NIS2 and KSC

Qualification of the entity, management duties and the course of implementing NIS2 and the Polish national cybersecurity act.

Legal status: August 2026

Preparing for NIS2 and KSC

See also: DPO and GDPR Incidents and Breaches Training and workshops AI Act

Preparing for NIS2 and KSC in your organisationWhether the entity qualifies, which measures apply and how responsibility is divided at board level depend on how the organisation actually works. Let us start by establishing where you stand today — no obligation and no sales preamble. Explore the service

When to apply for the KSC register? — LabLogic article graphic by Michał Rutkowski
NIS2 and KSC

When and how to apply for entry in the KSC register?

The deadline depends on the day the conditions were met. Entities that met them on 3 April 2026 file by 3 October 2026, everyone else has six months. The application is signed by the head of the entity and filed electronically in the system that maintains the register.

A score is not an implementation plan — LabLogic article graphic by Michał Rutkowski
NIS2 and KSC

What should a NIS2 gap analysis contain?

A gap analysis has to let the board take three decisions. What the organisation must meet, where it falls short and in what order it closes the difference. The act does not prescribe the form, so one thing decides its value.

Does every organization fall under NIS2? — LabLogic article graphic by Michał Rutkowski
NIS2 and KSC

Does every organization fall under NIS2?

Not every organization does, but every organization has to check. Qualification turns on the sector from Annex 1 or 2, the size of the entity calculated together with the group, and the categories covered regardless of size. The assessment is self-made, so a negative result also has to be documented.

Scroll to Top