Certification of the GTS of the Republic of Kazakhstan

Preparation and certification of state technical means of Kazakhstan.

Preparation and support for the certification of information systems and information facilities for compliance with the information security requirements of the Republic of Kazakhstan. Full cycle: from preliminary audit to obtaining the Certificate of Compliance.

What is GTS RK Certification

Certification is a mandatory procedure for confirming that information systems and information facilities comply with information security requirements established by the legislation of the Republic of Kazakhstan. The procedure is carried out by the State Technical Service (GTS) and includes a comprehensive assessment: from source code and architecture analysis to load testing and evaluation of information security functions.

Without a Certificate of Compliance, an information system cannot be put into production if it belongs to a category of facilities subject to mandatory certification.

Regulatory Framework

Law of the Republic of Kazakhstan “On Informatization”

The primary legal document establishing the procedure for certification of information facilities.

Unified Requirements (Resolution of the Government of the Republic of Kazakhstan No. 832)

Detail the technical and organizational requirements in the field of ICT and information security.

ST RK ISO/IEC 27002-2023

Mandatory standard for government bodies when organizing information security.

ST RK ISO/IEC 15408 and ST RK 1073

IT security evaluation criteria and requirements for cryptographic information protection.

Certification Preparation Stages

01

Preliminary Audit

Comprehensive assessment of the current state of the information system. We determine the level of compliance with the Unified Requirements and identify discrepancies that need to be addressed.

02

Development of Information Security Documentation

We create a complete documentation package: information security policy, access management procedures, instructions, backup plans, and incident response procedures.

03

Bringing the System into Compliance

Configuration of antivirus controls, access management systems, backup solutions, security event logging, and monitoring tools.

04

Test Preparation

Internal assessment based on the GTS methodology: testing information security functions, load scenarios, and security controls. We address any findings before submitting the application.

05

Certification Support

We prepare the application and complete documentation package for the GTS. We coordinate with the testing laboratory and respond promptly to requests. We support you through to obtaining the Certificate of Compliance.

What You Will Receive

  • Certificate of Compliance — an official document confirming that the information system complies with the information security requirements of the Republic of Kazakhstan.
  • Information Security Documentation Package — a complete set of policies, procedures, and instructions updated in accordance with legislative requirements.
  • Test Report — technical testing results with a detailed description of the verified security functions.
  • Roadmap — a plan for maintaining compliance with information security requirements after certification.
  • Expert Support — information security consultations for 3 months after obtaining the certificate.

Why SAQTEK

Expertise in Kazakhstan’s Legislation

In-depth knowledge of Kazakhstan’s information security regulatory framework. We monitor regulatory changes and promptly adapt our approach.

Comprehensive Approach

We do not simply prepare documentation — we actually bring the system into compliance so that certification can be successfully completed on the first attempt.

In-House Information Security Products

When necessary, we integrate solutions from our portfolio (SIEM, DLP, EDR) to address identified compliance gaps.

Post-Certification Support

We help maintain ongoing compliance with information security requirements. Continuous support and consultations.

Ready for Certification?

Submit a request — our engineer will conduct a free express assessment of your information system’s readiness for certification and explain the next steps.

Submit a Request →