SPK Penetration Test Requirement: What Should Portfolio Management Companies Do?
March 18, 2026, 3:02 p.m.

SPK's Penetration Test Requirement for Portfolio Management Companies

The Capital Markets Board (SPK) has imposed significant cybersecurity obligations on portfolio management companies under Communiqué No. VII-128.10 on Information Systems Management Procedures and Principles. Published in the Official Gazette dated 13.03.2025 and numbered 32840, this Communiqué entered into force on 30.06.2025, making it mandatory for institutions to regularly test their information systems security.

The Capital Markets Association of Turkey (TSPB) has additionally informed member institutions about this obligation through its General Letter.

Which Companies Are Subject to This Obligation?

All portfolio management companies subject to paragraphs (a), (b) and (c) of the first clause of Article 28 of SPK's Communiqué No. III-55.1 on Portfolio Management Companies; every institution with an activity authorization certificate must fulfill this obligation.

Institutions that may fall within this scope include:

  • Portfolio management companies
  • Fund management companies
  • Crypto asset service providers (subject to separate regulations)

According to Which Communiqué Will Penetration Testing Be Performed?

Within the scope of the transition process, pursuant to provisional Article 1 of the new Communiqué No. VII-128.10, the provisions of the old communiqué, Communiqué No. VII-128.9 on Information Systems Management (Repealed Communiqué), continue to be applied until 31.12.2025.

Therefore, portfolio management companies must have their 2025 penetration tests conducted in accordance with the procedures and principles in the Repealed Communiqué.

Important Calendar for 2025

  • 13.03.2025: New Communiqué No. VII-128.10 published in the Official Gazette
  • 30.06.2025: Communiqué entered into force
  • 31.12.2025: End of transition period — penetration tests will be conducted according to old provisions until this date
  • After 2025: Compliance with VII-128.10 and new procedures/principles mandatory

How Should Penetration Testing Be Conducted? What Should It Cover?

Penetration tests under SPK are not merely technical security scans; they are systematic security assessments covering the institution's entire information system infrastructure. They are typically expected to cover the following areas:

  • Internet Banking / Customer Portals: Web application and API security testing
  • Internal Network Infrastructure: Local network, Active Directory and server security
  • External Attack Surface: Internet-facing IPs and services
  • Mobile Applications: iOS/Android investment applications
  • Social Engineering: Phishing simulations

Is TSE Approved Company Mandatory?

SPK requires penetration tests to be conducted by competent and independent organizations. In practice, obtaining services from companies accredited according to TSE 13638 standard is the safest approach in terms of acceptance during audits.

⚠️ Attention: Portfolio management companies that fail to have penetration testing conducted by the end of 2025 may face non-compliance findings in SPK audits and be subject to administrative sanctions.

How Should Penetration Test Reporting Be Done?

Elements that penetration test reports under SPK should include:

  1. Executive Summary: Critical findings and overall risk assessment
  2. Technical Findings: CVSS score, description and evidence for each vulnerability
  3. Risk Classification: Critical / High / Medium / Low
  4. Corrective Action Plan: Recommended solution and priority for each finding
  5. Retest Report: Verification of remediated vulnerabilities

Difference from BRSA: Penetration Testing Under SPK

Although banks under BRSA and portfolio management companies under SPK are subject to similar obligations, there are some differences:

Criteria BRSA SPK
Regulatory Authority Banking Regulation and Supervision Agency Capital Markets Board
Scope Banks, participation banks, finance companies Portfolio management companies, brokerage houses
Related Communiqué Information Systems Regulation Communiqué No. VII-128.10
Period At least once a year At least once a year (after new Communiqué)

SPK Compliant Penetration Testing with Nordis Global

As Nordis Global, we offer specialized penetration testing services for portfolio management companies under SPK. Our TSE approved and ISO 27001 certified team works not only with technical testing but also with a comprehensive reporting package that will be accepted in audits.

  • ✅ TSE 13638 accredited penetration testing
  • ✅ Report format compliant with SPK reporting standards
  • ✅ Retest (re-verification) included
  • ✅ Executive summary for the board of directors

To meet your 2025 penetration testing obligation on time, contact us immediately.

Similar Posts