The National Cybersecurity System (KSC) is a system of institutions, regulations and procedures designed to protect Poland against threats in cyberspace. Its principles are specified in the Act on the National Cybersecurity System, and from April 3, 2026, its extensive amendment – KSC 2.0 – is in force.
The new regulations implement the EU NIS2 directive and replace the existing regulations in force since August 2018. Work on the draft amendment to the Act was carried out by the Ministry of Digitization, and the result is the expansion of the system to include new sectors of the economy and a number of obligations for thousands of companies and institutions. Covered entities must, among other things, register in the KSC List, i.e. the official list of key and important entities, and implement an information security management system (ISMS). Negligence may result in severe financial penalties.
What is the National Cybersecurity System?
The National Cybersecurity System (KSC) includes all entities responsible for the security of networks and IT systems in Poland: from state institutions, through specialized incident response teams, to companies and offices providing services important to the economy. Its goal is to ensure the continuity of operation of key services and quick response to cyber threats.
The legal basis of the system is the Act on the National Cybersecurity System, adopted in 2018 andthoroughly amended in 2026. The work on the draft amendment to the Act resulted from two reasons:
- Necessity to implement the EU NIS2 directive, which increased the requirements for member states.
- Growing scale of threats in cyberspace for which existing regulations are no longer sufficient.
The new regulations change the system in three main areas: they expand the catalog of companies and institutions covered by the act, specify their obligations for risk management and introduce real sanctions for non-compliance.
Is it possible to implement KSC in a week?
Who does the new regulations apply to? Key entities and important entities
The amendment to the KSC organizes the scope of entities covered by the Act into two categories: key entities and important entities. The affiliation is determined by a combination of two criteria: the sector of activity (indicated in the annexes to the Act) and thesize of the organization, calculated taking into account affiliated and partner companies.
Key entity and important entity
Key entities are organizations whose disruption would have the most serious consequences for the state and the economy, for example in energy, banking, health care, transport or digital infrastructure. This also includes the current key service operators who already operated under the old act. Important entities includeother industries added by the amendmentwhere the incident is serious but less severe on a national scale. This division translates into the intensity of supervision: key entities are subject to stricter control than important entities.
What industries and entities are covered by the act?
The amendment to the KSC has significantly expanded the catalog of industries covered by the national cybersecurity system.
In addition to energy, finance and health care, the act now covers, among others, waste management, production and distribution of food and chemicals, postal services, the space sector and the management of ICT services.
The Act does not distinguish between the private and public sectors, the obligations cover both.
On the state side there are public administration entities and local government entities covered by the Act, including municipal offices acting as a public sector entity. On the market side, the act covers production and service companies as well as digital service providers.
All these organizations have one principle in common: self-identification. The entity itself assesses whether it meets the sector and size criteria and then reports without waiting for the office’s decision. If the business profile indicates the status of a key or important entity, the obligation to register arises automatically.
What obligations does KSC impose?
Key entities are obliged to implement a coherent system for protecting their networks and IT systems, and important entities implement the same statutory requirements to a slightly lesser extent.
The essence of the responsibilities of key entities isthe implementation of an information security management system (ISMS), i.e. a set of policies, procedures and safeguards that the organization applies, documents and regularly updates.
This system consists of several pillars:
- Risk management – based on a risk analysis policy that identifies threats and selects appropriate safeguards.
- Security procedures – regulating access to systems, including multi-factor authentication (MFA) as a standard for account protection.
- Business continuity plan – allowing you to maintain services despite a failure or attack.
- Supply chain security – i.e. control of the risk posed by hardware and software suppliers, treated as a separate requirement of the security system.
- Cybersecurity training and cyber hygiene – regular raising of employee awareness, because humans remain the most common target of attacks. According to the report CERT Polska 2025, phishing was responsible for 30% of all registered incidents. Therefore, our Practical Anti-Phishing Training, thanks to personalized phishing simulations, tailored to real attacks from Polish cyberspace, teaches the team to recognize and report incidents.
These are selected pillars of a broader catalog of measures required by the KSC Act. The full scope additionally includes, among others: cryptography and communication security, security monitoring and testing, vulnerability handling, and physical and personnel security.
Incident reporting and the role of CSIRTs
In addition to preventive protection, statutory obligations includeincident reporting. Each entity must maintain incident handling procedures and report serious incidents to the appropriate CSIRT team within specified deadlines.
CSIRTs are computer security incident response teams. There are three national-level teams in Poland, of which the greatest role towards companies and local governments is played by CSIRT NASK. The amendment expanded their competences and added the possibility of creating sector-specific CSIRTs supporting entities in specific industries. Reporting an incident to CSIRT triggers support in analyzing the incident and mitigating its effects, and the CSIRT team can also warn other entities about the associated threat.
How to enter the KSC List?
Each key and important entity, after self-identification, must register in the official register. KSC List is a list of key and important entities maintained by the Ministry of Digitization, based on which the state knows who is responsible for the provision of key services and who is subject to the supervision obligation.
The Act provides for two modes of entry of an entity:
- Some organizations are entered into the register ex officio, i.e. on the initiative of the minister. This applies primarily to public entities, telecommunications undertakings, trust service providers and former operators of key services previously included in the list of key services.
- Other entities, mainly private ones, submit applications independently.
Self-registration takes place as online registration in the Wykaz KSC application. Login takes place via the National Node, i.e. a trusted profile, e-ID, electronic banking or qualified electronic signature. The application is submitted and signed by the entity’s manager or a person authorized by him. After the entry, the entity connects to the S46 system, a central channel for the exchange of information and threat warnings, acting as a digital cyber hub of the national system.
The most important date is October 3, 2026. By this date, newly covered entities must self-identify and submit an application for entry.
The full list of entities obliged to register results from the annexes to the Act and size criteria.
How to self-identify?
Self-identification involves checking on your own whether your organization is subject to the Act and assigning yourself to the appropriate category. The Ministry of Digitization describes it in three steps, based onArt. 5 and Annexes No. 1 and No. 2 to the Act
- Check the sector. Verify whether your activity falls within the sectors or subsectors from Annex 1 (key entities) or 2 (important entities). The actual nature of the activity is decisive; the PKD code has only auxiliary meaning.
- Determine the size of the entity. Apply micro, small, medium and large enterprise thresholds, including affiliated and partner enterprises. Size determines assignment to a key or important category. The exception are telecommunications entrepreneurs who are subject to the Act regardless of their size.
- Analyze the article. 5 of the Act.The provision specifies detailed rules for qualification, including cases covered by the Act, regardless of size. Meeting its conditions clearly means that the organization is subject to regulation.
After this analysis, the entity determines one of three results: it is a key entity, it is an important entity or it is not subject to the Act. The first two answers result in the obligation to enter the KSC List.
Manager’s liability and penalties for violations – KSC
KSC 2.0 moves responsibility for cybersecurity to the very top of the organization. It is the entity’s manager, i.e. the management board, director or commune head, who is personally responsible for the implementation of statutory obligations. He must approve the risk analysis and selection of security measures, provide a budget for them and undergo cybersecurity training himself. Delegating tasks to the IT department does not relieve it of this responsibility.
The implementation of obligations is verified by an audit. The first ISMS audit must be carried out by the key entity within 24 months of being covered by the Act, i.e. no later than April 3, 2028, and subsequent audits at least every three years. The audit checks whether the information security management system works in practice, and not just on paper.
Prepare your organization for KSC
Failure to fulfill obligations is subject to sanctions for violations in two dimensions.
- An organization may be subject to administrative fines for, among other things, failure to implement an ISMS or failure to register on the list.
- Separate fines apply to the manager and may reach the equivalent of 100% of his remuneration. However, the timing is important: penalties for most administrative obligations can be imposed only after April 3, 2028, which gives entities time to adapt.
Summary
The National Cybersecurity System, after the amendment of April 3, 2026, covers a much wider range of organizations than before and divides them into key entities and important entities. Each company and institution from the covered sectors must check its own status (self-identification), enter the KSC List by October 3, 2026, implement an information security management system (ISMS) and report incidents to the CSIRT teams. Responsibility for these obligations rests personally with the entity’s manager, and from April 3, 2028, failure to comply with them may result in real financial penalties.
The earlier an organization starts preparations, the easier it will be to meet the requirements of the Act without rushing and risking sanctions. A good starting point is a SECAWA ISMS audit. Together with our legal advisor Jerzy Muszyński we join ISMS legal audit and qualification of the entity under the Act with a technical cybersecurity audit, thanks to which you will receive a full picture of legal and technical gaps and a clear report with recommendations and action priorities, which will also serve as evidence of due diligence during inspections by the supervisory authority.

