07 October 2026
[kt_reading_time]
KSC 2026–2028 – who does the Act apply to, what needs to be implemented, and by when?


The amendment to the Act on the National Cybersecurity System, which implements the NIS2 Directive, has been in force since 3 April 2026. For many companies and institutions, this means new obligations related to cybersecurity, incident reporting, audits, and management accountability.
Before an organization starts planning KSC implementation, it should determine two things: whether it is subject to the Act and what status it has. The scope of its obligations, the type of supervision, and the deadlines depend on this.
KSC 2026–2028 – key deadlines
For organizations covered by the new regulations, there are three key dates.
| Deadline | What it means |
|---|---|
| 3 October 2026 | deadline for submitting an application for entry in the KSC Register for entities subject to self-registration |
| 3 April 2027 | deadline for implementing the obligations under the Act and starting to use the S46 system for entities that met the criteria on the date the amendment entered into force |
| 3 April 2028 | deadline for the first mandatory audit for essential entities that were not previously operators of essential services |
Entry in the KSC Register is only the beginning. By 3 April 2027, an organization should have the required processes, documentation, and technical and organizational measures in place. Responsibility for individual areas must also be clearly assigned.
The audit has a separate deadline and its own cycle. The date of 3 April 2028 therefore does not mean there is an extra year to implement KSC requirements.
Who does KSC apply to?
In a typical case, a company determines for itself whether it meets the criteria set out in the Act. It does not wait for an earlier administrative decision granting it a particular status.
The assessment should take into account:
- the actual type of business activity,
- the relevant annex to the Act,
- the size of the enterprise,
- the special rules set out in Article 5.
PKD codes can help, but they should not be the sole basis for the assessment. What matters most is what the organization actually does.
For businesses, company size is also important. The SME criteria for employment and financial data apply here. In some cases, data from partner and linked enterprises must also be included in the calculations.
So a simple test such as “50 employees or EUR 10 million in turnover” can be a starting point, but it is not enough for a final assessment.
Essential entity vs. important entity
Under the basic rules, the classification looks like this:
| Activity | Enterprise size | Status |
|---|---|---|
| Annex No. 1 | large enterprise | essential entity |
| Annex No. 1 | medium-sized enterprise | important entity |
| Annex No. 2 | medium-sized or large enterprise | important entity |
Annex No. 1 includes, among others, energy, transport, banking and financial market infrastructure, healthcare, water and wastewater management, and digital infrastructure. The last category includes, among others, DNS services, cloud computing, and data centers.
Annex No. 2 includes, among others, postal and courier services, waste management, food production and distribution, selected manufacturing sectors, including medical devices and electronics, as well as certain digital service providers.
This is only the basic framework. Article 5 also provides for situations in which an entity’s status is determined under different rules.
When does company size not determine whether KSC applies?
Some organizations are subject to the Act regardless of the standard size thresholds. This includes, among others, DNS service providers, qualified trust service providers, and certain public entities.
Special rules also apply to, among others, electronic communications providers and some entities providing cybersecurity-related services.
The Act also allows a competent authority to designate a specific entity as essential or important by administrative decision.
For this reason, classification should not be treated as a formality. It is a good idea to document the basis on which the organization concluded that it is subject to KSC and which category it falls into. An error at this stage can affect registration, audits, and the type of supervision.
KSC accountability can’t be handed off to IT
The KSC Act requires members of management to complete cybersecurity training and actively oversee implementation. We run training for boards and risk teams covering NIS2 and KSC obligations, incident management and management’s personal liability. Afterwards, you receive documentation you can use during an audit or inspection.What obligations does KSC impose?
Entry in the KSC Register is only the first step. The organization must put its cybersecurity management in order, prepare an incident handling process, and determine who is responsible for meeting each requirement.
In practice, the obligations can be grouped into four areas.
1. Information Security Management System
The ISMS should operate as an ongoing, documented process. It includes, among other things, regular risk assessments and the selection of appropriate organizational and technical measures.
Preparing policies and procedures is not enough. The organization must actually manage security and continuously adjust safeguards to the risks it has identified.
2. Incident handling and reporting
The company must prepare a process for detecting, classifying, handling, and reporting incidents.
A significant incident is reported in stages. An early warning must be submitted to the relevant CSIRT within 24 hours, the formal incident notification within 72 hours, and the final report, as a rule, within one month.
To meet these deadlines, roles, escalation paths, and decision-making rules must be defined in advance. A procedure prepared only after an incident occurs will be too late.
3. Security audit
Essential entities are required to conduct security audits of their information systems. Subsequent audits must be carried out at least once every three years.
For essential entities that were not previously operators of essential services, the deadline for the first audit is 3 April 2028.
Important entities are not subject to the same recurring audit requirement, but they may be subject to inspections and supervisory measures provided for in the Act.
4. Management oversight
The head of the entity is responsible for overseeing compliance with cybersecurity obligations. This includes security organization, division of responsibilities, provision of resources, and oversight of the implementation of adopted measures.
The Act also imposes requirements related to training for members of management and the competence of people responsible for cybersecurity.
Who is responsible for KSC implementation in a company?
KSC is not a project for the IT department alone. Implementation involves several functions, so responsibilities should be divided before the work begins.
| Role | Main responsibility |
|---|---|
| Management Board | oversight, budget, policy approval, allocation of responsibilities, training |
| CISO / security | gap analysis, risk assessment, asset inventory, documentation, ISMS coordination |
| IT | implementation of technical and operational measures |
| Compliance / legal | entity classification, registration, KSC Register, deadlines, compliance records |
| HR | training, onboarding, offboarding, and personnel requirements |
| Procurement | security requirements for suppliers and appropriate contractual provisions |
Without this division, it is easy to end up in a situation where IT is waiting for compliance, compliance is waiting for the CISO, and overall responsibility remains unclear.
Assigning a task to another person does not automatically transfer the responsibility of the head of the entity.
In a multi-member governing body, responsibility rests with the members of that body in accordance with the rules set out in the Act, taking into account the possibility of appointing a person responsible for carrying out the obligations. Delegating work does not replace oversight of how it is carried out.
What penalties does KSC provide for?
The Act distinguishes between the liability of the organization and that of its head.
| Who may be penalized | Amount |
|---|---|
| Essential entity | up to EUR 10 million or 2% of revenue from business activity earned in the previous financial year – whichever amount is higher; minimum PLN 20,000 |
| Important entity | up to EUR 7 million or 1.4% of revenue from business activity earned in the previous financial year; minimum PLN 15,000 |
| Head of a private entity | up to 300% of the remuneration received by the person being penalized |
| Head of a public entity | up to 100% of the remuneration received by the person being penalized |
For penalties imposed on the head of an entity, remuneration is calculated according to the rules used to calculate cash compensation for unused leave.
For infringements causing, among other things, a direct and serious cyber threat to national security, public security and public order, human life and health, or a risk of serious damage or disruption to service delivery, the Act also allows a penalty of up to PLN 100 million to be imposed on the entity.
In certain situations, temporary suspension from management duties may also be possible. Management liability may also involve the risk of recourse claims.
Where should KSC implementation start?
The first step is to determine whether the organization is subject to the Act and what status it has. Only then can the scope of obligations be defined, responsibilities assigned, and an implementation plan prepared.
In practice, the process looks like this:
- determining the actual type of activity and the size of the organization,
- checking the relevant annexes and the rules set out in Article 5,
- determining the entity’s status,
- determining how the entity should be entered in the KSC Register,
- assigning owners to individual obligations,
- conducting a gap analysis,
- preparing an implementation roadmap.
For entities subject to self-registration, the deadline for submitting an application for entry in the KSC Register is 3 October 2026.
By 3 April 2027, entities that met the criteria on the date the amendment entered into force should have implemented the obligations arising from the new regulations.
A good gap analysis shows exactly what is missing, who should address it, and in what order. Based on this, the organization can prepare an implementation roadmap instead of running several disconnected projects under the common label of “NIS2.”
What comes next after KSC classification?
Once the organization’s status has been determined, the next stages of work can begin:
- KSC implementation roadmap – how to turn the requirements of the Act into tasks, owners, and deadlines,
- ISMS under KSC – how to organize the information security management system,
- incident handling – how to prepare the company to report within 24 hours, 72 hours, and one month,
- supply chain security – how to manage supplier risk and contractual requirements,
- management board obligations – how to organize oversight and document compliance with the obligations.
If the organization is subject to KSC, the next step should be a gap analysis and a work roadmap leading up to 3 April 2027.

Łukasz Ratajczyk
Łukasz Ratajczyk
CTO
CTO with 12 years of experience across various industries. Specializes in optimizing cloud environments and modernizing infrastructure. A certified cloud architect, he leads a team of experienced DevOps engineers at Tenesys. Outside of work, he is a traveler and mountain biker.
Read also:
KSC Register Entry by October 3, 2026. Who Does It Apply To and How Should You Prepare?
If an organization meets the criteria for an essential or important entity under the KSC Act, it is responsible for determining its status and registering in the KSC Register. For entities that met the statutory criteria on the date the new regulations came into force, the deadline for submitting an application is October 3, 2026….Managing Cloud & SaaS Risk for Small FinTechs: A DORA Survival Guide
Imagine a regulatory auditor walking into your office tomorrow. They do not just ask to see your signed vendor contracts. Instead, they demand real proof of how you monitor the security of every single SaaS platform your team uses daily. For small FinTechs, this scenario triggers immediate panic. The legal officer is drowning in technical…Managing ICT Third-Party Risk – How to Audit Your Cloud & Software Vendors?
Your company likely relies on dozens of cloud tools and external SaaS platforms. Under the Digital Operational Resilience Act, you are legally accountable for the security flaws of every single one. If a niche vendor leaks data, regulators hold your financial institution responsible for the failure. This shift leaves compliance and security teams facing an…





