Who is subject to the KSC
The basic categories are essential entities and important entities. The Polish Act uses Annex 1 for key sectors and Annex 2 for important sectors, but merely operating in a listed sector is not enough to determine status. The type of entity, service actually provided, enterprise size, corporate links and statutory exceptions must all be examined.[1][2]
In many cases, size is determined using Annex I to Commission Regulation (EU) No 651/2014.[4] The popular shorthand of "50 employees or EUR 10 million" is not sufficient because partner and linked enterprises and KSC-specific rules may affect the calculation.
An essential entity may qualify because of its size and position in Annex 1, but the Act also identifies categories that are covered regardless of size. These include, among others, DNS service providers, qualified trust service providers, TLD registries, certain public entities and critical entities. Special rules also apply to electronic communications undertakings and managed security service providers.[2]
Important entities include, among others, medium-sized entities in Annex 1 that are not essential and at least medium-sized entities in Annex 2. The Act also contains separate rules for certain public entities and other explicitly listed categories.[2]
An organisation should therefore not be classified solely by a business activity code, sector label or headcount. The result of the classification exercise should be a short memorandum stating the legal basis, the relevant Annex entry, the size calculation, applicable exceptions and the date on which the entity met the criteria.
Register of entities and transitional periods
The KSC provides for a register of essential and important entities. Some entities are entered ex officio, while others must apply for entry in accordance with the statutory and transitional rules. The absence of an entry should not be treated as a safe assumption that the Act does not apply - the substantive criteria must be assessed first.[2]
Entities that met the criteria on 3 April 2026 generally have 12 months to comply with Chapter 3 obligations, meaning until 3 April 2027. An essential entity must arrange its first statutory audit within 24 months, which for entities covered from the date the amendment entered into force generally leads to 3 April 2028. Transitional provisions preserve specific arrangements for former operators of essential services.[2]
Information security management system under Article 8
Article 8 requires an information security management system in the information system used in processes affecting service delivery. The system must provide systematic risk assessment and risk management together with technical and organisational measures that are appropriate and proportionate to the assessed risk.[2]
Proportionality does not mean discretion without evidence. The Act requires consideration of factors including the state of the art, implementation cost, entity size, likelihood of incidents, risk exposure and social and economic impact.[2]
The measures cover areas including security policies and risk analysis, secure acquisition, development and maintenance of systems, testing, physical and personnel security, access control, supply-chain security, business continuity, backup and recovery, monitoring, effectiveness assessment, education, cryptography, authentication, asset management, vulnerability management and incident management.[2]
The Act does not say that every entity must buy a particular SIEM, EDR, firewall or SOC service. What is required is a risk-appropriate outcome. A tool is evidence of compliance only when it is properly configured, assigned to an owner and actually used.
Continuous monitoring is not synonymous with a service marketed as "SOC 24/7". An organisation must design monitoring for the systems and processes within KSC scope so that relevant events can be detected and handled in time. The operating model may be internal, outsourced or co-managed depending on risk and response-time requirements.
Entities covered by Regulation 2024/2690
For specified digital providers and trust service providers, detailed technical and methodological requirements also arise from Commission Implementing Regulation (EU) 2024/2690. It applies, among others, to DNS providers, TLD registries, cloud providers, data centres, CDNs, MSPs, MSSPs, online marketplaces, search engines, social networking platforms and trust service providers.[5]
Those requirements must not be copied automatically to every NIS2 entity. The Regulation has an enumerated scope. For an entity within that scope, however, it is an important audit criterion alongside the KSC.
Management accountability
Article 8c provides that the head of an essential or important entity remains responsible for the cybersecurity obligations of the entity even when some or all duties have been entrusted to another person. Where the head is a collective body and no responsible individual has been designated, all members are responsible.[2]
Article 8d requires management decisions concerning the ISMS, adequate financial planning, allocation of cybersecurity tasks, supervision of their performance, staff awareness and compliance.[2]
Article 8e creates a specific training obligation: the head of the entity and a person entrusted with the cybersecurity duties of the head must undergo training once in each calendar year, and participation must be documented.[2]
Outsourcing does not transfer this responsibility. A provider may operate a SOC, administer tools, perform audits or prepare incident-notification material, but management decisions and statutory accountability remain with the regulated entity.
Significant incident - the 24-hour / 72-hour / one-month clock
An essential or important entity submits an early warning of a significant incident without undue delay and no later than 24 hours after detection to the competent sectoral CSIRT. It then submits the incident notification without undue delay and no later than 72 hours after detection.[2]
| Stage | Deadline | Counted from |
|---|---|---|
| Early warning | within 24 hours | detection of the incident |
| Incident notification | within 72 hours | detection of the incident |
| Final report | within one month | the 72-hour notification |
| Intermediate report | on request | a request of the sectoral CSIRT |
These deadlines are not "time to start analysing". The organisation needs a classification procedure, assigned roles, communication channels, access to the necessary information and a decision-maker who can act outside normal office hours before an incident occurs.
Not every security event is a significant incident. Classification requires reference to the statutory criteria, applicable secondary legislation and, for entities within Regulation 2024/2690, the thresholds specified in that Regulation.[2][5]
KSC audit
An essential entity performs, at its own cost, a security audit of the information system used in the service-delivery process at least once every three years, counted from the date on which the auditors prepare and sign the report of the previous audit.[2]
A copy of the report must be submitted electronically to the competent cybersecurity authority within three working days after the entity receives it. The authority may order an external audit of an essential entity at any time and of an important entity following a significant incident or another breach of the Act.[2]
The statutory audit is not the same as ISO/IEC 27001 certification, vulnerability scanning or penetration testing. These activities can provide important evidence but answer different questions. ISO/IEC 27001 can help structure an ISMS, but the KSC does not impose a certification requirement.[8]
Auditor independence has both a practical and statutory dimension. A person who performs the tasks specified in Articles 8 and 9-13 for the audited entity, or performed them during the preceding year, may not conduct the Article 15 audit. The Act also specifies qualification and experience requirements for auditors.[2]
KSC and DORA
Special care is required in banking and financial market infrastructures. Article 8i of the KSC excludes a substantial part of the KSC rules on the ISMS and significant-incident reporting for essential or important entities in those sectors, preserving an expressly listed set of provisions and relying on the DORA regime.[2][6]
This means that a full KSC audit programme must not simply be added on top of DORA. Article 8i and the status of the specific entity must be checked first. DORA is not a "lighter version of NIS2"; it is a separate, detailed digital operational resilience regime for the financial sector.[6]
KSC and KRI in the public sector
A public entity may be subject to both the KSC and the Polish National Interoperability Framework (KRI). The 2024 KRI requires an information security management system and an internal information security audit at least annually.[9] The KSC has a different scope, different entity criteria and different supervisory mechanisms.
A single report labelled "KRI/NIS2/GDPR audit" should therefore not be produced without identifying the criteria. Evidence may be collected once where appropriate, but each finding should identify its specific legal basis and scope.
Penalties - an important transitional rule
The amendment introduced high statutory maximum penalties. For an essential entity, the maximum may reach EUR 10 million or 2% of revenue from business activity in the preceding financial year, with the higher amount applying subject to the Act. For an important entity the corresponding limits are EUR 7 million or 1.4% of revenue. In specific cases, the Act provides for a penalty of up to PLN 100 million.[2]
The Act also allows penalties to be imposed on the head of the entity. The upper limit is linked to the remuneration of that person, with a special rule for public entities.[2]
The key timing caveat is Article 35 of the amending Act: the new penalties listed there may be imposed for the first time only after two years have elapsed from entry into force. Since the amendment entered into force on 3 April 2026, this means 3 April 2028.[2]
The sanctions transition is not a security grace period. Chapter 3 obligations have their own transitional deadlines, and organisations should use the period to implement controls and accumulate evidence that the system works.
National strategy
On 10 March 2026 the Council of Ministers adopted the Cybersecurity Strategy of the Republic of Poland, published in Monitor Polski under item 309.[7] It is not a direct source of private-sector obligations in the way the KSC is, but it defines the direction of state policy and the context in which the national cybersecurity system is developing.
How to prepare an organisation
The first step should not be buying a tool but performing legal classification and mapping services. The organisation must determine whether it is essential or important, when it met the criteria and which processes and information systems affect service delivery.
The second step is a gap assessment against Article 8 and any specific legislation. A useful assessment combines documentation with technical evidence: configuration, logs, update status, scan results, recovery tests, incident records, contracts and actual access rights.
The third step is a remediation plan with owners, deadlines and documented risk decisions. A list of gaps without accountability and budget is not a management system.
The fourth step is incident readiness. The organisation should exercise classification of a significant incident, the 24/72-hour clock, decision-maker availability, communication with the CSIRT and collection of information for the final report.
The fifth step is continuous verification. An ISMS should leave evidence of operation: review results, tests, audits, training, vulnerability handling, configuration changes and risk decisions.
10 questions before a KSC audit
- What is the legal basis for classifying the organisation as essential or important?
- Which services and information systems are within scope?
- Do risks have owners, decisions and review dates?
- Does monitoring actually cover systems affecting the service, and is missing telemetry detected?
- Are vulnerabilities and patches prioritised using risk, exposure and information about exploitation?
- Are backups tested by restoration, and does continuity planning cover supplier dependencies?
- Can a significant incident be classified and reported within statutory deadlines outside office hours?
- Does management perform its own duties, including annual training, and retain evidence of supervision?
- Do supplier contracts support supply-chain risk management and access to evidence?
- Can the organisation demonstrate control effectiveness rather than merely the existence of procedures?
Frequently asked questions
- Does the KSC require a 24/7 SOC?
- It does not impose that general label. It requires monitoring and response capabilities appropriate to risk and statutory deadlines. For some services a 24/7 SOC will be a natural way to achieve that result, but the name of the service does not establish compliance.
- Does the KSC require ISO/IEC 27001?
- No. The standard can be a very useful ISMS model and source of evidence, but the KSC does not require ISO/IEC 27001 certification.
- Must an important entity undergo an audit every three years?
- The periodic audit in Article 15(1) is an obligation of an essential entity. The authority may, however, order an external audit of an important entity following a significant incident or another breach of the Act.
- Does outsourcing transfer the responsibility of the head of the entity?
- No. Article 8c expressly preserves that responsibility even when duties are assigned to another person.
- When may the new penalties first be imposed?
- Under Article 35 of the amending Act, after two years have elapsed from 3 April 2026 - that is, from 3 April 2028.
Need consulting in this area?
A free 30-60 minute consultation. No obligations. We discuss needs, scale and a high-level timeline.
Related content
Other competence areas
- IT security audit
- Vulnerability scanning
- Penetration testing
- Device and system hardening
- Email security audit
- KRI compliance audit
- KSC and NIS2 audit
- GDPR compliance audit
- Information security policy
- ISMS - information security management system
- Security awareness - onsite and online
- SOC 24/7 - monitoring and response
Compliance and regulation
Bibliography and sources
Legal and source status checked as of 29 August 2026. National acts link to ELI, EU acts to EUR-Lex.
- [1] regulationParliament of the Republic of Poland (2018). Act of 5 July 2018 on the National Cybersecurity System. Journal of Laws 2018 item 1560, as amended. Consolidated text of the Sejm Chancellery · tekst
- [2] regulationParliament of the Republic of Poland (2026). Act of 23 January 2026 amending the Act on the National Cybersecurity System and certain other acts. Journal of Laws 2026 item 252. Published on 2 March 2026, in force from 3 April 2026 · ELI
- [3] regulationEuropean Parliament and Council of the EU (2022). Directive (EU) 2022/2555 of 14 December 2022 (NIS2). · EUR-Lex
- [4] regulationEuropean Commission (2014). Commission Regulation (EU) No 651/2014, Annex I - the SME definition. · EUR-Lex
- [5] regulationEuropean Commission (2024). Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024. Its scope of application is enumerated · EUR-Lex
- [6] regulationEuropean Parliament and Council of the EU (2022). Regulation (EU) 2022/2554 of 14 December 2022 (DORA). · EUR-Lex
- [7] regulationCouncil of Ministers (2026). Resolution No 92 of the Council of Ministers of 10 March 2026 on the Cybersecurity Strategy of the Republic of Poland. Monitor Polski 2026 item 309. · M.P.
- [8] standardISO/IEC (2022). ISO/IEC 27001:2022 - Information security, cybersecurity and privacy protection - Information security management systems - Requirements. With Amd 1:2024 · ISO
- [9] regulationCouncil of Ministers (2024). Regulation of the Council of Ministers of 21 May 2024 on the National Interoperability Framework. Journal of Laws 2024 item 773. · ELI