NIS2 / KSC ACT • POLAND

NIS2 & Poland's KSC Act:Turn Requirements into Working Security Controls

A practical orientation to the major deadlines, governance duties and security measures, and where identity, access, monitoring and evidence controls fit within the broader programme.

Book a discovery callSee where Zelto can help

At a glance

01

03.04.2026

Act in force

02

03.10.2026

Registration deadline*

03

03.04.2027

Implementation deadline*

04

03.04.2028

First audit deadline*

Applicable key entities

* These dates describe key transition deadlines for entities meeting the statutory criteria when the amendment entered into force. Registration method, audit duties and timing depend on entity status and circumstances; some entities are entered ex officio.

From EU direction to operational controls

NIS2 sets the European direction. The amended KSC Act implements it in Poland. Each organisation must translate its applicable duties into governance, risk decisions and working controls.

NIS2 Directive

EU level

Amended KSC Act

Polish implementation

Organisation

Governance

Risk

Security controls

Incident response

Evidence

Are we in scope?

Use these questions to orient the conversation, not replace a legal assessment.

  1. 01

    What does your organisation do?

    Map actual activities and services to the sectors and entity types listed in the Act.

  2. 02

    How large is the organisation?

    Assess the applicable size criteria and the treatment of partner or linked enterprises. Headcount or turnover alone is not the full test.

  3. 03

    Do special rules or exceptions apply?

    Certain entity types, public bodies, services and decisions may bring an organisation into scope regardless of the standard size rule.

This is an initial orientation, not a legal determination.

Check the Ministry's coverage overview

Coverage, simplified

The amended KSC Act covers essential and important entities across a broad set of sectors. Exact activities and exceptions matter.

Energy & transport

Electricity, heat, fuels, gas, hydrogen; air, rail, water and road transport

Finance & health

Banking, market infrastructure, healthcare, pharmaceuticals and medical products

Water & public services

Drinking water, wastewater, public administration and other listed public entities

Digital & ICT

Digital infrastructure, electronic communications, managed ICT services and digital providers

Industry & supply

Chemicals, food, selected manufacturing, postal services and waste management

Research & space

Research organisations, space and specified nuclear-energy investment activities

Implementation journey

  1. 3 Apr 2026

    Amendment enters into force

    The transition periods begin for entities that meet the statutory criteria on this date.

  2. 3 Oct 2026

    Registration milestone

    Applicable key and important entities must complete the required entry process, subject to ex officio registration and their circumstances.

  3. 3 Apr 2027

    Controls operational

    Applicable entities complete implementation of the new duties, including their information security management system and S46 connection.

  4. 3 Apr 2028

    First audit milestone

    The first mandatory cybersecurity audit is due for applicable key entities; precise audit duties depend on status and prior classification.

Significant incident reporting sequence

For reportable significant incidents, the sequence starts when the organisation becomes aware. Supporting data must come from across the environment, for example identity and error logs, downstream systems and work notes.

  1. 24h

    Early warning

    Initial signal to the competent CSIRT or authority, without undue delay.

    Incidents must be reported through the S46 system to the appropriate CSIRT.

  2. 72h

    Incident notification

    An updated assessment of severity, impact and indicators where available.

  3. ≤ 1 month

    Final report

    A fuller account of the incident, root cause, mitigation and cross-border impact where relevant.

From requirements to implementation

Identity is a material control area, but it is only one part of an organisation-wide NIS2/KSC programme.

Governance

Management oversight turns security from a technical backlog into an accountable programme.

  • Ownership and decisions
  • Risk treatment
  • Policies and training

Identity & Access

Make access intentional, strong and traceable across workforce, admins, customers and third parties.

  • MFA and strong authentication
  • Joiner / mover / leaver
  • Privileged and third-party access
  • Access governance and telemetry

Incident Response

Prepare people, evidence and escalation paths before a reporting clock starts.

  • Detection and triage
  • CSIRT coordination
  • Reporting workflows

Business Continuity

Protect service resilience and establish recoverable operating modes.

  • Backups and recovery
  • Crisis procedures
  • Resilience testing

Supply-Chain Security

Address dependency and access risk across suppliers and service providers.

  • Supplier assurance
  • Third-party access
  • Contractual controls

Monitoring & Evidence

Collect usable telemetry and audit trails across the relevant technology estate.

  • Centralised logs
  • Investigation support
  • Operational evidence

Where Zelto fits

Clear responsibility boundaries create credible delivery. Zelto owns the technical areas it knows deeply and works alongside legal, GRC and broader cyber specialists.

NIS2 / KSC programme

Client / legal / GRC ownership

Governance & legal interpretation

Client + qualified legal / GRC support

Scope, legal duties, risk acceptance and programme governance.

Broader cyber programme

Client + specialist partners

Continuity, enterprise incident response, network and endpoint controls, supply chain and other domains.

Zelto-owned implementation

Identity & Access

Zelto

Architecture, authentication, lifecycle, privileged access, governance and identity telemetry.

Shared / supporting delivery

Monitoring & Evidence

Zelto + relevant tooling

Centralised logging, identity/security telemetry, audit trails and investigation support.

Two leadership views, one programme

For CISOs

Build a deliverable security programme

Translate scope and risk into controls that operate, produce evidence, and withstand real incidents. Your team has the tools but Zelto brings in extra hands and specialist expertise to implement them faster and make them audit-ready.

  • Confirm scope, systems and accountable owners
  • Establish the security-management and risk process
  • Prioritise identity, detection, response and continuity controls
  • Make reporting paths and evidence collection operational
  • Test readiness and close audit gaps

Why leadership should care

The amended framework makes cyber risk a management concern as well as a technical one. The right response is to implement governance in a measured way and not drive fear-based compliance.

01

Organisational exposure

Severe non-compliance can carry substantial financial consequences, with the applicable regime depending on entity type and circumstances.

02

Active responsibility

Management must oversee the programme and cannot simply delegate accountability away to IT or a supplier.

03

Decisions and evidence

Priorities, funding, accepted risks, training and remediation should be documented and revisited.

How Zelto helps

Identity & Access

Implement identity controls that work in daily operations and create defensible records.

MFA and phishing-resistant authentication

Workforce identity and Auth0 / CIAM where relevant

Lifecycle automation and joiner / mover / leaver

Privileged, admin and third-party access

Access governance and authentication policy

Identity telemetry and audit trails

Monitoring & Evidence

Connect identity signals to the wider monitoring and evidence model.

Centralised log management with TeskaLabs LogMan.io

Broader correlation and detection capabilities where required

Identity and security telemetry integration

Audit trails and investigation support

Incident evidence and monitoring integration

Not sure where your identity and monitoring controls stand?

Zelto can help assess and implement the identity, access and monitoring controls that form part of a broader NIS2/KSC readiness programme.

Book a discovery call