NIS2 · ISO/IEC 27001 · DORA · CRA

Compliance and audit: one framework at a time, from gap to evidence

NIS2, DORA, the Cyber Resilience Act and customer security questionnaires all land at once, while the evidence is scattered across systems and nobody owns it. We take one framework at a time, find the gaps and the owners, implement controls in your systems and collect evidence that holds up in front of an auditor.

// In short

A policy you cannot show in the system is not a control.

It is a document about a control. So we build compliance with NIS2 in Poland (KSC), DORA, the CRA and ISO/IEC 27001 from the systems up: a gap analysis against one framework, an obligations register with owners, controls in identity, cloud and data, and evidence from logs and configuration. We work with manufacturing, logistics, energy, financial and telecom companies.

// Pick a framework

One framework at a time, starting with the nearest deadline

We set the order by deadlines, customer contracts and what already works. Most controls carry over to the next one. Where your group or a customer expects a different framework, we also work to NIST CSF 2.0, and in industrial automation to IEC 62443.

  1. 01NIS2 / KSC

    NIS2 in Poland (KSC): implementation and audit readiness

    Chapter 3 obligations apply from 3 April 2027. Entities that were already essential on 3 April 2026 must complete their first audit by 3 April 2028.

    • Whether the act covers you, and in which category
    • ISMS, risk, incidents and business continuity
    • Annual, documented management training (Article 8e)
    • Pre-audit review against Article 15
    NIS2 compliance in Poland
  2. 02ISO/IEC 27001

    An ISMS ready for certification

    When a customer requires the certificate, or you want one management system for several frameworks.

    • ISMS scope and risk assessment
    • Statement of Applicability (SoA) for 93 controls
    • Internal audit and management review
    • Readiness for the certification body's audit
    ISO/IEC 27001
  3. 03DORA

    Operational resilience for financial entities

    ICT risk management, the register of information on ICT providers, and resilience testing.

    • ICT risk management framework
    • Register of information built from source data
    • Resilience testing program
    • ICT business continuity
    DORA compliance
  4. 04CRA

    Products with digital elements

    For manufacturers of hardware and software sold in the EU.

    • Reporting path for vulnerabilities and incidents
    • An SBOM for every product version
    • Vulnerability handling process
    • A plan for full application from 11 December 2027
    Cyber Resilience Act
  5. 05AI Act

    AI Act obligations and an AI management system

    Transparency duties under Article 50 apply from 2 August 2026, and the requirements for high-risk systems in Annex III from 2 December 2027.

    • Inventory of AI tools and use cases
    • Check whether a system falls under Annex III
    • Support for AI literacy in your team
    • An AI management system under ISO/IEC 42001
    AI Act and ISO/IEC 42001

// Deadlines

Deadlines that set the order of work

  1. DORA

    DORA applies from this date

    Financial entities submit a register of information on their ICT providers every year.

    KNF (Polish regulator) (opens in a new tab)
  2. CRA

    Vulnerability and incident reporting

    Applies to products placed on the market earlier, too (Article 69(3)).

    ENISA (opens in a new tab)
  3. KSC

    Chapter 3 obligations under the Polish KSC Act

    ISMS, risk, incidents, business continuity, supply chain and yearly management training.

    Dz.U. 2026 item 252 (opens in a new tab)
  4. CRA

    Full application of the Cyber Resilience Act

    Requirements for products with digital elements, including an SBOM and vulnerability handling.

    European Commission (opens in a new tab)
  5. KSC

    First audit deadline for essential entities

    Applies to entities that were already essential on 3 April 2026 (Article 33(2) of the amending act).

    KSC audit rules

As of . Sources: Dz.U. 2026 item 252 (Polish KSC Act), gov.pl, KSC deadlines, KNF, ENISA, European Commission.

// How we work

From gap to evidence, one framework at a time

We start with a fixed 5-week scope. You order the next stages separately, once you have seen the result of the first.

  1. 01Analysis

    Gap analysis and obligations register

    We compare the chosen framework's requirements with what already works: policies, configurations, logs and supplier contracts.

    • Gap analysis with priorities
    • Obligations register with owners
    • 90-day roadmap

    First step, 5 weeks

    One framework, without rewriting everything

    • Fixed scope and date agreed in writing before we start

    Key deliverable: one control implemented in a system, together with its evidence

    Request the first step
  2. 02Implementation

    Controls in your systems, with evidence

    We implement the control where it runs, so the evidence is produced along the way, not the week before the audit.

    • Identity and access
    • Cloud and endpoint configuration
    • Data pipelines and change management
    • Logs linked to requirements, with dates
    NIS2 evidence matrix
  3. 03Before the audit

    Pre-audit review

    The Polish KSC Act (Article 10(4)) counts automatically generated system logs as operational documentation. We check whether your logs and records show the auditor what they should. FutureCode Evidence Box can collect the evidence.

    • Evidence samples taken the way an auditor takes them
    • Prioritized list of fixes
    • Re-check after the fixes
    See the sample report

// DORA

DORA: a register of information built from data, not a spreadsheet

DORA has applied since 17 January 2025. Every year, the register of information on contracts with third-party ICT service providers takes the most work: since 2026 it shows contracts as of 31 December of the previous year, and in Poland the financial supervisor KNF collects it. We build it from data on contracts and providers, together with incident classification and a resilience testing program. More on the DORA compliance page.

As of 24 September 2026. Source: KNF.

// CRA

Cyber Resilience Act: reporting already applies

Since 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents through ENISA's Single Reporting Platform, including for products placed on the market earlier (Article 69(3)). Full application: 11 December 2027.

What to have ready

  • A reporting path rehearsed on one scenario
  • An SBOM for every product version
  • Vulnerability handling with an owner at every stage

Reporting deadlines, the SBOM and the path to CE marking are on our Cyber Resilience Act page. As of 24 September 2026. Sources: ENISA, European Commission.

// Customer questionnaires

Security questionnaires from customers: answers backed by evidence

A customer covered by NIS2 or DORA has to manage the risk of its suppliers, so it sends you a questionnaire. "Yes, we have a policy" is accepted less and less often.

  • We link every answer to an artifact: a configuration, a log, a policy with its review date or a test result
  • Where a control does not exist yet, we say so and give a date
  • Answers go into a library, so the next questionnaire starts from there, not from zero

// Independence

We tell you who cannot audit you

We run the readiness assessment. The formal KSC audit is done by someone else, independent of whoever implemented your controls.

Readiness assessment

  • We check controls, evidence and documentation the way an auditor will
  • You get a prioritized list of fixes
  • It shows the gaps before an auditor asks
  • It is not an audit under Article 15 of the KSC Act

Formal KSC audit (Article 15)

  • An accredited conformity assessment body
  • Or at least two qualified auditors: a certificate from the regulation's list or documented audit practice
  • Or a sectoral CSIRT that meets the same criteria
  • The auditor cannot be a person who performs tasks under Article 8 or Articles 9-13 at your company, or did so in the year before the audit (Article 15(2a))

We don't perform formal KSC audits. As of 24 September 2026, details: who may perform a KSC audit.

// Qualifications

Team credentials

Our audits are led by certified auditors. An auditor has to be objective, so we do not audit what we implemented. Our team also holds certifications in security, data protection and process management.

Certifications held by our team

  • CISA (Certified Information Systems Auditor)ISACA
  • IODO (Polish data protection officer certificate)
  • CompTIA Security+CompTIA
  • ITILAXELOS / PeopleCert
  • REQBRequirements Engineering Qualifications Board
  • SAFeScaled Agile
  • ISTQBInternational Software Testing Qualifications Board

// Scope

What we do, and what we don't

We agree the scope in writing before we start. We are just as clear about what we will not take on.

We do

  • Gap analysis against one framework: NIS2 (KSC), ISO/IEC 27001, DORA or the CRA
  • An obligations register with owners and deadlines
  • Controls implemented in your systems, with evidence
  • Evidence-based answers to customer security questionnaires
  • Pre-audit review and re-checks of fixes

We don't

  • A "KSC compliance certificate": no such document exists
  • A formal KSC audit under Article 15: an independent auditor performs it, not us
  • ISO/IEC 27001 certification: an accredited certification body issues it
  • TLPT or TIBER tests
  • A year-long program on slides with no working first step

If all you need is a document for the inspection file, we'll be upfront about that on the first call.

// FAQ

Questions about compliance

Which framework comes first?

The one with the nearest deadline, or the one that blocks sales. For companies covered by the Polish KSC Act, that is usually Chapter 3, which applies from 3 April 2027. If a large customer requires ISO/IEC 27001, we start there, because most of its controls carry over to KSC. We set the order on the first call, based on your deadlines and contracts.

Is ISO 27001 enough for NIS2 in Poland?

Not entirely. An ISMS aligned with ISO/IEC 27001 covers a large part of Article 8 of the KSC Act, but it does not replace the formal audit under Article 15 or the duties the standard does not cover: entry in the register, incident reporting within the statutory deadlines and annual, documented management training (Article 8e). We show which ISO controls you can reuse and what to add.

Can you audit us later?

Not the formal KSC audit: we don't perform those. We run readiness assessments. Article 15(2a) of the KSC Act also excludes an auditor who performed tasks under Article 8 or Articles 9-13 at your company in the year before the audit. We tell you plainly who can and who cannot perform the formal audit.

How should we answer a customer's security questionnaire?

With evidence, not statements. We link every answer to an artifact: a configuration, a log, a policy with its review date or a test result. Where a control is missing, we say so and give a date. Answers go into a library, so the next questionnaire starts from it.

Do DORA or the CRA apply to us?

DORA covers financial entities such as banks, insurers, investment firms and payment institutions, and indirectly their ICT providers, who end up in the register of information. The CRA covers manufacturers, importers and distributors of products with digital elements. If you sell software, or devices running software, in the EU, check now: vulnerability reporting has applied since 11 September 2026. More: DORA compliance and Cyber Resilience Act.

How long does the first step take, and what does it cost?

5 weeks, with a fixed scope and date agreed in writing before we start. We quote the price after the first call, once we know the framework and the number of systems in scope.

From the blog: compliance and audit

Let's start with one framework

In 30 minutes we work out which framework comes first and what goes into the first step.

Book a 30-minute call

Prefer to start in writing?

Describe your situation and we will send back the scope and date of the first step. We reply within one business day.

Request the first step