March 18, 2026, 3:02 p.m.
Why Is BDDK Penetration Testing Mandatory?
The Banking Regulation and Supervision Agency (BDDK) mandates periodic penetration tests to supervise the information systems security of banks and financial institutions. This requirement is regulated under the Regulation on Banks' Information Systems and Electronic Banking Services.
Which Tests Should Be Conducted Under BDDK Scope?
According to BDDK regulations, banks are required to conduct the following penetration tests:
- Network Infrastructure Tests: Internal and external network security assessment
- Web Application Tests: Internet banking and API security tests
- Mobile Application Tests: iOS and Android banking applications
- ATM Security Tests: ATM network and software security
- Social Engineering: Phishing simulations targeting employees
How Often Should BDDK Penetration Testing Be Conducted?
Under BDDK regulations, penetration tests must be conducted at least once a year. Additional tests may be required during critical system changes or new product launches.
Reporting and Audit Process
BDDK penetration test reports must be prepared for the institution's internal audit processes and should include the following elements:
- Executive Summary (critical findings)
- Technical Details (vulnerability descriptions, CVSS scores)
- Risk Rating (Critical/High/Medium/Low)
- Corrective Action Plan
- Verification (Retesting) Report
TSE Certified Firm Requirement
BDDK requires penetration tests to be conducted by firms accredited according to TSE 13638 standard. Test reports obtained from non-TSE certified firms may not be accepted during audits.
Nordis Global is a TSE-certified cybersecurity firm with experience in BDDK-compliant penetration testing services. For detailed information, contact our experts.
Similar Posts