What are NIS2 and KSC?
NIS2 (Network and Information Security Directive 2) is an EU cybersecurity directive designed to strengthen organisations’ resilience to cyber threats and the security of network and information systems. It introduces obligations for selected entities, including cybersecurity risk management, security measures and incident reporting. In Poland, NIS2 requirements were implemented through an amendment to the National Cybersecurity System Act (KSC), which entered into force on 3 April 2026.
Is our organisation subject to NIS2 / KSC requirements?
The scope of the regulation depends primarily on the sector and type of activity, the organisation’s size and specific criteria set out in the KSC Act. As a rule, it applies to medium-sized and large entities operating across 18 sectors, including energy, transport, healthcare, banking, digital infrastructure, public administration, water and wastewater, waste management, manufacturing, postal and courier services, and ICT service management. Organizations should assess whether the regulation applies to them and if it does, whether they qualify as an essential or important entity. Once the scope has been confirmed, a gap analysis should be performed to understand the actions needed to be taken to ensure compliance.
By when must our organisation comply with NIS2 / KSC requirements?
Essential and important entities that met the statutory criteria when the amendment entered into force should register in the KSC Register by 3 October 2026, unless they were entered automatically. The second key date is 3 April 2027 — by then, obligations introduced by the new legislation, including the required organisational and technical measures, must be implemented. Different timelines may apply in specific cases, for example for entities entered automatically or those meeting the criteria at a later date.
What are the consequences of non-compliance with NIS2 / KSC requirements?
Non-compliance with NIS2 / KSC requirements may lead to sanctions or administrative fines. The consequences depend on the type of entity, the nature of the non-compliance and the circumstances of the case. Irrespective of regulatory sanctions, insufficient safeguards may increase the risk of cyberattacks, operational disruption, data loss and financial damag
What is a Gap Analysis?
A Gap Analysis compares the way an organisation currently manages cybersecurity with NIS2 / KSC requirements. It covers areas including existing processes and documentation, roles and responsibilities, risk management, incident response, business continuity, supplier security, and the protection of systems and data. It shows which requirements are already met, where gaps remain and what actions should be taken to address them. The scope may be extended to include an implementation plan setting out priorities, responsibilities and indicative timelines.
Our organisation operates within an international group. Are NIS2 requirements the same in every country?
No. NIS2 is an EU directive, but each Member State implements it through their national legislation. This creates differences in timelines, detailed requirements, registration rules, regulatory expectations and supervisory practices. International groups should therefore ensure they address local requirements in each country they operate in. Through the Forvis Mazars international network, we involve local offices on international projects to provide support reflecting the requirements and supervisory practices in each specific jurisdiction as understanding each country’s requirements is key for ensuring compliance.
Can a small organisation also be subject to NIS2 / KSC requirements?
Yes. Although the KSC Act generally covers medium-sized and large entities in specified sectors, smaller organisations may also be in scope in certain circumstances. Some entities may be covered regardless of size due to the nature of their services, their particular importance to the economy or society, or designation by the competent authority. In addition, an organisation not directly subject to the KSC Act may receive demands to follow NIS2 / KSC cybersecurity requirements from regulated customers as part of their supply chain security management. The assessment of applicability should therefore consider both statutory criteria and the organisation’s role in the supply chain of entities subject to NIS2 / KSC.
Which areas of the organisation are affected by NIS2 / KSC requirements?
NIS2 / KSC requirements extend beyond IT and cover areas including management accountability, cybersecurity and risk management, incident response, business continuity, supplier and supply chain security, protection of information systems, documentation and reporting. Implementation typically requires cooperation between business, IT, security, risk, procurement, HR, legal and compliance teams, as well as executive management.
Does ISO/IEC 27001 certification mean compliance with NIS2 / KSC?
No. ISO/IEC 27001 certification generally indicates a higher level of maturity in information security management and may provide a strong foundation for preparation. However, it does not automatically demonstrate compliance with all NIS2 / KSC requirements. The certification scope and any requirements not fully covered by the existing management system should be assessed.
What does NIS2 / KSC preparation and implementation look like?
The process is typically delivered in stages: (1) assessment of whether the regulation applies and determination of entity status, (2) gap analysis against the requirements, (3) development of an implementation plan with priorities, ownership and timelines, (4) gap remediation implementation covering organisational, procedural and technical changes, (5) a post-implementation readiness assessment, and (6) an audit or self-assessment as required. The detailed scope depends on the organisation’s profile, existing arrangements and maturity level.
How can Forvis Mazars help?
The first step can be a short discussion about the organisation’s profile, the potential applicability of NIS2 / KSC and possible next actions. This discussion is introductory and does not replace a formal assessment of whether the regulation applies and what the organisation’s status may be. Depending on the organisation’s needs, we can support this assessment with a gap analysis, comparing existing processes with the requirements and identifying the necessary actions to ensure compliance. Based on the listed gaps, we can help develop an implementation plan and support organisational, procedural and technical changes during implementation phase. After implementation, we can perform a readiness assessment as an optional and separate stage to verify whether the arrangements operate effectively and the organisation is compliant. We can also perform or support you in performing an audit or self-assessment. For international groups, we can coordinate multi-country programmes, combining a consistent group-wide approach with the local expertise of Forvis Mazars teams. This provides a clear and practical path tailored to the organisation’s scale, risk profile and maturity.
This website uses cookies.
Some of these cookies are necessary, while others help us analyse our traffic, serve advertising and deliver customised experiences for you.
For more information on the cookies we use, please refer to our Privacy Policy.
This website cannot function properly without these cookies.
Analytical cookies help us enhance our website by collecting information on its usage.
We use marketing cookies to increase the relevancy of our advertising campaigns.