Industries · Telecommunications

NIS2 for tele­communi­cations: KSC, UKE and high-risk vendors

In Poland, network and service security moves from the old Telecommunications Law to the KSC Act, at the latest on 3 April 2027, when the KSC Chapter 3 obligations apply. An operator that is at least medium-sized is an essential entity, a smaller one an important entity. We help you prepare the ISMS, the network and vendor inventory, and the evidence for the regulator, the President of UKE.

// In short

Telecoms under the KSC Act: no size threshold

The act covers electronic communications undertakings as defined in the Polish Electronic Communications Law: telecom undertakings and providers of publicly available number-independent interpersonal communications services. Medium and large ones are essential entities, micro and small ones important entities. The act applies if they provide services in Poland. The competent authority is the President of UKE.

As of 24 September 2026. Sources (in Polish): Dz.U. 2026 item 252 (Articles 5, 5a, 41), Electronic Communications Law, Article 2(39).

What the KSC Act changes for operators

  1. From the Telecommunications Law to the KSC Act

    Article 8 of the KSC Act replaces Chapter VIIa of the old Telecommunications Law. Operators that performed its obligations keep applying them until they start the Chapter 3 obligations, at the latest on 3 April 2027 (Article 33(5) of the amending act).

  2. Every operator is in scope

    An electronic communications undertaking that is at least medium-sized is an essential entity (Article 5(1)(2)); a micro or small one is an important entity (Article 5(2)(4)). A small internet service provider also has Chapter 3 obligations.

  3. Supervision by the President of UKE

    For the electronic communications subsector, the competent cybersecurity authority is the President of UKE, the Office of Electronic Communications (Article 41(8a)).

  4. ISMS, incidents and the first audit

    ISMS and Article 8 measures from 3 April 2027. Reporting a serious incident: early warning within 24 hours, notification within 72 hours, final report within one month. An entity that was essential on 3 April 2026 completes its first audit by 3 April 2028.

  5. Management is personally accountable

    The head of the entity and the person to whom cybersecurity duties are delegated take training once every calendar year (Article 8e). Staff doing Article 8 and 11 work provide a certificate from the Polish National Criminal Register, KRK (Article 8f).

High-risk vendors

The Polish minister for digital affairs can declare a hardware or software vendor high-risk by decision (Article 67b). The procedure covers vendors of operators whose telecom revenue exceeded PLN 10 million in the previous financial year. After a decision, the covered products may not be introduced, and operators withdraw those that perform the critical functions in Annex 3 within 4 years (Article 67c).

// Annex 3

Critical functions: start with an inventory

Annex 3 of the act lists 10 categories of critical functions and maps them to 3GPP network functions:

  • device authentication and access rights (AMF, AUSF) and subscriber cryptographic data (UDM)
  • connectivity with devices and radio resources (base stations, radio units, antennas)
  • traffic routing (UPF), sessions (SMF), access policies (PCF) and network slice selection (NSSF)
  • network service registration (NRF), protection against external applications (NEF) and interconnection with other networks (SEPP)

Without a list of the network elements that perform these functions, with vendor and version, you cannot estimate what a high-risk vendor decision would cost you.

As of 24 September 2026. Source: Dz.U. 2026 item 252, Annex 3, Articles 67b and 67c (in Polish).

// Risks

Where operators lack evidence

The regulator and the auditor will ask the same questions: who has access to network elements, where they come from and how fast you recover after an outage.

  • Privileged access to network elements

    Shared accounts in the network operations center, vendor service accounts, jump hosts without session recording.

    Missing evidence: named accounts, MFA and a log of every administrative session.

  • An inventory that doesn't match the network

    The inventory and OSS systems show a different network from the one you see in device configurations.

    Missing evidence: an asset register built from configurations, with vendor and software version.

  • A small operator, the whole network in two people's hands

    Micro and small operators are important entities. Router configuration backups sit on the administrator's laptop, and there is no incident handling procedure.

    Missing evidence: dated configuration backups and a test of restoring them.

  • Subscriber portals and APIs

    The customer portal, the mobile app and partner integrations have access to subscriber data and services.

    Missing evidence: a penetration test result with re-checked fixes.

// How we help

Services that fit telecommunications

  1. 01KSC

    Network and vendor inventory

    Entity classification, gap analysis against Article 8 and a register that shows what a high-risk vendor decision would mean for you.

    First step, 5 weeks

    Critical functions on the network map

    • Annex 3 functions mapped to network elements
    • Vendor register with vendor and version
    • Gap analysis against Article 8 with priorities

    Key deliverable: a register of the network elements that perform critical functions, with vendor and version

    NIS2 compliance in Poland
  2. 02Testing

    Tests of portals, APIs and administrative access

    We test IT systems, subscriber portals, APIs and the path into the management network. On production network elements, only in an agreed window and without destructive tests.

    Penetration testing
  3. 03Team

    Security specialists for smaller operators

    A security engineer or GRC specialist joins your team for a defined scope. We have the KRK certificates for Article 8f ready before the start.

    Security specialists
  4. 04Data

    One register instead of three

    Data from OSS, inventory systems and device configurations joined into one source, with an owner and a change history.

    Data platforms

// Scope

What we do, and what we don't

We agree the scope and date in writing before we start.

We do

  • Classification: entity category and scope of obligations
  • An inventory of network elements against the Annex 3 critical functions
  • ISMS and a KSC pre-audit review
  • Penetration tests of IT systems, portals and APIs

We don't

  • Vendor assessments on national security grounds: that decision belongs to the minister
  • Destructive or load tests on the production network
  • A "KSC compliance certificate": no such document exists

We designed FutureCode Evidence Box for telecommunications, among other industries: it collects evidence in read-only mode and never changes production systems.

// FAQ

Questions from telecommunications

We are a small internet service provider. Does the KSC Act apply to us?

Yes. An electronic communications undertaking that is a micro or small enterprise is an important entity (Article 5(2)(4)). You have to meet the Chapter 3 obligations from 3 April 2027. Important entities have no periodic audit, but the authority can order one after a serious incident. As of 24 September 2026.

What happened to the security rules in the Telecommunications Law?

Chapter VIIa of the old Telecommunications Law stayed in force only until the NIS2 implementing provisions took effect (Article 68(3) of the act introducing the Electronic Communications Law). Operators that performed its obligations keep applying the old provisions until they start the KSC Chapter 3 obligations, at the latest by 3 April 2027 (Article 33(5) of the amending act). From then on, security obligations come from the KSC Act, while the Electronic Communications Law defines who is an electronic communications undertaking.

Who supervises us on cybersecurity?

The President of UKE, as the competent cybersecurity authority for the electronic communications subsector (Article 41(8a) of the KSC Act). The same authority covers the postal sector.

What does a high-risk vendor decision mean?

After the minister's decision, you may not put the covered ICT products, services and processes into use. An operator with telecom revenue above PLN 10 million in the previous financial year withdraws those that perform the critical functions in Annex 3 within 4 years, and the rest within 7 years (Articles 67b and 67c). Until then, repairs and updates needed for service continuity are allowed.

We run a messaging service without phone numbers. Are we in scope?

Probably. The Polish Electronic Communications Law counts providers of publicly available number-independent interpersonal communications services as electronic communications undertakings (Article 2(39)). If you provide such a service in Poland, the KSC Act covers you. We check it on the first call.

From the blog: access and encryption

Let's start with a map of critical functions

In 30 minutes we work out your entity category, which of your Telecommunications Law controls you can reuse and where to start the inventory.

Book a 30-minute call

Prefer the scope in writing?

Tell us about your network and the services you provide. We will send back the scope and date of the first step. We reply within one business day.

Request the first step