Key organizations must regularly assess the security of their IT systems used in delivering services. This is done through a formal security audit, which must be carried out at the organization's own cost at least once every three years. The three-year period is counted from the date the previous audit report was completed and signed by the auditors.
Once the audit is completed, the organization must submit a digital copy of the audit report to the national cybersecurity authority within three working days of receiving it.
In addition, the cybersecurity authority has the right to request an external audit at any time. This could happen, for example, after a serious security incident or if the organization violates cybersecurity rules. In such cases, the authority will define who is allowed to perform the audit, set a deadline for submission of the report, and may also decide the scope or focus areas of the audit.
These steps help ensure that critical services maintain a strong level of cybersecurity and remain accountable for their system security.