The rules of the game changed three days ago

On 3 April 2026, Poland joined the group of Member States that have finally — more than a year late — transposed the NIS-2 Directive into national law. The amendment to the Polish NIS-2 implementing act (the KSC Act), signed by the President in February and published in the Journal of Laws on 2 March, is not just another piece of legislation to be shelved next to the binder of security policies. It is a systemic change — and one that calls for action, not reading.

For thousands of Polish businesses and public institutions, the countdown has begun. Six months to register in the list of entities. Twelve months to implement the requirements. And penalties for inaction running into millions of euros. It is worth looking closely, then, at exactly what has changed and what follows from it for those the act applies to.

Who the amended KSC Act covers

The national cybersecurity system as it stood until now covered a relatively narrow group: operators of essential services designated by administrative decision, and digital service providers. The amendment reverses that logic. Instead of waiting for a decision from an authority, an entity must itself assess whether it meets the criteria for classification as an essential or important entity — and self-identify within the statutory deadline.

There are two types of criteria. First, sectoral: the act lists eighteen sectors of the economy, from energy through transport, health, drinking water and wastewater, to digital infrastructure, public administration and space. Second, thresholds: in the private sectors, what counts is the size of the undertaking measured by headcount (at least fifty employees) or annual turnover (at least ten million euros).

For the public sector — local government units, their subordinate units and municipal companies — the size thresholds do not apply. Here it is the nature of the activity that decides: a water utility serving a municipality of three thousand residents is subject to the same rules as a metropolitan water group. The difference lies only in the scale of the obligations, not in whether they exist.

The obligation calendar — six dates worth noting

The KSC amendment sets out a precise implementation timetable. Missing any of these deadlines can mean not only a financial penalty but also entry in the list ex officio, with all the consequences that entails.

The first date has already passed: 3 April 2026 — the day the act entered into force. All the deadlines run from that moment.

The second: 12 June 2026 — the launch of the S46 system, the electronic platform through which entities will submit applications for entry in the list, report incidents and communicate with the competent authorities. The system will be available at wykaz-ksc.gov.pl.

The third: 3 October 2026 — the final deadline for submitting an application for entry in the list of essential or important entities. Six months from the act's entry into force is not a lot of time once you factor in the need to self-identify first, to inventory your systems and to prepare the required documentation.

The fourth: 3 April 2027 — the deadline for full implementation of the statutory requirements. Twelve months to build or adapt an information security management system, carry out a risk analysis, implement technical and organisational measures, train staff and establish incident reporting procedures.

The fifth: 3 April 2028 — from that day, the competent authorities may impose administrative penalties at their full level. The two-year transition period does not, however, mean that the rules can be ignored with impunity until then — the authority is entitled to open proceedings earlier if it finds gross negligence.

The sixth: security audits — an essential entity must carry out its first security audit within twelve months of entry in the list, and every two years thereafter.

What exactly has to be implemented — ten pillars of security

The act requires essential and important entities to implement cybersecurity risk management measures covering at least ten areas. This is not an optional list — each of these elements must be reflected in the organisation's documentation and practice.

The first pillar is risk analysis and an information systems security policy. This is not a one-off document produced for the benefit of an audit, but a living process — regularly updated, taking account of changing threats and new assets.

The second is incident handling, covering procedures for detecting, responding to, analysing and recovering from events that compromise security. The KSC amendment introduces a three-stage reporting schedule for significant incidents: an early warning within twenty-four hours, an intermediate report within seventy-two hours and a final report within a month.

The third is business continuity — backup management, disaster recovery plans and crisis management. For water, sewerage and energy undertakings, where an interruption to service directly affects people's health and lives, this is no abstract requirement.

The fourth is supply chain security, including the security of relationships with direct suppliers and service providers. In practice this means auditing suppliers, security clauses in contracts and monitoring the risks that flow from dependence on third parties.

The remaining pillars cover: security in the acquisition, development and maintenance of networks and information systems; policies and procedures for assessing the effectiveness of risk management measures; basic cyber hygiene practices and training; policies on the use of cryptography and encryption; human resources security, access control and asset management; and the use of multi-factor authentication.

Management accountability — personal and non-delegable

This is perhaps the most important change the amended KSC Act brings. Responsibility for cybersecurity rests directly with the entity's management body — the company's management board, the head of a rural municipality, the mayor, the chief executive. Not with the IT specialist, not with the information security officer, not with an external consultant.

Management is required to approve risk management measures, oversee their implementation and answer for any failures. What is more, members of the management body must undergo cybersecurity training — not once, but regularly. This is not a formality. The competent authority may check whether the training took place, what it covered and whether its content was appropriate to the organisation's risk profile.

In a local government context, this means that a municipal head who signs an ordinance on the information security policy but has never attended training and does not understand what the document is about is exposing themselves to personal administrative liability.

Penalties — specific amounts, real consequences

The KSC amendment introduces a system of administrative penalties modelled on the familiar GDPR mechanism. For essential entities, a fine may reach EUR 10 million or 2% of total worldwide annual turnover, whichever is higher. For important entities, it is up to EUR 7 million or 1.5% of turnover.

The penalties do not apply only to security breaches. They may also be imposed for failing to submit an application for entry in the list, failing to report an incident within the required deadline, failing to implement the required risk management measures, or failing to comply with the competent authority's recommendations.

It is worth emphasising: the two-year transition period relating to the full level of penalties is not a two-year period of impunity. The competent authority may carry out inspections from the day the act enters into force — and any failures identified may form the basis for sanctions once the transition period ends, with retrospective effect covering findings made earlier.

What the S46 system will not do for you

The S46 system — the electronic platform supporting the national cybersecurity system — is a tool, not a solution. It will let you submit an application for entry in the list, report incidents and communicate with the authorities. What it will not do is carry out the organisation's risk analysis, write its security policies, train its staff or implement technical measures.

Organisations waiting for S46 to go live on the assumption that "we'll deal with it then" are losing valuable time. Registration is the last step in the process, not the first. Before an entity can submit an application, it must know which category it falls into (essential or important), identify its information systems, assess its risk and at least begin building a security management system.

What to do now — five steps for the next six months

For organisations that were not previously subject to the national cybersecurity rules but now fall within the scope of the amended act, we suggest the following sequence.

Step one: self-identification. Check whether the organisation meets the criteria for an essential or important entity, based on its sector and the size thresholds. This is not worth putting off — getting the classification wrong (or not making it at all) can cost more than the implementation itself.

Step two: an inventory of assets and information systems. It is hard to protect something you do not know about. A complete register of systems, devices, software and links to external suppliers is the foundation for everything that follows.

Step three: risk analysis. A methodical assessment of threats, vulnerabilities and potential consequences, carried out in a repeatable, documented way and tied to the context of the organisation's business.

Step four: building the ISMS documentation. Policies, procedures and instructions — tailored to the organisation, not copied from a template. Documentation that does not reflect reality is worse than none at all, because it creates a false sense of security.

Step five: registration in the S46 system. Once the platform goes live (12 June 2026), submit the application for entry in the list, together with the required information about the organisation and its systems.

The water and sewerage sector has its own funding and implementation route — we describe it in Cyber-secure water utilities — contracts and implementations.

How Fib.Code supports KSC 2.0 implementation

Fib.Code has worked for years with the kinds of organisations now facing national cybersecurity system obligations for the first time. We know the realities of local government, water utilities, district heating plants and municipal companies — we know that the cybersecurity budget in a municipality of five thousand residents looks nothing like that of a listed company, and we can deliver a solution within that budget that meets the act's requirements.

Our legal support with the amendment to the KSC Act covers the full cycle: from self-identification and gap analysis, through building the ISMS documentation, risk analysis and implementation of technical measures, to preparing for registration in the S46 system and ongoing support in the role of information security officer.

We wrote about how to choose an external partner for that role — and what to look out for so that the arrangement delivers real value — in our article on outsourcing the information security officer function.

Six months sounds like a lot. But anyone who has worked with local government knows that a procurement procedure can take three — and to start one, you first need to know the scope and cost of implementation. It is time to begin.

Book a free consultation: l.grabowski@fibcode.com | www.fibcode.com