Compliance & Regulations

Security Audits
and Compliance

We help organizations meet regulatory requirements and industry security standards. We carry out comprehensive compliance audits against ISO 27001, NIS2, GDPR, the NCSA, PCI DSS and DORA - from gap analysis to full support during certification.

  • Experience with ISO 27001, NIS2 and DORA audits
  • Auditors certified in CISA, CISSP, Lead Auditor
  • End-to-end support: from gap analysis to certification
Security and compliance audit

Standards and regulations

We specialize in the key information security standards and legal regulations in force in Poland and the European Union.

ISO 27001

Comprehensive preparation for certification of an Information Security Management System. Gap analysis, policy development, training and support during the certification audit.

NIS2 Directive

Verification of compliance with the requirements of the NIS2 Directive for essential and important entities. Assessment of risk management, incident reporting and supply chain security.

GDPR

Audit of personal data processing, data protection impact assessment (DPIA), verification of legal bases, breach notification procedures and the security of IT systems processing data.

NCSA / Act on the NCSS

Audit of compliance with the Act on the National Cybersecurity System. Verification of the obligations of operators of essential services and digital service providers.

PCI DSS

Assessment of compliance with payment card data security requirements. ASV scanning, penetration testing and preparation for PCI DSS v4.0 certification.

DORA

Support for financial institutions in meeting the requirements of the DORA Regulation on digital operational resilience - ICT testing, risk management and business continuity.

How do regulations connect with each other?

ISO 27001, NIS2 and DORA do not exist in a vacuum. They form a coherent ecosystem in which one standard is the foundation for the next. Understanding these dependencies is the key to efficient implementation.

ISO 27001

Foundation

The international ISMS standard. It forms the base on which the NIS2 and DORA requirements rest. Holding an ISO 27001 certificate significantly facilitates demonstrating compliance with both regulations.

93 controls (Annex A)Voluntary certification

NIS2 Directive

EU Law

Article 21 of NIS2 explicitly recommends the use of international standards (ISO 27001) as a means of meeting the requirements. ISO 27001 covers approx. 70% of NIS2 requirements.

DORA Regulation

Financial Sector

DORA is lex specialis relative to NIS2 for the financial sector. It requires an ICT risk management framework analogous to ISO 27001, adding mandatory TLPT testing (red teaming).

Strategy: start with ISO 27001

Implementing ISO 27001 as the first step lets you build a solid ISMS foundation and cover a significant portion of the NIS2 and DORA requirements at the same time. It is the most cost-effective path to full regulatory compliance.

Regulatory timeline

2016 / MAY

GDPR adopted

The General Data Protection Regulation enters into force (applicable from May 2018). It establishes data protection standards across the EU.

2022 / OCT

ISO 27001:2022

The updated version of the standard is published with 11 new controls, including cloud security, threat intelligence and data protection.

2022 / DEC

NIS2 & DORA adopted

The European Parliament adopts the NIS2 Directive and the DORA Regulation. The transposition and preparation periods begin.

2024 / OCT

NIS2 transposition deadline

Member states were required to transpose NIS2 into national law. Poland is working on an amendment to the NCSA (Act on the NCSS).

2025 / JAN

DORA applies

The DORA Regulation begins to apply directly in all EU countries. Financial institutions must be fully compliant.

2026 / 3 APR

Entry into force of the NCSA (Poland)

The amendment to the NCSA transposing NIS2 enters into force after a vacatio legis of 1 month. New obligations for essential and important entities.

2026 / 3 OCT

Entity registration (+6 months)

Obligation to submit a notification to the register of essential and important entities maintained by the minister responsible for digital affairs.

2027 / 3 APR

ISMS implementation (+12 months)

Deadline for implementing an information security management system compliant with the NCSA/NIS2 requirements.

2028 / 3 APR

First audit (+24 months)

Mandatory first compliance audit, applies only to essential entities. Important entities are exempt from this obligation.

International Standard

ISO 27001:2022

The gold standard of information security management. An Information Security Management System (ISMS) based on a process approach and continual improvement (PDCA).

Who it applies to:Any organization - certification is voluntary, but increasingly required by business partners and regulators
Scope:93 controls across 4 domains: organizational (37), people (8), physical (14), technological (34)
What's new in 2022:Threat intelligence, cloud security, ICT readiness for business continuity, secure coding

Relationships with other regulations

ISO 27001 → NIS2

Article 21(1) of NIS2 requires the implementation of appropriate risk management measures. ISO 27001 is explicitly named as a recognized framework. It covers approx. 70% of NIS2 requirements, including incident management, business continuity and supply chain security.

ISO 27001 → DORA

DORA requires an ICT risk management framework aligned with international standards. Organizations with an ISO 27001 certificate have already implemented ~60% of DORA requirements - what remains is to add TLPT testing, ICT third-party management and specific sector reporting.

ISO 27001 → GDPR

ISO 27001 supports compliance with Article 32 of the GDPR (security of processing). It is complemented by ISO 27701 - an extension of the ISMS for privacy management (PIMS), which maps directly to the GDPR requirements.

Key NIS2 requirements

Risk management (Article 21)

Mandatory implementation of appropriate technical, operational and organizational measures. The risk assessment must cover the supply chain.

Incident reporting (Article 23)

Early warning within 24h, notification within 72h, final report within 1 month. Reporting to the CSIRT or the competent national authority.

Management accountability (Article 20)

Management bodies are personally accountable for approving and overseeing cybersecurity measures. Mandatory training for senior staff.

Supply chain security

Assessment of ICT suppliers, management of risks related to outsourcing and relationships with technology partners.

EU Directive 2022/2555

The NIS2 Directive

The broadest cybersecurity regulation in EU history. It covers more than 18 sectors of the economy and introduces strict requirements for essential and important entities.

Who it applies to:Essential entities (energy, transport, health, finance, public administration) and important entities (postal services, food, manufacturing, ICT) - medium and large companies
Penalties:Up to EUR 10 million or 2% of annual turnover (essential entities), EUR 7 million or 1.4% (important entities)
Relationship with ISO 27001:NIS2 explicitly recommends the use of the ISO/IEC 27000 standards. Implementing ISO 27001 covers most of the Article 21 requirements
Relationship with DORA:Financial entities subject to DORA are exempt from the corresponding NIS2 requirements

Implementation timeline for NIS2 in Poland

From the entry into force of the act, organizations have strictly defined deadlines for registration, implementation of a security management system and the first audit.

December 2022
Publication of the NIS2 Directive
Published in the Official Journal of the European Union
October 2024
Transposition deadline
Deadline for transposition into the national law of EU member states
3 April 2026
Entry into force of the act
Amendment to the NCSA transposing NIS2 (vacatio legis, 1 month)
3 October 2026
Entity registration (+6 months)
Obligation to notify the register of essential and important entities
3 April 2027
ISMS implementation (+12 months)
Implementation of an information security management system
3 April 2028
First audit (+24 months)
Applies only to essential entities
EU Regulation 2022/2554

DORADigital Operational Resilience Act

The first pan-European regulation on the digital operational resilience of the financial sector. It applies directly from 17 January 2025 - with no need for transposition.

Who it applies to:Banks, insurers, investment funds, payment firms, exchanges, e-money institutions, as well as critical ICT third-party providers for the financial sector
Relationship with ISO 27001:The ICT risk management framework (Chapter II of DORA) builds on the ISO 27001 approach. An ISO certificate significantly accelerates compliance
Relationship with NIS2:DORA is lex specialis relative to NIS2 - financial entities apply DORA instead of the corresponding NIS2 provisions (Article 4 of DORA)

The 5 pillars of DORA

I

ICT risk management

A framework for identification, protection, detection, response and recovery. ICT security policies, asset classification and business continuity.

II

Incident reporting

Classification of ICT incidents, notification of supervisory authorities. Early warning within 4h, intermediate report within 72h, final report within 1 month.

III

Digital resilience testing

Regular penetration testing, vulnerability scanning, scenario-based testing. Advanced TLPT (Threat-Led Penetration Testing) every 3 years.

IV

ICT third-party risk management

Due diligence of ICT providers, contractual clauses, exit strategies. Critical ICT providers are subject to direct oversight by the EBA/ESMA/EIOPA.

V

Threat information sharing

Encouragement to share information on cyber threats among financial entities within trusted communities (ISACs).

Security audit process

What does our audit look like?

We carry out audits in a structured and transparent way. At every stage we report on progress and involve the right people from your organization.

1

Kick-off and Scoping

Kick-off workshops with stakeholders. We define the audit scope, the selected standards/regulations, the schedule and the key systems to be assessed.

2

Documentation Review

Review of existing policies, procedures and registers. Mapping of information processing processes and identification of critical assets.

3

Technical and Organizational Audit

Interviews with key personnel, verification of system configuration, access control, logs, backups. Technical security testing.

4

Reporting and Remediation Plan

A detailed report with nonconformities, priorities and specific recommendations. An implementation roadmap with estimated time and resources.

5

Implementation and Support

We help implement the recommendations - from drafting policies, through system configuration, to preparing the team for the certification audit.

Co deliver?

We don't stop at the report. We deliver a comprehensive package of documents, policies and recommendations, and then help you implement them.

Gap Analysis

A detailed compliance matrix comparing the organization's current state with the requirements of the chosen standard or regulation. Identification of missing controls and implementation priorities.

Policies and Procedures

Development or update of complete ISMS documentation: Information Security Policy, incident management procedures, business continuity plan (BCP/DRP).

Risk Assessment

Methodical identification, analysis and evaluation of information security risks. A risk matrix with assigned responsibilities and risk treatment plans.

Technical Audit

Verification of the configuration of IT systems, networks, servers and applications against regulatory requirements. Hardening, access control, encryption and event logging.

Employee Training

Awareness programs for employees and management. Phishing simulations, incident response workshops and training on security policies and procedures.

Certification Support

We accompany you during the certification audit. We help answer auditors' questions, present evidence and close any nonconformities within the set deadline.

Why choose PWNONE?

We combine technical expertise with audit experience. Our specialists not only find compliance gaps, but understand the technical context and can point to the most effective solutions.

Certified auditors

CISA, CISSP, ISO 27001 Lead Auditor, CRISC - our team holds internationally recognized audit and security certifications.

Risk-based approach

We don't implement "blindly" - we prioritize controls based on the real risk to your business, industry and threat model.

Pentest + Compliance = the full picture

As both a pentesting and an audit firm, we combine both worlds. We complement compliance audits with real technical security testing.

PWNONE audit team
50+

Compliance audits conducted

100%

Of clients achieved certification

6+

Standards and regulations covered

15+

Certified auditors

Prepare your organization for regulatory requirements

Non-compliance with NIS2 or the GDPR means financial penalties, plus the risk of losing the trust of customers and business partners. Start with a free consultation.