07 October 2026

[kt_reading_time]

KSC 2026–2028 – who does the Act apply to, what needs to be implemented, and by when?

Łukasz Ratajczyk

CTO

Linkedin

The amendment to the Act on the National Cybersecurity System, which implements the NIS2 Directive, has been in force since 3 April 2026. For many companies and institutions, this means new obligations related to cybersecurity, incident reporting, audits, and management accountability.

Before an organization starts planning KSC implementation, it should determine two things: whether it is subject to the Act and what status it has. The scope of its obligations, the type of supervision, and the deadlines depend on this.

KSC 2026–2028 – key deadlines

For organizations covered by the new regulations, there are three key dates.

DeadlineWhat it means
3 October 2026deadline for submitting an application for entry in the KSC Register for entities subject to self-registration
3 April 2027deadline for implementing the obligations under the Act and starting to use the S46 system for entities that met the criteria on the date the amendment entered into force
3 April 2028deadline for the first mandatory audit for essential entities that were not previously operators of essential services

Entry in the KSC Register is only the beginning. By 3 April 2027, an organization should have the required processes, documentation, and technical and organizational measures in place. Responsibility for individual areas must also be clearly assigned.

The audit has a separate deadline and its own cycle. The date of 3 April 2028 therefore does not mean there is an extra year to implement KSC requirements.

Who does KSC apply to?

In a typical case, a company determines for itself whether it meets the criteria set out in the Act. It does not wait for an earlier administrative decision granting it a particular status.

The assessment should take into account:

  • the actual type of business activity,
  • the relevant annex to the Act,
  • the size of the enterprise,
  • the special rules set out in Article 5.

PKD codes can help, but they should not be the sole basis for the assessment. What matters most is what the organization actually does.

For businesses, company size is also important. The SME criteria for employment and financial data apply here. In some cases, data from partner and linked enterprises must also be included in the calculations.

So a simple test such as “50 employees or EUR 10 million in turnover” can be a starting point, but it is not enough for a final assessment.

Essential entity vs. important entity

Under the basic rules, the classification looks like this:

ActivityEnterprise sizeStatus
Annex No. 1large enterpriseessential entity
Annex No. 1medium-sized enterpriseimportant entity
Annex No. 2medium-sized or large enterpriseimportant entity

Annex No. 1 includes, among others, energy, transport, banking and financial market infrastructure, healthcare, water and wastewater management, and digital infrastructure. The last category includes, among others, DNS services, cloud computing, and data centers.

Annex No. 2 includes, among others, postal and courier services, waste management, food production and distribution, selected manufacturing sectors, including medical devices and electronics, as well as certain digital service providers.

This is only the basic framework. Article 5 also provides for situations in which an entity’s status is determined under different rules.

When does company size not determine whether KSC applies?

Some organizations are subject to the Act regardless of the standard size thresholds. This includes, among others, DNS service providers, qualified trust service providers, and certain public entities.

Special rules also apply to, among others, electronic communications providers and some entities providing cybersecurity-related services.

The Act also allows a competent authority to designate a specific entity as essential or important by administrative decision.

For this reason, classification should not be treated as a formality. It is a good idea to document the basis on which the organization concluded that it is subject to KSC and which category it falls into. An error at this stage can affect registration, audits, and the type of supervision.

our service

KSC accountability can’t be handed off to IT

The KSC Act requires members of management to complete cybersecurity training and actively oversee implementation. We run training for boards and risk teams covering NIS2 and KSC obligations, incident management and management’s personal liability. Afterwards, you receive documentation you can use during an audit or inspection.

What obligations does KSC impose?

Entry in the KSC Register is only the first step. The organization must put its cybersecurity management in order, prepare an incident handling process, and determine who is responsible for meeting each requirement.

In practice, the obligations can be grouped into four areas.

1. Information Security Management System

The ISMS should operate as an ongoing, documented process. It includes, among other things, regular risk assessments and the selection of appropriate organizational and technical measures.

Preparing policies and procedures is not enough. The organization must actually manage security and continuously adjust safeguards to the risks it has identified.

2. Incident handling and reporting

The company must prepare a process for detecting, classifying, handling, and reporting incidents.

A significant incident is reported in stages. An early warning must be submitted to the relevant CSIRT within 24 hours, the formal incident notification within 72 hours, and the final report, as a rule, within one month.

To meet these deadlines, roles, escalation paths, and decision-making rules must be defined in advance. A procedure prepared only after an incident occurs will be too late.

3. Security audit

Essential entities are required to conduct security audits of their information systems. Subsequent audits must be carried out at least once every three years.

For essential entities that were not previously operators of essential services, the deadline for the first audit is 3 April 2028.

Important entities are not subject to the same recurring audit requirement, but they may be subject to inspections and supervisory measures provided for in the Act.

4. Management oversight

The head of the entity is responsible for overseeing compliance with cybersecurity obligations. This includes security organization, division of responsibilities, provision of resources, and oversight of the implementation of adopted measures.

The Act also imposes requirements related to training for members of management and the competence of people responsible for cybersecurity.

Who is responsible for KSC implementation in a company?

KSC is not a project for the IT department alone. Implementation involves several functions, so responsibilities should be divided before the work begins.

RoleMain responsibility
Management Boardoversight, budget, policy approval, allocation of responsibilities, training
CISO / securitygap analysis, risk assessment, asset inventory, documentation, ISMS coordination
ITimplementation of technical and operational measures
Compliance / legalentity classification, registration, KSC Register, deadlines, compliance records
HRtraining, onboarding, offboarding, and personnel requirements
Procurementsecurity requirements for suppliers and appropriate contractual provisions

Without this division, it is easy to end up in a situation where IT is waiting for compliance, compliance is waiting for the CISO, and overall responsibility remains unclear.

Assigning a task to another person does not automatically transfer the responsibility of the head of the entity.

In a multi-member governing body, responsibility rests with the members of that body in accordance with the rules set out in the Act, taking into account the possibility of appointing a person responsible for carrying out the obligations. Delegating work does not replace oversight of how it is carried out.

What penalties does KSC provide for?

The Act distinguishes between the liability of the organization and that of its head.

Who may be penalizedAmount
Essential entityup to EUR 10 million or 2% of revenue from business activity earned in the previous financial year – whichever amount is higher; minimum PLN 20,000
Important entityup to EUR 7 million or 1.4% of revenue from business activity earned in the previous financial year; minimum PLN 15,000
Head of a private entityup to 300% of the remuneration received by the person being penalized
Head of a public entityup to 100% of the remuneration received by the person being penalized

For penalties imposed on the head of an entity, remuneration is calculated according to the rules used to calculate cash compensation for unused leave.

For infringements causing, among other things, a direct and serious cyber threat to national security, public security and public order, human life and health, or a risk of serious damage or disruption to service delivery, the Act also allows a penalty of up to PLN 100 million to be imposed on the entity.

In certain situations, temporary suspension from management duties may also be possible. Management liability may also involve the risk of recourse claims.

Where should KSC implementation start?

The first step is to determine whether the organization is subject to the Act and what status it has. Only then can the scope of obligations be defined, responsibilities assigned, and an implementation plan prepared.

In practice, the process looks like this:

  1. determining the actual type of activity and the size of the organization,
  2. checking the relevant annexes and the rules set out in Article 5,
  3. determining the entity’s status,
  4. determining how the entity should be entered in the KSC Register,
  5. assigning owners to individual obligations,
  6. conducting a gap analysis,
  7. preparing an implementation roadmap.

For entities subject to self-registration, the deadline for submitting an application for entry in the KSC Register is 3 October 2026.

By 3 April 2027, entities that met the criteria on the date the amendment entered into force should have implemented the obligations arising from the new regulations.

A good gap analysis shows exactly what is missing, who should address it, and in what order. Based on this, the organization can prepare an implementation roadmap instead of running several disconnected projects under the common label of “NIS2.”

What comes next after KSC classification?

Once the organization’s status has been determined, the next stages of work can begin:

  • KSC implementation roadmap – how to turn the requirements of the Act into tasks, owners, and deadlines,
  • ISMS under KSC – how to organize the information security management system,
  • incident handling – how to prepare the company to report within 24 hours, 72 hours, and one month,
  • supply chain security – how to manage supplier risk and contractual requirements,
  • management board obligations – how to organize oversight and document compliance with the obligations.

If the organization is subject to KSC, the next step should be a gap analysis and a work roadmap leading up to 3 April 2027.

Łukasz Ratajczyk

Łukasz Ratajczyk

CTO

CTO with 12 years of experience across various industries. Specializes in optimizing cloud environments and modernizing infrastructure. A certified cloud architect, he leads a team of experienced DevOps engineers at Tenesys. Outside of work, he is a traveler and mountain biker.

Linkedin