NIS2 · ISO/IEC 27001 · DORA · CRA
Compliance and audit: one framework at a time, from gap to evidence
NIS2, DORA, the Cyber Resilience Act and customer security questionnaires all land at once, while the evidence is scattered across systems and nobody owns it. We take one framework at a time, find the gaps and the owners, implement controls in your systems and collect evidence that holds up in front of an auditor.
// In short
A policy you cannot show in the system is not a control.
It is a document about a control. So we build compliance with NIS2 in Poland (KSC), DORA, the CRA and ISO/IEC 27001 from the systems up: a gap analysis against one framework, an obligations register with owners, controls in identity, cloud and data, and evidence from logs and configuration. We work with manufacturing, logistics, energy, financial and telecom companies.
// Pick a framework
One framework at a time, starting with the nearest deadline
We set the order by deadlines, customer contracts and what already works. Most controls carry over to the next one. Where your group or a customer expects a different framework, we also work to NIST CSF 2.0, and in industrial automation to IEC 62443.
01NIS2 / KSC
NIS2 in Poland (KSC): implementation and audit readiness
Chapter 3 obligations apply from 3 April 2027. Entities that were already essential on 3 April 2026 must complete their first audit by 3 April 2028.
- Whether the act covers you, and in which category
- ISMS, risk, incidents and business continuity
- Annual, documented management training (Article 8e)
- Pre-audit review against Article 15
02ISO/IEC 27001
An ISMS ready for certification
When a customer requires the certificate, or you want one management system for several frameworks.
- ISMS scope and risk assessment
- Statement of Applicability (SoA) for 93 controls
- Internal audit and management review
- Readiness for the certification body's audit
03DORA
Operational resilience for financial entities
ICT risk management, the register of information on ICT providers, and resilience testing.
- ICT risk management framework
- Register of information built from source data
- Resilience testing program
- ICT business continuity
04CRA
Products with digital elements
For manufacturers of hardware and software sold in the EU.
- Reporting path for vulnerabilities and incidents
- An SBOM for every product version
- Vulnerability handling process
- A plan for full application from 11 December 2027
05AI Act
AI Act obligations and an AI management system
Transparency duties under Article 50 apply from 2 August 2026, and the requirements for high-risk systems in Annex III from 2 December 2027.
- Inventory of AI tools and use cases
- Check whether a system falls under Annex III
- Support for AI literacy in your team
- An AI management system under ISO/IEC 42001
// Deadlines
Deadlines that set the order of work
DORA
DORA applies from this date
Financial entities submit a register of information on their ICT providers every year.
KNF (Polish regulator) (opens in a new tab)CRA
Vulnerability and incident reporting
Applies to products placed on the market earlier, too (Article 69(3)).
ENISA (opens in a new tab)KSC
Chapter 3 obligations under the Polish KSC Act
ISMS, risk, incidents, business continuity, supply chain and yearly management training.
Dz.U. 2026 item 252 (opens in a new tab)CRA
Full application of the Cyber Resilience Act
Requirements for products with digital elements, including an SBOM and vulnerability handling.
European Commission (opens in a new tab)KSC
First audit deadline for essential entities
Applies to entities that were already essential on 3 April 2026 (Article 33(2) of the amending act).
KSC audit rules
As of . Sources: Dz.U. 2026 item 252 (Polish KSC Act), gov.pl, KSC deadlines, KNF, ENISA, European Commission.
// How we work
From gap to evidence, one framework at a time
We start with a fixed 5-week scope. You order the next stages separately, once you have seen the result of the first.
01Analysis
Gap analysis and obligations register
We compare the chosen framework's requirements with what already works: policies, configurations, logs and supplier contracts.
- Gap analysis with priorities
- Obligations register with owners
- 90-day roadmap
Request the first stepFirst step, 5 weeks
One framework, without rewriting everything
- Fixed scope and date agreed in writing before we start
Key deliverable: one control implemented in a system, together with its evidence
02Implementation
Controls in your systems, with evidence
We implement the control where it runs, so the evidence is produced along the way, not the week before the audit.
- Identity and access
- Cloud and endpoint configuration
- Data pipelines and change management
- Logs linked to requirements, with dates
03Before the audit
Pre-audit review
The Polish KSC Act (Article 10(4)) counts automatically generated system logs as operational documentation. We check whether your logs and records show the auditor what they should. FutureCode Evidence Box can collect the evidence.
- Evidence samples taken the way an auditor takes them
- Prioritized list of fixes
- Re-check after the fixes
// DORA
DORA: a register of information built from data, not a spreadsheet
DORA has applied since 17 January 2025. Every year, the register of information on contracts with third-party ICT service providers takes the most work: since 2026 it shows contracts as of 31 December of the previous year, and in Poland the financial supervisor KNF collects it. We build it from data on contracts and providers, together with incident classification and a resilience testing program. More on the DORA compliance page.
As of 24 September 2026. Source: KNF.
// CRA
Cyber Resilience Act: reporting already applies
Since 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents through ENISA's Single Reporting Platform, including for products placed on the market earlier (Article 69(3)). Full application: 11 December 2027.
What to have ready
- A reporting path rehearsed on one scenario
- An SBOM for every product version
- Vulnerability handling with an owner at every stage
Reporting deadlines, the SBOM and the path to CE marking are on our Cyber Resilience Act page. As of 24 September 2026. Sources: ENISA, European Commission.
// Customer questionnaires
Security questionnaires from customers: answers backed by evidence
A customer covered by NIS2 or DORA has to manage the risk of its suppliers, so it sends you a questionnaire. "Yes, we have a policy" is accepted less and less often.
- We link every answer to an artifact: a configuration, a log, a policy with its review date or a test result
- Where a control does not exist yet, we say so and give a date
- Answers go into a library, so the next questionnaire starts from there, not from zero
// Independence
We tell you who cannot audit you
We run the readiness assessment. The formal KSC audit is done by someone else, independent of whoever implemented your controls.
Readiness assessment
- We check controls, evidence and documentation the way an auditor will
- You get a prioritized list of fixes
- It shows the gaps before an auditor asks
- It is not an audit under Article 15 of the KSC Act
Formal KSC audit (Article 15)
- An accredited conformity assessment body
- Or at least two qualified auditors: a certificate from the regulation's list or documented audit practice
- Or a sectoral CSIRT that meets the same criteria
- The auditor cannot be a person who performs tasks under Article 8 or Articles 9-13 at your company, or did so in the year before the audit (Article 15(2a))
We don't perform formal KSC audits. As of 24 September 2026, details: who may perform a KSC audit.
// Qualifications
Team credentials
Our audits are led by certified auditors. An auditor has to be objective, so we do not audit what we implemented. Our team also holds certifications in security, data protection and process management.
Certifications held by our team
- CISA (Certified Information Systems Auditor)ISACA
- IODO (Polish data protection officer certificate)
- CompTIA Security+CompTIA
- ITILAXELOS / PeopleCert
- REQBRequirements Engineering Qualifications Board
- SAFeScaled Agile
- ISTQBInternational Software Testing Qualifications Board
// Scope
What we do, and what we don't
We agree the scope in writing before we start. We are just as clear about what we will not take on.
We do
- Gap analysis against one framework: NIS2 (KSC), ISO/IEC 27001, DORA or the CRA
- An obligations register with owners and deadlines
- Controls implemented in your systems, with evidence
- Evidence-based answers to customer security questionnaires
- Pre-audit review and re-checks of fixes
We don't
- A "KSC compliance certificate": no such document exists
- A formal KSC audit under Article 15: an independent auditor performs it, not us
- ISO/IEC 27001 certification: an accredited certification body issues it
- TLPT or TIBER tests
- A year-long program on slides with no working first step
If all you need is a document for the inspection file, we'll be upfront about that on the first call.
// FAQ
Questions about compliance
Which framework comes first?
The one with the nearest deadline, or the one that blocks sales. For companies covered by the Polish KSC Act, that is usually Chapter 3, which applies from 3 April 2027. If a large customer requires ISO/IEC 27001, we start there, because most of its controls carry over to KSC. We set the order on the first call, based on your deadlines and contracts.
Is ISO 27001 enough for NIS2 in Poland?
Not entirely. An ISMS aligned with ISO/IEC 27001 covers a large part of Article 8 of the KSC Act, but it does not replace the formal audit under Article 15 or the duties the standard does not cover: entry in the register, incident reporting within the statutory deadlines and annual, documented management training (Article 8e). We show which ISO controls you can reuse and what to add.
Can you audit us later?
Not the formal KSC audit: we don't perform those. We run readiness assessments. Article 15(2a) of the KSC Act also excludes an auditor who performed tasks under Article 8 or Articles 9-13 at your company in the year before the audit. We tell you plainly who can and who cannot perform the formal audit.
How should we answer a customer's security questionnaire?
With evidence, not statements. We link every answer to an artifact: a configuration, a log, a policy with its review date or a test result. Where a control is missing, we say so and give a date. Answers go into a library, so the next questionnaire starts from it.
Do DORA or the CRA apply to us?
DORA covers financial entities such as banks, insurers, investment firms and payment institutions, and indirectly their ICT providers, who end up in the register of information. The CRA covers manufacturers, importers and distributors of products with digital elements. If you sell software, or devices running software, in the EU, check now: vulnerability reporting has applied since 11 September 2026. More: DORA compliance and Cyber Resilience Act.
How long does the first step take, and what does it cost?
5 weeks, with a fixed scope and date agreed in writing before we start. We quote the price after the first call, once we know the framework and the number of systems in scope.
From the blog: compliance and audit
Let's start with one framework
In 30 minutes we work out which framework comes first and what goes into the first step.
Book a 30-minute callPrefer to start in writing?
Describe your situation and we will send back the scope and date of the first step. We reply within one business day.
Request the first step