What the free cybersecurity assessment is
The assessment is a questionnaire of ten questions about the state of information security in your organisation: how people sign in to key systems, backups, updates, access management and readiness for an incident. It takes about three minutes and requires no technical knowledge — the questions are written so that the person running the organisation can answer them, not only a systems administrator. At the end you receive a risk level and an indication of the areas worth addressing first. If the answers reveal significant gaps, Trenify Foundation offers a free audit, with no obligation and no fees.
Who it is for
The assessment and the audit are intended for non-profit organisations — foundations and associations — and for early-stage startups. These are organisations that usually have neither an in-house IT team nor a budget for commercial consultancy, yet process data belonging to people who trusted them: donors, beneficiaries, first users.
The questionnaire itself is open and anyone may use it, including a small business or a sole trader — the questions and conclusions are the same. The free audit as a service, however, remains reserved for non-profit organisations and startups, in line with the foundation's statutory purpose.
What the assessment covers
- how authentication works for email, banking and administrative panels,
- backups, and whether they have ever been restored,
- how current the website software and the tools in use are,
- management of accounts and permissions across the team,
- awareness of threats in the team and response to phishing attempts,
- incident readiness: who makes decisions, and against what plan.
What you get
- A risk level derived from your answers.
- Priority areas — what to fix first so that the largest share of risk disappears for the smallest effort.
- An offer of a free audit, if the answers reveal significant gaps and your organisation belongs to the groups described above.
Answers are treated as confidential and used solely to prepare the assessment and — if you leave contact details — to respond to your enquiry. Data processing is described in our Privacy Policy.
New regulations: NIS2, the AI Act and the CRA
Many organisations arrive here after hearing about new obligations. The amendment to the Polish National Cybersecurity System Act, in force since 3 April 2026, widened the scope of the regulation from roughly 400 entities to roughly 42,000 — yet most foundations and associations still fall outside it. Before you start preparing, it is worth establishing whether you have to at all.
Our explainers on these regulations are currently published in Polish, as they concern Polish implementing law and a Polish audience: