NIS2 in Poland · KSC · Article 8e

NIS2 management training: once a year, with records for the audit

Under Article 8e of Poland's KSC Act (NIS2 in Poland), the head of the entity and the person responsible for cybersecurity must attend training once per calendar year. We run it as a workshop on your own risks, not a lecture on the law, and leave you the records to show the auditor.

// In short

Article 8e training is a yearly board duty

Article 8e of the KSC Act requires the head of an essential or important entity, and the person they have made responsible for cybersecurity, to attend training once per calendar year. The duty applies together with Chapter 3, from 3 April 2027. We run a half-day board workshop and document it so you can show it to an auditor.

As of 24 September 2026. Source: Dz.U. 2026 item 252 (in Polish).

// Article 8e

Who, how often and what evidence

Who

  • The head of an essential or important entity
  • The person the head has made responsible for cybersecurity
  • We recommend training the whole board if you take budget and risk decisions together

How often

  • Once in every calendar year
  • From 3 April 2027, together with the other Chapter 3 obligations (Article 33(1) of the amending act)
  • Document every later session the same way as the first

Evidence

  • Dated agenda
  • Signed attendance list
  • Materials given to participants
  • Decisions and actions from the workshop

The head of the entity is personally liable: a fine of up to 300% of monthly remuneration, up to 100% in the public sector (Article 73a(4)). The authority can impose most fines, including those under Article 73a, from 3 April 2028 (Article 35 of the amending act). As of 24 September 2026, source: Dz.U. 2026 item 252 (in Polish).

What the workshop covers

  1. Article 8 duties and the head's liability

    What must work from 3 April 2027, who is accountable and which fines apply to the entity and to the head. With examples from your sector.

  2. Risk: what the board accepts and what it funds

    How to read the risk register, when a risk can be accepted and how to record that decision so it counts as evidence.

  3. Incident: the first 24 hours

    Early warning within 24 hours, notification within 72 hours, final report within one month of the notification. Who decides to report, who talks to customers and what the board needs to know in the first hour.

  4. Supply chain and customer questionnaires

    Which suppliers are critical, which security requirements go into contracts and how to answer customers in scope of NIS2 who ask about your controls.

  5. Business continuity

    How long an outage the business can take, who decides that, and when someone last checked that a restore actually works.

  6. AI in the company

    Shadow AI, customer data in public tools, and an approved path instead of a ban. The AI Act requires companies to support AI literacy among their staff (Article 4). More: AI governance and security.

  7. The Article 15 audit

    Who needs it, when it is due and what evidence the board should have ready. More: NIS2 audit readiness.

We agree the agenda with you

Before the workshop we talk to the person responsible for cybersecurity and pick examples from your systems, suppliers and events of the past year. How to prepare for an incident is covered in our article on data breaches.

// Formats

A board workshop and two add-ons

The workshop is the core. The incident exercise and the longer session for the person responsible for cybersecurity are optional.

  1. 01Board

    KSC board workshop

    Half a day, on site or remote. A discussion of your risks and decisions, not a lecture on the act.

    • Agenda in line with Article 8e, with examples from your sector
    • Examples from your systems and suppliers
    • Decisions and actions with owners
    • Training records for the audit file

    First step, half a day

    KSC board workshop

    • Preparatory call with the person responsible for cybersecurity
    • Workshop with the board
    • Training records after the workshop

    Key deliverable: agenda, attendance list, materials and decision list, ready to show an auditor

    Request the first step
  2. 02Incident

    Tabletop incident exercise

    A scenario built around your company, for example encrypted servers or a data leak at a supplier. The board works through the decisions of the first 72 hours.

    • Scenario on your systems and suppliers
    • Reporting decisions at 24 and 72 hours
    • Communication with customers and staff
    • Gaps in the procedure, listed after the exercise
  3. 03Responsible person

    A day for the person responsible for cybersecurity

    Hands-on work on the risk register, the incident procedure and the evidence. For the person the head of the entity has made responsible for cybersecurity.

    • Risk register and risk treatment plan
    • Incident handling and reporting procedure
    • Evidence for each Article 8 area
    • A board report that takes 10 minutes to read

// Scope

What we do and what we don't

We agree date, format and participants in writing before the workshop.

We do

  • Board workshop in line with Article 8e, on site or remote
  • Tabletop incident exercise
  • Training for the person responsible for cybersecurity
  • Training records: agenda, attendance list, materials, decision list
  • A reminder when next calendar year's training is due

We don't

  • Send recordings to play without talking to the board
  • Run template training that ignores your risks and suppliers
  • Issue attendance certificates without a workshop
  • Promise that training settles KSC: it is one of several Article 8 obligations

If you are not sure where you stand on the other obligations, start with a KSC gap analysis.

// FAQ

Questions about board training

Who must attend the Article 8e training?

The head of an essential or important entity and the person they have made responsible for cybersecurity. If your board has several members and takes risk decisions together, we recommend training the whole board. As of 24 September 2026.

How often is the training required?

Once per calendar year. The duty applies from 3 April 2027, together with the other Chapter 3 obligations (Article 33(1) of the amending act). We recommend holding the first session earlier, because the board takes its ISMS and risk decisions before that date.

How do we document the training for the audit?

Keep the dated agenda, the signed attendance list, the materials and the decision list from the workshop. We prepare these records after every session. Keep doing the same in later years: what counts is that the duty works every year, not that training happened once.

Does the training cover AI?

Yes, if your company uses AI tools. We cover shadow AI, data in public tools and an approved path. The AI Act requires companies to support AI literacy among their staff (Article 4), and the board is where that decision gets made.

We have companies in Poland and Germany. Is one training enough?

The agenda can be shared, but keep separate records for each company. In Germany, §38(3) BSIG requires management to attend training regularly and sets no fixed interval. Poland's KSC Act requires training once per calendar year.

How long is the workshop and who should attend?

Half a day. It works best with the board and the person responsible for cybersecurity, without a large audience, because we talk about your own risks, suppliers and decisions.

From the blog: risk, incidents and AI

Let's plan your first board training

In 30 minutes we agree the date, the format and the examples that go into the agenda.

Book a 30-minute call

Prefer to start in writing?

Tell us how many people will attend and which sector you are in, and we will send you an agenda and a date. We reply within one business day.

Request the first step