KSC and NIS2 in Poland in 2026 – Business Duties and Audits
Learn who is covered by Poland's amended KSC Act, the key deadlines, and how a statutory audit differs from a technical readiness assessment.

Poland implemented the NIS2 Directive through an amendment to the Act on the National Cybersecurity System, commonly referred to as the KSC Act. The new rules have applied since April 3, 2026, and introduced specific deadlines for essential and important entities operating in Poland.
This guide explains how to make an initial assessment of whether a business is covered, what actions it should plan, and how a statutory KSC audit differs from a practical IT security assessment.
This article provides general technical information. It is not legal advice or confirmation of an organization's status under the KSC Act.
NIS2 and KSC – what is the difference?
NIS2 is a European Union directive. For organizations operating in Poland, the detailed obligations are set primarily by the amended Polish KSC Act that implements the directive.
A generic “NIS2 checklist” is therefore not enough. An organization must consider the Polish legislation, its sector, company size, linked enterprises, information systems, and the services it provides.
The enacted amendment is available in Poland's official Journal of Laws, while practical dates and guidance are published by the Polish Ministry of Digital Affairs.
Who is covered by the amended KSC Act?
The Act distinguishes between essential entities and important entities. Employee headcount alone does not determine the classification.
| Category | General rule |
|---|---|
| Essential entity | Most commonly a large entity carrying out an activity listed in Annex 1, or an entity covered by a special rule in the Act |
| Important entity | Most commonly a medium-sized Annex 1 entity or a medium-sized or large Annex 2 entity that is not an essential entity |
The annexes cover sectors such as energy, transport, healthcare, digital infrastructure, public administration, postal services, waste management, food production and distribution, and selected manufacturing industries.
Some entities are covered regardless of size. Partner and linked enterprises may also affect the calculation. This is why the statement “NIS2 applies to every company with at least 50 employees” is too simplistic.
What should be checked first?
- the organization's actual activities and the relevant statutory annex,
- employee headcount, turnover, and balance sheet total,
- the group structure and linked enterprises,
- systems used to provide covered services,
- registration or registration duties in the KSC Register,
- any decisions issued by the competent authority.
Where the outcome determines the organization's legal obligations, the classification should be confirmed with a lawyer specializing in Polish cybersecurity law.
Key deadlines for 2026–2028
For entities that met the criteria when the amendment entered into force, the main dates are:
| Date | Obligation |
|---|---|
| October 3, 2026 | Deadline for self-registration in the KSC Register |
| April 3, 2027 | End of the period for connecting to S46 and implementing the required duties, including an ISMS |
| April 3, 2028 | First mandatory audit deadline for new essential entities that were not previously operators of essential services |
| April 3, 2028 | Monetary penalty provisions begin to apply |
Entities that become covered later calculate their deadlines under the statutory rules. Current explanations are published by the Polish Ministry of Digital Affairs.
What must an organization implement?
KSC compliance is not achieved by purchasing antivirus software. A covered organization must implement and maintain an information security management system and risk-appropriate safeguards.
In practice, this includes:
- cybersecurity governance and risk management,
- an inventory of systems, devices, services, and data,
- vulnerability and patch management,
- access controls, privileged accounts, and MFA,
- protection of networks, servers, endpoints, and email,
- backups and regular restoration tests,
- logging, monitoring, and incident handling,
- business continuity and disaster recovery,
- supplier and supply-chain security,
- training for staff and management,
- documentation, evidence, and continuous improvement.
Documentation matters, but it cannot replace working safeguards. A meaningful assessment should examine both procedures and how they operate in practice.
Statutory KSC audit vs. technical readiness assessment
These are not interchangeable services.
Statutory audit under Article 15 of the KSC Act
An essential entity must undergo a periodic audit at least once every three years. The audit may be performed by an appropriately accredited conformity assessment body, a team of at least two auditors meeting the statutory requirements, or the relevant sectoral CSIRT.
An auditor may not perform the audit if they currently carry out certain cybersecurity duties for the audited organization or performed them during the preceding year.
Important entities do not automatically undergo this periodic audit. However, the competent authority may order an external audit after a serious incident or another violation of the Act.
Technical readiness assessment
This practical review is intended to identify gaps before a statutory audit or to provide an independent view of the organization's current security. It may include scanning, configuration reviews, interviews, documentation review, backup testing, and supplier assessment.
Useful deliverables include:
- an executive summary,
- a risk register and technical evidence,
- a list of missing or ineffective safeguards,
- mapping of findings to KSC/NIS2 areas,
- a 30-, 90-, and 180-day remediation roadmap,
- verification after improvements are implemented.
Such a report helps an organization prepare, but it is not a statutory report under Article 15 of the KSC Act, a compliance certificate, or legal advice.
How to prepare step by step
1. Determine status and scope
Review the sector, company size, corporate links, essential services, and supporting systems. Determine whether the organization is an essential entity, an important entity, or outside the statutory scope.
2. Assess the current state
Collect documentation and evidence, then review infrastructure configurations, accounts, networks, endpoints, backups, monitoring, incident handling, and suppliers.
3. Prioritize risks
Address issues that could interrupt operations, cause data loss, or enable account takeover first. Purchasing a security product is not enough — it must be configured, monitored, and tested.
4. Implement the ISMS and safeguards
Procedures should reflect the real IT environment. Every important control should have an owner, an operating method, and evidence that it works.
5. Test effectiveness
Test backup restoration, incident scenarios, emergency access, communications, continuity arrangements, and threat detection.
6. Plan the independent statutory audit
If the organization is an essential entity or has received an order from the competent authority, select an appropriately authorized and independent audit team. Do not leave preparation until the final months before the deadline.
How can nex-IT help?
nex-IT provides technical IT security audits and KSC/NIS2 readiness assessments. We verify whether safeguards work in practice, identify risks, and prepare a prioritized remediation roadmap.
We do not present this service as a statutory audit under Article 15 of the Polish KSC Act and do not issue a legal compliance opinion. Where an organization requires a formal report, it should be prepared by an appropriately authorized and independent audit team.
Related articles
Keycloak vs Authentik - Open Source SSO for Business
Single sign-on (SSO) without per-user subscriptions? Keycloak and Authentik are two leading open-source identity management systems. Learn the differences, benefits and find out which solution nex-IT will deploy in your company.
Read moreCyber Resilience Act (CRA) - What Software Producers Need to Know
Practical guide to new EU cybersecurity requirements for digital products. Learn how to prepare your company for CRA compliance and avoid penalties.
Read moreSophos - Comprehensive Cybersecurity Solutions for Businesses | Sophos Partner
Discover Sophos solutions: XDR, MDR, firewall, email and endpoint protection. As an official Sophos partner, nex-IT will help you implement the best security for your business.
Read more
