uKSC audit · KSC audit · audit readiness

uKSC audit readiness: close gaps before the statutory audit

I help organise evidence, processes, ISMS and risk before a uKSC audit and perform readiness reviews. The scope of any statutory audit must be checked against the Act's auditor independence and qualification requirements.

Audit readiness

What I review before the audit

The goal is not to tick boxes. It is to find gaps that demonstrate ineffective controls or missing evidence.

01

ISMS and governance

Scope, roles, responsibilities, policies, management reviews and document currency.

02

Risk and controls

Methodology, risk register, treatment plan, control adequacy and risk acceptance.

03

Incidents and continuity

Procedures, escalation paths, exercises, backups, recovery and test evidence.

04

Suppliers and ICT chain

Security criteria, contracts, supplier risk assessment, monitoring and change oversight.

Statutory requirement

What uKSC says about audits

An essential entity carries out, at its own expense, a security audit of the information system used to provide the service at least once every three years. As a rule, the first audit is to be ensured within 24 months of meeting the criteria for recognition as an essential entity.

For entities that met the criteria when the amendment entered into force on 3 April 2026, transitional provisions provide a 24-month period from that date.

Independence: the audit cannot be performed by a person carrying out the specified uKSC tasks in the audited entity, nor by a person who performed those tasks there during the year preceding the audit.
Process

Preparing the organisation for a uKSC audit

Scope

Define services, systems, locations, processes and owners within the audit perimeter.

Evidence review

Review not only documents but also logs, reports, test records, registers and proof of control operation.

Remediation

Close risks with the greatest potential impact on audit outcome or real security first.

Readiness check

Re-test and organise the final evidence pack for auditors.

FAQ

uKSC audit — practical questions

Who is subject to the recurring statutory uKSC audit?

Article 15 of uKSC requires an essential entity to carry out a security audit of the information system at least once every three years.

When is the first audit for an essential entity?

As a rule, within 24 months of meeting the criteria. For entities meeting the criteria on 3 April 2026, transitional rules indicate 24 months from entry into force.

Can an important entity be audited?

Yes. In circumstances defined by the Act, the competent authority may order an external audit of an important entity, including in connection with a serious incident or another breach.

Can the person who implemented uKSC audit their own implementation?

The Act includes independence requirements. A person performing specified tasks in the audited entity, or who performed them there during the preceding year, cannot perform the audit.

Want to test readiness before the formal uKSC audit?

Do it while there is still time to close gaps and collect evidence.

Book a readiness review →