NIS2 and ISO compliance for European organisations — and their suppliers in Türkiye
NIS2 programmes, ISO/IEC 27001 and related management systems, virtual CISO leadership and GDPR transfer work for organisations across the European Union. Every engagement is led personally by our founder, a Lead Auditor in six ISO standards.
We take European organisations from “we are in scope and we are not sure what that means” to documented, auditable compliance — and we do the same for their suppliers in Türkiye.
Where compliance programmes fail
Most organisations do not fail NIS2 or ISO/IEC 27001 because of technology. They fail for four reasons we see repeatedly — and design our engagements to prevent.
The paperwork does not match the operation
Templates are bought, renamed and filed. The auditor asks for evidence that the procedure was followed and there is none. We write documentation from your actual processes, and build the evidence trail with it.
OT is quietly left out of scope
In manufacturing, production and control systems are treated as “not IT” and excluded. Under NIS2 and the national decrees they are squarely in scope. We treat OT/ICS as a first-class domain with its own policy, categorisation and risk treatment.
Supplier contracts cannot carry the obligation
An entity commits to a 24-hour early warning while its critical IT supplier may notify it days after an incident is resolved. We check supplier notification timelines against the statutory clock and remediate the contracts.
Nobody owns it after go-live
The consultant leaves, the management review is never held, the risk register ages. We hand over a running system — audit programme, review calendar, metrics — and stay available through the first cycle.
Compliance that cannot survive its first management review was never compliance. It was a document set.
Six service lines, one accountable consultant
Consulting, training and audit from the same person: the one who builds the system also trains your team and runs the internal audit before the external one. Deliverables are produced in English to international documentation standards.
NIS2 compliance
From scope and classification to audit-ready evidence under the national act — Slovakia, Romania and other member states.
NIS2 →ISO management systems
ISO/IEC 27001, 27701, 22301, 20000-1, 42001 and ISO 9001, built as one integrated system wherever scope allows.
Standards →Virtual CISO
Retained security leadership with a defined cadence and deliverables — including the Article 20 management-body work.
Packages →Data protection and transfers
GDPR programmes, and the Turkish, UAE and Qatari side of the same data flows: SCCs, TIAs and KVKK alignment.
Data protection →Training
Awareness, foundation and internal auditor courses for six standards; NIS2 training for management bodies, technical teams and suppliers.
Programmes →Audit
Internal audits, supplier security audits, pre-certification readiness reviews and NIS2 gap assessments.
Audit services →Standards and regulation we work with
Your supplier is in Türkiye. Your regulator is not.
NIS2 Article 21(2)(d) makes you responsible for the security of your suppliers. A large share of European manufacturing supply chains runs through Türkiye, and almost no consultancy works fluently on both sides of that line.
consultant, both jurisdictions — no coordination gap between an EU adviser and a local one
working languages for supplier engagement: English and Turkish
EU adequacy decisions covering Türkiye — every transfer needs the full package
NIS2 early warning — achievable only if your supplier is obliged to report to you first
We assess the Turkish supplier against your obligations, in Turkish and on site; remediate the contract and its notification timelines; build the GDPR transfer package; and reconcile it with Turkish KVKK — as one consultant, in both jurisdictions.
Two NIS2 programmes in two member states
Described without identifying the clients. In both, the national act was more decisive than the directive itself.
Slovakia — automotive components manufacturer
Important entity under NACE C29.3, in scope through NIS2 Annex II. End-to-end NIS2 and ISO/IEC 27001:2022 programme: cybersecurity strategy, risk management process and tool, a Statement of Applicability mapping all 93 Annex A controls to NIS2 and the Slovak Act, and a separate OT/ICS security policy.
The IT services agreement with the Turkish parent-group provider was remediated: a notification trigger of “three business days after resolution” was replaced with a 12-hour, detection-triggered outer limit.
NIS2ISO/IEC 27001:2022OT/ICSSupply chainRomania — NIS2 compliance programme
Completed under GEO 155/2024 and the DNSC registration regime: scope determination, gap analysis against the national requirements, and the documented management system built within the statutory deadline sequence.
Policies at 120 days, risk analysis and measures at six months, first external audit at twelve months. We planned backwards from the audit date, not forwards from the kick-off.
NIS2GEO 155/2024DNSCKuzey AKSU
Founder and Principal Consultant of Infosec Academy, and a Lead Auditor in six ISO standards. Over 25 years in IT and information security, fifteen of them leading security and infrastructure functions inside multinationals in banking, insurance, online financial services, industrial holdings, port operations, aviation maintenance and manufacturing.
He has built and run information security programmes from the ground up five times, and has been the person accountable during internal and external audits rather than the adviser standing beside them. Every engagement is led by him personally.
Having built the kind of programmes I now assess changes what I look for — and what I am willing to accept as evidence.Kuzey AKSU
Organisations where our founder held roles
- Citibank
- CIGNA Life Insurance
- GKFX
- Yıldırım Holding
- Mersin International Port
- myTECHNIC
- BSH Home Appliances Group
- HP Türkiye
- Habboush Group
- Coral Travel
- ATP
These are organisations where our founder was employed during his career. They are not client references.
Direct, as a partner, or on retainer
We work directly with end clients, and as a delivery partner or subcontractor to consultancies, law firms and IT service providers who need specialist capacity. Every proposal starts with a written scope — before any commercial figure is discussed.
What we will tell you honestly
- If your deadline is not achievable with the scope you want, we will say so at the scoping stage and propose what can realistically be completed first.
- If part of the work is better done by your own team with our oversight — and it often is, because they will have to run it afterwards — we will structure the engagement that way and price accordingly.
- If a standard or a framework is not going to help you, we will not sell it to you.
Questions we are asked
Does NIS2 apply to our suppliers in Türkiye?
NIS2 applies directly to entities established in the EU, but Article 21(2)(d) makes them responsible for the security of their supply chain. Turkish suppliers of ICT services, components or engineering support therefore meet NIS2-derived security and notification obligations through their contracts. We assess and remediate those relationships on both sides.
Is NIS2 a certification?
No. There is no NIS2 certificate and no accredited body that signs you off. A supervisory authority can ask at any point for evidence that the Article 21 measures are implemented and that the management body approved and oversees them. Where you also want a certificate, we run the programme so that ISO/IEC 27001 certification comes out of the same work.
How long does a NIS2 or ISO/IEC 27001 programme take?
Typically four to nine months, depending on entity size, OT footprint and how much documentation already exists. We plan backwards from the audit or statutory deadline, and if your date cannot be met with the scope you want, we say so in the scoping call.
Does Infosec Academy issue ISO certificates?
No. Certificates are issued by accredited certification bodies, which under ISO/IEC 17021-1 may not provide consultancy. We provide consulting, training, internal and supplier audits, and support you through the certification body’s audit.
Can you work with us as a subcontractor or partner?
Yes. Alongside direct engagements, we deliver named workstreams under a partner’s brand and client relationship — ISMS documentation, gap analysis, internal audit, supplier remediation — and take the Türkiye-side work for Slovak and Romanian firms whose clients have Turkish suppliers.
Let us start with a scoping conversation
Thirty to forty-five minutes is usually enough to establish scope, a realistic timeline, and whether we are the right people for the work.