11.09.2026
Gabrielius Vinciunas

Cyber Security Audit: Who Is Required to Conduct One and How Often?

A cyber security audit is mandatory for organisations subject to the requirements of the Lithuanian Law on Cyber Security. It must be conducted at least once every three years and, in certain cases, more frequently where required by the organisation’s risk profile, nature of operations, or other circumstances established by law. The audit must be carried out by independent assessors who meet the applicable requirements.

Cyber security gaps persist even in organisations that devote significant attention to this area. According to ENISA, half of surveyed organisations face challenges with vulnerability and patch management, while 49% struggle with business continuity. This is why it is important not only to implement security measures but also to regularly assess whether they work and whether identified gaps are being addressed.

For some Lithuanian organisations, assessing cyber security is not only good practice but also a legal obligation. The updated Law on Cyber Security (LCS), which transposes the NIS2 Directive, requires an independent cyber security audit, while implementation of these requirements is supervised by the National Cyber Security Centre (NCSC).

In this blog post, we explain which organisations are required to conduct a cyber security audit, how often it must be carried out, and what is important to know when preparing for one.

Who Is Required to Conduct a Cyber Security Audit?

An independent cyber security audit is mandatory for organisations on the Register of Cyber Security Entities. The LCS classifies them as essential and important entities. Although the supervision of these groups may differ, both are required to undergo regular independent cyber security audits.

The updated LCS significantly expanded the scope of cyber security regulation to include more organisations. Its scope may include organisations operating in energy, transport, banking, healthcare, digital infrastructure, public administration, postal and courier services, food, manufacturing, and other sectors specified by law.

However, a long list of sectors does not by itself answer the question for a particular company. Two businesses operating in the same sector will not necessarily have the same obligations. Whether an organisation falls within the scope of the regulation is determined according to the criteria set out in the LCS.

How Do You Know Whether Your Organisation Needs a Cyber Security Audit?

The NCSC notifies organisations when they are included in the Register of Cyber Security Entities. There is no need to look for your organisation on a public list. From the date of inclusion, the deadlines for implementing organisational and technical requirements and conducting the first independent cyber security audit begin to run.

The NCSC included the first entities in the register and notified them by 17 April 2025. However, the list is not final. According to the Ministry of National Defence, it is reviewed at least once a year.

This also matters to organisations that are not currently included in the register. Changes in company size, activities, or other circumstances may mean that LCS requirements apply to them in the future.

When Must the First Cyber Security Audit Be Conducted?

The first cyber security audit must be conducted within three years of an organisation’s inclusion in the Register of Cyber Security Entities. Before then, however, the organisation already has substantial groundwork to complete: the NCSC states that organisations must implement the organisational and technical cyber security requirements and begin regularly assessing their compliance.

At first glance, this may seem like plenty of time. The Ministry of National Defence states that cyber security entities must conduct an audit at least once every three years. Other important deadlines, however, arrive much sooner.

The timeline from inclusion in the register can be set out as follows:

  • Within 12 months – implement the organisational cyber security requirements;  
  • Within 24 months – implement the technical cyber security requirements;
  • Within 3 years – conduct the first independent cyber security audit;
  • Thereafter – repeat the audit at least once every three years.  

So, if an organisation was included in the register in 2025, it would be a mistake to start thinking about the audit only in 2028. By then, the necessary processes and technical measures must already be in place, and the organisation must be able to demonstrate how they work in practice.

A Compliance Assessment Does Not Replace an Audit

An annual compliance assessment and an independent cyber security audit are two separate processes with different purposes. The three-year period applies to the cyber security audit, while an annual compliance assessment is required alongside it. These are not the same check performed at different intervals – their purposes differ.

Each year, the organisation assesses how well it complies with the requirements that apply to it and, if non-conformities are identified, determines how to address them. The audit is a separate, independent assessment conducted in accordance with the NCSC methodology. An annual compliance assessment therefore does not replace the audit.

ISO 27001 Certification and the Cyber Security Audit

ISO 27001 certification can be an important indicator of an organisation’s information security maturity, but it does not replace the cyber security audit required under the LCS. The NCSC makes clear that an ISO 27001:2022 conformity assessment cannot automatically be treated as equivalent to that audit.

In practice, ISO 27001 means that considerable groundwork has already been done, but the cyber security audit remains a separate step. If an organisation is included in the Register of Cyber Security Entities, the procedure established by the NCSC applies.

As an ISO/IEC 27001-certified cyber security company, Baltic Amadeus has firsthand experience working within this framework. Its experts can help organisations make effective use of the ISO/IEC 27001 foundation they already have and avoid starting from scratch when preparing for the mandatory cyber security audit.

Why Is an Annual Compliance Assessment Useful?

An annual compliance assessment provides an interim check between cyber security audits, helping organisations identify changes and gaps before they accumulate. Three years is a relatively long period in which systems, suppliers, employees and the threat landscape can change significantly.

Over the course of a year, new systems may be introduced, access rights or suppliers may change, and areas that were previously addressed may require attention again. Reviewing the situation annually brings these issues to light earlier, rather than only a few months before the cyber security audit.

What Is Actually Assessed During a Cyber Security Audit?

A cyber security audit assesses compliance with applicable cyber security requirements and the evidence supporting that compliance. It looks beyond documentation to determine whether security controls and documented procedures actually work in the organisation’s day-to-day operations.

In February 2026, the NCSC approved the Cyber Security Audit Methodology. It sets out the audit principles, process, assessment approach, and requirements for auditors.

The assessment covers a range of cyber security areas, including:

  • cyber security risk management;
  • incident management and response preparedness;
  • business continuity and recovery;
  • access and identity management;
  • protection of networks and information systems;
  • vulnerability management;
  • supply chain risks;
  • employees’ cyber security competence.

ENISA data also shows why it is important to look beyond documentation. Vulnerability and patch management is challenging for 50% of surveyed organisations, business continuity for 49%, and supply chain risk management for 37%.

A well-documented procedure does not necessarily mean that everything will work as planned when an incident occurs. An audit helps identify that gap.

Who can be an Independent Cyber Security Auditor?

The specialist conducting it must meet the competence requirements established by the LCS and the NCSC and must be independent and impartial. When selecting an auditor, it is therefore important to consider not only the service provider, but also the qualifications and experience of the individual specialists who will conduct the audit.

Independence is particularly important. A specialist should not assess processes they have designed or managed themselves and then confirm that those same processes are working properly.

What Qualifications Must an Auditor Have?

An auditor’s competence may be demonstrated by international certifications that meet the established criteria, or by completing training and passing a qualification examination in accordance with the NCSC’s procedure. A certificate alone is not sufficient: the auditor’s experience, independence, impartiality, and compliance with other applicable requirements are also assessed.

Recognised cyber security qualifications include CISSP (Certified Information Systems Security Professional). CISA (Certified Information Systems Auditor) is another widely recognised qualification in the audit field.

When selecting cyber security audit services, it is therefore worth clarifying in advance:

  • who will actually conduct the audit;
  • what qualifications and experience the auditors have;
  • whether they have worked with similar organisations;
  • how their independence will be ensured;
  • what the audit scope and process will be;
  • whether an appropriate audit report will be prepared for submission to the NCSC.  

For example, Baltic Amadeus prepares cyber security audit reports in line with recognised standards for use when submitting documentation to the NCSC. If an organisation has specific deadlines, audit scope requirements, or other considerations, these can be discussed before the audit begins.

How Do You Need to Prepare for the Cyber Security Audit?

Organisations that manage cyber security continuously are typically better prepared for an audit. They know their weak points, regularly assess compliance, and address identified gaps. This also makes the audit itself more straightforward, as it evaluates processes and measures that are already in place within the organisation.

When preparing, it is worth answering five questions:

  • Is the audit scope clear? You need to know which networks and information systems will be assessed.
  • Have the applicable cyber security requirements been implemented? Documentation alone is not enough – the required measures must work in practice.
  • What did the latest compliance assessment show? If gaps were identified, it is important to verify that they have actually been addressed.
  • Can we demonstrate it? The auditor will need not only explanations, but also evidence that the processes work.
  • Has the auditor been selected in advance? It is better to agree on the audit scope and required information before the final deadline.  

A Cyber Security Audit Can Deliver More Than Regulatory Compliance

The audit is primarily required to ensure compliance with the LCS, but its value can extend much further. An independent assessment shows where the organisation’s protection works well and where gaps remain between documented rules and day-to-day practice.

For many organisations, regulation is a catalyst for adopting a more systematic approach to cyber security. According to ENISA, 70% of surveyed organisations in NIS2 sectors identified regulatory compliance as the primary driver of cyber security investment.

The benefits, however, extended beyond compliance. 41% of organisations reported improved risk management, 35% improved threat detection, and 26% improved incident response.

The same applies to a cyber security audit. Formally, it shows whether an organisation meets the applicable requirements. In practice, its value also lies in identifying the most significant gaps and deciding what to address first.

When to Start Planning a Cyber Security Audit

If an organisation has already been included in the Register of Cyber Security Entities, preparation should not be postponed until the audit deadline approaches. If there is still uncertainty about compliance or remaining gaps, it is worth assessing them in advance.

Baltic Amadeus’ cyber security team conducts both compliance assessments and independent cyber security audits. We can get involved at the stage your organisation is currently at – from preparation through the audit itself and its outcomes.

If you want to assess how ready your organisation is for an audit, or to determine whether it is time to start planning one, contact the Baltic Amadeus cyber security team.

Related Blogs

Let’s talk about your project

Starting something new or need support for an existing project? Reach out, and our experts will get back to you within one business day.

Start the conversation

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.