Industries · Energy, heat, water

Energy sector cybersecurity: power, heat and water utilities under NIS2

Energy, heat, gas, hydrogen and water are in Annex 1 of the Polish KSC Act, which implements NIS2. An organization that was already an essential entity on 3 April 2026 must complete its first audit by 3 April 2028. We help you build an ISMS that also covers SCADA and telemetry, and prepare evidence from your systems.

// In short

Sectors of high criticality run on control systems

Annex 1 covers mining under a license, electricity (including charging point operators), heat, oil and fuels, gas, nuclear power and hydrogen, plus drinking water supply and wastewater. Large companies in these sectors are essential entities, medium-sized ones important entities. Municipal companies can also come into scope as public entities.

As of 24 September 2026. Source: Dz.U. 2026 item 252, Article 5 and Annexes 1 and 2 (in Polish).

Which category, and which ISMS

Energy, heat and water under the KSC Act, as of 24 September 2026
SituationResultBasis
License to generate, transmit, distribute or trade electricity or heat; large companyEssential entityArticle 5(1)(1), Annex 1
The same, medium-sized companyImportant entityArticle 5(2)(1)
Water and wastewater utility, large or medium-sizedEssential or important entityAnnex 1
Supplying water or treating wastewater is a non-essential part of your businessOutside the water and wastewater sectorsAnnex 1
Municipal company performing public-utility tasks that is not an essential entityImportant entity as a public entity, if it performs a public task using information systems; ISMS under Annex 4Article 5(2)(8), Article 8(3)
Electricity company identified by the energy minister as a high-impact or critical-impact entityAlso the measures of the Network Code on Cybersecurity, Regulation (EU) 2024/1366Article 8b(3), Article 52a

If a company meets the criteria for both categories, it is an essential entity (Article 5(4)). Article 41 names the competent authority for each sector. Source: Dz.U. 2026 item 252 (in Polish).

// Deadlines

Deadlines for energy and water utilities

  1. Register

    Self-registration in the KSC register

    Deadline under Article 34(3) of the amending act. A company that misses it should apply right away. The authority can also enter an entity on its own initiative (Article 7j).

    How to register (gov.pl, Polish) (opens in a new tab)
  2. Chapter 3

    ISMS, incidents and business continuity

    Chapter 3 obligations for entities that met the criteria on 3 April 2026 (Article 33(1) of the amending act), including the systems that control grids and water intakes.

    Act text (Dz.U. 2026 item 252) (opens in a new tab)
  3. Audit

    First audit for essential entities

    For entities that were essential on 3 April 2026 (Article 33(2) of the amending act), then at least every 3 years. Former operators of essential services keep their existing 3-year cycle.

    Who may audit

As of . Sources (in Polish): Dz.U. 2026 item 252, gov.pl, KSC deadlines.

// OT and evidence

Where utilities lack evidence

An auditor looks past the policy to how access to substations, pumping stations and the control room works today.

  • SCADA and telemetry connected to the office network

    Substations, pumping stations and switchgear connect through cellular modems and VPN tunnels set up over the years by different contractors. Nobody has a complete list of entry points.

    Missing evidence: a map of remote connections and firewall rules with a review date.

  • Remote access for integrators and service teams

    A service account shared by several people at the vendor, with a password unchanged since the site was commissioned.

    Missing evidence: named accounts, session approval and a session log.

  • An asset register that can't see field controllers

    The inventory lists servers and laptops but skips PLCs, recorders and telemetry devices, with their vendor and software version.

    Missing evidence: a register built from passive network monitoring, with vendor and version.

  • A vendor that could be declared high-risk

    If the Polish minister for digital affairs declares a hardware or software vendor high-risk, you may not introduce new products covered by the decision and must withdraw existing ones within 7 years (Articles 67b and 67c). Without an asset register that records the vendor, you cannot estimate the impact.

  • A continuity plan never exercised

    The manual operation procedure exists, but nobody has run it on a night shift.

    Missing evidence: an exercise result with a date, duration and list of fixes.

// How we help

Services that fit energy and water utilities

  1. 01KSC

    An ISMS that includes OT, and a pre-audit review

    Gap analysis against Article 8, an obligations register with owners and a KSC pre-audit review. This is a readiness assessment, not the formal Article 15 audit.

    First step, 5 weeks

    KSC with control systems in scope

    • Gap analysis against Article 8, including SCADA and telemetry
    • Obligations register with owners
    • Plan to prepare for the first audit

    Key deliverable: one OT control implemented together with its evidence, for example remote access with a session log

    NIS2 compliance in Poland
  2. 02Architecture

    IT and OT based on IEC 62443

    Zones and conduits, remote access and PLC configuration backups. The review ends with a plan of changes, each with an owner and a date.

    IEC 62443 and OT
  3. 03Testing

    Penetration tests of IT and customer-facing apps

    Customer portals, meter reading apps, remote access and the office network. Control systems only passively or on a test copy.

    Penetration testing
  4. 04Continuity

    A business continuity plan with an exercise

    Business impact analysis, manual operation, a restore test of the dispatch systems and a result you can show the auditor.

    Business continuity

// Scope

What we do, and what we don't

We agree the scope and date in writing before we start.

We do

  • Classification: whether and how the act covers you, municipal companies included
  • An ISMS that covers SCADA and telemetry
  • KSC pre-audit review and re-checks of fixes
  • An asset and supplier register with vendor and version

We don't

  • Active tests on systems that control grids or water intakes
  • A formal KSC audit under Article 15: an independent auditor performs it, not us
  • A "KSC compliance certificate": no such document exists

We designed FutureCode Evidence Box for energy and water utilities, among other industries: it works inside your network without internet access and never runs active tests on OT.

// FAQ

Questions from utilities

We are a municipal water company. How does the act classify us?

First as a water and wastewater utility under Annex 1: a large company is an essential entity, a medium-sized one an important entity. A municipal company that is not an essential entity is also an important entity as a public entity, if it performs a public task using information systems (Article 5(2)(8)). An important entity that is a public entity builds its ISMS under Annex 4 (Article 8(3)).

When do we need our first audit?

If you were an essential entity on 3 April 2026, your first audit is due by 3 April 2028, and then at least every 3 years. An entity that becomes essential later has 24 months from meeting the criteria (Article 16). Former operators of essential services keep their existing cycle. Important entities have no periodic audit, but the authority can order one after a serious incident (Article 15(1b)). As of 24 September 2026.

What is the Network Code on Cybersecurity, and does it apply to us?

It is Delegated Regulation (EU) 2024/1366 on cybersecurity aspects of cross-border electricity flows. In Poland, the minister responsible for energy identifies high-impact and critical-impact entities (Article 52a). Only those apply its measures on top of the KSC Act (Article 8b(3)). It does not cover heat, gas or water.

Can you test our SCADA systems?

On live systems, only passively: we observe traffic, configuration and access. Active tests happen on a test copy or on spare hardware, after the rules of engagement are signed. Keeping the grid and water supply running comes before any test.

What about devices from vendors outside the EU?

For now, inventory them with vendor and version. The act provides for a procedure to declare a vendor high-risk (Article 67b). After such a decision, you may not introduce the covered products, and existing ones must be withdrawn within 7 years. The register shows what a decision would affect.

From the blog: audits and risk

Let's start with one substation or one water intake

In 30 minutes we work out your entity category, when your first audit is due and which site to start with. Before the call, you can go through the NIS2 evidence matrix.

Book a 30-minute call

Prefer the scope in writing?

Tell us about your company and the sites you want to start with. We will send back the scope and date of the first step. We reply within one business day.

Request the first step