NIS2/KSC · Gap analysis
Gap analysis
NIS2 gap analysis against the Polish KSC Act: scope, method, gap report, compliance matrix and an implementation plan to meet the 3 April 2027 deadline.
NIS2/KSC · Pricing
NIS2 audit cost depends mainly on the size of your organisation, the number of locations and of systems supporting your services, and on what you already have in place, such as ISO/IEC 27001. We do not publish fixed prices: we quote gap analysis, KSC Act implementation support and penetration testing individually, after a short scoping call. We reply to enquiries within 24 hours on business days.
01Pricing factors
The main factors and how they affect the cost of a gap analysis. We give a specific amount in our proposal.
| Factor | Impact on cost | Why |
|---|---|---|
| Size of the organisation and group structure | High | More units, linked companies and process owners mean more interviews and more evidence to check. |
| Number of locations | Medium to high | Physical security and business continuity are assessed for every location where the systems operate. |
| Number of services and systems | High | The Act covers the information system used to provide a service - and each service may rely on a different set of systems. |
| Sector | Medium | Digital providers also apply Implementing Regulation (EU) 2024/2690, and the financial sector mostly applies DORA. |
| Maturity | High | ISO/IEC 27001 in place, a risk register and up-to-date procedures narrow the analysis down to the differences from the Act. |
| Scope of technical verification | Medium | Sampling configurations is part of a gap analysis; a full penetration test is quoted separately. |
| ICT suppliers | Low to medium | With many critical suppliers, a review of contracts and security assessments is added. |
| Urgency | Medium | A start at short notice means re-planning our team's work - and the closer we get to 3 April 2027, the more such requests we receive. |
| Report language and audience | Low | A report in both English and Polish (e.g. for the group board and the local team) or an additional presentation for the supervisory board. |
02Packages
You can commission the services together or separately. We quote each of them in our proposal, because the scope of the same package varies from one organisation to another.
A gap analysis against the KSC Act with an implementation plan - before you spend budget on solutions.
Individual quote quoted after a short scoping call
Implementing the information security management system together with your team, or supporting a team that implements it on its own.
Individual quote the quote depends on the scope and the division of tasks
A security audit of the information system, carried out in cooperation with a partner by auditors who meet the requirements of Art. 15(2) of the Act.
Individual quote the quote depends on the number of services, systems and locations
The duties and liability of the head of the entity, and the decisions the Act requires.
Individual quote the quote depends on the format and the number of participants
A hands-on test of your technical safeguards - evidence of system testing and of assessing the effectiveness of measures.
Individual quote pricing factors are set out in our pentest pricing guide
We usually start with a gap analysis: afterwards you know how much work is left and can compare implementation proposals with a concrete plan in hand. We carry out the KSC audit under Art. 15 in cooperation with a partner, with one proviso: we do not audit organisations that we helped to implement a security management system in the year before the audit. Pricing factors for penetration testing are set out in our penetration testing pricing guide.
03Budget
Consultancy fees are only part of the budget. When you plan implementation, take every component into account.
| Component | What it covers | Who usually delivers it |
|---|---|---|
| Analysis and plan | Gap analysis, scope assessment, prioritised implementation plan | An external consultant or an internal team |
| Documentation and processes | Risk analysis, policies, procedures, incident handling, supplier management | An internal team with consultant support |
| Technology | E.g. multi-factor authentication, backups, monitoring and logs, vulnerability management | IT and technology suppliers - licence and hardware purchases are outside the consultancy service |
| Team time | Involvement of process owners, administrators, and the procurement and legal teams | Your organisation |
| Education | Staff education and annual training for the head of the entity | An internal team or an external trainer |
| Verification | Penetration tests, a business continuity plan test, a review of the effectiveness of measures | Independent testers and the internal team |
| Art. 15 audit | Essential entities: the first audit by 3 Apr 2028, then at least once every 3 years | Auditors who meet the requirements of the Act and are independent of the people who implemented the system |
What affects implementation cost most is how the work is divided: the more your team does, the less you pay for external services - but the more time your people have to spend. The plan from the gap analysis shows both options. Implementation stages and the division of tasks are described on our NIS2 implementation page.
04Cost of inaction
Facts from the Act, without scaremongering - so that your cost comparison is complete.
| Who it applies to | Amount |
|---|---|
| Essential entity | up to EUR 10 million or 2% of revenue from business activity in the previous financial year, whichever is higher; not less than PLN 20,000 |
| Important entity | up to EUR 7 million or 1.4% of revenue from business activity in the previous financial year; not less than PLN 15,000 |
| Head of the entity | up to 300% of remuneration (calculated in the same way as pay in lieu of annual leave), up to 100% in a public entity |
A fine is only part of the cost. The competent authority may also issue decisions ordering, among other things, an audit - of an essential entity at any time, and of an important entity after a significant incident or another infringement - and the implementation of audit recommendations (Art. 15(1b), Art. 53(5)). The most expensive item, however, remains the incident itself: service downtime, system recovery and obligations towards customers. The liability of the board is described in more detail in our guide to the NIS2/KSC audit.
05Enquiry
The more of this information you provide up front, the shorter the scoping call and the sooner you get a proposal:
06Public sector
The KSC Act covers many Polish public entities - including public finance sector units, regional (voivodeship) governments, district (powiat) offices and municipal offices employing at least 50 people, counted in full-time equivalents (Annex 1), as well as local government budgetary units, cultural institutions and municipal companies (Annex 2). Important entities that are public entities apply the requirements of Annex 4 to the Act instead of Art. 8(1) (Art. 8(3)).
If you are preparing a request for proposals or a tender, you can invite us to submit a proposal. We will prepare it on the basis of your specification (the description of the subject matter of the contract).
We do not quote a fixed amount, because the scope of a gap analysis for a company with one location and a few systems is completely different from that for a group with many services. The cost depends on size, the number of locations and systems, the sector, maturity and the scope of technical verification. We give the price and timeline in our proposal after a short scoping call.
Usually, yes. We use your Statement of Applicability, risk register and the evidence from your management system, and focus the analysis on the requirements of the Act that the standard does not cover. One condition: the scope of the certificate should include the systems used to provide the service. More: NIS2 gap analysis.
We quote it separately, because the price depends on the number of services, systems and locations covered by the audit. We carry out the audit in cooperation with a partner, by auditors who meet the requirements of Art. 15(2). An essential entity should plan it in its budget: the first audit is due by 3 April 2028, then at least once every 3 years. If we supported your implementation in the year before the audit, another auditor will carry it out - in that case we help you prepare for it.
Yes - the plan from the gap analysis breaks the work down by risk and deadline, and each stage can be commissioned separately. Bear in mind, though, that the obligations under the Act must be in place by 3 April 2027, so the plan has to fit that deadline. The stages are described on our NIS2 implementation page.
Yes. Based on your specification (the description of the subject matter of the contract), we will prepare a proposal with the scope, a schedule and a list of deliverables. When describing the scope, it helps to distinguish between a gap analysis, implementation support and the Art. 15 audit - three different services with different requirements for the contractor.
NIS2/KSC · Gap analysis
NIS2 gap analysis against the Polish KSC Act: scope, method, gap report, compliance matrix and an implementation plan to meet the 3 April 2027 deadline.
NIS2/KSC · Implementation
NIS2 implementation step by step: registration, risk analysis, policies, technical measures, incidents, suppliers and audit, with a timeline to 3 April 2027.
Penetration testing · Pricing
How much does a penetration test cost? What drives the price of a pentest, our packages, an enquiry checklist and what to watch for in the cheapest proposal.
Tell us briefly what you need - we will come back with proposed next steps. We work in English and Polish.
or call +48 575 621 877