NIS2 / KSC: obligation assessment, readiness review and implementation support

Support in assessing NIS2/KSC requirements, conducting a readiness assessment and implementing the measures required for compliance.

NIS2 & KSC: Key obligations, deadlines and challenges

The Network and Information Security 2 (NIS2) Directive introduces new requirements related to cybersecurity management, risk management and organisational resilience to incidents. Its objective is to strengthen the cybersecurity posture of entities providing services that are essential to the economy, public administration and society. In Poland, the requirements have been implemented into national legislation through amendments to the National Cybersecurity System Act (KSC), which entered into force on 3 April 2026.

Key deadlines

Organisations subject to the regulation must implement the required organisational and technical measures by 3 April 2027. Entities meeting the criteria for designation as an essential entity or an important entity, and which have not been included in the KSC Register automatically, should complete a self-assessment and submit an application for registration by 3 October 2026.

Organisations operating in international groups

For organisations operating within international groups, it is also important to consider that the implementation timeline and approach to NIS2 may vary across jurisdictions. As a result, local KSC requirements may need to be aligned with group-wide expectations, policies and experience gained from NIS2 implementation programmes in other countries.

Early steps towards NIS2 and KSC compliance

For many organisations, the first challenge is not the implementation of NIS2 requirements itself, but determining whether the regulation applies and identifying which actions should be planned in advance. In practice, preparing for compliance often involves organisational, procedural and technical changes that require coordination across multiple business functions and stakeholder groups.

Is your organisation within the scope of NIS2 / KSC?

Key criteria that typically determine whether an organisation falls within the scope of the regulation:

  • sector and nature of business activities;
  • organisation size and group structure;
  • importance of services provided to customers, the economy or society;
  • dependence of critical processes on information systems;
  • potential impact of disruption on business operations or the supply chain.

Key questions for organisations:

  • Does the regulation apply to our business activities?
  • Should the organisation be registered in the KSC Register as an essential entity or an important entity?
  • To what extent do existing measures meet NIS2 / KSC requirements?
  • What actions should be planned and implemented before the applicable regulatory deadlines?

NIS2 applies to organisations operating across 18 sectors, including energy, transport, healthcare, food production, selected manufacturing industries, digital infrastructure, ICT service management, postal and courier services, as well as selected digital services. However, sector classification alone does not determine whether an organisation is subject to the regulation. Establishing the applicability of NIS2 and KSC requirements requires an assessment of the organisation’s specific circumstances, activities and role within the broader economic ecosystem.

 

Speak with our experts

Forvis Mazars support for NIS2 / KSC compliance

Preparing for NIS2 and KSC compliance requires addressing both organisational and technical requirements. In many cases, this involves coordinating efforts across multiple business functions and stakeholders. Forvis Mazars provides support tailored to the organisation's specific needs and level of readiness, from assessing regulatory obligations and identifying gaps to implementing the measures required for compliance.

 

PhaseScope of supportOutcome for the organisation
1. Assessment of NIS2 / KSC obligationsReview of activities, sector, organisation size and applicable regulatory criteria.Assessment of potential regulatory applicability, indication of possible status as an essential or important entity, and recommendations for next steps.
2. Organisational readiness assessmentReview of processes, documentation and governance mechanisms against NIS2 / KSC requirements.Gap analysis, prioritisation of actions and identification of areas requiring improvement.
3. Action plan and recommendationsDefinition of required actions, implementation priorities, responsibilities and timelines.A practical implementation roadmap tailored to the organisation's needs.
4. Implementation and ongoing supportSupport in developing policies, procedures, governance frameworks, reporting processes and supplier oversight mechanisms.Support with implementing agreed changes and ongoing expert advisory assistance.

Timelines may vary depending on the scope of work, complexity of the organisation and availability of relevant information. The duration and scope of the implementation phase will be determined by the organisation’s size, level of readiness and the extent of the measures required to achieve compliance.

Areas commonly assessed as part of NIS2 / KSC readiness

  • Cybersecurity governance and management accountability
  • Risk management
  • Incident response
  • Business continuity and recovery
  • Third-party and supply chain security
  • Policies, procedures and documentation
  • Reporting, oversight and communication
  • Technical and organisational measures

 

Start with an initial assessment

A short conversation can help assess whether the organisation may be subject to NIS2 / KSC requirements, identify which obligations may apply, and determine the actions that should be prioritised. Ahead of the meeting, we can provide a set of key diagnostic questions to help structure the assessment and support the next steps towards compliance.

 

Speak with our experts

What are NIS2 and KSC?

NIS2 (Network and Information Security Directive 2) is an EU cybersecurity directive designed to strengthen organisations’ resilience to cyber threats and the security of network and information systems. It introduces obligations for selected entities, including cybersecurity risk management, security measures and incident reporting. In Poland, NIS2 requirements were implemented through an amendment to the National Cybersecurity System Act (KSC), which entered into force on 3 April 2026.

Is our organisation subject to NIS2 / KSC requirements?

The scope of the regulation depends primarily on the sector and type of activity, the organisation’s size and specific criteria set out in the KSC Act. As a rule, it applies to medium-sized and large entities operating across 18 sectors, including energy, transport, healthcare, banking, digital infrastructure, public administration, water and wastewater, waste management, manufacturing, postal and courier services, and ICT service management. Organizations should assess whether the regulation applies to them and if it does, whether they qualify as an essential or important entity. Once the scope has been confirmed, a gap analysis should be performed to understand the actions needed to be taken to ensure compliance.

By when must our organisation comply with NIS2 / KSC requirements?

Essential and important entities that met the statutory criteria when the amendment entered into force should register in the KSC Register by 3 October 2026, unless they were entered automatically. The second key date is 3 April 2027 — by then, obligations introduced by the new legislation, including the required organisational and technical measures, must be implemented. Different timelines may apply in specific cases, for example for entities entered automatically or those meeting the criteria at a later date.

What are the consequences of non-compliance with NIS2 / KSC requirements?

Non-compliance with NIS2 / KSC requirements may lead to sanctions or administrative fines. The consequences depend on the type of entity, the nature of the non-compliance and the circumstances of the case. Irrespective of regulatory sanctions, insufficient safeguards may increase the risk of cyberattacks, operational disruption, data loss and financial damag

What is a Gap Analysis?

A Gap Analysis compares the way an organisation currently manages cybersecurity with NIS2 / KSC requirements. It covers areas including existing processes and documentation, roles and responsibilities, risk management, incident response, business continuity, supplier security, and the protection of systems and data. It shows which requirements are already met, where gaps remain and what actions should be taken to address them. The scope may be extended to include an implementation plan setting out priorities, responsibilities and indicative timelines. 

Our organisation operates within an international group. Are NIS2 requirements the same in every country?

No. NIS2 is an EU directive, but each Member State implements it through their national legislation. This creates differences in timelines, detailed requirements, registration rules, regulatory expectations and supervisory practices. International groups should therefore ensure they address local requirements in each country they operate in. Through the Forvis Mazars international network, we involve local offices on international projects to provide support reflecting the requirements and supervisory practices in each specific jurisdiction as understanding each country’s requirements is key for ensuring compliance.

Can a small organisation also be subject to NIS2 / KSC requirements?

Yes. Although the KSC Act generally covers medium-sized and large entities in specified sectors, smaller organisations may also be in scope in certain circumstances. Some entities may be covered regardless of size due to the nature of their services, their particular importance to the economy or society, or designation by the competent authority. In addition, an organisation not directly subject to the KSC Act may receive demands to follow NIS2 / KSC cybersecurity requirements from regulated customers as part of their supply chain security management. The assessment of applicability should therefore consider both statutory criteria and the organisation’s role in the supply chain of entities subject to NIS2 / KSC.

Which areas of the organisation are affected by NIS2 / KSC requirements?

NIS2 / KSC requirements extend beyond IT and cover areas including management accountability, cybersecurity and risk management, incident response, business continuity, supplier and supply chain security, protection of information systems, documentation and reporting. Implementation typically requires cooperation between business, IT, security, risk, procurement, HR, legal and compliance teams, as well as executive management.

Does ISO/IEC 27001 certification mean compliance with NIS2 / KSC?

No. ISO/IEC 27001 certification generally indicates a higher level of maturity in information security management and may provide a strong foundation for preparation. However, it does not automatically demonstrate compliance with all NIS2 / KSC requirements. The certification scope and any requirements not fully covered by the existing management system should be assessed.

What does NIS2 / KSC preparation and implementation look like?

The process is typically delivered in stages: (1) assessment of whether the regulation applies and determination of entity status, (2) gap analysis against the requirements, (3) development of an implementation plan with priorities, ownership and timelines, (4) gap remediation implementation covering organisational, procedural and technical changes, (5) a post-implementation readiness assessment, and (6) an audit or self-assessment as required. The detailed scope depends on the organisation’s profile, existing arrangements and maturity level.

How can Forvis Mazars help?

The first step can be a short discussion about the organisation’s profile, the potential applicability of NIS2 / KSC and possible next actions. This discussion is introductory and does not replace a formal assessment of whether the regulation applies and what the organisation’s status may be. Depending on the organisation’s needs, we can support this assessment with a gap analysis, comparing existing processes with the requirements and identifying the necessary actions to ensure compliance. Based on the listed gaps, we can help develop an implementation plan and support organisational, procedural and technical changes during implementation phase. After implementation, we can perform a readiness assessment as an optional and separate stage to verify whether the arrangements operate effectively and the organisation is compliant. We can also perform or support you in performing an audit or self-assessment. For international groups, we can coordinate multi-country programmes, combining a consistent group-wide approach with the local expertise of Forvis Mazars teams. This provides a clear and practical path tailored to the organisation’s scale, risk profile and maturity.

Want to know more?