Compliance with the Cybersecurity Act
We determine whether you are an essential or important entity, implement the thirteen measures from Annex II of the Regulation and assemble the evidence an auditor asks for.
What this work actually means
The Act says what has to exist. Our job is to make it exist, with deadlines and owners.
The clock starts on the day the competent authority delivers your categorisation notice. Who counts as an essential and who as an important entity, which deadlines run from that notice and how large the fines are, all of that is set out on the page on the Cybersecurity Act. This page is about the work that follows.
The work is not about writing documents but about setting up processes that leave a record. For every sub-measure that binds you there has to be something you can produce: who owns it, when it was last carried out and what shows that it was. A policy nobody follows counts for as much at an audit as no policy at all.
That is why we first establish how many of the 99 sub-measures of Annex II of the Regulation actually bind you. The level of implementation set for you by the national risk assessment changes the size of the job more than the size of the organisation does, so without it neither duration nor cost can be estimated seriously.
Responsibility stays with the management body and we do not take it over, because Article 29 of the Act does not allow it to be passed on. What we do take over is running the work: the order, the deadlines, the drafting, the evidence set and an internal check before anyone external arrives.
How we run the alignment
Eight steps from the categorisation notice to a body of evidence that survives an audit.
Establishing the category and the scope of obligations
We check which annex covers you, what your category is and which level of measures follows from the authority’s notice. From that follows how many of the 99 sub-measures bind you and which are voluntary.
Gap analysis for every sub-measure
We go through the sub-measures one by one and record, for each, whether a document exists, whether there is evidence of application and who owns it. The result is not only a score but also a list of concrete gaps, ordered by what each costs and how long it takes.
Management decision and assignment of ownership
The management body adopts the strategic security policy, provides the resources and appoints owners for the measures. Without that the rest cannot be closed out, because a measure without an owner does not exist in practice.
Assets, risks and policies
The critical asset inventory, the risk assessment and the risk register come first, because everything else takes its rationale from them. We write policies and procedures so that they can be followed, not merely shown.
Incident handling and reporting deadlines
We set up a procedure with triage, an internal reporting deadline and a contact list, together with forms for the early warning within 24 hours, the notification within 72 hours and the final report within 30 days of the notification.
Supply chain and contract clauses
We list direct suppliers and service providers and introduce security clauses into contracts, including the right to audit and vulnerability management. This takes the longest because it means reopening existing contracts, so we ask for the supplier list as early as the second step.
Training and awareness
Regular cyber hygiene training for all employees, specific training for those with security duties and awareness sessions for the management body. Every session leaves an attendance list and a date, because that is what proves it.
Evidence set and internal check
Everything produced is arranged by measure and sub-measure, the way an auditor will ask for it, and we walk through it using the same scoring formulas. The findings come to you, so there is time to fix things before anyone external arrives.
What must exist at the end
A short list. The full one depends on the level of measures determined for you.
- Strategic cyber security policy adopted by the management body
- Resource decision and appointment of owners for the measures
- Critical asset inventory and list of critical data
- Risk assessment, risk register and risk treatment plan
- Policies and procedures for the measures of Annex II
- Incident procedure with triage and an internal reporting deadline
- Register of direct suppliers and security clauses in contracts
- Training plan and records, with attendance lists and dates
- Records of the annual report to management on the state of cyber security
- Business continuity and recovery plans, with testing records
- Records of vulnerability scans and of security patching
- An evidence set arranged by measure and sub-measure
Frequently asked questions
The questions we are asked most often before we start.
We have missed the deadline. Is it too late to start?
No. The competent authority also looks at whether you are acting seriously. A picture of the current state and a remediation plan with dates and owners are the best answer to an enquiry, because they show the failure is being addressed rather than overlooked.Do you carry out the audit yourselves?
We do not. Only a managed security service provider holding the national security certificate for auditing may run one, and Riskoria does not hold it. What we do is the preparation: the evidence set, an internal check using the same scoring formulas, and the fixes before the auditor arrives. Who may act as an auditor is set out on the page on the Act.We have ISO 27001. Does that make us compliant?
A large part of the work is done, but it is not the same thing. The standard and the Regulation overlap only in part, so we map your records to the catalogue controls and fill the difference. What is usually missing are the incident reporting deadlines, the clauses towards suppliers and the records of annual reporting to management.How long does alignment take?
Two to three weeks for the picture of the current state, and from a few months to a year to close the gaps, depending on size and on what is already in place. The longest part is reopening supplier contracts, so we ask for the supplier list early.How much of our time does the project take?
Less than people expect, but not none. For the picture of the current state we need conversations with the people who actually keep the systems running, usually five to eight hours in total. After that the work is ours, and your time goes on management decisions, approving the drafts, and the evidence only your own people can produce.What do we need to have ready to start?
Your categorisation notice if it has arrived, a list of systems and services, a list of direct suppliers, and whatever policies and procedures already exist, however out of date. If the notice has not arrived yet we start from the list of systems, because that comes first in any case.Where to go next
Pages that go deeper into individual parts of this work.
From the blog: the Cyber Security Act
The three latest texts on the Act, the measures and the audit.
Let us start with a picture of where you are.
Half an hour, no obligation. Tell us where you stopped and we will tell you what comes next and how long it takes.
