The difference between an essential and an important entity comes down to one sentence: important entities self-assess, essential entities undergo an independent cybersecurity audit. That is a difference in cost, in time, and in who holds the pen.
Who may perform it
The audit cannot be run by any consultant. It is performed by a service provider holding the prescribed authorisation, and for state administration bodies by the competent information security authority.
Whoever built the system may not also assess it. If someone offers you both the implementation and the formal audit, that is not a saving but a conflict of interest - and the findings of such an audit carry no weight with the authority.
How the process runs
- Notice and scoping. Which systems, processes and locations are covered, and which level of implementation applies to your category.
- Audit plan. Schedule, interviewees, and the documentation to be submitted in advance.
- Documentation review. Policies, procedures, registers and records - before the interviews, not instead of them.
- Interviews. With the board, with process owners and with the people who actually perform the measures. This is where the gap between what is written and what is done shows fastest.
- Evidence sampling. The auditor picks a sample and asks for evidence for each selected control. Not everything is checked; the sample supports a conclusion about the whole.
- Findings and deadlines. A report setting out findings, their seriousness and the time allowed to remedy them.
How the auditor scores
Scoring uses the same framework as the self-assessment: a score per control, with a threshold each control must reach and an additional average threshold per sub-measure.
Practically important: documentation and implementation are scored separately. A perfect policy that is not applied does not produce a high score, and good practice without records produces no score at all - because it cannot be evidenced.
What usually is not accepted
- A document with no date and no approval. A policy nobody adopted is a draft, not a policy.
- A record created after the audit was announced. It shows in the dates, and in what is missing for the period before.
- A screenshot instead of a record. An image of the current state does not evidence that the control operated throughout the period.
- A risk register with no owners and no changes. If it has not changed in a year, it is not used in decision-making.
- A continuity plan that has never been exercised. Without an exercise record, the plan documents intent, not capability.
- Training without records. "Everyone attended" is not evidence; a list with names and dates is.
- Supplier measures with no contractual basis. A provider's verbal assurance does not replace a clause.
Nearly all of these have the same cause: the evidence is being manufactured at the moment of the audit. Most measures are evidenced by records that arise during the cycle, so they cannot be produced retrospectively. That is why twelve months is not generous.
How to prepare
- Score yourself against the same framework. An internal review simulating the audit produces the same findings, without the consequences.
- Walk the documentation chronologically. Is there a record for every month of the period, or only for the last one?
- Check what cannot be fixed quickly. The annual board reporting cycle, the continuity exercise and training records all need calendar time.
- Prepare the interviewees. Not to learn answers, but to know where things are - an auditor can tell the difference.
We carry out internal audits and reviews that simulate the audit process. The formal independent audit of essential entities is performed by an authorised provider. More on what we do at Audits and internal reviews, and the scoring framework is explained in How the self-assessment is actually scored.
Sources
Not sure where you stand?
Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.