Short answer
With two decisions that the board itself must make: who in the organization is the entity manager within the meaning of the KSC Act, and whether the entity’s qualification has been determined and documented. Only after these does a gap analysis, implementation plan, and budget make sense—without them, the organization finances work whose scope no one can justify. The Act does not allow the entity manager’s responsibility to be transferred to the IT department or to a vendor, so the first decision is a board decision, not a task to be delegated.
Why this question arises at all
Preparation for NIS2 is sometimes initiated from the middle. The board learns that the organization is subject to new regulations, assigns the matter to the IT or compliance department, and after a few weeks receives a list of missing procedures and a quote for tools. The question of sequence returns only when an expenditure must be approved that no one can link to a specific obligation.
The source of this confusion is the structure of the regulations. Directive (EU) 2022/2555 itself binds the Member State, not the business—an organization’s obligations arise from the Act on the National Cybersecurity System (KSC) as amended by the amendment of January 23, 2026, which entered into force on April 3, 2026. The Act changes something that was not so clear in the previous legal state: it places responsibility for performing cybersecurity obligations on the entity manager, imposes on them an obligation for documented training, and provides for a separate financial penalty for that person, independent of the penalty imposed on the entity.
Cybersecurity therefore ceases to be a matter that the board can simply acknowledge. It becomes an area in which the board makes decisions and must be able to show the basis on which it made them.
The second reason is the calendar. Entry in the KSC Register for entities registering on application falls within the period until October 3, 2026, the adaptation period ends on April 3, 2027, and the first mandatory audit of essential entities that were not previously operators of essential services, as well as the application of provisions on financial penalties, fall on April 3, 2028. These dates are not an argument for haste. However, they determine which work must be completed this year and which still has all of 2027.
What should the board know?
Responsibility for performing obligations under the KSC Act rests with the entity manager and cannot be transferred by contract or resolution—tasks can be delegated, not responsibility. The entity manager has an obligation to undergo documented cybersecurity training, and the Act provides for a separate financial penalty for them, in addition to the penalty for the entity.
Entity qualification is based on self-assessment: no one will notify the organization that it is subject, and the result of the assessment—including a negative one—should be documented. The scope of implementation depends on the entity’s category and what the organization already has, so a budget set before a gap analysis is a guessed budget. Deadlines divide the work into two stages: registration in 2026, implementation and connection to the S46 system by April 3, 2027.
What must be determined before the decision
Who is the entity manager and what the Act requires of them
This question sounds formal but determines everything else. In organizations with a multi-member board, responsibility applies to the body, but practice requires identifying a person who leads the matter, reports it to the board, and is responsible for the completeness of decision-making materials. In capital groups, qualification and status are determined separately for each entity, so there are as many entity managers as there are companies covered by the Act—a common group project does not replace this.
From this determination, three things follow that the board should ask at the first meeting devoted to this matter: who is responsible by name, what training they have completed or will complete, and by what procedure they receive information about incidents. The third question is most often omitted, yet it determines the ability to report a serious incident within the required timeframe—early warning within 24 hours of detection and full notification within 72 hours.
Whether qualification is determined and documented
Qualification is not a formality opening the project, but its foundation. It determines whether the organization is an essential or important entity, and from that—whether it must plan an audit cycle and under what supervisory regime it will operate. The criteria and method of conducting self-assessment are described separately in the material on entity qualification; what matters here is what the board should receive from this assessment.
A useful qualification result is not the sentence “we are subject.” It is a brief document: which lines of business were assigned to sectors from the annexes of the Act, how the entity’s size was calculated taking into account related and partner enterprises, what category was adopted, and who approved this conclusion. Without this record, the board has no way to demonstrate that the decision was informed—and with a negative qualification result, this document is the only trace that it was conducted at all.
What the organization already has
Preparation for NIS2 rarely starts from scratch. Organizations with a certified information security management system, with implemented GDPR, with a functioning incident response procedure, or with obligations arising from the DORA regulation already have some of the required elements—usually in a different arrangement and under a different name.
Establishing the starting point is the step that most strongly affects cost. A board that orders “NIS2 implementation” without this inventory usually pays for duplication of already existing procedures and for documentation describing processes that the organization does not conduct. Documentation should show how the organization actually operates; if it describes an invented state, during an audit it works against it.
The practical scope of this review is finite: risk analysis and its currency, access and authorization management, backups with recovery testing, event logging, incident reporting and response procedure, business continuity plan, requirements for suppliers in existing contracts, and verification of clean criminal records for personnel in positions specified in the Act.
Who is responsible for what on the operational side
The entity manager’s responsibility does not eliminate the need to assign tasks. The Act requires, among other things, the designation of a person responsible for contacts with entities of the national cybersecurity system, and in practice, process owners and risk owners are also needed—that is, people who can say what will happen to a specific service when a specific system is unavailable.
A common organizational arrangement looks like this: security formally belongs to IT, but decisions about priorities are made in business lines, and no one has a mandate to resolve disputes between them. In such an arrangement, implementation stops at the risk analysis stage, because assessing the consequences of process interruption requires input from the business, and the business does not feel it owns the matter. Resolving this issue is a management decision, not a technical one.
What board decisions determine the pace
Three decisions actually condition the progress of work, and none of them can be made at a lower level. The first is the level of risk that the organization accepts—without it, risk analysis ends with a list of threats without a conclusion. The second is the financial and human resources assigned to tasks, along with a determination of what the organization does independently and what it entrusts to a security service provider. The third concerns suppliers: supply chain oversight requires changes in contracts and in the procurement process, and these go beyond the competence of the IT department.
A separate element not worth closing at this stage is long-term hardware commitments related to provisions on high-risk suppliers. The President signed the amendment and simultaneously referred to the Constitutional Tribunal a motion concerning, among other things, these provisions and protective orders. The motion did not suspend the Act’s validity, but this fragment of regulation may change—as of August 2026, I have not noted a Tribunal ruling.
Checklist of initial decisions
To check off before the first budget decision:
- The entity manager and the person leading the matter have been identified by name, and the determination has been recorded in minutes or a resolution.
- Entity qualification is determined, has an assigned category and written justification; in a capital group—separately for each company.
- The application for entry in the KSC Register has been submitted, or the date of its submission before October 3, 2026 has been set.
- A person responsible for contacts with entities of the national cybersecurity system has been designated.
- An inventory has been prepared of what the organization already has: risk analysis, access management, backups, logs, incident procedure, business continuity, requirements for suppliers.
- It has been determined by what route and within what timeframe information about a serious incident reaches the entity manager.
- Training for the entity manager and the method of its documentation have been planned.
- A deadline has been set by which the board will receive a gap analysis with a proposal of priorities.
Only after this list does the conversation about budget have a foundation, because the scope of work results from the difference between the required state and the actual state, not from the catalog of vendor offers.
Conclusions and next steps
Preparation for NIS2 begins with a decision about responsibility, not with implementation. A board that first names the entity manager, confirms qualification in writing, and inventories the starting point buys itself something more than order: it buys the ability to justify each subsequent expenditure with a specific statutory obligation.
A sensible sequence for the coming months looks like this. By autumn 2026, close qualification, self-assessment documentation, and entry in the KSC Register—these are formal tasks, but without them nothing further will proceed. In parallel, commission an inventory of the current state and gap analysis so that the board can adopt scope, priorities, and budget at one meeting. Leave 2027 for implementing the information security management system, connecting to the S46 system, and consolidating processes, and plan preparation for the first audit with a buffer, as a check of a functioning system, not as a separate documentation project.
The measure of progress is not the number of documents. It is the answer to the question of whether the organization can indicate who is responsible, how it learns of an incident, what it does in the first day, and what it can use to demonstrate that this is how it actually operates.
Related materials
- Does every data breach need to be reported? — decision on reporting and distinguishing a security event from a personal data breach; a related thread for organizations that are simultaneously subject to GDPR.
- How often should employees be trained on personal data protection? — training obligation versus good practice, including with regard to management.
Sources
- Directive (EU) 2022/2555 of the European Parliament and of the Council of December 14, 2022 (NIS2) — EUR-Lex: eur-lex.europa.eu (accessed: August 17, 2026)
- Act of January 23, 2026 amending the Act on the National Cybersecurity System and certain other acts (Journal of Laws 2026, item 252) — Journal of Laws: dziennikustaw.gov.pl (accessed: August 17, 2026) (in Polish)
- Amendment to the KSC Act — obligations of essential and important entities — Ministry of Digitization: gov.pl (accessed: August 17, 2026) (in Polish)
- Amendment to the KSC Act — key deadlines — Ministry of Digitization: gov.pl (accessed: August 17, 2026) (in Polish)
- Amendment to the Act on the National Cybersecurity System — Knowledge Base, gov.pl: gov.pl (accessed: August 17, 2026) (in Polish)
- Amendment to the Act on the National Cybersecurity System — status after parliamentary work — CyberPolicy NASK-PIB: cyberpolicy.nask.pl (accessed: August 17, 2026) (in Polish)
- President signed the Act on the National Cybersecurity System and referred a motion to the Constitutional Tribunal — Prawo.pl: prawo.pl (accessed: August 17, 2026) (in Polish)
Let’s determine the first step for your organization
If qualification is already determined and the open question is the scope and sequence of work, it is worth starting with a gap analysis—it shows how many of the requirements the organization meets today and what is actually missing. Support in preparing for NIS2 and KSC includes determining the scope of obligations, gap analysis, and an action plan that can be maintained and demonstrated during an audit.
This material is general and educational in nature. It does not constitute individual legal advice or a recommendation for a specific organization. The scope of obligations should be assessed taking into account its situation.
Legal status: August 2026.