NIS2/KSC audit and implementation

Prepare your organisation for NIS2 requirements

We support entity self-identification, gap analysis and implementation of risk management, supply-chain security and incident handling under NIS2 and the Polish National Cybersecurity System Act.

Cosmic visualisation of resilient infrastructure, a secure supply chain and NIS2 incident protection

Current obligations

NIS2 in Poland: from self-identification to an operational ISMS

The amendment to the Polish National Cybersecurity System Act entered into force on 3 April 2026. The scope of duties depends on the sector, the entity’s actual activities, its size and specific statutory criteria.

Entity self-identification

We analyse the entity’s actual activities, statutory sectors, size and applicable exemptions to assess whether it is an essential or important entity.

Registration and schedule

We organise the data required for registration and prepare an implementation plan aligned with statutory deadlines.

Security management system

We design roles, policies, risk assessment, supplier oversight, business continuity and metrics required to maintain cyber resilience.

Management accountability

We prepare approval rules for security measures, risk reporting and training that support informed decisions by management bodies.

NIS2 compliance audit

We assess the organisation, its technology and implementation evidence

Our gap analysis is not merely a list of legal provisions. Each gap is connected with a risk, owner, recommendation and target date.

Process and infrastructure audit

We assess asset, access and vulnerability management, backups, cryptography, business continuity and safeguard effectiveness.

Supply-chain security

We assess supplier criticality, contractual requirements, risk monitoring and procedures for events affecting ICT partners.

Incident handling and reporting

We develop event classification, escalation paths, evidence records and communications required for timely reporting.

Training and exercises

We prepare management and operational teams and test procedures through exercises and internal audits.

Action plan

NIS2 implementation path

01

Self-identification

We analyse the entity’s actual activities, statutory sectors and entity types, enterprise size and any specific qualifying criteria. We determine its potential status as an essential or important entity and identify the services, processes, organisational units and material dependencies within scope.

02

Gap and risk analysis

We compare the current state with NIS2 and Polish KSC requirements, assessing risk management, assets, incidents, business continuity, suppliers, vulnerabilities, access and existing safeguards. The results form a prioritised action plan with owners and deadlines.

03

Implementation

We design and launch the security management system, roles, policies, procedures, safeguards, and incident handling and reporting processes. We support management and team training and collect evidence demonstrating fulfilment of the applicable obligations.

04

Maintenance and audit

We monitor metrics, risks, incidents, suppliers and corrective actions, and update the arrangements following organisational or technological changes. We conduct internal audits and tests to maintain inspection readiness and the continuing effectiveness of the implemented measures.

Engagement outcome

What does the client receive?

Deliverables are tailored to the entity’s status, operating profile, risk and the agreed support model.

Documented self-identification

An analysis of the applicable criteria, covered services and organisational units, with reasoning supporting the potential essential or important entity status.

Gap and risk assessment report

Findings concerning processes, technology and implementation evidence, linked to risks, priorities and recommended treatment.

Obligation implementation roadmap

An action plan with owners, deadlines, dependencies and acceptance criteria covering organisational, technical and reporting requirements.

Procedures and implementation evidence

Documentation for risk, supplier, incident and business continuity management, together with organised evidence of fulfilment.

Frequently asked questions

FAQ: NIS2 and Polish KSC legislation

Does NIS2 already apply in Poland?

Yes. The Polish amendment implementing NIS2 entered into force on 3 April 2026.

Who is covered by NIS2 requirements?

The requirements primarily apply to essential and important entities operating in statutory sectors. The assessment requires analysis of the entity’s actual activities, size, the applicable annex and specific statutory criteria.

Which deadlines are most important?

For entities meeting the criteria when the amendment entered into force, relevant dates include the deadline for submitting an application for entry in the register by 3 October 2026 and implementing security obligations by 3 April 2027. Each deadline should be confirmed for the specific circumstances.

What does a NIS2 audit cover?

The scope is tailored to the organisation. It typically covers risk management, assets, incidents, business continuity, suppliers, vulnerabilities, access, backups, training, management accountability and implementation evidence.

Does ISO 27001 certification prove NIS2 compliance?

ISO 27001 can strongly support systematic information security management, but it does not automatically confirm fulfilment of every NIS2 or Polish KSC obligation.

Related areas

Build one security and compliance system

ISO 27001 implementation

ISMS, risk analysis, readiness audit and continual information security improvement.

Learn more →

GDPR audit

Personal data protection, controller and DPO roles, breaches and data protection by design.

Learn more →

NIS2/KSC — official information

Read the Polish Ministry of Digital Affairs notice on the amendment and implementation dates.

Learn more →

Ready for a security audit?

Contact us for a free 30-minute initial consultation.

Book a consultation ↗