Market perspective

ISO/IEC 42001, SOC 2 and NIS2 implementation for Poland

Polish organizations need to distinguish AI governance, customer-requested service assurance, and any national cyber duties that apply to them. ISO/IEC 42001 and SOC 2 can be useful, while the Polish KSC framework gives a distinct route for entities within its scope.

Establish the AI management system first

ISO/IEC 42001 should start with a register of AI systems, uses, suppliers, owners, data, and people affected. Define which legal entities, teams, and lifecycle stages the management system covers. Then set risk and impact criteria, review points, escalation, and a way to record decisions when an AI system changes.

For organizations serving the EU, role- and system-specific AI Act duties need separate analysis. The management system can supply facts and controls but cannot be described as an automatic legal compliance determination.

Assess the Polish KSC obligations explicitly

Poland's Ministry of Digital Affairs describes the amended national cybersecurity system law, KSC, implementing NIS2, including obligations for entities classified as key or important. Its guidance identifies an information security management system as part of the implementation work for in-scope entities.

The correct starting point is an applicability review using official Polish sources: entity, sector, services, and legal status. Once scope is known, build accountable risk management, incident handling, continuity, supplier, and evidence processes. A generic ISO or SOC 2 project should not be presented as a complete KSC legal response.

Use ISO/IEC 27001 to operate security governance

ISO/IEC 27001 can structure an information security management system, with scope, risks, treatment, controls, performance review, and continual improvement. It may provide a strong operational base for KSC work where relevant and for SOC 2 control evidence, but local obligations and reporting channels must be mapped independently.

Assign named owners to both technical measures and management decisions. A register of controls without proof of operation does little for an external assessment or incident response.

Prepare SOC 2 around a service, not the country

A Polish SaaS or service company may pursue SOC 2 when customers want AICPA-style assurance. The system description, relevant Trust Services Criteria, supplier roles, and evidence period should reflect the service sold. A licensed CPA firm performs the examination.

SOC 2 is neither a KSC approval nor an ISO certificate. If the same access, change, incident, or vendor process supports multiple outcomes, show each mapping with exact scope and evidence rather than claiming broad equivalence.

Common questions

Clarify the outcome before the work.

Does every Polish company fall under the amended KSC rules?

No blanket statement is appropriate. The law distinguishes entities and sectors, so each organization should assess applicability against official guidance.

Does an ISO/IEC 27001 certificate finish NIS2 work?

No automatic conclusion follows. In-scope duties must be mapped to the national law and the services of the organization.

Is SOC 2 available to a Polish service provider?

Yes, where the provider seeks independent assurance over a defined service for its customers.

Work with Normstone

Make the next assurance decision clear.

Tell us your service, AI use, and customer requirements. We’ll help shape the scope.

Start a conversation