What uKSC says about audits
An essential entity carries out, at its own expense, a security audit of the information system used to provide the service at least once every three years. As a rule, the first audit is to be ensured within 24 months of meeting the criteria for recognition as an essential entity.
For entities that met the criteria when the amendment entered into force on 3 April 2026, transitional provisions provide a 24-month period from that date.