Home/Audit/NIS2 / KSC 2.0 audit

02 · Audit

NIS2 / KSC 2.0 audit and compliance

We check whether NIS2 applies to you, audit your organization against the 10 risk management measures and implement what is missing — policies, incident reporting, business continuity, supplier oversight and board training.

24 h / 72 hincident reporting deadlines
90 daysimplementation plan
EUR 10 millionor 2% of turnover — maximum fine

Service details

What is NIS2?

NIS2 (Directive (EU) 2022/2555) is the European Union's cybersecurity law for organizations that provide services essential to the economy and society. It replaces the original NIS directive, covers many more sectors and companies, and requires them to manage cybersecurity risk, report significant incidents and oversee the security of their suppliers — with the management board personally accountable.

In Poland, NIS2 is transposed by the amendment to the National Cybersecurity System Act (KSC 2.0). Remote Admin helps you determine whether and how you are covered, audits your organization against the requirements and implements what is missing — from policies and procedures to incident reporting and security testing.

  • Classification: essential or important entity
  • Gap analysis against the 10 measures of Art. 21
  • Implementation, training and evidence for the supervisor
Audit

Our services

How we help you implement NIS2

NIS2 compliance audit

A thorough review of your IT infrastructure, processes and security policies, with a gap report and an implementation plan with priorities.

Policies and procedures

Risk management, information security policy, access control, cryptography, asset management — documentation that meets the directive's requirements.

Incident reporting readiness

Detection, classification and an incident procedure that lets you meet the 24-hour, 72-hour and one-month reporting deadlines.

Business continuity

Continuity and disaster recovery plans, backup policy and recovery tests that keep your services running during an attack.

Supply chain security

Assessment of IT suppliers, security requirements in contracts and ongoing oversight of third parties with access to your systems.

Training — including the board

Cyber hygiene training for employees and mandatory cybersecurity training for management bodies, as NIS2 requires.

Who it applies to

Essential and important entities — 18 sectors

Sectors of high criticality

Energy, transport, banking and financial market infrastructure, healthcare, drinking water and wastewater, digital infrastructure, ICT service management, public administration, space.

Other critical sectors

Postal and courier services, waste management, chemicals, food production and distribution, manufacturing (including medical devices, electronics, vehicles), digital providers, research organizations.

Size threshold

As a rule, medium and large enterprises (50+ employees, or annual turnover and balance sheet above EUR 10 million) — with exceptions for entities of particular importance regardless of size.

Poland: KSC 2.0

The amendment to the Polish National Cybersecurity System Act (KSC) transposes NIS2 — an entity register, obligations and penalties enforced by national authorities.

Obligations

Ten risk management measures (Art. 21)

  • Risk analysis and information system security policies
  • Incident handling and reporting: 24 h / 72 h / 1 month
  • Business continuity, backup and crisis management
  • Supply chain security and supplier relationships
  • Security in system acquisition, development and maintenance
  • Policies for assessing the effectiveness of measures (audits, testing)
  • Cyber hygiene and training — including for the management board
  • Cryptography and encryption
  • Human resources security, access control, asset management
  • Multi-factor authentication and secure communications

Key facts

NIS2 by the numbers

24 hearly warning of a significant incident
72 hincident notification with impact assessment
€10 millionor 2% of turnover — maximum fine for essential entities
€7 millionor 1.4% of turnover — maximum fine for important entities

How we work

NIS2 audit in four steps

1. Classification and scopeDetermining whether, and in which category, the organization falls under NIS2/KSC 2.0; a map of systems and processes subject to obligations.
2. Gap analysisMaturity assessment against the 10 measures of Art. 21 — a report with priorities and a remediation plan.
3. ImplementationPolicies, incident procedure with on-call coverage, business continuity plan, testing program, supplier oversight.
4. Evidence and maintenanceDocumentation for the supervisory authority, management board training, periodic reviews and re-audits.

Questions and answers

NIS2 FAQ

Does NIS2 apply to my company?

It applies mainly to medium and large organizations (50 or more employees, or annual turnover and balance sheet above EUR 10 million) operating in one of the 18 sectors listed in the directive — for example energy, transport, banking, healthcare, digital infrastructure, ICT service management, manufacturing or food. Some entities, such as DNS and trust service providers, are covered regardless of size. We start every engagement by checking your classification.

What is the difference between an essential and an important entity?

Both must meet the same risk management and reporting obligations. The difference is in supervision and penalties: essential entities are supervised proactively and face fines of up to EUR 10 million or 2% of global turnover, while important entities are supervised after the fact, with fines of up to EUR 7 million or 1.4% of turnover.

What are the incident reporting deadlines?

For a significant incident: an early warning within 24 hours of becoming aware of it, an incident notification with an initial assessment within 72 hours, and a final report within one month. Meeting these deadlines requires monitoring and a rehearsed procedure — which is why many clients combine NIS2 with our 24/7 SOC.

Is the management board personally responsible?

Yes. Under NIS2, management bodies approve the cybersecurity risk management measures, oversee their implementation and can be held liable for failures. Board members are also required to take part in cybersecurity training.

What is KSC 2.0?

KSC 2.0 is the amendment to the Polish National Cybersecurity System Act that transposes NIS2 into Polish law. It defines which entities are covered, their registration, obligations and the penalties enforced by Polish authorities.

Does NIS2 cover online shops?

Not as such. In the digital area NIS2 covers online marketplaces, search engines and social networking platforms, as well as cloud, data center and managed IT service providers. A regular online shop is usually covered only if it falls into another sector, such as food distribution or manufacturing, and meets the size threshold.

What does a NIS2 audit deliver?

A classification of your organization, a maturity assessment against the 10 measures of Art. 21, a gap report with priorities and an implementation plan — typically for the next 90 days — plus, if you continue with us, the documentation and evidence for the supervisory authority.

How does NIS2 relate to DORA and ISO 27001?

Financial entities covered by DORA follow DORA as the more specific law for ICT risk. ISO 27001 is not required by NIS2, but an existing ISMS covers a large part of its measures and makes compliance much easier — we take it into account in the gap analysis.

Can you support us after the audit?

Yes. We implement the missing measures, run penetration tests and vulnerability scanning, provide a vCISO to lead security on an ongoing basis and repeat audits periodically.

Related services

Often combined with this service

First step

Let's talk about a NIS2 / KSC 2.0 audit.

30 minutes, no slide deck. We'll tell you straight whether this service solves your problem, what scope makes sense and how much it costs.

Book a consultation

A proposal with scope and pricing within 48 hours of the call.

Go to contact