Legal status: the current KRI and draft RD313
The KRI Regulation of 21 May 2024 entered into force on 23 May 2024.[1] Section 19(1) requires management to establish, implement, operate, monitor, review, maintain, and improve an information security management system. Subsection 2 sets operational requirements concerning, among other things, internal rules, inventories, access management, training, mobile and remote work, information protection, updates, vulnerabilities, contracts with external parties, incident reporting, compliance controls, and audit.
At the same time, the amended National Cybersecurity System Act has applied since 3 April 2026, while draft regulation RD313 for a new KRI framework has been listed in the government's legislative work programme since July 2026.[5][6] These are separate regimes. A report titled "KRI/NIS2/ISO audit" must identify the criteria supporting each conclusion.
The current regulation will not remain in force indefinitely. A change to the statutory authorisation in the Act on Computerisation takes effect on 23 February 2027.[4] In the explanatory material for RD313, the government states that the 2024 regulation remains applicable until the new implementing rules enter into force, while the change in authorisation causes the current KRI regulation to lose force.[6]
As of 29 August 2026, RD313 is still a draft, not binding law. An entity must not be audited as though the draft were already in force. The organisation may nevertheless be prepared for the anticipated change, provided the distinction between current requirements and forward-looking recommendations is explicit.
Who is subject to KRI
The personal scope follows the Act on Computerisation of Activities of Entities Performing Public Tasks, not merely the organisation's name.[2] It includes, among others, public-finance-sector entities and other entities listed in Article 2, subject to statutory exclusions and special provisions.
For a municipality, county, or region, population and size do not create a general exemption from the annual audit requirement. A municipal company or another legal person, however, should not be presumed to fall within KRI merely because local government owns it. Its legal status and the statutory criteria must be examined.
Likewise, the label "healthcare entity" alone does not determine whether the full KRI regime applies. Legal form and statutory status matter.
The first working document should therefore be a scope note identifying:
- the legal basis for KRI applicability;
- organisational units and locations;
- public tasks and the systems supporting them;
- cloud services and supplier-operated systems;
- exclusions and their justification.
What Section 19 actually requires
Section 19(2) contains 14 points. The groups below organise audit work; they are not a replacement legal catalogue.
Governance and risk. The audit should verify that internal rules are current, risk analyses are actually performed, and safeguards are selected on that basis. A risk spreadsheet alone is not evidence of an operating system. Decisions, owners, and records of risk treatment are required.
Assets, configuration, and access rights. An up-to-date inventory of hardware and software must be maintained, including information on type and configuration. The auditor should reconcile the inventory against a sample of the real environment rather than merely verify that a file exists. Access rights should correspond to duties and be changed without delay when a person's responsibilities change. In practice, a sample of new employees, transferred staff, and terminated personnel is tested.
People and working practices. KRI requires training for persons involved in information processing. Topics include threats, consequences of security breaches, responsibility, and measures reducing human error. The regulation does not prescribe one universal training frequency for all organisations. Mobile and remote-working rules and their actual use should be tested separately.
System protection and vulnerabilities. The audit covers access monitoring, protection against unauthorised disclosure, alteration, deletion, or destruction of information, software updates, protection of system files, cryptography proportionate to risk, and reduction of threats arising from published vulnerabilities. KRI does not impose a universal "30 days for every patch" deadline, a mandatory CIS Level 1 profile, or purchase of a particular EDR class. Technical parameters must follow risk, architecture, and other applicable requirements, which links this area to vulnerability scanning and hardening.
Suppliers and media. Contracts with external parties should include information-security requirements. The audit should not stop at locating a security clause: it should determine whether the clause reflects actual supplier access and responsibility and whether the organisation monitors compliance.
Incidents, controls, and audit. KRI requires rules for prompt incident reporting, compliance checks of systems, and an annual internal information-security audit.[1]
KRI and PN-ISO/IEC 27001
Section 19(3) is significant but often overstated. The requirements of Section 19(1) and (2) are deemed satisfied when the ISMS is developed on the basis of PN-ISO/IEC 27001 and the establishment of controls, risk management, and auditing are carried out using the indicated related Polish Standards, including PN-ISO/IEC 27002 and PN-ISO/IEC 27005.[1][9][10][11]
This is not a requirement to obtain ISO/IEC 27001 certification. A certificate and the annual KRI audit answer different questions. Certification may provide strong evidence of ISMS maturity, but it does not release management from ensuring the legally required audit in the appropriate scope and interval.
Audit methodology in 2026
ISO 19011:2026, published on 27 May 2026, replaced the 2018 edition and is the current guidance for auditing management systems.[7] ISO/IEC 27007:2020 remains the published standard for ISMS auditing, although ISO marks it as "to be revised" and is developing the next edition.[8]
These standards provide methodology. They neither change the KRI obligation nor create a KRI auditor licence.
A sound audit should include:
- establishing the mandate and criteria;
- analysing public tasks, processes, and systems in scope;
- reviewing documentation;
- interviewing process owners;
- testing a sample of evidence;
- technical verification of selected configurations, accounts, logs, backups, and systems;
- comparing declarations, documentation, and actual state;
- formulating findings linked to specific criteria;
- a remediation plan;
- reverification of the most important findings.
The audit should not be reduced to asking "is there a procedure?". For backups, evidence may be a restore-test result; for access rights, a sample of accounts; for updates, actual system status; for logging, events and retention; for suppliers, the contract and evidence of oversight.
Independence and competence
KRI does not establish a state licensing list for auditors or a mandatory set of personal certifications. The organisation nevertheless remains responsible for the credibility of the examination.
A person who administers the audited system every day or has just implemented the control being assessed has difficulty objectively auditing their own work. ISO 19011 treats impartiality and objectivity as important audit principles.[7]
This does not mean every audit must be outsourced. In a large organisation, an independent internal-audit team may provide sufficient separation. In a small unit where one person manages nearly all IT, an external auditor is often a practical way to reduce conflict of interest. Note that this is a different criterion from the KSC audit, where the Act expressly prohibits auditing one's own statutory tasks.
What the report should contain
The regulation does not prescribe a report template. The report is nevertheless a principal piece of evidence that the audit occurred and should allow a competent reader to reconstruct what was examined.
A useful minimum includes:
- legal basis and criteria;
- organisational and technical scope;
- audit dates;
- audit team and independence considerations;
- methods used;
- sample size and selection method;
- limitations;
- findings with specific criteria and evidence;
- impact or risk assessment;
- recommendations;
- action plan, owners, and deadlines;
- the closure evidence required for each finding.
A statement of "compliant" or "non-compliant" without supporting evidence is an opinion, not an audit finding.
What the Supreme Audit Office found
A Polish Supreme Audit Office review covering 24 local-government offices showed that the problem is not limited to missing documents. Seventeen units had no business-continuity policies, 12 had incomplete asset identification or inadequate classification, and 11 lacked required security provisions in IT service or equipment contracts. In nine offices, the audit was not performed or was unreliable.[3]
These results should not be extrapolated to all Polish local governments. They do, however, show why a questionnaire-only audit can miss implementation weaknesses. A questionnaire asks whether a procedure exists; an inspection checks whether anyone executed it.
KRI, KSC, and NIS2
Since 3 April 2026, some public entities have been subject to both KRI and the amended KSC.[5] The criteria are not identical.
KRI requires an annual internal information-security audit for entities in its scope. KSC imposes separate cybersecurity obligations and requires essential entities to undergo the statutory security audit of the information system at least once every three years.[5]
One project may share interviews and evidence, but the report must show which finding relates to KRI, which to KSC, and which to an adopted standard. A combined audit must not blur the legal bases, because the entity would then not know exactly what was required of it or to whom it is accountable.
What changes on 23 February 2027
As of 29 August 2026, two points can be stated with high confidence:
- the current KRI regulation remains in force;
- due to the change in statutory authorisation, it is expected to lose force with the new regime from 23 February 2027, while RD313 is intended to provide the new implementing regulation.[4][6]
The current RD313 draft cannot be presented as the final law for 2027. Its text can still change before promulgation. An audit report should therefore separate two layers: findings against the law in force today, and a clearly marked forward-looking analysis that does not create a non-conformity.
KRI audit preparation checklist
- The legal basis for KRI applicability has been established.
- Public tasks and supporting systems have been identified.
- An up-to-date asset and configuration inventory exists.
- Risk analysis is current and leads to decisions.
- Access rights are granted and removed in a controlled process.
- Personnel receive role-appropriate training.
- Remote and mobile-working rules reflect reality.
- Update and vulnerability processes leave evidence.
- Supplier contracts contain security requirements.
- Incidents can be reported and handled under an established process.
- Logs required by Section 20 are recorded and retained.
- Previous audit findings have owners and status.
- The audit team is sufficiently independent of the audited area.
- The report distinguishes KRI requirements from KSC, GDPR, and standards.
Frequently asked questions
- Does a small municipality have to perform the annual KRI audit?
-
Municipal size does not create a general exemption. The entity and the systems supporting public tasks must still be scoped correctly, because they define the area to be examined.
- Where exactly is the audit requirement?
-
In Section 19(2)(14) of the KRI Regulation of 21 May 2024. Section 20 concerns accountability and system logs and is not the basis for this obligation.
- Can the municipality's IT administrator audit their own systems?
-
That model creates an objectivity problem. Where the same person designs, administers, and evaluates controls, independence is limited. Roles should be separated or an auditor independent of the area should be used.
- Must the report be in writing?
-
The regulation does not prescribe a template, but the organisation must be able to demonstrate that the audit occurred, what it covered, and what it found. A durable report with supporting evidence is the normal method of accountability.
- Does ISO/IEC 27001 certification replace the KRI audit?
-
Not automatically. Certification and the annual KRI audit have different criteria and purposes. A certificate may nevertheless reduce the amount of work if the management-system evidence is current and covers the right scope.
- Does failure to perform the audit automatically trigger a financial penalty?
-
KRI should not be described as a simple tariff. Failure to audit breaches a regulatory requirement, but consequences depend on the supervisory basis, type of entity, and circumstances. An audit report should not invent sanctions that the applicable provision does not state.
- Can KRI and KSC audits be combined?
-
Evidence collection and some audit activities can be shared, but conclusions must be derived separately from the applicable criteria. The report must show clearly which basis supports which finding.
- Does the KRI obligation disappear on 23 February 2027?
-
The current regulation is expected to lose force because of the changed statutory authorisation and to be replaced by a new regulation. This does not mean that information security or auditing disappears. The final act must be assessed after promulgation.
- Is a vulnerability scan enough as the annual KRI audit?
-
No. Scanning provides evidence about part of the requirements on vulnerabilities and updates. Section 19 also covers internal rules, risk, inventory, access rights, training, contracts, and incidents, none of which a scanner examines.
- How should the sample be selected?
-
The sample should be linked to risk and population size, and the selection method should be recorded in the report. A random sample of five accounts out of a thousand has different evidential value from a targeted sample of privileged accounts and people who left during the period examined.
Need consulting in this area?
A free 30-60 minute consultation. No obligations. We discuss needs, scale and a high-level timeline.
Related content
Other competence areas
- IT security audit
- Vulnerability scanning
- Penetration testing
- Device and system hardening
- Email security audit
- KSC and NIS2 audit
- GDPR compliance audit
- Information security policy
- ISMS - information security management system
- Security awareness - onsite and online
- SOC 24/7 - monitoring and response
Compliance and regulation
Bibliography and sources
Law and standards verified on 29 August 2026. Legal acts link to ELI, standards to the ISO catalogue, audit findings to the Supreme Audit Office.
- [1] regulationCouncil of Ministers of the Republic of Poland (2024). Regulation of 21 May 2024 on the National Interoperability Framework, minimum requirements for public registers and electronic information exchange, and minimum requirements for ICT systems. Journal of Laws 2024 item 773. · ELI
- [2] regulationParliament of the Republic of Poland (2005). Act of 17 February 2005 on Computerisation of Activities of Entities Performing Public Tasks. Current text. · ELI
- [3] reportPolish Supreme Audit Office (2025). Cybersecurity in local governments - findings from an audit of 24 offices. NIK. · nik.gov.pl
- [4] regulationParliament of the Republic of Poland (2025). Act of 12 September 2025 amending the Act on Computerisation of Activities of Entities Performing Public Tasks and certain other acts. Basis for the changed authorisation to issue the KRI regulation. · ELI
- [5] regulationParliament of the Republic of Poland (2018). Act of 5 July 2018 on the National Cybersecurity System. As in force on 29 August 2026, together with the amending Act of 23 January 2026, Journal of Laws 2026 item 252. · ELI
- [6] regulationChancellery of the Polish Prime Minister (2026). Draft KRI regulation, reference RD313. First published on 10 July 2026. Still a draft on 29 August 2026. · gov.pl
- [7] standardInternational Organization for Standardization (2026). ISO 19011:2026 - Guidelines for auditing management systems. ISO. Edition 4, published on 27 May 2026. · iso.org
- [8] standardInternational Organization for Standardization (2020). ISO/IEC 27007:2020 - Guidelines for information security management systems auditing. ISO/IEC. ISO status as of 29 August 2026: published, to be revised. · iso.org
- [9] standardInternational Organization for Standardization (2022). ISO/IEC 27001:2022 - Information security, cybersecurity and privacy protection - Information security management systems - Requirements. ISO/IEC. · iso.org
- [10] standardInternational Organization for Standardization (2022). ISO/IEC 27002:2022 - Information security, cybersecurity and privacy protection - Information security controls. ISO/IEC. · iso.org
- [11] standardInternational Organization for Standardization (2022). ISO/IEC 27005:2022 - Information security, cybersecurity and privacy protection - Guidance on managing information security risks. ISO/IEC. · iso.org