What is changing
From a formal role to full accountability for security
Until now, the role of central government administration in the KSC system was mostly limited to appointing a CSIRT contact person. The amendment brings ministries, central offices and key public institutions into the full set of obligations – with their own risk assessment, audit and personal accountability of management, just like in the private sector.
Change 1
Essential regardless of size
A public entity listed in Annex I to the KSC Act is an essential entity regardless of its size (Article 5(1)(4)(d) KSC) – this applies to public authorities, ZUS, KRUS, NFZ, NBP, BGK and research institutes.
⚠ No size threshold
Change 2
The head of the office is accountable, not just IT
Approving risk management measures, oversight and mandatory cybersecurity training are the duties of the head of the unit. The personal fine for the head of a public entity is up to 100% of monthly salary.
✓ Personal liability
Change 3
From a contact point to a full ISMS
Obligations expand from appointing a contact person to a full Information Security Management System: risk assessment, policies, incident management and audit.
✓ A full ISMS, not just a contact
Map of obligations
Five blocks of obligations – each must be backed by evidence
NIS2 is not about documents – it is about risk management measures that are appropriate, up to date and effective. Inspections and audits ask for evidence: who approved it, when it was reviewed, what the test result was and what was done with the findings.
1
Classification and registration
Confirming essential entity status (no size threshold for Annex I entities), registering in the KSC register and appointing a person responsible for contact with the competent authority.
2
Risk management and security measures
A documented risk assessment for citizen-facing systems, internal systems and public registers, policies, access control and backups isolated from the production network.
3
Personnel vetting and supply chain
Criminal record checks for staff with access to critical systems, and risk assessment of IT suppliers and integrators that operate the office’s registers and line-of-business systems.
4
Incident handling
Classifying a significant incident, early warning within 24 h, full notification within 72 h, final report within one month, reporting to CSIRT GOV or CSIRT NASK and – in the case of a personal data breach – to UODO (the Polish data protection authority).
5
Management oversight, training and audit
Approval of measures by the head of the unit, mandatory management training, staff training and the first security audit – mandatory for essential entities.
Timeline
Specific dates from the Ministry of Digital Affairs
3 Apr 2026
The amended KSC Act enters into force. All further deadlines are counted from this date.
3 Oct 2026
Entry in the KSC register for entities meeting the essential entity criteria on the date the Act entered into force.
3 Apr 2027
Implementation of statutory obligations: ISMS, incident reporting, appointing contact persons, staff criminal record checks. Connection to the S46 system.
3 Apr 2028
First mandatory security audit for essential entities. End of the two-year transition period for fines.
ongoing
Incident reporting within 24 h / 72 h, risk reviews, backup testing, supplier assessments, management and staff training.
Legal basis and source of the timeline: the Polish Act of 5 July 2018 on the National Cybersecurity System (KSC), as amended (2026 amendment – Journal of Laws 2026, item 252), and announcements of the Ministry of Digital Affairs. “Public entities – central government administration” sector – Annex I (essential, no size threshold – Article 5(1)(4)(d) KSC). It covers, among others, public authorities, public finance sector units (Article 9 of the Public Finance Act), ZUS, KRUS, NFZ, NBP, BGK, research institutes, the State Water Holding Polish Waters (PGW Wody Polskie) and the Polish Development Fund (PFR).
Sector specifics
Who exactly is covered as central government administration
“Public administration” in the KSC Act is not the same as local government (JST) – it is a separate category covering central and regional government administration: ministries, central offices, selected public institutions and entities of particular importance to public finances.
No size threshold
Public authorities and central offices
Ministries, central offices and public authorities – an essential entity regardless of headcount (PKD 84 / NACE 84).
No size threshold
ZUS, KRUS, NFZ
Key social security and health insurance institutions (Social Insurance Institution, Agricultural Social Insurance Fund, National Health Fund) – public finance sector units under Article 9 of the Public Finance Act.
No size threshold
NBP, BGK and development institutions
Narodowy Bank Polski (the central bank), Bank Gospodarstwa Krajowego (the national development bank), the Polish Development Fund and other development institutions.
Sector of high criticality
Research institutes
Research institutes operating under separate acts – covered as Annex I public entities.
Sector of high criticality
PGW Wody Polskie
State Water Holding Polish Waters – a public entity established under the Water Law Act and listed among the public entities covered by KSC.
Different category
Local government (JST)
Municipal, county and regional government offices have separate, differentiated size thresholds – a different category from central government administration (see our separate material on public utilities).
Not theory – real attacks on central government administration
The report of the Government Plenipotentiary for Cybersecurity points to a sharp rise in cyberattacks on ministries and central government bodies. Below are two confirmed incidents from recent years.
2024
Polish Space Agency
Security services detected unauthorised access to the government agency’s ICT infrastructure – the incident was confirmed by the Minister of Digital Affairs.
Source: rp.pl
2024
Public Procurement Office and KIO
A cyberattack on the IT systems of the Public Procurement Office and the National Appeals Chamber, resulting in a personal data breach – confirmed by the Minister of Digital Affairs.
Source: KICB, Ministry of Digital Affairs announcement
2023-2025
Ministries and central government bodies
Reports of the Government Plenipotentiary for Cybersecurity show a sharp rise in cyberattacks, particularly on ministries and central government bodies, mainly from Russia and Belarus.
Source: Report of the Government Plenipotentiary for Cybersecurity
Implication for the ISMS: central government systems often run nationwide registers (benefits, records, public procurement) and are targeted by espionage and sabotage attacks, not just opportunistic ransomware. The incident response plan should include cooperation with CSIRT GOV from the outset, not only CSIRT NASK.
BCMLogic Next in central government administration
BCMLogic Next – a platform where NIS2 compliance is maintained, not just described
We do not compete with the integrator running your KSC implementation project – including the “Cybersecure Government” (Cyberbezpieczny Rząd) programme. BCMLogic Next provides what a project usually does not: one place where risks, policies, incidents, suppliers and deadlines are up to date and ready to show an auditor or supervisory authority.
Already have documentation? We move it into the system. Starting from scratch? Wizards guide you through.
Existing documentation – regardless of who prepared it – can be migrated to BCMLogic Next by us, by your team or by the partner who created it. Alternatively, wizards guide you through each NIS2 obligation step by step, so you can build a complete set of documentation directly in the application.
Risk assessment of the office’s systems
The wizard guides you through identifying citizen-facing systems and public registers, threats and impacts. An auditable risk register with a history of every change.
Step-by-step wizard
Policies and procedures
A library of templates tailored to central government administration. Approval workflow for the head of the unit, version history and a full audit trail.
Ready-made templates
Backups and business continuity
A business continuity plan wizard with isolated backups of public registers and sabotage/ransomware scenarios.
Espionage attack scenarios
Incident management
A 24 h / 72 h timer in line with NIS2/KSC requirements. An incident classification wizard with parallel reporting to CSIRT GOV/NASK and UODO.
24 h / 72 h timer
IT suppliers and integrators
A register of line-of-business system suppliers and integrators with cybersecurity risk assessment and personnel vetting.
Supplier register
Audit readiness
A dashboard showing the status of NIS2 and KSC obligations. An audit readiness report generated with one click, available to the auditor and supervisory authority.
Report for the auditor
Funding support: the “Cybersecure Government” programme.
In 2025, grants worth PLN 258 million were paid to 48 central government entities and voivodeship offices to modernise their IT networks. BCMLogic Next can be implemented as part of this type of grant project – so that ISMS documentation does not end on acceptance day but stays alive throughout the period required by law.
In 2025, grants worth PLN 258 million were paid to 48 central government entities and voivodeship offices to modernise their IT networks. BCMLogic Next can be implemented as part of this type of grant project – so that ISMS documentation does not end on acceptance day but stays alive throughout the period required by law.
Online demo
Want to see how it works in practice?
The BCMLogic Next demo environment is available online. You can explore it on your own – no registration, no sales call. If you prefer personal contact, book a short meeting and we will show you the platform live in a central government context.
🖥
Online demo environment
Ready-made demo data – risk assessment, incidents, continuity plans, NIS2 compliance dashboard. Available immediately, no installation.
📞
A short meeting with our team
30 minutes – we show the platform live and answer questions specific to your office and where you are in your NIS2 preparations.
FAQ · NIS2 and KSC in public administration
Frequently asked questions about NIS2 and KSC in public administration
Classifying your office, deadlines, accountability of the head of the unit, ISMS, incident reporting and audit preparation.
Is a ministry or central office subject to NIS2 and the Polish KSC Act?
Yes. Public entities listed in Annex I to the KSC Act – including public authorities, central offices, ZUS, KRUS, NFZ, NBP, BGK and research institutes – are essential entities regardless of size (Article 5(1)(4)(d) KSC). This means the full set of obligations: entry in the KSC register, an ISMS, incident reporting and a mandatory audit.
Are municipalities, counties and regional offices in the same category as central government?
No. Local government units have separate classification rules and differentiated thresholds under KSC. Their status must be determined separately – the NIS2 Qualifier can help.
By when must a public office register in the KSC register and implement an ISMS?
The amendment has applied since 3 April 2026. Entities meeting the criteria on the date it entered into force must register in the KSC register by 3 October 2026 and implement their obligations, including the ISMS, by 3 April 2027. The first security audit of an essential entity is due by 3 April 2028.
What are the obligations and liability of the head of the unit?
The head of the unit approves risk management measures, oversees their implementation and completes mandatory cybersecurity training. Failure to meet these obligations can result in a personal fine of up to 100% of monthly salary. That is why a clear picture of the ISMS is needed – who approved what, when and with what result.
How do KSC requirements relate to the National Interoperability Framework (KRI)?
The KRI regulation has for years required entities performing public tasks to maintain an information security management system. KSC adds, among other things, incident reporting, supply chain oversight, personnel vetting and a mandatory audit. The most sensible approach is to maintain one ISMS that meets the requirements of both regulations, rather than two parallel sets of documents.
Should a public office report incidents to CSIRT GOV or CSIRT NASK?
Central government administration generally works with CSIRT GOV, but it is worth confirming the competent team for your unit in advance. The deadlines are 24 h for the early warning, 72 h for the full notification and one month for the final report. If the incident involves personal data, a parallel 72 h deadline applies for notifying UODO.
Does a NIS2 fine require an incident to occur?
No. Penalties may also result from failing to meet other obligations, such as registration, risk management, incident reporting or the required audit.
What is a GRC system and why are documents and spreadsheets not enough for a public office?
A GRC (governance, risk and compliance) system is software in which risks, policies, continuity plans, incidents, suppliers and tasks are linked together and have owners and deadlines. Documents and spreadsheets quickly go out of date and have to be gathered manually before an audit. In BCMLogic Next, the history of approvals, reviews and tests is recorded as you go.
We have documentation from an implementation project or the “Cybersecure Government” programme. Do we need to start over?
No. Existing materials can be migrated to BCMLogic Next by your team, BCMLogic or the integrator who prepared them. The goal is not to recreate documentation, but to keep it up to date after the project ends.
How do you prepare a public office for its first KSC audit?
Start by compiling the evidence: an up-to-date risk assessment for citizen-facing systems and registers, policies approved by the head of the unit, continuity plans with backup test history, a supplier and integrator register, an incident register and training records. BCMLogic Next lets you keep this information up to date and generate an audit readiness report.
Can BCMLogic Next be funded by a grant or bought through public procurement?
Yes. Implementation can be part of a project financed by grant programmes such as “Cybersecure Government”, and the purchase follows the rules of the Polish Public Procurement Law. We are happy to help prepare the information needed for the tender specification.
Next step
See how BCMLogic Next keeps you NIS2-compliant every day
The BCMLogic Next demo environment is available online – you can explore it on your own, with no registration and no sales call. Or book a short meeting and we will show you the platform live in a central government context.