ISMS implementation aligned with ISO 27001, KSC and NIS2
We build an information security management system that meets ISO/IEC 27001:2022 and the amended Polish National Cybersecurity System Act (KSC). We start with a gap analysis and finish with an internal audit and preparation for certification.
- Led by ISO 27001 and ISO 22301 lead auditors
- Incident procedure ready for 24h and 72h reports in S46, Poland's national incident reporting system
- We test the controls, not just the documents describing them
- 3 October 2026
Last day to apply for entry in the register of essential and important entities (the KSC register)
- 3 April 2027
The ISMS must be in place at entities that met the essential or important entity criteria on 3 April 2026
- 3 April 2028
First audit for essential entities covered since the Act took effect. Authorities can impose penalties from this date
Law as of September 2026.
Who ISMS implementation is for
Most companies come to us in one of four situations.
Essential and important entities
The amended KSC Act has applied since 3 April 2026 and explicitly requires an ISMS. An entity that obtains this status has 12 months to implement it.
Suppliers to KSC-regulated companies
Customers covered by the Act must manage supply chain risk, so their questionnaires ask about your security policy, SoA and certificate. Without them, it is harder to get through the customer's procurement process.
Companies that need a certificate
Because a tender, a bank or a foreign customer requires it. We prepare the organization for the audit; the certificate is issued by an accredited certification body.
An ISMS that exists only on paper
The policies exist, but nobody follows them, and the risk analysis is three years old. We start with a gap analysis and build on what already exists instead of rewriting everything.
What ISO 27001 gives you, and what needs to be added
The ISMS required by the KSC Act is, in practice, a system built on ISO/IEC 27001. The standard covers most of the requirements, but it does not cover some statutory obligations. We add those during implementation.
| Area | KSC / NIS2 requirement | What ISO 27001:2022 provides | What we add |
|---|---|---|---|
| Risk management | Systematic risk assessment and risk management | Clauses 6.1.2 and 6.1.3: risk assessment methodology, risk treatment plan and Statement of Applicability. Clauses 8.2 and 8.3: periodic assessment and carrying out the plan | Risk assessment for the services that bring the company under the Act, not only for servers and laptops |
| Incidents | Significant incident: early warning within 24h, notification within 72h, final report within one month | A.5.24–A.5.28: planning, assessment, response, lessons learned and evidence. No statutory deadlines | Criteria for reporting an incident, a path to the CSIRT via S46 and a scenario-based exercise |
| Business continuity | Contingency and recovery plans, backups, crisis management | A.5.29, A.5.30 and A.8.13: security during disruption, ICT readiness, information backup | A BIA with RTO and RPO and a restore test. ISO 22301 when a full system is needed |
| Supply chain | Security of relationships with ICT service and product suppliers | A.5.19–A.5.23: supplier requirements, agreements, monitoring, cloud services | Supplier classification, a security questionnaire and model contract clauses |
| Management | The head of the entity approves measures, oversees implementation and completes training. Personally liable | Clauses 5.1 and 9.3: leadership and management review | Board training and a review calendar, so that oversight leaves a documented trail |
| Contact with the KSC system | Entry in the KSC register and at least two contact persons (one in micro and small companies) | A.5.5 and A.5.31: contact with authorities and legal requirements. No KSC register entry or statutory contact persons | Help with the application, appointing contact persons and connecting to S46 |
| Audit | Essential entity: first audit within 24 months of meeting the criteria, then at least every 3 years. For entities covered since 3 April 2026 the deadline is 3 April 2028 | Clause 9.2: internal audit, plus annual certification body audits when certified | An internal audit against the Act's requirements that shows what to fix before the statutory audit |
The list of standards published by the Polish Ministry of Digital Affairs on 10 September 2026 is for reference only. Applying a standard does not by itself establish compliance with the Act; what counts is a working ISMS. Source: gov.pl (in Polish)
How the implementation works
Six stages, each leaving documents or records for the auditor. The whole project usually takes 4 to 8 months, depending on the size of the company and how much is already in place.
Gap analysis
Interviews with process owners, a review of documents and configurations. Output: a gap report against ISO 27001 and the Act, with priorities.
Scope and risk analysis
We set the ISMS boundaries, list assets and services and choose a methodology. Output: a risk register with a treatment plan approved by the board.
Documentation and SoA
Information security policy, procedures and a Statement of Applicability for the 93 Annex A controls.
Implementing controls
MFA, backups, access rights, event logging, incident handling. We use technical tests to verify that the controls work.
Training and exercises
Board training, staff training and an incident handling exercise, after which we improve the procedure.
Internal audit and management review
We check the system the way an auditor will. Output: an audit report and review minutes, the evidence that the ISMS works.
Want a certificate? We help you choose an accredited certification body and stay with you during the stage 1 and stage 2 audits.
What you get after implementation
Documents and records you can show to an auditor, a supervisory authority or a customer asking about security.
Gap analysis report
Baseline against ISO 27001 and the KSC Act, with priorities.
Asset and risk register
With owners, ratings and a risk treatment plan.
Statement of Applicability (SoA)
93 controls with a justification of whether and how you apply them.
Policy and procedures
An information security policy and operating procedures written for your organization.
Incident handling procedure
With reporting criteria and the 24h, 72h and one-month deadlines.
Business continuity plan
BCP and DRP with RTO and RPO for the services the business depends on.
Training programme
For the board and staff, with attendance records that serve as audit evidence.
Internal audit report
Together with the management review minutes.
Why PWNONE
Lead auditors on the team
Implementation is led by people holding ISO 27001 and ISO 22301 lead auditor certificates issued by TÜV NORD Polska. They know what the certification body will ask.
Controls tested by attack
We are also a penetration testing firm (OSCP, OSWE). Before a control is marked as implemented in the SoA, we check that it works.
Documents people actually use
The policy is a few pages long and the procedures describe how you really work. Auditors talk to staff, so a document nobody knows achieves nothing.
Maintenance after implementation
An ISMS needs regular review and updates. We can take this over as part of our vCISO service.
Explore vCISO
Talk to an auditor before you start
In the consultation we will establish whether the KSC Act covers your company and where to start. If a smaller scope than a full implementation is enough, we will say so.
Frequently asked questions
How long does ISMS implementation take?
Usually 4 to 8 months. Most of the time goes into technical changes; documents are the smaller part of the work. A small company with well-organized IT will be closer to the lower end, an organization with several sites and in-house software closer to the upper end.
How much does ISMS implementation cost?
The price depends on the number of employees and sites, the ISMS scope and how much is already in place. We quote after a free consultation. If you want a certificate, the certification body's audit is a separate cost paid directly to that body.
Is an ISO 27001 certificate enough to meet the KSC requirements?
Not entirely. A well-implemented standard covers most ISMS requirements, but the Act imposes obligations the standard does not cover: entry in the KSC register, incident reporting via S46 within 24 and 72 hours, personal liability of the head of the entity and audits of essential entities. During implementation we prepare the company for each of them.
Does the KSC Act require an ISO 27001 certificate?
No. The Act requires a working ISMS, not a certificate. A certificate is useful when you want to demonstrate compliance to customers or in tenders.
Is it worth implementing ISO 27001 and ISO 22301 together?
Yes, if service downtime is your main risk. Both standards share the same clause structure, so part of the documentation, the internal audits and the management reviews can be run jointly. The KSC Act requires business continuity plans anyway.
What is a Statement of Applicability (SoA)?
A document in which, for each of the 93 Annex A controls of ISO/IEC 27001:2022, you state whether you apply it, why, and to what extent it is implemented. It is where the auditor starts.
Who issues the ISO 27001 certificate?
A certification body accredited, for example, by the Polish Centre for Accreditation (PCA). PWNONE does not issue certificates. We prepare the organization for the audit and support it during the audit.
What is the deadline for implementing an ISMS under the KSC Act?
Companies that met the criteria for an essential or important entity on 3 April 2026 have until 3 April 2027. Those that meet the criteria later have 12 months from that date. An essential entity must complete its first audit within 24 months of meeting the criteria, and then at least every 3 years. For entities covered since the Act took effect, that deadline is 3 April 2028. This does not apply to former operators of essential services.