NIS2 in Poland · KSC · Article 15
NIS2 audit readiness in Poland: we check the evidence before the auditor does
Entities that were already essential on 3 April 2026 must complete their first Article 15 audit under Poland's KSC Act by 3 April 2028. We go through your controls and evidence the way the auditor will and leave you a fix list with owners. This is a readiness assessment, not a formal KSC audit.
// In short
A KSC pre-audit review is a dress rehearsal for Article 15
A pre-audit review checks whether your Article 8 obligations under the KSC Act, Poland's NIS2 law, work in practice and can be proven with evidence from your systems. It serves essential entities before their first audit and important entities the authority may order to be audited. It ends with an evidence index, a fix list and a re-check.
As of 24 September 2026. Source: Dz.U. 2026 item 252 (in Polish).
When you need a KSC audit
| Who | Audit deadline | Legal basis |
|---|---|---|
| Already essential on 3 April 2026, the day the amending act entered into force | First audit by 3 April 2028, then at least every 3 years | Article 33(2) of the amending act, Article 15 |
| Becomes essential later | Within 24 months of meeting the criteria | Article 16 |
| Former operator of essential services | Keeps its existing 3-year audit cycle | Dz.U. 2026 item 252 |
| Important entity | No periodic audit. The authority can order one by decision after a serious incident or another breach of the act | Article 15(1b) |
Sources (in Polish): Dz.U. 2026 item 252, gov.pl, KSC deadlines.
Seven questions to ask before the audit
Can you show the board's ISMS decisions?
Policies carry an approval date and a last-review date, and risk decisions are on record. A document with no trace of the decision behind it is not enough.
Does the risk register have owners and dates?
Every risk has an owner, a treatment decision and a due date. The treatment plan is current, not frozen on the day it was written.
Can you trace one incident from detection to final report?
Early warning within 24 hours, notification within 72 hours, final report within one month of the notification. We take one event, or the record of an exercise, and check that tickets, times and logs form a single timeline.
Does your restore test have a date, a duration and a result?
A continuity plan without a test is a statement of intent. The evidence is the test record: what was restored, how long it took and what you fixed afterwards.
Do you know which suppliers are critical?
A supplier register with a risk rating, security requirements in the contracts and the date of the last review.
Does the asset inventory come from your systems?
Systems, data and owners generated by tools, not written down from memory. We compare the list with what the configuration shows.
Does this year's management training have an attendance list?
Article 8e requires training once per calendar year for the head of the entity and the person responsible for cybersecurity. Evidence: agenda, date and attendance list. We also run NIS2 management training.
System logs count as documentation
Article 10(4) of the KSC Act treats automatically generated system logs as operational documentation. So the review starts with what your systems already record, and the FutureCode Evidence Box can collect it. The NIS2 evidence matrix (XLSX, no sign-up) lists example evidence for each area.
// Process
How the pre-audit review works
Audit scope and calendar
We confirm whether and when an Article 15 audit applies to you, which services and systems it covers and who owns each area on your side.
Evidence index
We collect the evidence and map it to the Article 8 areas: policies, registers, logs, configurations, tickets and test results.
Samples and interviews
We pick samples the way an auditor does: tickets, access changes, restore tests, supplier assessments. We interview control owners and the board.
Readiness report
The state of each area, gaps linked to specific evidence, and a fix list with owners and dates, written so it can be checked again.
Re-check
Once the fixes are in, we check them again against the evidence and update the index you hand to the auditor.
Evidence index ready for the auditor
// First step
Fixed scope, results in writing
We agree scope and date in writing before we start. You order the second stage once you have seen the result of the first.
01Review
KSC pre-audit review
We cover all Article 8 areas, or first the ones where you see the highest risk. The review team includes certified auditors and security engineers.
- ISMS documents with dates and approvals
- Samples of logs, configurations, tickets and tests
- Interviews with control owners
- Readiness report with a fix list
Request the first stepFirst step, 5 weeks
KSC pre-audit review
- Evidence index mapped to the Article 8 areas
- Gap list with priorities
- Fix plan with owners and dates
Key deliverable: an evidence index with the gaps marked, ready to complete
02After the fixes
Re-check and audit-day plan
When the fixes are ready, we verify them and prepare your team for the auditor's interviews.
- Fixes re-checked against evidence
- Up-to-date evidence index for the auditor
- A named owner for each area
- Mock interview with control owners
// Independence
A pre-audit review is not a KSC audit
We run the pre-audit review. A formal Article 15 audit is done by someone else and has its own requirements for auditors.
Pre-audit review
- Checks controls and evidence before the audit
- Ends with a fix list and a re-check
- Serves your own fixes and does not replace an Article 15 audit
Formal KSC audit (Article 15)
- An accredited conformity assessment body, at least two qualified auditors, or a sectoral CSIRT that meets the same criteria
- Auditor qualifications: a certificate from the list in the 2018 regulation, 3 years of practice auditing information system security, or 2 years plus a relevant postgraduate diploma
- The auditor cannot be anyone who performs Article 8 or 9-13 tasks at your company, or did so in the year before the audit (Article 15(2a))
What we will not do
- Formal KSC audits under Article 15: we don't perform them
- A "KSC compliance certificate": no such document exists
We tell you up front who can audit you and who cannot. As of 24 September 2026. Sources (in Polish): gov.pl, auditor qualifications, Dz.U. 2018 item 1999. More: who may perform a KSC audit.
// Scope
What we do and what we don't
We agree scope and date in writing before we start.
We do
- Check whether and when an Article 15 audit applies to you
- Review ISMS documents and evidence across all Article 8 areas
- Sample logs, configurations, tickets and restore tests
- Write a readiness report with a fix list, owners and dates
- Re-check the fixes and prepare an evidence index for the auditor
We don't
- Perform the formal Article 15 audit: we only prepare you for it
- Write documents that describe controls you do not have
- Promise that the audit will end without findings
- Review on the basis of questionnaires alone, without evidence from systems
If you need implementation rather than a review, start with a KSC gap analysis.
// FAQ
Questions about audit readiness
What is the difference between a pre-audit review and a KSC audit?
A KSC audit is the formal Article 15 audit, performed by an accredited body, at least two qualified auditors or a sectoral CSIRT. A pre-audit review covers the same areas and evidence, but its result is for your own fixes. In Poland it is often called a "zero audit" (audyt zerowy).
When is our first KSC audit due?
If you were already an essential entity on 3 April 2026, the first audit is due by 3 April 2028 (Article 33(2) of the amending act), and then at least every 3 years. An entity that becomes essential later has 24 months from meeting the criteria (Article 16). Important entities have no periodic audit, but the authority can order one (Article 15(1b)). As of 24 September 2026.
Can you perform our formal audit after the review?
No. We don't perform formal KSC audits. The Article 15 audit is done by an accredited conformity assessment body, at least two qualified auditors or a sectoral CSIRT. The auditor cannot be anyone who performs Article 8 or 9-13 tasks at your company, or did so in the year before the audit (Article 15(2a)). On the first call we explain what your auditor has to meet.
Do system logs count as evidence?
Yes. Article 10(4) of the KSC Act treats automatically generated system logs as operational documentation. A dated log, configuration or test result shows that a control works. A written procedure only shows that someone wrote it.
How long does the review take and what do you need from us?
The first step takes 5 weeks and has a fixed scope. We need your ISMS documents, a contact person for each area and a few hours of interviews with control owners. Any system access is read-only.
We are an important entity. Is a review worth it?
The authority can order you to be audited after a serious incident or another breach of the act (Article 15(1b)). A review shows how you would do in that audit before anyone orders it. The same evidence helps when customers send you security questionnaires.
From the blog: audits and evidence
Let's see how you would do in the audit
In 30 minutes we confirm whether and when an Article 15 audit applies to you and agree the scope of the review. Before the call, take a look at the NIS2 evidence matrix.
Book a 30-minute callPrefer to start in writing?
Describe your situation and we will send you the scope and date of the review. We reply within one business day.
Request the first step