{"id":3921,"date":"2026-08-18T11:46:38","date_gmt":"2026-08-18T09:46:38","guid":{"rendered":"https:\/\/www.lablogic.pl\/where-should-the-board-begin-preparing-for-nis2\/"},"modified":"2026-08-18T13:37:10","modified_gmt":"2026-08-18T11:37:10","slug":"where-should-the-board-begin-preparing-for-nis2","status":"publish","type":"post","link":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/","title":{"rendered":"Where should the board begin preparing for NIS2?"},"content":{"rendered":"\n<p class=\"ll-art-meta wp-block-paragraph\"><strong>Micha\u0142 Rutkowski<\/strong> \u2022 for the board and management \u2022 published August 18, 2026 \u2022 updated August 18, 2026 \u2022 8 min read<\/p>\n\n<div class=\"wp-block-columns ll-art-shell is-layout-flex wp-container-core-columns-is-layout-7387b849 wp-block-columns-is-layout-flex\">\n\n<div class=\"wp-block-column ll-art-rail is-layout-flow wp-block-column-is-layout-flow\">\n\n<div class=\"wp-block-group ll-art-railinner is-layout-constrained wp-block-group-is-layout-constrained\">\n\n<div class=\"wp-block-group ll-art-railcard is-layout-constrained wp-block-group-is-layout-constrained\">\n<p class=\"wp-block-paragraph\">On this page<\/p>\n\n<ul class=\"wp-block-list\">\n<li><a href=\"#krotka-odpowiedz\">Short answer<\/a><\/li>\n<li><a href=\"#dlaczego\">Why this question arises at all<\/a><\/li>\n<li><a href=\"#zarzad\">What should the board know?<\/a><\/li>\n<li><a href=\"#co-ustalic\">What must be determined before the decision<\/a><\/li>\n<li><a href=\"#checklista\">Checklist of initial decisions<\/a><\/li>\n<li><a href=\"#wnioski\">Conclusions and next steps<\/a><\/li>\n<\/ul>\n\n<\/div>\n\n\n\n<div class=\"wp-block-group ll-art-railcard ll-art-railmeta is-layout-constrained wp-block-group-is-layout-constrained\">\n<p class=\"wp-block-paragraph\">Legal status<\/p>\n<p class=\"wp-block-paragraph\"><strong>August 2026.<\/strong>  The KSC Act as amended by the amendment of January 23, 2026 (Journal of Laws 2026, item 252), in force from April 3, 2026. Next deadline: self-registration in the KSC Register by October 3, 2026.  <\/p>\n<p class=\"wp-block-paragraph\">Last significant update: August 18, 2026.<\/p>\n<\/div>\n\n<\/div>\n\n<\/div>\n\n\n\n<div class=\"wp-block-column ll-art-main is-layout-flow wp-block-column-is-layout-flow\">\n\n<div class=\"wp-block-group ll-art-answer is-layout-constrained wp-block-group-is-layout-constrained\">\n\n<h2 class=\"wp-block-heading\" id=\"krotka-odpowiedz\">Short answer<\/h2>\n\n<p class=\"wp-block-paragraph\">With two decisions that the board itself must make: who in the organization is the entity manager within the meaning of the KSC Act, and whether the entity&#8217;s qualification has been determined and documented. Only after these does a gap analysis, implementation plan, and budget make sense\u2014without them, the organization finances work whose scope no one can justify. The Act does not allow the entity manager&#8217;s responsibility to be transferred to the IT department or to a vendor, so the first decision is a board decision, not a task to be delegated.  <\/p>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"dlaczego\">Why this question arises at all<\/h2>\n\n<p class=\"wp-block-paragraph\">Preparation for NIS2 is sometimes initiated from the middle. The board learns that the organization is subject to new regulations, assigns the matter to the IT or compliance department, and after a few weeks receives a list of missing procedures and a quote for tools. The question of sequence returns only when an expenditure must be approved that no one can link to a specific obligation.  <\/p>\n<p class=\"wp-block-paragraph\">The source of this confusion is the structure of the regulations. Directive (EU) 2022\/2555 itself binds the Member State, not the business\u2014an organization&#8217;s obligations arise from the Act on the National Cybersecurity System (KSC) as amended by the amendment of January 23, 2026, which entered into force on April 3, 2026. The Act changes something that was not so clear in the previous legal state: it places responsibility for performing cybersecurity obligations on the entity manager, imposes on them an obligation for documented training, and provides for a separate financial penalty for that person, independent of the penalty imposed on the entity.<\/p>\n<p class=\"wp-block-paragraph\">Cybersecurity therefore ceases to be a matter that the board can simply acknowledge. It becomes an area in which the board makes decisions and must be able to show the basis on which it made them. <\/p>\n<p class=\"wp-block-paragraph\">The second reason is the calendar. Entry in the KSC Register for entities registering on application falls within the period until October 3, 2026, the adaptation period ends on April 3, 2027, and the first mandatory audit of essential entities that were not previously operators of essential services, as well as the application of provisions on financial penalties, fall on April 3, 2028. These dates are not an argument for haste. However, they determine which work must be completed this year and which still has all of 2027.<\/p>\n\n\n<div class=\"wp-block-group ll-art-board is-layout-constrained wp-block-group-is-layout-constrained\">\n\n<h2 class=\"wp-block-heading\" id=\"zarzad\">What should the board know?<\/h2>\n\n<p class=\"wp-block-paragraph\">Responsibility for performing obligations under the KSC Act rests with the entity manager and cannot be transferred by contract or resolution\u2014tasks can be delegated, not responsibility. The entity manager has an obligation to undergo documented cybersecurity training, and the Act provides for a separate financial penalty for them, in addition to the penalty for the entity. <\/p>\n<p class=\"wp-block-paragraph\">Entity qualification is based on self-assessment: no one will notify the organization that it is subject, and the result of the assessment\u2014including a negative one\u2014should be documented. The scope of implementation depends on the entity&#8217;s category and what the organization already has, so a budget set before a gap analysis is a guessed budget. Deadlines divide the work into two stages: registration in 2026, implementation and connection to the S46 system by April 3, 2027.  <\/p>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"co-ustalic\">What must be determined before the decision<\/h2>\n\n\n<h3 class=\"wp-block-heading\">Who is the entity manager and what the Act requires of them<\/h3>\n<p class=\"wp-block-paragraph\">This question sounds formal but determines everything else. In organizations with a multi-member board, responsibility applies to the body, but practice requires identifying a person who leads the matter, reports it to the board, and is responsible for the completeness of decision-making materials. In capital groups, qualification and status are determined separately for each entity, so there are as many entity managers as there are companies covered by the Act\u2014a common group project does not replace this.  <\/p>\n<p class=\"wp-block-paragraph\">From this determination, three things follow that the board should ask at the first meeting devoted to this matter: who is responsible by name, what training they have completed or will complete, and by what procedure they receive information about incidents. The third question is most often omitted, yet it determines the ability to report a serious incident within the required timeframe\u2014early warning within 24 hours of detection and full notification within 72 hours. <\/p>\n\n<h3 class=\"wp-block-heading\">Whether qualification is determined and documented<\/h3>\n<p class=\"wp-block-paragraph\">Qualification is not a formality opening the project, but its foundation. It determines whether the organization is an essential or important entity, and from that\u2014whether it must plan an audit cycle and under what supervisory regime it will operate. The criteria and method of conducting self-assessment are described separately in the material on entity qualification; what matters here is what the board should receive from this assessment.  <\/p>\n<p class=\"wp-block-paragraph\">A useful qualification result is not the sentence &#8220;we are subject.&#8221; It is a brief document: which lines of business were assigned to sectors from the annexes of the Act, how the entity&#8217;s size was calculated taking into account related and partner enterprises, what category was adopted, and who approved this conclusion. Without this record, the board has no way to demonstrate that the decision was informed\u2014and with a negative qualification result, this document is the only trace that it was conducted at all.  <\/p>\n\n<h3 class=\"wp-block-heading\">What the organization already has<\/h3>\n<p class=\"wp-block-paragraph\">Preparation for NIS2 rarely starts from scratch. Organizations with a certified information security management system, with implemented GDPR, with a functioning incident response procedure, or with obligations arising from the DORA regulation already have some of the required elements\u2014usually in a different arrangement and under a different name. <\/p>\n<p class=\"wp-block-paragraph\">Establishing the starting point is the step that most strongly affects cost. A board that orders &#8220;NIS2 implementation&#8221; without this inventory usually pays for duplication of already existing procedures and for documentation describing processes that the organization does not conduct. Documentation should show how the organization actually operates; if it describes an invented state, during an audit it works against it.  <\/p>\n<p class=\"wp-block-paragraph\">The practical scope of this review is finite: risk analysis and its currency, access and authorization management, backups with recovery testing, event logging, incident reporting and response procedure, business continuity plan, requirements for suppliers in existing contracts, and verification of clean criminal records for personnel in positions specified in the Act.<\/p>\n\n<h3 class=\"wp-block-heading\">Who is responsible for what on the operational side<\/h3>\n<p class=\"wp-block-paragraph\">The entity manager&#8217;s responsibility does not eliminate the need to assign tasks. The Act requires, among other things, the designation of a person responsible for contacts with entities of the national cybersecurity system, and in practice, process owners and risk owners are also needed\u2014that is, people who can say what will happen to a specific service when a specific system is unavailable. <\/p>\n<p class=\"wp-block-paragraph\">A common organizational arrangement looks like this: security formally belongs to IT, but decisions about priorities are made in business lines, and no one has a mandate to resolve disputes between them. In such an arrangement, implementation stops at the risk analysis stage, because assessing the consequences of process interruption requires input from the business, and the business does not feel it owns the matter. Resolving this issue is a management decision, not a technical one.  <\/p>\n\n<h3 class=\"wp-block-heading\">What board decisions determine the pace<\/h3>\n<p class=\"wp-block-paragraph\">Three decisions actually condition the progress of work, and none of them can be made at a lower level. The first is the level of risk that the organization accepts\u2014without it, risk analysis ends with a list of threats without a conclusion. The second is the financial and human resources assigned to tasks, along with a determination of what the organization does independently and what it entrusts to a security service provider. The third concerns suppliers: supply chain oversight requires changes in contracts and in the procurement process, and these go beyond the competence of the IT department.   <\/p>\n\n<div class=\"wp-block-group ll-art-note is-layout-constrained wp-block-group-is-layout-constrained\">\n<p class=\"wp-block-paragraph\">A separate element not worth closing at this stage is long-term hardware commitments related to provisions on high-risk suppliers. The President signed the amendment and simultaneously referred to the Constitutional Tribunal a motion concerning, among other things, these provisions and protective orders. The motion did not suspend the Act&#8217;s validity, but this fragment of regulation may change\u2014as of August 2026, I have not noted a Tribunal ruling.   <\/p>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"checklista\">Checklist of initial decisions<\/h2>\n\n<p class=\"wp-block-paragraph\">To check off before the first budget decision:<\/p>\n\n<div class=\"wp-block-group ll-art-check is-layout-constrained wp-block-group-is-layout-constrained\">\n\n<ul class=\"wp-block-list\">\n<li>The entity manager and the person leading the matter have been identified by name, and the determination has been recorded in minutes or a resolution.<\/li>\n<li>Entity qualification is determined, has an assigned category and written justification; in a capital group\u2014separately for each company.<\/li>\n<li>The application for entry in the KSC Register has been submitted, or the date of its submission before October 3, 2026 has been set.<\/li>\n<li>A person responsible for contacts with entities of the national cybersecurity system has been designated.<\/li>\n<li>An inventory has been prepared of what the organization already has: risk analysis, access management, backups, logs, incident procedure, business continuity, requirements for suppliers.<\/li>\n<li>It has been determined by what route and within what timeframe information about a serious incident reaches the entity manager.<\/li>\n<li>Training for the entity manager and the method of its documentation have been planned.<\/li>\n<li>A deadline has been set by which the board will receive a gap analysis with a proposal of priorities.<\/li>\n<\/ul>\n\n<\/div>\n\n<p class=\"wp-block-paragraph\">Only after this list does the conversation about budget have a foundation, because the scope of work results from the difference between the required state and the actual state, not from the catalog of vendor offers.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"wnioski\">Conclusions and next steps<\/h2>\n\n<p class=\"wp-block-paragraph\">Preparation for NIS2 begins with a decision about responsibility, not with implementation. A board that first names the entity manager, confirms qualification in writing, and inventories the starting point buys itself something more than order: it buys the ability to justify each subsequent expenditure with a specific statutory obligation. <\/p>\n<p class=\"wp-block-paragraph\">A sensible sequence for the coming months looks like this. By autumn 2026, close qualification, self-assessment documentation, and entry in the KSC Register\u2014these are formal tasks, but without them nothing further will proceed. In parallel, commission an inventory of the current state and gap analysis so that the board can adopt scope, priorities, and budget at one meeting. Leave 2027 for implementing the information security management system, connecting to the S46 system, and consolidating processes, and plan preparation for the first audit with a buffer, as a check of a functioning system, not as a separate documentation project.   <\/p>\n<p class=\"wp-block-paragraph\">The measure of progress is not the number of documents. It is the answer to the question of whether the organization can indicate who is responsible, how it learns of an incident, what it does in the first day, and what it can use to demonstrate that this is how it actually operates. <\/p>\n\n<h2 class=\"wp-block-heading\">Related materials<\/h2>\n\n<ul class=\"wp-block-list\">\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/\">Does every data breach need to be reported?<\/a><\/strong>  \u2014 decision on reporting and distinguishing a security event from a personal data breach; a related thread for organizations that are simultaneously subject to GDPR. <\/li>\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/how-often-should-employees-be-trained-on-personal-data-protection\/\">How often should employees be trained on personal data protection?<\/a><\/strong>  \u2014 training obligation versus good practice, including with regard to management. <\/li>\n<\/ul>\n\n\n<h2 class=\"wp-block-heading\">Sources<\/h2>\n\n<ul class=\"wp-block-list ll-art-sources\">\n<li>Directive (EU) 2022\/2555 of the European Parliament and of the Council of December 14, 2022 (NIS2) \u2014 EUR-Lex: <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX%3A32022L2555\" target=\"_blank\" rel=\"noreferrer noopener\">eur-lex.europa.eu<\/a> (accessed: August 17, 2026) <\/li>\n<li>Act of January 23, 2026 amending the Act on the National Cybersecurity System and certain other acts (Journal of Laws 2026, item 252) \u2014 Journal of Laws: <a href=\"https:\/\/dziennikustaw.gov.pl\/D2026000025201.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">dziennikustaw.gov.pl<\/a> (accessed: August 17, 2026)  (in Polish)<\/li>\n<li>Amendment to the KSC Act \u2014 obligations of essential and important entities \u2014 Ministry of Digitization: <a href=\"https:\/\/www.gov.pl\/web\/cyfryzacja\/nowelizacja-ustawy-o-krajowym-systemie-cyberbezpieczenstwa-ksc---obowiazki-podmiotow-kluczowych-i-waznych\" target=\"_blank\" rel=\"noreferrer noopener\">gov.pl<\/a> (accessed: August 17, 2026) (in Polish)<\/li>\n<li>Amendment to the KSC Act \u2014 key deadlines \u2014 Ministry of Digitization: <a href=\"https:\/\/www.gov.pl\/web\/cyfryzacja\/nowelizacja-ustawy-o-krajowym-systemie-cyberbezpieczenstwa-ksc--najwazniejsze-terminy\" target=\"_blank\" rel=\"noreferrer noopener\">gov.pl<\/a> (accessed: August 17, 2026) (in Polish)<\/li>\n<li>Amendment to the Act on the National Cybersecurity System \u2014 Knowledge Base, gov.pl: <a href=\"https:\/\/www.gov.pl\/web\/baza-wiedzy\/nowelizacja-ustawy-o-krajowym-systemie-cyberbezpieczenstwa\" target=\"_blank\" rel=\"noreferrer noopener\">gov.pl<\/a> (accessed: August 17, 2026) (in Polish)<\/li>\n<li>Amendment to the Act on the National Cybersecurity System \u2014 status after parliamentary work \u2014 CyberPolicy NASK-PIB: <a href=\"https:\/\/cyberpolicy.nask.pl\/wp-content\/uploads\/2026\/02\/Nowelizacja-ustawy-o-krajowym-systemie-cyberbezpieczenstwa-stan-po-pracach-parlamentarnych-1.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">cyberpolicy.nask.pl<\/a> (accessed: August 17, 2026) (in Polish)<\/li>\n<li>President signed the Act on the National Cybersecurity System and referred a motion to the Constitutional Tribunal \u2014 Prawo.pl: <a href=\"https:\/\/www.prawo.pl\/biznes\/prezydent-podpisal-ustawe-o-krajowym-systemie-cyberbezpieczenstwa-i-skierowal-wniosek-do-tk,1537069.html\" target=\"_blank\" rel=\"noreferrer noopener\">prawo.pl<\/a> (accessed: August 17, 2026) (in Polish)<\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-group ll-art-author is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 class=\"wp-block-heading\">Author<\/h2>\n<p class=\"wp-block-paragraph\"><strong>Micha\u0142 Rutkowski<\/strong> \u2014 LabLogic. Combines legal, organizational, and technological perspectives in working with boards of medium and large organizations: support and performance of DPO functions, preparation for NIS2 and KSC, incident response, audits, and training. Contact: M.Rutkowski@LabLogic.pl  <\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group ll-art-cta is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 class=\"wp-block-heading\">Let&#8217;s determine the first step for your organization<\/h2>\n<p class=\"wp-block-paragraph\">If qualification is already determined and the open question is the scope and sequence of work, it is worth starting with a gap analysis\u2014it shows how many of the requirements the organization meets today and what is actually missing. Support in preparing for NIS2 and KSC includes determining the scope of obligations, gap analysis, and an action plan that can be maintained and demonstrated during an audit. <\/p>\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/www.lablogic.pl\/en\/nis2-and-ksc-preparation-and-implementation-support-for-organizations\/\">Support in preparing for NIS2 and KSC<\/a><\/div>\n\n<\/div>\n\n<\/div>\n\n\n\n<div class=\"wp-block-group ll-art-disclaimer is-layout-constrained wp-block-group-is-layout-constrained\">\n<p class=\"wp-block-paragraph\">This material is general and educational in nature. It does not constitute individual legal advice or a recommendation for a specific organization. The scope of obligations should be assessed taking into account its situation.  <\/p>\n<p class=\"wp-block-paragraph\"><strong>Legal status: August 2026.<\/strong><\/p>\n<\/div>\n\n<\/div>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>With two board decisions: who is the entity manager within the meaning of the KSC Act, and whether the qualification has been documented. Only after these does a gap analysis, implementation plan, and budget make sense. <\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[74],"tags":[78],"class_list":["post-3921","post","type-post","status-publish","format-standard","hentry","category-nis2","tag-for-management"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Boards start NIS2 with responsibility and qualification, not implementation. The order of decisions, the KSC Act deadlines and a first-decisions checklist.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Micha\u0142 Rutkowski\"\/>\n\t<meta name=\"keywords\" content=\"for-management\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"LabLogic - Micha\u0142 Rutkowski | DPO, RODO, NIS2 i Cybersecurity w praktyce\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Where should the board begin preparing for NIS2? | LabLogic - Micha\u0142 Rutkowski\" \/>\n\t\t<meta property=\"og:description\" content=\"Boards start NIS2 with responsibility and qualification, not implementation. The order of decisions, the KSC Act deadlines and a first-decisions checklist.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/lablogic-logo-primary.svg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/lablogic-logo-primary.svg\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-08-18T09:46:38+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-08-18T11:37:10+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Where should the board begin preparing for NIS2? | LabLogic - Micha\u0142 Rutkowski\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Boards start NIS2 with responsibility and qualification, not implementation. The order of decisions, the KSC Act deadlines and a first-decisions checklist.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/lablogic-logo-primary.svg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/where-should-the-board-begin-preparing-for-nis2\\\/#article\",\"name\":\"Where should the board begin preparing for NIS2? | LabLogic - Micha\\u0142 Rutkowski\",\"headline\":\"Where should the board begin preparing for NIS2?\",\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/user_lablogic\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2020\\\/03\\\/LABLOGIC_LOGO2.png\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#articleImage\"},\"datePublished\":\"2026-08-18T11:46:38+02:00\",\"dateModified\":\"2026-08-18T13:37:10+02:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/where-should-the-board-begin-preparing-for-nis2\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/where-should-the-board-begin-preparing-for-nis2\\\/#webpage\"},\"articleSection\":\"NIS2 and KSC, for-management, Optional\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/where-should-the-board-begin-preparing-for-nis2\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/nis2\\\/#listItem\",\"name\":\"NIS2 and KSC\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/nis2\\\/#listItem\",\"position\":2,\"name\":\"NIS2 and KSC\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/nis2\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/where-should-the-board-begin-preparing-for-nis2\\\/#listItem\",\"name\":\"Where should the board begin preparing for NIS2?\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/where-should-the-board-begin-preparing-for-nis2\\\/#listItem\",\"position\":3,\"name\":\"Where should the board begin preparing for NIS2?\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/nis2\\\/#listItem\",\"name\":\"NIS2 and KSC\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#organization\",\"name\":\"LabLogic Micha\\u0142 Rutkowski\",\"description\":\"DPO, RODO, NIS2 i Cybersecurity w praktyce\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"telephone\":\"+48586231777\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2020\\\/03\\\/LABLOGIC_LOGO2.png\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/where-should-the-board-begin-preparing-for-nis2\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/where-should-the-board-begin-preparing-for-nis2\\\/#organizationLogo\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/user_lablogic\\\/#author\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/user_lablogic\\\/\",\"name\":\"Micha\\u0142 Rutkowski\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/where-should-the-board-begin-preparing-for-nis2\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Micha\\u0142 Rutkowski\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/where-should-the-board-begin-preparing-for-nis2\\\/#webpage\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/where-should-the-board-begin-preparing-for-nis2\\\/\",\"name\":\"Where should the board begin preparing for NIS2? | LabLogic - Micha\\u0142 Rutkowski\",\"description\":\"Boards start NIS2 with responsibility and qualification, not implementation. The order of decisions, the KSC Act deadlines and a first-decisions checklist.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/where-should-the-board-begin-preparing-for-nis2\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/user_lablogic\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/user_lablogic\\\/#author\"},\"datePublished\":\"2026-08-18T11:46:38+02:00\",\"dateModified\":\"2026-08-18T13:37:10+02:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"name\":\"LabLogic Consulting\",\"description\":\"DPO, RODO, NIS2 i Cybersecurity w praktyce\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Where should the board begin preparing for NIS2? | LabLogic - Micha\u0142 Rutkowski","description":"Boards start NIS2 with responsibility and qualification, not implementation. The order of decisions, the KSC Act deadlines and a first-decisions checklist.","canonical_url":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/","robots":"max-image-preview:large","keywords":"for-management","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/#article","name":"Where should the board begin preparing for NIS2? | LabLogic - Micha\u0142 Rutkowski","headline":"Where should the board begin preparing for NIS2?","author":{"@id":"https:\/\/www.lablogic.pl\/en\/author\/user_lablogic\/#author"},"publisher":{"@id":"https:\/\/www.lablogic.pl\/en\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2020\/03\/LABLOGIC_LOGO2.png","@id":"https:\/\/www.lablogic.pl\/en\/#articleImage"},"datePublished":"2026-08-18T11:46:38+02:00","dateModified":"2026-08-18T13:37:10+02:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/#webpage"},"isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/#webpage"},"articleSection":"NIS2 and KSC, for-management, Optional"},{"@type":"BreadcrumbList","@id":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","position":1,"name":"Home","item":"https:\/\/www.lablogic.pl\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/nis2\/#listItem","name":"NIS2 and KSC"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/nis2\/#listItem","position":2,"name":"NIS2 and KSC","item":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/nis2\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/#listItem","name":"Where should the board begin preparing for NIS2?"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/#listItem","position":3,"name":"Where should the board begin preparing for NIS2?","previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/nis2\/#listItem","name":"NIS2 and KSC"}}]},{"@type":"Organization","@id":"https:\/\/www.lablogic.pl\/en\/#organization","name":"LabLogic Micha\u0142 Rutkowski","description":"DPO, RODO, NIS2 i Cybersecurity w praktyce","url":"https:\/\/www.lablogic.pl\/en\/","telephone":"+48586231777","logo":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2020\/03\/LABLOGIC_LOGO2.png","@id":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/#organizationLogo"},"image":{"@id":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/#organizationLogo"}},{"@type":"Person","@id":"https:\/\/www.lablogic.pl\/en\/author\/user_lablogic\/#author","url":"https:\/\/www.lablogic.pl\/en\/author\/user_lablogic\/","name":"Micha\u0142 Rutkowski","image":{"@type":"ImageObject","@id":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g","width":96,"height":96,"caption":"Micha\u0142 Rutkowski"}},{"@type":"WebPage","@id":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/#webpage","url":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/","name":"Where should the board begin preparing for NIS2? | LabLogic - Micha\u0142 Rutkowski","description":"Boards start NIS2 with responsibility and qualification, not implementation. The order of decisions, the KSC Act deadlines and a first-decisions checklist.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/#website"},"breadcrumb":{"@id":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/#breadcrumblist"},"author":{"@id":"https:\/\/www.lablogic.pl\/en\/author\/user_lablogic\/#author"},"creator":{"@id":"https:\/\/www.lablogic.pl\/en\/author\/user_lablogic\/#author"},"datePublished":"2026-08-18T11:46:38+02:00","dateModified":"2026-08-18T13:37:10+02:00"},{"@type":"WebSite","@id":"https:\/\/www.lablogic.pl\/en\/#website","url":"https:\/\/www.lablogic.pl\/en\/","name":"LabLogic Consulting","description":"DPO, RODO, NIS2 i Cybersecurity w praktyce","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.lablogic.pl\/en\/#organization"}}]},"og:locale":"en_US","og:site_name":"LabLogic - Micha\u0142 Rutkowski | DPO, RODO, NIS2 i Cybersecurity w praktyce","og:type":"article","og:title":"Where should the board begin preparing for NIS2? | LabLogic - Micha\u0142 Rutkowski","og:description":"Boards start NIS2 with responsibility and qualification, not implementation. The order of decisions, the KSC Act deadlines and a first-decisions checklist.","og:url":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/","og:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/lablogic-logo-primary.svg","og:image:secure_url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/lablogic-logo-primary.svg","article:published_time":"2026-08-18T09:46:38+00:00","article:modified_time":"2026-08-18T11:37:10+00:00","twitter:card":"summary","twitter:title":"Where should the board begin preparing for NIS2? | LabLogic - Micha\u0142 Rutkowski","twitter:description":"Boards start NIS2 with responsibility and qualification, not implementation. The order of decisions, the KSC Act deadlines and a first-decisions checklist.","twitter:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/lablogic-logo-primary.svg"},"aioseo_meta_data":{"post_id":"3921","title":null,"description":"Boards start NIS2 with responsibility and qualification, not implementation. The order of decisions, the KSC Act deadlines and a first-decisions checklist.","keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-08-18 09:57:45","updated":"2026-08-18 11:42:05","seo_analyzer_scan_date":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"spectra_blocks_featured_image_url":null,"spectra_blocks_author_info":{"display_name":"Micha\u0142 Rutkowski","avatar_url":"https:\/\/secure.gravatar.com\/avatar\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g","author_link":"https:\/\/www.lablogic.pl\/en\/author\/user_lablogic\/","description":""},"_links":{"self":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/3921","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/comments?post=3921"}],"version-history":[{"count":4,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/3921\/revisions"}],"predecessor-version":[{"id":3939,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/3921\/revisions\/3939"}],"wp:attachment":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/media?parent=3921"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/categories?post=3921"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/tags?post=3921"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}