Security Audits
and Compliance
We help organizations meet regulatory requirements and industry security standards. We carry out comprehensive compliance audits against ISO 27001, NIS2, GDPR, the NCSA, PCI DSS and DORA - from gap analysis to full support during certification.
- Experience with ISO 27001, NIS2 and DORA audits
- Auditors certified in CISA, CISSP, Lead Auditor
- End-to-end support: from gap analysis to certification

Standards and regulations
We specialize in the key information security standards and legal regulations in force in Poland and the European Union.
ISO 27001
Comprehensive preparation for certification of an Information Security Management System. Gap analysis, policy development, training and support during the certification audit.
NIS2 Directive
Verification of compliance with the requirements of the NIS2 Directive for essential and important entities. Assessment of risk management, incident reporting and supply chain security.
GDPR
Audit of personal data processing, data protection impact assessment (DPIA), verification of legal bases, breach notification procedures and the security of IT systems processing data.
NCSA / Act on the NCSS
Audit of compliance with the Act on the National Cybersecurity System. Verification of the obligations of operators of essential services and digital service providers.
PCI DSS
Assessment of compliance with payment card data security requirements. ASV scanning, penetration testing and preparation for PCI DSS v4.0 certification.
DORA
Support for financial institutions in meeting the requirements of the DORA Regulation on digital operational resilience - ICT testing, risk management and business continuity.
How do regulations connect with each other?
ISO 27001, NIS2 and DORA do not exist in a vacuum. They form a coherent ecosystem in which one standard is the foundation for the next. Understanding these dependencies is the key to efficient implementation.
ISO 27001
FoundationThe international ISMS standard. It forms the base on which the NIS2 and DORA requirements rest. Holding an ISO 27001 certificate significantly facilitates demonstrating compliance with both regulations.
NIS2 Directive
EU LawArticle 21 of NIS2 explicitly recommends the use of international standards (ISO 27001) as a means of meeting the requirements. ISO 27001 covers approx. 70% of NIS2 requirements.
DORA Regulation
Financial SectorDORA is lex specialis relative to NIS2 for the financial sector. It requires an ICT risk management framework analogous to ISO 27001, adding mandatory TLPT testing (red teaming).
Strategy: start with ISO 27001
Implementing ISO 27001 as the first step lets you build a solid ISMS foundation and cover a significant portion of the NIS2 and DORA requirements at the same time. It is the most cost-effective path to full regulatory compliance.
Regulatory timeline
GDPR adopted
The General Data Protection Regulation enters into force (applicable from May 2018). It establishes data protection standards across the EU.
ISO 27001:2022
The updated version of the standard is published with 11 new controls, including cloud security, threat intelligence and data protection.
NIS2 & DORA adopted
The European Parliament adopts the NIS2 Directive and the DORA Regulation. The transposition and preparation periods begin.
NIS2 transposition deadline
Member states were required to transpose NIS2 into national law. Poland is working on an amendment to the NCSA (Act on the NCSS).
DORA applies
The DORA Regulation begins to apply directly in all EU countries. Financial institutions must be fully compliant.
Entry into force of the NCSA (Poland)
The amendment to the NCSA transposing NIS2 enters into force after a vacatio legis of 1 month. New obligations for essential and important entities.
Entity registration (+6 months)
Obligation to submit a notification to the register of essential and important entities maintained by the minister responsible for digital affairs.
ISMS implementation (+12 months)
Deadline for implementing an information security management system compliant with the NCSA/NIS2 requirements.
First audit (+24 months)
Mandatory first compliance audit, applies only to essential entities. Important entities are exempt from this obligation.
ISO 27001:2022
The gold standard of information security management. An Information Security Management System (ISMS) based on a process approach and continual improvement (PDCA).
Relationships with other regulations
Article 21(1) of NIS2 requires the implementation of appropriate risk management measures. ISO 27001 is explicitly named as a recognized framework. It covers approx. 70% of NIS2 requirements, including incident management, business continuity and supply chain security.
DORA requires an ICT risk management framework aligned with international standards. Organizations with an ISO 27001 certificate have already implemented ~60% of DORA requirements - what remains is to add TLPT testing, ICT third-party management and specific sector reporting.
ISO 27001 supports compliance with Article 32 of the GDPR (security of processing). It is complemented by ISO 27701 - an extension of the ISMS for privacy management (PIMS), which maps directly to the GDPR requirements.
Key NIS2 requirements
Risk management (Article 21)
Mandatory implementation of appropriate technical, operational and organizational measures. The risk assessment must cover the supply chain.
Incident reporting (Article 23)
Early warning within 24h, notification within 72h, final report within 1 month. Reporting to the CSIRT or the competent national authority.
Management accountability (Article 20)
Management bodies are personally accountable for approving and overseeing cybersecurity measures. Mandatory training for senior staff.
Supply chain security
Assessment of ICT suppliers, management of risks related to outsourcing and relationships with technology partners.
The NIS2 Directive
The broadest cybersecurity regulation in EU history. It covers more than 18 sectors of the economy and introduces strict requirements for essential and important entities.
Implementation timeline for NIS2 in Poland
From the entry into force of the act, organizations have strictly defined deadlines for registration, implementation of a security management system and the first audit.
DORADigital Operational Resilience Act
The first pan-European regulation on the digital operational resilience of the financial sector. It applies directly from 17 January 2025 - with no need for transposition.
The 5 pillars of DORA
ICT risk management
A framework for identification, protection, detection, response and recovery. ICT security policies, asset classification and business continuity.
Incident reporting
Classification of ICT incidents, notification of supervisory authorities. Early warning within 4h, intermediate report within 72h, final report within 1 month.
Digital resilience testing
Regular penetration testing, vulnerability scanning, scenario-based testing. Advanced TLPT (Threat-Led Penetration Testing) every 3 years.
ICT third-party risk management
Due diligence of ICT providers, contractual clauses, exit strategies. Critical ICT providers are subject to direct oversight by the EBA/ESMA/EIOPA.
Threat information sharing
Encouragement to share information on cyber threats among financial entities within trusted communities (ISACs).

What does our audit look like?
We carry out audits in a structured and transparent way. At every stage we report on progress and involve the right people from your organization.
Kick-off and Scoping
Kick-off workshops with stakeholders. We define the audit scope, the selected standards/regulations, the schedule and the key systems to be assessed.
Documentation Review
Review of existing policies, procedures and registers. Mapping of information processing processes and identification of critical assets.
Technical and Organizational Audit
Interviews with key personnel, verification of system configuration, access control, logs, backups. Technical security testing.
Reporting and Remediation Plan
A detailed report with nonconformities, priorities and specific recommendations. An implementation roadmap with estimated time and resources.
Implementation and Support
We help implement the recommendations - from drafting policies, through system configuration, to preparing the team for the certification audit.
Co deliver?
We don't stop at the report. We deliver a comprehensive package of documents, policies and recommendations, and then help you implement them.
Gap Analysis
A detailed compliance matrix comparing the organization's current state with the requirements of the chosen standard or regulation. Identification of missing controls and implementation priorities.
Policies and Procedures
Development or update of complete ISMS documentation: Information Security Policy, incident management procedures, business continuity plan (BCP/DRP).
Risk Assessment
Methodical identification, analysis and evaluation of information security risks. A risk matrix with assigned responsibilities and risk treatment plans.
Technical Audit
Verification of the configuration of IT systems, networks, servers and applications against regulatory requirements. Hardening, access control, encryption and event logging.
Employee Training
Awareness programs for employees and management. Phishing simulations, incident response workshops and training on security policies and procedures.
Certification Support
We accompany you during the certification audit. We help answer auditors' questions, present evidence and close any nonconformities within the set deadline.
Why choose PWNONE?
We combine technical expertise with audit experience. Our specialists not only find compliance gaps, but understand the technical context and can point to the most effective solutions.
Certified auditors
CISA, CISSP, ISO 27001 Lead Auditor, CRISC - our team holds internationally recognized audit and security certifications.
Risk-based approach
We don't implement "blindly" - we prioritize controls based on the real risk to your business, industry and threat model.
Pentest + Compliance = the full picture
As both a pentesting and an audit firm, we combine both worlds. We complement compliance audits with real technical security testing.

Compliance audits conducted
Of clients achieved certification
Standards and regulations covered
Certified auditors