Data · Cybersecurity · Compliance · AI
Security that drives growth.
We organize data, secure systems and roll out AI so that you can show every business process and every control in your systems. We work with companies that have to demonstrate compliance with NIS2, DORA or the AI Act. Every engagement starts with a fixed-scope first step of 4 to 6 weeks.
// Areas
Four areas, one accountable team
Data and cybersecurity work falls apart in silos, so we plan every project around the whole company from day one. There is no AI without security, no security without governance and no reliable data without standards. Every project team includes someone with at least 10 years in IT.
01Data
Data with an owner, a definition and a change history
Nobody can tell you within an hour which reports break when one table changes. We sort out owners, definitions and lineage, and the same metadata then serves both AI and the auditor.
- Data catalog with owners
- Documented definitions and data lineage
- Impact analysis in change management
- One agreed definition per KPI
- Register of data flows to third parties
Data governance and metadataFirst step, 5 weeks
One flow, end to end
- Flow map with owners
- Control gaps and a 90-day roadmap
Key deliverable: a working data catalog for one domain
02Cybersecurity
Tests that check real attack paths
Too often a scanner sets the order of fixes instead of business impact. We validate attack paths by hand, so you fix what an attacker would actually use.
- Attack surface and dependency map
- Manual validation of real attack paths
- Review of permissions and integrations
- Priorities set by business impact
- A retest of every fix, not a promise that it is closed
Penetration testingFirst step, 4 weeks
One system and its integrations
- Attack surface and dependency map
- Backlog with owners and dates
Key deliverable: at least one critical path closed
03Compliance and audit
From gap to evidence, step by step
A policy that never makes it into your systems does not protect your company. It is just a document. We help you turn the requirements of NIS2, ISO/IEC 27001 and DORA into concrete work: every task has an owner and a deadline, controls run in your systems, and the evidence is ready before the auditor arrives.
- Gap analysis against one framework
- Obligations register with owners
- Controls documented and implemented in your systems
- Audit-ready evidence
- Answers to customer security questionnaires
Compliance and auditFirst step, 5 weeks
One framework, without rewriting everything
- Gap analysis with priorities
- Obligations register and a 90-day roadmap
Key deliverable: one control implemented in a system, with its evidence
04AI
An approved path for AI instead of bans
A ban does not protect your company, because people will switch to personal accounts anyway. We start with strategy: where AI delivers real value, which risks you are prepared to accept and in what order you scale what works. Then we set up access, data filtering and logging so that the approved tools are simply easier to use than a personal account. We also test the security of applications built on LLMs.
- AI strategy: use cases with real value and acceptable risk
- Inventory of AI tools and use cases
- Risk classification and vendor role
- Access that mirrors existing permissions
- Data filtering and event logging
- Security testing of LLM apps and agents
AI governance and securityFirst step, 6 weeks
One approved AI path
- AI use inventory and vendor assessment
- Assessment of a private option for one use case
Key deliverable: an approved path with access control and logging in one department
// Deadlines
Dates worth having in your calendar
Each date comes from the legal text and links to its source. On the first call we tell you plainly what needs work now and what can wait.
Machinery
Machinery Regulation
Regulation (EU) 2023/1230 applies from this date, including the requirement to protect machinery against corruption (tampering) through connected devices and software (Annex III, 1.1.9).
EUR-Lex 2023/1230 (opens in a new tab)KSC
NIS2 in Poland (KSC): Chapter 3 obligations
ISMS, risk management, incident handling, business continuity, supply chain, asset management and yearly management training (Article 33(1) of the 2026 amending act).
Dz.U. 2026 item 252 (opens in a new tab)AI Act
High-risk AI systems under Annex III
The date was moved by Regulation (EU) 2026/1744. Systems under Annex I (EU product legislation) follow on 2 August 2028.
EUR-Lex 2026/1744 (opens in a new tab)CRA
Cyber Resilience Act fully applies
Requirements for products with digital elements. Reporting of vulnerabilities and incidents has applied since 11 September 2026.
European Commission, CRA (opens in a new tab)KSC
First KSC audit deadline for essential entities
Applies to entities that were already essential on 3 April 2026 (Article 33(2) of the amending act). From this date the authority can also impose most administrative fines (Article 35 of the amending act).
gov.pl, KSC deadlines (opens in a new tab)
As of . Sources: Dz.U. 2026 item 252 (Polish KSC Act), gov.pl, KSC deadlines, Regulation (EU) 2026/1744, Regulation (EU) 2023/1230, European Commission, CRA.
// Product: FutureCode Evidence Box
Compliance evidence straight from your systems
FutureCode Evidence Box runs inside your network, with no internet access. It collects evidence read-only from cloud services, identity systems, endpoints, code repositories and configurations, then maps the findings to selected ISO/IEC 27001 and NIS2 requirements.
A human signs off the result: an auditor reviews the exception queue, and the evidence pack is sealed after sign-off. A sample readiness report built on fictional data shows what you get.
// How we work
From the first step to a working control
The same process sits under every engagement. The first stage matters most, because it decides whether the next ones make sense.
Assessment
4 to 6 weeks with a fixed scope: one data flow, one system, one department or one framework. You get one working result and a 90-day roadmap.
Pilot
We extend what worked, measured against success criteria agreed up front, not after the fact.
Implementation
The control goes into the process, not into a binder. The framework and documentation stay with you.
Operate and improve
Reviews, retests and updated evidence before the next audit. We measure what we agreed at the start.
// Why us
Decisions we stick to
Each of them costs us something, which is why you will find them in the contract, not just on this page.
01Team
Senior people only
We don't put juniors on your systems. Everyone on the project has at least 5 years of hands-on experience in their field, and we can name the team in the contract.
02Partner
A partner on the project
There is no account-management layer. The person who agrees the scope with you runs the project through to the end.
03Scope
Fixed scope and date
Scope, date and price are agreed in writing before we start. The first step takes 4 to 6 weeks, and there are no surprise invoices.
04Capacity
One assessment per area
We never run two assessments in the same area in parallel. If we can't start on your date, we say so right away.
05Retest
Retest at no extra cost
After a penetration test, we retest your fixes without charging for it. A finding is closed by a test result, not by someone saying so.
06Independence
Someone else runs the formal audit
We don't perform formal KSC audits under Article 15. We prepare you for them, implement the controls and support you day to day. The auditor has to be independent of whoever implemented the controls, so we tell you plainly who can audit you and who cannot.
// Credentials
Team credentials
Our team includes certified auditors as well as data and security engineers. We have built data systems and software for more than 10 EU clients (as of September 2026). Below are the certifications our team holds. When we agree the scope, we show you which of them the people on your project have.
Certifications held by our team
- CISA (Certified Information Systems Auditor)ISACA
- IODO (Polish data protection officer certificate)
- CompTIA Security+CompTIA
- ITILAXELOS / PeopleCert
- REQBRequirements Engineering Qualifications Board
- SAFeScaled Agile
- ISTQBInternational Software Testing Qualifications Board
- Databricks
- Snowflake
- Azure
- AWS
- SQL Server
- Hadoop
- dbt
- Airflow
- Prefect
From the blog
Data, security, compliance and AI
We write the way we work: specific, dated and sourced. Here are the latest posts from our four main topics.
// FAQ
Questions we hear most often
Where do we start if we don't know whether NIS2 applies to us?
With your sector and the size thresholds. We check both on one call and confirm the result in writing. In Poland, self-registration in the register of essential and important entities is due by 3 October 2026, and the authority can also add a company on its own initiative. In Germany, NIS2 has applied through the new BSIG since 6 December 2025 (as of 24 September 2026).
If it applies, we start with a gap analysis: 5 weeks, fixed scope. Details: NIS2 compliance in Poland (KSC).
Our industry pages show which rules apply in manufacturing, logistics, energy and water, finance and telecom.
How long does the first step take, and what does it cost?
4 to 6 weeks, depending on the area. We quote the price before we start, together with the written scope and date, and there are no surprise invoices. We can give you a range on the first call, once we know which system or framework is involved.
Do you perform formal KSC audits?
No. We prepare you for the KSC audit, implement the controls and provide ongoing support. A formal audit under Article 15 of the Polish KSC Act (NIS2 in Poland) is carried out by an accredited conformity assessment body, at least two qualified auditors or a sectoral CSIRT.
The auditor has to be independent of whoever implemented your controls (Article 15(2a)). We tell you who can audit you and who cannot. As of 24 September 2026.
Does our data leave the company?
It doesn't have to. FutureCode Evidence Box runs inside your network with no internet access and receives updates from physical media. Personal identifiers such as Polish PESEL (national ID) and NIP (tax) numbers are masked before they are stored, and every engagement has its own encryption key.
We don't paste client data into public AI tools. Our rules are on the How we use AI page.
Do you work with companies outside Poland?
Yes. We work with companies in Poland, the DACH region and the rest of the EU. For groups with sites in several countries, we bring the obligations from the Polish KSC Act and the German BSIG into one plan, since both implement the same NIS2 directive.
Tell us what's blocking you.
We reply within one business day with questions about scope and a rough timeline. The call is about your problem, not a sales pitch.
Book a 30-minute call (opens in a new tab)Prefer to write?
Describe the system or regulation you're dealing with. We'll come back with questions and a proposed first step.
Write to us


