In brief
Essential and important entities that met the criteria on 3 April 2026 must meet the Chapter 3 duties of the Polish KSC act from 3 April 2027. From October 2026 that leaves 26 weeks. The plan below splits them into nine stages and lists the evidence for each: documents, registers and system logs.
Key takeaways
- Chapter 3 of the amended KSC act (ISMS, risk, incidents, business continuity, supply chain, assets) applies from 3 April 2027 (art. 33(1) of the amending act).
- The application for entry in the register of essential and important entities is due by 3 October 2026. It is the first step, not the implementation.
- Automatically generated system log records count as operational documentation (art. 10(4)), so logs are evidence, as long as someone retains and reviews them.
- The head of the entity and the person entrusted with the head's cybersecurity duties complete training once per calendar year, and attendance must be documented (art. 8e).
- An entity that was essential when the amendment entered into force must have its first audit completed by 3 April 2028 (art. 33(2) of the amending act).
Any NIS2 implementation plan for Poland works back from one date: 3 April 2027. From that day, essential and important entities that met the criteria on 3 April 2026 must meet the Chapter 3 duties of the amended National Cybersecurity System Act (KSC), Poland's transposition of Directive (EU) 2022/2555.
Those duties cover an information security management system (ISMS, in Polish SZBI), risk assessment, incident handling, business continuity and supply chain security. From October that leaves about 26 weeks. Below we split them into stages and name the evidence you will show an auditor for each. Our services around the act are on the NIS2 compliance in Poland page.
Which KSC deadlines apply to your company?
The amending act (Journal of Laws 2026, item 252) entered into force on 3 April 2026. The transition dates sit in the amending act, not in the KSC act itself. The Ministry of Digital Affairs lists them on its key dates page (in Polish). As of 30 September 2026:
| Date | What | Legal basis |
|---|---|---|
| 3 October 2026 | Application for entry in the register of essential and important entities (self-registration) | art. 33(3) and art. 34(3) of the amending act |
| 3 April 2027 | Chapter 3 duties: ISMS, incidents, documentation, management training, contact persons | art. 33(1) of the amending act |
| 3 April 2028 | First audit of an essential entity, then at least every 3 years | art. 33(2) of the amending act, KSC art. 15(1) |
| after 3 April 2028 | Most administrative fines apply | art. 35 of the amending act |
The later start of fines does not delay the duties. From 3 April 2027 the competent authority can ask about your ISMS, and it can order an external audit of an essential entity at any time (art. 15(1b)). The head of the entity is personally responsible, and a personal fine can reach 300% of their monthly salary (art. 73a(4)).
What must be in place on 3 April 2027?
The core is art. 8: an ISMS covering the information system your service depends on. The act lists the measures one by one, which makes it easy to turn them into a checklist. The organizational duties of art. 8c-8f, 9, 10, 11 and 14 add to this.
- Risk: systematic incident risk assessment and risk management (art. 8(1) point 1).
- Technical and organizational measures (art. 8(1) point 2 letters a-n): policies, security in acquiring and developing systems, physical security, HR security, ICT supply chain, business continuity plans, continuous monitoring, effectiveness reviews, staff education, cyber hygiene, cryptography, multi-factor authentication where appropriate, asset management, access control.
- Incidents: incident management (art. 8(1) point 4) and reporting significant incidents to the competent sectoral CSIRT: early warning within 24 hours of detection, notification within 72 hours, final report within one month of the notification (art. 11(1)).
- People: at least two people named as contacts for the national cybersecurity system (art. 9(1)), a criminal record certificate from the National Criminal Register for staff doing art. 8 or 11 work (art. 8f), yearly management training (art. 8e).
- Documentation: normative and operational, controlled and versioned, kept for at least 2 years after withdrawal (art. 10).
- Structure: an internal cybersecurity team or a contract with a managed security service provider (art. 14).
If you already run an ISMS to ISO/IEC 27001, much of this list is covered. The gaps tend to be in the details: reporting deadlines, criminal record checks, management training, document control. We compare the two in our article on ISO/IEC 27001 and why it matters, and the EU background is in our overview of the NIS2 directive.
What does a 26-week NIS2 implementation plan look like?
The plan assumes you start in the first week of October 2026 and either have a gap analysis or can run one in the first month. Stages overlap. The order matters: without an asset register you cannot assess risk, and without a risk assessment you cannot justify your choice of measures.
| Weeks | Work | Evidence at the end of the stage |
|---|---|---|
| 1-2 | Management decision, scope (services and systems), budget, project owner, two named contacts, register entry | Board resolution or decision, responsibility matrix, register application receipt, contact list |
| 3-5 | Asset register, gap analysis against art. 8, first management briefing | Asset register with owners, prioritized gap report, attendance list |
| 6-8 | Risk method and assessment, risk treatment plan | Risk register, risk treatment plan approved by the head of the entity |
| 9-12 | ISMS policies, access control, cryptography, document control | Policies with version numbers and approval dates, document register |
| 13-16 | Incident procedure, classification, route to the sectoral CSIRT and S46, the national incident reporting system, monitoring | Procedure, incident log, reporting drill record, log retention settings |
| 17-19 | Supply chain: ICT supplier list, assessment, contract requirements | Supplier register with risk ratings, clauses or amendments |
| 20-22 | Business continuity: impact analysis, plans, recovery test | Continuity plan, recovery plan, test record with findings |
| 23-24 | Management training in 2027, staff education, criminal record certificates | Documented training attendance, education program, certificate register |
| 25-26 | Effectiveness review, management review, list of open actions | Effectiveness report, review minutes, action plan with dates |
Why does management training appear twice? Art. 8e requires training once per calendar year. A session in October 2026 gives the board what it needs to make project decisions, but it does not count for 2027, the first year in which the duty applies.
What NIS2 evidence will an auditor ask for in each area?
Art. 10 splits documentation into normative and operational. Normative means policies, plans and descriptions. Operational means records that prove the activities required by the normative documents were carried out, "including automatically generated records in information system logs" (art. 10(4), our translation). A policy with no records behind it is a document about a control, not a control.
| Area | Provision | Operational evidence |
|---|---|---|
| Access control | art. 8(1) point 2 letter n | Permission exports, account review records, sign-in logs with MFA |
| Patching and vulnerabilities | art. 8(1) point 5 letters b and d | Scan reports, patch history, tickets with fix dates |
| Monitoring | art. 8(1) point 2 letter g | SIEM or EDR alerts, daily on-call reports, log retention |
| Incidents | art. 11(1) | Incident log, S46 reports with timestamps, final reports |
| Business continuity | art. 8(1) point 2 letter f | Backup job logs, restore test records |
| Supply chain | art. 8(1) point 2 letter e, art. 8(2) | Supplier assessments, questionnaire results, contract change history |
| People | art. 8e, art. 8f | Training confirmations, criminal record certificate register with dates received |
The full list of 26 requirements with evidence, source systems and owners is in our NIS2 evidence matrix (XLSX download). Our article on the CISA certification and compliance covers who may perform the formal art. 15 audit and which certificates the regulation accepts.
What does the act require from the head of the entity?
The head of the entity is responsible for the cybersecurity duties even after handing some or all of them to another person (art. 8c(3)). If the head is a multi-member board and no one has been named as responsible, every board member is responsible (art. 8c(2)).
- Decides on preparing, implementing, reviewing and overseeing the ISMS (art. 8d point 1).
- Plans the budget for the cybersecurity duties (art. 8d point 2).
- Assigns cybersecurity tasks and oversees them (art. 8d point 3).
- Completes training once per calendar year, together with the person entrusted with the head's cybersecurity duties; attendance is documented (art. 8e).
The evidence here is decision minutes, a budget line and training certificates, not a sentence in a policy. We run training scoped to art. 8e as part of our NIS2 management training.
Where does KSC implementation usually stall?
- Scope set to "the whole company". The ISMS covers the information system your service depends on. A scope that is too wide burns weeks on systems with no effect on the service.
- Policies before risk. Policy templates without a risk register cannot explain why you chose these measures and not others.
- Logs without retention. If a system overwrites its log after 7 days, you have no operational documentation for the last quarter.
- Suppliers left for last. Contract amendments take negotiation, so start them mid-project, not in March.
- Continuity tested on paper. A plan without a restore test record does not show that the plan works.
Implementation does not end on 3 April 2027. Reviews and effectiveness checks come back every year, so set them up as a cycle from the start, as we describe in our article on continuous IT audits. For a technical review of data protection, see how a technology audit improves data security.
Where should you start this week?
- Check that the register application has been filed. The deadline is 3 October 2026.
- Name a project owner and the two contacts.
- Run a gap analysis against art. 8, or schedule it for the first 3 weeks.
- Check log retention on the systems your service depends on.
We do not perform formal KSC audits under art. 15. We run NIS2 readiness assessments, implementation and ongoing support, and we tell you who may perform the formal audit. If you want to walk through this plan on your own systems, get in touch.
Frequently asked questions
- When does NIS2 compliance become mandatory in Poland?
Entities that met the essential or important entity criteria on 3 April 2026 must meet the Chapter 3 duties of the KSC act from 3 April 2027 (art. 33(1) of the amending act, Journal of Laws 2026, item 252).
- Do system logs count as KSC evidence?
Yes. Art. 10(4) counts automatically generated records in information system logs as operational documentation. Documentation is kept for at least 2 years after it is withdrawn (art. 10(7)).
- How often must management complete cybersecurity training?
Once per calendar year, together with the person entrusted with the head's cybersecurity duties. Attendance must be documented (art. 8e).
- Does an important entity need a KSC audit?
The periodic art. 15 audit applies to essential entities. The authority can order an important entity, by decision, to undergo an external audit after a significant incident or another breach of the act (art. 15(1b)).
- Is there a KSC or NIS2 compliance certificate?
No. The act requires a security audit of the information system with a report (art. 15), not a certificate. An ISO/IEC 27001 certificate helps but does not replace the KSC audit.

