Institute

Institute

The Institute is IS Consulting's expert initiative. Beyond our advisory work, we engage with the security of the whole market: we share knowledge, analyse the impact of regulation and take part in public consultations at national and European level. The materials published here are expert and informational in nature. We base our positions on European sources and formulate them as a contribution to dialogue, from the perspective of small and medium organisations and the healthcare sector.

Flagship project

The ASCLEPIUS project

Our flagship undertaking is ASCLEPIUS, a project in which a consortium of Polish microenterprises, coordinated by IS Consulting, raises the level of cybersecurity at European healthcare facilities. The project is funded by the Digital Europe Programme via the ECCC, and we provide services to beneficiaries pro bono. We work in an advisory, vendor agnostic model, focusing on maturity, resilience and real world feasibility.

Explore the project

Whitepapers

Overview analyses of the impact of regulation on organisations, with practical preparation guidance.

  • Navigating EU Cybersecurity Laws

    English

    A Comprehensive Guide for SMEs

    A cross-cutting guide to the EU cybersecurity regulatory landscape (GDPR, NIS2, DORA, CRA, AI Act, sector-specific rules) from the SME perspective, including a timeline of key deadlines, a twelve-month implementation roadmap, compliance checklists and a regulatory map. Useful for SME owners and managers and for compliance officers who want to establish which rules apply to them and how to prepare.

  • NIS2 & CRA: New EU Regulations, New Opportunity?

    Polish

    An analysis of the impact of the NIS2 directive and the CRA regulation on Polish small and medium enterprises and non-governmental organisations, covering benefits, costs, risks, indirect obligations arising from the supply chain and practical preparation steps. Useful for boards and staff of SMEs and NGOs assessing the scope of their obligations and planning implementation.

  • CRA in Healthcare

    English

    EU Cyber Resilience Act: Impact on Healthcare Supply Chain

    An analysis of the impact of the CRA regulation on the healthcare supply chain, covering vulnerabilities in medical devices and software, the obligations of four stakeholder groups (device manufacturers, pharmaceutical distributors, smart pharmacies, IT suppliers), the tiered conformity assessment system and links to MDR, NIS2, GDPR and EHDS. Useful for healthcare entities and their suppliers preparing for CRA requirements ahead of 2027.

Position papers

Consultation position papers contributing to regulatory work, from the perspective of SMEs and healthcare.

  • Position paper: cross-border identification and authentication (EHDS)

    English

    Draft Commission Implementing Regulation on an Interoperable, Cross-Border Identification and Authentication Mechanism for Natural Persons, Health Professionals and Healthcare Providers for the Purposes of the Cross-Border Exchange of Personal Electronic Health Data

    A consultation position paper on the draft Commission implementing regulation on the cross-border identification and authentication mechanism for the exchange of electronic health data under EHDS, contributing the perspective of practical IAM implementation in healthcare. It highlights areas needing clarification, such as representation and legal guardianship, attribute protection, proportionality for smaller entities and operational resilience.

  • Position paper: MyHealth@EU

    English

    Draft Commission Implementing Regulation on MyHealth@EU

    A consultation position paper on the draft Commission implementing regulation on MyHealth@EU, assessing the draft positively and offering recommendations in the areas of greatest operational and security significance, such as requirements for national contact points, response to critical incidents, cryptography and proportionality for less mature national systems. Useful for organisations involved in work on cross-border health data exchange.

  • Position paper: ENISA ad hoc working group on standardisation

    English

    Statement on the ENISA Ad Hoc Working Group on Cybersecurity Standardization

    A position paper contributing to the work of the ENISA ad hoc working group on cybersecurity standardisation, emphasising the SME perspective and the need for proportionality, technological neutrality and reliance on existing international standards. It sets out five principles recommended to keep standards workable in the reality of smaller organisations.

  • Position paper: reform of the Cybersecurity Act (CSA2)

    English

    IS Consulting Position on the Proposed Reform of the Cybersecurity Act (CSA2)

    A position paper contributing to the discussion on the reform of the Cybersecurity Act (CSA2), setting out four principles (proportionality and a risk-based approach, certification as a mechanism that facilitates compliance, consistency of the EU regulatory framework, technological neutrality) from the perspective of SME feasibility. Useful for consultation participants and organisations following the development of European certification frameworks.

  • Position paper: Cybersecurity Strategy of the Republic of Poland

    Polish

    Strategia Cyberbezpieczeństwa Rzeczypospolitej Polskiej. Wnioski i Rekomendacje

    A consultation contribution to the draft Cybersecurity Strategy of the Republic of Poland, analysing the draft's provisions regarding the separation of state roles (regulator, integrator, trust operator) and the risk of crowding out the commercial services market, with proposals for instruments strengthening demand and feasibility in the SME segment. It brings the market and SME perspective to the debate on national cybersecurity policy.

ShieldNet

We created ShieldNet, a cybersecurity framework intended for organisations with limited resources. ShieldNet is now developed as a separate project, with its own website and its own development path. It consists of a controls framework with a management system, sector add-ons including one for healthcare, and an education programme mapped to the ECSF. IS Consulting uses ShieldNet internally and recommends it to clients. ShieldNet is not a regulatory requirement.

Learn more at shieldnet.eu