Industries · Energy, heat, water
Energy sector cybersecurity: power, heat and water utilities under NIS2
Energy, heat, gas, hydrogen and water are in Annex 1 of the Polish KSC Act, which implements NIS2. An organization that was already an essential entity on 3 April 2026 must complete its first audit by 3 April 2028. We help you build an ISMS that also covers SCADA and telemetry, and prepare evidence from your systems.
// In short
Sectors of high criticality run on control systems
Annex 1 covers mining under a license, electricity (including charging point operators), heat, oil and fuels, gas, nuclear power and hydrogen, plus drinking water supply and wastewater. Large companies in these sectors are essential entities, medium-sized ones important entities. Municipal companies can also come into scope as public entities.
As of 24 September 2026. Source: Dz.U. 2026 item 252, Article 5 and Annexes 1 and 2 (in Polish).
Which category, and which ISMS
| Situation | Result | Basis |
|---|---|---|
| License to generate, transmit, distribute or trade electricity or heat; large company | Essential entity | Article 5(1)(1), Annex 1 |
| The same, medium-sized company | Important entity | Article 5(2)(1) |
| Water and wastewater utility, large or medium-sized | Essential or important entity | Annex 1 |
| Supplying water or treating wastewater is a non-essential part of your business | Outside the water and wastewater sectors | Annex 1 |
| Municipal company performing public-utility tasks that is not an essential entity | Important entity as a public entity, if it performs a public task using information systems; ISMS under Annex 4 | Article 5(2)(8), Article 8(3) |
| Electricity company identified by the energy minister as a high-impact or critical-impact entity | Also the measures of the Network Code on Cybersecurity, Regulation (EU) 2024/1366 | Article 8b(3), Article 52a |
If a company meets the criteria for both categories, it is an essential entity (Article 5(4)). Article 41 names the competent authority for each sector. Source: Dz.U. 2026 item 252 (in Polish).
// Deadlines
Deadlines for energy and water utilities
Register
Self-registration in the KSC register
Deadline under Article 34(3) of the amending act. A company that misses it should apply right away. The authority can also enter an entity on its own initiative (Article 7j).
How to register (gov.pl, Polish) (opens in a new tab)Chapter 3
ISMS, incidents and business continuity
Chapter 3 obligations for entities that met the criteria on 3 April 2026 (Article 33(1) of the amending act), including the systems that control grids and water intakes.
Act text (Dz.U. 2026 item 252) (opens in a new tab)Audit
First audit for essential entities
For entities that were essential on 3 April 2026 (Article 33(2) of the amending act), then at least every 3 years. Former operators of essential services keep their existing 3-year cycle.
Who may audit
As of . Sources (in Polish): Dz.U. 2026 item 252, gov.pl, KSC deadlines.
// OT and evidence
Where utilities lack evidence
An auditor looks past the policy to how access to substations, pumping stations and the control room works today.
SCADA and telemetry connected to the office network
Substations, pumping stations and switchgear connect through cellular modems and VPN tunnels set up over the years by different contractors. Nobody has a complete list of entry points.
Missing evidence: a map of remote connections and firewall rules with a review date.
Remote access for integrators and service teams
A service account shared by several people at the vendor, with a password unchanged since the site was commissioned.
Missing evidence: named accounts, session approval and a session log.
An asset register that can't see field controllers
The inventory lists servers and laptops but skips PLCs, recorders and telemetry devices, with their vendor and software version.
Missing evidence: a register built from passive network monitoring, with vendor and version.
A vendor that could be declared high-risk
If the Polish minister for digital affairs declares a hardware or software vendor high-risk, you may not introduce new products covered by the decision and must withdraw existing ones within 7 years (Articles 67b and 67c). Without an asset register that records the vendor, you cannot estimate the impact.
A continuity plan never exercised
The manual operation procedure exists, but nobody has run it on a night shift.
Missing evidence: an exercise result with a date, duration and list of fixes.
// How we help
Services that fit energy and water utilities
01KSC
An ISMS that includes OT, and a pre-audit review
Gap analysis against Article 8, an obligations register with owners and a KSC pre-audit review. This is a readiness assessment, not the formal Article 15 audit.
NIS2 compliance in PolandFirst step, 5 weeks
KSC with control systems in scope
- Gap analysis against Article 8, including SCADA and telemetry
- Obligations register with owners
- Plan to prepare for the first audit
Key deliverable: one OT control implemented together with its evidence, for example remote access with a session log
02Architecture
IT and OT based on IEC 62443
Zones and conduits, remote access and PLC configuration backups. The review ends with a plan of changes, each with an owner and a date.
IEC 62443 and OT03Testing
Penetration tests of IT and customer-facing apps
Customer portals, meter reading apps, remote access and the office network. Control systems only passively or on a test copy.
Penetration testing04Continuity
A business continuity plan with an exercise
Business impact analysis, manual operation, a restore test of the dispatch systems and a result you can show the auditor.
Business continuity
// Scope
What we do, and what we don't
We agree the scope and date in writing before we start.
We do
- Classification: whether and how the act covers you, municipal companies included
- An ISMS that covers SCADA and telemetry
- KSC pre-audit review and re-checks of fixes
- An asset and supplier register with vendor and version
We don't
- Active tests on systems that control grids or water intakes
- A formal KSC audit under Article 15: an independent auditor performs it, not us
- A "KSC compliance certificate": no such document exists
We designed FutureCode Evidence Box for energy and water utilities, among other industries: it works inside your network without internet access and never runs active tests on OT.
// FAQ
Questions from utilities
We are a municipal water company. How does the act classify us?
First as a water and wastewater utility under Annex 1: a large company is an essential entity, a medium-sized one an important entity. A municipal company that is not an essential entity is also an important entity as a public entity, if it performs a public task using information systems (Article 5(2)(8)). An important entity that is a public entity builds its ISMS under Annex 4 (Article 8(3)).
When do we need our first audit?
If you were an essential entity on 3 April 2026, your first audit is due by 3 April 2028, and then at least every 3 years. An entity that becomes essential later has 24 months from meeting the criteria (Article 16). Former operators of essential services keep their existing cycle. Important entities have no periodic audit, but the authority can order one after a serious incident (Article 15(1b)). As of 24 September 2026.
What is the Network Code on Cybersecurity, and does it apply to us?
It is Delegated Regulation (EU) 2024/1366 on cybersecurity aspects of cross-border electricity flows. In Poland, the minister responsible for energy identifies high-impact and critical-impact entities (Article 52a). Only those apply its measures on top of the KSC Act (Article 8b(3)). It does not cover heat, gas or water.
Can you test our SCADA systems?
On live systems, only passively: we observe traffic, configuration and access. Active tests happen on a test copy or on spare hardware, after the rules of engagement are signed. Keeping the grid and water supply running comes before any test.
What about devices from vendors outside the EU?
For now, inventory them with vendor and version. The act provides for a procedure to declare a vendor high-risk (Article 67b). After such a decision, you may not introduce the covered products, and existing ones must be withdrawn within 7 years. The register shows what a decision would affect.
From the blog: audits and risk
Let's start with one substation or one water intake
In 30 minutes we work out your entity category, when your first audit is due and which site to start with. Before the call, you can go through the NIS2 evidence matrix.
Book a 30-minute callPrefer the scope in writing?
Tell us about your company and the sites you want to start with. We will send back the scope and date of the first step. We reply within one business day.
Request the first step