Cybersecurity regulation readiness
The opening question: does Turkey's Cybersecurity Law or your sector regulator reach you directly, or only because you supply goods or services to critical infrastructure operators? From there, a risk analysis, an incident response plan, supplier security, logging and a set of documents structured along ISO 27001 lines that you can produce whenever someone asks.