Skip to main content

infosecacademy Eğitim Danışmanlık Hizmetleri

NIS2 · ISO management systems · vCISO · Data protection

NIS2 and ISO compliance for European organisations — and their suppliers in Türkiye

NIS2 programmes, ISO/IEC 27001 and related management systems, virtual CISO leadership and GDPR transfer work for organisations across the European Union. Every engagement is led personally by our founder, a Lead Auditor in six ISO standards.

NIS2ISO 27001ISO 27701ISO 22301ISO 42001GDPRKVKK
In one sentence
We take European organisations from “we are in scope and we are not sure what that means” to documented, auditable compliance — and we do the same for their suppliers in Türkiye.
Why programmes fail

Where compliance programmes fail

Most organisations do not fail NIS2 or ISO/IEC 27001 because of technology. They fail for four reasons we see repeatedly — and design our engagements to prevent.

The paperwork does not match the operation

Templates are bought, renamed and filed. The auditor asks for evidence that the procedure was followed and there is none. We write documentation from your actual processes, and build the evidence trail with it.

OT is quietly left out of scope

In manufacturing, production and control systems are treated as “not IT” and excluded. Under NIS2 and the national decrees they are squarely in scope. We treat OT/ICS as a first-class domain with its own policy, categorisation and risk treatment.

Supplier contracts cannot carry the obligation

An entity commits to a 24-hour early warning while its critical IT supplier may notify it days after an incident is resolved. We check supplier notification timelines against the statutory clock and remediate the contracts.

Nobody owns it after go-live

The consultant leaves, the management review is never held, the risk register ages. We hand over a running system — audit programme, review calendar, metrics — and stay available through the first cycle.

Compliance that cannot survive its first management review was never compliance. It was a document set.
The Türkiye–EU supply chain bridge

Your supplier is in Türkiye. Your regulator is not.

NIS2 Article 21(2)(d) makes you responsible for the security of your suppliers. A large share of European manufacturing supply chains runs through Türkiye, and almost no consultancy works fluently on both sides of that line.

1

consultant, both jurisdictions — no coordination gap between an EU adviser and a local one

2

working languages for supplier engagement: English and Turkish

0

EU adequacy decisions covering Türkiye — every transfer needs the full package

24h

NIS2 early warning — achievable only if your supplier is obliged to report to you first

We assess the Turkish supplier against your obligations, in Turkish and on site; remediate the contract and its notification timelines; build the GDPR transfer package; and reconcile it with Turkish KVKK — as one consultant, in both jurisdictions.

Delivered programmes

Two NIS2 programmes in two member states

Described without identifying the clients. In both, the national act was more decisive than the directive itself.

Slovakia — automotive components manufacturer

Important entity under NACE C29.3, in scope through NIS2 Annex II. End-to-end NIS2 and ISO/IEC 27001:2022 programme: cybersecurity strategy, risk management process and tool, a Statement of Applicability mapping all 93 Annex A controls to NIS2 and the Slovak Act, and a separate OT/ICS security policy.

The IT services agreement with the Turkish parent-group provider was remediated: a notification trigger of “three business days after resolution” was replaced with a 12-hour, detection-triggered outer limit.

NIS2ISO/IEC 27001:2022OT/ICSSupply chain

Romania — NIS2 compliance programme

Completed under GEO 155/2024 and the DNSC registration regime: scope determination, gap analysis against the national requirements, and the documented management system built within the statutory deadline sequence.

Policies at 120 days, risk analysis and measures at six months, first external audit at twelve months. We planned backwards from the audit date, not forwards from the kick-off.

NIS2GEO 155/2024DNSC
The principal consultant

Kuzey AKSU

Founder and Principal Consultant of Infosec Academy, and a Lead Auditor in six ISO standards. Over 25 years in IT and information security, fifteen of them leading security and infrastructure functions inside multinationals in banking, insurance, online financial services, industrial holdings, port operations, aviation maintenance and manufacturing.

He has built and run information security programmes from the ground up five times, and has been the person accountable during internal and external audits rather than the adviser standing beside them. Every engagement is led by him personally.

Having built the kind of programmes I now assess changes what I look for — and what I am willing to accept as evidence.Kuzey AKSU

Organisations where our founder held roles

  • Citibank
  • CIGNA Life Insurance
  • GKFX
  • Yıldırım Holding
  • Mersin International Port
  • myTECHNIC
  • BSH Home Appliances Group
  • HP Türkiye
  • Habboush Group
  • Coral Travel
  • ATP

These are organisations where our founder was employed during his career. They are not client references.

How we engage

Direct, as a partner, or on retainer

We work directly with end clients, and as a delivery partner or subcontractor to consultancies, law firms and IT service providers who need specialist capacity. Every proposal starts with a written scope — before any commercial figure is discussed.

What we will tell you honestly

  • If your deadline is not achievable with the scope you want, we will say so at the scoping stage and propose what can realistically be completed first.
  • If part of the work is better done by your own team with our oversight — and it often is, because they will have to run it afterwards — we will structure the engagement that way and price accordingly.
  • If a standard or a framework is not going to help you, we will not sell it to you.
Frequently asked questions

Questions we are asked

Does NIS2 apply to our suppliers in Türkiye?

NIS2 applies directly to entities established in the EU, but Article 21(2)(d) makes them responsible for the security of their supply chain. Turkish suppliers of ICT services, components or engineering support therefore meet NIS2-derived security and notification obligations through their contracts. We assess and remediate those relationships on both sides.

Is NIS2 a certification?

No. There is no NIS2 certificate and no accredited body that signs you off. A supervisory authority can ask at any point for evidence that the Article 21 measures are implemented and that the management body approved and oversees them. Where you also want a certificate, we run the programme so that ISO/IEC 27001 certification comes out of the same work.

How long does a NIS2 or ISO/IEC 27001 programme take?

Typically four to nine months, depending on entity size, OT footprint and how much documentation already exists. We plan backwards from the audit or statutory deadline, and if your date cannot be met with the scope you want, we say so in the scoping call.

Does Infosec Academy issue ISO certificates?

No. Certificates are issued by accredited certification bodies, which under ISO/IEC 17021-1 may not provide consultancy. We provide consulting, training, internal and supplier audits, and support you through the certification body’s audit.

Can you work with us as a subcontractor or partner?

Yes. Alongside direct engagements, we deliver named workstreams under a partner’s brand and client relationship — ISMS documentation, gap analysis, internal audit, supplier remediation — and take the Türkiye-side work for Slovak and Romanian firms whose clients have Turkish suppliers.

Let us start with a scoping conversation

Thirty to forty-five minutes is usually enough to establish scope, a realistic timeline, and whether we are the right people for the work.