National Cybersecurity System and the KSC Act – 2026 guide

The Polish National Cybersecurity System (KSC) is the framework of cybersecurity obligations for designated entities. The amendment to the KSC Act implements NIS2 in Polish law and sets out qualification, deadlines, ISMS, incident and audit requirements.

In Poland, a discussion of “NIS2 in a company” usually means working with the KSC Act: determining whether the entity is in scope, its status and deadlines, and the organisational and technical obligations to implement.

Key KSC deadlines

  1. 3 Apr 2026

    The amendment to the KSC Act entered into force.

  2. 3 Oct 2026

    Deadline for entry in the KSC Register for entities that met the criteria on 3 Apr 2026. The general rule is six months from meeting the criteria.

  3. 3 Apr 2027

    For the initial group of entities: deadline to implement obligations and start using the S46 System.

  4. 3 Apr 2028

    First audit deadline for key entities that were not previously operators of essential services. Existing OUK operators retain their three-year cycle.

  5. 3 Apr 2028

    Provisions on penalties start to apply.

Who does the KSC Act apply to?

  • Activity listed in Annex 1 or Annex 2 to the Act
  • Company-size criteria (medium / large) where the Act requires them
  • Consideration of partner and linked enterprises when assessing company size
  • Cases covered regardless of size where the Act so provides
  • Possible identification or classification by a competent authority in cases provided for by the Act

PKD classification or employee headcount alone is not enough. The assessment requires analysis of the activity actually performed, sector, size including the group, and exceptions. Confirm formal classification with legal counsel.

Key entity vs important entity

This comparison helps organise the differences, but does not replace reading the Act or an individual classification. The comparison article provides further detail and illustrative scenarios.

Comparison of key and important entities
AreaKey entityImportant entity
Basis for classificationArticle 5 KSC + statutory annexes and criteriaArticle 5 KSC + statutory annexes and criteria
AnnexMore often connected with Annex 1 in typical scenariosMore often connected with Annex 2 in typical scenarios
SizeRelevant where required by the Act; size-independent exceptions existRelevant where required by the Act; size-independent exceptions exist
Shared obligations (among others)KSC Register, S46, ISMS, risk, suppliers, incidents, documentationKSC Register, S46, ISMS, risk, suppliers, incidents, documentation
Recurring auditAt least once every 3 yearsNo general recurring obligation as for a key entity; the authority may order an audit in specified cases

Details: key and important entities under KSC.

Key obligations

  • Entry in the KSC Register
  • Use of the S46 System (Cyber Hub) as required
  • Implementation of an information security management system (ISMS)
  • Risk management
  • Inventory of assets and services that support service delivery
  • Supply-chain security
  • Incident management
  • Reporting serious incidents (including 24 h / 72 h / final report)
  • Normative and operational documentation and evidence that controls operate
  • A cybersecurity-responsible function or agreement with a suitable provider
  • Manager accountability and training (delegation does not remove accountability)
  • Personnel requirements, including Article 8f, subject to statutory exceptions

Serious incident – 24 h, 72 h and one month

A serious incident has a statutory definition in Article 2(7) KSC. There is no single universal numerical threshold for every entity. The usual reporting rhythm is an early warning within 24 hours, notification within 72 hours and a final report generally within one month of notification, subject to exceptions and ongoing handling.

Read the full guide to reporting a serious incident

Is SIEM enough?

No. SIEM can support continuous monitoring, event detection and evidence collection, but it does not replace risk management, business continuity, supplier security, procedures, access control, training or the documentation required for an ISMS.

See what an ISMS under the KSC Act covers

KSC guides

How DevSentinel can help

  • Current-state and gap assessment within an agreed scope
  • Map of services, systems and responsibilities
  • ISMS implementation and priority plan
  • Documentation and processes, both normative and operational
  • Incident-reporting process and playbook
  • Audit preparation
  • Technical remediation: hardening, monitoring, backups and application fixes

I do not provide formal legal advice or guarantee compliance, certification or a positive inspection outcome. Formal entity classification should be confirmed with appropriate legal counsel.

Go to the KSC and NIS2 implementation service

FAQ

How does KSC differ from NIS2?

NIS2 is an EU directive. In Poland, its implementation is carried out through the amendment to the KSC Act, which sets local obligations, deadlines and entity classification.

Who does the KSC Act apply to?

Entities specified by the Act, usually according to the type of activity in the annexes and, where required, size criteria, taking account of exceptions and authority decisions.

Does a company with 50 employees automatically fall under KSC?

No. Employee count alone is not decisive. Activity, sector, size criteria including the group, and statutory exceptions all matter.

When must an entity enter the KSC Register?

For entities meeting the criteria on 3 Apr 2026, the deadline is 3 Oct 2026. The general rule is six months from meeting the criteria. Self-registration has been available since 7 May 2026.

Must an important entity also implement an ISMS?

Yes. Obligations include an ISMS, risk management and incident management. Differences include the recurring audit for key entities and the authority’s ability to order an audit of an important entity.

Who is accountable for KSC implementation?

Responsibility rests with the entity’s manager. Delegating tasks does not remove that responsibility. Manager training takes place once a year and must be documented.

Does SIEM ensure KSC compliance?

No. SIEM supports monitoring and detection but does not replace the full ISMS, processes, supplier arrangements, business continuity or documentation.

Must every entity conduct an audit every three years?

A key entity conducts an audit at least once every three years. An important entity does not have the same general recurring obligation, although the authority may order an audit in specified cases.

Official sources