NIS2 / KSC: obligation assessment, readiness review and implementation support

Support in assessing NIS2/KSC requirements, conducting a readiness assessment and implementing the measures required for compliance.

NIS2 & KSC: Key obligations, deadlines and challenges

The Network and Information Security 2 (NIS2) Directive introduces new requirements related to cybersecurity management, risk management and organisational resilience to incidents. Its objective is to strengthen the cybersecurity posture of entities providing services that are essential to the economy, public administration and society. In Poland, the requirements have been implemented into national legislation through amendments to the National Cybersecurity System Act (KSC), which entered into force on 3 April 2026.

Key deadlines

Organisations subject to the regulation must implement the required organisational and technical measures by 3 April 2027. Entities meeting the criteria for designation as an essential entity or an important entity, and which have not been included in the KSC Register automatically, should complete a self-assessment and submit an application for registration by 3 October 2026.

Organisations operating in international groups

For organisations operating within international groups, it is also important to consider that the implementation timeline and approach to NIS2 may vary across jurisdictions. As a result, local KSC requirements may need to be aligned with group-wide expectations, policies and experience gained from NIS2 implementation programmes in other countries.

Early steps towards NIS2 and KSC compliance

For many organisations, the first challenge is not the implementation of NIS2 requirements itself, but determining whether the regulation applies and identifying which actions should be planned in advance. In practice, preparing for compliance often involves organisational, procedural and technical changes that require coordination across multiple business functions and stakeholder groups.

Is your organisation within the scope of NIS2 / KSC?

Key criteria that typically determine whether an organisation falls within the scope of the regulation:

  • sector and nature of business activities;
  • organisation size and group structure;
  • importance of services provided to customers, the economy or society;
  • dependence of critical processes on information systems;
  • potential impact of disruption on business operations or the supply chain.

Key questions for organisations:

  • Does the regulation apply to our business activities?
  • Should the organisation be registered in the KSC Register as an essential entity or an important entity?
  • To what extent do existing measures meet NIS2 / KSC requirements?
  • What actions should be planned and implemented before the applicable regulatory deadlines?

NIS2 applies to organisations operating across 18 sectors, including energy, transport, healthcare, food production, selected manufacturing industries, digital infrastructure, ICT service management, postal and courier services, as well as selected digital services. However, sector classification alone does not determine whether an organisation is subject to the regulation. Establishing the applicability of NIS2 and KSC requirements requires an assessment of the organisation’s specific circumstances, activities and role within the broader economic ecosystem.

 

Speak with our experts

Forvis Mazars support for NIS2 / KSC compliance

Preparing for NIS2 and KSC compliance requires addressing both organisational and technical requirements. In many cases, this involves coordinating efforts across multiple business functions and stakeholders. Forvis Mazars provides support tailored to the organisation's specific needs and level of readiness, from assessing regulatory obligations and identifying gaps to implementing the measures required for compliance.

 

PhaseScope of supportOutcome for the organisationTimeline*
1. Assessment of NIS2 / KSC obligationsReview of activities, sector, organisation size and applicable regulatory criteria.Assessment of potential regulatory applicability, indication of possible status as an essential or important entity, and recommendations for next steps.

1–2 weeks

2. Organisational readiness assessmentReview of processes, documentation and governance mechanisms against NIS2 / KSC requirements.Gap analysis, prioritisation of actions and identification of areas requiring improvement.

3–5 weeks

3. Action plan and recommendationsDefinition of required actions, implementation priorities, responsibilities and timelines.A practical implementation roadmap tailored to the organisation's needs.

1–2 weeks

4. Implementation and ongoing supportSupport in developing policies, procedures, governance frameworks, reporting processes and supplier oversight mechanisms.Support with implementing agreed changes and ongoing expert advisory assistance.

From several weeks to several months

*Timelines are indicative and may vary depending on the scope of work, complexity of the organisation and availability of relevant information. The duration and scope of the implementation phase will be determined by the organisation’s size, level of readiness and the extent of the measures required to achieve compliance.

Areas commonly assessed as part of NIS2 / KSC readiness

  • Cybersecurity governance and management accountability
  • Risk management
  • Incident response
  • Business continuity and recovery
  • Third-party and supply chain security
  • Policies, procedures and documentation
  • Reporting, oversight and communication
  • Technical and organisational measures

 

Start with an initial assessment

A short conversation can help assess whether the organisation may be subject to NIS2 / KSC requirements, identify which obligations may apply, and determine the actions that should be prioritised. Ahead of the meeting, we can provide a set of key diagnostic questions to help structure the assessment and support the next steps towards compliance.

 

Speak with our experts

Want to know more?