NIS2 in Poland · KSC

NIS2 compliance in Poland (KSC): implementation and audit readiness

Poland's amended National Cybersecurity System Act (KSC) has been in force since 3 April 2026, and its Chapter 3 obligations apply from 3 April 2027. We take you from gap analysis to controls you can see in your systems, and prepare the evidence for the first audit.

// In short

The KSC Act is Poland's implementation of NIS2

It covers essential and important entities in 18 sectors, about 42,000 organizations by industry estimates. From 3 April 2027 they need an information security management system (ISMS), risk management, incident handling, business continuity and yearly management training. We help you implement this and prove it with evidence from your systems before an auditor asks.

As of 24 September 2026. Source: Dz.U. 2026 item 252 (in Polish).

// Deadlines

KSC deadlines

  1. Register

    Self-registration in the KSC register

    Deadline under Article 34(3) of the amending act. If you have not applied yet, do it now. The authority can also enter an entity on its own initiative (Article 7j).

    How to register (gov.pl, Polish) (opens in a new tab)
  2. Chapter 3

    Chapter 3 obligations

    ISMS, risk, incidents, business continuity, supply chain, assets and management training. Applies to entities that already met the criteria on 3 April 2026 (Article 33(1) of the amending act).

    Act text (Dz.U. 2026 item 252) (opens in a new tab)
  3. Audit

    First audit deadline for essential entities

    Applies to entities that were already essential on 3 April 2026, the day the amending act entered into force (Article 33(2) of the amending act). After that, an audit at least every 3 years. An entity that becomes essential later has 24 months from meeting the criteria (Article 16). Former operators of essential services keep their existing 3-year audit cycle.

    Who may audit
  4. Fines

    Most administrative fines

    From this date, the authority can impose the fines in Article 73(1) to (4), Articles 73a to 73c and Article 76b of the KSC Act (Article 35 of the amending act). The fine under Article 73(5), up to PLN 100 million, is not covered by this transition period and already applies.

    gov.pl, KSC deadlines (Polish) (opens in a new tab)

As of . Sources (in Polish): Dz.U. 2026 item 252, gov.pl, KSC deadlines, self-registration.

// Who is in scope

Who the KSC Act covers

Whether you are an essential or an important entity depends on sector, size and the services you provide. We check this against your data before implementing anything.

  1. 01Sectors

    18 sectors

    Among them energy, transport, banking, health, water, digital infrastructure, manufacturing, food and postal services. Industry estimates put the number at about 42,000 Polish organizations.

  2. 02Size

    Size thresholds

    As a rule, the act covers medium-sized and large companies in these sectors. Some services are covered regardless of company size.

  3. 03MSSP

    Managed security service providers

    Providers of managed security services are covered even as small enterprises. The definition in Article 2(4j) also includes security testing, audits and advisory.

  4. 04Supply chain

    Suppliers to covered companies

    Even if the act does not cover you, your customers must manage their supply chain risk. Expect security questionnaires and new contract clauses.

    Answering questionnaires

What has to work from 3 April 2027

  1. Information security management system (ISMS)

    Policies, roles and reviews that work in practice. Evidence: approved documents with review dates and a trail of decisions.

  2. Risk management

    Risk assessment for information systems and a risk treatment plan. Evidence: a risk register with owners and deadlines.

  3. Incident handling

    Detecting, handling and reporting incidents within the statutory deadlines. Evidence: tickets in the system, response times and logs.

  4. Business continuity

    Continuity and disaster recovery plans. Evidence: a restore test result with its date and duration.

  5. Supply chain

    Supplier assessment and security requirements in contracts. Evidence: a supplier register with assessments and review dates.

  6. Asset management

    An up-to-date inventory of systems, data and their owners. Evidence: a register generated from the systems, not from memory.

  7. Management training (Article 8e)

    The head of the entity is personally liable. Once per calendar year, they complete the training together with the person they have given cybersecurity duties. Evidence: agenda, date and attendee list.

Evidence from systems, not binders

The act (Article 10(4)) counts automatically generated system logs as operational documentation, so we start with what your systems already record. Many of these requirements overlap with an ISO/IEC 27001 implementation. The NIS2 evidence matrix (XLSX, no sign-up) shows what evidence to prepare for each area.

// How we help

Implementation and pre-audit review

Two packages you can order separately. Both end in evidence.

  1. 01Implementation

    From gap analysis to a control with evidence

    A 26-week plan with owners and dates. If you have less time, we start with the highest-risk areas.

    • Gap analysis against Article 8 of the KSC Act
    • Obligations register with owners
    • Controls implemented in your systems
    • ISMS documentation that describes what actually runs

    First step, 5 weeks

    KSC without rewriting everything

    • Gap analysis with priorities
    • Obligations register with owners
    • 90-day roadmap

    Key deliverable: one control implemented in a system, together with its evidence

    Request the first step
  2. 02Before the audit

    KSC pre-audit review

    We check controls and evidence the way an Article 15 auditor will, before they do. This is a readiness assessment, not a formal audit. FutureCode Evidence Box can collect the evidence. See the output in the sample readiness report.

    • Review of ISMS documentation and evidence
    • Samples of logs, configurations and tickets
    • Prioritized list of fixes
    • Re-check after the fixes
    Independence rules

// How we can help

Audit readiness, management training and a fractional CISO

Three services for specific obligations under the act. You can order each one separately, also without an implementation project.

  1. 01Article 15

    NIS2 audit readiness in Poland

    Your controls and evidence checked the way an auditor will, with a fix list and a re-check.

    Audit readiness
  2. 02Article 8e

    NIS2 management training

    Yearly training for the head of the entity and the person responsible for cybersecurity, documented for the audit.

    Management training
  3. 03Ongoing

    Fractional CISO for KSC

    Risk register, incident readiness, customer questionnaires and a quarterly board report.

    Fractional CISO

// Formal KSC audit

Who may perform a KSC audit

An essential entity must have an Article 15 audit at least every 3 years. For an important entity, the authority can order one by decision after a serious incident or another breach of the act (Article 15(1b)).

May perform it (Article 15(2))

  • An accredited conformity assessment body
  • At least two auditors, each with a certificate from the regulation's list (among them ISACA CISA, CISM, CRISC, CISSP, CIA, ISO/IEC 27001 Lead Auditor, ISO 22301 Lead Auditor), 3 years of practice auditing information system security, or 2 years of practice plus a relevant postgraduate diploma
  • A sectoral CSIRT whose auditors meet the same criteria

May not perform it (Article 15(2a))

  • A person who performs tasks under Article 8 or Articles 9-13 at your company
  • A person who performed them in the year before the audit starts
  • A single auditor working alone (Article 15(2) requires at least two)

We don't perform formal KSC audits; we prepare you for them. We tell you up front who can audit you and who cannot. As of 24 September 2026. Sources (in Polish): gov.pl, auditor qualifications, Dz.U. 2018 item 1999.

Facts that often get mixed up

As of 24 September 2026
What you often hearWhat the law saysBasis
The head of the entity faces a fine of up to 600% of salaryUp to 300% of monthly remuneration, 100% in the public sectorArticle 73a(4) and (5)
You can get a KSC compliance certificateNo such certificate exists. The act provides for the Article 15 auditArticle 15
Fines apply from October 2026Most fines apply from 3 April 2028. Exception: Article 73(5)Article 35 of the amending act
An ISO/IEC 27001 certificate replaces the KSC auditIt does not, although many controls overlapArticle 15

Source: Dz.U. 2026 item 252 (in Polish).

// Scope

What we do, and what we don't

We agree the scope and date in writing before we start.

We do

  • Classification: whether the act covers you, and in which category
  • Gap analysis against Article 8 and a 26-week implementation plan
  • Controls implemented in your systems, with evidence
  • KSC pre-audit review and re-checks of fixes
  • A KRK certificate from the Polish National Criminal Register for each of our staff who do Article 8 or 11 work at KSC entities (Article 8f)

We don't

  • A "KSC compliance certificate": no such document exists
  • A formal KSC audit under Article 15: an independent auditor performs it, not us
  • Template policies that nobody follows
  • A year-long program on slides with no working first step

If all you need is a document for the inspection file, we'll be upfront about that on the first call.

// FAQ

Questions about NIS2 in Poland

Does the KSC Act apply to us?

It depends on sector, size and services. If you operate in one of the 18 sectors and are at least a medium-sized company, most likely yes. Some services, such as managed security services, are covered even for small enterprises. International groups should check each company established in Poland. We go through it on the first call.

We haven't registered in the KSC register yet. What now?

Register now, whether or not the 3 October 2026 deadline has passed. Self-registration has been open since 7 May 2026 at wykaz-ksc.gov.pl. The authority can also enter an entity on its own initiative (Article 7j). You have to meet the Chapter 3 obligations by 3 April 2027 whether or not you are registered, so start the gap analysis in parallel.

Who may perform a KSC audit?

An accredited conformity assessment body, at least two qualified auditors (a certificate from the list, such as ISACA CISA, or documented practice), or a sectoral CSIRT that meets the same criteria. The auditor cannot be a person who performed tasks under Article 8 or Articles 9-13 at your company in the year before the audit (Article 15(2) and (2a)).

How long does implementation take?

It depends on what already works. We lay out the implementation plan over 26 weeks, with owners and dates; if there is less time, we start with the highest-risk areas. The first step takes 5 weeks and has a fixed scope.

Does ISO 27001 replace the KSC audit?

No. A certification body issues the ISO/IEC 27001 certificate against the standard, while the KSC audit follows Article 15 of the act. An ISMS aligned with ISO/IEC 27001 still shortens the path to meeting the KSC Act, because many controls overlap.

What fines apply, and from when?

Most administrative fines can be imposed from 3 April 2028 (Article 35 of the amending act). The exception is Article 73(5) (up to PLN 100 million), which is not covered by the transition period. The head of the entity faces a fine of up to 300% of monthly remuneration, 100% in the public sector (Article 73a(4) and (5)). As of 24 September 2026.

From the blog: NIS2 and security audits

Let's start with a KSC gap analysis

In 30 minutes we check whether the act covers you and in which category, and agree the scope of the first step. Before the call, you can go through the NIS2 evidence matrix.

Book a 30-minute call

Prefer to start in writing?

Describe your situation and we will send back the scope and date of the first step. We reply within one business day.

Request the first step