Service

Readiness review

The first step for an organisation that wants to know where it stands and what to do first. In 2.5 days you get a prioritised list of gaps and a 90-day action plan.

What you get

  1. A check whether your organisation is subject to the regulations and whether its status on the KSC register is correct.
  2. Interviews with key people.
  3. A review of documents and actual practice.
  4. A list of gaps prioritised by risk and requirements.
  5. A 90-day action plan, discussed with management.

Who it is for

  • Entities on the KSC register before or during implementation.
  • Companies whose clients require evidence of security.
  • Organisations that want to start without a large project.

How it works

2.5 days of work: interviews, a review of documents and practice, and a discussion of the results with management. We give you a fixed price and fixed scope in the first conversation. The fee is credited towards implementation or ongoing support.

What the review is not

The review is not a statutory audit within the meaning of Article 15 of the Polish National Cybersecurity System Act. It is a diagnosis that shows where to start.