NIS2 / KSC · healthcare

NIS2 in healthcare.
Documentation is only the beginning.


Healthcare is a sector of high criticality under the Polish KSC Act. For hospitals and other healthcare providers, this means not only new formal obligations, but also the need to put in order the risks, responsibilities and dependencies on systems, devices and suppliers that the continuity of patient care relies on.
The deadlines are already running: entities meeting the criteria on the day the amendment entered into force must register in the KSC register by 3 October 2026 and fully implement their obligations by 3 April 2027. Essential entities must also complete their first security audit.
BCMLogic Next helps you connect KSC/NIS2 requirements with day-to-day risk management, BIA, continuity plans, incidents, suppliers and the evidence you need for the audit.

What is changing
NIS2/KSC in healthcare: three issues to put in order operationally
NIS2 covers a wider group of healthcare entities and changes how cybersecurity is managed: self-assessment, management accountability and IT, OT and supplier risk become part of a single process.

Change 1
You classify yourself – and you register yourself
The entity should verify whether it meets the criteria of an essential or important entity, and then fulfil the obligations relating to the KSC register and cybersecurity contact persons.
⚠ Registration within 6 months

Change 2
Management is accountable, not the IT department
Management approves risk management measures and oversees their implementation. The security of systems supporting treatment, diagnostics and patient services becomes an issue for the whole organisation, not just the IT team.
✓ Personal liability

Change 3
The scope is the whole organisation: IT, OT and suppliers
Risk must be linked to clinical and administrative processes, HIS/PACS/LIS systems, infrastructure, medical devices, communications, and service and technology suppliers.
✓ IT + OT + supply chain
Scale of liability

A fine is one risk. An interruption in patient care is another.

EUR 10 million
or 2% of annual turnover, whichever is higher. Maximum fine for an essential entity.
300%
of remuneration – personal fine for the head of the entity.
24 h / 72 h
early warning and full notification of a significant incident. Final report – within one month.

A fine does not require an incident. Penalties may also result from failing to meet obligations relating to registration, risk management, reporting or audit. Details in the FAQ.

Map of obligations
Five areas a healthcare facility must be able to demonstrate and maintain
In practice, audits and daily operations require answers to simple questions: who is responsible, when the risk was assessed, what the plan is after an outage, when it was tested and whether corrective actions were completed.
1
Classification and registration
Assessing the facility’s status, entry in the KSC register and keeping data and contact persons up to date.
2
Risk management and security measures
Risk assessment for processes and systems supporting patient care, security measures, BIA, business continuity and regular reviews.
3
Supply chain
Assessment of medical and IT system suppliers, maintenance, cloud, communications and other services whose failure could affect the facility’s operations.
4
Incident handling
Incident classification, meeting the required reporting deadlines, documenting decisions, communication and post-incident actions.
5
Management oversight, training and audit
Management oversight, training, security audit, a corrective action plan and the ability to show its implementation history.

Timeline
Deadlines counted from the Act’s entry into force
3 Apr 2026
The KSC Act implementing NIS2 enters into force. All further deadlines are counted from this date.
3 Oct 2026
+6 months
Registration in the KSC register (S46 system) and appointment of a cybersecurity contact person. The nearest deadline for most healthcare entities.
3 Apr 2027
+12 months
Full implementation of the information security management system and statutory measures – including documentation and approval by management.
3 Apr 2028
+24 months
First security audit for essential entities – then at regular intervals. From this point on, fines become a real prospect.
ongoing
Incident reporting within 24 h / 72 h, risk reviews, plan testing, supplier assessments, management and staff training.

Legal basis: Directive (EU) 2022/2555 (NIS2) and the Polish Act of 5 July 2018 on the National Cybersecurity System (KSC), as amended. “Health” sector – Annex I (sectors of high criticality): including healthcare providers, EU reference laboratories, entities carrying out research and development of medicinal products, manufacturers of basic pharmaceutical products and preparations, and manufacturers of medical devices considered critical during a public health emergency. Specific classification depends on the type of activity and the rules in Article 5 of the KSC Act.
Sector specifics
In a hospital, system downtime quickly becomes an operational problem
In healthcare, cybersecurity is about data, system availability and continuity of care at the same time. An outage of HIS, PACS, LIS, network infrastructure or an external supplier’s service can disrupt registration, diagnostics, access to results or the work of an entire ward.
Hospitals and healthcare providers
Inpatient care providers
HIS, ward systems, medical records, building infrastructure and medical devices. System unavailability directly affects admissions, treatment and patient records.
Diagnostics and laboratories
Imaging and laboratory diagnostics
PACS, RIS, LIS and networked diagnostic equipment. An outage means delayed results and a switch to emergency procedures.
Emergency and urgent care
Emergency departments, admissions and medical transport
Care where minutes count. Continuity plans must provide for working without systems and quickly restoring access to patient data.
Clinics and outpatient care
Primary and specialist care
Registration, e-prescriptions, e-referrals and records – heavily dependent on practice management systems, connectivity and integration with e-health systems.
Pharmaceuticals and medical devices
Manufacturers of medicines and medical devices
Research and development, manufacturing of pharmaceutical substances and preparations, and critical medical devices – with production systems (OT), quality and supply chain.
Technology and service suppliers
Medical systems, maintenance and IT
Medical system vendors, integrators, equipment maintenance and cloud providers – often with remote access to the facility’s environment, hence the focus on supply chain oversight.
What this means in practice: risk assessments and continuity plans must cover IT as well as medical devices, building technical infrastructure (OT) and dependencies on suppliers and maintenance providers. More details in the FAQ.
BCMLogic Next in healthcare
A GRC system for healthcare: risk, business continuity and KSC in one place
BCMLogic Next brings together risks, BIA, policies, continuity plans, incidents, suppliers, actions and deadlines. Your facility no longer has to collect audit information from multiple spreadsheets, documents and mailboxes.

🔄
Already have documentation? We move it into the system. Starting from scratch? Wizards guide you through.
Already have an ISMS, risk assessment, BCP or procedures? They can be migrated to the system and maintained there. If some areas are still being built, wizards guide users through the next steps.
⚠️
Facility risk assessment
Risks linked to processes, systems and assets, risk owners, actions and change history.
Step-by-step wizard
📋
Policies and procedures
Templates, approval workflows, version history and audit trail.
Ready-made templates
🔄
Business continuity plans
BIA, BCP and DRP for critical services and processes, test schedules, failure scenarios and exercise history.
HIS, PACS, LIS failure scenarios
🚨
Incident management
Incident handling with 24 h / 72 h deadlines, classification and a clear course of action.
24 h / 72 h timer
🏭
Suppliers and supply chain
Register and risk assessment of system, maintenance, cloud, communications and medical technology suppliers, with review dates.
Medical and IT supplier register
✅
Audit readiness
Compliance status, approval and review history, and reports that support audit preparation.
Report for the auditor
Note for the largest entities – the CER Directive:
Some healthcare entities may also be subject to other sector-specific and resilience requirements. The scope should be assessed separately; details are in the FAQ.
Online demo
Want to see how it works in practice?
Explore BCMLogic Next with demo data or book a 30-minute meeting and walk through a healthcare facility scenario with us: risk, BIA, business continuity, incidents, suppliers and audit preparation.
🖥

Online demo environment
Ready-made demo data: risks, BIA, incidents, continuity plans, suppliers and KSC/NIS2 requirements.
📞

A short meeting with our team
30 minutes for a system walkthrough and questions about your facility and where you are in your KSC/NIS2 preparations.

Request demo access or book a 30-minute meeting →

FAQ · NIS2 and GRC in healthcare

Frequently asked questions about NIS2 and KSC in healthcare

Answers to the questions that come up most often when classifying a facility, implementing KSC/NIS2 and preparing for the audit.
Is every hospital and healthcare provider subject to KSC/NIS2?
Not automatically. Healthcare is a sector of high criticality under KSC, but classification depends on the type of activity (e.g. healthcare provider, laboratory, manufacturer of medicines or medical devices), the size of the entity and the rules in Article 5 of the KSC Act. Status should be verified individually – the NIS2 Qualifier can help.
Can a hospital risk assessment be limited to IT?
No. In healthcare, the risk assessment should also cover medical devices and technical infrastructure (OT), process dependencies, technology and maintenance suppliers, and the continuity of infrastructure operations.
Does a NIS2 fine require an incident to occur?
No. Penalties may also result from failing to meet other obligations, such as registration, risk management, incident reporting or the required audit.
We already have an ISMS and documentation. Do we need to start over?
No. Existing materials can be migrated to the platform by your team, BCMLogic or a partner. The goal is not to recreate documentation, but to keep risks, plans, actions and evidence in a single GRC system.
Does BCMLogic Next replace a consultant, auditor or IT team?
It does not have to. BCMLogic Next can act as the platform that maintains the results of a project delivered by an external consultant or integrator. It lets you keep working with risks, documentation, suppliers, incidents and tasks after the implementation ends.
How do you prepare a hospital for a KSC/NIS2 audit?
The platform keeps a history of changes, approvals, reviews, tests and actions. As a result, the information needed for an audit does not have to be gathered from multiple spreadsheets, documents and systems every time.
How do you connect cybersecurity with hospital business continuity?
The starting point is a BIA: which services are critical, which systems, devices, people and suppliers they depend on, and how long the facility can operate in emergency mode. BCMLogic Next links BIA, risks and continuity plans, so a ransomware attack or HIS outage scenario has assigned procedures, owners and a test history.
Can a healthcare entity also be subject to the CER Directive?
Some healthcare entities may also be subject to critical entity resilience rules. Their status needs to be verified separately. BCMLogic Next can be used to manage requirements and evidence for multiple regulations in one environment.
Where should a hospital start its NIS2/KSC implementation?
By confirming the entity’s status and assessing the current state. Next, assign process and risk owners, carry out or update the risk assessment and BIA, identify critical dependencies, plan actions and define how incidents and reviews will be handled.
How should medical system supplier risk be managed?
First you need to know which suppliers affect patient care and have access to key systems. In BCMLogic Next you can maintain a supplier register, risk assessments, requirements, actions, review dates and links to the processes and systems each supplier relates to.

Next step
See how a GRC system for hospitals and healthcare works
Explore the platform online or book a short demo based on processes and risks typical of a healthcare provider.