Blog

NIS2 2026 – Who Does the New Law Apply To and What Obligations Does It Impose?

NIS 2

Poland’s amended National Cybersecurity System Act (KSC), which implements the EU’s NIS2 directive, took effect on 3 April 2026. Organizations covered by the law fall into two categories – essential entities and important entities – determined jointly by sector and company size. Covered organizations have 6 months to register, 12 months to implement the required obligations, and 24 months for their first security audit, with fines reaching EUR 10 million for essential entities and EUR 7 million for important entities.

In this article we explain exactly what the amendment changed, how to determine whether your organization is covered, what obligations it imposes, and how to prepare for implementation step by step.

Legal status at time of publication: the amendment was signed by the President of Poland on 19 February 2026 and simultaneously referred to the Constitutional Tribunal for subsequent review. Subsequent review does not suspend the act’s validity – until any ruling by the Tribunal, the provisions remain fully in force. It’s worth checking the status of these proceedings regularly, since a ruling could change the scope or wording of some provisions.

What Did the 2026 KSC Amendment Change?

The amendment of 23 January 2026 (Journal of Laws 2026, item 252) is the deepest change to the KSC act since it was first passed in 2018. Rather than a cosmetic update, it changes the logic of the entire system:

  • it replaces the previous split between operators of essential services (OES) and digital service providers (DSP) with two new categories – essential entities and important entities,
  • it significantly expands the list of sectors covered by the regulation (including waste management, manufacturing, the food industry, postal services, local government units, space, and research),
  • it replaces an administrative decision with self-identification – the organization itself determines its status based on sector and size, then registers in a central register (the S46 system),
  • it massively raises the maximum fines – from the previous PLN 200,000 to EUR 10 million (essential entities) or EUR 7 million (important entities),
  • it introduces personal liability for the head of the entity for negligence in cybersecurity,
  • it imposes a new, clearly formalized obligation to manage supply chain risk.

How Does KSC Relate to the NIS2 Directive?

KSC is the Polish act through which the EU’s NIS2 directive (Directive (EU) 2022/2555 of the European Parliament and of the Council) is transposed into national law. In other words: NIS2 sets a common EU-wide framework for network and information system security, while the specific obligations for Polish businesses and institutions come from the national KSC act that implements it.

The previous 2018 version of KSC implemented the earlier NIS directive (2016). The 2026 amendment brings Polish law in line with the considerably more demanding NIS2 – hence the broader sectoral scope, new entity categories, and higher fines. It’s a similar transposition mechanism to the one the DORA regulation plays in the financial sector – a different regulation, the same goal: forcing a systematic approach to digital risk management.

Who Does the New Law Apply To?

Whether an organization is covered depends jointly on two criteria: its sector of activity and its company size (as defined in Commission Regulation (EU) No 651/2014).

Sector Category Example entities
Energy Essential Power plants, grid operators, gas/fuel/heat distributors
Transport Essential Airlines, rail, ports, large road carriers
Banking and financial market infrastructure Essential Banks, credit unions, central securities depositories, exchanges, clearing houses
Healthcare Essential Hospitals, laboratories, manufacturers of critical medical devices
Drinking water and wastewater Essential Water utilities, wastewater treatment plants, distributors
Digital infrastructure Essential DNS providers, data centers, cloud providers, CDNs
ICT service management (B2B) Essential MSPs, MSSPs, systems integrators, IT outsourcing
Public administration Essential Central government offices and designated local government units
Postal and courier services Important Postal operators, courier companies
Waste management Important Landfills, sorting facilities, incineration plants
Manufacturing (chemicals, food, electronics, machinery, vehicles) Important Medium and large manufacturers
Digital service providers Important Marketplaces, search engines, social networking platforms

Regardless of company size, an organization is always treated as an essential entity if it is, among others: a DNS service provider, a qualified trust service provider, an entity recognized as critical under Directive (EU) 2022/2557, a top-level domain (TLD) registry, or a designated public entity.

What Is the Difference Between an Essential Entity and an Important Entity?

Criterion Essential entity Important entity
Basis for classification Annex 1 to the KSC act Annex 2 to the KSC act
Typical size Large enterprise (250+ employees or turnover > EUR 50 million) Medium enterprise (50-249 employees or turnover EUR 10-50 million)
Type of oversight Proactive – regular ex-officio inspections Reactive – inspection after an incident or a signal
Security audit Mandatory, cyclical Optional – only on the regulator’s request
Maximum fine EUR 10 million or 2% of turnover (min. PLN 20,000) EUR 7 million or 1.4% of turnover (min. PLN 15,000)
Possible suspension of activity Yes No

If an entity meets the criteria for both categories at the same time, the act assigns it essential entity status.

How to Check If Your Company Is Covered by KSC

Before going through the steps below, you can use the free NIS2/KSC self-assessment tool, which gives a preliminary status indication in a few questions. A full, documented self-identification is still best carried out in four steps:

  1. Sector – does the company’s activity fall under Annex 1 or Annex 2 to the act? If not, the company generally isn’t covered based on the general sectoral criteria.
  2. Size – is the company at least a medium-sized enterprise as defined in Regulation (EU) No 651/2014 (50+ employees or turnover above EUR 10 million)? Micro and small companies are mostly outside the scope of the act, except for entities treated as essential regardless of size.
  3. Size-independent exceptions – does the company provide services from the list of always-essential entities (DNS, qualified trust services, critical infrastructure)?
  4. Classification decision – based on points 1-3, the organization (typically the board) formally decides whether it is an essential entity, an important entity, or not covered by the act, and documents that decision.

BCMLogic expert commentary: in practice, the biggest source of confusion isn’t the sector itself, but correctly calculating the size thresholds within corporate groups and assessing whether a given service actually matches the description in the annex. It’s worth documenting this analysis – in the event of an inspection, the organization must be able to show the basis on which it concluded it was (or wasn’t) covered by the act.

What Obligations Do Entities Covered by KSC Have?

The catalog of obligations is largely shared between both categories – the main difference lies in the intensity of oversight and the level of fines. The key obligations include:

  • Registration in the register of essential and important entities (the S46 system) – within 6 months of meeting the criteria,
  • Implementing an information security management system (ISMS) that includes systematic risk assessment,
  • Appointing contact persons – at least two, responsible for liaison with the competent authorities,
  • Reporting incidents within strict deadlines: early warning within 24h, notification of a significant incident within 72h, final report within 1 month,
  • Annual cybersecurity training for the head of the entity,
  • Background checks for personnel carrying out security-related tasks,
  • Security audit – mandatory and cyclical for essential entities, on the regulator’s request for important entities,
  • Supply chain risk management (see below).

What Role Does Risk Management Play?

Risk management is the foundation the entire KSC obligation framework rests on – it isn’t a one-off task, but an ongoing process. The act requires systematic risk assessment as part of the information security management system, and failing to carry it out properly is itself grounds for a fine.

In practice, this means maintaining a cybersecurity risk register, regularly updating risk assessments as context changes (new threats, infrastructure changes, new vendors), and linking those assessments to concrete remediation measures – not just documentation produced for audit purposes.

How Does KSC Address Vendor and Supply Chain Risk?

This is one of the most significant new elements compared to the previous version of the act (which implemented the earlier NIS1). The amendment introduces a mandatory obligation to manage supply chain risk, including:

  • assessing risk associated with relationships with vendors and service providers, including ICT service providers,
  • particular attention to high-risk suppliers,
  • including cybersecurity requirements in contracts with vendors,
  • assessing the overall quality of vendors’ cybersecurity practices, including the security of their own development and production processes.

In practice, this means an entity covered by the act can’t limit itself to securing its own infrastructure – it must also have a documented process for assessing and monitoring vendor risk, especially for vendors critical to business continuity. This is similar in nature to third-party risk management (TPRM), a discipline familiar from the broader GRC framework.

How to Prepare Your Organization to Meet the Requirements

Practical preparation for KSC is best broken down into stages aligned with the statutory timeline:

  1. Self-identification – a formal board decision on the organization’s status (essential / important / not covered), documented with an analysis of sector and size thresholds.
  2. Assigning responsibility – the head of the entity (typically the entire board, as defined by the act), a person delegated to handle cybersecurity, and at least two contact persons.
  3. Registration – submitting a registration application in the S46 system within 6 months of meeting the criteria.
  4. Building or updating the ISMS – including a risk register, security policies, and incident reporting procedures, with a 12-month deadline.
  5. Addressing vendor risk – inventorying critical vendors, assessing risk, and updating contracts with security clauses.
  6. Preparing for the audit – gathering documentation and evidence of compliance before the 24-month deadline for the first security audit.

KSC and NIS2 at a glance – the 5 most important obligations

  1. Registration in the register of essential and important entities (within 6 months)
  2. Implementing an information security management system with risk assessment
  3. Reporting incidents within 24h / 72h / 1 month deadlines
  4. Managing supply chain risk and assessing high-risk suppliers
  5. Annual cybersecurity training for the head of the entity
Obligation What it covers Who is responsible Example actions
Registration Registering as an essential or important entity in the S46 system Board / head of the entity Submitting the registration application within 6 months of meeting the criteria
ISMS and risk assessment Information security management system with cyclical risk assessment Person delegated to cybersecurity Maintaining and updating the cybersecurity risk register
Incident reporting Notifying the CSIRT of incidents within statutory deadlines Contact persons (min. 2) Submitting an early warning within 24h of detecting an incident
Vendor risk Assessing and monitoring supply chain risk Procurement / security function, with the board Inventorying critical vendors and adding security clauses to contracts
Security audit Verifying compliance with the act’s requirements Internal audit / independent auditor Completing the first audit before the 24-month deadline

Common Mistakes When Implementing KSC

  • Delaying self-identification – putting off the status decision until an inspection, instead of proactively determining it in the first weeks after the act took effect.
  • Treating the ISMS as a one-off document – instead of a living process with regular risk updates.
  • Ignoring vendor risk – focusing solely on your own infrastructure while neglecting the assessment of critical vendors.
  • No clearly assigned ownership – failing to appoint a person delegated to cybersecurity or the contact persons required by the act.
  • Underestimating personal liability – treating KSC as “an IT department issue,” when the act explicitly holds the head of the entity accountable.

FAQ

Does KSC apply to small businesses?

In most cases, no – the act generally covers medium and large enterprises. The exception is entities always treated as essential regardless of size, such as DNS service providers or qualified trust service providers.

When did the amended KSC act take effect?

The amendment took effect on 3 April 2026. Covered entities have 6 months to register, 12 months to implement the obligations under Chapter 3 of the act, and 24 months to complete their first security audit.

What is the difference between an essential entity and an important entity?

An essential entity is typically a large organization in a highest-criticality sector (Annex 1), subject to proactive oversight and higher fines. An important entity is typically a medium-sized enterprise in an important sector (Annex 2), or in an essential sector without meeting the large-enterprise threshold, subject to reactive oversight.

What fines apply for non-compliance with KSC?

Essential entities face fines of up to EUR 10 million or 2% of annual turnover; important entities up to EUR 7 million or 1.4% of turnover. For violations that endanger state security, an extraordinary fine of up to PLN 100 million is possible, and the head of the entity is personally liable.

Can KSC implementation be managed without a dedicated system?

At an early stage, yes. As the number of vendors, risks and required audit documentation grows, however, managing this purely in spreadsheets becomes hard to maintain and hard to demonstrate quickly in the event of an inspection.

Could the Constitutional Tribunal strike down the KSC provisions?

In theory, yes – until the Tribunal rules, the act remains fully in force under the presumption of constitutionality. It’s worth monitoring the status of these proceedings, since a ruling could change the scope or wording of some provisions.

Summary

The KSC amendment implementing NIS2 isn’t a cosmetic change – it’s a new logic for Poland’s cybersecurity system, with a broader scope of covered entities, mandatory self-identification, and fines many times higher than before. The most important practical first step is a fast, well-documented classification decision – it determines the entire implementation timeline and how much time is realistically left to prepare.

See What This Could Look Like for Your Organization

If your organization is still determining its status under KSC, or looking for a way to bring vendor risk, the risk register and compliance documentation together in one place, it’s worth seeing what this looks like on a GRC platform. BCMLogic Solutions helps financial and technology companies manage operational risk, business continuity and regulatory compliance – in line with ISO 22301, ISO 27001 and requirements such as DORA and NIS2/KSC.

Book a Demo →