Compliance audit: prove to regulators and clients that you comply
Comprehensive compliance audits for key cybersecurity regulations. We help organizations achieve and maintain compliance with ISO 27001, NIS2, DORA, MiCA, GDPR, CIS Benchmarks, ASVS, and AI Governance — gap analysis, requirements mapped to your processes and a prioritised remediation roadmap.
- 0Regulations and standards covered
- ISO 27001Lead Auditor certified auditors
- 2–4 weeksAudit of one regulation
- Risk analysisPartial
- Incidents 24h/72hGap
- Business continuityOK
- Supply chainGap
- Secure developmentPartial
- Effectiveness reviewOK
- Cyber hygieneOK
- CryptographyOK
- Access controlPartial
- MFA and commsOK
- 84requirements
- 31gaps
- 10Art. 21 areas
Our certifications
Compliance audits are led by ISO 27001 Lead Auditors and engineers holding OSCP, OSEP, OSCE³ and CISSP — we combine regulatory knowledge with hands-on security testing practice.






Why is a compliance audit essential?
The growing number of cybersecurity regulations — from NIS2 and DORA to AI Act — places increasingly demanding requirements on organizations. Non-compliance means not only financial penalty risks but above all threats to data security, business continuity, and company reputation. Our experts will help you navigate through the regulatory landscape and implement required security measures.
An IT compliance audit for companies is also a commercial argument: more and more clients send security questionnaires during B2B sales, and a report from an independent audit lets you answer them reliably and fast. Where a questionnaire asks for proof that controls work, we pair the audit with penetration testing as evidence that controls work.
- Gap analysis — non-conformity identification
- Remediation roadmap with priorities
- Regulatory implementation support
- AI Governance & AI Act compliance
- One requirements matrix for NIS2, DORA and ISO 27001 — evidence collected once
max. penalty for GDPR violation
max. penalty for NIS2 violation (or 2% of turnover)
max. penalty for AI Act violation (or 7% of turnover)
Regulations and standards: NIS2, DORA, ISO 27001, GDPR, MiCA, CIS, OWASP ASVS, AI governance
We help organizations achieve and maintain compliance with key cybersecurity regulations. Each regulation is audited against its own list of requirements, and the results are combined into a single matrix.
ISO 27001
International information security management standard. We help implement an Information Security Management System (ISMS), prepare the organization for certification, and maintain compliance in a continuous improvement cycle. Our auditors hold ISO 27001 Lead Auditor certification.
- Gap analysis against ISO 27001:2022 requirements
- Development of security policies and procedures
- Risk analysis and management (ISO 27005)
- Implementation of required Annex A controls
- Statement of Applicability (SoA)
- Certification audit preparation
- Surveillance audits and recertification support
NIS2 / KSC
The NIS2 Directive (Network and Information Security) and the Polish National Cybersecurity System Act (KSC) require operators of essential and important services to implement cyber risk management measures. Penalties for non-compliance can reach EUR 10 million or 2% of annual turnover.
- Verification whether the organization falls under NIS2/KSC
- Cybersecurity maturity assessment (as-is)
- Gap analysis against NIS2 requirements
- Implementation of risk management measures (Art. 21)
- Incident reporting processes (Art. 23)
- Supply chain security
- KSC compliance audit and implementing regulations
DORA
Digital Operational Resilience Act (DORA) is an EU regulation governing the digital operational resilience of the financial sector. It applies to banks, insurers, investment firms, payment institutions, and their critical ICT providers. Requirements include ICT risk management, resilience testing, and incident reporting. See also DORA readiness for banking and fintech.
- DORA compliance gap analysis
- ICT risk management framework (Art. 5-16)
- Incident classification and reporting procedures (Art. 17-23)
- Digital operational resilience testing (Art. 24-27)
- ICT third-party risk management (Art. 28-44)
- Threat-Led Penetration Testing (TLPT)
MiCA
Markets in Crypto-Assets Regulation (MiCA) is an EU regulation governing crypto-asset markets. It imposes cybersecurity, customer protection, and operational resilience obligations on crypto-asset service providers (CASPs). Providers must implement ICT security policies and are subject to regulatory oversight.
- MiCA readiness assessment
- ICT security policies for CASPs
- Incident management procedures
- Cryptographic key and wallet protection
- Customer and fund protection mechanisms
- CASP licensing preparation
RODO / GDPR
The General Data Protection Regulation (GDPR) requires organizations to implement appropriate technical and organizational measures to protect personal data. We audit GDPR compliance from a cybersecurity perspective — verifying whether implemented measures are adequate to the risk and comply with the ‘privacy by design’ principle. For medical data see GDPR and HIPAA compliance in healthcare.
- Technical data protection measures audit (Art. 32)
- Data Protection Impact Assessment (DPIA)
- Encryption and pseudonymization verification
- Personal data access control review
- Breach notification procedures (Art. 33-34)
- Privacy by Design and Privacy by Default
CIS Benchmarks
CIS Benchmarks are globally recognized security configuration guidelines developed by the Center for Internet Security. We conduct detailed CIS Benchmark compliance audits for operating systems, databases, clouds, containers, and network devices — both automated and manual. Details: CIS benchmark configuration audit.
- Windows Server, Linux (Ubuntu, RHEL, CentOS)
- AWS, Azure, GCP — CIS Cloud Benchmarks
- Docker, Kubernetes — Container Security
- Oracle, MS SQL, PostgreSQL, MySQL
- Cisco, Palo Alto, Fortinet — Network Devices
- Apache, Nginx, IIS — Web Servers
OWASP ASVS
Application Security Verification Standard (ASVS) is an OWASP framework defining web application security requirements at 3 verification levels. It provides a complete set of controls that should be implemented in applications — from authentication and session management to cryptography and attack protection.
ASVS verification levels
- Level 1 — basic security (for all applications)
- Level 2 — advanced security (business applications processing sensitive data)
- Level 3 — highest level (critical applications: banking, healthcare, infrastructure)
ASVS audit scope
- Authentication and session management
- Access control and authorization
- Input and output data validation
- Cryptography and key management
- Error handling and logging
- Data protection and privacy
- Communication security (API, WebSocket)
AI Governance & AI Security
The EU AI Act introduces the world’s first comprehensive regulations on artificial intelligence. We audit AI systems from inventory and risk classification to the technical safeguards of models and LLMs. Full AI Governance scope below.
- AI system inventory and risk classification (AI Act)
- AI Governance framework: policies, human oversight, XAI
- AI Security: prompt injection, adversarial ML, MLOps
- Compliance with NIST AI RMF, ISO/IEC 42001, OWASP LLM Top 10
AI Governance & AI Security
The EU AI Act introduces the world’s first comprehensive regulations on artificial intelligence. Organizations deploying AI systems must ensure their security, transparency, accountability, and legal compliance. Our AI Governance services cover the full cycle — from AI system inventory, through risk classification, to AI management framework implementation.
AI risk classification (AI Act)
- Unacceptable risk systems (prohibited) — social scoring, subliminal manipulation, real-time biometric identification
- High-risk systems — recruitment, credit scoring, medical diagnostics, critical infrastructure, law enforcement
- Limited risk systems — chatbots, deepfakes, content generation systems (transparency requirement)
- Minimal risk systems — anti-spam filters, recommendation systems (no additional requirements)
Reference standards and frameworks
- EU AI Act — European Parliament Regulation
- NIST AI Risk Management Framework (AI RMF 1.0)
- ISO/IEC 42001 — Artificial Intelligence Management System
- ISO/IEC 23894 — AI Risk Management
- OWASP Top 10 for LLM Applications
- OWASP Machine Learning Security Top 10
- ENISA AI Threat Landscape
Framework AI Governance
We help organizations implement a comprehensive AI management framework covering organizational structures, policies, processes, and tools ensuring responsible use of artificial intelligence.
- AI system inventory — mapping all AI components in the organization (models, training data, pipelines, APIs)
- Risk classification — assessing each AI system against AI Act risk categories and potential impact on fundamental rights
- AI policies and procedures — developing ethical AI policy, model validation procedures, training data management, and drift monitoring
- Transparency and explainability (XAI) — mechanisms for documenting algorithmic decisions, explainability for end users
- Human oversight — implementing human supervision mechanisms over AI systems, escalation and intervention procedures
- Bias and fairness management — model bias auditing, fairness testing, bias mitigation procedures
- Data Governance for AI — training data quality, lineage, privacy-preserving ML, synthetic data
- Model Risk Management — model validation, A/B testing, performance monitoring, model retirement procedures
AI Security — technical safeguards
AI system security requires dedicated protection measures against attacks specific to machine learning and natural language processing.
- Adversarial attack protection — model robustness testing against manipulated inputs (adversarial examples)
- ML/MLOps pipeline security — protecting training, versioning, and model deployment processes
- Prompt injection and jailbreaking — LLM security testing for prompt injection, data extraction, and instruction bypass
- Model extraction and model inversion — protecting models against IP theft and training data leakage
- Data poisoning — training data integrity verification and contamination protection
- AI supply chain security — dependency audit, ML libraries, and pretrained models (Hugging Face, PyPI)
- AI Red Teaming — AI system attack simulations following NIST AI RMF and OWASP Top 10 for LLM methodology
Scope of the compliance audit
The audit covers documentation, processes, IT systems and organizational practices — everything a certification auditor, a regulator or a client’s security questionnaire will ask about.
Documentation and policies
Security policies, procedures, risk registers, Statement of Applicability, DPIA, supplier contracts — completeness, currency and conformity with the requirements.
Processes and organization
Risk management, incident handling and reporting, business continuity, board oversight, training and the roles responsible for security.
IT systems and technical controls
Access control, encryption and pseudonymization, logging, backups, configuration against CIS Benchmarks and application security against OWASP ASVS.
Suppliers and supply chain
ICT third-party risk (DORA Art. 28-44, NIS2), contracts and SLAs, assessment of subcontractors, and of AI components and open-source libraries in the supply chain.
How we conduct the audit: methodology and process
A proven, repeatable process for achieving regulatory compliance — an audit of a single regulation typically takes 2–4 weeks.
- 01
Scope & mapping
We identify applicable regulations, define the audit scope, and map business processes to compliance requirements. We establish which NIS2, DORA, ISO 27001 and GDPR requirements overlap, so that evidence is collected once.
- 02
Gap analysis
We compare the current state with regulatory requirements. We identify non-conformities, assess risk, and prioritize gaps — based on documentation, interviews with your team and technical verification of systems.
- 03
Remediation roadmap
We deliver a detailed action plan with specific steps, responsibilities, costs, and implementation timeline. The report with the compliance matrix and executive summary is published to the vulnerability management platform.
- 04
Implementation & validation
We support recommendation implementation, develop documentation, and conduct final validation of audit readiness. Verification of the applied fixes within 30 days of the report is included in the price.
Compliance audit pricing
The price depends on the number of regulations, locations, systems and suppliers in scope. We prepare a quote after a short scoping call.
Compliance audit — quote after a scoping call. For example, a NIS2 audit with gap analysis: self-identification and gap analysis from PLN 9,999 net, a full audit PLN 20,000–45,000 net; implementation of the recommendations is quoted after the audit. Larger scopes (several regulations, multiple entities or locations) are always quoted as an open “from” price with no upper limit.
Always included in every audit
- Report: executive summary + requirements matrix with compliance status, risk rating and evidence
- Remediation roadmap with steps, responsibilities and a timeline
- Verification of the applied fixes (retest) within 30 days of the report
- Access to the VIPentest vulnerability management platform with the status of every non-conformity
- Consultation with the auditor after the audit and implementation support
What you get in the compliance audit report
The report is meant to be evidence of due diligence for the regulator and the auditor, and a work plan for your team.
Executive summary
A summary for the board: compliance level with each regulation, the most important risks and the decisions to be made — ready to show to a client.
Requirements matrix
Every requirement of the regulation (e.g. Art. 21 NIS2, Annex A of ISO 27001, Art. 32 GDPR) mapped to your processes with a status: met, partial, gap.
Non-conformities with risk rating
Each gap with a description of the impact, risk level, evidence and an indication whether it requires a change in documentation, process or configuration.
Remediation roadmap
An action plan with concrete steps, responsibilities, cost estimates and a timeline — from quick fixes to implementation projects.
Documentation and SoA
In ISO 27001 audits — a skeleton of policies and procedures plus the Statement of Applicability; in NIS2 and DORA — templates for incident reporting and supplier assessment procedures.
Validation and VM platform
Verification of the applied fixes within 30 days included, plus access to the vulnerability management platform with the status of every non-conformity.
Who a compliance audit is for
The set of applicable regulations depends on the industry, the size of the organization and the type of data processed — during the initial consultation we help establish which ones apply to you.
Financial sector
Banks, insurers, payment institutions, investment firms and their ICT providers covered by DORA, and crypto-asset service providers covered by MiCA.
Essential and important entities
Critical infrastructure operators, energy, healthcare, transport, public administration and digital service providers covered by NIS2 and the Polish KSC Act.
Companies processing personal data
Any organization processing personal data (GDPR), and companies whose clients send security questionnaires or require ISO 27001.
Organizations deploying AI
Companies building or buying AI and LLM systems that must classify risk under the AI Act and implement AI Governance and technical safeguards.
Frequently asked questions about compliance audits
Answers to the most common questions about compliance audits for NIS2, DORA, ISO 27001, GDPR and AI Act.
What is a compliance audit?
A compliance audit is a systematic process of verifying whether an organization meets the requirements of specific regulations, standards, and legal norms related to information security. It includes analysis of documentation, processes, IT systems, and organizational practices for compliance with frameworks such as ISO 27001, NIS2, DORA, GDPR, and AI Act. The result is a gap analysis and a remediation plan with priorities.
Which regulations apply to my organization?
This depends on the industry, organization size, and type of data processed. The financial sector is subject to DORA and potentially MiCA (crypto-assets). Critical infrastructure operators — NIS2/KSC. Any organization processing personal data — GDPR. Companies using AI — AI Act. ISO 27001 is voluntary but often required by contractors and regulators. During an initial free consultation, we help identify all applicable regulations.
How does a compliance audit work and how long does it take?
The audit begins with scope analysis and identification of applicable regulations (1-2 days). Then we conduct a gap analysis — comparing the current state with requirements (1-3 weeks, depending on scope). Based on the results, we prepare a report with risk assessment, non-conformity prioritization, and a remediation roadmap. The entire audit process for a single regulation typically takes 2-4 weeks.
What is ASVS and when should it be applied?
ASVS (Application Security Verification Standard) is an OWASP framework defining security requirements for web applications at three levels. It is worth applying when: you are building a new application and want to define security requirements from the start, auditing an existing application for security, need to demonstrate compliance with regulations requiring application security (PCI DSS, DORA), or want to improve AppSec process maturity.
What is AI Governance and why is it so important now?
AI Governance is a set of principles, policies, processes, and management structures aimed at responsible, secure, and ethical use of artificial intelligence in an organization. In the context of the EU AI Act, which is the world’s first comprehensive law regulating AI, organizations must classify AI systems by risk level, implement human oversight mechanisms, ensure algorithm transparency, document AI decision-making processes, and protect systems against adversarial attacks. Non-compliance with the AI Act can result in penalties of up to EUR 35 million or 7% of global turnover.
How does a compliance audit differ from an IT security audit?
A compliance audit answers the question “do we meet the requirements of a specific regulation or standard” — the reference point is a list of requirements (e.g. Art. 21 NIS2, Annex A of ISO 27001, Art. 32 GDPR), and the result is a gap matrix and a remediation plan. An IT security audit assesses the real level of protection: configuration, vulnerabilities, processes and people, regardless of what a regulator requires. The two complement each other — a compliance audit often shows where a penetration test or a CIS benchmark configuration audit is needed.
Can one audit cover NIS2, DORA and ISO 27001 at the same time?
Yes. The requirements of NIS2, DORA and ISO 27001 overlap to a large extent (risk management, incidents, business continuity, supply chain, access control), so during Scope & Mapping we build a single requirements matrix and map your processes onto it. Each piece of evidence is collected once, and the report shows compliance separately for each regulation. This shortens the audit and reduces the workload for your team.
Can I share the compliance audit report with a client or regulator?
Yes — the report is prepared to serve as evidence of due diligence. It contains a description of the scope and methodology, a requirements matrix with compliance status, a list of non-conformities with risk ratings, and a remediation plan with a timeline. You can hand the executive summary to the board or to a client who sent you a security questionnaire, and the detailed part to a certification auditor or a supervisory authority.
Ready to ensure regulatory compliance?
Contact us to discuss a compliance audit scope tailored to your organization. We’ll help identify applicable regulations and implement required security measures.
- Enquiry confirmedWe reply within 24 h on business days and ask about the scope.
- Scoping call under NDAWe agree on goals, environment, dates and access.
- Quote and test planUsually the same day after the call. No commitment.
- Fix verification within 30 days included
Write to us: free quote and scoping consultation
Tell us which regulations apply to you (or which ones you are unsure about) and how many entities, locations and systems you have — we will propose a scope and a quote for the compliance audit. We reply within 24 business hours and sign an NDA before discussing details.
