03.04.2026
NIS2 / KSC ACT • POLAND
NIS2 & Poland's KSC Act:Turn Requirements into Working Security Controls
A practical orientation to the major deadlines, governance duties and security measures, and where identity, access, monitoring and evidence controls fit within the broader programme.
At a glance
03.10.2026
Registration deadline*
03.04.2027
Implementation deadline*
03.04.2028
First audit deadline*
Applicable key entities
* These dates describe key transition deadlines for entities meeting the statutory criteria when the amendment entered into force. Registration method, audit duties and timing depend on entity status and circumstances; some entities are entered ex officio.
From EU direction to operational controls
NIS2 sets the European direction. The amended KSC Act implements it in Poland. Each organisation must translate its applicable duties into governance, risk decisions and working controls.
NIS2 Directive
EU level
Amended KSC Act
Polish implementation
Organisation
Governance
Risk
Security controls
Incident response
Evidence
Are we in scope?
Use these questions to orient the conversation, not replace a legal assessment.
- 01
What does your organisation do?
Map actual activities and services to the sectors and entity types listed in the Act.
- 02
How large is the organisation?
Assess the applicable size criteria and the treatment of partner or linked enterprises. Headcount or turnover alone is not the full test.
- 03
Do special rules or exceptions apply?
Certain entity types, public bodies, services and decisions may bring an organisation into scope regardless of the standard size rule.
This is an initial orientation, not a legal determination.
Check the Ministry's coverage overviewCoverage, simplified
The amended KSC Act covers essential and important entities across a broad set of sectors. Exact activities and exceptions matter.
Energy & transport
Electricity, heat, fuels, gas, hydrogen; air, rail, water and road transport
Finance & health
Banking, market infrastructure, healthcare, pharmaceuticals and medical products
Water & public services
Drinking water, wastewater, public administration and other listed public entities
Digital & ICT
Digital infrastructure, electronic communications, managed ICT services and digital providers
Industry & supply
Chemicals, food, selected manufacturing, postal services and waste management
Research & space
Research organisations, space and specified nuclear-energy investment activities
Implementation journey
3 Apr 2026
Amendment enters into force
The transition periods begin for entities that meet the statutory criteria on this date.
3 Oct 2026
Registration milestone
Applicable key and important entities must complete the required entry process, subject to ex officio registration and their circumstances.
3 Apr 2027
Controls operational
Applicable entities complete implementation of the new duties, including their information security management system and S46 connection.
3 Apr 2028
First audit milestone
The first mandatory cybersecurity audit is due for applicable key entities; precise audit duties depend on status and prior classification.
Significant incident reporting sequence
For reportable significant incidents, the sequence starts when the organisation becomes aware. Supporting data must come from across the environment, for example identity and error logs, downstream systems and work notes.
24h
Early warning
Initial signal to the competent CSIRT or authority, without undue delay.
Incidents must be reported through the S46 system to the appropriate CSIRT.
72h
Incident notification
An updated assessment of severity, impact and indicators where available.
≤ 1 month
Final report
A fuller account of the incident, root cause, mitigation and cross-border impact where relevant.
From requirements to implementation
Identity is a material control area, but it is only one part of an organisation-wide NIS2/KSC programme.
Governance
Management oversight turns security from a technical backlog into an accountable programme.
- Ownership and decisions
- Risk treatment
- Policies and training
Identity & Access
Make access intentional, strong and traceable across workforce, admins, customers and third parties.
- MFA and strong authentication
- Joiner / mover / leaver
- Privileged and third-party access
- Access governance and telemetry
Incident Response
Prepare people, evidence and escalation paths before a reporting clock starts.
- Detection and triage
- CSIRT coordination
- Reporting workflows
Business Continuity
Protect service resilience and establish recoverable operating modes.
- Backups and recovery
- Crisis procedures
- Resilience testing
Supply-Chain Security
Address dependency and access risk across suppliers and service providers.
- Supplier assurance
- Third-party access
- Contractual controls
Monitoring & Evidence
Collect usable telemetry and audit trails across the relevant technology estate.
- Centralised logs
- Investigation support
- Operational evidence
Where Zelto fits
Clear responsibility boundaries create credible delivery. Zelto owns the technical areas it knows deeply and works alongside legal, GRC and broader cyber specialists.
NIS2 / KSC programme
Client / legal / GRC ownership
Governance & legal interpretation
Client + qualified legal / GRC support
Scope, legal duties, risk acceptance and programme governance.
Broader cyber programme
Client + specialist partners
Continuity, enterprise incident response, network and endpoint controls, supply chain and other domains.
Zelto-owned implementation
Identity & Access
Zelto
Architecture, authentication, lifecycle, privileged access, governance and identity telemetry.
Shared / supporting delivery
Monitoring & Evidence
Zelto + relevant tooling
Centralised logging, identity/security telemetry, audit trails and investigation support.
Two leadership views, one programme
For CISOs
Build a deliverable security programme
Translate scope and risk into controls that operate, produce evidence, and withstand real incidents. Your team has the tools but Zelto brings in extra hands and specialist expertise to implement them faster and make them audit-ready.
- Confirm scope, systems and accountable owners
- Establish the security-management and risk process
- Prioritise identity, detection, response and continuity controls
- Make reporting paths and evidence collection operational
- Test readiness and close audit gaps
Why leadership should care
The amended framework makes cyber risk a management concern as well as a technical one. The right response is to implement governance in a measured way and not drive fear-based compliance.
01
Organisational exposure
Severe non-compliance can carry substantial financial consequences, with the applicable regime depending on entity type and circumstances.
02
Active responsibility
Management must oversee the programme and cannot simply delegate accountability away to IT or a supplier.
03
Decisions and evidence
Priorities, funding, accepted risks, training and remediation should be documented and revisited.
How Zelto helps
Identity & Access
Implement identity controls that work in daily operations and create defensible records.
MFA and phishing-resistant authentication
Workforce identity and Auth0 / CIAM where relevant
Lifecycle automation and joiner / mover / leaver
Privileged, admin and third-party access
Access governance and authentication policy
Identity telemetry and audit trails
Monitoring & Evidence
Connect identity signals to the wider monitoring and evidence model.
Centralised log management with TeskaLabs LogMan.io
Broader correlation and detection capabilities where required
Identity and security telemetry integration
Audit trails and investigation support
Incident evidence and monitoring integration
Official sources
Last updated: August 2026
This page provides general information about NIS2 and the Polish KSC Act and does not constitute legal advice. Organisations should confirm their specific legal obligations with qualified counsel where required.
Not sure where your identity and monitoring controls stand?
Zelto can help assess and implement the identity, access and monitoring controls that form part of a broader NIS2/KSC readiness programme.