KSC and NIS2 in Poland - Who Is Affected by the New Obligations and What Consequences Could Companies Face?

Cybersecurity is no longer just a technical problem for the IT department. Today, it is an element of management responsibility, business continuity, revenue protection, and the security of the entire supply chain. One of the most important regulations in this area is the Act on the National Cybersecurity System, commonly referred to as the KSC.
The amendment to the KSC, which implemented the requirements of the EU NIS2 Directive into Polish law, significantly expanded the range of entities covered by the regulation. The previous categories of operators of essential services and digital service providers were replaced with essential entities and important entities. According to estimates by the Polish Ministry of Digital Affairs, the new rules may apply to approximately 38,000 organizations, including around 27,000 public-sector entities.
What Is the National Cybersecurity System?
The National Cybersecurity System is a set of laws, institutions, procedures, and mechanisms designed to increase the resilience of the state, public administration, and businesses against cyberattacks.
The KSC defines, among other things:
which organizations are subject to cybersecurity obligations;
what organizational and technical security measures they should implement;
how they should manage risk;
how they should detect and handle incidents;
when and to whom serious incidents must be reported;
how compliance with the obligations is supervised;
what sanctions may be imposed on a company and its management.
The KSC should not be treated as a single certificate, product, or IT system. A company does not “implement KSC” in the same way it deploys antivirus software. In practice, an organization must implement an Information Security Management System, procedures, responsibilities, technical safeguards, and an ongoing risk management process.
Who Is Subject to the KSC?
Simply conducting business activity does not automatically mean that an organization falls under the Act. The following factors must be analyzed together:
the type of business activity;
the sector listed in the annexes to the Act;
the size of the enterprise;
capital and organizational relationships;
the importance of the services provided;
exceptions where company size is irrelevant.
This process is known as self-identification. The entity independently assesses whether it meets the criteria for classification as an essential or important entity. The analysis should be based primarily on Article 5 of the Act and Annexes 1 and 2.
Essential Entities
This category primarily includes larger organizations operating in sectors considered critical to the state and society. As a general rule, this applies to entities listed in Annex 1 that exceed the thresholds for a medium-sized enterprise.
Essential entities may include organizations operating in sectors such as:
energy, district heating, gas, fuels, hydrogen, and nuclear energy;
air, rail, water, and road transport;
banking and financial market infrastructure;
healthcare;
manufacturing and distribution of medicinal products and medical devices;
drinking water supply;
wastewater collection and treatment;
digital infrastructure;
electronic communications;
ICT service management;
space;
public administration and public-sector entities.
In certain cases, an organization may be classified as an essential entity regardless of its size. This may include DNS service providers, qualified trust service providers, critical entities, certain public-sector entities, top-level domain registries, and domain name registration service providers.
Important Entities
An important entity may include, among others, a medium-sized enterprise operating in an essential sector that does not meet the criteria for classification as an essential entity, as well as medium-sized and larger enterprises operating in sectors listed in Annex 2.
Important sectors include, among others:
postal services;
waste management;
manufacturing, production, and distribution of chemicals;
food production, processing, and distribution;
manufacturing of electrical equipment;
manufacturing of computers, electronics, and optical equipment;
manufacturing of machinery and equipment;
manufacturing of vehicles, trailers, semi-trailers, and transport equipment;
digital service providers;
research organizations;
certain public and municipal entities.
The Act also provides specific rules for electronic communications providers, trust service providers, managed cybersecurity service providers, and healthcare entities. In some cases, small businesses and micro-enterprises may also fall within the scope of the regulation.
For this reason, simply assuming that a company is “too small for NIS2” may be incorrect.
Key Obligations Under the KSC
1. Entry in the KSC Register
Entities covered by the Act are required to be entered in the register of essential and important entities. Some organizations are registered automatically, while others must carry out self-identification and complete the registration process themselves.
Entities that met the criteria when the amendment entered into force should complete registration by 3 October 2026.
Failure to register does not mean that a company is exempt from the rules. If it meets the statutory criteria, the obligations may apply regardless of whether the organization has completed the registration process correctly.
2. Information Security Management System
One of the core obligations is the implementation of an Information Security Management System - ISMS in systems used in processes that affect the provision of services.
The ISMS should include systematic risk assessment and proportionate technical and organizational measures. The Act refers, among other things, to:
security and risk management policies;
security of system acquisition, development, and operation;
security testing;
physical and environmental security;
personnel security;
supplier and supply chain risk management;
business continuity plans, contingency plans, and disaster recovery;
continuous system monitoring;
procedures for assessing the effectiveness of security measures;
employee training and cyber hygiene;
cryptography and encryption;
secure communications;
multi-factor authentication, where appropriate;
asset management;
access control;
vulnerability and incident management;
regular software updates.
In practice, this means that simply purchasing a firewall, antivirus software, or monitoring service is not enough. An organization must be able to demonstrate that its security measures are based on risk analysis, properly documented, regularly tested, and actually used.
3. Incident Management
A company must have procedures that allow it to:
detect an incident;
determine its scale;
preserve evidence;
limit the spread of the threat;
restore services;
document the course of the incident;
report the incident to the relevant CSIRT.
Specific deadlines apply to serious incidents:
early warning - no later than 24 hours after detection;
formal notification - no later than 72 hours;
final report - generally within one month of notification.
These short deadlines require preparation in advance. A company should not be deciding for the first time during an attack who is responsible for decision-making, where logs are stored, how to isolate an infected device, or who is responsible for communicating with the CSIRT.
4. Management Responsibility
The new rules clearly elevate cybersecurity to the management level. The head of the entity is responsible for ensuring compliance with the obligations, making decisions concerning the ISMS, planning the budget, assigning responsibilities, and supervising implementation.
In the case of a multi-member management body, responsibility may apply to all members if no specific person has been designated. Assigning tasks to an employee, an external IT specialist, or a service provider does not release management from responsibility.
Management and individuals assigned cybersecurity responsibilities should also complete documented training once a year.
5. Cybersecurity Audits
Essential entities are required to carry out independent cybersecurity audits. The first audit for entities covered by the amendment should be completed by 3 April 2028, with subsequent audits carried out at least once every three years.
The audit should not be limited to reviewing documentation. It must assess whether procedures and security measures have actually been implemented, whether they are effective, and whether they are appropriate to the organization’s risk profile.
What Are the Consequences of Non-Compliance?
Financial Penalties for Essential Entities
For an essential entity, the maximum penalty may amount to:
EUR 10 million, or
2% of revenue generated from business activity in the previous financial year,
whichever amount is higher. The minimum penalty is PLN 20,000.
Penalties for Important Entities
For an important entity, the maximum penalty may amount to:
EUR 7 million, or
1.4% of revenue generated from business activity in the previous financial year.
The minimum penalty is PLN 15,000.
Penalties of Up to PLN 100 Million
If a violation results in a direct and serious cyber threat to national security, public order, defense, human life or health, or creates a risk of serious financial damage or major disruption to service provision, the penalty may reach as much as PLN 100 million.
Personal Penalties for Management
Penalties may be imposed not only on the organization, but also directly on its management. The penalty may amount to up to 300% of the individual’s monthly remuneration, and in the case of the head of a public entity - up to 100% of remuneration.
Liability may arise, among other things, from:
failure to implement an appropriate ISMS;
improper risk management;
failure to provide management training;
failure to report an incident;
failure to carry out an audit;
failure to designate contact persons;
inadequate supervision of compliance obligations.
Penalties for Each Day of Delay
To compel an organization to comply with an authority’s decision, an additional periodic penalty ranging from PLN 500 to PLN 100,000 for each day of delay may be imposed.
Restriction or Suspension of Business Activity
For an essential entity, the authority may apply measures significantly more serious than a financial penalty. In certain cases, these may include:
restricting or suspending a license to operate;
suspending part or all of the organization’s activities;
prohibiting the head of the entity from performing management functions;
publishing information about the measures applied in the Public Information Bulletin.
Operational and Business Consequences
In addition to statutory sanctions, inadequate security may lead to:
suspension of production or service delivery;
ransomware encryption of data;
loss of documentation and backups;
compromise of employee accounts;
theft of trade secrets;
personal data breaches;
termination of contracts;
claims from customers and business partners;
loss of access to contracts requiring compliance with KSC or NIS2;
increased cyber insurance costs;
loss of reputation and customer trust;
liability under other regulations, including GDPR;
the need to implement expensive emergency security measures.
In many cases, downtime, data loss, and supply chain disruption generate greater losses than the administrative penalty itself.
Key Deadlines
For entities that met the criteria on the date the amendment entered into force, the following deadlines apply:
3 October 2026 - entry in the KSC Register;
3 April 2027 - implementation of obligations, including the ISMS, incident management, and required procedures;
3 April 2027 - connection to the S46 system;
3 April 2028 - first mandatory audit for relevant essential entities.
The Act provides that the new financial penalties may be imposed for the first time after two years from the date the amendment entered into force. This does not, however, postpone the deadlines for implementing obligations or release organizations from responsibility for cybersecurity.
Why Is It Worth Implementing KSC Requirements?
Fewer Incidents
Structured management of assets, updates, permissions, and vulnerabilities helps eliminate many of the most common attack paths before cybercriminals can exploit them.
Shorter Downtime
Business continuity plans, tested backups, and recovery procedures reduce the time needed to resume operations after a failure or cyberattack.
Greater Control Over Infrastructure
In many companies, knowledge about systems, passwords, suppliers, and configurations is held by only one person or by an external IT provider. KSC requires documentation, clear allocation of responsibilities, and regular verification of security measures.
A More Secure Supply Chain
An organization must assess not only its own security, but also risks related to software vendors, cloud providers, hosting providers, maintenance services, and IT service providers. This reduces the likelihood of an attack being carried out through a less secure partner.
Greater Credibility
A mature cybersecurity management system increases a company’s credibility with customers, investors, insurers, and business partners. More and more large organizations require their suppliers to demonstrate appropriate security measures, even if the supplier itself is not directly subject to the KSC.
Better Preparation for Other Regulations
A properly implemented ISMS makes it easier to meet requirements arising from GDPR, ISO/IEC 27001, sector-specific regulations, supplier security requirements, and contractual obligations.
How to Begin Implementation
The first step should be a formal assessment of whether the organization falls within the scope of the Act. The organization should then:
identify the services and processes covered by the regulation;
inventory systems, devices, data, and suppliers;
perform a risk assessment and gap analysis;
designate responsible individuals;
prepare an implementation plan and budget;
develop ISMS documentation;
implement technical security measures;
prepare incident handling and reporting procedures;
test backups and business continuity arrangements;
train management and employees;
collect evidence demonstrating compliance;
prepare the organization for inspections and audits.
KSC Is More Than a Legal Obligation
One of the biggest mistakes is treating KSC compliance as a one-time documentation project. Even the best-prepared procedures will not provide real security if they are not followed, tested, and regularly updated. A proper implementation should combine legal, organizational, and technical measures. This includes not only policies and risk analysis, but also network segmentation, access control, multi-factor authentication, secure backups, monitoring, endpoint protection, vulnerability management, and preparing the company to respond effectively to incidents.
KSC should therefore be treated not only as a statutory requirement, but also as a foundation for building a resilient organization. A company that organizes and strengthens its security in advance reduces the risk of penalties, downtime, and data loss, while also improving its credibility and ability to grow safely.
This material is for informational purposes only. The final classification of a specific organization as an essential or important entity should take into account the type of business activity, company size, related entities, and the detailed provisions of the Act.


Comments