How to Implement KSC / NIS2 - a Guide for Companies

12 March 2026, Compliance, Cybersecurity, NIS2/KSC, Tools

Poland has implemented the NIS2 Directive through an amendment to the Act on the National Cybersecurity System (KSC). This is an important step for us towards strengthening the common European protection against cyber threats. In this article, you will learn how to meet the new, stringent requirements for managing cybersecurity risks, how to report incidents, and what other obligations are introduced by the new regulations.

Zdjęcie autora: r.pr. Paweł Radecki

The Author:

r.pr. Paweł Radecki

Share this article

Introduction

Our guide presents the main assumptions of the Act on the National Cybersecurity System (KSC) following the amendment that implemented the NIS2 Directive. We explain the key elements of the NIS2 requirements specified in the KSC Act. We will also provide you with practical tips on how to implement the new regulations.

Here you will find detailed information about:

  • changes and obligations introduced by the Act on the National Cybersecurity System (KSC),
  • qualification for the group of essential and important entities,
  • obligations of essential and important entities,
  • sectors to which the regulations apply,
  • relevant cybersecurity authorities,
  • procedures for reporting incidents,
  • risk management measures in your company.

NIS2

What is the NIS2 Directive and why is its implementation important for your company

The NIS2 Directive (Network and Information Security Directive 2) is EU legislation aimed at ensuring a uniform, high level of cybersecurity in EU member states in response to the continuously growing cyber threats. It is the successor to the NIS Directive from 2016 – the first EU legal act regulating cybersecurity issues, which imposed obligations on operators of essential services and member states regarding incident response and cooperation between CSIRT teams (Computer Security Incident Response Team).

How to implement NIS2 - guide for companies

The NIS2 Directive  builds upon the earlier regulations of the NIS 1 Directive. It addresses new threats and shortcomings of its predecessor by increasing and tightening obligations regarding cybersecurity. Among other things, it encompasses more sectors and entities, introduces new categories of entities, namely essential entities and important entities (the previous directive referred to key service operators and digital service providers), and imposes stricter requirements concerning cybersecurity risk management, incident reporting, and management accountability. The new regulations also foresee sanctions for non-compliance with these obligations and establish mechanisms for responding to large-scale incidents at both national and European levels, as well as for cooperation and information exchange between authorities and private entities.

The Polish legislator has implemented the requirements set forth by the NIS2 Directive through the amendment of the Act on the National Cybersecurity System (UoKSC). This Act defines new obligations for Polish entrepreneurs that correspond to the requirements of NIS2. Proper fulfillment of these obligations will require a proactive approach – not only responding to incidents but also preventing them through systematic actions such as risk management, supplier control, and management engagement.

At both the national and EU levels, the NIS2 Directive promotes cooperation and information exchange through:

  • a cooperation group – an entity supporting cooperation and the exchange of best practices among member states,
  • the CSIRT network – a network of Computer Security Incident Response Teams that coordinate cybersecurity-related activities,
  • the European network of cybersecurity crisis liaison organizations (CyCLONe) – a platform for rapid information exchange and coordination of actions in crisis situations,
  • the European vulnerability database – a central repository of information on security vulnerabilities that supports risk management.
READ MORE: NIS2 Directive: Strengthening Cybersecurity in the EU

Who is subject to the NIS2 requirements

NIS2 Directive – compared to the NIS 1 Directive – includes additional sectors of the economy. This requirement is reflected in the Act on the National Cybersecurity System (KSC). Entities covered by the new regulation are divided into two groups: essential sectors and important sectors. The classification of entities is based on specific criteria that businesses must meet to be recognized as essential or important entities. These entities are listed in the annexes to the Act.

KSC - Essential Entities

  • Energy
  • Transport
  • Banking and financial market infrastructure
  • Healthcare
  • Drinking water supply
  • Sewage disposal
  • Digital infrastructure
  • Management of ICT services
  • Space
  • Public entities

KSC - Important Entities

  • Postal services
  • Nuclear energy investments
  • Waste management
  • Production (including chemicals, food, medical devices, electronics, machinery, vehicles)
  • Providers of digital services
  • Scientific research
  • Public entities

The regulations primarily cover medium and large enterprises, but in some sectors – also micro and small companies as well as entities that are not entrepreneurs. Entities engaged in medical activities established by the Head of the Internal Security Agency (ABW) or the Head of the Intelligence Agency are excluded from the Act.

The assessment of whether one falls under the provisions of the KSC Act can be complicated, therefore it certainly requires meticulous analysis. It is advisable to involve experts in this process who can help navigate it safely and effectively.

The main differences between essential and important entities can be found in the table below.

ESSENTIAL ENTITIESIMPORTANT ENTITIES
Ex ante and ex post supervisionEx post supervision
On-site inspections and remote supervisionOn-site inspections and remote ex post supervision
Regular and targeted security auditsTargeted security audits
Security scansSecurity scans
Requests for access to data, documents, and informationRequests for access to data, documents, and information
Requests for information necessary to assess the cybersecurity risk management measures adopted by a given entityRequests for information necessary to assess (ex post) the cybersecurity risk management measures adopted by a given entity
Ad hoc audits (may be mandated by the relevant authority at any time)Ad hoc audits (may be mandated by the relevant authority in the event of a serious incident or other violation of the provisions of the Act on the National Cybersecurity System)

NIS2

Extension of obligations and new supervision mechanisms 

What changes does the amendment to the Act on the National Cybersecurity System bring

  • Expands the catalog of entities subject to the national cybersecurity system to include new sectors of the economy, including wastewater, ICT, space, postal services, production, distribution of chemicals and food, and public entities (the scope of obligations in some sectors differs compared to other sectors, e.g., in the banking sector and financial market infrastructure).
  • Introduces new categories of entities – essential entities and important entities.
  • Imposes an obligation for self-registration in the register of essential entities and important entities.
  • Places obligations related to risk management on essential entities and important entities.
  • Significantly expands and specifies the provisions regarding the application of technical and organizational measures.
  • Establishes the responsibility of the manager of an essential entity or important entity for the implementation of cybersecurity tasks, including the obligation for appropriate training, and provides for penalties in case of non-compliance with the imposed tasks.
  • Introduces an obligation for essential entities to conduct security audits every three years and ad-hoc audits at the request of the relevant authority – also applicable to important entities.
  • Imposes an obligation for essential entities and important entities to report incidents via an information technology system.
  • Creates sectoral CSIRTs to support essential entities and important entities in handling cybersecurity incidents.
  • Expands the competencies of CSIRTs at the national level, including CSIRT NASK, in connection with the increasing number of essential entities and important entities requiring support in incidents.
  • Grants cybersecurity authorities greater supervisory powers and enforcement capabilities. This includes the ability to issue warnings, appoint officials to monitor the compliance of essential entities, mandate security assessments of information systems, and conduct security audits and inspections.
  • Introduces new financial penalties for non-compliance with obligations, including for the lack of an information security management system or registration in the register of essential entities and important entities.
  • Establishes a national incident and crisis response plan for large-scale cybersecurity incidents, outlining the principles of action and cooperation among relevant authorities.
  • Expands the competencies of the minister responsible for informatization, enabling the identification of high-risk suppliers and issuing protective orders to mitigate the effects of critical incidents.
  • Grants the Government Plenipotentiary for Cybersecurity the right to issue recommendations, request information, commission studies, and purchase software for the Joint Cybersecurity Operations Center to enhance the security level of information systems.
  • Expands the competencies of the Minister for Digitization to include educational activities in the field of cybersecurity, including campaigns and educational programs.
  • Introduces a catalog of criteria that the competent authority for cybersecurity must analyze in order to undertake supervisory actions and enforce regulations, including imposing financial penalties.
  • Establishes the institution of periodic financial penalties to compel a key entity or an important entity to fulfill its obligations.
  • Introduces the obligation to report early warnings, which allows for requests for guidelines on mitigating the effects of an incident or for technical support (the sectoral CSIRT is obliged to provide assistance within 24 hours).
  • Enables joining the system through cloud solutions, without the need to enter into agreements or purchase special devices.
  • Imposes on key entities and important entities the obligation to adapt their information systems to the minimum technical and functional requirements within 6 months of the publication of these requirements by the Minister for Digitization on his BIP page.

NIS2 - download guide

What does the registration process as a key entity or important entity look like

  • An entity that meets the criteria for being recognized as a key entity or an important entity must submit an application for entry into the register of key entities and important entities via the information system within 3 months.
  • The application is to be prepared in electronic form and must be signed with a qualified electronic signature, a trusted signature, the personal signature of the head of the key entity or the important entity, or a person authorized by them, or a qualified electronic seal. In the case of an application submitted by an attorney-in-fact, a power of attorney in electronic form must be attached.
  • The entry is made at the moment the application is submitted in the IT system.
  • Telecommunications entrepreneurs, trust service providers, public entities, and critical entities are entered into the register ex officio by the minister responsible for digitization based on data from public registers, the electronic address database, or information from supervisory authorities. In the event of deficiencies, the minister calls for their supplementation within 2 months from the delivery of the call, under the threat of a financial penalty. Supplementation of data occurs by submitting an application for a change of entry in the register.
  • Key entities and important entities receive a notification of their entry into the register, which is delivered by the minister responsible for digitization.
  • In the event of a change in data, an application for a change of entry in the register must be submitted within 14 days.
  • If an entity conducts several types of activities, they should be indicated in the application separately.
  • An entity that no longer meets the conditions for being recognized as a key entity or an important entity must submit an application for removal from the register along with justification.
  • The minister responsible for digitization provides data from the register to CSIRT MON, CSIRT NASK, and CSIRT GOV, as well as to the relevant sectoral CSIRT, the authority responsible for the supervised sector, and the key entity or important entity – in relation to the matters concerning them.
  • Data may be provided upon request to other entities mentioned in the Act on the KSC (such as relevant services and institutions) to the extent necessary to fulfill their statutory obligations.

OUR OFFER

We offer three support paths – from a quick diagnosis to a comprehensive legal opinion.

  1. Preliminary assessment – a quick analysis allowing to determine whether and to what extent the organization is subject to the requirements of NIS2 – start a short test.
  2. Free in-depth analysis – a detailed assessment based on a proprietary tool supported by artificial intelligence, which allows for the analysis of significantly more variables and scenarios - schedule a consultation with our advisor.
  3. Final legal opinion – a final, written opinion prepared by our team of lawyers, containing a clear conclusion along with justification - request a quote for the legal opinion.

Cybersecurity authorities responsible for supervision and enforcement of regulations

  • Minister responsible for energy – for the energy sector and the nuclear energy investment sector
  • Minister responsible for transport – for the transport sector (excluding the water transport subsector)
  • Minister responsible for maritime economy and Minister responsible for inland navigation – for the water transport subsector
  • Financial Supervision Authority – for the banking sector and the infrastructure of financial markets
  • Minister responsible for health – for the healthcare sector (excluding military entities) and the subsector of medical device production and in vitro diagnostic medical devices
  • Minister of National Defence – for the healthcare sector (military entities), the digital infrastructure sector (military), the sector of public entities subordinate to the Minister of National Defence or supervised by him, and for the office servicing this minister
  • Minister responsible for water management – for the drinking water supply and distribution sector and the collective sewage disposal sector
  • Minister responsible for informatization – for the civil digital infrastructure sector, the digital service providers sector, the ICT service management sector, and the sector of public entities (excluding entities subordinate to the Minister of National Defence or supervised by him, the office servicing this minister, entities from the sector subordinate to the Minister of Public Finances, and public entities mentioned in a sector other than the public entities sector)
  • Minister responsible for public finances – for the sector of public entities subordinate to the Minister of Public Finances
  • Authority competent for a given sector – for a public entity mentioned in a sector other than the public entities sector
  • President of the Office of Electronic Communications – for the electronic communications subsector (excluding military entities) and the postal services sector
  • Minister responsible for the economy – for the space sector, the chemicals production, manufacturing, and distribution sector, and the production sector (excluding the medical device production subsector and in vitro diagnostic medical devices)
  • Minister responsible for agriculture – for the food production, processing, and distribution sector
  • Minister responsible for climate – for the waste management sector
  • Minister responsible for higher education and science – for the research sector

Computer security incident response teams responsible for coordinating incidents reported by entities assigned in accordance with the Act on the National Cybersecurity System

  • CSIRT MON – for entities related to defense
  • CSIRT GOV – for public administration and state institutions
  • CSIRT NASK – for other entities (the majority of civil entities), including the private sector, local government units, budgetary units, municipal budgetary establishments, research institutes, cultural institutions, and municipal companies
  • Sectoral CSIRT – if designated for a specific sector (e.g., energy, health)

E-learning: cybersecurity

How to prepare the organization for the requirements of the Act on the National Cybersecurity System / NIS2 – key obligations

  1. Self-assessment and registration – checking compliance with the Act on the National Cybersecurity System and reporting as a key entity or important entity.
  2. Designation of a responsible person – reporting the data of the person or persons responsible for cybersecurity to the relevant CSIRT.
  3. Implementation of a risk management system to protect networks, systems, and their environment from incidents using technical, operational, and organizational measures.
  4. Implementation of necessary policies and procedures.
  5. Ensuring the security of human resources, basic cyber hygiene practices, and cybersecurity training for staff and management.
  6. Applying multi-factor or continuous authentication and secure forms of communication – voice, text, and video – within the entity as needed.
  7. Monitoring and threat detection – implementing mechanisms for continuous security monitoring.
  8. Ensuring service resilience – maintaining the availability of critical services by implementing business continuity and crisis management plans,
  9. Incident reporting, including reporting an incident to CSIRT within 24 hours of detection – in accordance with the rapid notification procedure.
  10. Management responsibility – oversight by the board and personal accountability for compliance with regulations.
  11. Documentation of activities – maintaining and storing documentation related to cybersecurity.
  12. Audit and control – conducting an audit of the security management system (once every 3 years, with the first audit to be conducted within 24 months from the date of meeting the criteria for being recognized as a key entity).
READ MORE: Is a Security Operations Center (SOC) necessary to meet the requirements of the KSC / NIS2?

Cybersecurity is not a one-time task, but an ongoing process that requires a systematic approach, diligence, continuity, adaptation, and testing.

The management remains primarily responsible; however, the entire organization must be involved in this process. Effective functioning requires close cooperation among departments and substantive units – without it, security cannot be ensured.

How to implement the requirements of the KSC / NIS2 in five steps

  1. Compliance audit with the KSC / NIS2 Act

Conduct a comprehensive assessment of the current state of information security in your company. This way, you will identify whether there are threats, vulnerabilities, and compliance with the NIS2 requirements specified in the KSC Act.

Actions

  • Review of current policies, procedures, and security measures.
  • Identification of critical IT assets and potential security gaps.
  • Assessment of compliance with current regulations and cybersecurity standards.
  1. Risk analysis

Identify information security threats and business continuity risks that you face. Implement security measures appropriate to the threats you identify. This way, you will minimize potential damage to the company, ensure its operational continuity, and increase resilience to cyber incidents.

NIS2, like GDPR, does not specify particular protective measures – it is up to you, based on the conducted risk analysis, to determine adequate security measures.

Risk analysis is a key step that allows for the identification of resources, threats, and security gaps.

Cezary Lutyński

PROMOTIONAL OFFER

Time for a Professional Risk Analysis

Are you wondering what real threats are lurking for your company? During a brief conversation, you will learn about our offer and receive a discount.

CHOOSE A CALL DATE

Actions

  • Determining the likelihood of various types of incidents occurring.
  • Assessing the potential impacts of incidents on the continuity of business operations.
  • Developing risk management plans that take into account various threat scenarios.
  1. Implementation of Adequate Security Measures

Introduce appropriate and proportional – to the assessed risk – technical and organizational measures (at least those mentioned in Article 8 of the KSC). This way, you will secure your company against cyber incidents.

Note: For public entities that are important entities, the requirements for the information security management system are specified in Annex 4 to the KSC. Failure to fulfill obligations in this regard may result in a financial penalty for the important entity.

Actions

  • Implementation of access control mechanisms and physical security measures.
  • Deployment of continuous monitoring of information systems.
  • Securing the ICT supply chain.
  • Regular software updates.
  1. Development of Documentation and Procedures

Create and implement documentation – policies and procedures that comply with the NIS2 requirements specified in Article 8 of the KSC. This documentation should include, among others:

  • risk and security analyses of information systems,
  • incident response and reporting procedures,
  • business continuity management,
  • ensuring the maintenance of critical services in the event of an incident and rapid recovery of systems after a failure,
  • ensuring supply chain security (risk assessment of suppliers and elimination of high-risk suppliers),
  • acquisition, development, and maintenance of networks and information systems, responding to detected vulnerabilities,
  • assessment of the effectiveness of risk management measures,
  • application of cryptography and encryption,
  • access control and asset management.

In this way, you will support information security management in your company.

Actions

  • Development and implementation of policies and procedures.
  • Documentation of incident response procedures and business continuity plans.
  • Documentation of the implementation of procedures specified in the documentation.
READ MORE: How to implement the KSC / NIS2 Act – information security policy
  1. Training for management and staff

Ensure the appropriate competencies of individuals responsible for cybersecurity, increasing their awareness and skills. This applies to both management and staff. This will enable you to effectively implement security policies and procedures.

The manager of a key entity or an important entity, as well as the person entrusted with the responsibilities of the manager in the area of cybersecurity, must undergo cybersecurity training at least once a year. It is necessary to document such participation.

The training aims to prepare individuals responsible for cybersecurity to effectively manage the protection of information systems within the organization, as well as to fulfill obligations arising from regulations, including, among others, in the area of:

  • applications for the list of key entities and important entities,
  • supervision over the security management system and making related decisions,
  • identification of threats,
  • incident response,
  • collaboration with response teams,
  • conducting risk assessments,
  • preparation for audits,
  • protection of confidential information.

All this to operate in accordance with regulations and ensure the digital security of the organization.

Actions

  • Organization of training for management regarding information security management and compliance with legal regulations.
  • Regular training for staff on the basic principles of cyber hygiene and specific obligations of NIS2 specified in the Act on the national cybersecurity system.
  • Familiarization of all employees with incident response procedures and their assigned roles and responsibilities.

Risk management measures in the area of cybersecurity

If your company is a key entity or an important entity, you are obliged to implement information security management measures. You do this to protect your information systems and ensure the continuity of service delivery. Below you will find the detailed requirements that you must meet.

  1. Risk Analysis and Security of Information Systems

  • Systematically assess the risks of incidents occurring and establish a risk management plan.
  • Implement appropriate and proportionate technical and organizational measures relative to the assessed risk. Take into account the latest state of knowledge, implementation costs, the size of the entity, and the likelihood of incidents occurring.
READ MORE: How to Implement the KSC / NIS2 Act – Risk Management
  1. Incident Management

  • Manage incidents – detect, record, analyze, classify, prioritize, take corrective actions, and mitigate the effects of incidents.
  • Gather information on cyber threats and vulnerabilities of the information system you use to provide the service.
READ MORE: How to Implement the KSC / NIS2 Act – Incident Management
  1. Business Continuity Measures

  • Maintain and securely operate the information system.
  • Implement, document, and maintain action plans that enable continuous and uninterrupted service delivery and ensure the confidentiality, integrity, availability, and authenticity of information. Remember that these plans should also include data recovery after a failure and crisis management.
READ MORE: How to Implement the KSC / NIS2 Act – Business Continuity
  1. Supply Chain Security and Continuity

  • Ensure the security and continuity of the supply chain of ICT products, ICT services, and ICT processes upon which the provision of services depends. This includes the relationships between your company and the hardware or software supplier.
READ MORE: How to implement the KSC / NIS2 Act – supply chain
  1. Security during the creation, development, and maintenance of systems

  • Implement a continuous monitoring system for information systems used to provide services.
  • Implement policies and procedures regarding the disclosure and handling of security vulnerabilities.
  1. Principles and procedures for assessing the effectiveness of cybersecurity risk management measures

  • Implement policies and procedures for assessing the effectiveness of technical and organizational measures used in risk management.
  1. Basic security principles and computer training

  • Increase employee awareness of cybersecurity, including basic principles of cyber hygiene.
  1. Policies regarding the proper use of cryptography and encryption

  • Implement policies and procedures regarding the use of cryptography, including encryption.
  1. Human resources security, access control principles, and resource management

  • Ensure physical and environmental security. Include access control in this regard.
  • Implement policies regarding resource management and access control.
  1. Use of multi-factor, secure voice/video/text communication and secure emergency communication

  • Use secure electronic communication measures within the national cybersecurity system that include multi-factor authentication.
  • Employ mechanisms that ensure the confidentiality, integrity, availability, and authenticity of data processed in the information system.
  • Regularly update software according to the manufacturer's recommendations. Include an impact analysis of updates on the security of the provided service and the criticality level of individual updates.

Consider that all measures must:

  • be proportional to the risk, size, cost, and impact and degree of harm of incidents,
  • take into account the latest state of knowledge, and where appropriate – also relevant European and international standards.

Powers of National Authorities

The Act on the National Cybersecurity System, in accordance with the requirements of the NIS2 Directive, provides for minimum competencies of national authorities in enforcing compliance with regulations. National authorities:

  • issue warnings for non-compliance with regulations,
  • issue binding orders,
  • order the cessation of activities that violate regulations,
  • require entities to ensure compliance with risk management measures or fulfill incident reporting obligations within a specified timeframe and in a specified manner,
  • require informing individuals or legal entities for whom services are provided about a serious cyber threat that may affect those services,
  • require the implementation – within a reasonable timeframe – of recommendations issued as a result of a security audit,
  • appoint an official for a specified period to monitor the implementation of specific actions,
  • impose the obligation to publicly disclose information about regulatory violations,
  • impose administrative fines,
  • suspend certifications or permits granted to an entity if the deadline for implementing actions has not been met (applies to essential entities),
  • temporarily deprive individuals in managerial positions of the ability to perform their functions (applies to essential entities).

Incident Reporting

The Act on the National Cybersecurity System, in accordance with the NIS2 requirement, introduces the obligation to gradually report incidents that have a serious impact on the provision of services. An incident must be reported to the relevant CSIRT.

An incident is classified as serious if it involves a significant deterioration in the quality or interruption of the continuity of the provided service, significant financial losses, or causes harm to individuals or other entities. The thresholds for classifying an incident as serious are specified in the regulation of the Council of Ministers.

TERMACTIONDESCRIPTION
24 hoursEarly

warning

- Providing information regarding the occurrence of the incident, the time of occurrence, detection, and duration.

- Indicating whether there is a suspicion of unlawful or malicious activity – if an assessment at this stage is possible.

- Determining whether the incident may affect other EU countries.

- If necessary – submitting a request to the relevant CSIRT for guidance or advice on measures to mitigate the effects of the incident or for additional technical support in handling it.

72 hoursIncident

report

- Describing the incident and its causes, indicating the service it concerns, determining the severity and consequences of the incident, as well as the probable effects on information systems and services provided.

- Presenting the preventive and corrective actions taken.

- Updating the information provided in the early warning – if there are any changes.

- Providing other relevant information – if it arises.

upon requestStatus

report



- Presenting the remedial actions taken.

- Providing current information about the incident.



The periodic report is submitted upon request of the relevant sectoral CSIRT.

1 monthFinal

report

- Preparation of a detailed description of the incident, including its severity and consequences.

- Identification of the type of threat or the primary cause that was likely the source of the incident.

- Presentation of the measures taken and implemented to mitigate the risk.

- Description of the cross-border effects of the incident – if any occurred.

- Submission of a progress report – if the incident is ongoing.

- Provision of a final report – within one month of the resolution of the incident.

In some cases, you must notify your service recipients of serious cyber threats. If it is in the public interest, CSIRT or the relevant competent authority may inform the public about a serious incident or require your company to do so.

Reports and notifications must be submitted via the information technology system of the Ministry of Digital Affairs. If it is not possible to submit them through the system, the method of making notifications will be specified by CSIRT in a communication on the website of the Ministry of National Defence, the Scientific and Academic Computer Network – National Research Institute, the Internal Security Agency, or the competent cybersecurity authority.

For public entities, the regulations provide for certain distinctions. Incident reporting is carried out by units designated for this purpose in accordance with the provisions of the Act on the National Cybersecurity System (KSC). The units designated for specific public entities may indicate deadlines by which they should provide information about incidents.

It should be noted that if the incident constitutes a breach of personal data protection, it may also need to be reported to the President of the Polish Data Protection Authority.

Information about the following may also be submitted to CSIRT:

  • other incidents,
  • cyber threats (e.g., new attack methods),
  • results of risk assessments,
  • vulnerabilities (e.g., gaps in systems),
  • potential events that may impact cybersecurity,
  • technologies used (e.g., new systems and software).

Liability for non-compliance with NIS2 requirements specified in KSC

The senior management of key and important entities is personally responsible for managing risks related to cyber threats and for the fulfillment of obligations in this regard by the managed entity. This responsibility cannot be excluded or limited, meaning that management cannot transfer it to other delegated persons, e.g., those dealing with IT.

If the governing body of the entity is a multi-member body and no individual has been designated as responsible for this area, the responsibility lies with all members of that body.

The purpose of this assumed responsibility is to ensure that cybersecurity is identified among the main objectives of the organization.

NIS2

Management Responsibilities

The top management of the company is responsible for managing cybersecurity risks in essential or important entities. If management fails to comply with the requirements of NIS2 specified in the KSC, it may result in financial penalties, and in egregious cases, the suspension of certifications or permits necessary for conducting business, or even a prohibition on holding managerial positions (these measures do not apply to public entities).

Individuals holding managerial positions in essential or important entities must:

  • approve the cybersecurity risk management measures implemented by the entity,
  • oversee the implementation of risk management measures,
  • participate in training to acquire sufficient knowledge and skills, as well as to identify risks and assess cybersecurity risk management practices and their impact on the services provided by the entity,
  • regularly provide similar training to their employees,
  • be accountable for non-compliance with regulations.

Financial penalties may be imposed for violations:

For essential entities:

up to 10,000,000 EUR or up to 2% of the total annual global turnover achieved in the previous financial year – whichever of these values is higher

For important entities:

up to 7,000,000 EUR or up to 1.4% of the total annual global turnover achieved in the previous financial year – depending on which of these values is higher

Benefits of implementing NIS2 / KSC

Implementing the requirements of NIS2 / the KSC Act translates into greater resilience to potential disruptions in activities crucial for the functioning of the state and the security of the Polish economy and society. Entities participating in this system will also feel the benefits – by adhering to legal requirements and high standards, they ensure the security of their own organization.

Caring for security is a manifestation of the organization's responsibility, which in turn translates into increased trust towards it and a better reputation.

The requirements concerning individual actions, such as the obligation to assess suppliers within the supply chain, allow for the early detection of potential threats and the avoidance of incidents.

Compliance with the requirements may also lead to an increase in the number of collaborations, particularly with entities from the public sector, where such compliance is crucial. A well-functioning system and cooperation among EU member states also contribute to enhanced security and effectiveness in responding to cross-border threats.

NIS2 - five elements that will determine the success of implementation

Guidelines or supporting materials regarding NIS2

The European Union Agency for Cybersecurity (ENISA) has published detailed technical guidelines for the implementation of NIS2, including, among others, mapping requirements to ISO/NIST standards, examples of compliance evidence, and practical advice:

How to Implement NIS2 / KSC – Summary

NIS2 / KSC represents another significant step towards improving cybersecurity and poses a challenge for both the business world and the public sector. The new obligations will affect many companies and public entities, and failure to comply may result in substantial fines and personal liability for management personnel.

The direction set by the European Union appears to be sound and forward-looking. Security in the digital world is crucial and simultaneously very seriously threatened. According to an old Chinese proverb: the best time to plant a tree was 20 years ago, and the second-best time is now. Today is the best time to ensure a secure future for your organization with the help of highly qualified specialists.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.