Security standard

KRI

The Polish National Interoperability Framework (KRI) is a Council of Ministers regulation of 12 April 2012 that obliges every entity performing public tasks to run an information security management system and to conduct an annual information security audit. It is the core, legally binding security standard for Polish public offices, municipalities, counties and public hospitals.

Start assessmentRead about the standard
27
controls in Guardiso
28
free-test questions
PL · EN
two languages

What is the KRI regulation?

The Council of Ministers Regulation of 12 April 2012 on the National Interoperability Framework, minimum requirements for public registers and electronic information exchange, and minimum requirements for IT systems (Journal of Laws 2012, item 526, as amended) was issued under the Polish act on the computerisation of entities performing public tasks. It defines how public administration IT systems must interoperate, which data formats to use for exchange, and — most importantly from a security perspective — the minimum information security requirements every public entity must meet.

The heart of the regulation is §20, which mandates developing, implementing, operating, monitoring, reviewing and improving an information security management system (ISMS) that ensures the confidentiality, availability and integrity of information, taking into account authenticity, accountability, non-repudiation and reliability. Unlike voluntary standards, KRI is generally applicable law — its requirements are non-negotiable and subject to inspection.

Who does it apply to?

The regulation covers entities performing public tasks within the meaning of the Polish computerisation act. In practice this means the entire central and local government administration as well as units carrying out public tasks — regardless of size.

  • Municipalities, counties and voivodeships — offices and their organisational units (social welfare centres, schools, municipal utilities).
  • Central government — ministries, voivodeship offices, central agencies and inspectorates.
  • Public healthcare providers — hospitals, clinics and other facilities delivering publicly funded services.
  • Courts, prosecution offices, public universities and other public finance sector units performing public tasks with IT systems.
  • Private entities to the extent that they perform public tasks entrusted to them by the administration.

Key requirements of §20

Section 20(2) lists the specific areas a public entity’s ISMS must cover. It is the practical checklist auditors and inspectors work from.

  • Up-to-date internal information security regulations, maintained in line with a changing environment.
  • An inventory of hardware and software used for information processing, covering their type and configuration.
  • Periodic risk analyses covering loss of integrity, availability or confidentiality of information, plus risk-minimising actions.
  • Access rights management — access adequate to duties, promptly changed or revoked on role change or departure.
  • Training for people involved in information processing: threats, consequences of breaches, use of safeguards.
  • Rules for secure remote work and mobile data processing.
  • Protection of processed information against theft, unauthorised access, damage and disruption — including access monitoring and safeguards at the system, network and application level.
  • Third-party service contracts containing clauses guaranteeing an appropriate level of information security.
  • Software updates, backups, cryptographic mechanisms and response to published vulnerabilities.
  • Prompt reporting and handling of information security incidents.
  • An internal information security audit at least once a year (§20(2)(14)).

The annual audit and inspections

KRI does not provide for certification — compliance is verified by an internal audit which, under §20(2)(14), must take place at least once a year. The audit can be performed by the entity’s internal audit unit or an independent external auditor; what matters is the auditor’s independence from the audited IT area and a documented plan, report and recommendations.

KRI compliance is regularly inspected by the Polish Supreme Audit Office (NIK) as well as ministerial and voivodeship inspections. NIK inspections of information security in local governments and hospitals have repeatedly found the same gaps: no annual audit, outdated risk analyses, active accounts of former employees, and no backup restore tests. Importantly, §20(3) of the regulation states that ISMS requirements are deemed met if the system is built on the Polish standard PN-ISO/IEC 27001 — so implementing ISO 27001 satisfies the KRI requirements.

KRI vs the national cybersecurity act, NIS 2 and GDPR

KRI does not operate in a vacuum. Public entities are simultaneously covered by the Polish national cybersecurity act (KSC), which requires reporting incidents to the competent CSIRT, and its amendment implementing the NIS 2 directive significantly expands the catalogue of obligations and sanctions. In parallel, every office and hospital processes personal data, so GDPR applies — with the duty to notify the Polish DPA of breaches within 72 hours and to sign data processing agreements with suppliers.

The good news is that these requirements largely overlap: a properly run KRI ISMS (inventory, risk analysis, access rights, training, backups, incidents, audit) forms a shared foundation for KSC/NIS 2 and GDPR compliance. Effort invested once pays off across all three regimes.

How does Guardiso help?

Guardiso turns the KRI regulation’s requirements into a ready-to-run system — from the first self-assessment, through registers and policies, to evidence for the annual auditor.

  • KRI controls seeded automatically when you enable the standard — with Polish descriptions, implementation statuses and owners.
  • An information security policy and internal regulations generated from templates tailored to public sector entities, with versioning and management approval.
  • A risk register with periodic risk analysis — ready evidence of meeting the §20(2) requirements.
  • Asset inventory, access reviews and employee training run as recurring tasks with automatic reminders.
  • An incident register with an external reporting path (CSIRT, the Polish DPA) and deadlines.
  • An audit module: audit plan, KRI checklist, findings report and year-over-year tracking of recommendation follow-up.
  • Cross-mapping to ISO 27001, NIS 2 (the Polish KSC act) and GDPR — work done for KRI satisfies the overlapping requirements of the other frameworks.
Official sources
01Select standard›02Complete the self assessment›03Close gaps in Guardiso
—
KRI readiness score
0/28 answered
The score updates live as you answer.

Other standards to assess

ISO 27001GlobalGDPREUNIS 2 (Polish KSC act)EU · PLSOC 2GlobalDORAEUTISAXAutomotiveISO 9001GlobalISO 42001 (AI)GlobalPCI DSSGlobalNIST CSFUSANIST 800-53USAHIPAAUSACMMC 2.0USACyber EssentialsUKSOX ITGCUSABIO2NLEU AI ActEUISO 27701GlobalISO 22301GlobalISO 14001GlobalISO 45001GlobalISO 13485MedicalIEC 62304MedicalMDREU · MedicalISO 14971MedicalDCB0129UKMiCAEUIEC 62443GlobalISO 21434Automotive
Browse all 30 standards