Entity self-identification
We analyse the entity’s actual activities, statutory sectors, size and applicable exemptions to assess whether it is an essential or important entity.
NIS2/KSC audit and implementation
We support entity self-identification, gap analysis and implementation of risk management, supply-chain security and incident handling under NIS2 and the Polish National Cybersecurity System Act.
Current obligations
The amendment to the Polish National Cybersecurity System Act entered into force on 3 April 2026. The scope of duties depends on the sector, the entity’s actual activities, its size and specific statutory criteria.
We analyse the entity’s actual activities, statutory sectors, size and applicable exemptions to assess whether it is an essential or important entity.
We organise the data required for registration and prepare an implementation plan aligned with statutory deadlines.
We design roles, policies, risk assessment, supplier oversight, business continuity and metrics required to maintain cyber resilience.
We prepare approval rules for security measures, risk reporting and training that support informed decisions by management bodies.
NIS2 compliance audit
Our gap analysis is not merely a list of legal provisions. Each gap is connected with a risk, owner, recommendation and target date.
We assess asset, access and vulnerability management, backups, cryptography, business continuity and safeguard effectiveness.
We assess supplier criticality, contractual requirements, risk monitoring and procedures for events affecting ICT partners.
We develop event classification, escalation paths, evidence records and communications required for timely reporting.
We prepare management and operational teams and test procedures through exercises and internal audits.
Action plan
We analyse the entity’s actual activities, statutory sectors and entity types, enterprise size and any specific qualifying criteria. We determine its potential status as an essential or important entity and identify the services, processes, organisational units and material dependencies within scope.
We compare the current state with NIS2 and Polish KSC requirements, assessing risk management, assets, incidents, business continuity, suppliers, vulnerabilities, access and existing safeguards. The results form a prioritised action plan with owners and deadlines.
We design and launch the security management system, roles, policies, procedures, safeguards, and incident handling and reporting processes. We support management and team training and collect evidence demonstrating fulfilment of the applicable obligations.
We monitor metrics, risks, incidents, suppliers and corrective actions, and update the arrangements following organisational or technological changes. We conduct internal audits and tests to maintain inspection readiness and the continuing effectiveness of the implemented measures.
Engagement outcome
Deliverables are tailored to the entity’s status, operating profile, risk and the agreed support model.
An analysis of the applicable criteria, covered services and organisational units, with reasoning supporting the potential essential or important entity status.
Findings concerning processes, technology and implementation evidence, linked to risks, priorities and recommended treatment.
An action plan with owners, deadlines, dependencies and acceptance criteria covering organisational, technical and reporting requirements.
Documentation for risk, supplier, incident and business continuity management, together with organised evidence of fulfilment.
Frequently asked questions
Yes. The Polish amendment implementing NIS2 entered into force on 3 April 2026.
The requirements primarily apply to essential and important entities operating in statutory sectors. The assessment requires analysis of the entity’s actual activities, size, the applicable annex and specific statutory criteria.
For entities meeting the criteria when the amendment entered into force, relevant dates include the deadline for submitting an application for entry in the register by 3 October 2026 and implementing security obligations by 3 April 2027. Each deadline should be confirmed for the specific circumstances.
The scope is tailored to the organisation. It typically covers risk management, assets, incidents, business continuity, suppliers, vulnerabilities, access, backups, training, management accountability and implementation evidence.
ISO 27001 can strongly support systematic information security management, but it does not automatically confirm fulfilment of every NIS2 or Polish KSC obligation.
Related areas
ISMS, risk analysis, readiness audit and continual information security improvement.
Learn more →Personal data protection, controller and DPO roles, breaches and data protection by design.
Learn more →Read the Polish Ministry of Digital Affairs notice on the amendment and implementation dates.
Learn more →Contact us for a free 30-minute initial consultation.
Book a consultation ↗