National Cybersecurity System and the KSC Act – 2026 guide
The Polish National Cybersecurity System (KSC) is the framework of cybersecurity obligations for designated entities. The amendment to the KSC Act implements NIS2 in Polish law and sets out qualification, deadlines, ISMS, incident and audit requirements.
In Poland, a discussion of “NIS2 in a company” usually means working with the KSC Act: determining whether the entity is in scope, its status and deadlines, and the organisational and technical obligations to implement.
Key KSC deadlines
3 Apr 2026
The amendment to the KSC Act entered into force.
3 Oct 2026
Deadline for entry in the KSC Register for entities that met the criteria on 3 Apr 2026. The general rule is six months from meeting the criteria.
3 Apr 2027
For the initial group of entities: deadline to implement obligations and start using the S46 System.
3 Apr 2028
First audit deadline for key entities that were not previously operators of essential services. Existing OUK operators retain their three-year cycle.
3 Apr 2028
Provisions on penalties start to apply.
Who does the KSC Act apply to?
- Activity listed in Annex 1 or Annex 2 to the Act
- Company-size criteria (medium / large) where the Act requires them
- Consideration of partner and linked enterprises when assessing company size
- Cases covered regardless of size where the Act so provides
- Possible identification or classification by a competent authority in cases provided for by the Act
PKD classification or employee headcount alone is not enough. The assessment requires analysis of the activity actually performed, sector, size including the group, and exceptions. Confirm formal classification with legal counsel.
Key entity vs important entity
This comparison helps organise the differences, but does not replace reading the Act or an individual classification. The comparison article provides further detail and illustrative scenarios.
| Area | Key entity | Important entity |
|---|---|---|
| Basis for classification | Article 5 KSC + statutory annexes and criteria | Article 5 KSC + statutory annexes and criteria |
| Annex | More often connected with Annex 1 in typical scenarios | More often connected with Annex 2 in typical scenarios |
| Size | Relevant where required by the Act; size-independent exceptions exist | Relevant where required by the Act; size-independent exceptions exist |
| Shared obligations (among others) | KSC Register, S46, ISMS, risk, suppliers, incidents, documentation | KSC Register, S46, ISMS, risk, suppliers, incidents, documentation |
| Recurring audit | At least once every 3 years | No general recurring obligation as for a key entity; the authority may order an audit in specified cases |
Details: key and important entities under KSC.
Key obligations
- Entry in the KSC Register
- Use of the S46 System (Cyber Hub) as required
- Implementation of an information security management system (ISMS)
- Risk management
- Inventory of assets and services that support service delivery
- Supply-chain security
- Incident management
- Reporting serious incidents (including 24 h / 72 h / final report)
- Normative and operational documentation and evidence that controls operate
- A cybersecurity-responsible function or agreement with a suitable provider
- Manager accountability and training (delegation does not remove accountability)
- Personnel requirements, including Article 8f, subject to statutory exceptions
Serious incident – 24 h, 72 h and one month
A serious incident has a statutory definition in Article 2(7) KSC. There is no single universal numerical threshold for every entity. The usual reporting rhythm is an early warning within 24 hours, notification within 72 hours and a final report generally within one month of notification, subject to exceptions and ongoing handling.
Read the full guide to reporting a serious incidentIs SIEM enough?
No. SIEM can support continuous monitoring, event detection and evidence collection, but it does not replace risk management, business continuity, supplier security, procedures, access control, training or the documentation required for an ISMS.
See what an ISMS under the KSC Act coversKSC guides
Key entity vs important entity
Differences under Article 5, the annexes and size criteria—without the “50 employees = KSC” shortcut.
Does your company fall under KSC?
A practical self-assessment path: sector, annexes, size, exceptions and assessment documentation.
KSC Register and S46 System
Application, deadlines, data, power of attorney and access to S46 Cyber Hub.
Serious incident: 24/72 h
Definition, reporting stages, and a checklist of roles and evidence.
ISMS under KSC
Control scope, evidence and a first 90-day plan—including whether SIEM is enough.
How DevSentinel can help
- Current-state and gap assessment within an agreed scope
- Map of services, systems and responsibilities
- ISMS implementation and priority plan
- Documentation and processes, both normative and operational
- Incident-reporting process and playbook
- Audit preparation
- Technical remediation: hardening, monitoring, backups and application fixes
I do not provide formal legal advice or guarantee compliance, certification or a positive inspection outcome. Formal entity classification should be confirmed with appropriate legal counsel.
Go to the KSC and NIS2 implementation serviceFAQ
How does KSC differ from NIS2?
NIS2 is an EU directive. In Poland, its implementation is carried out through the amendment to the KSC Act, which sets local obligations, deadlines and entity classification.
Who does the KSC Act apply to?
Entities specified by the Act, usually according to the type of activity in the annexes and, where required, size criteria, taking account of exceptions and authority decisions.
Does a company with 50 employees automatically fall under KSC?
No. Employee count alone is not decisive. Activity, sector, size criteria including the group, and statutory exceptions all matter.
When must an entity enter the KSC Register?
For entities meeting the criteria on 3 Apr 2026, the deadline is 3 Oct 2026. The general rule is six months from meeting the criteria. Self-registration has been available since 7 May 2026.
Must an important entity also implement an ISMS?
Yes. Obligations include an ISMS, risk management and incident management. Differences include the recurring audit for key entities and the authority’s ability to order an audit of an important entity.
Who is accountable for KSC implementation?
Responsibility rests with the entity’s manager. Delegating tasks does not remove that responsibility. Manager training takes place once a year and must be documented.
Does SIEM ensure KSC compliance?
No. SIEM supports monitoring and detection but does not replace the full ISMS, processes, supplier arrangements, business continuity or documentation.
Must every entity conduct an audit every three years?
A key entity conducts an audit at least once every three years. An important entity does not have the same general recurring obligation, although the authority may order an audit in specified cases.
Official sources
- KSC Act amendment text (ELI / Dziennik Ustaw)
- gov.pl – amendment to the National Cybersecurity System (KSC) Act
- gov.pl – obligations of key and important entities
- gov.pl – key KSC deadlines
- gov.pl – entry in the KSC Register / S46 System
- gov.pl – KSC Register opens access to S46 Cyber Hub
- cyber.gov.pl – FAQ