NIS2 / KSC / CYBERSECURITY

NIS2 and local law KSC: preparation and effective implementation for organizations

I help define the scope of obligations, assess readiness, and translate requirements into responsibilities, priorities, and actions that can be maintained and demonstrated during an audit. A single process connecting management decisions with the actions of legal, compliance, IT, and cybersecurity teams.

Nearest deadline: 3 October 2026 — entry in the KSC Register.

KEY KSC DEADLINES

April 3, 2026

KSC amendment in force

The act implementing the NIS2 directive has entered into force.

NEAREST DEADLINE

October 3, 2026

Deadline for entry into the KSC Register

For entities meeting the criteria on April 3, 2026, that have not been entered ex officio.

April 3, 2027

End of adaptation period

Deadline for starting to use S46 and implementing obligations arising from the act.

April 3, 2028

First security audit

Deadline for the first audit of essential entities; further audits at least every three years.

The 3 October 2026 deadline comes from a ministerial announcement rather than directly from the act, so it may change. For entities that start meeting the criteria later, deadlines are generally counted from the moment the criteria are met. The scope and schedule are confirmed individually. This information is general in nature and does not constitute individual legal advice.

Does this apply to your organisation?

PRIMARY PATH

1

Type of activity

Qualification follows actual activity, not the registered scope of business.

2

Size of the organisation

Thresholds are assessed together with linked and partner enterprises.

Both conditions must be met together.

or

SPECIAL PATH

3

Special criteria

Some entities are covered regardless of their size.

Size of the organisation is then not assessed.

The organisation is covered by the KSC Act

From that moment, not from an administrative decision.

Entry in the KSC Register

It follows from qualification rather than creating it — the duty arises earlier.

The assessment should be documented even when it ends with „we are not covered”.

Documentation is proof of system operation, not an end in itself. The recorded qualification assessment is the first such piece of evidence.

When is support needed?

The starting point may vary. The working method remains structured and adapted to the actual need.

Uncertain status

It is unclear whether the organization is subject to KSC and what obligations apply.

No plan

Priorities, roles, and a realistic implementation sequence are needed.

Implementation in progress

Actions are ongoing, but there is a lack of consistency, pace, or evidence of completion.

Audit preparation

Verification of readiness, documentation, and process operations is needed.

Implementation covers three interconnected areas

Management and responsibility

  • Roles of management and process owners
  • Scope of decisions and oversight
  • Risk associated with services and assets

Operational resilience

  • Incidents and communication
  • Business continuity and testing
  • Suppliers and supply chain

Evidence and audit readiness

  • Plan, actions, and responsibilities
  • Documentation consistent with the actual state
  • Measurable progress and complete evidence

How does the project proceed?

Each stage concludes with a specific result and a decision on the next step.

STEP 1

Scope identification

We establish whether and to what extent the organization is covered by NIS2 and the KSC Act, and what obligations follow from it.

STEP 2

Gap and risk analysis

I compare the actual state with the requirements and point out priorities and the decisions that belong to the board.

STEP 3

Implementation plan

We agree on roles, the order of actions and milestones, so that the implementation has an owner and a deadline.

STEP 4

Implementation support

I lead the changes in documentation and processes and prepare the teams for their new obligations.

STEP 5

Maintenance and audit

I check that the adopted solutions work and update them after changes in the organization and in the law.

In projects combining cybersecurity and data protection, the scope can be coordinated with external DPO / IOD support.

How to tell if the implementation is working?

Six statements that should simply be true after a good implementation.

The board knows who owns which risk.

The risk analysis has a date, an author and a management decision.

The incident reporting procedure has been rehearsed, not only written.

Supplier contracts carry security requirements, and someone checks them.

A change in the organisation leaves a trace in the documentation, not in an inbox.

An auditor receives a complete set of evidence without a week of preparation.

Organizational capabilities

Clear decisions

Management receives the information needed to act.

Implementation control

Progress, responsibilities, and delays are visible.

Lasting readiness

The system is maintained, tested, and updated.

Collaboration and tools

Support does not replace existing teams. It organises responsibility and helps translate requirements into actions for process owners, IT and suppliers.

LabLogic’s role

Qualification, analysis, priorities, coordination, recommendations, and control of the agreed scope’s implementation.

Organization’s role

Management decisions, access to information, designation of action owners, and implementation of changes in processes and safeguards.

Role of IT and suppliers

Technical information, security implementation, testing, and evidence of completion.

Application for KSC compliance — Red Into Green

Depending on the scope, the Red Into Green application can support the recording of risks, actions, responsibilities, incidents, and evidence. The tool organizes work but does not replace expert assessment or organizational decisions.

Support requiring the combination of several perspectives

Effective KSC implementation combines law, security, technology, processes, and management responsibility. I work at the intersection of these areas, supporting organizations from diagnosis to maintaining readiness.

Over 20 years of experience

Knowledge of systems, services, suppliers, and the realities of the organization’s operations.

Law, IT, and cybersecurity in one process

I translate requirements into risks, decisions, and concrete actions.

Working with complex organizations

Communication tailored to management and cooperation with legal, compliance, and IT departments.

Frequently asked questions

How to determine if an organization is subject to KSC?

We start with the type of services provided, sector, scale of operations, and the organization’s role. Then we organize the criteria and confirm the scope of obligations, considering the current legal status.

Do I support the organization in full implementation?

Yes. I support the organization in planning and conducting the implementation — from qualification and gap analysis, through action plans, documentation, and team preparation, to readiness verification. Responsibility for decisions and actions remains with the organization.

How does cooperation with the current IT or compliance department look?

We build a single, common plan and a clear division of responsibilities. We utilize existing safeguards and processes, and fill in missing elements without creating unnecessary bureaucracy.

What is the Red Into Green application used for?

The Red Into Green application helps organize risks, actions, responsibilities, incidents, and evidence. It is professional support for project implementation but does not replace joint analysis or organizational decisions.

How long does the project take?

The time depends on the scope of obligations, the organization’s maturity, and the number of required changes. After a diagnostic conversation, I propose stages, priorities, and a realistic schedule instead of a single rigid declaration.

What information is needed at the beginning?

A brief description of the organization, main services, current security management approach, and stage of preparation is sufficient. Confidential documents and incident details are shared only after agreeing on a secure channel.

Related services

SERVICE

Incidents and breaches

When an incident occurs, the organization may need a separate assessment, coordination of decisions, communication, and corrective actions.

See incident support →

SERVICE

NIS2 training for boards and management

Implementation requires a shared understanding of responsibilities, risks, and decision-making.

See GDPR and NIS2 training →

Related reading

Questions that come back before filing the application for entry — answered from the wording of the KSC Act.

KNOWLEDGE BASE · NEAREST DEADLINE

When and how to apply for entry in the KSC register?

The deadline, the procedure in the S46 system and the declaration of the head of the entity made under criminal liability.

Read →

KNOWLEDGE BASE

Does every organization fall under NIS2?

Qualifying the entity — the step that has to precede the application.

Read →

KNOWLEDGE BASE

Where should the board begin preparing for NIS2?

The order of management decisions once the status is established.

Read →

KNOWLEDGE BASE

What should a NIS2 gap analysis contain?

Assessing readiness for the obligations under Chapter 3 of the Act.

Read →

KNOWLEDGE BASE

What should NIS2 training for the board cover?

The training obligation of the head of the entity under Article 8e of the KSC Act.

Read →

DIAGNOSTIC CONVERSATION

Let’s determine the right first step for your organization

Initially, a brief description of the situation is enough. After our conversation, I will propose an adequate scope: qualification, gap analysis, an implementation plan, or full implementation support.

Confidential documents and incident details are shared only after agreeing on a secure channel.

BRIEFLY DESCRIBE YOUR SITUATION

The administrator of the data provided in the form is Michał Rutkowski, operating LabLogic Consulting. I use the data to handle inquiries and prepare a response or offer. Details can be found in the Privacy Policy. Do not send passwords, special categories of data, or full incident documentation.

Scroll to Top