The legal position: the audit is in § 19, not § 20
The Council of Ministers regulation of 21 May 2024 sets out the Polish National Interoperability Framework, the minimum requirements for public registers and the electronic exchange of information, and the minimum requirements for ICT systems. It entered into force on 23 May 2024. [1]
Under § 19(1) the management of the entity is to establish, implement, operate, monitor, review, maintain and improve an information security management system. The system is to protect the confidentiality, availability and integrity of information, taking account of authenticity, accountability, non-repudiation and reliability.
The audit requirement reads: ensure a periodic internal audit in the area of information security, no less often than once a year. The old designation "§ 20(2)(14)" should therefore not be repeated. In the current regulation § 20 concerns the recording of user and administrator actions, access to configuration and to protected data, and the retention of logs - as a rule for two years, unless separate provisions state otherwise. Those mechanisms may well be examined during an audit, but they are not its legal basis. [1]
Who the obligation binds
The range of entities has to be established from article 2 of the Informatisation Act, not from the organisation's name. The act covers, among others, public finance sector units, other state organisational units without legal personality, certain legal persons under dominant public funding or supervision, their associations and unions, research institutes, units of the Lukasiewicz Network, non-public higher education institutions and federations of entities in the higher education and science system. The act also contains exclusions and provisions applying only to selected entities. [2]
- A municipality, county or voivodeship: size and population create no exemption. The sample may be smaller, but the annual criterion stands.
- A budgetary unit or local government budgetary establishment: as a rule it falls within the public finance sector; the systems and processes covered still have to be identified correctly.
- A municipal company or other legal person: assume neither inclusion nor exclusion. Examine the conditions in article 2(1)(3), including the purpose of establishment, funding, control and the composition of governing bodies.
- A healthcare provider: legal form and ownership status matter. Merely providing health services does not settle whether the whole of KRI applies.
- A university: public universities fall within the public finance sector, and non-public ones are named in article 2(1) of the Informatisation Act.
Before the audit, prepare a short scoping note: the basis on which the entity is covered, the organisational units, the public tasks, the systems supporting those tasks, the sites, the cloud services and the suppliers. This reduces the risk both of missing a system and of examining an area for which there is no proper legal criterion.
What § 19 actually requires
Paragraph 2 contains fourteen points. The groupings below are a working order for the audit, not a new legal catalogue:
- Governance and risk. Current internal regulations, periodic risk analyses, the selection of safeguards and additional measures where the risk justifies them.
- Assets and entitlements. A current inventory of hardware and software with type and configuration, appropriate entitlements and their prompt amendment when duties change.
- People and ways of working. Training covering threats, the consequences of breaches, responsibility and measures that reduce human error, together with rules for mobile and remote working.
- Protection of information and systems. Monitoring of access, detection of unauthorised activity, protection against disclosure, modification, deletion and destruction, updates, resilience to failure, protection of system files, cryptography proportionate to risk, and reduction of the threats arising from vulnerabilities.
- Suppliers and media. Security clauses in third-party contracts, and rules limiting the risk of theft of information and of the means of processing it, including mobile devices.
- Incidents, checks and audit. Rules for prompt incident reporting, checks on system conformity, and the annual internal information security audit.
The regulation does not impose an identical technical configuration on every organisation. MFA, EDR, network segmentation, disk encryption, immutable backups or a patching deadline may all be appropriate safeguards, but their use and their parameters should follow from risk, from specific legal provisions, from contracts and from the architecture. KRI on its own establishes no universal "30 days to patch", no annual review of all entitlements, no CIS Level 1 profile and no obligation to buy a particular class of product.
KRI and PN-ISO/IEC 27001 - a facility, not a duty to certify
§ 19(3) refers expressly to the Polish Standards. The requirements of paragraphs 1 and 2 are treated as met where the information security management system was developed on the basis of PN-ISO/IEC 27001 and where the establishment of safeguards, risk management and auditing are carried out on the basis of the related Polish Standards, including PN-ISO/IEC 27002 and PN-ISO/IEC 27005. [1] [10] [11] [12]
This is a significant presumption of conformity, but it is not an obligation to obtain an ISO/IEC 27001 certificate. Certification and internal audit play different roles. A certificate on its own does not substitute for evidence that an audit covering the right entity, the right systems and the current legal requirements was performed in the year in question.
When designing the audit programme, ISO 19011:2026 - the current guidance on auditing management systems - and ISO/IEC 27007:2020 on auditing information security management systems are both useful. ISO 19011:2026 replaced the 2018 edition. [8] [9]
How to run an audit that produces a usable result
1. Establish the mandate, the criteria and independence
The regulation creates no list of licensed KRI auditors and no compulsory set of certificates. Nor does it say whether the work should be done by an employee or a firm. The head of the entity should nevertheless assure competence, impartiality and a division of roles such that the auditor is not assessing their own implementation or their own day-to-day administration. In its most recent inspections the Polish Supreme Audit Office treated a breach of independence and objectivity as a defect in the audit. [3]
2. Build the scope from processes and systems
Connect the public tasks to information, applications, infrastructure, sites, personnel and suppliers. A scope of "the IT department" is usually too narrow: entitlements, contracts, training, business continuity and risk acceptance are also decided by management, HR, procurement, process owners and business administrators.
3. Draw up a criterion-evidence-test matrix
For each requirement, state the expected evidence and how it will be examined. An inventory, for example, is confirmed not only by spreadsheets but by comparing the register with the directory service, the management console and a sample of devices. The effectiveness of revoking entitlements is confirmed by a sample of terminated employments and changed roles. Contractual safeguards are examined on a sample of active suppliers.
4. Gather evidence from several sources
An interview shows the declared process, a document the designed process, and a configuration, a log entry, a ticket and a test result the process as executed. A sound conclusion should rest on evidence proportionate to the risk. A remote audit is possible for part of the scope, but inspecting the server room, physical safeguards or work on site may require a visit.
5. Separate a nonconformity from a recommendation
A nonconformity requires a specific criterion and evidence that it is not met. A recommendation may raise resilience even though it does not follow literally from KRI. Keeping the two apart protects the report from presenting the auditor's preferences as a legal obligation.
6. Close the loop with corrective action
For each finding, state the owner, the priority, the action, the deadline and how it will be verified. Risk accepted at the appropriate level of management does not disappear; it should remain on the register with its justification and a date for review.
The report: not named in the provision, but the key evidence
§ 19(2)(14) does not say that the audit must be "in writing", nor does it set a page count or a rating scale. Without recorded evidence, however, it is hard to demonstrate that the obligation was discharged or to oversee the follow-up. Good documentation therefore covers:
- the approved purpose, scope, criteria, period examined and the composition of the team;
- declarations of impartiality and a description of the audit's limitations;
- the programme of work, the sample and a register of the evidence obtained;
- findings recorded as: criterion, state of affairs, evidence, consequence or risk;
- a summary for management that does not conceal limitations and uncertainty;
- an action plan and the result of checking that it was carried out.
The number of pages and person-days depends on the number of systems, sites and suppliers, on complexity and on the quality of the earlier documentation. Universal ranges for a "small" or "medium" municipality, offered without establishing the scope, are false precision.
What the audit office inspections show
In a report published in July 2026 the Polish Supreme Audit Office described a sample of 17 authorities drawing the highest-value grants under the "Cyber-secure Local Government" programme. In eight of them (47 per cent) the audit for 2023 or 2024 had not been carried out, had been carried out unreliably, or independence and objectivity had been compromised. That is a result for a defined sample, not an estimate for all Polish local authorities. [3]
In a separate inspection of 24 authorities, reported in 2025, in nine cases the audit for 2023 had not been performed or was found unreliable or compromised as to independence and objectivity. In 17 authorities no business continuity policy had been established, in 12 information assets were identified and classified incompletely, and 11 IT purchase or service contracts lacked appropriate security provisions. [4]
Both results reinforce two conclusions: an audit cannot stop at checking whether documents exist, and its sample and conclusions should not be generalised beyond the population examined.
The KRI audit versus the KSC/NIS2 audit
The amendment to the act on the national cybersecurity system was promulgated on 2 March 2026 and entered into force on 3 April 2026. It is no longer a draft. The act uses the notions of an essential entity and an important entity. Classifying an entity requires a separate analysis under the act and its annexes; it does not follow automatically from being subject to KRI. [5]
- KRI: currently an internal information security audit no less often than once a year, for entities covered by the relevant provisions of the Informatisation Act and the regulation.
- KSC: an essential entity is subject to an audit at least once every three years; the competent authority may order an audit in the cases set out in the act, and the supervisory mechanism for an important entity is different.
- Transitional deadlines: for entities meeting the criteria on the day the act entered into force, it provides as a rule 12 months to discharge the chapter 3 obligations and 24 months for an essential entity's first audit.
One team can gather common evidence, but the report should have a matrix separating the KRI, KSC and - where the organisation applies it - ISO/IEC 27001 criteria. A KSC audit should not be presented as an automatic substitute for a KRI audit, or the other way round. NIS2 is the EU source, but in 2026 the current obligations of Polish entities have to be assessed primarily on the basis of the enacted KSC act. [6]
What may change in 2027
The ELI record for the 2024 regulation gives a repeal date of 23 February 2027. In July 2026 draft RD313 for a new regulation was published, with adoption by the Council of Ministers planned for the fourth quarter of 2026. The explanatory material for the draft announces the removal from the new KRI of the requirements concerning the information security management system, on the basis that the area is to be governed by the amended KSC act. [1] [7]
No audit: what can be said without overstating it
The KRI regulation contains no schedule of administrative fines of its own for a missing audit. Failure to discharge the obligation is nonetheless a nonconformity that an inspection may expose, and it weakens the ability to demonstrate proper oversight of information security.
The maximum sanctions under the GDPR, NIS2 or the KSC act should not be transferred automatically to every case. Liability under those regimes requires their own material and personal scope, a breach of a specific obligation and the conduct of the appropriate proceedings. A missing KRI audit may form part of a wider assessment, but on its own it does not determine a penalty under another statute.
Checklist for preparing for a KRI audit
The list helps assemble the material, but it does not replace establishing the scope and examining whether the safeguards are effective.
- Basis and scope. The entity's status and the systems supporting public tasks are documented.
- Owners. Owners of processes, information, systems and risks are named.
- Internal regulations. Approved, accessible, consistent and updated after changes.
- Inventory. Registers of hardware, software, services and configuration can be reconciled with the technical state.
- Risk. The analysis covers current processes, suppliers, remote working and significant changes.
- Entitlements. Access is granted, changed and revoked on the basis of approved decisions; privileged access is controlled.
- Training. The content matches the roles, and the organisation holds evidence of delivery and of evaluating effectiveness.
- Suppliers. Contracts contain safeguards proportionate to access, data and service continuity.
- Technical operations. Evidence is available of updates, backups, restores, monitoring, vulnerability handling and incident response.
- Logs. The events to be recorded, the protection of logs, access to them and the retention period are set in line with § 20 and any specific provisions.
- Impartiality. The auditor is not assessing their own current administration or implementation without appropriate organisational safeguards.
- Follow-up. Findings have owners, deadlines, risk decisions and planned verification.
Frequently asked questions
- Is a small municipality subject to the KRI audit obligation?
Yes. Neither size nor population removes a local authority from the scope of the Informatisation Act. The scope and sample should, however, be matched to the systems, the public tasks and the risk.
- Which provision contains the audit obligation?
§ 19(2)(14) of the 2024 regulation. § 20 concerns system logs and accountability.
- Who may carry out a KRI audit?
The regulation names no closed list of qualifications and no required form of engagement. Competence, objectivity and the absence of self-review have to be assured. It may be a competent employee from outside the area examined, or an external provider.
- Can the authority's IT officer audit the systems they maintain?
That arrangement carries a fundamental self-review problem. Responsibility for implementation and operation has to be separated from assessment. Where resources are limited, a competent person from outside the area examined, or an external service, can be used.
- Does the report have to be in writing?
The provision does not expressly require a written form or a page count. A documented plan, sample, evidence, findings, report and corrective actions are nevertheless needed to demonstrate that the obligation was discharged and that oversight is effective.
- Does an ISO/IEC 27001 certificate replace the KRI audit?
Not automatically. § 19(3) allows the requirements to be treated as met where the system and its processes rest on the designated Polish Standards, but the certificate alone does not evidence the scope and date of a specific KRI audit.
- Is a municipal company always subject to KRI?
That cannot be settled by municipal ownership alone. The conditions in article 2 of the Informatisation Act have to be examined, including the purpose of establishment, funding, control and the nature of the tasks.
- Does a missing audit automatically mean a fine?
KRI contains no schedule of fines of its own. A missing audit is a nonconformity and may be exposed in an inspection. Applying sanctions under the KSC act, the GDPR or other provisions requires the conditions of that regime to be satisfied separately.
- Can the KRI audit and the KSC audit be combined?
Interviews, samples and evidence can be shared, but the criteria, the range of entities, the frequency and the conclusions have to remain separate. A conformity matrix for both legal bases is worth including in the report.
- Will the obligation disappear on 23 February 2027?
The content of future law should not be assumed. RD313 is a draft. Until a new regulation enters into force the current § 19 applies, and before auditing in 2027 the promulgated text and the transitional provisions have to be checked.
Need consulting in this area?
A free 30-60 minute consultation. No obligations. We discuss needs, scale and a high-level timeline.
Related content
Other competence areas
- IT security audit
- Vulnerability scanning
- Penetration testing
- Device and system hardening
- Email security audit
- KSC and NIS2 audit
- GDPR compliance audit
- Information security policy
- ISMS - information security management system
- Security awareness - onsite and online
- SOC 24/7 - monitoring and response
Compliance and regulation
Bibliography and sources
Legal position and sources checked on 24 August 2026. Legal acts, official documents and standards catalogues link to the primary sources.
- [1]akt prawnyRada Ministrów (2024). Rozporządzenie Rady Ministrów z dnia 21 maja 2024 r. w sprawie Krajowych Ram Interoperacyjności, minimalnych wymagań dla rejestrów publicznych i wymiany informacji w postaci elektronicznej oraz minimalnych wymagań dla systemów teleinformatycznych. Dz.U. 2024 poz. 773. ELI.
- [2]akt prawnySejm RP. Ustawa o informatyzacji działalności podmiotów realizujących zadania publiczne. Tekst ujednolicony uwzględniający Dz.U. 2025 poz. 1703 i zmiany z 2026 r. ELI.
- [3]kontrolaNajwyższa Izba Kontroli (2026). Mimo realizacji projektu "Cyberbezpieczny Samorząd" poziom odporności urzędów gmin na cyberataki wciąż nieznany, 21 lipca 2026 r. NIK.
- [4]kontrolaNajwyższa Izba Kontroli (2025). Cyberbezpieczeństwo w samorządach kuleje. Wyniki kontroli 24 urzędów. NIK.
- [5]akt prawnySejm RP (2026). Ustawa z dnia 23 stycznia 2026 r. o zmianie ustawy o krajowym systemie cyberbezpieczeństwa oraz niektórych innych ustaw. Dz.U. 2026 poz. 252. ELI.
- [6]prawo UEParlament Europejski i Rada UE (2022). Dyrektywa (UE) 2022/2555 (NIS2). Dz.U. UE L 333 z 27.12.2022. EUR-Lex.
- [7]projektKancelaria Prezesa Rady Ministrów (2026). Projekt rozporządzenia w sprawie Krajowych Ram Interoperacyjności, numer RD313, opublikowany 10 lipca 2026 r. Gov.pl.
- [8]normaInternational Organization for Standardization (2026). ISO 19011:2026 - Guidelines for auditing management systems. ISO.
- [9]normaISO/IEC (2020). ISO/IEC 27007:2020 - Guidelines for information security management systems auditing. ISO.
- [10]normaISO/IEC (2022). ISO/IEC 27001:2022 - Information security management systems - Requirements. ISO.
- [11]normaISO/IEC (2022). ISO/IEC 27002:2022 - Information security controls. ISO.
- [12]normaISO/IEC (2022). ISO/IEC 27005:2022 - Guidance on managing information security risks. ISO.