Regulatory exposure

KSC/NIS2: whether and where it applies to your organisation.

We organise your status, obligations and open questions, so you know where KSC actually applies to you and what the next decision is, without penalty scare tactics or artificial urgency.

01 Fit

When this service fits

When you need to establish whether and where KSC/NIS2 applies to your organisation, as regulatory exposure and a supply chain factor, rather than a full implementation. KSC is the act on the national cybersecurity system, which implements the EU NIS 2 directive (amending act of 23 January 2026, Dz.U. 2026 poz. 252). The obligations of Polish entities arise from the act, not directly from the directive.

02 Scope

What we review

  • Your status under KSC. The act distinguishes between an essential entity and an important entity based on sector (annexes) and the size of the enterprise (art. 5). Where the criteria overlap, the entity is essential.
  • The core obligation is an information security management system and risk management measures (art. 8).
  • Senior management completes training once per calendar year (art. 8e).
  • A major incident is reported to the relevant sectoral CSIRT: an early warning within 24 hours, a notification within 72 hours, and a final report within one month (art. 11).
  • An essential entity carries out an audit at least once every 3 years. An important entity has no cyclical audit, but the competent authority may order an audit in the event of a major incident or a breach of the rules (art. 15).
  • Entry into the register of entities (the KSC ICT system, commonly known as S46, art. 46) and the impact on the board and management liability.
  • The impact on the supply chain and the link with cyber insurance and with OT/IEC 62443.

Tool Quick check

Quick check by NIP number

Based on registry data (GUS), we will point out KSC applicability indicators in a few seconds.

We do not store NIP numbers. The result is preliminary and does not determine the entity's status.

03 Result

What decision the result supports

The result is a map of exposure, open questions and next decisions, not a legal opinion.

04 Inputs

What to prepare

  • A short description of your activity, sector and the scale of the organisation.
  • Your PKD codes and whether you provide digital services or are an ICT supplier to an essential entity.
  • The available security documentation and any requirements that have come from clients, an auditor or an insurer.

05 Terms

How scope and quotation are set

Scope and quotation depend on the number of entities and locations covered by the analysis, the extent of the questionnaire and the conversations required. We establish both after a short scoping call.

06 Limits

What this service does not replace

This is not a legal opinion or an implementation done for you. We separate legal interpretation from the technical and organisational part; on legal questions you work with advisers and law firms. Holding ISO 27001 makes it easier to meet KSC requirements, but it does not automatically mean compliance. IEC 62443 is not a general statutory obligation for every company with OT.

07 Process

Signal → review → evidence → decision

Signal

Who is asking about your KSC/NIS2 status?

Review

Whether, and as which entity, you may be subject?

Evidence

Which obligations actually apply to you?

Decision

Where to begin and what to defer?

08 Questions

Questions before starting

  • Is this a legal opinion? No. It is a map of exposure, open questions and next decisions; legal interpretation stays with advisers and law firms.
  • What are the key dates?
    • The KSC amending act entered into force on 3 April 2026.
    • Entries into the register of entities (the KSC ICT system, commonly known as S46, art. 46): ex officio from 13 April to 6 May 2026, and self-registration on application from 7 May to 3 October 2026.
    • Implementation of the obligations from chapter 3 (including art. 8 and art. 14) and the start of using the S46 system within 12 months of entry into force, that is by 3 April 2027.
    • The first audit of an essential entity within 24 months, that is by 3 April 2028.
  • Is this about penalty scare tactics? No. Administrative penalties are imposed by the act (art. 73): for an essential entity up to EUR 10 million or 2% of turnover, for an important entity up to EUR 7 million or 1.4%. A moratorium applies, however: financial penalties may be imposed for the first time only after 2 years from entry into force, that is from 3 April 2028 (art. 35). The act also provides for personal liability of a manager up to 300% of remuneration (art. 73a). For this reason we build urgency on real grounds, not on penalties.

09 Contact

Discuss the KSC/NIS2 Exposure Check scope

A few sentences about the organisation let us set the scope of the KSC/NIS2 exposure map.

Discuss your organisation

Source: Directive (EU) 2022/2555, Dz.U. 2026 poz. 252. Editorial review: CZ Cybersecurity sp. z o.o. Content reviewed: 21 July 2026.