Regulatory exposure

KSC/NIS2: whether and where it applies to your organisation.

Before the question of security measures comes another one: whether KSC covers the organisation at all, and if so, as an essential or an important entity. The Exposure Check answers that and shows what follows from the answer.

01 Fit

When this service fits

When you need to establish whether and where KSC/NIS2 applies to your organisation, as regulatory exposure and a supply chain factor. KSC is the act on the national cybersecurity system, which implements the EU NIS 2 directive (amending act of 23 January 2026, Dz.U. 2026 poz. 252). The obligations of Polish entities arise from the act, not directly from the directive.

02 Scope

What we review

  • Your status under KSC. The act distinguishes between an essential entity and an important entity based on sector (annexes) and the size of the enterprise (art. 5). Where the criteria overlap, the entity is essential.
  • The core obligation is an information security management system and risk management measures (art. 8).
  • Senior management completes training once per calendar year (art. 8e).
  • A major incident is reported to the relevant sectoral CSIRT: an early warning within 24 hours, a notification within 72 hours, and a final report within one month (art. 11).
  • An essential entity carries out an audit at least once every 3 years. An important entity has no cyclical audit, but the competent authority may order an audit in the event of a major incident or a breach of the rules (art. 15).
  • Entry into the register of entities (the KSC ICT system, commonly known as S46, art. 46) and the impact on the board and management liability.
  • The impact on the supply chain and the link with cyber insurance and with OT/IEC 62443.

Tool Quick check

Quick check by NIP number

Based on registry data (GUS), we will point out KSC applicability indicators in a few seconds.

We do not store NIP numbers. The result is preliminary and does not determine the entity's status.

03 Result

What decision the result supports

The result is a map of exposure, open questions and next decisions.

04 Inputs

What to prepare

  • A short description of your activity, sector and the scale of the organisation.
  • Your PKD codes and whether you provide digital services or are an ICT supplier to an essential entity.
  • The available security documentation and any requirements that have come from clients, an auditor or an insurer.

05 Terms

How scope and quotation are set

Scope and quotation depend on the number of entities and locations covered by the analysis, the extent of the questionnaire and the conversations required. We establish both after a short scoping call.

06 Limits

What falls outside the scope

This is not a legal opinion or an implementation done for you. We separate legal interpretation from the technical and organisational part; on legal questions you work with advisers and law firms. Holding ISO 27001 makes it easier to meet KSC requirements, but it does not automatically mean compliance. IEC 62443 is not a general statutory obligation for every company with OT.

07 Process

Signal → review → evidence → decision

Signal

Who is asking about your KSC/NIS2 status?

Review

Whether, and as which entity, you may be subject?

Evidence

Which obligations actually apply to you?

Decision

Where to begin and what to defer?

08 Questions

Questions before starting

  • Is this a legal opinion? No. It is a map of exposure, open questions and next decisions; legal interpretation stays with advisers and law firms.
  • What are the key dates?
    • The KSC amending act entered into force on 3 April 2026.
    • Entries into the register of entities (the KSC ICT system, commonly known as S46, art. 46): ex officio from 13 April to 6 May 2026, and self-registration on application from 7 May to 3 October 2026.
    • Implementation of the obligations from chapter 3 (including art. 8 and art. 14) and the start of using the S46 system within 12 months of entry into force, that is by 3 April 2027.
    • The first audit of an essential entity within 24 months, that is by 3 April 2028.
  • What penalties does the act provide for? Administrative penalties are imposed by the KSC act (art. 73): for an essential entity up to EUR 10 million or 2% of turnover, for an important entity up to EUR 7 million or 1.4%, in both cases whichever is higher. The act also provides for personal liability of a manager up to 300% of remuneration (art. 73a). Most of these are under a moratorium: penalties under art. 73(1)–(4), art. 73a–73c and art. 76b may be imposed for the first time only after 2 years from entry into force, that is from 3 April 2028 (art. 35 of the amending act). The moratorium does not cover art. 73(5), the penalty of up to PLN 100 million for a breach causing a direct and serious threat to defence, state security, public order, or human life and health.

09 Contact

Discuss the KSC/NIS2 Exposure Check scope

A few sentences about the organisation let us set the scope of the KSC/NIS2 exposure map.

Talk to us

Source: Directive (EU) 2022/2555, Dz.U. 2026 poz. 252. Editorial review: CZ Cybersecurity sp. z o.o. Content reviewed: 19 August 2026.