ISO 27001 · KSC · NIS2

ISMS implementation aligned with ISO 27001, KSC and NIS2

We build an information security management system that meets ISO/IEC 27001:2022 and the amended Polish National Cybersecurity System Act (KSC). We start with a gap analysis and finish with an internal audit and preparation for certification.

  • Led by ISO 27001 and ISO 22301 lead auditors
  • Incident procedure ready for 24h and 72h reports in S46, Poland's national incident reporting system
  • We test the controls, not just the documents describing them
Deadlines under the KSC Act
  1. 3 October 2026

    Last day to apply for entry in the register of essential and important entities (the KSC register)

  2. 3 April 2027

    The ISMS must be in place at entities that met the essential or important entity criteria on 3 April 2026

  3. 3 April 2028

    First audit for essential entities covered since the Act took effect. Authorities can impose penalties from this date

Law as of September 2026.

Who ISMS implementation is for

Most companies come to us in one of four situations.

Essential and important entities

The amended KSC Act has applied since 3 April 2026 and explicitly requires an ISMS. An entity that obtains this status has 12 months to implement it.

Suppliers to KSC-regulated companies

Customers covered by the Act must manage supply chain risk, so their questionnaires ask about your security policy, SoA and certificate. Without them, it is harder to get through the customer's procurement process.

Companies that need a certificate

Because a tender, a bank or a foreign customer requires it. We prepare the organization for the audit; the certificate is issued by an accredited certification body.

An ISMS that exists only on paper

The policies exist, but nobody follows them, and the risk analysis is three years old. We start with a gap analysis and build on what already exists instead of rewriting everything.

ISO 27001 vs the KSC Act

What ISO 27001 gives you, and what needs to be added

The ISMS required by the KSC Act is, in practice, a system built on ISO/IEC 27001. The standard covers most of the requirements, but it does not cover some statutory obligations. We add those during implementation.

Risk managementSystematic risk assessment and risk managementClauses 6.1.2 and 6.1.3: risk assessment methodology, risk treatment plan and Statement of Applicability. Clauses 8.2 and 8.3: periodic assessment and carrying out the planRisk assessment for the services that bring the company under the Act, not only for servers and laptops
IncidentsSignificant incident: early warning within 24h, notification within 72h, final report within one monthA.5.24–A.5.28: planning, assessment, response, lessons learned and evidence. No statutory deadlinesCriteria for reporting an incident, a path to the CSIRT via S46 and a scenario-based exercise
Business continuityContingency and recovery plans, backups, crisis managementA.5.29, A.5.30 and A.8.13: security during disruption, ICT readiness, information backupA BIA with RTO and RPO and a restore test. ISO 22301 when a full system is needed
Supply chainSecurity of relationships with ICT service and product suppliersA.5.19–A.5.23: supplier requirements, agreements, monitoring, cloud servicesSupplier classification, a security questionnaire and model contract clauses
ManagementThe head of the entity approves measures, oversees implementation and completes training. Personally liableClauses 5.1 and 9.3: leadership and management reviewBoard training and a review calendar, so that oversight leaves a documented trail
Contact with the KSC systemEntry in the KSC register and at least two contact persons (one in micro and small companies)A.5.5 and A.5.31: contact with authorities and legal requirements. No KSC register entry or statutory contact personsHelp with the application, appointing contact persons and connecting to S46
AuditEssential entity: first audit within 24 months of meeting the criteria, then at least every 3 years. For entities covered since 3 April 2026 the deadline is 3 April 2028Clause 9.2: internal audit, plus annual certification body audits when certifiedAn internal audit against the Act's requirements that shows what to fix before the statutory audit

The list of standards published by the Polish Ministry of Digital Affairs on 10 September 2026 is for reference only. Applying a standard does not by itself establish compliance with the Act; what counts is a working ISMS. Source: gov.pl (in Polish)

How the implementation works

Six stages, each leaving documents or records for the auditor. The whole project usually takes 4 to 8 months, depending on the size of the company and how much is already in place.

1
2–3 weeks

Gap analysis

Interviews with process owners, a review of documents and configurations. Output: a gap report against ISO 27001 and the Act, with priorities.

2
3–4 weeks

Scope and risk analysis

We set the ISMS boundaries, list assets and services and choose a methodology. Output: a risk register with a treatment plan approved by the board.

3
4–6 weeks

Documentation and SoA

Information security policy, procedures and a Statement of Applicability for the 93 Annex A controls.

4
2–4 months

Implementing controls

MFA, backups, access rights, event logging, incident handling. We use technical tests to verify that the controls work.

5
in parallel with stage 4

Training and exercises

Board training, staff training and an incident handling exercise, after which we improve the procedure.

6
2–3 weeks

Internal audit and management review

We check the system the way an auditor will. Output: an audit report and review minutes, the evidence that the ISMS works.

Want a certificate? We help you choose an accredited certification body and stay with you during the stage 1 and stage 2 audits.

What you get after implementation

Documents and records you can show to an auditor, a supervisory authority or a customer asking about security.

Gap analysis report

Baseline against ISO 27001 and the KSC Act, with priorities.

Asset and risk register

With owners, ratings and a risk treatment plan.

Statement of Applicability (SoA)

93 controls with a justification of whether and how you apply them.

Policy and procedures

An information security policy and operating procedures written for your organization.

Incident handling procedure

With reporting criteria and the 24h, 72h and one-month deadlines.

Business continuity plan

BCP and DRP with RTO and RPO for the services the business depends on.

Training programme

For the board and staff, with attendance records that serve as audit evidence.

Internal audit report

Together with the management review minutes.

Why PWNONE

Lead auditors on the team

Implementation is led by people holding ISO 27001 and ISO 22301 lead auditor certificates issued by TÜV NORD Polska. They know what the certification body will ask.

Controls tested by attack

We are also a penetration testing firm (OSCP, OSWE). Before a control is marked as implemented in the SoA, we check that it works.

Documents people actually use

The policy is a few pages long and the procedures describe how you really work. Auditors talk to staff, so a document nobody knows achieves nothing.

Maintenance after implementation

An ISMS needs regular review and updates. We can take this over as part of our vCISO service.

Explore vCISO
Bartosz Machnik, CBDO of PWNONE
Free consultation

Talk to an auditor before you start

In the consultation we will establish whether the KSC Act covers your company and where to start. If a smaller scope than a full implementation is enough, we will say so.

Bartosz Machnik
CBDO and co-founder of PWNONE
ISO 27001 and ISO 22301 Lead Auditor, NIS2 auditor (TÜV NORD Polska), member of ISSA Poland

Frequently asked questions

How long does ISMS implementation take?

Usually 4 to 8 months. Most of the time goes into technical changes; documents are the smaller part of the work. A small company with well-organized IT will be closer to the lower end, an organization with several sites and in-house software closer to the upper end.

How much does ISMS implementation cost?

The price depends on the number of employees and sites, the ISMS scope and how much is already in place. We quote after a free consultation. If you want a certificate, the certification body's audit is a separate cost paid directly to that body.

Is an ISO 27001 certificate enough to meet the KSC requirements?

Not entirely. A well-implemented standard covers most ISMS requirements, but the Act imposes obligations the standard does not cover: entry in the KSC register, incident reporting via S46 within 24 and 72 hours, personal liability of the head of the entity and audits of essential entities. During implementation we prepare the company for each of them.

Does the KSC Act require an ISO 27001 certificate?

No. The Act requires a working ISMS, not a certificate. A certificate is useful when you want to demonstrate compliance to customers or in tenders.

Is it worth implementing ISO 27001 and ISO 22301 together?

Yes, if service downtime is your main risk. Both standards share the same clause structure, so part of the documentation, the internal audits and the management reviews can be run jointly. The KSC Act requires business continuity plans anyway.

What is a Statement of Applicability (SoA)?

A document in which, for each of the 93 Annex A controls of ISO/IEC 27001:2022, you state whether you apply it, why, and to what extent it is implemented. It is where the auditor starts.

Who issues the ISO 27001 certificate?

A certification body accredited, for example, by the Polish Centre for Accreditation (PCA). PWNONE does not issue certificates. We prepare the organization for the audit and support it during the audit.

What is the deadline for implementing an ISMS under the KSC Act?

Companies that met the criteria for an essential or important entity on 3 April 2026 have until 3 April 2027. Those that meet the criteria later have 12 months from that date. An essential entity must complete its first audit within 24 months of meeting the criteria, and then at least every 3 years. For entities covered since the Act took effect, that deadline is 3 April 2028. This does not apply to former operators of essential services.

Start with a gap analysis

After 2–3 weeks you know where you stand against ISO 27001 and the KSC Act and how much work remains. That is the basis for deciding on a full implementation.