What is changing
NIS2/KSC: three issues to put in order operationally
NIS2 covers a wider group of telecom companies and changes how cybersecurity is managed: self-assessment, management accountability and system, process and supplier risk become part of a single process.
Change 1
You classify yourself – and you register yourself
The entity should determine which KSC category its activity falls into and whether it is an essential or important entity. For some digital infrastructure categories, special classification rules apply regardless of size.
⚠ Registration within 6 months
Change 2
Management is accountable, not the IT department
Management approves risk management measures and oversees their implementation. NIS2/KSC is therefore not just a task for the NOC, SOC, security team or IT department.
✓ Personal liability
Change 3
The scope is the whole organisation: network, IT, services and suppliers
The risk assessment should cover the service end to end: network and management systems, cloud or data centre, DNS, service platforms, privileged access and hardware, software, maintenance and connectivity suppliers.
✓ Network + IT + supply chain
Map of obligations
Five areas you need to maintain and be able to demonstrate
Audits and inspections quickly come down to specifics: who approved the risk, when the plan was tested, which actions are open, how the supplier was assessed and where the change history is.
1
Classification and registration
Self-identification, entry in the KSC register and keeping data and contact persons up to date.
2
Risk management and security measures
Risk assessment of the network, IT systems and services delivered, security measures, business continuity and regular reviews.
3
Supply chain
Assessment of hardware, software, maintenance and ICT service suppliers and control of security requirements and third-party access.
4
Incident handling
Incident classification, meeting the required reporting deadlines and documenting decisions, communication and post-incident actions.
5
Management oversight, training and audit
Management oversight, training, security audit, and planning and monitoring of corrective actions.
Timeline
Deadlines counted from the Act’s entry into force
3 Apr 2026
The KSC Act implementing NIS2 enters into force. All further deadlines are counted from this date.
3 Oct 2026
+6 months
+6 months
Registration in the KSC register (S46 system) and appointment of a cybersecurity contact person. The nearest deadline for most telecom companies.
3 Apr 2027
+12 months
+12 months
Full implementation of the information security management system and statutory measures – including documentation and approval by the management board.
3 Apr 2028
+24 months
+24 months
First security audit for essential entities – then at regular intervals. From this point on, fines become a real prospect.
ongoing
Incident reporting within 24 h / 72 h, risk reviews, plan testing, supplier assessments, board and staff training.
Legal basis: Directive (EU) 2022/2555 (NIS2) and the Polish Act on the National Cybersecurity System (KSC). Annex I covers, among others, digital infrastructure, electronic communications and ICT service management. Specific classification depends on the services provided and the rules in Article 5 of the KSC Act.
Sector specifics
A single outage can hit thousands of customers and dependent services at once
In telecommunications and digital infrastructure, availability is part of the product. A failure of the network, DNS, a management platform, a data centre or a cloud service can disrupt customers and other essential entities. That is why risk must be linked to service continuity and technology dependencies.
Telecommunications
Electronic communications providers
Fixed and mobile network operators, internet access, voice services and other public communications services.
Cloud and data centres
Cloud and data centre providers
Cloud services and data centres are a shared dependency for many customers – a power, cooling or platform failure can hit many services at once.
DNS and domains
DNS, TLD and domain registration
DNS, TLD registries and domain registration services directly affect the availability of internet services.
Traffic exchange and CDN
IXP and CDN providers
IXPs and CDNs are part of the traffic and content delivery path, so the risk assessment should consider availability, redundancy and dependencies.
Trust services
Trust service providers
Electronic signatures and seals, timestamps and certificates. Key compromise or service unavailability undermines trust in electronic transactions and documents.
Managed ICT services
Managed service providers (MSPs and MSSPs)
Customer infrastructure and security managed remotely, heavily dependent on platforms and administration tools – hence the focus on access control and supply chain oversight.
What this means in practice: risk assessments and continuity plans must cover the network and IT systems as well as service platforms, locations (nodes, data centres) and dependencies on hardware, software, maintenance and connectivity suppliers. More details in the FAQ.
BCMLogic Next for digital infrastructure
A GRC system for telecommunications and digital infrastructure
BCMLogic Next connects risks, BIA, continuity plans, incidents, suppliers, actions and deadlines. As a result, the NOC/SOC, security, compliance and service owners all work on one up-to-date dependency model.
Already have documentation? We move it into the system. Starting from scratch? Wizards guide you through.
We can migrate your existing documentation into the system or start with wizards that guide users step by step.
Network, system and service risk assessment
Risk assessment for services, network, systems and infrastructure, with risk owners, actions and change history.
Step-by-step wizard
Policies and procedures
Templates, approval workflows, version history and audit trail.
Ready-made templates
Business continuity plans
BIA, BCP and DRP for critical services, scenarios for network failure, DDoS or supplier unavailability, test schedules and exercise history.
Network failure and DDoS scenarios
Incident management
Incident handling with 24 h / 72 h deadlines, classification and a clear course of action.
24 h / 72 h timer
Suppliers and supply chain
Register and risk assessment of hardware, software, cloud, maintenance and ICT service suppliers, with monitoring of requirements and reviews.
Supplier and maintenance register
Audit readiness
Compliance status, approval and review history, and reports that support audit preparation.
Report for the auditor
Note for the largest entities – the CER Directive:
Some digital infrastructure organisations may also be subject to critical entity resilience requirements. The scope should be verified separately; details are in the FAQ.
Some digital infrastructure organisations may also be subject to critical entity resilience requirements. The scope should be verified separately; details are in the FAQ.
Online demo
Want to see how it works in practice?
Explore BCMLogic Next with demo data or book a 30-minute meeting and walk through an operator or digital infrastructure provider scenario with us.
🖥
Online demo environment
Ready-made demo data: risks, incidents, business continuity and NIS2 compliance.
📞
A short meeting with our team
30 minutes for a system walkthrough and questions about your organisation and where you are in your NIS2 preparations.
FAQ · NIS2 and GRC in telecommunications and digital infrastructure
Frequently asked questions about NIS2/KSC in telecommunications and digital infrastructure
A brief guide to classification, ISMS, service continuity, suppliers and audit preparation.
Who does NIS2/KSC cover in digital infrastructure and telecommunications?
The scope includes electronic communications providers, IXPs, DNS service providers, TLD registries, cloud computing, data centre services, CDNs, trust services and certain managed service providers. Essential or important entity status must be determined based on the type of activity and Article 5 of the KSC Act.
Can the risk assessment be limited to office IT systems?
No. In telecommunications and digital infrastructure, the risk assessment should also cover the network and network management systems, service platforms, DNS, data centres, privileged access, dependencies on technology and maintenance suppliers, and the continuity of infrastructure operations.
Does a NIS2 fine require an incident to occur?
No. Penalties may also result from failing to meet other obligations, such as registration, risk management, incident reporting or the required audit.
We already have an ISMS and NIS2 documentation. Do we need to start over?
No. Existing materials can be migrated to the platform by your team, BCMLogic or a partner. The goal is not to recreate documentation, but to keep risks, plans, actions and evidence in a single GRC system.
Does BCMLogic Next replace a NIS2 consultant or integrator?
It does not have to. BCMLogic Next can act as the platform that maintains the results of a project delivered by an external consultant or integrator. It lets you keep working with risks, documentation, suppliers, incidents and tasks after the implementation ends.
How does BCMLogic Next support audit preparation?
The platform keeps a history of changes, approvals, reviews, tests and actions. As a result, the information needed for an audit does not have to be gathered from multiple spreadsheets, documents and systems every time.
Is digital infrastructure also subject to CER?
Some telecom and digital infrastructure companies may also be subject to critical entity resilience rules. Their status needs to be verified separately. BCMLogic Next can be used to manage requirements and evidence for multiple regulations in one environment.
How do you connect NIS2 with telecom and digital service continuity?
First, identify critical services and their dependencies: network, systems, locations, staff and suppliers. BCMLogic Next links BIA, risks and continuity plans, so a change in infrastructure or at a supplier is also reflected in plans and the risk assessment.
How should hardware, cloud and ICT service supplier risk be managed?
Start with suppliers whose failure or breach could affect the service: hardware, software and cloud vendors, data centres, maintenance providers and subcontractors with privileged access. A GRC system lets you maintain risk assessments, requirements, actions and review dates together with service dependencies.
Next step
See how a GRC system for telecommunications and digital infrastructure works
Explore the platform online or book a short demo tailored to the services, risks and requirements of your organisation.