Let’s talk
Wondering how this plays out in your organisation? Get in touch — I answer personally.
Short answer
NIS2 documentation under Article 10 of the Polish Act on the National Cybersecurity System (KSC) concerns the security of the information system used to provide the service, and an essential or important entity develops, applies and updates it (Article 10(1)). Normative documentation covers the documentation of two management systems (information security and business continuity), the documentation of infrastructure protection, the technical documentation of the information system and the documentation arising from the specific nature of the service in the sector or subsector (Article 10(3)). Operational documentation consists of records attesting to the performance of activities required by the normative documentation, including logs (Article 10(4)). The entity establishes control over the documentation and retains it as a rule for at least two years from its withdrawal from use or the end of the provision of the service, and in fact longer because the period is counted from 1 January (Article 10(6) and (7)). Its destruction is confirmed by a disposal report (Article 10(8)). An entity that met the criteria on 3 April 2026 implements these obligations by 3 April 2027 (Article 33(1) of the amending act), and an entity covered later implements them within 12 months of meeting the criteria or of being served with the decision recognising it (Article 16(1), Article 7l(7) and Article 7m(6)). The head of the entity is responsible for the entity’s performance of these obligations, and where the management board has several members all of them are responsible unless a responsible person has been designated (Article 8c). Other obligations also end with a document or record, including incident registration, the annual training of the head of the entity and the audit of an essential entity. Separate rules apply to entities in the banking and financial market infrastructure sectors (Article 8i).
Why this question arises at all
The question “I bought NIS2-compliant documentation. Am I compliant with the KSC Act?” is included in the set of questions and answers of the Minister of Digital Affairs (question 3.7). The Minister replies that purchased documentation “signed by the board and put away in a ‘NIS2 cabinet’” will not ensure real cybersecurity. The set has no legal force, but according to the Minister it is useful in interpreting the provisions. Moreover, the definition in Article 10(4) implies that a ready-made package contains no operational documentation, because that documentation only arises from the organisation’s activity. Ready-made NIS2 documentation can therefore be at most a starting point.
On this point the Polish Act goes further than the Directive. In Article 21(2) the NIS2 Directive lists the minimum elements of cybersecurity risk-management measures, including policies and procedures, but contains no catalogue of documentation. The division into normative and operational documentation is introduced only by Article 10 of the KSC Act, and it is that provision that defines the scope of NIS2 documentation in Poland.
An important entity gets no relief in this respect. Recital 122 of the Directive links the light supervision of important entities with the statement that they should not be required to systematically document compliance with cybersecurity risk-management measures. A recital is not a provision, however, and Article 5 of the Directive does not preclude provisions ensuring a higher level of cybersecurity provided that they are consistent with Member States’ obligations laid down in Union law. Article 10 of the KSC Act applies in the same wording to essential and important entities. The differences lie outside it, for example in the supervisory regime (Article 53(3)) and in the requirements for the information security management system (the “management system”) in an important entity that is a public entity (Article 8(3)).
What has to be established before the board adopts the documentation
NIS2 documentation under Article 10 covers four blocks of obligations. A public entity performs the obligations under Article 10 if it uses an information system to perform a public task (Article 16d). In some public entities these obligations may be taken over by another unit under Article 16e.
| Block | What it covers | Basis | Exceptions and limitations | Deadline |
|---|---|---|---|---|
| Normative documentation | five types of documentation, from the documentation of the information security management system to the documentation arising from the specific nature of the service in the sector or subsector | Article 10(3) | data on a specialised armed security formation only where such a formation protects the infrastructure; the content of the management system documentation depends on the requirements the entity applies (Article 8(1) or Annex 4) | the provision has been in force since 3 April 2026; implementation by 3 April 2027 or within 12 months of meeting the criteria or of being served with the recognition decision |
| Operational documentation | records attesting to the performance of activities required by the normative documentation, including logs | Article 10(4) | the scope is set by the normative documentation | the same deadline |
| Control over the documentation | access only for authorised persons, protection of documents and version marking | Article 10(6) | paragraph 6 provides for no exceptions | the same deadline |
| Retention and disposal | at least two years from the withdrawal of the documentation from use or the end of the provision of the service, counted from 1 January of the year following the year in which the retention period expires; disposal report kept permanently | Article 10(7) and (8) | Article 10(7) does not apply to entities subject to the Act on the National Archival Resource and Archives; paragraph 8 provides for no such exclusion | the same deadline |
Where NIS2 documentation begins and ends
The obligation concerns the documentation of the security of the information system that the entity uses to provide the service (Article 10(1)). Put simply, an information system means devices and software processing data together with the data processed in electronic form (Article 2(14)).
According to the Minister of Digital Affairs the processes of providing services should be analysed, including processes related to the service and required by law such as those serving the exercise of customer or consumer rights (question 3.4). In the Minister’s view the assessment of a system used in these processes should consider among other things whether it is necessary to provide the service and whether it controls processes on which the service depends.
According to the Minister the management system should cover systems related to the activities listed in Annex 1 or Annex 2 to the Act. It should also cover systems needed in the process of providing the service, for example accounting systems without which a public entity cannot provide public services to citizens. In the Minister’s view systems fully separated from the provision of the service and with no impact on it are not subject to the obligation to be covered by the management system (question 3.4). The Minister also treats production as a service (question 14.10). For a manufacturer the criterion of controlling processes may therefore cover production planning and control systems.
A public entity also includes in its management system an information system provided by another public entity, for example a public register system, to the extent of its competences (Article 8(4)).
Article 10(1) refers to the system used in the process of providing the service, while Article 8(1) refers more broadly to the system used in the processes affecting its provision. The documentation of the management system nevertheless belongs to the normative documentation (Article 10(3)(1)). In my assessment the documentation of the management system therefore covers its entire scope and not only the systems used directly to provide the service. The scope of services and systems covered by the management system determines the volume of documentation and the cost of maintaining it. The head of the entity plans adequate financial resources for cybersecurity obligations (Article 8d(2)).
Article 8i(1) disapplies the provisions on the management system in relation to entities in the banking and financial market infrastructure sectors. Article 10 is not among the provisions that apply to them despite that exclusion. In my assessment Article 10 is a provision concerning that system and does not cover those entities, because the first type of normative documentation is the documentation of the management system (Article 10(3)(1)). A different reading may rely on the fact that Article 10(3) also covers the documentation of infrastructure protection and technical documentation. Under both readings Article 10 is not among the provisions whose performance by those entities is subject to supervision and penalties under the KSC Act (Article 8i(3)). According to the Minister the provisions of the DORA Regulation take precedence over the Act in this sector (question 14.2).
What falls to the board
The head of the entity is responsible among other things for the entity’s performance of the obligations under Article 10 (Article 8c(1)). The definition of the head of the entity refers to the Accounting Act and, for a public finance sector unit, to the Public Finance Act (Article 2(8a)). Where the management board has several members the head of the entity means the members of the board excluding persons holding a power of attorney granted by the entity (Article 3(1)(6) of the Accounting Act). The head of the entity also remains responsible where the obligations have been entrusted to another person with that person’s consent (Article 8c(3)).
The Act does not require the board to write the documents itself. The head of the entity decides on the management system from its preparation to its review and supervision (Article 8d(1)). The head also assigns cybersecurity tasks and supervises their performance (Article 8d(3)). The Act therefore does not prohibit assigning the approval of procedures to their owners. Decisions concerning the management system nevertheless remain with the head of the entity (Article 8d(1)).
The Act does not specify the form of the head’s decision. Evidence of the decision may be a board resolution with a date, the scope of services and systems and the designation of the responsible person. The designation matters because without it all members of the board are responsible (Article 8c(2)). In my assessment the designated person should be a member of the board. Article 8c(2) and (3) and Article 4(5) of the Accounting Act regulate the designation of a responsible person separately from entrusting obligations to another person. Designating a person from outside the board is closer to entrusting obligations under Article 8c(3), and such entrusting does not release the head of the entity from responsibility.
Nor is the head of the entity released by entrusting tasks to a security director or to a managed security service provider. The entity sets up internal structures responsible for cybersecurity or concludes an agreement with such a provider (Article 14).
The head of the entity and the person to whom the head’s cybersecurity obligations have been entrusted undergo training once every calendar year. The scope of the training covers among other things the obligations under Articles 9 to 12b, including the documentation obligation, and participation in the training is documented (Article 8e).
Five types of normative documentation
Normative documentation consists of five types of documentation (Article 10(3)).
- documentation of the information security management system;
- documentation of the protection of the infrastructure used to provide the service;
- documentation of the business continuity management system;
- technical documentation of the information system used in the process of providing the service;
- documentation arising from the specific nature of the service provided in the given sector or subsector.
The Act describes the documentation of infrastructure protection in the most detail. It consists of seven elements (Article 10(3)(2)(a) to (g)).
- a description of the service and of the infrastructure in which the service is provided;
- an assessment of the current state of infrastructure protection;
- a risk assessment for the infrastructure facilities;
- a risk treatment plan;
- a description of the technical safeguards of the infrastructure facilities;
- the rules for organising and carrying out the physical protection of the infrastructure;
- data on a specialised armed security formation protecting the infrastructure, provided only where such a formation exists.
The Act does not list the content of the documentation under Article 10(3)(3) to (5). The obligation to document business continuity plans, contingency plans and disaster recovery plans follows from Article 8(1)(2)(f).
The content of the management system documentation depends on the requirements the entity applies. These are usually set by Article 8(1), and according to the Minister the documentation of that system should include all the elements indicated in Article 8 (question 3.5).
An important entity that is a public entity applies the requirements of Annex 4 instead of Article 8(1). The same applies to the important entities from the higher education and science system indicated in Article 8(3), excluding research organisations. Both groups apply the requirements of the Annex to the extent of public tasks performed using information systems. Part IV of the Annex requires documenting the performance of the actions indicated in the management system. According to the Minister the regulation on the National Interoperability Framework remains in force until an amendment removes from it the provisions on implementing the management system. The amendment is to be made by 22 February 2027 (question 14.12).
According to the Minister an important entity that is a public entity applying Annex 4 “formally has no obligation to carry out a risk assessment” (question 3.15). The answer does not, however, refer to Article 10(3)(2)(c). The Annex replaces only Article 8(1) and not Article 10. In my assessment the documentation of infrastructure protection, including the risk assessment for its facilities, therefore also concerns those entities.
The entities indicated in Article 8b(1), among them cloud computing service providers, apply within the management system the measures set out in Commission Implementing Regulation (EU) 2024/2690. Entities from the electricity subsector recognised as high-impact or critical-impact entities additionally apply the measures set out in Commission Delegated Regulation (EU) 2024/1366 (Article 8b(3)).
Documentation may be kept in paper or electronic form (Article 10(5)). The Minister accepts that an organisation whose management system has been implemented according to a standard may use and adapt its existing documentation (question 3.6).
However, documentation compliant with ISO/IEC 27001 does not necessarily cover the whole of Article 10. Certification sometimes covers only part of the services and systems covered by the Act. Among other things the standard also does not require documentation of infrastructure protection in seven elements or a disposal report with the content set out in Article 10(8).
Operational documentation as evidence that procedures work
Operational documentation consists of records attesting to the performance of activities required by the provisions of the normative documentation, including records generated automatically in system logs (Article 10(4)). If a procedure requires an access rights review once a quarter, the operational documentation is the record of each such review. If the business continuity plan provides for a test of restoring from backup, the operational documentation is the report of each test.
The provision expressly names logs, that is automatic records of events. They attest to the operation of continuous monitoring of the information system (Article 8(1)(2)(g)) and make it possible to reconstruct the course of events after an incident.
Staff education is a mandatory element of the management system (Article 8(1)(2)(i)), so records of training provided for in the normative documentation belong to the operational documentation. The composition of such records is described in How to document training so that it serves as evidence for the authority?.
How NIS2 documentation is protected
The entity establishes control over the documentation. This control must meet three conditions (Article 10(6)).
- Access to documents is limited to persons authorised in accordance with the tasks they perform.
- Documents are protected against damage, destruction and loss. They are also protected against unauthorised access, improper use or loss of integrity.
- Successive versions of documents are marked so that the changes made can be identified.
According to the Minister evidence of the assignment of access to the documentation must be presented at the request of the inspectors (question 3.5). Version marking makes it possible to show during an inspection or after an incident which procedure applied on a given day.
How long NIS2 documentation is retained
The entity retains the documentation for at least two years from the day of its withdrawal from use or the end of the provision of the service (Article 10(7)). According to the provision the period is “counted from 1 January of the year following the year in which its retention period expires”. In my assessment a reading that takes both parts of the provision into account allows the documentation to be destroyed at the earliest on 1 January of the third year after the year of its withdrawal. Documentation withdrawn in 2027 could thus be destroyed at the earliest on 1 January 2030. The provision also allows a reading under which destruction would be possible only from 1 January 2032. A cautious entity may adopt a longer period in its retention and disposal policy. Article 10(7) does not apply to entities subject to the Act on the National Archival Resource and Archives. Article 10(8) provides for no such exclusion.
The destruction of withdrawn documentation is confirmed by a disposal report (Article 10(8)). The report contains in particular the date of the report, the identification of the destroyed documentation, a description of the method of destruction and the details of the approving person. Disposal reports are kept permanently.
The retention and disposal rules also cover logs as operational documentation. A log that has ceased to be used must be retained for at least two more years (Article 10(7)). It is therefore worth defining in the retention and disposal policy the moment at which a log is withdrawn from use. In my assessment the wording of Article 10(8) implies that automatic log rotation also requires a disposal report. A report will not replace the minimum period, however, so rotation in a shorter cycle will not satisfy Article 10(7).
One solution may be a periodic report for a whole category of records. Alongside the elements of Article 10(8) it would indicate the system, the type of logs and the date range. The default rotation settings are worth checking in every system and cloud service. The log archive is protected against loss of integrity (Article 10(6)(2)). Logs usually contain personal data, such as IP addresses. The record of processing activities states, where possible, the envisaged time limits for erasure of those data (Article 30(1)(f) GDPR). Retention longer than the KSC Act requires must be separately justified (Article 5(1)(e) GDPR).
Documents and records outside Article 10
Besides Article 10 the Act provides for other obligations that end with a document or record.
- The head of the entity allows a person to perform tasks under Article 8 or Article 11 only after receiving information from the National Criminal Register that the person has not been convicted of offences against the protection of information (Article 8f(1)). A valid security clearance granting access to classified information marked “confidential” or higher replaces the information from the register (Article 8f(3)).
- Incident handling includes incident registration (Article 2(10) and Article 11(1)(1)).
- An essential entity carries out an audit at least once every three years and provides the authority with a copy of the report within 3 working days of receiving it (Article 15(1) and (1a)). If it met the criteria on 3 April 2026, it carries out its first audit by 3 April 2028 (Article 33(2) of the amending act).
Deadline, supervision by the authority and penalties
The amending act entered into force on 3 April 2026 (Article 49 of the amending act). Entities that met the criteria for recognition as essential or important on that day perform the obligations under Chapter 3 of the KSC Act within 12 months of that date (Article 33(1) of the amending act). The obligation under Article 10 belongs to that chapter, so the deadline expires on 3 April 2027. An entity that meets the criteria later has 12 months from the day on which it meets them (Article 16(1)). An entity recognised as essential or important by a decision counts 12 months from the service of that decision (Article 7l(7) and Article 7m(6)).
The supervisory authority may carry out inspections (including remote ones) and request access to documents and evidence of the implementation of the requirements of Article 8(1) (Article 53(2)(1), (5) and (6) and Article 53(17)). In relation to an important entity the authority exercises ex post supervision, in particular where there is a justified suspicion of a possible infringement of the Act (Article 53(3)(2)).
A request to provide documents sets a time limit adequate to its scope and not shorter than 7 days (Article 53c(2)(5)). Failure to comply with such a request is a separate ground for a penalty on the entity (Article 73(1)(15)). During an inspection an entrepreneur presents the requested documents without delay (Article 56(1)). The ex post nature of supervision therefore does not release the entity from being ready, because operational records for a past period cannot be produced in a few days. According to the Minister what is required is proof of applying the provisions of the Act, not the presentation of formally correct documents (question 11.6).
A financial penalty applies to an entity that does not perform the obligations under Article 10(1), also in the case of a one-off omission (Article 73(1)(4) and (1b)). For an essential entity the upper limit of the penalty is EUR 10 000 000 or 2% of revenue from business activity in the previous financial year, whichever is higher (Article 73(3)). For an important entity it is EUR 7 000 000 or 1.4% of revenue (Article 73(4)). Article 73(4) does not say which amount applies. For infringements of cybersecurity risk-management measures the NIS2 Directive provides for the higher amount, although it calculates the percentage on the worldwide turnover of the undertaking to which the entity belongs (Article 34(5) of the Directive).
The head of the entity may be subject to a penalty for failure to perform at least one of the obligations under Article 10(1) and (6) to (8) (Article 73a(1)(8)). The condition is that the duration, scope or nature of the infringement justifies it. The penalty may also be imposed for a one-off omission and irrespective of the penalty on the entity (Article 73a(2) and (3)). It amounts to up to 300% of remuneration calculated according to the rules for determining the cash equivalent for annual leave, and in a public entity as a rule up to 100% (Article 73a(4) and (5)).
The penalty on the entity and the penalty on the head of the entity may be imposed at the earliest after 3 April 2028 (Article 35 of the amending act). The deferral does not cover the penalty of up to PLN 100 000 000 under Article 73(5), which the Minister calls extraordinary (questions 12.1 and 12.6). The provision links it with an infringement causing a direct and serious cyber threat to defence, state security, public security and order or human life and health. It also mentions the threat of causing serious property damage or serious disruption to the provision of services. The Minister joins the two effects with the conjunction “and”, which does not appear in the provision (question 12.6). Nor does the deferral cover supervisory measures under Article 53, such as a warning and orders, or the implementation deadline.
Conclusions and next steps
Remember
NIS2 documentation serves as evidence when the normative documents describe the organisation’s actual activities and the operational records confirm them.
It is therefore worth starting the work with a board decision rather than with a template.
- Adopt a resolution on the scope of services and systems covered by the documentation and designate the responsible person on the board.
- Commission a comparison of existing documents with the five types of normative documentation.
- Set up a documentation register with the owner, version, review date and withdrawal date of each document.
- Approve a retention and disposal policy that also covers logs.
- Plan a budget for maintaining the documentation and the log archive.
- Check whether the participation of the board and of the person entrusted with the head’s obligations in the annual training is documented.
- Ask the five control questions at a board meeting every quarter and record the answers in the minutes.
The board can check the state of NIS2 documentation with five control questions.
- Which services and systems have we covered by the documentation and who approved that scope?
- Does each normative document have an owner, a version number and the date of its last review?
- Can we show records of the performance of three procedures selected by the board for the last quarter?
- What did we change in the documentation after the last system change or the last incident?
- Who has access to the documentation, how long do we keep logs and who approves the disposal report?
Related materials
- What risk management measures must an essential entity implement? — the system whose operation the documentation attests to.
- What should a NIS2 gap analysis contain? — comparing the current state with the requirements of the Act.
- How to document training so that it serves as evidence for the authority? — training records as part of the operational documentation.
- Where should the board begin preparing for NIS2? — the order of the board’s decisions.
Sources
- Act of 5 July 2018 on the National Cybersecurity System, consolidated text as at 18 August 2026 — Article 2(8a), (10) and (14), Article 7l(7), Article 7m(6), Article 8, Article 8b(1) and (3), Articles 8c to 8f, Article 8i(1) and (3), Articles 9 to 12b, Article 14, Article 15(1) and (1a), Article 16, Article 16d, Article 16e, Article 53(2) to (5) and (17), Article 53c, Article 56(1), Article 73, Article 73a and Annexes 1, 2 and 4 (in Polish) — isap.sejm.gov.pl.
- Act of 23 January 2026 amending the Act on the National Cybersecurity System and certain other acts (Journal of Laws 2026, item 252) — Article 33(1) and (2), Article 35 and Article 49 (in Polish) — isap.sejm.gov.pl.
- Accounting Act of 29 September 1994 (consolidated text, Journal of Laws 2026, item 522, as amended) — Article 3(1)(6) and Article 4(5) (in Polish) — isap.sejm.gov.pl.
- Public Finance Act of 27 August 2009 (in Polish) — isap.sejm.gov.pl.
- Act of 14 July 1983 on the National Archival Resource and Archives (in Polish) — isap.sejm.gov.pl.
- Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 (NIS2) — Article 5, Article 21(2), Article 34(5) and recital 122 — eur-lex.europa.eu.
- Regulation of the Council of Ministers of 21 May 2024 on the National Interoperability Framework, minimum requirements for public registers and the exchange of information in electronic form and minimum requirements for ICT systems (Journal of Laws 2024, item 773) (in Polish) — isap.sejm.gov.pl.
- Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 (DORA) — eur-lex.europa.eu.
- Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 — eur-lex.europa.eu.
- Commission Delegated Regulation (EU) 2024/1366 of 11 March 2024 — eur-lex.europa.eu.
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) — Article 5(1)(e) and Article 30(1)(f) — eur-lex.europa.eu.
- Minister of Digital Affairs, National cybersecurity system — questions and answers on the amendment of the KSC Act, update of June 2026 — questions 3.4 to 3.7, 3.15, 11.6, 12.1, 12.6, 14.2, 14.10 and 14.12 (in Polish) — gov.pl.
Let’s check that the documentation describes what you actually do
Documentation is best reviewed before the deadline, not before an inspection. NIS2 and KSC readiness support covers determining the scope of systems, reviewing normative and operational documentation and adopting rules for control and retention.
This material is general and educational in nature. It is not an individual legal opinion or a recommendation for any specific organisation. The scope of the obligations should be assessed against the situation of the organisation concerned.
Legal status: October 2026.