Poland’s amended National Cybersecurity System Act (KSC), which implements the EU’s NIS2 directive, took effect on 3 April 2026. Organizations covered by the law fall into two categories – essential entities and important entities – determined jointly by sector and company size. Covered organizations have 6 months to register, 12 months to implement the required obligations, and 24 months for their first security audit, with fines reaching EUR 10 million for essential entities and EUR 7 million for important entities.
In this article we explain exactly what the amendment changed, how to determine whether your organization is covered, what obligations it imposes, and how to prepare for implementation step by step.
What Did the 2026 KSC Amendment Change?
The amendment of 23 January 2026 (Journal of Laws 2026, item 252) is the deepest change to the KSC act since it was first passed in 2018. Rather than a cosmetic update, it changes the logic of the entire system:
- it replaces the previous split between operators of essential services (OES) and digital service providers (DSP) with two new categories – essential entities and important entities,
- it significantly expands the list of sectors covered by the regulation (including waste management, manufacturing, the food industry, postal services, local government units, space, and research),
- it replaces an administrative decision with self-identification – the organization itself determines its status based on sector and size, then registers in a central register (the S46 system),
- it massively raises the maximum fines – from the previous PLN 200,000 to EUR 10 million (essential entities) or EUR 7 million (important entities),
- it introduces personal liability for the head of the entity for negligence in cybersecurity,
- it imposes a new, clearly formalized obligation to manage supply chain risk.
How Does KSC Relate to the NIS2 Directive?
KSC is the Polish act through which the EU’s NIS2 directive (Directive (EU) 2022/2555 of the European Parliament and of the Council) is transposed into national law. In other words: NIS2 sets a common EU-wide framework for network and information system security, while the specific obligations for Polish businesses and institutions come from the national KSC act that implements it.
The previous 2018 version of KSC implemented the earlier NIS directive (2016). The 2026 amendment brings Polish law in line with the considerably more demanding NIS2 – hence the broader sectoral scope, new entity categories, and higher fines. It’s a similar transposition mechanism to the one the DORA regulation plays in the financial sector – a different regulation, the same goal: forcing a systematic approach to digital risk management.
Who Does the New Law Apply To?
Whether an organization is covered depends jointly on two criteria: its sector of activity and its company size (as defined in Commission Regulation (EU) No 651/2014).
Regardless of company size, an organization is always treated as an essential entity if it is, among others: a DNS service provider, a qualified trust service provider, an entity recognized as critical under Directive (EU) 2022/2557, a top-level domain (TLD) registry, or a designated public entity.
What Is the Difference Between an Essential Entity and an Important Entity?
If an entity meets the criteria for both categories at the same time, the act assigns it essential entity status.
How to Check If Your Company Is Covered by KSC
Before going through the steps below, you can use the free NIS2/KSC self-assessment tool, which gives a preliminary status indication in a few questions. A full, documented self-identification is still best carried out in four steps:
- Sector – does the company’s activity fall under Annex 1 or Annex 2 to the act? If not, the company generally isn’t covered based on the general sectoral criteria.
- Size – is the company at least a medium-sized enterprise as defined in Regulation (EU) No 651/2014 (50+ employees or turnover above EUR 10 million)? Micro and small companies are mostly outside the scope of the act, except for entities treated as essential regardless of size.
- Size-independent exceptions – does the company provide services from the list of always-essential entities (DNS, qualified trust services, critical infrastructure)?
- Classification decision – based on points 1-3, the organization (typically the board) formally decides whether it is an essential entity, an important entity, or not covered by the act, and documents that decision.
BCMLogic expert commentary: in practice, the biggest source of confusion isn’t the sector itself, but correctly calculating the size thresholds within corporate groups and assessing whether a given service actually matches the description in the annex. It’s worth documenting this analysis – in the event of an inspection, the organization must be able to show the basis on which it concluded it was (or wasn’t) covered by the act.
What Obligations Do Entities Covered by KSC Have?
The catalog of obligations is largely shared between both categories – the main difference lies in the intensity of oversight and the level of fines. The key obligations include:
- Registration in the register of essential and important entities (the S46 system) – within 6 months of meeting the criteria,
- Implementing an information security management system (ISMS) that includes systematic risk assessment,
- Appointing contact persons – at least two, responsible for liaison with the competent authorities,
- Reporting incidents within strict deadlines: early warning within 24h, notification of a significant incident within 72h, final report within 1 month,
- Annual cybersecurity training for the head of the entity,
- Background checks for personnel carrying out security-related tasks,
- Security audit – mandatory and cyclical for essential entities, on the regulator’s request for important entities,
- Supply chain risk management (see below).
What Role Does Risk Management Play?
Risk management is the foundation the entire KSC obligation framework rests on – it isn’t a one-off task, but an ongoing process. The act requires systematic risk assessment as part of the information security management system, and failing to carry it out properly is itself grounds for a fine.
In practice, this means maintaining a cybersecurity risk register, regularly updating risk assessments as context changes (new threats, infrastructure changes, new vendors), and linking those assessments to concrete remediation measures – not just documentation produced for audit purposes.
How Does KSC Address Vendor and Supply Chain Risk?
This is one of the most significant new elements compared to the previous version of the act (which implemented the earlier NIS1). The amendment introduces a mandatory obligation to manage supply chain risk, including:
- assessing risk associated with relationships with vendors and service providers, including ICT service providers,
- particular attention to high-risk suppliers,
- including cybersecurity requirements in contracts with vendors,
- assessing the overall quality of vendors’ cybersecurity practices, including the security of their own development and production processes.
In practice, this means an entity covered by the act can’t limit itself to securing its own infrastructure – it must also have a documented process for assessing and monitoring vendor risk, especially for vendors critical to business continuity. This is similar in nature to third-party risk management (TPRM), a discipline familiar from the broader GRC framework.
How to Prepare Your Organization to Meet the Requirements
Practical preparation for KSC is best broken down into stages aligned with the statutory timeline:
- Self-identification – a formal board decision on the organization’s status (essential / important / not covered), documented with an analysis of sector and size thresholds.
- Assigning responsibility – the head of the entity (typically the entire board, as defined by the act), a person delegated to handle cybersecurity, and at least two contact persons.
- Registration – submitting a registration application in the S46 system within 6 months of meeting the criteria.
- Building or updating the ISMS – including a risk register, security policies, and incident reporting procedures, with a 12-month deadline.
- Addressing vendor risk – inventorying critical vendors, assessing risk, and updating contracts with security clauses.
- Preparing for the audit – gathering documentation and evidence of compliance before the 24-month deadline for the first security audit.
KSC and NIS2 at a glance – the 5 most important obligations
- Registration in the register of essential and important entities (within 6 months)
- Implementing an information security management system with risk assessment
- Reporting incidents within 24h / 72h / 1 month deadlines
- Managing supply chain risk and assessing high-risk suppliers
- Annual cybersecurity training for the head of the entity
Common Mistakes When Implementing KSC
- Delaying self-identification – putting off the status decision until an inspection, instead of proactively determining it in the first weeks after the act took effect.
- Treating the ISMS as a one-off document – instead of a living process with regular risk updates.
- Ignoring vendor risk – focusing solely on your own infrastructure while neglecting the assessment of critical vendors.
- No clearly assigned ownership – failing to appoint a person delegated to cybersecurity or the contact persons required by the act.
- Underestimating personal liability – treating KSC as “an IT department issue,” when the act explicitly holds the head of the entity accountable.
FAQ
Does KSC apply to small businesses?
In most cases, no – the act generally covers medium and large enterprises. The exception is entities always treated as essential regardless of size, such as DNS service providers or qualified trust service providers.
When did the amended KSC act take effect?
The amendment took effect on 3 April 2026. Covered entities have 6 months to register, 12 months to implement the obligations under Chapter 3 of the act, and 24 months to complete their first security audit.
What is the difference between an essential entity and an important entity?
An essential entity is typically a large organization in a highest-criticality sector (Annex 1), subject to proactive oversight and higher fines. An important entity is typically a medium-sized enterprise in an important sector (Annex 2), or in an essential sector without meeting the large-enterprise threshold, subject to reactive oversight.
What fines apply for non-compliance with KSC?
Essential entities face fines of up to EUR 10 million or 2% of annual turnover; important entities up to EUR 7 million or 1.4% of turnover. For violations that endanger state security, an extraordinary fine of up to PLN 100 million is possible, and the head of the entity is personally liable.
Can KSC implementation be managed without a dedicated system?
At an early stage, yes. As the number of vendors, risks and required audit documentation grows, however, managing this purely in spreadsheets becomes hard to maintain and hard to demonstrate quickly in the event of an inspection.
Could the Constitutional Tribunal strike down the KSC provisions?
In theory, yes – until the Tribunal rules, the act remains fully in force under the presumption of constitutionality. It’s worth monitoring the status of these proceedings, since a ruling could change the scope or wording of some provisions.
Summary
The KSC amendment implementing NIS2 isn’t a cosmetic change – it’s a new logic for Poland’s cybersecurity system, with a broader scope of covered entities, mandatory self-identification, and fines many times higher than before. The most important practical first step is a fast, well-documented classification decision – it determines the entire implementation timeline and how much time is realistically left to prepare.
See What This Could Look Like for Your Organization
If your organization is still determining its status under KSC, or looking for a way to bring vendor risk, the risk register and compliance documentation together in one place, it’s worth seeing what this looks like on a GRC platform. BCMLogic Solutions helps financial and technology companies manage operational risk, business continuity and regulatory compliance – in line with ISO 22301, ISO 27001 and requirements such as DORA and NIS2/KSC.

