evidence in BDDK, CBRT, PCI DSS, ISO 27001 and DORA audits.
- Support through closure: once fixes are in place, we retest and report that the findings are closed.
- Sector experience: more than 50 enterprise clients, primarily in banking and finance, insurance, energy and critical infrastructure, automotive, retail and healthcare.
Frequently asked questions
What is a TSE-accredited penetration testing firm?
It is a penetration testing firm accredited by the Turkish Standards Institution under TS 13638, after an audit of its methodology, staff competence, confidentiality and reporting processes. Omniverse is a TS 13638 accredited firm.
Where can I find the list of TSE-accredited penetration testing firms?
TSE publishes the list of accredited penetration testing firms through its official channels. We recommend checking that the firm you plan to work with is on the list and that its certificate is valid.
Is TSE accreditation given to the firm or to the tester?
Both. TSE accredits penetration testing firms and certifies individual penetration testers separately. For enterprise tests, the firm is expected to be accredited and the team to include certified testers.
Is a TSE-accredited penetration test mandatory?
It depends on the regulation your organisation is subject to. In banking, the public sector and critical infrastructure, auditors frequently expect testing by TSE-accredited firms; for other organisations it is the most common way to demonstrate the competence of the test.
Let’s define your scope together
Tell us what you need and we will prepare a tailored proposal.