Competence · Regulatory audit · position at 24 August 2026

The KSC/NIS2 audit in 2026: who is covered, what to check and when

In Poland, NIS2 is no longer a "future KSC". The amended act on the national cybersecurity system has applied since 3 April 2026 [2]. It is that current act - not the text of the directive - that is the primary criterion for a national audit.

When citing a provision, take care which version of the text you quote. The last consolidated text was announced by the Marshal of the Sejm on 29 December 2025 (Journal of Laws 2026 item 20) and reflects the legal position as at 23 December 2025, that is before the NIS2 transposing amendment [1]. Anyone citing item 20 alone is citing wording that no longer applies. The practical answer is to use the unified text published through ELI, which incorporates successive amendments, and to state in the report the date of the legal position the examination was based on.

The most pressing date for entities not entered on the register ex officio is 3 October 2026, the end of the first self-registration period in the KSC register. [5] Before that, however, the organisation's status has to be established correctly. Headcount alone, the name of a sector or a business classification code will not do.

NIS2 and KSC: which instrument applies in Poland

Directive (EU) 2022/2555, known as NIS2, sets a common European level of protection, supervision and incident reporting. [3] Member States transpose it into national law. In Poland that happened through the act of 23 January 2026 amending the KSC act, in force since 3 April 2026. [2]

The label "UKSC" is sometimes used as shorthand for the bill or the amendment. It is not, however, the name of a separate legal regime still waiting in the wings. An audit must cite the specific provision of the current KSC act, the relevant annex and any applicable implementing act. Mapping to articles 20, 21 and 23 of NIS2 helps interpret the purpose of the rules, but it does not replace examining Polish law.

Who is an essential entity and who is an important one

The Polish act uses the notions of an essential entity and an important entity. They should not be reversed or replaced by the former category of operator of essential services. The starting point is annex 1, "Essential sectors", and annex 2, "Important sectors", but qualification requires a multi-stage test. [1]

  1. Service and sector. The activity actually carried out has to be matched to a specific type of entity in the annex, not merely to the general name of an industry or a classification code.
  2. Size of the enterprise. Where the act refers to size, annex I to Regulation (EU) No 651/2014 applies. [6] That means, among other things, taking partner and linked enterprises into account. The popular rule of "50 employees or EUR 10 million" is too simplified to settle status.
  3. Exceptions independent of size. The act names categories that may be essential regardless of size, including DNS providers, qualified trust service providers, top-level domain name registries, critical entities and certain public bodies.
  4. Special provisions and decisions. The authority may decide that an organisation is an essential or important entity where its service is of exceptional significance at the level of a voivodeship, the country or several sectors.

In public administration there is no rule that "every local authority is an essential entity". The act qualifies individual public bodies separately. Among important entities it names, for instance, local government budgetary units and establishments, local government cultural institutions and companies performing tasks of public utility. An analysis of the particular legal person or organisational unit, its legal basis and the services it provides is necessary. [1]

The outcome of qualification should be a written memorandum: the provision relied on, the annex entry, the financial and employment data together with the aggregation rules, the exceptions, and the mode of entry on the register. The auditor should also check whether changes of ownership, taking on a new service or growth of the group have altered an earlier assessment.

The timetable of obligations: 2026-2028

  • 3 April 2026 - the amendment enters into force.
  • 13 April to 6 May 2026 - first entries made ex officio, covering among others former operators of essential services, trust service providers, telecommunications undertakings and public bodies.
  • 7 May to 3 October 2026 - the first self-registration period for entities that met the criteria on the day the act entered into force and were not entered ex officio.
  • 3 April 2027 - for entities covered on the day the amendment entered into force, the end of the period for implementing the chapter 3 obligations and starting to use the S46 system.
  • 3 April 2028 - the deadline for the first statutory audit for essential entities that were not previously operators of essential services; former operators keep their own audit cycle.
  • After 3 April 2028 - the new administrative fines listed in article 35 of the amending act may be imposed for the first time. This transitional rule does not defer the underlying obligations or their individual implementation deadlines.

An organisation that begins to meet the criteria later counts the relevant deadlines from the moment it comes within the rules, under article 16 of the act. The schedule therefore has to be maintained individually, not copied from the calendar of an entity that existed before the amendment. The official list of deadlines is published by the Ministry of Digital Affairs. [5]

What to audit in the information security management system

Article 8 of the act requires an ISMS to be implemented in the information systems used in processes affecting the provision of the service. The measures are to be appropriate and proportionate to the risk, the size of the organisation, the likelihood of incidents, their social and economic consequences, the cost of implementation and the state of the art. [1]

An audit should not reduce that provision to a list of ten policies. It should examine whether the risk management mechanism genuinely covers:

  • security policies, the risk methodology and risk treatment decisions;
  • secure acquisition, development, maintenance and operation of systems, including testing and vulnerability management;
  • physical, environmental and personnel security, and access control;
  • the supply chain, contractual requirements and the risk of dependence on suppliers;
  • business continuity, contingency and recovery plans, and evidence that they have been tested;
  • continuous monitoring of systems affecting the service, and evaluation of the effectiveness of safeguards;
  • staff education, cyber hygiene and training for management;
  • cryptography, encryption and secure communication, including multi-factor authentication where appropriate;
  • asset inventory, software updates and the handling of threats and vulnerabilities;
  • incident management: detection, classification, response, communication, reporting and lessons learned.

An important exception for the public sector: an important entity that is a public body - and the higher education and science units named in the act - performs public tasks under the special regime of article 8(3) and the requirements of annex 4. An audit cannot mechanically apply the same matrix as for an enterprise under article 8(1). [1]

For DNS providers, TLD registries, cloud, data centres, CDNs, managed services and managed security services, online marketplaces, search engines and social platforms, Commission Implementing Regulation (EU) 2024/2690 must additionally be taken into account. [4]

The scope does not end at article 8

Articles 9 and 10 add organisational and documentary obligations. As a rule an entity designates at least two people for contact with the national cybersecurity system; a micro or small enterprise and an important entity that is a public body designate at least one. Users must also be given a way to report a cyber threat, incident or vulnerability, and use of S46 must begin once the entity is entered on the register.

Security documentation covers a normative and an operational part. An audit should therefore examine not only policies but also the records confirming that procedures are carried out, including automatically generated logs. Article 10 further governs version control, access, integrity and retention of the documentation. [1]

Management responsibility and outsourcing

The head of the entity is responsible for discharging the act's obligations. Where the organisation is run by a collegiate body and no specific person has been designated, the responsibility extends to all its members. Delegating tasks to a CISO, the IT department or a supplier does not remove that responsibility. [1]

In practice an audit should look for evidence that management:

  • approved and periodically reviews the ISMS and the risk acceptance criteria;
  • provided adequate funding and assigned owners to the obligations;
  • receives meaningful reports on risk, incidents, vulnerabilities and progress on remediation;
  • designated the person leading cybersecurity work and oversees them;
  • provided the required training once in each calendar year and retained records of attendance.

The act imposes no four-hour or eight-hour course and requires no particular training certificate. The content should nonetheless allow management to understand their own obligations and to assess the organisation's risk.

The scope of organisational controls also covers article 8f. People designated to perform the ISMS and incident handling tasks named in the act present, before starting, a criminal record certificate confirming the absence of convictions for offences against the protection of information. The act provides an exception for a person holding a valid security clearance for access to classified information at the level of at least "confidential". An audit should check the obligation itself and the secure handling of the document, without creating unnecessary copies of criminal record data. [1]

Article 14 permits either an internal structure or a contract with a provider of managed security services. Outsourcing is therefore permissible, but the contract has to enable the entity to classify and handle incidents on time, to access evidence, to control subcontractors, to maintain service continuity and to audit the provider. Management responsibility stays with the organisation.

Incidents: 24 hours, 72 hours and the final report

The deadlines run from detection of a significant incident, not from every security alert. The assessment should rest on the statutory definition and the thresholds applicable to the type of entity. An audit must cite the source of the current thresholds instead of applying an invented, universal list of ransomware, record counts or downtime. [1]

  1. within 24 hours - an early warning to the relevant sectoral CSIRT;
  2. within 72 hours - notification of the significant incident with a current assessment of the event;
  3. at the CSIRT's request - an intermediate report;
  4. within a month of the 72-hour notification - the final report; if the incident is still ongoing, a progress report and then a final report within a month of its conclusion.

For a trust service provider the act sets a special 24-hour deadline for notifying a significant incident. An important entity that is a public body, on the other hand, benefits from the exception in article 12c: it does not submit an early warning, an intermediate report, a progress report or a final report; the 72-hour notification still applies to it.

A good audit test links a record from a SIEM or ticketing system, the time the team took to assess it, the process owner's decision, the content of the S46 notification and the later supplements. That checks not only that a procedure exists but that the organisation can execute it within the time available.

The article 15 audit versus a readiness assessment

The market uses "NIS2 audit" for both a gap assessment before implementation and the statutory audit of information system security. The two are not interchangeable.

  • A readiness or gap assessment can be carried out earlier, iteratively and by a flexibly assembled team. Its purpose is to plan for compliance. It does not automatically become an article 15 audit.
  • The statutory audit is subject to article 15's requirements on frequency, the qualifications of the team, independence, documentation, the report and its transmission to the authority.

An essential entity carries out the audit at its own cost at least once every three years, counted from the day the report of the previous audit was drawn up and signed. It sends a copy of the report to the competent cybersecurity authority electronically within three working days of receiving it. [1]

An important entity has no automatic three-year cycle. The authority may, however, order it to undergo an external audit after a significant incident or another breach of the act, and may specify the scope and the type of auditor. The authority may equally order an additional audit of an essential entity.

Who may carry out the statutory audit

The act provides for an accredited conformity assessment body with the appropriate scope, or a team of at least two auditors meeting one of the statutory routes: a specified certificate, appropriate practical experience, or experience combined with relevant postgraduate study. A sectoral CSIRT may also carry out the audit, if its auditors meet those conditions.

A certificate is not the only permissible route. The current implementing act listing the recognised certificates has to be checked, and experience documented as the act defines it. Independence matters too: a person performing the tasks under article 8 and articles 9-13 in the audited entity - or who performed them in the previous year - may not audit that entity under article 15.

How to run a credible KSC/NIS2 audit

  1. Confirm the criteria. Establish the legal status, the service, the sector, the category of entity, the transitional deadlines and the competent authority and CSIRT.
  2. Define the service scope. Map the processes affecting its provision, the IT and OT systems, sites, data, roles, suppliers and dependencies. A scope built solely on a network diagram will be incomplete.
  3. Build a requirements matrix. Tie every applicable provision of the act and implementing regulation to a control, an owner, evidence and a test. Standards may support the methodology but cannot replace the legal criterion.
  4. Examine both design and operation of controls. A policy shows intent; samples of configuration, logs, incidents, changes, backups, exercises and supplier assessments show execution. The sample period should match the risk and the frequency of the process.
  5. Test an incident scenario. A tabletop exercise should cover detection, threshold classification, the decision, communication with management, S46, preservation of evidence and parallel obligations such as those under the GDPR.
  6. Assess adequacy, not merely presence. The act requires measures that are appropriate and proportionate. An auditor should explain why a given gap increases the risk to the specific service.
  7. Report separately. The report should distinguish a legal nonconformity, a control weakness, an observation and a recommendation. Every finding must state the criterion, the facts, the evidence, the risk and the owner of the action.
  8. Close the corrective actions. A plan alone does not remove a nonconformity. A deadline, an owner, acceptance criteria and a re-test of effectiveness are needed.

The KSC act, ISO/IEC 27001 and KRI do not replace one another

ISO/IEC 27001:2022 sets requirements for an information security management system, ISO/IEC 27007:2020 helps plan and conduct ISMS audits, and the current general standard for auditing management systems is ISO 19011:2026. [8][9][10] These standards organise methodology and evidence, but they are voluntary unless a contract or another provision gives them particular weight.

An ISO/IEC 27001 certificate does not automatically demonstrate conformity with the KSC act. The scope of certification may not cover every regulated service, S46, the statutory deadlines, incident classification, the specific duties of management or the requirements of article 15.

A public body may in parallel be subject to the annual internal audit under § 19(2)(14) of the KRI regulation. [7] Evidence and tests can be shared, but a KRI audit does not replace an article 15 audit, and a KSC audit does not discharge the KRI obligation.

Penalties: statutory ceilings, not an automatic tariff

The Polish act sets its own limits for administrative financial penalties. For an essential entity the ceiling is the higher of EUR 10 million or 2 per cent of turnover from business activity. The minimum penalty is PLN 20,000. For an important entity it is the higher of EUR 7 million or 1.4 per cent of turnover, with a minimum of PLN 15,000. Special rules on the basis apply where the period of activity is shorter or there is no turnover. [1]

In the situations set out in article 73(5) - connected among other things with a direct serious cyber threat to defence, state or public security, life and health, or a risk of serious damage - the penalty may reach PLN 100 million. The head of the entity may be penalised separately, as a rule up to 300 per cent of their remuneration; for the head of a public body the act sets a special limit of 100 per cent, except for entities simultaneously covered by another sector. [1]

These are not amounts imposed automatically. The authority applies the statutory criteria for setting a penalty and administrative procedure. Transitional provisions allow the new penalties to be imposed for the first time from 3 April 2028. That is not a compliance holiday, however: the deadlines for registration, implementing safeguards, S46, reporting and auditing all run, and the authority has supervisory measures available as well.

Checklist: preparing for a KSC/NIS2 audit

A checklist for the owner of the compliance programme. Every item should have an owner, a deadline and verifiable evidence.

  1. A written qualification of the organisation citing the relevant annex, the size test and an analysis of the corporate group.
  2. Confirmed entry on the KSC register, or a self-registration plan, ahead of the relevant deadline.
  3. A map of the service, processes, systems, data, sites, suppliers and dependencies.
  4. A risk analysis and risk treatment plan approved by management.
  5. A requirements matrix for article 8 or, where applicable, article 8(3) and annex 4.
  6. An incident classification procedure citing the source of the current thresholds and the relevant CSIRT.
  7. S46 readiness and a rehearsal of the 24/72-hour path and the final report, taking the exceptions into account.
  8. Documented management decisions, funding, assignment of roles and annual training.
  9. Assessment of critical suppliers and contracts providing evidence, escalation, continuity and a right to audit.
  10. Tests of backups, recovery, service continuity, vulnerabilities, privileged access and monitoring.
  11. Verified qualifications and independence of the auditors, where the examination is to satisfy article 15.
  12. A register of nonconformities and corrective actions with a re-test of effectiveness.

Frequently asked questions

Is every company with at least 50 employees covered by the KSC act?

No. The type of activity and the relevant row of annex 1 or 2 have to be examined together with the formal size test, including partner and linked entities, and with the exceptions that apply irrespective of size. An employment threshold alone does not settle it.

What is the difference between an essential and an important entity?

Both carry extensive risk management and reporting duties. What differs is chiefly the qualification criteria, the supervisory model, the limits on penalties and the automatic audit obligation. Final status follows from article 5 of the act, the relevant annex and any decision of the authority.

When does the self-registration deadline fall?

For entities meeting the criteria on 3 April 2026 and not entered ex officio, the Ministry of Digital Affairs gives 3 October 2026 as the end of the first self-registration period. An entity entered ex officio should not submit a further application.

Must an important entity be audited every three years?

There is no automatic three-year cycle under article 15 for it. The authority may nevertheless order an external audit after a significant incident or another breach of the act. Regular internal evaluation of ISMS effectiveness still follows from risk management.

Can the IT department carry out the statutory audit itself?

A person performing the article 8 and articles 9-13 tasks in the audited entity, or who performed them in the previous year, does not meet the independence requirement of article 15. Internal self-assessment remains useful but should not be presented as the statutory audit.

Does an ISO/IEC 27001 certificate replace the KSC audit?

No. It can supply valuable evidence and reduce duplicate testing, but the statutory audit has its own scope, auditor qualifications, independence requirement, report and deadlines.

Do the 24 and 72 hours apply to every SOC alert?

No. The schedule applies to a significant incident determined against the relevant thresholds. Every alert should nonetheless be recorded and assessed, so that the organisation can defend its decision to report or not to report.

Does an important entity that is a public body report in the same way?

Not entirely. Article 12c relieves it of the early warning, the intermediate report, the progress report and the final report. The duty to notify a significant incident within 72 hours remains.

Does outsourcing cybersecurity transfer responsibility to the provider?

No. The act permits an external provider of managed security services, but the head of the entity remains responsible for compliance. The contract and the oversight must ensure the obligations are discharged on the organisation's behalf.

Does the annual KRI audit replace the KSC audit?

No. Some evidence and tests may be shared, but the criteria, scope, addressees and formal requirements of the two audits differ.

Does the absence of penalties until 2028 mean implementation can wait?

No. The deferral concerns the first imposition of the new financial penalties, not the obligations themselves. Registration, preparing S46, implementing the ISMS and the statutory audit deadlines all run earlier.

Need consulting in this area?

A free 30-60 minute consultation. No obligations. We discuss needs, scale and a high-level timeline.

Bibliography and sources

Legal position and sources verified on 24 August 2026. Current texts of legal acts and official communications take precedence.

  1. [1] prawoUstawa z 5 lipca 2018 r. o krajowym systemie cyberbezpieczeństwa - tekst jednolity ogłoszony obwieszczeniem Marszałka Sejmu z 29 grudnia 2025 r., Dz.U. 2026 poz. 20, oddający stan prawny na 23 grudnia 2025 r. Późniejsze zmiany, w tym nowelizację obowiązującą od 3 kwietnia 2026 r., uwzględnia tekst ujednolicony w ELI. · tekst ujednolicony (PDF) · karta aktu
  2. [2] prawoUstawa z 23 stycznia 2026 r. o zmianie ustawy o krajowym systemie cyberbezpieczeństwa oraz niektórych innych ustaw, Dz.U. 2026 poz. 252. · Tekst aktu
  3. [3] prawo UEDyrektywa Parlamentu Europejskiego i Rady (UE) 2022/2555 (NIS2). · EUR-Lex
  4. [4] prawo UERozporządzenie wykonawcze Komisji (UE) 2024/2690 dotyczące wymogów technicznych i metodologicznych oraz incydentów poważnych dla wskazanych dostawców cyfrowych. · EUR-Lex
  5. [5] informacja urzędowaMinisterstwo Cyfryzacji (2026), "Nowelizacja ustawy o KSC - najważniejsze terminy" oraz instrukcja samorejestracji. · Terminy · Samorejestracja
  6. [6] prawo UERozporządzenie Komisji (UE) nr 651/2014, załącznik I - definicja MŚP i zasady ustalania danych przedsiębiorstwa. · EUR-Lex
  7. [7] prawoRozporządzenie Rady Ministrów z 21 maja 2024 r. w sprawie Krajowych Ram Interoperacyjności, Dz.U. 2024 poz. 773. · ELI
  8. [8] normaISO (2026), ISO 19011:2026 - Guidelines for auditing management systems. · ISO
  9. [9] normaISO/IEC (2020), ISO/IEC 27007:2020 - Guidelines for information security management systems auditing. · ISO
  10. [10] normaISO/IEC (2022), ISO/IEC 27001:2022 - Information security management systems - Requirements. · ISO
4crypto.eu