NIS2/KSC · Pricing

NIS2 audit cost and implementation budget

NIS2 audit cost depends mainly on the size of your organisation, the number of locations and of systems supporting your services, and on what you already have in place, such as ISO/IEC 27001. We do not publish fixed prices: we quote gap analysis, KSC Act implementation support and penetration testing individually, after a short scoping call. We reply to enquiries within 24 hours on business days.

01Pricing factors

NIS2 audit cost: what drives the price

The main factors and how they affect the cost of a gap analysis. We give a specific amount in our proposal.

Pricing factors for a NIS2/KSC gap analysis
Factor Impact on cost Why
Size of the organisation and group structure High More units, linked companies and process owners mean more interviews and more evidence to check.
Number of locations Medium to high Physical security and business continuity are assessed for every location where the systems operate.
Number of services and systems High The Act covers the information system used to provide a service - and each service may rely on a different set of systems.
Sector Medium Digital providers also apply Implementing Regulation (EU) 2024/2690, and the financial sector mostly applies DORA.
Maturity High ISO/IEC 27001 in place, a risk register and up-to-date procedures narrow the analysis down to the differences from the Act.
Scope of technical verification Medium Sampling configurations is part of a gap analysis; a full penetration test is quoted separately.
ICT suppliers Low to medium With many critical suppliers, a review of contracts and security assessments is added.
Urgency Medium A start at short notice means re-planning our team's work - and the closer we get to 3 April 2027, the more such requests we receive.
Report language and audience Low A report in both English and Polish (e.g. for the group board and the local team) or an additional presentation for the supervisory board.

02Packages

Packages: gap analysis, implementation and testing

You can commission the services together or separately. We quote each of them in our proposal, because the scope of the same package varies from one organisation to another.

  • Starting point

    Start here

    Gap analysis

    A gap analysis against the KSC Act with an implementation plan - before you spend budget on solutions.

    Individual quote quoted after a short scoping call

    • Scope assessment: essential entity, important entity or out of scope
    • Interviews, document review and technical verification
    • Gap report and compliance matrix
    • Prioritised implementation plan to 3 Apr 2027
    • Board presentation
    Outcome
    You know what you have, what is missing and how much work remains
    Who it is for
    Essential and important entities starting implementation, organisations with ISO/IEC 27001 in place checking the differences
  • Implementation

    Implementation support

    Implementing the information security management system together with your team, or supporting a team that implements it on its own.

    Individual quote the quote depends on the scope and the division of tasks

    • Risk analysis and risk register
    • Policies and procedures tailored to your organisation
    • Technical measures and incident handling
    • Requirements for ICT suppliers
    • Audit preparation
    Outcome
    Obligations implemented and documented before the deadline
    Who it is for
    Organisations without a compliance team or with limited IT resources
  • Statutory audit

    KSC audit (Art. 15)

    A security audit of the information system, carried out in cooperation with a partner by auditors who meet the requirements of Art. 15(2) of the Act.

    Individual quote the quote depends on the number of services, systems and locations

    • A team of at least two auditors with the required qualifications
    • Independence check before the audit starts
    • Assessment of documents and evidence, interviews, sampling
    • Written report with audit documentation
    • Copy of the report ready to submit to the authority within 3 working days
    Outcome
    An audit report under Art. 15 of the KSC Act
    Who it is for
    Essential entities (first audit by 3 Apr 2028) and important entities when ordered by the authority
  • Board

    Board training

    The duties and liability of the head of the entity, and the decisions the Act requires.

    Individual quote the quote depends on the format and the number of participants

    • Duties of the head of the entity and penalties
    • Board decisions in the security management system
    • Incidents: reporting deadlines and the board's role
    • Supply chain, audit and supervision
    Outcome
    The board understands its duties and knows what to ask the team
    Who it is for
    Boards and the people to whom the head of the entity has entrusted cybersecurity duties
  • Verification

    Penetration testing

    A hands-on test of your technical safeguards - evidence of system testing and of assessing the effectiveness of measures.

    Individual quote pricing factors are set out in our pentest pricing guide

    • Web applications, APIs, mobile applications
    • Infrastructure, internal network and Active Directory
    • Cloud and source code review
    • Retest after remediation
    Outcome
    A report with evidence, CVSS scores and recommendations
    Who it is for
    Essential and important entities, service providers to regulated industries

We usually start with a gap analysis: afterwards you know how much work is left and can compare implementation proposals with a concrete plan in hand. We carry out the KSC audit under Art. 15 in cooperation with a partner, with one proviso: we do not audit organisations that we helped to implement a security management system in the year before the audit. Pricing factors for penetration testing are set out in our penetration testing pricing guide.

03Budget

NIS2 implementation cost: what goes into the budget

Consultancy fees are only part of the budget. When you plan implementation, take every component into account.

Components of a NIS2/KSC implementation budget
Component What it covers Who usually delivers it
Analysis and plan Gap analysis, scope assessment, prioritised implementation plan An external consultant or an internal team
Documentation and processes Risk analysis, policies, procedures, incident handling, supplier management An internal team with consultant support
Technology E.g. multi-factor authentication, backups, monitoring and logs, vulnerability management IT and technology suppliers - licence and hardware purchases are outside the consultancy service
Team time Involvement of process owners, administrators, and the procurement and legal teams Your organisation
Education Staff education and annual training for the head of the entity An internal team or an external trainer
Verification Penetration tests, a business continuity plan test, a review of the effectiveness of measures Independent testers and the internal team
Art. 15 audit Essential entities: the first audit by 3 Apr 2028, then at least once every 3 years Auditors who meet the requirements of the Act and are independent of the people who implemented the system

What affects implementation cost most is how the work is divided: the more your team does, the less you pay for external services - but the more time your people have to spend. The plan from the gap analysis shows both options. Implementation stages and the division of tasks are described on our NIS2 implementation page.

04Cost of inaction

The cost of non-compliance

Facts from the Act, without scaremongering - so that your cost comparison is complete.

Maximum fines under the KSC Act
Who it applies to Amount
Essential entity up to EUR 10 million or 2% of revenue from business activity in the previous financial year, whichever is higher; not less than PLN 20,000
Important entity up to EUR 7 million or 1.4% of revenue from business activity in the previous financial year; not less than PLN 15,000
Head of the entity up to 300% of remuneration (calculated in the same way as pay in lieu of annual leave), up to 100% in a public entity

A fine is only part of the cost. The competent authority may also issue decisions ordering, among other things, an audit - of an essential entity at any time, and of an important entity after a significant incident or another infringement - and the implementation of audit recommendations (Art. 15(1b), Art. 53(5)). The most expensive item, however, remains the incident itself: service downtime, system recovery and obligations towards customers. The liability of the board is described in more detail in our guide to the NIS2/KSC audit.

05Enquiry

How to prepare a NIS2 audit enquiry

The more of this information you provide up front, the shorter the scoping call and the sooner you get a proposal:

  1. Sector and type of business - ideally with information on whether an application for registration has been submitted.
  2. Size - the number of employees and of companies in the group, and the number of locations.
  3. Services and systems - which services you provide and which systems support them, including in the cloud and at suppliers.
  4. Current state - ISO/IEC 27001 or other standards, existing policies, recent audits and tests.
  5. Scope - a gap analysis only, or also implementation support and penetration testing.
  6. Timing - when you want to start and when you need the plan.
  7. Audience and language - the board, the supervisory board or the parent company, and the language of the report.

06Public sector

Requests for proposals and tenders for a cybersecurity audit

The KSC Act covers many Polish public entities - including public finance sector units, regional (voivodeship) governments, district (powiat) offices and municipal offices employing at least 50 people, counted in full-time equivalents (Annex 1), as well as local government budgetary units, cultural institutions and municipal companies (Annex 2). Important entities that are public entities apply the requirements of Annex 4 to the Act instead of Art. 8(1) (Art. 8(3)).

If you are preparing a request for proposals or a tender, you can invite us to submit a proposal. We will prepare it on the basis of your specification (the description of the subject matter of the contract).

What to include in the specification

  • type of service - gap analysis, implementation support or the Art. 15 audit (which we carry out in cooperation with a partner); for the latter, the requirements for auditors follow from Art. 15(2) of the Act,
  • scope - units, locations, services and systems,
  • deliverables - gap report, compliance matrix, implementation plan, presentation for management,
  • timing - taking into account the 3 April 2027 deadline for implementing the obligations,
  • organisational requirements - confidentiality, how documents are accessed, contact persons.

Frequently asked questions

How much does a NIS2 audit cost?

We do not quote a fixed amount, because the scope of a gap analysis for a company with one location and a few systems is completely different from that for a group with many services. The cost depends on size, the number of locations and systems, the sector, maturity and the scope of technical verification. We give the price and timeline in our proposal after a short scoping call.

Is a gap analysis cheaper if we have ISO/IEC 27001?

Usually, yes. We use your Statement of Applicability, risk register and the evidence from your management system, and focus the analysis on the requirements of the Act that the standard does not cover. One condition: the scope of the certificate should include the systems used to provide the service. More: NIS2 gap analysis.

How much does the Art. 15 KSC audit cost?

We quote it separately, because the price depends on the number of services, systems and locations covered by the audit. We carry out the audit in cooperation with a partner, by auditors who meet the requirements of Art. 15(2). An essential entity should plan it in its budget: the first audit is due by 3 April 2028, then at least once every 3 years. If we supported your implementation in the year before the audit, another auditor will carry it out - in that case we help you prepare for it.

Can implementation be split into stages?

Yes - the plan from the gap analysis breaks the work down by risk and deadline, and each stage can be commissioned separately. Bear in mind, though, that the obligations under the Act must be in place by 3 April 2027, so the plan has to fit that deadline. The stages are described on our NIS2 implementation page.

Do you respond to requests for proposals from public bodies?

Yes. Based on your specification (the description of the subject matter of the contract), we will prepare a proposal with the scope, a schedule and a list of deliverables. When describing the scope, it helps to distinguish between a gap analysis, implementation support and the Art. 15 audit - three different services with different requirements for the contractor.

Sources

  1. Act of 23 January 2026 amending the National Cybersecurity System Act and certain other acts (Dz.U. 2026 item 252) (in Polish) ()
  2. Act of 5 July 2018 on the National Cybersecurity System (KSC Act; Dz.U. 2018 item 1560, as amended) - ISAP, unofficial consolidated text prepared by the Chancellery of the Sejm (in Polish) ()
  3. Ministry of Digital Affairs - Q&A on the amendment to the KSC Act (explanatory document, not legally binding) (in Polish) ()

Legal status as of Updated

Related services

Let's talk about your project or audit

Tell us briefly what you need - we will come back with proposed next steps. We work in English and Polish.

or call +48 575 621 877