Free Phishing Test

KSC self-identification is an independent assessment of whether the organization is subject to the Act on the National Cybersecurity System (KSC), implementing the NIS2 directive, and assigning itself to one of three categories: key entity, important entity or no obligation. To conduct it, you need to check the sector of activity, the size of the enterprise and the conditions set out in Art. 5 of the Act. The result of positive qualification is the obligation to enter the KSC Register by October 3, 2026. The amendment to the KSC Act will cover, according to the estimates of the Ministry of Digitization, approximately 38-42 thousand entities subject to regulation in Poland.

What is self-identification in KSC?

You may be running a company operating in a sector covered by the regulations KSC 2.0. However, you have not received an official letter informing you that from today you are a key or important entity. Your organization must be the first to check whether the new obligations actually apply to it.

This is what self-identification is all about. This is an independent assessment of whether the activities conducted are subject to the KSC 2.0 Act, and if so, whether the organization should be classified as a key entity or an important entity. The starting point for such an analysis is Art. 5 of the Act and Annexes No. 1 and No. 2, which indicate the sectors, subsectors and types of activities covered by the regulation.

In practice, however, it is not enough to check the PKD code entered in the National Court Register. What is much more important is what the company actually does, what services it provides and on what market it operates. If the organization’s actual activities fall within the sector covered by the Act, the provisions may apply even if the main PKD code does not indicate so.

Properly performed self-identification should result in a clear answer:

If the analysis shows that the company belongs to one of the first two categories, the next step will be to make an entry in the KSC List. This is an official register of key and important entities, kept by the Minister of Digitization in the application wykaz-ksc.gov.pl and technically based on the S46 System.

Who is obliged to self-identify?

The obligation to self-identify applies to every entity operating in the sector indicated in the annexes to the Act on the National Cybersecurity System – regardless of whether it is a private company, a company with local government participation, or an office. Two pillars determine membership in the system: sector of activity and size of the organization.

The sector decides whether a given activity is included in the catalog protected by the Act at all – energy, finance, health care, transport, water and sewage management and several other industries listed in Annexes 1 and 2 (read more in the article about the amendment to the KSC). However, size determines which of the two categories of entities an entity that meets the sector criterion falls into.

The key entity criteria from Annex 1 differ from the important entity criteria from Annex 2 primarily in the importance of the potential effects of the incident on the state and the economy, not in the assessment mechanism itself.

When calculating the size, not only one’s own employment and finances are taken into account, but also related and partner enterprises – a Polish company may suddenly become a large entrepreneur through a foreign investor or shares in a capital group, even if it employs few people itself. The Act on the National Cybersecurity System does not distinguish between the private and public sectors: the obligations cover both, and the fact that the owner of the company is a commune or the State Treasury does not in itself determine the qualification.

We can help you determine whether your organization is subject to KSC – as part of an ISMS audit, which combines the perspective of a legal advisor with technical security diagnosis and practical team training.

How to self-identify KSC? Three steps according to the Ministry of Digitization

The Ministry of Digitization divides the self-identification process into three steps: checking the sector, determining the size of the enterprise and analyzing Art. 5 of the Act. The order matters – only the result of all three steps together gives the answer whether the entity is key, important, or not subject to the Act at all.

01 Check your business sector

The first step is to verify whether the business activity is within the sectors or subsectors indicated in Annex No. 1 (key entities) or Annex No. 2 (important entities) to the Act. The Ministry of Digitization emphasizes that what matters in this assessment is the actual nature of the business, and the PKD code has only auxiliary meaning – the actual scope of services provided or tasks performed is decisive, not the entry in the register.

For example, a company that operates in one industry on paper, but actually provides services from the sector covered by the Act – e.g. as a subcontractor in the energy or health care supply chain – should verify itself in relation to this real scope of activity, not in relation to the code in the National Court Register. Even an entity providing services only partially covered by the Act should analyze this part of its activities separately.

02 Specify the size of the company

The second step is to determine the size of the entity according to the thresholds of micro, small, medium and large enterprises, including affiliated and partner enterprises.

The thresholds are checked separately: it is enough to exceed one criterion – employment or financial – for the company to be placed in a higher size category, even if the second criterion remains unmet.

There is one clear exception to this rule. Telecommunications undertakings covered by the amendment to the Act, regardless of their size, have a different qualification threshold for the key/important category than other industries:

SizeType of entity (telecommunications undertaking)
Large entrepreneurkey entity
Medium-sized entrepreneurentity key
Small entrepreneurimportant entity
Micro-entrepreneurimportant entity

This is exactly the exception explained by the case from our webinar about KSC: a telecommunications organization employing less than 50 people, but with a revenue of over EUR 10 million, is a key entity – despite the small number of employees, because in telecommunications already an average entrepreneur has the status crucial, not important.

We invited a legal advisor and a partner of a digital law firm to a discussion about UKSC / NIS2, during which we broadly discussed the topic of self-identification and entry into the KSC List – receive free access to the recording and additional materials!

03 Analyze the article. 5 of the Act

The third step is the analysis of art. 5 of the KSC (Article 5 of the Act on the National Cybersecurity System), which specifies detailed rules for recognizing entities as key or important, including cases of being covered by the Act, regardless of their size. Only after analyzing this provision can you finally determine whether the entity is key, important or not subject to the provisions at all

Meeting the conditions of Art. 5 clearly means that the entity will be subject to the provisions of the Act regardless of the result of the second step – it is this path that allows, for example, a small municipal company to fall into the category of an important entity despite not meeting the size thresholds (full case in the section below). In some cases, an organization that does not formally meet the size criteria, but meets the sectoral conditions set out in Art. 5.

Additional tools to help with self-identification

Before you start manual analysis from scratch, compare your findings with ready-made tools:

  1. SME qualifier from PARP – the official tool for determining the size of an enterprise.
  2. UKSC/NIS2 Validator by Muszyński Law Firm – a free preview tool covering all three steps.
  3. Guides of the Ministry of Digitization – official explanations and answers to questions, updated on an ongoing basis.

None of these tools is a substitute for legal analysis. They provide an indicative result, based on data that you enter yourself – they do not take into account nuances such as affiliated enterprises, sector exceptions or the conditions under Art. 5.

If you have any doubts about the qualifications of key and important entities, it is best not to guess on your own – contact us to discuss the result of self-identification and the scope of the ISMS audit tailored to your organization.

Key or important entity? Examples of qualifications from practice

The sector and size criteria themselves sound simple on paper, but in practice, lawyers specializing in KSC regularly receive questions about borderline cases. The table below shows six typical situations and their qualification score.

Municipal company: waterworks and sewage, 20 employees

Limited limited liability company with 100% of the commune’s shares, operating in the water and sewage sector (Annex No. 1) and employing 20 people, does not reach the threshold of an average entrepreneur in terms of size. Nevertheless, it qualifies as an important entity – it does not meet the size criteria, but carries out a public utility task using information systems (Article 5(2)(8) of the UKSC).

Telecommunications entrepreneur below the employment threshold

A telecommunications company employing less than 50 people but with revenues exceeding EUR 10 million meets the criteria of a medium-sized entrepreneur despite low employment. In telecommunications, a medium-sized entrepreneur already has key status – this is a sector exception, so the company qualifies as a key entity.

Energy operator with over 250 employees

A large energy company (Annex No. 1), employing over 250 people, qualifies as a key entity – the sector and size clearly indicate this. However, it is worth remembering that some operators of particular importance for the energy system (e.g. transmission system operators) may be key entities regardless of their size – similarly to the telecommunications exception described above. Therefore, step 3, i.e. analysis of Art. 5, it is worth verifying even in seemingly obvious cases.

Catering company outside the sectors from the attachments

A small catering company employing 15 people operates outside the sectors indicated in the annexes to the Act – it is not subject to the KSC. The food sector covered by the amendment mainly concerns wholesale distribution and large-scale industrial production and processing of food, not catering and catering services operating locally. A company from the food industry should check on which side of this border it actually is, instead of relying solely on the general term “food sector”.

IT supplier for the energy operator

A small IT company (30 employees), providing services to an energy operator, does not itself operate in the sector indicated in the attachments – it is not automatically covered. Being a supplier of an entity covered by the KSC does not in itself determine coverage by the Act, but the contractor may impose contractual requirements.

The result of self-identification based on sector and size is not always final

The Act provides for an additional path: the minister may, by administrative decision, recognize an entity as key if it is the only one providing a service of key importance for critical social or economic activity via an information system – regardless of the fact that according to the size thresholds the entity would be considered important or even outside the scope of the Act. This applies, for example, to the only water supplier in the commune, with no alternative for residents: lack of competition on the local market may be the basis for the minister’s decision, even if the company does not meet the threshold of a medium-sized entrepreneur.

A separate category consists of digital service providers (e.g. providers of cloud, trading platforms or internet search engines) andexisting key service operators, operating under the old Act of 2018 – both groups were entered into the KSC List ex officio, without the need for self-registration.

The case of a municipal company from the table above comes directly from the questions asked at our webinar on the implementation of KSC. Legal advisor Jerzy Muszyński explained when such a company may be considered an important entity despite not meeting the employment threshold:

It may be determined by the fact that the company carries out public tasks, a public utility task within the meaning of the Municipal Economy Act, and carries out public tasks using information systems.
Jerzy Muszyński, legal advisor at SECAWA

Marcin Serafin drew attention to a threshold that is easy to forget about in such a company – the number of employees is not the only criterion:

This is something that could potentially be important […] because if it is to reach this threshold of ten million euros in turnover or balance sheet total, it will be subject to this regardless of whether it has twenty or two hundred employees.
Marcin Serafin, digital law specialist, partner of the Sterberg law firm

Twenty employees of a water and sewage company from our table are not enough to cross the threshold of a medium-sized entrepreneur – but if its turnover or balance sheet total reached EUR 10 million, qualification would be certain regardless of employment.

By when do you have to self-identify? Key terms

The deadline for self-identification and entry into the KSC List is October 3, 2026. The schedule is as follows:

Self-registration takes place via the Wykaz KSC application, after logging in with a trusted profile, e-ID, electronic banking or qualified signature.

The lack of penalties until 2028 does not mean the absence of an obligation – failure to self-identify and register is a violation of the regulations from day one, but not financially enforceable. Why this distinction can be confusing, we described in more detail in the article about why the lack of penalties until 2028 is a trap.

The most common errors when self-identifying and starting the implementation of the KSC Amendment

Legal advisor Jerzy Muszyński, based on implementation experience and control practice, pointed out six errors during the webinar that most often mean that the KSC implementation starts in the wrong direction from the very beginning:

The group of key and important entities that make these mistakes include both large, experienced organizations and those entering the system for the first time. KSC imposes the obligation not only to register, but above all to conduct real risk management – neglect of the duties of key entities is usually revealed only during an inspection or security incident.

Why is it worth leaving an evidentiary trail?

Self-identification without documentation is self-identification that does not exist in the eyes of the controller. As Jerzy Muszyński emphasized:

Every company should perform such self-identification and approach this self-identification in an evidential way, i.e. leave some trace of this self-identification.
Jerzy Muszyński, legal advisor at SECAWA

In practice, an evidentiary trail means a specific set of documents, not the decision itself recorded in an email or agreed at a management meeting. It’s worth preparing:

Such a set of documents serves two functions at once. Firstly, it organizes the analysis itself – it is difficult to confuse a category when the data is compiled in one place and not scattered in the memory of several people. Secondly, it becomes defensible material: if the regulator asks why the company qualified in a certain way, the answer is a document, not a memory from a conversation from a year and a half ago.

Self-identification documentation is not an isolated trace – it becomes the first element of broader information security management system (ISMS) documentation, which will need to be expanded after being included in the list. A positive result of self-identification triggers the obligation to enter the KSC List, and the documentation referred to above is proof that this entry obligation was preceded by a reliable analysis, not guesswork.

Application to the KSC List – frequently asked questions

What is self-identification in KSC? Self-identification is an independent assessment of whether an organization is subject to the Act on the National Cybersecurity System and assigning itself to the category of a key or important entity or determining that the Act does not apply to it. The analysis is carried out independently, without a request from the office.

By when do you have to self-identify? The window for self-registration in the KSC List lasts from May 7 to October 3, 2026. Entities entered ex officio – m.in. public and telecommunications entrepreneurs – were registered earlier, by May 6, 2026.

Is there a penalty for failure to report by October 3, 2026? Not immediately. Fines are in force only from April 3, 2028, but the registration obligation itself runs regardless of this exclusion – the delay does not eliminate the violation of the regulations, but only postpones its financial enforcement.

Is a company that is a supplier of an entity covered by the KSC also subject to the Act? Not automatically. The mere fact of being a supplier of a key or important entity does not determine coverage by the act, but the contractor may impose security requirements in the contract – this is a typical mechanism for spreading the obligations of regulated entities to the rest of the supply chain.

Does outsourcing at KSC exempt you from statutory obligations? No. Outsourcing at KSC – for example, outsourcing hosting, cloud or data center services to an external supplier – does not transfer statutory liability. The key entity ensures the security of its systems regardless of whether it maintains the infrastructure itself or through a subcontractor, and must supervise this as part of supply chain management.

What tools help in self-identification? The SME qualifier from PARP and the UKSC/NIS2 validator from the Muszyński law firm provide an indicative result based on self-entered data. None of them replaces legal analysis – if in doubt, it is worth consulting the result with a lawyer specializing in KSC.

Summary

Self-identification is determined at the intersection of three elements: the sector of activity, the size of the enterprise and the conditions set out in Art. 5 of the Act – none of them alone gives a certain answer. An error made at this stage costs more than the classification error itself: it leads to an unnecessary implementation project, overlooked responsibilities, or documentation that will not withstand the question of why the company qualified this way and not another.

The deadline for registration in the KSC List is October 3, 2026, and organizations that are already unsure about their status today usually do not start any other implementation work.

We implement KSC in the alliance of law (Kancelaria Muszyński) and technology (SECAWA) – from the qualification of the entity, through cybersecurity audit, to the action plan and team training. If you want to determine where your organization stands, ask about an ISMS audit.

Arrange an ISMS audit: legal analysis of the entity’s qualifications, technical security review and a report with action priorities in one study.

Penalties for non-compliance with UKSC/NIS2 will not apply until April 2028 – sounds like good news, but it is not. The two-year period without sanctions can easily be confused with the impression that there is still plenty of time. And this is the worst reason to delay implementation of the amendment to the Act (KSC 2.0).

Because punishment is not the first thing that will happen. First comes the incident: interrupted business continuity, customers who cannot be served, and contracts that go to better-prepared competitors.

Therefore, the real deadline to think about when implementing UKSC/NIS2 is not written in the Act. It is determined by the first incident, customer pressure and personal responsibility of the management board – and these do not wait until 2028. During the webinar on KSC implementation, we broke down this trap into prime factors – if you want to gain access to recordings and materials, fill out the form on this page.

Where did the two-year penalty-free period come from?

The Act provides for a transitional period during which administrative fines for non-compliance are not imposed. It covers the first two years of the regulations being in force, i.e. until April 2028. This also applies to a situation in which the entity does not report to the KSC List on time (by October 3, 2026).

For the first two years after the entry into force of the act, i.e. until April 2028, no penalties will be imposed at all. There is a clear exclusion in our act – it will not be possible to impose a financial penalty for someone who does not report to the list of KSC entities by October 3.
Marcin Serafin, digital law specialist, partner of the Sterberg law firm

However, it is worth separating two things: no penalty from no obligation. The provisions apply from the date the Act enters into force – only the possibility of their financial enforcement in the first period is excluded. The deadlines for the implementation itself (full implementation of the ISMS and connection to the S46 system by April 3, 2027) run regardless of this exclusion.

Postponing the topic until 2028 is actually abandoning it

The main effect of delay is that theorganization does not start workat all. Failure to register is usually a symptom of a broader problem – uncertainty about one’s status, which blocks subsequent steps. Marcin Serafin pointed this out:

If someone does not report, it is probably not because they already know everything, but just forgot to do it – but probably because they have put it off and are still not entirely sure whether they are subject to it, to what extent they are subject to it, and consequently they cannot actually start work related to the implementation.  And this is actually the whole point.
Marcin Serafin, digital law specialist, partner of the Sterberg law firm

The entire process of preparing the organization is postponed – from qualifications, through systems inventory, to response procedures. It is worth remembering that compliance is not the default state: as noted in the interview, most organizations still need to be adapted to NIS2 and KSC, and being “automatically” compliant is the exception, not the rule.

The risk of punishment increases with the risk of the incident

Administrative punishment rarely occurs in isolation from the event. In practice, it is the result of an incident – loss of data or interruption of business continuity – and not the formal misconduct itself.The less prepared the organization, the greater the probability that such an event will occur, and the more serious its consequences.

At the webinar about KSC, an important caveat was made: high-profile, publicly disclosed ransomware attacks are only the tip of the iceberg. Below it are organizations that suffered measurable losses, numbering in millions, as a result of incidents, although they never made headlines. From this perspective, the date 2028 is irrelevant for risk assessment – events are not guided by the legislator’s calendar.

There is also a personal dimension. The amendment makes the management responsible for cybersecurity, and delegating tasks to the IT department does not remove this responsibility – it also changes the position of the person responsible for security, as we wrote about in more detail in the article “How does UKSC/NIS2 affect the role of CISO?”.

Why are penalties not the main tool for enforcing compliance with UKSC?


Sanctions are not a mechanism on which the legislator bases the effectiveness of regulations. If the goal was to enforce compliance through the threat of penalties, the design of the regulations would be different.

The legislator does not think that penalties will force someone to implement or not implement – because if that were the case, automatic scanning of everyone would be implemented, not administrative proceedings and so on. However, the legislator thinks that if we deal with issues, we will think about how to adapt, we will analyze the risks associated with us and therefore we will adapt and it will be a process, not a one-off project that will end.
Marcin Serafin, digital law specialist, partner of the Sterberg law firm

The purpose of regulation is to encourage organizations to manage risk on an ongoing basis. Cybersecurity treated as a permanent process, and not a one-off project closed with an entry in the list, actually reduces the likelihood of an incident. It is this change in approach, and not formal compliance itself, that is the effect that UKSC is about.

The market enforces requirements faster than the legislator

Compliance with UKSC/NIS2 is increasingly verified not by authorities, but by contractors. This was pointed out by Jerzy Muszyński, legal advisor:

The pressure associated with KSC is not due to deadlines and penalties, but rather because – in my opinion – these requirements are starting to flow through the supply chain, contracts, customer audits, requests for proposals and management accountability.  Because, in fact, for the first time in such a broader context, we can talk about the company’s management board being an active entity participating in the current management of cybersecurity within the company’s structures.
Jerzy Muszyński, legal advisor to SECAWA

This is confirmed by experience with GDPR. Over the eight years that the regulations have been in force, approximately one hundred financial penalties have been imposed in Poland, and yet the level of security has clearly increased – it was not caused by sanctions, but by market requirements.

With UKSC, the mechanism is the same: the entity covered by the act must manage the security of the entire supply chain, so it transfers the requirements to its suppliers by contract. An organization that does not meet the standard will not receive a fine from the state, but may lose its contract – and this happens well before 2028.

How to use the time to implement UKSC requirements?

It is worth treating the time until the sanctions enter into force as a space for calm, documented implementation, carried out without last-minute pressure. First, four actions make sense:

→ self-identification with the evidence left – determining whether and as what entity the organization is subject to the regulations,
→ inventory of critical systems and verification of backup copies of data on which business continuity depends,
→ developing and testing an incident response procedure,
→ implementation plan within a 30/60/90-day horizon, ready to be presented to the management board.

We advise how to approach the implementation of KSC – from the qualification of the entity, through legal and technical audit, to the action plan and team education. If you want to determine where your organization stands, briefly describe the situation to us and we will show you the first step.

KSC does not add new responsibilities to the CISO, but rather changes his role in the organization. Building digital resilience is something that mature companies have been doing for a long time – many of them have implemented security procedures, appointed responsible people, and systematically conducted tailored and realistic phishing simulations or organized cybersecurity training before the amendment appeared.

It is not a new technical obligation that raises the profile of the CISO role today, but the responsibility that has fallen on the management board. Amendment to the KSC Act, implementing the NIS2 directive, makes management personally responsible for cybersecurity.

We talked about what this change looks like in practice in a webinar with Marcin Serafin – a digital law specialist and partner of Sterberg law firm – and Jerzy Muszyński, a legal advisor who runs his own law firm. The conversation was moderated by Maciej Kołtoński, thanks to which there was also a business perspective. And if you want to watch the entire recording, fill out the form on this page.

What actually changes KSC in the CISO position?

KSC changes the position of the CISO – from a person performing technical tasks to a management partner who is personally responsible for cybersecurity.

So far, security has been treated as the subject of the IT department. The amendment shifts this burden higher, to the very top of the organization: it is the management who approves the risk analysis, provides the budget and is responsible for its own training, and delegating tasks to IT does not relieve it of its responsibility.

As legal advisor Jerzy Muszyński emphasized during the webinar:

For the first time, in such a broader context, we can talk about the fact that […] the company’s management board is to be an active entity participating in the ongoing management of cybersecurity within the company’s structures.
Jerzy Muszyński, legal advisor at SECAWA

The board needs a CISO as a risk translator

The management board, which is personally responsible for cybersecurity, necessarily must have someone who understands the risk, can manage it and translates it into decisions. It is from this relationship that the new position of CISO comes from.

Marcin Serafin described this mechanism directly:

When our management board members have their duties in terms of regular training, making decisions, and supervising the entire system of thinking about cybersecurity, they inevitably start to have to use someone who will explain this reality to them. Who will actually support them, and not just replace them.
Marcin Serafin, digital law specialist, partner of the Sterberg law firm

In other words: The CISO ceases to be a contractor, and becomes an advisor on whose analysis the management bases its own decisions – and its own responsibility.

CISO becomes an integral part of business

KSC 2.0 ends treating cybersecurity as a separate world, separated from business. Today, systems, data and tools are already a business – not an addition to it.

I hope that the problem of many CISOs who were left to themselves will end: do your own thing, tinker with your devices, analyze your reports, but don’t disturb our business. This is something that has to end – because this business is all about software and all these tools.
Marcin Serafin, digital law specialist, partner of the Sterberg law firm

For organizations, this means that security is no longer an incidental expense, but a condition for business continuity.

Not everyone is happy with this “promotion”

The growing importance of the CISO comes at a price – close, demanding cooperation with the management board. Not every specialist dreams of explaining risk to managers and sitting at the decision-making table. “This is a kind of increase in the importance of the CISO role within the organization (…). The CISO as a partner for the management is not left alone.” – said Marcin Serafin during webinar about KSC.

The advantage, however, is this: CISO stops working in a vacuum. He gains the support of the management board, but in return he has to spend more time explaining what exactly the threats are and how to solve them.

Why is there no single, universal definition of the CISO role?

A CISO in one organization is not the same as a CISO in another – these roles can be extremely different. The KSC clarifies the duties, but does not impose a single model for filling this position.

A CISO in an organization is not [equal to] another CISO in another organization. These roles are indeed extremely different.
Marcin Serafin, digital law specialist, partner of the Sterberg law firm

The differences in the CISO role concern resources, independence and the right to make decisions – some act independently, others are dependent on the management at every step.

Implication for the decision maker: Before filling this role, the board must decide the scope of authority, budget and independence of the CISO.

What does KSC mean in practice – for the management board and for CISO

Real change occurs when the CISO gets access to the management board, a budget and the right to make decisions – not just a title.

In practice, this means three things:

for the management board: training, social-engineering tests and penetration testing, approving risk analysis and security budget is an obligation, not a gesture of good will,
for CISO: more time to translate the risk in the language of business than on the risk itself tools
for the organization: clear path, who receives the decision and who is responsible for it.

Summary

The new position of CISO comes from the responsibility that KSC has placed on the management board.

This is a change that both parties can benefit from:

There is one condition: the CISO role must be given resources, budget and the right to make decisions.

The entire conversation – with specific examples, implementation schedule and question session is available on request. Sign up and you will receive access to the webinar recording and a set of materials (presentation and UKSC/NIS2 validator).

Free webinar. How to approach the implementation of KSC sensibly: so as not to take on everything at once, but also to complete the duties on time.

Poland’s Digitalization Strategy until 2035 is the first comprehensive document in the country’s history that organizes the country’s digital transformation around one goal – improving the quality of life of citizens thanks to digitization. It was developed by the Ministry of Digitization, and in October 2024 it was submitted for public consultations as a project replacing the Integrated State Computerization Program.

The document organizes activities around four horizontal areas:

They are complemented by detailed areas divided into three levels: state (including e-services, digital identity, cloud computing, open data), people (safe digital space) and economy and technologies (including artificial intelligence). In this structure, cybersecurity plays the role of a foundation that crosses other areas, and the credibility of all e-services depends on it.

The strategy sets out an increasing path of expenditure on digitalization: from approximately 0.8% of GDP in 2025 to 2% of GDP in 2030 and ultimately 5% of GDP in 2035, which corresponds to approximately PLN 100 billion annually after 2030.

Security teams will feel the effects of the Strategy very concretely. It announces:

In the following, we explain what the Strategy is, what it covers, what its schedule is and how to translate its provisions into the priorities of security teams.

What is the Polish Digitization Strategy until 2035?

Poland’s Digitization Strategy until 2035 is a cross-sectoral strategic document in the field of state computerization, which for the first time covers the digitization of the country as a whole – not as a separate ministry, but as a process permeating almost all areas of functioning of society, the state and the economy. The primary goal of the document is to improve the quality of life of citizens through digitalization by 2035

The strategy was prepared by Ministry of Digitization in cooperation with other government administration offices and with the participation of social and business stakeholders. It replaces the Integrated State Computerization Program and is intended to constitute a strategic basis for spending European funds intended for digitalization, setting the direction of negotiations for the upcoming financial perspective.

The document’s objectives are developed in related sectoral documents, including:

The conclusion for security managers is obvious: the general provisions of the Strategy will be detailed in sectoral regulations, which will directly affect the everyday work of IT and security teams. Tracking these documents is not a formality, but a source of specific obligations.

Why was the Strategy created?

The State Digitization Strategy was created to organize the development of digital services, which have so far been built in isolation from each other, without a common direction. As Deputy Minister of Digital Affairs Dariusz Standerski put it, the document “ends this era of fragmented development of digital services” and for the first time “defines our digital plan for the next decade.”

We set specific goals – in ten years, Poland will be the leader in the digital development of Europe. By 2030, 100% of key public services will be available digitally, 85% of Poles will have basic digital competences by 2035, and we will allocate 5% of GDP to digitization.
Dariusz Standerski, Deputy Minister of Digitization

The document responds to a specific ambition: Poland is to become the leader of digitalization in the European Union, and not remain a recipient of other people’s technologies. This is achieved by measurable goals with deadlines and indicators, including:

The strategy also clearly defines what digitalization should not do: make people dependent, disinform or exclude. Protecting citizens’ digital rights, protecting children and young people against harmful platform mechanisms and building technological sovereignty are treated on an equal footing with the development of e-services. The whole thing fits into the EU agenda “The Road to the Digital Decade” by 2030.

What does the Polish Digitization Strategy cover?

The strategy organizes the country’s digitalization in two dimensions: four horizontal areas, which constitute the foundation of the transformation, andthree levels containing detailed areas.

Four horizontal areas

This is the starting point of the entire Strategy – areas whose condition determines the success of the rest:

Three levels: State, People, Economy and Technologies

The remaining objectives of the Strategy are grouped into 17 areas on three levels:

On what principles is the Strategy based?

The strategy declares the principles according to which digitalization is to take place – and they set the limits of implementation:

Goals of the Polish Digitization Strategy

The strategy translates the vision into measurable goals, most of which have target values ​​set for 2035. The most important of them:

Schedule of the Polish Digitization Strategy

The strategy spreads the goals over time, from the most urgent institutional changes in 2025-2026 to the target year of 2035. Key milestones resulting from the indicator table:

The strategy is multi-annual, therefore it provides for a permanent management cycle, i.e. review of the document every 2 years and monitoring once a year, with a report to the Committee for Digitization and publication on the website of the Ministry of Digitization.

Summary

The State Digitization Strategy until 2035 combines Poland’s digital development into one measurable plan for the first time, in which cybersecurity is one of the four foundations determining the success of the rest.

For security teams, this is not an announcement of specific changes: a central cybersecurity institution based on PCOC, mandatory sector CSIRTs, a mechanism for identifying and limiting high-risk suppliers, a national migration plan to post-quantum cryptography and linking IT projects with the State Information Architecture.

These directions become binding through related regulations, primarily amendment of the Act on the KSC implementing the NIS2 directive and the Act on the National Certification System cybersecurity. The sooner the organization translates the provisions of the Strategy into its own map of responsibilities, the lower the risk that adaptation to new requirements will become an emergency action instead of a planned one.

The National Cybersecurity System (KSC) is a system of institutions, regulations and procedures designed to protect Poland against threats in cyberspace. Its principles are specified in the Act on the National Cybersecurity System, and from April 3, 2026, its extensive amendment – KSC 2.0 – is in force.

The new regulations implement the EU NIS2 directive and replace the existing regulations in force since August 2018. Work on the draft amendment to the Act was carried out by the Ministry of Digitization, and the result is the expansion of the system to include new sectors of the economy and a number of obligations for thousands of companies and institutions. Covered entities must, among other things, register in the KSC List, i.e. the official list of key and important entities, and implement an information security management system (ISMS). Negligence may result in severe financial penalties.

What is the National Cybersecurity System?

The National Cybersecurity System (KSC) includes all entities responsible for the security of networks and IT systems in Poland: from state institutions, through specialized incident response teams, to companies and offices providing services important to the economy. Its goal is to ensure the continuity of operation of key services and quick response to cyber threats.

The legal basis of the system is the Act on the National Cybersecurity System, adopted in 2018 andthoroughly amended in 2026. The work on the draft amendment to the Act resulted from two reasons:

  1. Necessity to implement the EU NIS2 directive, which increased the requirements for member states.
  2. Growing scale of threats in cyberspace for which existing regulations are no longer sufficient.

The new regulations change the system in three main areas: they expand the catalog of companies and institutions covered by the act, specify their obligations for risk management and introduce real sanctions for non-compliance.

Is it possible to implement KSC in a week?

Who does the new regulations apply to? Key entities and important entities

The amendment to the KSC organizes the scope of entities covered by the Act into two categories: key entities and important entities. The affiliation is determined by a combination of two criteria: the sector of activity (indicated in the annexes to the Act) and thesize of the organization, calculated taking into account affiliated and partner companies.

Key entity and important entity

Key entities are organizations whose disruption would have the most serious consequences for the state and the economy, for example in energy, banking, health care, transport or digital infrastructure. This also includes the current key service operators who already operated under the old act. Important entities includeother industries added by the amendmentwhere the incident is serious but less severe on a national scale. This division translates into the intensity of supervision: key entities are subject to stricter control than important entities.

What industries and entities are covered by the act?

The amendment to the KSC has significantly expanded the catalog of industries covered by the national cybersecurity system.

In addition to energy, finance and health care, the act now covers, among others, waste management, production and distribution of food and chemicals, postal services, the space sector and the management of ICT services.

The Act does not distinguish between the private and public sectors, the obligations cover both.

On the state side there are public administration entities and local government entities covered by the Act, including municipal offices acting as a public sector entity. On the market side, the act covers production and service companies as well as digital service providers.

All these organizations have one principle in common: self-identification. The entity itself assesses whether it meets the sector and size criteria and then reports without waiting for the office’s decision. If the business profile indicates the status of a key or important entity, the obligation to register arises automatically.

What obligations does KSC impose?

Key entities are obliged to implement a coherent system for protecting their networks and IT systems, and important entities implement the same statutory requirements to a slightly lesser extent.

The essence of the responsibilities of key entities isthe implementation of an information security management system (ISMS), i.e. a set of policies, procedures and safeguards that the organization applies, documents and regularly updates.

This system consists of several pillars:

These are selected pillars of a broader catalog of measures required by the KSC Act. The full scope additionally includes, among others: cryptography and communication security, security monitoring and testing, vulnerability handling, and physical and personnel security.

Incident reporting and the role of CSIRTs

In addition to preventive protection, statutory obligations includeincident reporting. Each entity must maintain incident handling procedures and report serious incidents to the appropriate CSIRT team within specified deadlines.

CSIRTs are computer security incident response teams. There are three national-level teams in Poland, of which the greatest role towards companies and local governments is played by CSIRT NASK. The amendment expanded their competences and added the possibility of creating sector-specific CSIRTs supporting entities in specific industries. Reporting an incident to CSIRT triggers support in analyzing the incident and mitigating its effects, and the CSIRT team can also warn other entities about the associated threat.

How to enter the KSC List?

Each key and important entity, after self-identification, must register in the official register. KSC List is a list of key and important entities maintained by the Ministry of Digitization, based on which the state knows who is responsible for the provision of key services and who is subject to the supervision obligation.

The Act provides for two modes of entry of an entity:

  1. Some organizations are entered into the register ex officio, i.e. on the initiative of the minister. This applies primarily to public entities, telecommunications undertakings, trust service providers and former operators of key services previously included in the list of key services.
  2. Other entities, mainly private ones, submit applications independently.

Self-registration takes place as online registration in the Wykaz KSC application. Login takes place via the National Node, i.e. a trusted profile, e-ID, electronic banking or qualified electronic signature. The application is submitted and signed by the entity’s manager or a person authorized by him. After the entry, the entity connects to the S46 system, a central channel for the exchange of information and threat warnings, acting as a digital cyber hub of the national system.

The most important date is October 3, 2026. By this date, newly covered entities must self-identify and submit an application for entry.
Jerzy Muszyński, Legal Advisor to SECAWA

The full list of entities obliged to register results from the annexes to the Act and size criteria.

How to self-identify?

Self-identification involves checking on your own whether your organization is subject to the Act and assigning yourself to the appropriate category. The Ministry of Digitization describes it in three steps, based onArt. 5 and Annexes No. 1 and No. 2 to the Act

After this analysis, the entity determines one of three results: it is a key entity, it is an important entity or it is not subject to the Act. The first two answers result in the obligation to enter the KSC List.

Manager’s liability and penalties for violations – KSC

KSC 2.0 moves responsibility for cybersecurity to the very top of the organization. It is the entity’s manager, i.e. the management board, director or commune head, who is personally responsible for the implementation of statutory obligations. He must approve the risk analysis and selection of security measures, provide a budget for them and undergo cybersecurity training himself. Delegating tasks to the IT department does not relieve it of this responsibility.

The implementation of obligations is verified by an audit. The first ISMS audit must be carried out by the key entity within 24 months of being covered by the Act, i.e. no later than April 3, 2028, and subsequent audits at least every three years. The audit checks whether the information security management system works in practice, and not just on paper.

Prepare your organization for KSC

Failure to fulfill obligations is subject to sanctions for violations in two dimensions.

  1. An organization may be subject to administrative fines for, among other things, failure to implement an ISMS or failure to register on the list.
  2. Separate fines apply to the manager and may reach the equivalent of 100% of his remuneration. However, the timing is important: penalties for most administrative obligations can be imposed only after April 3, 2028, which gives entities time to adapt.

Summary

The National Cybersecurity System, after the amendment of April 3, 2026, covers a much wider range of organizations than before and divides them into key entities and important entities. Each company and institution from the covered sectors must check its own status (self-identification), enter the KSC List by October 3, 2026, implement an information security management system (ISMS) and report incidents to the CSIRT teams. Responsibility for these obligations rests personally with the entity’s manager, and from April 3, 2028, failure to comply with them may result in real financial penalties.

The earlier an organization starts preparations, the easier it will be to meet the requirements of the Act without rushing and risking sanctions. A good starting point is a SECAWA ISMS audit. Together with our legal advisor Jerzy Muszyński we join ISMS legal audit and qualification of the entity under the Act with a technical cybersecurity audit, thanks to which you will receive a full picture of legal and technical gaps and a clear report with recommendations and action priorities, which will also serve as evidence of due diligence during inspections by the supervisory authority.

The analysis of incidents reported to the President of the Personal Data Protection Office (PUODO) in 2025 paints a disturbing picture: over 22,400 reported personal data protection breaches are a signal that the current risk management models are becoming ineffective. Moreover, the CERT Polska team handled over 250,000 security incidents in 2025 (over 600,000 reports, of which approximately 250,000 were identified as incidents). This is more than twice as high as in 2024.

In the era of full implementation of the AI Act (Regulation on Artificial Intelligence) and the evolution of threats, cybersecurity is no longer the domain of IT departments and is becoming a key element of the legal responsibility of management boards.

Risk modeling in the light of Art. 15 AI Act

Although many organizations use AI systems that do not qualify as high-risk systems, it isArt. 15 AI Actsets today the standards of “due diligence” in risk analysis. According to this provision, systems should be resistant to:

In legal practice, we increasingly recommend the use of the Art. 15 AI Act framework as an element of a data protection impact assessment (DPIA). The 2025 incidents showed that the unauthorized use of intelligent assistants to transcribe meetings without participants’ consent is not only a violation of privacy, but a potential legal tort. 

Identity as a legal parameter (Art. 32 GDPR)

The statistics are ruthless: 1/3 of breaches last year resulted from credential compromise. From the point of view of the data controller (ADO), the failure to implement multi-factor authentication (MFA) in 2025 may be interpreted as afailure to comply with the obligation to implement appropriate technical measuresin accordance with Art. 32 of the GDPR. 

The example of a doctor impersonated in order to obtain prescriptions for opioids shows that the legal consequences of a violation go beyond administrative fines – civil liability for personal injury is involved. 

AI Act checklist for CISOs for 2026:
High-risk AI systems

Security by Design – from code to compliance

“Security is not a function, but a consequence of decisions made when writing code.” This statement is strongly supported by thePrivacy by Designprinciple (Art. 25 GDPR). More than 75% of IT incidents that constituted data breaches resulted from application errors (e.g. SQL Injection). For a lawyer, this means that a compliance audit must include not only documentation (policies, registers), but also verification of software development processes and regular code reviews. 

HR verification challenges: NIS-2 and UKSC

The amendment to the Act on the National Cybersecurity System (UKSC) and theNIS-2guidelines introduce new rigors for personnel verification. It is worth paying attention to Implementing Regulation 2024/20690, which in point 10.2 suggests verifying the background of employees in certain cases. 

However, there is an important coincidence with labor law. The Provincial Administrative Court’s judgment (II SA/Wa 190/22) sets the limits of the admissibility of monitoring employees’ activity on social media. Administrators must balance the obligation to ensure security and protect employee privacy. 

Summary

2025 proved that “it doesn’t take a big hole to sink a ship – just one that no one knows about.” Effective data protection in 2026 requires abandoning “paper compliance” in favor of real vulnerability management and incorporating cybersecurity into the organization’s KPI structure. 

Although some provisions of the AI ​​Act have been in force since 2025 – including prohibitions on unacceptable practices and regulations on general AI models (GPAI) – the key moment for many organizations falls on August 2, 2026. From this date, all entities operating in the European Union that offer or use high-risk artificial intelligence systems must meet the detailed requirements arising from the AI ​​Act.

These responsibilities are not limited to legal departments – they include CISO, IT, security, compliance and board teams. Negligence may lead to severe sanctions: up to EUR 35 million or 7% of global turnover for the use of prohibited practices (e.g. behavioral manipulation, social scoring) and up to EUR 15 million or 3% for other non-compliance.

In this article, we show you how toachieve compliance with the AI ​​Act – with an emphasis onkey actions in 2026.

What is the AI ​​Act and who does it apply to?

What is the AI ​​Act?

AI Act is a regulation adopted by the European Union in order tocreate uniform rules for the design, implementation and supervision of artificial intelligence systems. It is directly applicable in all member states – like the GDPR – and covers both companies operating inside and outside the EU if their AI systems impact users in the EU.

The AI ​​Act is not limited to classic AI models. It also includes modern generative systems, autonomous agents, and even tools used only internally (e.g. for HR, finance or IT). In practice, if your organization uses any AI solution – even experimentally – the regulations apply.

What are the main goals of the AI ​​Act?

The AI ​​Act has one overarching goal – to increase trust in artificial intelligence. It does this through specific requirements regarding the security of systems, the transparency of their operation and the protection of users’ fundamental rights. In practice, this means, among others:

What do the provisions of the AI ​​Act cover and who do they apply to?

The AI ​​Act Regulation covers awide range of entities involved in the lifecycle of artificial intelligence systems, regardless of whether they operate in the European Union or offer their services to users in the EU. Obligations arising from the AI ​​Act concern in particular:

The scope of responsibilities depends on the level of risk assigned to a given system – the higher the risk, the more stringent the supervision, documentation and compliance requirements. You can read in detail about high-risk systems in the next part of the article.

AI Act checklist for CISOs:
High-risk AI systems

Schedule for implementation of AI Act provisions

The AI ​​Act formally entered into force on August 1, 2024, but the provisions will be implemented in stages – giving organizations time to prepare for compliance and implement necessary changes to AI systems, documentation and operational processes.

AI Act key dates

What next?

Why are the years 2026-2027 crucial for CISOs in the context of the AI ​​Act?

It is during these two years that themost operational obligations come into force for organizations using AI – both for high-risk Annex III models and non-standard solutions. Companies must be ready not only to comply with the AI ​​Act in terms of new implementations, but also to audit and adapt all existing systems that will be classified as high-risk systems under Art. 6 section 1 or are included in Annex III.

When does an AI system become high-risk?

AI risk classification system

The AI ​​Act classifies artificial intelligence systems into four levels of risk, based on the impact their use may have on the health, safety and fundamental rights of EU citizens. This classification determines the scope of responsibilities of organizations implementing or using a given system.

Four levels of AI risk according to the AI ​​Act

  1. Prohibited uses of AI (Unacceptable risk)
    AI systems that, by definition, pose a serious threat to human rights and freedoms are prohibited – e.g. behavioral manipulation, assessment of citizens (social scoring), mass recognition of emotions in the workplace or schools.
  2. High risk
    These are systems that – due to their impact on the lives of individuals – are subject to the most stringent regulations. They include, among others: AI in recruitment, education, health care, critical infrastructure, law enforcement and lending.
  3. Limited risk
    AI systems that do not directly affect the security or rights of users, but require transparency of operation. Example: chatbots – the user must be informed that he is talking to AI, not a human.
  4. Minimal risk or no risk
    AI used in purely functional or entertainment tools – e.g. photo filters, product recommendations. There are no specific regulatory obligations, but the implementation of good practices is recommended.

Free series of meetings for CISOs
AI vs Cybersecurity

What AI systems are considered high risk?

Artificial intelligence systems classified as high-risk (AI systems) are those that canactually impact the safety, fundamental rights or lives of users. The AI ​​Act details which applications are subject to such classification – based on the risk approach known from sector regulations, such as NIS2.

According to Annex III of the AI ​​Act, systems are considered high risk if they are used in the following areas:

From August 2, 2026, obligations related to these systems will apply to organizations that introduce them to the market or use them in their operational activities. FromAugust 2, 2027 – also for systems that are not explicitly listed in the Annex, but meet the general high-risk criteria specified in Art. 6 section 1 AI Act.

What are the obligations of organizations implementing high-risk systems?

Organizations that create or implement AI systems classified as high risk must meet a number of technical, organizational and documentation requirements set out in Chapter III of the AI ​​Act. The purpose of these obligations is to ensure security, transparency and compliance with the fundamental rights of end-users.

Key responsibilities include:

All of the above activities must be documented, regularly reviewed and available for review by regulatory authorities. From August 2026, failure to meet any of these obligations may result in financial sanctions and a ban on using the AI ​​system.

How to prepare your organization for the AI ​​Act? Key tips for CISOs for 2026

Summary

AI Act, the EU regulation on artificial intelligence, introduces coherent regulations for artificial intelligence systems used in the European Union. From August 2026, organizations implementing high-risk artificial intelligence systems must demonstrate full compliance with the new regulations.

The provisions of the AI ​​Act include, among others: compliance assessment, implementation of a quality management system, human supervision over AI operation, model transparency and mandatory documentation and registration. The regulation on artificial intelligence also provides for significant sanctions for violations – therefore, every organization using AI technologies should now prepare to meet the obligations that the Artificial Intelligence Act is intended to introduce.