
In a world where a single cyber incident can halt production, paralyze a supply chain, or expose the confidential data of thousands of customers, cybersecurity has become an operational cornerstone of every business. April 3, 2026 is a date that permanently changes the rules of the game for the Polish internet and economy. That’s the day the long-awaited amendment to the National Cybersecurity System Act (UKSC), implementing the EU’s NIS2 directive, comes into force. Time is running out, and penalties for non-compliance can reach millions of euros. Find out whether your company falls under the new rules and how to avoid steep sanctions.
What is the amended KSC Act and the NIS2 directive?
The amended National Cybersecurity System Act (KSC 2.0) is a revolution in Polish law aimed at strengthening the digital resilience of the state, public administration, and key economic sectors. The legislative process wrapped up in early 2026 – the President signed the act on February 19, and it was published in the Journal of Laws on March 2.
The provisions take effect after a one-month vacatio legis, meaning April 3, 2026. The new regulations introduce strict requirements for risk management and incident response and – most importantly – shift responsibility for cybersecurity from IT departments directly onto the shoulders of company boards.
Who does the new KSC Act apply to in 2026? Essential and important entities
The amendment dramatically broadens the scope of companies covered by the regulations. The previous split between operators of essential services and digital service providers now gives way to a broader classification into essential entities and important entities. Estimates suggest the number of organizations covered by the obligation will multiply several times over in Poland.
The basic classification principle is the so-called size-cap rule:
- Essential entities: Mainly large enterprises (over 250 employees or turnover above EUR 50 million) operating in sectors such as energy, transport, banking, healthcare, drinking water, digital infrastructure, or public administration. Regardless of size, this group also includes DNS service providers, public entities, and domain name registries.
- Important entities: This category mainly covers medium-sized enterprises (50-249 employees or turnover of EUR 10-50 million) in sectors such as postal services, waste management, food, chemicals, medical device, electronics or vehicle production and distribution, as well as digital service providers and research organizations.
Note: An organization must independently verify (self-identify) whether, based on its PKD business activity codes and size criteria, it qualifies under the new regulation.
The most important obligations for companies – what must you implement?
The KSC Act imposes a series of rigorous obligations on companies aimed at ensuring business continuity. The most important of these are:
- Registration in the KSC registry (System S46): Every entity must register with a special registry maintained by the Ministry of Digital Affairs in the S46 IT system.
- Implementing an Information Security Management System (ISMS): Companies must, among other things, conduct systematic risk assessments, secure their supply chain, and implement appropriate cryptographic measures.
- Continuous monitoring and incident reporting (SOC): The act requires strict reporting of so-called major incidents to the relevant CSIRT team. This process is subject to tight time limits:
- An early warning must be sent within 24 hours.
- A full incident report is required within 72 hours.
- A final report must be filed within 1 month. To meet these requirements, organizations in practice need to rely on round-the-clock Security Operations Centers (SOC), whether their own or outsourced.
- Cybersecurity audits: Essential entities will be required to undergo a mandatory, independent audit at least once every two years.
KSC 2.0 implementation timeline – key deadlines through 2028
Managing the implementation timeline is critical for avoiding fines. Below is the updated statutory calendar:
- April 3, 2026 – The amended act takes effect.
- October 3, 2026 – Final deadline (6 months) for essential and important entities to self-identify and submit an application for entry into the S46 system registry.
- April 3, 2027 – End of the 12-month transition period for fully implementing risk management measures (ISMS) and integrating with the S46 system.
- April 3, 2028 – Deadline for conducting the first mandatory audit for newly designated essential entities. From this point on, full enforcement of financial administrative penalties will also begin.
Penalties for UKSC non-compliance – watch out for board liability!
Sanctions for ignoring NIS2 rules in Poland are among the strictest in Europe. Depending on the entity’s tier, they amount to:
- For essential entities: up to EUR 10,000,000 or up to 2% of annual global turnover.
- For important entities: up to EUR 7,000,000 or up to 1.4% of annual global turnover.
- In extreme cases (threats to state security or human life), Polish law provides for fines of up to PLN 100,000,000.
The biggest change, however, is the personal liability of company management and boards. For failing to properly oversee cybersecurity procedures, executives can face a financial penalty ranging from 100% (in public institutions) to several hundred percent of their salary, and can even be banned from holding management positions.
High-Risk Suppliers (HRS) – what you need to know
The act also introduces a strict procedure for excluding so-called High-Risk Suppliers (HRS) from the market. Proceedings in this matter will be conducted by the Minister of Digital Affairs. If a supplier of given software or telecommunications equipment is placed on the HRS list, essential and important entities will be required to fully stop purchasing its solutions and withdraw existing equipment from use within 4 to 7 years.
It’s worth noting that when the President of Poland signed the act in February 2026, he simultaneously referred the provisions on high-risk suppliers to the Constitutional Tribunal for subsequent review. Nevertheless, the law has been in force since April 2026, and companies must comply with the restrictions.
Summary: How to prepare your company for KSC 2.0
2026 leaves no room for illusions – investing in cybersecurity is a legal and business requirement. The best practice, recommended by experts in IT and GRC, is to start the process with an independent gap analysis, which precisely identifies the differences between your company’s current state and NIS2 requirements.
Don’t be fooled by myths – having ISO 27001-compliant documentation sitting in a drawer isn’t enough to meet KSC’s rigorous requirements. Make sure you have continuous infrastructure monitoring in place (for example, through an outsourced SOC service) and start the implementation process immediately, since the clock on the 12-month transition period has been ticking since April 3, 2026.
