Where should the board begin preparing for NIS2?

Michał Rutkowski • for the board and management • published June 23, 2026 • updated September 12, 2026 • 8 min read

Short answer

With two decisions that the board itself must make. These are who in the organization is the entity manager within the meaning of the KSC Act, and whether the entity’s qualification has been determined and documented. Only after these does a gap analysis, implementation plan, and budget make sense—without them, the organization finances work whose scope no one can justify. The Act does not allow the entity manager’s responsibility to be transferred to the IT department or to a vendor, so the first decision is a board decision, not a task to be delegated.

Why this question arises at all

Preparation for NIS2 is sometimes initiated from the middle. The board learns that the organization is subject to new regulations, assigns the matter to the IT or compliance department, and after a few weeks receives a list of missing procedures and a quote for tools. The question of sequence returns only when an expenditure must be approved that no one can link to a specific obligation.

The source of this confusion is the structure of the regulations. Directive (EU) 2022/2555 itself binds the Member State, not the business—an organization’s obligations arise from the Act on the National Cybersecurity System (KSC) as amended by the amendment of January 23, 2026, which entered into force on April 3, 2026. The Act changes something that was not so clear in the previous legal state. It places responsibility for performing cybersecurity obligations on the entity manager (Article 8c), imposes on them an obligation to undergo documented training once per calendar year (Article 8e), and provides for a separate financial penalty for that person—up to 300% of their remuneration, and up to 100% in a public entity (Article 73a(4) and (5))—independent of the penalty imposed on the entity.

Cybersecurity therefore ceases to be a matter that the board can simply acknowledge. It becomes an area in which the board makes decisions and must be able to show the basis on which it made them.

The second reason is the calendar. Entry in the KSC Register for entities registering on application falls within the period until October 3, 2026, the adaptation period ends on April 3, 2027, and the twenty-four-month deadline for the first audit of essential entities expires on April 3, 2028; after that date financial penalties may also be imposed for the first time—the deferral does not cover only the extraordinary penalty of up to PLN 100 million. The registration schedule itself does not follow from the Act but from the communication of the Minister of Digitization of April 8, 2026, which the minister may amend; the date of October 3, 2026 applies to entities that met the criteria on April 3, 2026, while an organization that meets them later has six months from that moment to submit the application—for entry ex officio, the deadline runs from service of the summons. These dates are not an argument for haste. However, they determine which work must be completed this year and which has until April 3, 2027.

What should the board know?

Responsibility for performing obligations under the KSC Act rests with the entity manager and cannot be transferred by contract or resolution—tasks can be delegated, not responsibility. The entity manager has an obligation to undergo documented cybersecurity training, and the Act provides for a separate financial penalty for them, in addition to the penalty for the entity.

Entity qualification is based on self-assessment. No one will notify the organization that it is subject, and the result of the assessment—including a negative one—should be documented. The scope of implementation depends on the entity’s category and what the organization already has, so a budget set before a gap analysis is a guessed budget. Deadlines divide the work into two stages. The first is registration in 2026, the second is implementation and connection to the S46 system by April 3, 2027.

What must be determined before the decision

Who is the entity manager and what the Act requires of them

This question sounds formal but determines everything else. In organizations with a multi-member board, responsibility applies to the body, but practice requires identifying a person who leads the matter, reports it to the board, and is responsible for the completeness of decision-making materials. In capital groups, qualification and status are determined separately for each entity, so there are as many entity managers as there are companies covered by the Act—a common group project does not replace this.

From this determination, three things follow that the board should ask at the first meeting devoted to this matter. These are who is responsible by name, what training they have completed or will complete, and by what procedure they receive information about incidents. The third question is most often omitted, yet it determines the ability to report a serious incident within the required timeframe—early warning within 24 hours of detecting a serious incident and notification within 72 hours, also counted from detection and not from the early warning.

Whether qualification is determined and documented

Remember

Qualification is not a formality opening the project, but its foundation.

It determines whether the organization is an essential or important entity, and from that—whether it must plan an audit cycle and under what supervisory regime it will operate. The criteria and method of self-assessment are set out in Does every organization fall under NIS2?. What the board should receive from that assessment is a concrete result.

A useful qualification result is not the sentence “we are subject.” It is a brief document. It records which lines of business were assigned to sectors from the annexes of the Act, how the entity’s size was calculated taking into account related and partner enterprises, what category was adopted, and who approved this conclusion. Without this record, the board has no way to demonstrate that the decision was informed—and with a negative qualification result, this document is the only trace that it was conducted at all.

What the organization already has

Preparation for NIS2 rarely starts from scratch. Organizations with a certified information security management system, with implemented GDPR, with a functioning incident response procedure, or with obligations arising from the DORA regulation already have some of the required elements—usually in a different arrangement and under a different name.

Establishing the starting point is the step that most strongly affects cost. A board that orders “NIS2 implementation” without this inventory usually pays for duplication of already existing procedures and for documentation describing processes that the organization does not conduct. Documentation should show how the organization actually operates; if it describes an invented state, during an audit it works against it.

The practical scope of this review is finite. It covers risk analysis and its currency, access and authorization management, backups with recovery testing, event logging, incident reporting and response procedure, business continuity plan, requirements for suppliers in existing contracts, and verification of the criminal record of persons performing tasks related to the information security management system and to incident handling—information from the National Criminal Register on the absence of convictions for offences against the protection of information, whereby a valid security clearance at the “confidential” level or higher replaces this requirement.

Who is responsible for what on the operational side

The entity manager’s responsibility does not eliminate the need to assign tasks. The Act requires, among other things, the designation of at least two persons responsible for contacts with entities of the national cybersecurity system; one person is sufficient only for a micro or small enterprise and for an important entity that is a public entity. In practice, process owners and risk owners are also needed—that is, people who can say what will happen to a specific service when a specific system is unavailable.

A common organizational arrangement looks like this. Security formally belongs to IT, but decisions about priorities are made in business lines, and no one has a mandate to resolve disputes between them. In such an arrangement, implementation stops at the risk analysis stage, because assessing the consequences of process interruption requires input from the business, and the business does not feel it owns the matter. Resolving this issue is a management decision, not a technical one.

What board decisions determine the pace

Three decisions actually condition the progress of work, and none of them can be made at a lower level. The first is the level of risk that the organization accepts—without it, risk analysis ends with a list of threats without a conclusion. The second is the financial and human resources assigned to tasks, along with a determination of what the organization does independently and what it entrusts to a security service provider. The third concerns suppliers. Supply chain oversight requires changes in contracts and in the procurement process, and these go beyond the competence of the IT department.

A separate element not worth closing at this stage is long-term hardware commitments related to provisions on high-risk suppliers. The President signed the amendment and simultaneously referred to the Constitutional Tribunal a motion concerning, among other things, these provisions and protective orders. The motion did not suspend the Act’s validity, but this fragment of regulation may change—as of August 2026, I have not noted a Tribunal ruling.

Checklist of initial decisions

Things to check off before the first budget decision.

  • The entity manager and the person leading the matter have been identified by name, and the determination has been recorded in minutes or a resolution.
  • Entity qualification is determined, has an assigned category and written justification; in a capital group—separately for each company.
  • The application for entry in the KSC Register has been submitted, or the date of its submission before October 3, 2026 has been set—the deadline from the communication of the Minister of Digitization applies to entities that met the criteria on April 3, 2026; if the criteria are met later, six months run from that moment.
  • At least two persons responsible for contacts with entities of the national cybersecurity system have been designated (one person only for a micro or small enterprise, or for an important entity that is a public entity).
  • An inventory has been prepared of what the organization already has. It covers risk analysis, access management, backups, logs, incident procedure, business continuity, requirements for suppliers.
  • It has been determined by what route and within what timeframe information about a serious incident reaches the entity manager.
  • Training for the entity manager and the method of its documentation have been planned.
  • A deadline has been set by which the board will receive a gap analysis with a proposal of priorities.

Only after this list does the conversation about budget have a foundation, because the scope of work results from the difference between the required state and the actual state, not from the catalog of vendor offers.

Conclusions and next steps

Preparation for NIS2 begins with a decision about responsibility, not with implementation. A board that first names the entity manager, confirms qualification in writing, and inventories the starting point buys itself something more than order. It buys the ability to justify each subsequent expenditure with a specific statutory obligation.

A sensible sequence for the coming months looks like this. By autumn 2026, close qualification, self-assessment documentation, and entry in the KSC Register—these are formal tasks, but without them nothing further will proceed. In parallel, commission an inventory of the current state and gap analysis so that the board can adopt scope, priorities, and budget at one meeting. Complete the implementation of the information security management system and the connection to the S46 system by April 3, 2027. After that date what remains is consolidating processes and preparing for the first audit, which falls due by April 3, 2028.

The measure of progress is not the number of documents. It is the answer to the question of whether the organization can indicate who is responsible, how it learns of an incident, what it does in the first day, and what it can use to demonstrate that this is how it actually operates.

Sources

  • Act of July 5, 2018 on the National Cybersecurity System, consolidated text — ISAP: isap.sejm.gov.pl (accessed: August 18, 2026) (in Polish)
  • Directive (EU) 2022/2555 of the European Parliament and of the Council of December 14, 2022 (NIS2) — EUR-Lex: eur-lex.europa.eu (accessed: August 17, 2026)
  • Act of January 23, 2026 amending the Act on the National Cybersecurity System and certain other acts (Journal of Laws 2026, item 252) — Journal of Laws: dziennikustaw.gov.pl (accessed: August 17, 2026) (in Polish)
  • Communication of the Minister of Digitization of April 8, 2026 on deadlines under the amendment to the KSC Act (Official Journal of the Minister of Digitization, item 7) — Ministry of Digitization: gov.pl (accessed: August 18, 2026) (in Polish)
  • Amendment to the KSC Act — obligations of essential and important entities — Ministry of Digitization: gov.pl (accessed: August 17, 2026) (in Polish)
  • President signed the Act on the National Cybersecurity System and referred a motion to the Constitutional Tribunal — Prawo.pl: prawo.pl (accessed: August 17, 2026) (in Polish)

Let’s determine the first step for your organization

If qualification is already determined and the open question is the scope and sequence of work, it is worth starting with a gap analysis—it shows how many of the requirements the organization meets today and what is actually missing. Support in preparing for NIS2 and KSC includes determining the scope of obligations, gap analysis, and an action plan that can be maintained and demonstrated during an audit.

Author

Michał Rutkowski — LabLogic. He combines the legal, organisational and technological perspective in his work with the boards of medium-sized and large organisations: support for and performance of the DPO role, preparation for NIS2 and the Polish KSC Act, incident response, audits and training. Contact: M.Rutkowski@LabLogic.pl · LinkedIn

This material is general and educational in nature. It is not an individual legal opinion or a recommendation for any specific organisation. The scope of the obligations should be assessed against the situation of the organisation concerned.

Legal status: August 2026.

Scroll to Top