A typical digital forensics report is between 30 and 80 pages. In comprehensive cases, files involving multiple devices or a large amount of supplementary evidence exceed 150 pages. The report includes an evidence record compliant with the ISO 27037 chain, methodology, the hash chain, findings, conclusion, and appendices. A CMK 67-73 (Code of Criminal Procedure) expert opinion is presented in this format.

TL;DR

  • Standard digital forensics report: 30-80 pages.
  • Comprehensive case (10+ devices, multi-tenant examination): 150-300 pages.
  • Mandatory sections: cover, summary, methodology, findings, conclusion, appendices, hash list.
  • Compliance with ISO 27037 and NIST SP 800-86 methodology is critical for admissibility in court.
  • A CMK 67-73 expert opinion is submitted with the sworn expert's signature and a copy of the diploma.

Detailed answer

How the report length is determined

The page count of a digital forensics report is directly proportional to the number of devices examined, the number of case questions addressed, and the volume of findings. The principle is the individual documentation of concrete findings, not page inflation. The table below is produced from DSET case records of the last 24 months.

Case type Typical pages Number of devices Duration
Single phone, message/media examination 25-40 1 3-7 days
Single computer, email or stolen data 35-60 1 5-10 days
Employee misuse (HDD + phone + USB) 60-100 3-5 10-20 days
Post-incident examination of ransomware 80-150 5-15 15-30 days
Multiple suspects, corporate investigation 150-300+ 10+ 30-60 days

Standard report template (DSET, ISO 27037 compliant)

  1. Cover and identification. Report number, date, requesting authority, expert name and title, total page count, confidentiality class.
  2. Executive summary (1-2 pages). The case question, the method in brief, the main findings, the conclusion statement. Judges and lawyers read this section quickly.
  3. Legal framework. References to CMK 67, 68, 69, 70, 73; the Expert Witness Law (Bilirkisilik Kanunu), Article 12 of the KVKK, and USOM regulations.
  4. Chain of custody. The device receipt record, visual records, serial number, transport case seal.
  5. Methodology. Hardware used (write blocker, FTK Imager, Tableau), software (Cellebrite UFED, Magnet AXIOM, Autopsy, Volatility, X-Ways), version numbers, license information.
  6. Hash chain. The MD5/SHA-1/SHA-256 values of the original device, comparison before and after imaging. A minimum of SHA-256 is recommended per NIST SP 800-86.
  7. Findings. Each case question is a separate subheading. Screenshots, log excerpts, file paths, timestamps (UTC + local).
  8. Interpretation and conclusion. The expert opinion, degrees of certainty (certain, highly probable, possible, indeterminate). No speculation is made.
  9. Appendices. Hash list, file inventory, log dumps, tool version certificates, the expert's resume and a copy of the diploma.

The difference of a CMK 67-73 expert opinion

A court-appointed expert report (bilirkisi raporu) is prepared upon assignment by the court, whereas an expert opinion (uzman mutalaasi) is prepared at a party's request. Pursuant to CMK 67/6, the parties may submit their own expert opinion to the case file. The opinion is not as binding as a court-appointed expert report; however, in Yargitay (Court of Cassation) decisions it is seen that when an opposing opinion satisfies the judge, it leads to the appointment of a new court expert. DSET opinions include references to ISO 27037 and NIST SP 800-86 together with the expert's expert-witness regional list number and a copy of the diploma.

Characteristics of a report rejected in court

Common characteristics of reports rejected or returned in the decisions of the 8th and 12th Criminal Chambers of the Yargitay:

  • Missing hash value. A report is not accepted without the mathematical proof showing that the evidence has not changed.
  • No write blocker used. Not using a write blocker during imaging raises suspicion that the evidence could have been altered.
  • No methodology stated. Saying "an examination was carried out" is not enough; which software, which version, and which steps must be documented.
  • Speculative interpretation. Instead of "it is probable that the defendant did it," one writes "the following operation was recorded under this user account at this time."
  • Timestamp inconsistency. Failure to distinguish between local time, UTC, and device time.

Hash chain example (report appendix)

Device: Western Digital WD10EZEX, S/N: WD-WCC6Y2KZ8R0L
Image file: case-2026-117.E01
MD5     : 8a3f9b2c7e1d4a6b8c5e9f0a1b2c3d4e
SHA-1   : 5f8a7b9c2d3e4f1a6b8c9d0e1f2a3b4c5d6e7f8a
SHA-256 : 3a7c9e2b4d8f1a6c3e5b7d9f1a3c5e7b9d1f3a5c7e9b1d3f5a7c9e1b3d5f7a9c
Operator: Expert M.D., expert-witness registry no 12345
Date    : 2026-06-01 14:32 UTC+03
Write blocker: Tableau T356789, FW v3.21
Imaging tool: AccessData FTK Imager 4.7.1

DSET report writing guide

At DSET, every report goes out after a two-stage double review (peer review). The first expert compiles the findings, and the second expert checks the hash verification and methodology compliance. This step is intended to meet the Yargitay's "objective assessment" criterion.

Related resources: incident response flow /en/rehber/siber-olay-mudahale-playbook-nist-800-61-checklist, KVKK breach notification flow /en/rehber/kvkk-72-saat-veri-ihlali-bildirim-sablonu, first 24 hours after ransomware /en/rehber/fidye-yazilim-ilk-24-saat-aksiyon-cizelgesi.

Frequently Asked Questions (FAQ)

How long does it take to prepare a digital forensics report?

A standard single-device case is completed in 5-10 business days, and multi-device cases in 15-30 business days. With the emergency service these times can be cut in half.

How many hash algorithms should be used for the report?

NIST SP 800-86 recommends a minimum of SHA-256. DSET reports MD5, SHA-1, and SHA-256 together; this provides both legacy tool compatibility and cryptographic security at the same time.

Is an expert opinion accepted by the court?

Pursuant to CMK 67/6, the parties may submit an expert opinion to the case file. The judge assesses the opinion freely. A solid opinion may lead to a re-examination of the existing court-appointed expert report.

Who can sign the report?

Experts registered in the Expert Witness Regional List of the Ministry of Justice, holding a degree and certification in the information technology field, sign the report. The DSET team consists of experts certified in CHFI, GCFE, and EnCE.

Is a separate report required in a KVKK breach investigation?

Yes. Under Article 12 of the KVKK, the technical measures taken by the data controller and the scope of the breach must be documented in a separate digital forensics report. This report is used as an annex to the notification submitted to the Board within 72 hours.


DSET Digital Forensics Laboratory Hacettepe Teknokent, Beytepe, Ankara ISO 27001, ISO 27037 methodology, CHFI/GCFE/EnCE experts Phone: +90 536 662 38 09, Email: [email protected] 20+ years of court experience.