Cybersecurity for businesses and institutions

Cybersecurity audit and implementation — NIS2, NCSA 2.0 and ISO 27001 without the chaos

From the cybersecurity audit, through compliance analysis, to a full ISO 27001 implementation and NIS2 / NCSA obligations. Check in 2 minutes which requirements actually apply to your organisation.

18sectors covered by NIS2 and NCSA 2.0
EUR 10 mor 2% of turnover — the maximum non-compliance fine
~2 minthat's how long the wizard takes
NIS2NCSA 2.0ISO/IEC 27001GDPRDORA

Your compliance status

Sample wizard result — check yours in 6 steps.

NIS2 DirectiveEU legal obligationRequired
NCSA 2.0Polish law transposing NIS2Required
ISO/IEC 27001management system certificationStrongly recommended
Run the wizard for your company
Why now

NIS2 and NCSA 2.0 are no longer optional — they are the law

The amendment to the Polish National Cybersecurity System Act (NCSA 2.0) transposes the EU NIS2 Directive into Polish law. It covers thousands of companies and institutions that were not subject to any cybersecurity regulation before.

Short deadlines

After the law enters into force, organisations have limited time for registration, risk analysis and implementation of controls. Delay raises cost and risk.

Severe fines

Non-compliance can trigger fines of up to EUR 10 m or 2% of annual turnover — depending on the entity category.

Management liability

Cybersecurity oversight is the personal responsibility of executive management — this is no longer just an IT department matter.

Supply chain pressure

Even if you are not formally in scope of NIS2, your bigger partners will require security attestation to keep working with you.

Scope of services

Cybersecurity audit and implementation — end-to-end, in one place

We combine an IT security audit, regulatory compliance analysis and full implementation. We don't leave you with a report — we run the project all the way to certification and legal compliance.

Stage 1 Cybersecurity audit

Information & IT security audit

The first step of every project. An IT security audit and network security audit show where you really stand and what needs fixing.

  • Asset and process inventory
  • Risk and vulnerability analysis
  • Prioritised report with an action plan
How does a cybersecurity audit go?
  1. Kick-off meeting and scope agreement
  2. Review of documentation, configuration and processes
  3. Technical tests and interviews with the team
  4. Risk assessment report with recommendations

ISO 27001 compliance audit

An ISO 27001 audit verifies how well your information security management system meets the standard's requirements — and what stands between you and certification.

  • Assessment against Annex A
  • Gap analysis
  • Roadmap to certification
What's included in the ISO 27001 audit?

We review the security policy, risk management, organisational and technical controls, plus documentation. You receive a list of non-conformities with priorities and the time required to address them.

NCSA 2.0 / NIS2 compliance audit

The NIS2 and NCSA audit determines whether you are an essential or important entity, and how far you are from meeting your statutory obligations.

  • Entity classification under the law
  • Assessment of obligations and deadlines
  • Path to compliance
Who needs an NCSA / NIS2 audit?

Mostly companies in sectors covered by the directive (energy, healthcare, transport, ICT, manufacturing and others) and their suppliers. If you're not sure — check it in the wizard below.

Stage 2 Implementation and certification

ISO 27001 implementation & certification

We run the ISO 27001 implementation from scratch through to certification by an accredited body — with ready documentation and a trained team.

  • ISMS and documentation
  • Support during the certification audit
  • Post-certification system maintenance
How long does an ISO 27001 implementation take?

Usually a few to a dozen-or-so months — depending on the size of the organisation and the starting point. We set the exact schedule after the initial audit.

NIS2 implementation

NIS2 implementation is not just paperwork — it's real processes: risk management, incident handling, business continuity and supply chain security.

  • Risk management measures
  • Incident reporting procedures
  • Management board training
Where to start with NIS2 implementation?

From determining whether you are an essential or important entity, and from risk analysis. The rest — processes, documentation and controls — we build on that foundation.

NCSA implementation

NCSA implementation aligns your organisation with the Polish National Cybersecurity System Act — registration, reporting obligations and controls.

  • Registration in the NCSA system
  • Required controls implementation
  • Cooperation with the proper CSIRT
How does NCSA 2.0 differ from NIS2?

NIS2 is an EU directive, while NCSA 2.0 is the Polish law that transposes it. For a company operating in Poland, NCSA 2.0 is the direct legal basis for its obligations.

Not sure where to start?

Check in the wizard which regulations apply to your organisation — or book a free consultation.

Go to the wizard
Interactive wizard

Does your organisation need certification?

Answer 6 short questions and we'll check whether NIS2 and NCSA 2.0 obligations apply to you, and how well ISO 27001 certification fits your situation. No contact details required.

Step 1 of 6
Benefits

Why implement ISO 27001, NIS2 and NCSA 2.0?

It's not just regulatory compliance. A well-run project organises the whole company, reduces the risk of costly incidents and opens doors to bigger contracts.

Let's talk about your business

Regulatory compliance

Meet NIS2 and NCSA 2.0 obligations and avoid financial penalties and management liability.

Real resilience

Fewer successful attacks, shorter incident response time and faster restoration of operations.

Edge in tenders

ISO 27001 certification is often a prerequisite for tender participation and B2B work with large companies.

Client trust

Verified information security builds credibility with clients, partners and insurers.

Streamlined processes

Clear roles, procedures and documentation — no more knowledge locked in the heads of individual people.

Lower loss exposure

Reduced probability of downtime, data breaches and financial losses caused by attacks.

How we work

From first call to compliance maintenance

1

Consultation

Free conversation and initial situation analysis.

2

Audit

Cybersecurity audit and gap analysis.

3

Plan

Implementation schedule with priorities.

4

Implementation

Processes, controls and documentation.

5

Certification

Support during audit and compliance filing.

6

Maintenance

Monitoring, reviews and continuous improvement.

Extend security

Services that strengthen your organisation

The best procedures won't work without people and proven controls. These services close the cybersecurity topic in practice.

Cybersecurity awareness training

Building threat awareness among employees and management.

Risk analysis workshops

Practical vulnerability identification, estimation and treatment of risk.

Social engineering tests

Controlled social engineering campaigns testing your team's alertness.

Penetration tests & network audit

Network security audit and penetration tests verifying real system resilience.

Security by Default and Zero Trust

Designing security architecture in a least-trust model.

Post-implementation support

CISO/DPO outsourcing and management system maintenance after certification.

Frequently asked questions

Cybersecurity without the jargon

Short answers to the questions we hear most often before a project begins.

What is ISO 27001?
ISO/IEC 27001 is the international standard specifying requirements for an Information Security Management System. ISO 27001 certification confirms that the organisation manages risk in an organised way and protects the confidentiality, integrity and availability of information.
What is NIS2?
NIS2 is the EU directive raising the level of cybersecurity in essential and important sectors of the economy. It imposes obligations on covered entities for risk management, incident reporting and supply chain security.
What is NCSA 2.0?
NCSA 2.0 is the informal name of the amendment to the Polish National Cybersecurity System Act, which transposes the NIS2 directive into Polish law. For companies operating in Poland, this act is the direct legal basis for their obligations.
What is DORA?
DORA is the EU regulation on digital operational resilience of the financial sector. It covers banks, insurers, payment institutions and their ICT service providers, with detailed requirements for ICT risk management.
Who is covered by NIS2 and NCSA 2.0?
As a rule, medium and large entities from the listed sectors (energy, healthcare, transport, digital infrastructure, manufacturing, waste management). Some entities are covered regardless of size. The simplest way to check is the wizard above or during an audit.
What are the non-compliance fines?
The regulations provide severe financial penalties — depending on the entity category reaching millions of euros or a percentage of annual turnover — as well as supervisory measures and personal management liability for cybersecurity oversight.
How long does implementation take and how much does it cost?
It depends on the size of the organisation, industry and starting point. That's why we begin with an audit and initial analysis — based on which we present a realistic schedule and pricing, with no hidden costs.
How does an audit differ from an implementation?
A cybersecurity audit answers the question "where are we and what's missing". Implementation is the work that closes those gaps — introducing processes, controls and documentation, and leading to certification or legal compliance.
Contact

Strengthen your company — before someone else does it for you

Tell us where you are right now. Together we'll decide whether you need an audit, an implementation or full certification — and what will deliver the fastest result.

DC
Damian CelebudzkiSenior Information Security Consultant
What's next?
  • 1
    We get back to you

    Usually within 1 business day — by phone or e-mail.

  • 2
    Free situation analysis

    Together we decide which obligations and certificates really apply to you.

  • 3
    Concrete plan and quote

    You get recommendations and a schedule — with no commitment.

Fill in the form

We'll get in touch to discuss your situation and the next steps.


    We reply within 1 business day. Your data stays inside our team.

    Wybierz pola, które mają być pokazane. Inne będą ukryte. Przeciągnij i upuść, aby zmienić kolejność.
    • Obraz
    • SKU
    • Ocena
    • Cena
    • Stan magazynowy
    • Dostępność
    • Dodaj do koszyka
    • Opis
    • Treść
    • Waga
    • Wymiary
    • Dodatkowe informacje
    Kliknij na zewnątrz, aby ukryć pasek porównania
    Porównaj