Skip to content
Müşavir

Compliance

Our certification roadmap, with today's status

We do not hold a certificate for any standard today, and we do not hide it. Below we publish the quarter in which we aim to be ready for each standard and how far preparation has progressed. When an item is completed, this page is updated with the independent audit details.

Write to us

Compliance roadmap

None of these items is a completed certification. The percentage is the estimated progress of internal preparation; quarters are targets and may change.

2026 Q4

VERBİS obligation assessment and registration

Assessing the registration obligation, data inventory, retention and destruction policy, registration if required

%55

2027 Q1

ISO 9001

Quality management system, roadmap

%30

2027 Q1

EU AI Act readiness

Assessment of risk classification and transparency obligations

%40

2027 Q2

ISO/IEC 27001

Information security management system, roadmap

%35

2027 Q3

ISO/IEC 27701

Privacy information management, roadmap

%20

2027 Q4

ISO/IEC 42001

AI management system, roadmap

%15

2027 Q4

SOC 2 Type II

Observation period and independent audit, roadmap

%10

What the standards mean

The table explains the scope of each standard and what it changes for you. The status column shows today's reality.

StandardScopeWhat it means for youStatus today
VERBİS obligation assessment and registrationAssessing the Data Controllers Registry obligation, a personal data inventory and registration if requiredAn official record of which data we process, why and for how longRoadmap
ISO 9001Quality management systemDefined and measured support, release and change processesRoadmap
EU AI Act (2024/1689)Risk-based rules for AI systemsDocumented risk class and transparency obligations for the assistantsReadiness assessment
ISO/IEC 27001Information security management systemIndependent audit of risk assessment, access, incident management and supplier controlsRoadmap
ISO/IEC 27701Privacy information management on top of 27001Audit of controls in both the controller and processor rolesRoadmap
ISO/IEC 42001AI management systemResponsible development and monitoring of AI featuresRoadmap
SOC 2 Type IIEffectiveness of security and availability controls over a periodAn auditor's report that the controls actually worked for monthsRoadmap

Frequently asked questions

Which certifications does Müşavir hold today?

None. Every item on this page is a roadmap item. When we obtain a certificate, we will announce it here with the certification body and scope.

What do the percentages show?

The estimated progress of internal preparation: writing policies and procedures, risk assessment, implementing controls and collecting evidence. They do not reflect an independent audit result.

Can you answer our security questionnaire without a certificate?

Yes. We answer your questionnaire in writing based on the actual practices on our security and data processing pages; if we do not yet apply a control, we say so.

Why is SOC 2 Type II last?

A Type II report audits that controls worked throughout an observation period lasting months. The controls within the 27001 scope need to be in place first, then the observation period can start.

Related

Send us your compliance questions

Let us go through the documents and controls your procurement process asks for together.

Write to us